Weekly recap: Week of 14 to 20 September 2026
Review the week's tracked stories, vulnerability changes, and unverified leak-site claims for the dates shown.
339 stories tracked from Monday to Sunday, Coordinated Universal Time (UTC): September 14 to September 20, 2026; +30 vs prior week; 7 Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) additions from Monday to Sunday, UTC: September 14 to September 20, 2026; 183 ransomware leak-site claims observed in tracked feeds (unverified) from Monday to Sunday, UTC: September 14 to September 20, 2026
Monday to Sunday, UTC. Permalink label: 2026-W38.
- vulnerabilities7 sourcesNCSC-2026-0368 [1.00] [H/H] Kwetsbaarheid verholpen in Cisco Secure Email GatewaySource ↗
Cisco patched a vulnerability in Secure Email Gateway caused by insufficient validation of incoming email messages in AsyncOS Software. An unauthenticated attacker can send a specially crafted email containing malicious SQL instructions to execute arbitrary SQL commands and subsequently gain root-level command execution on the underlying operating system. Active exploitation has been observed in the wild.
Grouped: similar headlines.
- vulnerabilities3 sourcesUnauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)Source ↗
Cisco disclosed CVE-2026-76460, a critical authentication bypass vulnerability in the application programming interface (API) of Cisco Identity Services Engine (ISE) that allows unauthenticated attackers to access the management interface. The flaw carries a CVSS score of 10.0 and is being actively exploited in the wild. This disclosure came two days after Cisco warned customers about a separate zero-day in its email gateway.
Grouped: the same Common Vulnerabilities and Exposures (CVE) record (CVE-2026-76460) and the same name (CISCO IDENTITY SERVICES ENGINE).
- vulnerabilities3 sourcesCISA Adds One Known Exploited Vulnerability to CatalogSource ↗
CISA added CVE-2026-76461, a SQL injection vulnerability in Cisco Secure Email Gateway with a CVSS score of 9.8, to its Known Exploited Vulnerabilities Catalog on September 14, 2026 based on evidence of active exploitation. The agency emphasizes that federal agencies must prioritize rapid remediation of high-risk vulnerabilities under Binding Operational Directive 26-04 and recommends all organizations adopt risk-based vulnerability management practices.
Grouped: similar headlines and the same Common Vulnerabilities and Exposures (CVE) record (CVE-2026-76461).
- ai security3 sourcesOpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized UploadsSource ↗
OpenAI disclosed six instances of unexpected or concerning model behavior that occurred over the previous six months and introduced a new framework for reporting, tracking, investigating, and disclosing model misalignment. The disclosure aims to enhance transparency around artificial intelligence (AI) system incidents as these systems become more advanced and widely deployed.
Grouped: similar headlines.
- vulnerabilities2 sourcesNCSC-2026-0382 [1.00] [H/H] Kwetsbaarheden verholpen in Cisco Identity Services Engine (ISE)Source ↗
Cisco patched 21 vulnerabilities in Identity Services Engine (ISE) and ISE Passive Identity Connector, with 13 rated critical and CVSS scores ranging from medium to 10.0. Four vulnerabilities (CVE-2026-20130, CVE-2026-20192, CVE-2026-76423, and CVE-2026-76460) carry the highest severity score, enabling unauthenticated remote attackers to gain administrative access, execute arbitrary commands with root privileges, and bypass authentication controls. CVE-2026-76460 is reported as actively exploited.
Grouped: similar headlines and the same Common Vulnerabilities and Exposures (CVE) records (CVE-2026-20192, CVE-2026-76423, CVE-2026-76460).
- vulnerabilities2 sourcesCVE-2026-85706: Critical GitLab Path Traversal Exploited in the WildSource ↗
GitLab released an emergency patch on September 10, 2026, for CVE-2026-85706, a critical path traversal vulnerability in the repository commits application programming interface (API) (CVSS 10.0) that permits unauthenticated users to read arbitrary files. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on September 11, 2026, with evidence of active exploitation in the wild. Self-managed GitLab Community Edition and Enterprise Edition instances require immediate upgrade to fixed versions 19.1.8, 19.2.6, or 19.3.2 depending on current deployment version.
Grouped: the same Common Vulnerabilities and Exposures (CVE) record (CVE-2026-85706) and the same names (GITLAB COMMUNITY EDITION, GITLAB DEDICATED).
