As cited
Copy frozen at (site build).
threat intel
21st September – Threat Intelligence Report
A weekly threat intelligence roundup covering government and supply chain breaches, active exploitation of critical vulnerabilities in Cisco and Check Point products, and multiple campaigns from state-aligned and cybercriminal groups targeting government, technology, and financial sectors. Artificial intelligence (AI) threats include new attack techniques like BragJack against AI-enabled browsers and the discovery of Luciferus, an uncensored AI service for malware creation. Major patch releases from Oracle, Cisco, ISC, and Check Point address hundreds of flaws, including actively exploited remote code execution vulnerabilities.
Why it matters: Government and critical infrastructure operators must assess exposure from the Japan breach and oil tanker attacks, which demonstrate virtual private network (VPN) and onboard system targeting; Brevo and Gyazo customers should evaluate risk from compromised credentials and session tokens; organizations running Cisco ISE, Check Point Management Servers, Oracle products, or BIND 9 DNS services require immediate patching for actively exploited critical flaws; teams managing AI-enabled systems face new hijacking and jailbreak risks; enterprises with Microsoft 365 deployments need detection for GhostCode device-code phishing; security teams should brief executives on WaterPlum's $15 million cryptocurrency theft from 7,000 wallets targeting IT professionals.
- Source published
- First seen by Cybersecurity Tracker