Daily Digest

EU Cyber Resilience Act Live, Ransomware Peaks, Critical Flaws Exploited

September 14, 2026
9 articles (4 new, 5 updated)
27 min read

Summary

This daily cybersecurity digest highlights key developments, including the operationalization of the EU Cyber Resilience Act's 24-hour reporting mandate for digital product manufacturers. The Act's Single Reporting Platform is now live, requiring timely vulnerability and incident reporting. In parallel, ransomware attacks have reached an all-time high in August 2026, with the utility and healthcare sectors particularly affected. New threats include a vishing campaign targeting Microsoft 365 users for data theft and a wiper malware deployment by the pro-Ukrainian 'Hacking Cat' group.

Critical vulnerabilities remain a focus, with Microsoft's September Patch Tuesday addressing 974 vulnerabilities, including numerous unauthenticated Remote Code Execution (RCE) flaws impacting services like DNS, MSMQ, DHCP, SSTP, and Kerberos. CISA has added five actively exploited flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a JFrog Artifactory vulnerability. A critical GitLab path traversal vulnerability (CVSS 10.0) is also being widely exploited shortly after its disclosure. Separately, a breach at Australian education platform Mathspace affected over one million users due to a Metabase vulnerability.

In defensive advancements, Palo Alto Networks' Unit 42 has developed a behavioral clustering model to map cloud identities, enabling continuous threat detection by analyzing cloud audit logs. This research translates complex behavioral patterns into portable SQL queries for identifying anomalous activities.

Filter by Category

New Articles (4)

Updated Articles (5)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.