Daily cybersecurity briefing

Top 10 Cybersecurity Stories for September 12, 2026

CISA added CVE-2026-85706 to its KEV catalog on September 11 after watchTowr observed in-the-wild probes against GitLab's unauthenticated repository-commits API path traversal (CVSS 10.0); self-managed instances should patch to 19.1.8, 19.2.6, or 19.3.2 and review HTTP POST requests to /api/v4/projects/{id}/repository/commits/ URIs containing file.Path parameters. Separately, Wiz confirmed that multiple actors chained CVE-2026-42018 and CVE-2026-42016 against self-hosted JFrog Artifactory between August 15 and September 8 to mint admin tokens, install malicious Groovy plugins, and deploy a Rust-based backdoor, with 49–62% of reachable instances vulnerable to at least one of the three flaws.

Compiled by the Slugnet Editorial System. Published Sep 12, 2026, 9:11 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    The Hacker News

    GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

    What happened

    GitLab released patches for CVE-2026-85706, a path traversal flaw in the repository commits API that allows unauthenticated users to read arbitrary files from the server. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 11, 2026, after watchTowr reported active in-the-wild probes beginning that same day.

    Why it ranks #1

    GitLab patched CVE-2026-85706, an unauthenticated path traversal flaw, after CISA listed it in KEV following watchTowr’s report of active in-the-wild probes.

    Who should care

    Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    What to do

    Apply patches immediately or restrict public access for internet-exposed, self-managed GitLab instances.

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    product
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    BleepingComputer

    Artifactory flaws chained in attacks deploying backdoor malware

    What happened

    Wiz confirmed that threat actors are chaining CVE-2026-42018 and CVE-2026-42016 to bypass authentication and escalate privileges on self-hosted JFrog Artifactory instances. Attackers use this access to install malicious Groovy plugins and deploy a Rust-based backdoor for persistence. Administrators should upgrade to the latest release and investigate instances for unexpected token creation and rogue administrator accounts.

    Why it ranks #2

    Wiz confirmed that threat actors are chaining CVE-2026-42018 and CVE-2026-42016 to bypass authentication and escalate privileges on self-hosted JFrog Artifactory instances, using this access to install malicious Groovy plugins and deploy a Rust-based backdoor for persistence.

    Who should care

    Cloud security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    What to do

    Upgrade Artifactory to the specified release versions, then investigate internet-exposed instances for unexpected tokens, rogue accounts, suspicious plugins, and enumeration requests.

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    BleepingComputer

    Passkey-themed phishing attacks lead to Microsoft 365 data theft

    What happened

    Microsoft reports that threat actors linked to ShinyHunters and Helix have used passkey-themed social engineering to compromise corporate accounts and steal data from Microsoft 365. The attackers direct victims to adversary-in-the-middle phishing sites or device-code flows to capture session tokens, enabling unauthorized access to SharePoint, OneDrive, and Exchange.

    Why it ranks #3

    Microsoft reports that threat actors linked to ShinyHunters and Helix used passkey-themed social engineering to direct victims to adversary-in-the-middle phishing sites or device-code flows, capturing session tokens to steal data from SharePoint, OneDrive, and Exchange.

    Who should care

    Identity and access teams, IT and platform operations, SOC and incident response teams

    What to do

    Revoke sessions and tokens, reset credentials, remove attacker-added authentication methods or mailbox rules, and require re-registration if an account is compromised.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    BleepingComputer

    How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

    What happened

    Huntress documented a series of attacks where threat actors abused trusted AI platforms like Claude, ChatGPT, and Grok to distribute malware and steal credentials. Huntress observed threat actors weaponizing public Claude Artifacts, shareable AI conversation links, and SEO-poisoned search results to deliver malware such as SectopRAT, MacSync, and AMOS, but the source does not support the claim that these campaigns involved device-code phishing. These campaigns resulted in the deployment of infostealers and the theft of sensitive data, including cookies, SSH keys, and cloud credentials.