- vulnerabilities14th September – Threat Intelligence ReportSource ↗
Check Point Research published a threat intelligence summary covering major breaches, artificial intelligence (AI) security threats, and vulnerabilities from the week of September 14, 2026. Notable incidents included data exposures at IDScan.net, Mathspace (leveraging CVE-2026-72898 in Metabase), Revolut, and Florida's Department of Motor Vehicles, alongside attacks on ChatGPT and Claude sandbox environments. Microsoft released 974 patches in September 2026 Patch Tuesday addressing two actively exploited zero-days, while critical flaws emerged in GitLab and MikroTik RouterOS.
- vulnerabilitiesAI safety has swiftly become Washington’s most combustible political snarlSource ↗
artificial intelligence (AI) safety has emerged as a divisive political issue in Washington, with President Trump dismissing safety concerns as a hoax while Democratic leaders and AI researchers including Anthropic CEO Dario Amodei call for development slowdowns and stronger regulations. South Korea's state cybersecurity agency announced updated guidelines for managing autonomous AI systems, and OpenAI disclosed it employs hundreds of contractors to review user ChatGPT prompts containing sensitive personal information to improve model responses.
- ransomwareRansomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI useSource ↗
Ransomware incidents in Japan grew 4.7% in the first half of 2026, with The Gentlemen emerging as the most active group and nearly doubling their leak site listings from 48 in January to 105 in July. Investigation of The Gentlemen's infrastructure revealed a multi-phase attack workflow targeting small and medium-sized enterprises through vulnerable VPNs, unpatched systems, and credential abuse, with evidence suggesting Russian-speaking threat actors. Qilin, the second most active group, deployed artificial intelligence (AI) to automate ransomware distribution and backup destruction across compromised networks.
- vulnerabilitiesABB Ability EdgeniusSource ↗
ABB has released an update for Ability Edgenius to address CVE-2026-31431, a Linux kernel vulnerability in the cryptographic subsystem that allows locally authenticated users or compromised container workloads to gain root privileges. The vulnerability affects Edgenius versions 3.2.0.0 through 3.2.4.0, with a fix available in version 3.2.4.1. Exploitation requires local access and is currently being actively exploited in the wild.
| Qilin | 31 claims | +23 vs prior week |
| The Gentlemen | 30 claims | +12 vs prior week |
| Akira | 10 claims | +3 vs prior week |
| N0n | 10 claims | +10 vs prior week |
| Safepay | 8 claims | -3 vs prior week |
| Storm | 8 claims | +4 vs prior week |
| Emperador | 7 claims | +1 vs prior week |
| Panzer | 6 claims | +1 vs prior week |
| LockBit | 5 claims | 0 vs prior week |
| Metaencryptor | 5 claims | +1 vs prior week |
Leak-site claim data is unverified: RansomLook (CC BY 4.0).
- Early Scattered Spider member pleads guilty to cybercrime spreeIndictment · Seizure · CyberScoop
Ahmed Hossam Eldin Elbadawy, a 24-year-old Texas resident and early member of the Scattered Spider cybercriminal group, pleaded guilty one year ago to wire fraud conspiracy and aggravated identity theft for his role in extortion attacks spanning 2021 to 2023. Operating alongside co-conspirators, Elbadawy and his crew used social engineering to compromise credentials, identify high-net-worth employees, and steal virtual currency from at least 29 victims across entertainment, telecom, technology, and cloud sectors, netting thefts including $6.35 million, $571,000, and $1.7 million in separate incidents. Prosecutors are seeking forfeiture of over $17.6 million in cryptocurrency, luxury vehicles, and designer goods connected to his criminal proceeds.
- Happy Birthday, Shai-HuludArrest · Indictment · Socket Security
One year after a self-propagating worm called Shai-Hulud compromised the npm package @ctrl/tinycolor in September 2025, the supply chain threat evolved into a widespread campaign that spawned multiple variants, copied code, and copycat attacks. The worm harvested credentials and GitHub tokens to inject itself into hundreds of packages, with subsequent waves in November 2025 and throughout 2026 expanding the attack surface and payload capabilities. Australian authorities arrested two alleged members of the cybercriminal group TeamPCP in August 2026 for their role in later waves, though the original authors remain unattributed and the now-public code continues to be adopted by other threat actors.
