Daily Digest

Critical Exploits, Data Breaches, and Policy Watchdog

September 12, 2026
8 articles (6 new, 2 updated)
24 min read

Summary

Critical Vulnerabilities Under Active Exploitation:

  • GitLab Path Traversal Vulnerability (CVE-2026-85706): CISA has added this critical vulnerability to its Known Exploited Vulnerabilities catalog, mandating remediation for U.S. Federal agencies due to confirmed active exploitation.
  • Cisco Firewall Flaws: Cisco is warning of active exploitation of two vulnerabilities in its Secure Firewall Management Center by ransomware gangs and state actors, including a CVSS 10.0 authentication bypass.

Data Breach Incidents and Updates:

  • LHC Group Health Data Breach: Following the disclosure of a data breach affecting over 162,000 individuals, a law firm has launched an investigation, suggesting potential class-action lawsuits.
  • Indian Tech Firm i2k2 Networks and Others Breach: Multiple data breaches have been reported, impacting i2k2 Networks, Grunthal Welding & Supplies Ltd., and India LEI, highlighting ongoing threats across various sectors.

New Threats and Operational Disruptions:

  • AI Weaponized in Supply Chain Attacks: High-profile attacks on Uber Freight, Ceva Logistics, and Fairlife demonstrate the growing threat of AI being used to orchestrate complex supply chain disruptions.
  • Windows 11 Update KB5124008 Breaks Always On VPN: The September 2026 cumulative update for Windows 11 is reportedly causing issues with Always On VPN connections, impacting secure remote access for enterprise users.

Policy and Legal Developments:

  • Ukrainian Conti Ransomware Developer Sentenced: An individual involved in the Conti ransomware operation has been sentenced to four years in prison in the U.S. for his role as an intruder and developer.
  • US Cybersecurity Information Sharing Law Faces Expiration: The Cybersecurity Information Sharing Act of 2015, which provides liability protections for sharing cyber threat intelligence, is set to expire in December 2026, prompting discussions on renewal and updates.

Filter by Category

New Articles (6)

Updated Articles (2)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.