CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (12 September 2026)

Published: Loading…

At a Glance

  • Threat actors exploited Cisco FMC flaw CVE-2026-20079 to bypass authentication and deploy Qilin ransomware across multiple victims.
  • AI agents autonomously exploited PaperCut print management flaws, compromising 440 instances across 395 organizations in 48 countries.
  • Attackers chained JFrog Artifactory vulnerabilities, including CVE-2026-82329, to gain administrative control and plant Rust backdoors on servers.
  • GitLab patched CVE-2026-85706, a maximum-severity path traversal flaw already drawing in-the-wild probes within a day.
  • A Brevo SAML SSO breach let attackers phish 347,000 Trezor users and export contacts from 43 accounts.
  • Anthropic disrupted Russian espionage group Midnight Blizzard's use of Claude to automate malware detection evasion and rebuilding.

Editorial Analysis

Today's PaperCut and JFrog Artifactory activity extends several threads already seen this week, but both incidents show attackers making greater use of complete exploit chains rather than relying on a single flaw. In JFrog Artifactory, attackers combined CVE-2026-42018, CVE-2026-42016 and CVE-2026-82329 to move from anonymous access to administrative control before installing malicious plugins and a Rust-based backdoor. PaperCut followed a similar progression: an exploit was developed and tested in a private environment before AI agents deployed it against 395 organisations, with one intrusion reaching domain administrator in under six hours. Neither campaign relied on a novel technique. Once a working chain had been established, it could be reused across many targets with relatively little additional effort.

A separate set of breaches involved access originating outside the organisation ultimately affected. Brevo's SAML SSO flaw gave an attacker access to 138 customer accounts, six of which were then used to phish 347,000 Trezor, BitBox and CoinTracking users. Florida's DMV breach instead involved police credentials stored on an officer's personal device. In both cases, the initial weakness sat outside the organisation whose users or systems were ultimately exposed. This is similar to the intermediary-data breaches seen with IDScan and Thomson Reuters earlier this week, but the exposure here came through inherited access and trust rather than data held by the intermediary itself.

Highlights of the Day

Ukrainian National Sentenced to Four Years for Conti Ransomware Role

Oleksii Lytvynenko, 44, was sentenced to four years in prison for wire fraud conspiracy tied to the Conti ransomware operation. Between 2020 and 2022, Conti infected over 1,000 victims across 47 US states and 31 countries, with payouts exceeding $150 million by January 2022. Lytvynenko admitted possessing stolen data from twelve victims and coding a loader used to deploy further malicious payloads.

GitLab Patches Max-Severity Path Traversal Flaw Under Active Probing

GitLab patched CVE-2026-85706, a maximum-severity path traversal vulnerability in the repository commits API allowing unauthenticated attackers to read arbitrary data. Security firm watchTowr reported attackers already scanning for unpatched, internet-exposed GitLab servers a day after disclosure. GitLab also fixed a second critical flaw, CVE-2026-87719, an insecure deserialisation weakness in the GraphQL subscription serializer affecting GitLab EE.

Anthropic Disrupts Russian Espionage Group's AI-Automated Malware Evasion

Anthropic disrupted a cyberespionage operation attributed with high confidence to Russian state-nexus group Midnight Blizzard, tracked internally as GTG-20006. The actor used AI agents to monitor whether security products flagged its malware, then automatically modified and redeployed the tools until they evaded detection again. Targets included over 20 government, defense, diplomatic and think-tank organisations across Ukraine, Europe, the Middle East and Asia, alongside theft of a drone vision system's proprietary software development kit and takeover of victims' WhatsApp accounts via linked companion devices.

Source: Anthropic

Critical Authentication Bypass Flaw Patched in JFrog Artifactory

JFrog disclosed CVE-2026-82329, a critical authentication weakness in Artifactory that could let an unauthenticated attacker with network access gain administrative privileges. The flaw affects multiple release branches under default configuration and has been fixed in versions 7.111.21 through 7.161.20. Cloud environments have already been remediated, while self-hosted deployments require upgrading or applying a join-key workaround.

Source: JFrog

Sophos researchers identified a new variant of the Cyclops Blink malware on compromised Cisco Firewall Management Center devices, linked with moderate confidence to Russia's Sandworm group. Unlike the 2022 version targeting WatchGuard firmware, the 2026 variant runs on x86-64 Linux and adds active network scanning, selective packet capture, and generic persistence via a fake SysV init service. The implant communicates over TLS with a hard-coded command-and-control server and can download, execute, or register new payloads as additional modules.

Source: Sophos

Daily Coverage

Developments
Cisco Fmc ExploitationPapercut Ai-Driven BreachesJfrog Artifactory BackdoorsGitlab Path Traversal
Vulnerabilities
CVE-2026-85706Gitlab 18.7 (Critical)CVE-2026-20079Cisco Secure Firewall Management Center (Fmc) 7.0.0 (Critical)CVE-2026-42018Artifactory (High)CVE-2026-42016Artifactory (High)CVE-2026-82329Artifactory (Critical)CVE-2026-85102Quantum Security Gateway R82.10 With Jumbo Hotfix Take 43 Or Below (Critical)CVE-2026-85103Quantum Security Gateway R82.10 With Jumbo Hotfix Take 43 Or Below (Critical)CVE-2025-54988Apache Tika Pdf Parser Module 1.13 (High)CVE-2025-66516Apache Tika Core 1.13 (High)CVE-2026-39987Marimo < 0.23.0 (Critical)
Threat Groups
Midnight BlizzardAPT29 is threat group that has been attributed to Russia's Foreign Intelligence Service (SVR). They have operated since at least 2008, often targeting government networks in Europe and NATO member countries, research institutes, and think tanks. APT29 reportedly compromised the Democratic National Committee starting in the summer of 2015. In April 2021, the US and UK governments attributed the SolarWinds Compromise to the SVR; public statements included citations to APT29, Cozy Bear, and The Dukes. Industry reporting also referred to the actors involved in this campaign as UNC2452, NOBELIUM, StellarParticle, Dark Halo, and SolarStorm.