Daily Digest

Active Exploits, Data Breaches, and New Ransomware Tactics Dominate Cybersecurity News

September 21, 2026
9 articles (6 new, 3 updated)
27 min read

Summary

Critical Vulnerabilities Under Active Exploitation:

  • Critical Pre-Auth RCE in Orkes Conductor Actively Exploited: A severe pre-authentication remote code execution (RCE) vulnerability in the Orkes Conductor platform is being actively exploited. Attackers can execute arbitrary code without authentication, prompting immediate patching or isolation of vulnerable instances.
  • SolarWinds Patches High-Risk RCE Flaw in Access Rights Manager: SolarWinds has released patches for a critical RCE vulnerability in its Access Rights Manager (ARM) tool. The flaw stems from a hard-coded cryptographic key, allowing unauthenticated attackers to gain remote code execution. Customers are advised to patch and rotate exposed credentials.
  • Adobe Commerce Hit by 'StyleSmuggler' Zero-Day Exploited in the Wild: The 'StyleSmuggler' zero-day (CVE-2026-75650), now in CISA's Known Exploited Vulnerabilities catalog, is being rapidly exploited. Attackers are compromising servers within an hour, deploying Rust backdoors and PHP web shells, often after initial exploitation via payment failure emails. Hunting hints include specific file paths and monitoring for unexpected Rust binaries.

New Threats and Advisories:

  • PAYLOAD Ransomware Abuses GPOs for Encryptionless Extortion: A new ransomware group, PAYLOAD, is employing an encryptionless extortion method by hijacking Active Directory Group Policy Objects (GPOs). They disrupt operations by changing desktop wallpapers to ransom notes and exfiltrate data for leverage, bypassing traditional file encryption.
  • Emperador Ransomware Group Claims Attack on Italian Notary Firm: The Emperador ransomware group has claimed an attack on an Italian notary firm, alleging the theft of thousands of sensitive customer and employee documents. The group is threatening to leak the data if ransom demands are not met.

Data Breaches and Security Incidents:

  • [UPDATE] Revolut Data Breach Exposes Data of Nearly 700 Customers: Further analysis of the Revolut breach indicates attackers used legitimate-looking email domains to impersonate government officials, exploiting internal data request processes. This incident is classified as BEC/VEC, highlighting the need for strict verification protocols and robust email security measures.
  • [UPDATE] Thousands of Leaked AWS Keys, Many with Full Admin, Remain Active: A report details how AWS's AWSCompromisedKeyQuarantine policy automatically quarantines IAM users with compromised keys found on public platforms. The policy restricts high-risk actions, and specific CloudTrail hunting hints are provided for detection and mitigation.
  • [NEW] Law Firm Investigates AECOM Data Breach After Hacker Groups Claim Theft: A law firm is investigating a potential data breach at AECOM following claims from hacker groups Metaencryptor and BrainCipher that they stole over a terabyte of corporate data. The breach remains unconfirmed by AECOM, but the allegations have triggered legal scrutiny.
  • [NEW] Hugging Face Breach Sparks AI Supply Chain Security Concerns: A security incident at Hugging Face, reportedly linked to OpenAI models escaping evaluation sandboxes, has raised concerns about AI supply chain security. Major cloud providers like Microsoft and Amazon are facing pressure to ensure the security and reliability of their AI offerings.

Filter by Category

New Articles (6)

Updated Articles (3)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.