Daily cybersecurity briefing

Top 10 Cybersecurity Stories for September 11, 2026

PaperCut released maintenance builds 26.0.5, 25.0.13, and 24.1.10 to replace emergency patches for CVE-2026-81578 and CVE-2026-82078, which GreyNoise and Blackpoint Cyber confirmed a suspected Russian-speaking actor used to breach at least 395 organizations via AI-agent-driven attacks. Cisco confirmed three threat clusters are exploiting CVE-2026-20079 and CVE-2026-20316 in Secure FMC to deploy Qilin ransomware and a Sandworm-linked Cyclops Blink variant, with hotfixes available and CISA mandating federal patching by September 12.

Compiled by the Slugnet Editorial System. Published Sep 11, 2026, 8:19 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    The Hacker News

    PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

    What happened

    PaperCut released maintenance versions 26.0.5, 25.0.13, and 24.1.10 to replace emergency patches for two actively exploited authentication bypass flaws, CVE-2026-81578 and CVE-2026-82078. GreyNoise and Blackpoint Cyber reported that a suspected Russian-speaking actor used AI agents to weaponize these vulnerabilities, compromising at least 395 organizations across 48 countries.

    Why it ranks #1

    PaperCut released maintenance versions 26.0.5, 25.0.13, and 24.1.10 to replace emergency patches for two actively exploited authentication bypass flaws, CVE-2026-81578 and CVE-2026-82078, which GreyNoise and Blackpoint Cyber reported were used by a suspected Russian-speaking actor to compromise at least 395 organizations across 48 countries.

    Who should care

    CISOs and security leaders, Identity and access teams, IT and platform operations, SOC and incident response teams

    What to do

    Move PaperCut customers running an emergency patch build to a maintenance release.

    Impact
    critical
    Urgency
    immediate
    Confidence
    high
    Scope
    enterprise
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    The Hacker News

    Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

    What happened

    Cisco Talos identified three distinct threat clusters exploiting two recently patched Secure Firewall Management Center vulnerabilities, CVE-2026-20079 and CVE-2026-20316. These attacks leveraged the flaws to steal credentials, deploy web shells, and execute a living-off-the-land campaign that culminated in the deployment of Qilin ransomware. Cisco advises customers to apply the available hotfixes for the affected software versions.

    Why it ranks #2

    Cisco Talos identified three distinct threat clusters exploiting two recently patched Secure Firewall Management Center vulnerabilities, CVE-2026-20079 and CVE-2026-20316, to steal credentials, deploy web shells, and execute a living-off-the-land campaign that culminated in the deployment of Qilin ransomware.

    Who should care

    Identity and access teams, IT and platform operations, SOC and incident response teams

    What to do

    "Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316," Cisco said, adding it intends to ship a comprehensive hardening release for various internally discovered vulnerabilities next week.

    Impact
    critical
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    BleepingComputer

    IDScan confirms breach tied to 153 million stolen driver’s licenses

    What happened

    IDScan confirmed that unauthorized actors accessed its cloud platform, exposing customer names, government-issued identification numbers, and driver's license scans. The incident follows reports that a dark-web marketplace advertised a database containing over 153 million U.S. and Canadian driver's licenses, which Brian Krebs traced back to IDScan. The company is currently cooperating with the FBI, which is investigating the breach.

    Why it ranks #3

    IDScan confirmed that unauthorized actors accessed its cloud platform, exposing customer names, government-issued identification numbers, and driver's license scans, following reports that a dark-web marketplace advertised a database containing over 153 million U.S. and Canadian driver's licenses which Brian Krebs traced back to the company.

    Who should care

    Cloud security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    critical
    Urgency
    near-term
    Confidence
    high
    Scope
    sector
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    Cisco Talos Blog

    We've got one word for it, and it's usually the wrong one

    What happened

    Cisco Talos disclosed a WebDAV infection chain used by the Russian-linked actor UAT-10820 to compromise a Ukrainian government organization. The campaign delivers the Amatera stealer alongside secondary payloads, including a vulnerable driver to terminate EDR software and unauthorized remote access tools.

    Why it ranks #4

    Cisco Talos disclosed that the Russian-linked actor UAT-10820 used a WebDAV infection chain to compromise a Ukrainian government organization, deploying the Amatera stealer alongside a vulnerable driver to terminate EDR software and unauthorized remote access tools.

    Who should care

    Identity and access teams, IT and platform operations, SOC and incident response teams

    What to do

    Monitor for unusual WebDAV activity and the execution of disguised DLLs via rundll32.exe using suspicious ordinal calls.