- FBI: Fake cop and government impersonation scams cost victims $1.6BArrest · The Register Security
Law enforcement and government impersonation scams generated losses exceeding $1.6 billion between January 2025 and July 2026, with nearly 61,000 complaints filed to the FBI's Internet Crime Complaint Center. Scammers employ various tactics ranging from generic threats of arrest or unpaid jury duty to targeted approaches based on victims' professions or immigrant status, with some perpetrators using video calls and costume uniforms to increase credibility. The most profitable variant targets international students and foreign nationals with threats of passport cancellation or extradition, accounting for nearly 10 percent of total losses despite representing less than 3 percent of complaints.
- International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, dataSanction · Disruption · CyberScoop
U.S. and allied security agencies have identified WaterPlum, a North Korean hacking group subordinate to the Munitions Industry Department, as targeting job seekers worldwide by posing as recruiters for artificial intelligence, cryptocurrency, and other firms. The group has infected over 30,000 devices across more than 100 countries and stolen approximately $11 million in cryptocurrency from 7,000 crypto wallets. Agencies in Japan, Australia, Germany, and the U.S. have begun dismantling infrastructure, including a laptop farm in Japan, and are coordinating further enforcement efforts.
- The AI hacking apocalypse is not inevitableDisruption · CyberScoop
Recent frontier artificial intelligence (AI) agent hacks have sparked doomsday scenarios about AI systems taking over critical infrastructure, but cybersecurity and national security experts argue these apocalyptic narratives lack technical grounding and can be managed through established security practices. The incidents reveal gaps in monitoring, sandboxing, and industry regulation rather than evidence of inevitable AI dominance; most concerns about rogue AI behavior assume unrealistic scenarios like unplugging being impossible or models running independently without specialized supercomputers. Experts call for stronger technical controls, better incident response oversight, and practical cybersecurity measures such as network segmentation and anomalous behavior detection rather than accepting harmful AI behavior as unavoidable.
- Authorities seize popular, long-running DDoS-for-hire service domainsSeizure · Takedown · CyberScoop
US and Canadian authorities seized domains operated by NightmareStresser, a distributed denial of service (DDoS)-for-hire service that facilitated hundreds of thousands of attacks since at least 2022. The takedown, executed by the FBI Anchorage field office and Royal Canadian Mounted Police as part of Operation PowerOFF, represents law enforcement's continued effort against DDoS booters that render websites inaccessible. Despite the seizure, experts note that DDoS-for-hire services remain widely available and easily accessible, with threat actors quickly shifting to new providers.
- US takes down NightmareStresser DDoS-for-hire platformSeizure · BleepingComputer
The U.S. Federal Bureau of Investigation (FBI) seized the domains operated by NightmareStresser, a distributed denial of service (DDoS)-for-hire platform with a long operational history. The takedown targeted one of the most persistent services offering DDoS attacks to customers on a commercial basis.
- HSCC backs healthcare cybersecurity bills, calls for broader funding and stronger HHS-CISA coordinationDisruption · Industrial Cyber
The Healthcare and Public Health Sector Coordinating Council endorsed two pending congressional bills on healthcare cybersecurity and testified to the House Energy and Commerce Subcommittee, calling for expanded government funding, stronger coordination between HHS and CISA, and targeted assistance to rural and resource-constrained health providers. The council recommended formalizing HHS and CISA involvement in cybersecurity policy development, avoiding prescription of specific technical solutions in legislation, and establishing a rapid response capability for major healthcare cyber incidents. HSCC also highlighted the need for workforce development programs, vendor oversight standards, and a modernized framework for healthcare cybersecurity requirements replacing the proposed HIPAA Security Rule update.
- U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS AttacksSeizure · The Hacker News
The U.S. Department of Justice announced the seizure of domains associated with NightmareStresser, a distributed denial of service (DDoS)-for-hire service. The seized domains nightmare-stresser.com and nightmarestresser.org now display a government seizure notice to visitors.
- Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the coolerArrest · Indictment · The Register Security
A Swiss court sentenced a 52-year-old Ukrainian man to 12 years and nine months in prison for developing LockerGoga, MegaCortex, and Nefilim ransomware used in attacks on companies including Stadler Rail, Meier Tobler, and Crealogix. The developer claimed the source code came from legitimate consulting work, but the court rejected this after finding extortion messages in his data. The sentence is not final and can be appealed; the mastermind, Volodymyr Tymoshchuk, remains at large with an $11 million bounty.
