Daily Digest

Zero-Days Exploited, AI Security Tools Launch, Ransomware Surges

September 23, 2026
8 articles (6 new, 2 updated)
24 min read

Summary

Critical Vulnerabilities Under Active Exploitation:

  • Check Point Zero-Days in Management Servers and VPNs Under Active Attack: Check Point has released urgent patches for two critical, actively exploited zero-day vulnerabilities (CVE-2026-93616 and CVE-2026-85102) affecting their management servers and VPNs. Both have been added to CISA's KEV catalog, indicating widespread exploitation and requiring immediate attention.
  • F5 BIG-IP APM Zero-Day (CVE-2026-94127) Actively Exploited for RCE: F5 has issued an emergency patch for CVE-2026-94127, a critical unauthenticated RCE vulnerability in BIG-IP APM, which is being actively exploited. CISA has mandated federal agencies patch this vulnerability by September 25, 2026.

Evolving Threat Landscape and Tactics:

  • [UPDATE] Ransomware Attacks Hit 2026 High in July, NCC Group Reports: Ransomware activity reached a new 2026 record in August with 1,073 publicly reported victims, a 12% increase from July. The industrial sector remains the primary target, and the Qilin ransomware group has become the most prolific.
  • [UPDATE] BigCommerce Data Breach Caused by Compromised Third-Party App: Further analysis of the BigCommerce supply chain attack reveals that the compromised API key was used to inject malicious scripts into affected storefronts, suggesting a potential Magecart-style attack vector.
  • CLOSEDQUORUM: First Malware Found Using AI Panel for C2 Decisions: Cisco Talos discovered 'CLOSEDQUORUM,' a Windows malware implant that uses a panel of four commercial LLMs for its command-and-control decisions, representing a significant shift towards attack automation.
  • Malicious 'indexed-btree' NPM Package Amasses Millions of Downloads: A malicious npm package, 'indexed-btree,' was downloaded nearly two million times per week before removal. It evaded detection by hiding its loader and used the Ethereum blockchain for its second-stage C2.
  • DarkMe RAT Abandons Zero-Days for Simpler Phishing Attacks: The APT group Water Hydra has shifted from using zero-day exploits to distributing the DarkMe RAT via phishing emails with malicious .pif file attachments, indicating a move towards lower-cost, higher-volume attacks.

Industry Response to AI Security:

  • Vendors Launch New Tools to Secure Enterprise AI Adoption: In response to the rapid adoption of generative AI, cybersecurity vendors have released new platforms to discover and manage 'shadow AI,' control sensitive data flow into LLMs, and enforce responsible AI use policies.

Filter by Category

New Articles (6)

Updated Articles (2)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.