Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (12 September 2026)
Published: Loading…
At a Glance
- Threat actors exploited Cisco FMC flaw CVE-2026-20079 to bypass authentication and deploy Qilin ransomware across multiple victims.
- AI agents autonomously exploited PaperCut print management flaws, compromising 440 instances across 395 organizations in 48 countries.
- Attackers chained JFrog Artifactory vulnerabilities, including CVE-2026-82329, to gain administrative control and plant Rust backdoors on servers.
- GitLab patched CVE-2026-85706, a maximum-severity path traversal flaw already drawing in-the-wild probes within a day.
- A Brevo SAML SSO breach let attackers phish 347,000 Trezor users and export contacts from 43 accounts.
- Anthropic disrupted Russian espionage group Midnight Blizzard's use of Claude to automate malware detection evasion and rebuilding.
Editorial Analysis
Today's PaperCut and JFrog Artifactory activity extends several threads already seen this week, but both incidents show attackers making greater use of complete exploit chains rather than relying on a single flaw. In JFrog Artifactory, attackers combined CVE-2026-42018, CVE-2026-42016 and CVE-2026-82329 to move from anonymous access to administrative control before installing malicious plugins and a Rust-based backdoor. PaperCut followed a similar progression: an exploit was developed and tested in a private environment before AI agents deployed it against 395 organisations, with one intrusion reaching domain administrator in under six hours. Neither campaign relied on a novel technique. Once a working chain had been established, it could be reused across many targets with relatively little additional effort.
A separate set of breaches involved access originating outside the organisation ultimately affected. Brevo's SAML SSO flaw gave an attacker access to 138 customer accounts, six of which were then used to phish 347,000 Trezor, BitBox and CoinTracking users. Florida's DMV breach instead involved police credentials stored on an officer's personal device. In both cases, the initial weakness sat outside the organisation whose users or systems were ultimately exposed. This is similar to the intermediary-data breaches seen with IDScan and Thomson Reuters earlier this week, but the exposure here came through inherited access and trust rather than data held by the intermediary itself.
Highlights of the Day
Ukrainian National Sentenced to Four Years for Conti Ransomware Role
Oleksii Lytvynenko, 44, was sentenced to four years in prison for wire fraud conspiracy tied to the Conti ransomware operation. Between 2020 and 2022, Conti infected over 1,000 victims across 47 US states and 31 countries, with payouts exceeding $150 million by January 2022. Lytvynenko admitted possessing stolen data from twelve victims and coding a loader used to deploy further malicious payloads.
GitLab Patches Max-Severity Path Traversal Flaw Under Active Probing
GitLab patched CVE-2026-85706, a maximum-severity path traversal vulnerability in the repository commits API allowing unauthenticated attackers to read arbitrary data. Security firm watchTowr reported attackers already scanning for unpatched, internet-exposed GitLab servers a day after disclosure. GitLab also fixed a second critical flaw, CVE-2026-87719, an insecure deserialisation weakness in the GraphQL subscription serializer affecting GitLab EE.
Anthropic Disrupts Russian Espionage Group's AI-Automated Malware Evasion
Anthropic disrupted a cyberespionage operation attributed with high confidence to Russian state-nexus group Midnight Blizzard, tracked internally as GTG-20006. The actor used AI agents to monitor whether security products flagged its malware, then automatically modified and redeployed the tools until they evaded detection again. Targets included over 20 government, defense, diplomatic and think-tank organisations across Ukraine, Europe, the Middle East and Asia, alongside theft of a drone vision system's proprietary software development kit and takeover of victims' WhatsApp accounts via linked companion devices.
Critical Authentication Bypass Flaw Patched in JFrog Artifactory
JFrog disclosed CVE-2026-82329, a critical authentication weakness in Artifactory that could let an unauthenticated attacker with network access gain administrative privileges. The flaw affects multiple release branches under default configuration and has been fixed in versions 7.111.21 through 7.161.20. Cloud environments have already been remediated, while self-hosted deployments require upgrading or applying a join-key workaround.
Cyclops Blink Malware Resurfaces With Expanded Linux Capabilities
Sophos researchers identified a new variant of the Cyclops Blink malware on compromised Cisco Firewall Management Center devices, linked with moderate confidence to Russia's Sandworm group. Unlike the 2022 version targeting WatchGuard firmware, the 2026 variant runs on x86-64 Linux and adds active network scanning, selective packet capture, and generic persistence via a fake SysV init service. The implant communicates over TLS with a hard-coded command-and-control server and can download, execute, or register new payloads as additional modules.
Daily Coverage