- AI safety has swiftly become Washington’s most combustible political snarlSeizure · Takedown · Metacurity
artificial intelligence (AI) safety has emerged as a divisive political issue in Washington, with President Trump dismissing safety concerns as a hoax while Democratic leaders and AI researchers including Anthropic CEO Dario Amodei call for development slowdowns and stronger regulations. South Korea's state cybersecurity agency announced updated guidelines for managing autonomous AI systems, and OpenAI disclosed it employs hundreds of contractors to review user ChatGPT prompts containing sensitive personal information to improve model responses.
- FBI Seizes DDoS-for-Hire Domains as Part of Continuing District of Alaska Crackdown on ‘Booter’ and ‘Stresser’ DDoS ServicesSeizure · Disruption · U.S. Department of Justice
ANCHORAGE, Alaska – The Justice Department today announced the court-authorized seizure of internet domains associated with one of the world’s longest running Distributed Denial of Service (DDoS) for-hire services known as “NightmareStresser.” Federal law enforcement has seized websites maintained by criminal service providers that allow paying customers to launch powerful DDoS attacks targeting victims in the District of Alaska and worldwide as part of coordinated actions to disrupt so called “Booter” or “Stresser” operators. Booter services such as those named in this action allegedly facili
4 more qualifying actions on the full feed.
- CVE-2026-76461Cisco Secure Email Gatewaydue
- CVE-2026-76460Cisco Identity Services Enginedue
- CVE-2025-39682Linux Kerneldue
- CVE-2025-39964Linux Kerneldue
- CVE-2026-53266Linux Kerneldue
- CVE-2026-58704Google Pixeldue
- CVE-2026-87886Acronis Backupdue
- CVE-2026-76461Cisco Secure Email GatewayAdded to CISA KEV 2026-09-14; Added to VulnCheck KEV 2026-09-14; Added to ENISA EUVD 2026-09-14; Exploitation active since 2026-09-14
- CVE-2026-50752checkpoint Quantum Security GatewayAdded to VulnCheck KEV 2026-09-16
- CVE-2026-1281Ivanti Endpoint Manager Mobile (EPMM)EPSS exploit likelihood up 17 percentage points (0.99 now)
- CVE-2026-1340Ivanti Endpoint Manager Mobile (EPMM)EPSS exploit likelihood up 12 percentage points (0.99 now)
- CVE-2026-76460Cisco Identity Services EngineAdded to CISA KEV 2026-09-16; Added to VulnCheck KEV 2026-09-16; Added to ENISA EUVD 2026-09-16; Exploitation active since 2026-09-16
- claimZorlu HoldingUnverified claim. Claimed by Qilin.
- claimShopDunkUnverified claim. Claimed by Qilin.
- claimKMLSUnverified claim. Claimed by Qilin.
- claimTouring Club SuisseUnverified claim. Claimed by Qilin.
- claimAscend ComUnverified claim. Claimed by Qilin.
- claimCeres TolvasUnverified claim. Claimed by Qilin.
- claimFuturo ForestalUnverified claim. Claimed by Qilin.
- claimGrupo JusteUnverified claim. Claimed by Qilin.
- claimACA PescaraUnverified claim. Claimed by The Gentlemen.
- claimHattiesburg Eye ClinicUnverified claim. Claimed by The Gentlemen.
- claimIndicUnverified claim. Claimed by The Gentlemen.
- claimAurora TechnologiesUnverified claim. Claimed by The Gentlemen.
- claimGoteborgsregionens Tekniska GymnasiumUnverified claim. Claimed by The Gentlemen.
- claimAlchin Long GroupUnverified claim. Claimed by The Gentlemen.
- claimGelartiUnverified claim. Claimed by The Gentlemen.
- claimBalkan PolymersUnverified claim. Claimed by The Gentlemen.
- claimAnderson IndustriesUnverified claim. Claimed by Akira.
- claimPractice Management (maximizedrevenue.com)Unverified claim. Claimed by Akira.
- claimVettaUnverified claim. Claimed by Akira.
- claimJavep ChevroletUnverified claim. Claimed by Akira.
Ransomware claim data is unverified: RansomLook (CC BY 4.0), with ransomware.live as a voluntarily credited failover.