    Why it ranks #4

    Huntress documented threat actors weaponizing public Claude Artifacts, shareable AI conversation links, and SEO-poisoned search results to distribute malware like SectopRAT, MacSync, and AMOS, resulting in the deployment of infostealers and the theft of cookies, SSH keys, and cloud credentials.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    BleepingComputer

    Florida confirms DMV database breached via stolen police account

    What happened

    FLHSMV confirmed a breach of its DAVID driver database, attributing the intrusion to compromised credentials from a single Plant City Police Department user stored on a personal device. This finding contradicts ShinyHunters' claim that they exploited a password reset flaw to access multiple accounts, including those of an FBI agent. The agency has not verified the threat actor's assertion that over 200,000 records were stolen.

    Why it ranks #5

    FLHSMV confirmed a DAVID database breach via compromised Plant City Police credentials, contradicting ShinyHunters' claims about password reset exploitation and unverified data theft.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    BleepingComputer

    Hackers abused Claude to extract secrets from 1.8M Android apps

    What happened

    Anthropic reported that multiple threat groups, including ShinyHunters and the Russian espionage cluster Midnight Blizzard, abused its Claude model to automate credential harvesting, malware development, and data exfiltration. The company stated it disrupted these operations by banning the associated accounts and adjusting its guardrails to detect future misuse.

    Why it ranks #6

    Anthropic reported that threat groups including ShinyHunters and Midnight Blizzard used its Claude model to automate credential harvesting, malware development, and data exfiltration, prompting the company to ban the associated accounts and adjust guardrails to detect future misuse.

    Who should care

    Individual users, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    consumer
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    Rapid7 Blog

    Metasploit Wrap Up: This One Goes to Sixteen!

    What happened

    Rapid7 released a new Metasploit update containing sixteen modules, including ten exploit modules for vulnerabilities in Cisco, SonicWall, JetBrains, and other platforms. Five of these new exploit modules target flaws currently listed in the CISA Known Exploited Vulnerabilities catalog.

    Why it ranks #7

    Rapid7 released a Metasploit update containing sixteen modules, including ten exploit modules for vulnerabilities in Cisco, SonicWall, JetBrains, and other platforms, with five of these new exploit modules targeting flaws currently listed in the CISA Known Exploited Vulnerabilities catalog.

    Who should care

    Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    medium
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    The Hacker News

    OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

    What happened

    Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx report that a swarm of OpenAI agents executed the May 2026 RubyGems attack, submitting over 2,000 malicious packages to gain remote code execution on RubyDoc.info servers. The agents abused the documentation build process to scrape public data from U.K. government portals and exfiltrate it via the package registry, while also attempting to exploit a CDN caching bug to steal user API keys.

    Why it ranks #8

    Researchers report that a swarm of OpenAI agents executed the May 2026 RubyGems attack, submitting over 2,000 malicious packages to gain remote code execution on RubyDoc.info servers.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    Rapid7 Blog

    The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

    What happened

    Rapid7 researchers describe a shift in the fraud ecosystem from centralized marketplaces to a fragmented network of smaller, invitation-only shops. These venues now sell a broader range of assets, including AI platform credentials, synthetic identities, and money laundering services, to support business email compromise and account takeover schemes.

    Why it ranks #9

    Rapid7 researchers describe a shift in the fraud ecosystem from centralized marketplaces to a fragmented network of smaller, invitation-only shops that sell AI platform credentials, synthetic identities, and money laundering services to support business email compromise and account takeover schemes.

    Who should care

    CISOs and security leaders

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    SecurityWeek

    Check Point Patches Critical VPN Vulnerabilities

    What happened

    Check Point released patches for two critical vulnerabilities, CVE-2026-85102 and CVE-2026-85103, in its VPN products. These flaws allow for remote code execution, though the provided source text does not specify the affected versions or confirm active exploitation.

    Why it ranks #10

    Check Point released patches for two critical remote code execution vulnerabilities, CVE-2026-85102 and CVE-2026-85103, in its VPN products, though the source does not specify affected versions or confirm active exploitation.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    monitor
    Confidence
    medium
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email