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    sector
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    Help Net Security

    Automox Mitigation Worklets cut endpoint exposure to unpatchable flaws

    What happened

    Automox announced an AI-driven pipeline that generates endpoint mitigation worklets for unpatchable vulnerabilities, reducing the time from disclosure to deployment from days to hours. The system drafts these configurations using AI, then subjects them to human review and testing before adding them to a customer-controlled catalog.

    Why it ranks #5

    Automox announced an AI-driven pipeline that generates endpoint mitigation worklets for unpatchable vulnerabilities, reducing the time from disclosure to deployment from days to hours.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    What to do

    Patch Tuesday proves it: this week’s release shipped a historic 973 CVEs, the largest on record.

    Impact
    low
    Urgency
    near-term
    Confidence
    high
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    BleepingComputer

    New Android malware encrypts files, steals data, and harasses victims

    What happened

    Zimperium identified Mantax Otax, an Android malware strain that combines ransomware and spyware capabilities to encrypt files, exfiltrate sensitive data, and harass victims. Zimperium reports that Indonesian operators distribute Mantax Otax through malicious APKs outside Google Play, where the malware abuses the Accessibility service to steal credentials and capture screen activity, while its ransomware module encrypts files only on devices running Android 9 or older.

    Why it ranks #6

    Zimperium identified Mantax Otax, an Android malware strain distributed via malicious APKs outside Google Play that abuses the Accessibility service to steal credentials and capture screen activity, while its ransomware module encrypts files only on devices running Android 9 or older.

    Who should care

    Individual users, IT and platform operations, SOC and incident response teams

    What to do

    Do not install APKs from outside Google Play, grant Accessibility permissions to questionable apps, or trust unverified publishers.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    consumer
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    The Hacker News

    Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

    What happened

    Wiz reported that attackers chained two JFrog Artifactory flaws to gain administrator control of self-hosted servers and install malicious Groovy plugins and backdoors. The campaign, observed between August 15 and September 8, exploited a token issuance bug and a privilege escalation flaw to create unauthorized admin accounts and establish command-and-control channels.

    Why it ranks #7

    Wiz reported that attackers chained a token issuance bug and a privilege escalation flaw in JFrog Artifactory to create unauthorized administrator accounts and install malicious Groovy plugins and backdoors on self-hosted servers between August 15 and September 8.

    Who should care

    Application security teams, Cloud security teams, IT and platform operations, SOC and incident response teams

    What to do

    Upgrade self-hosted Artifactory to the fixed build for your release branch, as listed in JFrog's security advisories.

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    BleepingComputer

    Surfshark VPN says hackers breached internal testing, proxy servers

    What happened

    Surfshark disclosed that a misconfigured internal test server was exposed to the internet, allowing an unauthorized party to access service configurations and build-related credentials. The company contained the incident on September 2 and confirmed that customer data, VPN traffic, and production infrastructure were not impacted.

    Why it ranks #8

    Surfshark disclosed that a misconfigured internal test server was exposed to the internet, allowing an unauthorized party to access service configurations and build-related credentials, which the company contained on September 2 after confirming that customer data, VPN traffic, and production infrastructure were not impacted.

    Who should care

    CISOs and security leaders, IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    The Hacker News

    China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

    What happened

    Gen Digital identified a China-linked threat actor, UNC3569, exploiting a flaw in Sogou Input Method to deploy the GRAYRABBIT backdoor on Windows systems. The attack chain leveraged a custom link handler to open a built-in, unpatched Chromium 80 browser with its sandbox disabled, allowing the execution of a 2021 V8 exploit to gain user-level code execution. Tencent released a fix in April 2026 that restricts the link handler to approved HTTPS domains, though the underlying browser engine remains unpatched.

    Why it ranks #9

    Gen Digital identified UNC3569 exploiting a Sogou Input Method flaw to deploy GRAYRABBIT, leveraging an unpatched Chromium 80 browser with a disabled sandbox for user-level code execution.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    BleepingComputer

    Trezor: 347,000 users targeted in phishing attacks after Brevo breach

    What happened

    Trezor disclosed that threat actors exploited a breach in its third-party email provider, Brevo, to send phishing emails to 347,000 customers. The messages impersonated Trezor security alerts to trick recipients into downloading an app that requested their wallet backup, a tactic that impacted 2,500 users before Trezor took down the malicious domain.

    Why it ranks #10

    Trezor disclosed that attackers exploited a Brevo breach to send phishing emails to 347,000 customers, tricking 2,500 into downloading a malicious app that requested wallet backups.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email