Daily Digest

Critical Exploits, New Ransomware, and AI-Driven Attacks Dominate Cybersecurity News

September 25, 2026
9 articles (7 new, 2 updated)
27 min read

Summary

Critical Vulnerabilities Under Active Exploitation:

  • [UPDATE] F5 BIG-IP APM Zero-Day (CVE-2026-94127) Actively Exploited for RCE: The number of internet-exposed BIG-IP APM deployments potentially vulnerable has increased, with compromise leading to traffic decryption, credential theft, lateral movement, and service disruption. Hunting hints include monitoring BIG-IP LTM logs for 'tmm' crashes and scrutinizing '*/oauth/' URL patterns.
  • [NEW] Critical WordPress Path Traversal Flaw Actively Exploited (CVE-2026-87902): A critical, unauthenticated path traversal vulnerability in WordPress Core (CVSS 9.2) is being actively exploited, allowing attackers to include local PHP files and potentially achieve remote code execution. All site owners are urged to update to version 7.1.2 or patched versions.
  • [NEW] SolarWinds Patches Critical Unauthenticated RCE Flaws in Observability Platform: SolarWinds has released patches for two remote code execution vulnerabilities in its Observability Self-Hosted platform, CVE-2026-28324 (CVSS 9.8) and CVE-2026-28325 (CVSS 8.8), both exploitable by unauthenticated attackers. Customers should update to version 2026.2.3.

Emerging Threats and Evolving Tactics:

  • [NEW] New Ransomware Group 'n0n' Threatens to Destroy Victim Backups: A new ransomware group, 'n0n', is escalating its extortion tactics by threatening to encrypt or destroy victim backups in addition to data theft. Primarily targeting financial services, technology, and retail, the group relies on compromised credentials for initial access.
  • [NEW] Healthcare Sector Faces Surge in Social Engineering & Vishing Attacks: The healthcare and pharmaceutical industries are experiencing a rise in sophisticated social engineering and vishing attacks, with threat actors using aggressive phone tactics and medical-themed domains to steal credentials and cause operational downtime.
  • [NEW] Microsoft Links Ransomware Affiliate Storm-2570 to Four Malware Families: Microsoft has identified a single ransomware affiliate, Storm-2570, deploying Qilin, DragonForce, Anubis, and BERT ransomware. The group consistently uses RMM tools for C2, Mimikatz for credential harvesting, and Rclone for data exfiltration.
  • [NEW] AI Agents Used to Steal 600,000+ Credit Cards in Automated Attacks: A Chinese-speaking threat actor has leveraged commercially available AI agents to automate a campaign against online retailers, stealing over 600,000 credit card records and deploying web skimmers. The attacks targeted major companies across various sectors.
  • [NEW] New Windows Botnet 'x47.c' Advertised with AI Wallet Draining Feature: A new Windows botnet, 'x47.c', is being sold on dark web forums and features a 'denial of wallet' attack method to drain victims' paid AI service credits by generating heavy, billable requests using stolen API keys.

Policy and Industry Guidance:

  • [UPDATE] CISA & FBI Warn of Third-Party Risks to Industrial Control Systems: Updated guidance clarifies recommendations for critical infrastructure sectors, detailing enhanced compliance requirements for third-party access, including dedicated temporary accounts with MFA, comprehensive logging, and strict network segmentation. Mitigation strategies emphasize Zero Trust principles and formal vendor risk management programs.

Filter by Category

New Articles (7)

Updated Articles (2)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.