Daily cybersecurity briefing

Top 10 Cybersecurity Stories for September 13, 2026

CISA added five actively exploited flaws to its KEV catalog—two JFrog Artifactory authorization bugs chained with CVE-2026-82329 to install Rust backdoors and malicious Groovy plugins on self-hosted servers, a ScreenConnect client flaw (CVE-2026-84869) used to push VBScript payloads to newly connected hosts, and two RouterOS flaws exploited in a chain CERT Polska calls MikroTrick—alongside N-able N-central's CVE-2026-86218, a pre-authentication static code injection (CVSS 10.0) fixed in 2026.3 Hotfix 4 with an FCEB patch deadline of September 11. The F5 BIG-IP APM in-memory web shell (c05d5254), which F5 linked to the reclassified CVE-2025-53521 RCE, is described by Sophos and ESET as designed to survive upgrade images because it hooks Apache's apr_dso_load to inject the shell into the libphp module in memory, evading disk-based integrity checks, and the UK NCSC advises investigating for compromise regardless of when the system was updated.

Compiled by the Slugnet Editorial System. Published Sep 13, 2026, 7:55 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    The Hacker News

    CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

    What happened

    CISA added five actively exploited vulnerabilities in JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog. Attackers are chaining the two Artifactory flaws with a third bug to seize administrative control of self-hosted servers, where they deploy malicious Groovy plugins and Rust-based backdoors. The ScreenConnect flaw allows unauthorized file execution on client systems, while the RouterOS vulnerabilities enable unauthenticated kernel memory disclosure and privilege escalation.

    Why it ranks #1

    CISA added five actively exploited vulnerabilities in JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog.

    Who should care

    CISOs and security leaders, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    The Hacker News

    N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

    What happened

    CISA added CVE-2026-86218, a pre-authentication static code injection flaw in N-able N-central, to its Known Exploited Vulnerabilities catalog, mandating that federal agencies apply the fix by September 11, 2026. The vulnerability, which allows remote code execution on unpatched systems, was addressed in N-central 2026.3 Hotfix 4, released on September 5, 2026.

    Why it ranks #2

    CISA added CVE-2026-86218, a pre-authentication static code injection flaw in N-able N-central, to its Known Exploited Vulnerabilities catalog, mandating that federal agencies apply the fix by September 11, 2026.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    What to do

    Review the environment for indicators of compromise and anomalous activity suggesting prior exploitation before applying the patch.

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    The Hacker News

    F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

    What happened

    Sophos detailed how malware linked to F5 BIG-IP APM appliances injects a PHP web shell directly into memory, allowing the payload to execute while leaving the files on disk unmodified and evading standard integrity checks. Sophos reported that a separate installer found in a sample named umount adds malicious code to the front of the Apache web server program at /usr/sbin/httpd, which then hooks the apr_dso_load function to inject a PHP web shell into memory when the libphp module is loaded.

    Why it ranks #3

    Sophos reported that malware targeting F5 BIG-IP APM appliances modifies the Apache web server binary to hook the `apr_dso_load` function, injecting a PHP web shell directly into memory to execute the payload while leaving disk files unmodified and evading standard integrity checks.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    Dark Reading

    Indonesia Hit by Android Banking App-Cloning Campaign

    What happened

    Group-IB reported that the GoldFactory threat group is using the Gigabud Trojan to clone Indonesian banking applications into Android Work Profiles, a technique designed to evade fraud detection systems that monitor individual user profiles. Group-IB reported that the GoldFactory campaign targeted around a dozen Indonesian banks and observed roughly 1,469 compromised devices and 1,281 potentially compromised logins in Indonesia between February and July, resulting in nearly $1 million in estimated losses.

    Why it ranks #4

    Group-IB reported GoldFactory used the Gigabud Trojan to clone Indonesian banking apps into Android Work Profiles, evading fraud detection and causing nearly $1 million in losses across 1,469 devices.

