Daily Digest

Ransomware Surges, ICS & Aviation Cyber Risks Highlighted

September 24, 2026
8 articles (7 new, 1 updated)
24 min read

Summary

Critical Vulnerabilities Under Active Exploitation:

  • [UPDATE] Ransomware Attacks Reached Record High in August 2026, NCC Group Finds: A recent report details a record high in ransomware attacks for August 2026, identifying top threat actors like Qilin and The Gentlemen. The update includes technical insights into common MITRE ATT&CK techniques, cyber observables, and hunting hints for detection, alongside mitigation strategies mapped to D3FEND techniques.
  • [NEW] MGM Resorts Shuts Down Systems to Contain Unspecified Cyberattack: MGM Resorts International has initiated a shutdown of some computer systems to manage a detected cyberattack on September 23, 2026, leading to operational disruptions. The nature of the attack, involved threat actors, and potential data compromise are still under investigation.
  • [NEW] ShinyHunters Claims FBI Hack, Cites Revenge and PeopleSoft Zero-Day: The extortion group ShinyHunters has claimed responsibility for breaching the FBI, alleging the use of a PeopleSoft zero-day vulnerability to access sensitive data. The group stated the attack was a retaliatory act, though the FBI has not confirmed the claim.

New Threats and Advisories:

  • [NEW] CISA & FBI Warn of Third-Party Risks to Industrial Control Systems: CISA and the FBI have issued a joint advisory concerning the significant cyber risks posed by third-party Industrial Control System (ICS) integrators. The guidance recommends critical infrastructure operators implement least privilege, strengthen contractual security, and enhance remote access monitoring.
  • [NEW] GAO: FAA Lacks Real-Time Monitoring for Aviation Cyber Threats: A U.S. Government Accountability Office (GAO) report has identified cybersecurity weaknesses at the FAA, noting a lack of required risk assessments and real-time monitoring capabilities for threats to the National Airspace System (NAS), leaving aircraft communication systems vulnerable.

Policy & Industry Notes:

  • [NEW] Google Fined €403M by Irish DPC for GDPR Location Data Violations: Ireland's Data Protection Commission (DPC) has fined Google €403 million for GDPR violations related to the processing of user location data between 2018 and 2020. The DPC found Google's practices lacked lawfulness, fairness, and transparency concerning its 'Web & App Activity' and 'Location History' features.
  • [NEW] AI and Cloud Complexity Create New Risks for Manufacturers: Thales: The 2026 Thales Data Threat Report for manufacturing highlights executive concerns about AI-driven security threats, with 67% citing the rapid pace of AI change as a top risk. The report also points to cloud security gaps, including low encryption rates for sensitive data and limited visibility into data location.
  • [NEW] Law Firm Investigates Data Breach at Infotree Global Solutions: Edelson Lechtzin LLP is investigating a data breach at Infotree Global Solutions, where an employee inadvertently emailed sensitive personal information, including names and Social Security numbers, to an unauthorized party. The company has notified affected individuals and offered identity protection services.

Filter by Category

New Articles (7)

Updated Articles (1)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.