Daily cybersecurity briefing

Top 10 Cybersecurity Stories for September 14, 2026

Cisco confirmed that state-sponsored and ransomware actors are actively exploiting CVE-2026-20079, an authentication bypass in Secure Firewall Management Center, and N-able shipped an emergency hotfix for CVE-2026-86218, a pre-auth RCE in N-central already exploited in the wild. Sophos separately reported a Linux rootkit on compromised F5 BIG-IP APM appliances that keeps its web shell in memory to evade disk-based detection, while the Dutch NCSC issued an imminent-exploitation warning for two Check Point VPN flaws (CVE-2026-85102, CVE-2026-85103) for which no public proof-of-concept exists yet.

Compiled by the Slugnet Editorial System. Published Sep 14, 2026, 7:22 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    Help Net Security

    Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited

    What happened

    Sophos identified a Linux rootkit on compromised F5 BIG-IP APM devices that conceals a web shell in memory rather than writing it to disk. This technique evades standard file-based detection methods on the access policy enforcement platform used by enterprises and government agencies.

    Why it ranks #1

    Sophos identified a Linux rootkit on compromised F5 BIG-IP APM devices that conceals a web shell in memory rather than writing it to disk, evading standard file-based detection methods on the access policy enforcement platform used by enterprises and government agencies.

    Who should care

    Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    The Hacker News

    Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

    What happened

    Socket researchers identified that the "Twitch Enhanced Viewer | JeetBot" browser extension routed OAuth session tokens from nearly 31,000 users to operator-controlled proxy servers, exposing the credentials in cleartext request logs. The extension, which claimed to provide region-unlocked streaming, forwarded these bearer tokens as URL query parameters for every channel watched outside a hardcoded list of ten Russian streamers. The developer has since released version 85.8.7 to stop the token transmission, though previously leaked credentials remain valid for account access.

    Why it ranks #2

    Socket researchers identified that the "Twitch Enhanced Viewer | JeetBot" browser extension routed OAuth session tokens from nearly 31,000 users to operator-controlled proxy servers, exposing the credentials in cleartext request logs.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    BleepingComputer

    Revolut discloses data breach exposing financial info, passports

    What happened

    Revolut disclosed a data breach after staff fulfilled a fraudulent request for customer information that arrived via an email using a legitimate government agency's domain and valid authentication credentials. The exposed data includes identity documents, facial verification images, and full transaction histories, including Bitcoin records, for an undisclosed number of customers.

    Why it ranks #3

    Revolut disclosed a data breach after staff fulfilled a fraudulent request for customer information that arrived via an email using a legitimate government agency's domain and valid authentication credentials, exposing identity documents, facial verification images, and full transaction histories for an undisclosed number of customers.

    Who should care

    CISOs and security leaders, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    sector
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    BleepingComputer

    Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

    What happened

    The Dutch NCSC warns that exploitation of two critical Check Point VPN flaws, CVE-2026-85102 and CVE-2026-85103, is imminent. These vulnerabilities allow remote attackers to execute arbitrary code on Security Gateways and Management Servers by exploiting improper certificate validation and a heap overflow in the ASN.1 decoder. The Dutch NCSC urges system administrators to apply Check Point's September 9 security updates for CVE-2026-85102 and CVE-2026-85103 or, for Site-to-Site VPN users, modify rules to limit access to specific, trusted IP addresses.

    Why it ranks #4

    The Dutch NCSC warns that imminent exploitation of Check Point VPN flaws CVE-2026-85102 and CVE-2026-85103 enables remote code execution, requiring immediate patching or access restrictions.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    Help Net Security

    WhatsApp Restricted Chat locks a conversation to your primary phone

    What happened

    WhatsApp is testing a "Restricted Chat" feature in its Android beta that prevents specific conversations from syncing to linked devices like WhatsApp Web or secondary phones. This setting isolates sensitive messages on the primary mobile device, blocking access by modified web clients or AI agents that might otherwise read the data. The feature remains under development and is not yet enabled for beta testers.

    Why it ranks #5

    WhatsApp is testing a "Restricted Chat" feature in its Android beta that prevents specific conversations from syncing to linked devices like WhatsApp Web or secondary phones.

    Who should care

    Individual users

    Impact
    moderate
    Urgency
    monitor
    Confidence
    high
    Scope
    consumer
    Status
    monitoring
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    Help Net Security

    Certificate failures can cost firms over $250,000

    What happened

    DigiCert’s Certificate Management Outlook reports that 34% of companies experienced service outages from expired certificates, with 21% facing 25 or more hours of downtime. The survey indicates that nearly one in four respondents attributed their most significant certificate incident to costs exceeding $250,000. These findings coincide with the CA/Browser Forum’s plan to shorten public TLS certificate lifespans to 47 days by 2029, which will increase renewal and validation workloads.

    Why it ranks #6

    DigiCert’s survey reports that 34% of companies experienced service outages from expired certificates, with 21% facing 25 or more hours of downtime, while nearly one in four respondents attributed their most significant certificate incident to costs exceeding $250,000.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    Help Net Security

    Cybersecurity attention fades within months after a breach

    What happened

    A ManageEngine survey of 700 IT and cybersecurity leaders in the US and Canada found that 80% of organizations see their post-incident security focus fade within one to six months. Close to half of these organizations reverted to their existing structures and strategies without implementing broader changes to governance or training.

    Why it ranks #7

    A ManageEngine survey of 700 IT leaders found 80% of organizations see post-incident security focus fade within one to six months, with half reverting to existing structures without broader governance or training changes.

    Who should care

    CISOs and security leaders, IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    Help Net Security

    Turn it off and on again, but for critical infrastructure

    What happened

    KTH Royal Institute of Technology researchers trained a reinforcement learning agent to detect intrusions in a segmented industrial network using only packet counts, as direct system state observation is often unavailable. The agent autonomously decides when to reset supervisory hosts or water tank processes to renew credentials and change IP addresses, accepting brief operational interruptions to contain the threat.

    Why it ranks #8

    KTH Royal Institute of Technology researchers demonstrated a reinforcement learning agent that detects intrusions in segmented industrial networks using only packet counts and autonomously resets supervisory hosts or water tank processes to renew credentials and change IP addresses.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    low
    Urgency
    monitor
    Confidence
    high
    Scope
    sector
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    SecurityWeek

    Telus Warns Customers of Account Breaches

    What happened

    Telus disclosed that stolen credentials enabled a multi-month campaign to access subscriber personal data and billing records. The company has notified affected customers regarding the unauthorized access to their accounts.

    Why it ranks #9

    Telus disclosed that stolen credentials enabled a multi-month campaign to access subscriber personal data and billing records, prompting the company to notify affected customers regarding the unauthorized access to their accounts.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    monitor
    Confidence
    medium
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    SecurityWeek

    BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

    What happened

    SecurityWeek reports that multiple espionage-motivated threat actors have adopted the BlueMoon exploit kit, which chains recent Chrome and Windows zero-day vulnerabilities. The source describes these deployments as opportunistic and rushed, though it provides no further technical details or confirmed impact data.

    Why it ranks #10

    SecurityWeek reports that multiple espionage-motivated threat actors have adopted the BlueMoon exploit kit to chain recent Chrome and Windows zero-day vulnerabilities, a development that warrants monitoring due to the active use of unpatched operating system and browser flaws in ongoing campaigns.

    Who should care

    CISOs and security leaders, IT and platform operations, SOC and incident response teams

    Impact
    low
    Urgency
    near-term
    Confidence
    medium
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email