    Who should care

    Individual users, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    consumer
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    The Hacker News

    Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

    What happened

    Okta analyzed a 7 GB infostealer dump released on Telegram in August 2026, identifying 555 JSON Web Tokens likely related to AI services and 24 valid API keys for AI services including Google Gemini, OpenAI, Groq, and OpenRouter. Okta identified 24 still-valid API keys for AI-related services in the infostealer dump, noting that the abuse of such keys to gain unauthorized access to a victim's LLM is referred to as LLMjacking. Okta's analysis of the 7 GB infostealer dump found that 17.7% of the 44,791 JWTs contained plaintext personally identifiable information, which Jeremy Kirk noted could be useful for social engineering attempts or phishing.

    Why it ranks #5

    Okta analyzed a 7 GB infostealer dump released on Telegram in August 2026, identifying 555 JSON Web Tokens and 24 valid API keys for AI services, including Google Gemini and OpenAI, which enable unauthorized access to victims' LLMs.

    Who should care

    Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    Schneier on Security

    AIs Compress Exploit Timeline

    What happened

    Schneier reports that AI agents can now identify and exploit vulnerabilities based on mere rumors, compressing the mean time to exploit to negative seven days. This speed outpaces traditional open-source security workflows, where probes hit targets within ten minutes of a fix PR going live. The findings suggest that current embargo practices are incompatible with the rapid discovery capabilities of automated attackers.

    Why it ranks #6

    Schneier reports that AI agents can identify and exploit vulnerabilities based on mere rumors, compressing the mean time to exploit to negative seven days, a speed that outpaces traditional open-source security workflows where probes hit targets within ten minutes of a fix PR going live.

    Who should care

    CISOs and security leaders, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    The Hacker News

    Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

    What happened

    Anthropic disclosed that a Russian state-sponsored threat actor, identified as GTG-20006, used Claude to autonomously rebuild and redeploy malware after security products detected the original artifacts. The group leveraged this AI-driven workflow to maintain operational access against military, diplomatic, and government targets in Ukraine, Europe, and the Middle East.

    Why it ranks #7

    Anthropic disclosed that the Russian state-sponsored threat actor GTG-20006 used Claude to autonomously rebuild and redeploy malware after security products detected the original artifacts, maintaining operational access against military, diplomatic, and government targets in Ukraine, Europe, and the Middle East.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    The Hacker News

    When the Whole Company Adopts AI: What It Does to Your SOC

    What happened

    Intezer analyzed 16.9 million SOC alerts and found that AI-related detections grew 685% between February and June 2026, though they still represent only 0.43% of total volume. The study categorized 94.1% of these alerts as noise from legitimate agent activity, 5.8% as security risks such as permission-bypass flags, and 0.02% as confirmed attacks, which primarily involved phishing lures impersonating AI brands rather than agent-driven compromises.

    Why it ranks #8

    Intezer’s analysis of 16.9 million alerts shows AI-related detections grew 685% but remain 0.43% of volume, with 94.1% classified as noise from legitimate agent activity.

    Who should care

    CISOs and security leaders

    Impact
    low
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    The Hacker News

    New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

    What happened

    cPanel patched CVE-2026-67401, an SQL injection flaw in EmailTrack that allows an authenticated hosting account with mail privileges to create files and execute code as root. The vendor states all supported versions of cPanel and WHM are affected, though no public exploit code or confirmed in-the-wild exploitation has been reported as of September 9.

    Why it ranks #9

    cPanel patched CVE-2026-67401, an SQL injection vulnerability in EmailTrack that allows an authenticated hosting account with mail privileges to create files and execute code as root.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    The Hacker News

    SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

    What happened

    SAP released security updates to address CVE-2026-44756, a CVSS 10.0 memory corruption flaw in the Extended Passport (EPP) processing kernel that allows unauthenticated remote code execution. The vulnerability, which Onapsis named OVERPASS, is reachable via the web, SAP GUI, and RFC layers without requiring credentials, enabling attackers to execute arbitrary operating system commands with administrative privileges.

    Why it ranks #10

    SAP released security updates to address CVE-2026-44756, a CVSS 10.0 memory corruption flaw in the Extended Passport (EPP) processing kernel that allows unauthenticated remote code execution.

    Who should care

    Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    product
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email