Daily Digest

AI Fuels Sophisticated Attacks; Critical Vulnerabilities Demand Immediate Patching

September 13, 2026
7 articles (5 new, 2 updated)
21 min read

Summary

Critical Vulnerabilities Under Active Exploitation:

  • GitLab Path Traversal Vulnerability (CVE-2026-85706): This critical vulnerability, rated CVSS 10.0, is now actively being exploited in the wild, with exploitation attempts observed within 24 hours of the patch release. CISA has added it to its KEV catalog, mandating federal agencies to patch by September 14, 2026. Self-managed GitLab users are urged to apply patches immediately to prevent compromise.
  • CISA Adds Five Actively Exploited Flaws to KEV Catalog: CISA has added five actively exploited vulnerabilities affecting JFrog Artifactory (CVE-2026-42016, CVE-2026-82329), ConnectWise ScreenConnect (CVE-2026-84869), and MikroTik RouterOS (CVE-2026-67277, CVE-2026-86060) to its KEV catalog. These flaws pose significant risks, including remote code execution and administrative control, and federal agencies have a tight deadline for remediation.

Industrial Control Systems and Critical Infrastructure Under Threat:

  • [UPDATE] Threat Actors Use AI Scripts to Target Siemens PLCs: Siemens has released patches for a critical vulnerability (CVE-2026-12345) affecting SIMATIC S7 series PLCs, allowing unauthenticated remote attackers unauthorized access. This follows warnings about threat actors actively targeting these PLCs with AI-generated scripts. Asset owners should apply firmware updates and ensure proper network segmentation.
  • Ransomware Attack Hits Texas Water Treatment Facility via Vendor: A ransomware attack has disrupted operations at a Texas water treatment facility, believed to have originated through a compromised third-party vendor. This incident highlights the persistent threat of supply chain attacks against operational technology environments and follows a pattern of increasing cyberattacks against U.S. water systems.

Emerging Threats and Vendor Advisories:

  • Microsoft Details AI-Assisted Invoice Fraud Impersonating CEOs: Microsoft has uncovered a large-scale business email compromise (BEC) campaign using generative AI to impersonate CEOs and trick employees into fraudulent payments. The campaign sent over a million emails in three days, leveraging AI-generated templates, impersonation domains, and forged email chains for convincing narratives.
  • Check Point Patches Two Critical 9.8 CVSS Flaws in VPN Products: Check Point has released patches for two critical vulnerabilities (CVE-2026-85102, CVE-2026-85103) affecting its VPN and security management products. Rated CVSS 9.8, these flaws could allow remote, unauthenticated attackers to execute arbitrary code. Admins are strongly urged to apply the provided hotfixes immediately.

Industry and Policy Notes:

  • Anthropic CEO Urges AI Industry to Slow Down, Citing Takeover Risks: Dario Amodei, CEO of Anthropic, has called for the AI industry to slow its development pace due to escalating safety concerns, warning of potential AI takeover of the internet within 6 to 12 months. This warning is echoed by other industry leaders and follows recent AI safety incidents and employee resignations.

Filter by Category

New Articles (5)

Updated Articles (2)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.