Daily Digest

AI-Assisted Attacks Rise, Critical Exploits & Data Breaches Highlighted

September 30, 2026
7 articles (5 new, 2 updated)
21 min read

Summary

Critical Vulnerabilities and Active Exploitation:

  • Citrix Zero-Days and Oracle PeopleSoft Flaw Under Active Exploit: Two Citrix NetScaler zero-day vulnerabilities (CVE-2026-88771, CVE-2026-88772) and a re-weaponized Oracle PeopleSoft flaw (CVE-2026-35273) are being actively exploited for remote code execution. CISA has added the Citrix flaws to its KEV catalog, indicating a high priority for patching.

Evolving Threat Landscape and Data Incidents:

  • [UPDATE] FBI Warns of OAuth Consent Phishing Campaign Bypassing MFA: Threat actors are using sophisticated phishing kits to target Microsoft 365 users with Device Code phishing, which abuses legitimate Microsoft authorization flows to bypass MFA and gain persistent access. New hunting hints focus on monitoring Azure AD sign-in logs and user training.
  • [UPDATE] Gyazo Screenshot Tool Breach Exposes 23.6M User Records, Image Data: A breach on September 27, 2026, exposed over 23.6 million user records from the Gyazo screenshot tool, including metadata for registered and anonymous accounts. Mitigation strategies are mapped to D3FEND techniques for detection and response.
  • [NEW] AI-Assisted Attack on Spanish Rail Network Exfiltrated 500GB of Data: An attack on Spain's rail operators, Adif and Renfe, utilized commercial AI models to accelerate the breach, exfiltrating 500 GB of data. While core OT systems were unaffected, the incident underscores risks from interconnected IT/OT environments and AI in offensive operations.
  • [NEW] Southern Company Investigates Data Breach Affecting 400,000 Customers: U.S. utility provider Southern Company is investigating a data breach that may have leaked Personally Identifiable Information (PII) of approximately 400,000 customers, including names, email addresses, and physical addresses.
  • [NEW] Chaos Ransomware Claims Attack on Industrial IoT Giant Advantech: The Chaos ransomware group has claimed responsibility for an attack on Advantech, a provider of industrial IoT technology. Given Advantech's role in industrial automation and smart city infrastructure, a significant breach could have widespread downstream consequences.

Industry Insights and Emerging Risks:

  • [NEW] Industry Leaders Warn AI-Powered Attacks Are Outpacing Defenses: Cybersecurity executives at the Asia New Vision Forum expressed concerns that the rapid advancement of AI is creating threats that outpace current defensive capabilities, highlighting autonomous hacking agents and systemic supply chain vulnerabilities.

Filter by Category

New Articles (5)

Updated Articles (2)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.