# CyberWireDaily\n> Security Breaches, Threats & Cyber News\n\nDaily coverage of cybersecurity breaches, malware, ransomware, vulnerabilities, and the forces shaping digital security. Updated every morning.\n\n## Recent Articles\n- [CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV](https://cyberwiredaily.net/article/2026-09-12-cisa-adds-5-actively-exploited-artifacto/): CISA has formally added five vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active expl\n- [When the Whole Company Adopts AI: What It Does to Your SOC](https://cyberwiredaily.net/article/2026-09-12-when-the-whole-company-adopts-ai-what-it/): # When Enterprise AI Adoption Floods Security Operations Centers Security operations centers face a new deluge. Alerts \n- [OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers](https://cyberwiredaily.net/article/2026-09-12-openai-agents-linked-to-rubygems-campaig/): A coordinated attack on RubyGems in May 2026 leveraged autonomous OpenAI agents to achieve remote code execution on Ruby\n- [Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware](https://cyberwiredaily.net/article/2026-09-12-cisco-fmc-flaws-exploited-to-steal-crede/): Cisco has disclosed that multiple advanced threat groups are actively exploiting two recently patched vulnerabilities in\n- [AI Governance Can't Wait](https://cyberwiredaily.net/article/2026-09-12-ai-governance-cant-wait/): # Adversaries Weaponize AI Defense Blind Spots, Forcing Urgent Governance Reckoning Threat actors have discovered a cri\n- [Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors](https://cyberwiredaily.net/article/2026-09-12-attackers-chain-jfrog-artifactory-flaws-/): Attackers exploited two chained vulnerabilities in JFrog Artifactory to seize administrator access on self-hosted instan\n- [China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor](https://cyberwiredaily.net/article/2026-09-12-china-linked-unc3569-exploited-sogou-inp/): China-linked threat actor UNC3569 exploited a zero-day vulnerability in Sogou Input Method to deploy the GRAYRABBIT back\n- [PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws](https://cyberwiredaily.net/article/2026-09-12-papercut-replaces-emergency-patches-with/): PaperCut released consolidated security patches Thursday that supersede multiple emergency updates addressing two active\n- [Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days](https://cyberwiredaily.net/article/2026-09-12-microsoft-patches-record-974-flaws-inclu/): Microsoft released fixes for a record 974 vulnerabilities across its product line during Patch Tuesday, marking the larg\n- [Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing](https://cyberwiredaily.net/article/2026-09-12-grindr-to-pay-26-million-to-settle-uk-cl/): Grindr has agreed to pay £26 million ($35.1 million) to settle a lawsuit brought against it by U.K. regulators and priva\n- [Threat Actor Generates 1M Personalized Fraud Emails in 3 Days](https://cyberwiredaily.net/article/2026-09-12-threat-actor-generates-1m-personalized-f/): # Threat Actor Generates 1 Million Personalized Fraud Emails in 3 Days Using AI Attackers have crossed a new threshold \n- [CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate](https://cyberwiredaily.net/article/2026-09-12-cisa-calls-for-more-guidance-less-spin-a/): # CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate The Cybersecurity and Infrastructure Security Agen\n- [Why AI Is So Good at Scamming Humans](https://cyberwiredaily.net/article/2026-09-12-why-ai-is-so-good-at-scamming-humans/): Frontier AI models excel at social engineering because they combine linguistic fluency with behavioral modeling at scale\n- [GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure](https://cyberwiredaily.net/article/2026-09-11-gitlab-cvss-10-file-read-flaw-draws-in-t/): GitLab released security patches this week addressing a critical path traversal vulnerability that triggered active expl\n- [Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks](https://cyberwiredaily.net/article/2026-09-11-anthropic-says-seven-china-based-ai-labs/): Anthropic disclosed Thursday that it disrupted large-scale unauthorized distillation attacks against its Claude AI model\n- [Claude Used to Automate Exploitation and Data Theft Across Multiple Victims](https://cyberwiredaily.net/article/2026-09-11-claude-used-to-automate-exploitation-and/): Anthropic disclosed that multiple threat actor groups exploited Claude AI models to execute coordinated cyber attacks, a\n- [Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection](https://cyberwiredaily.net/article/2026-09-11-russian-state-sponsored-hackers-use-clau/): Anthropic disclosed that Russian state-sponsored hackers exploited Claude, its AI assistant, to automate malware develop\n- [Your Critical Vulnerabilities Might Not Be Your Biggest Risk](https://cyberwiredaily.net/article/2026-09-11-your-critical-vulnerabilities-might-not-/): # Critical Vulnerabilities Demand Context Beyond Severity Scores Security teams excel at detecting vulnerabilities. Fin\n- [Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain](https://cyberwiredaily.net/article/2026-09-11-papercut-ai-swarm-attack-heralds-changes/): # AI-Powered Swarm Attacks Reshape Threat Landscape, Forcing Defense Strategy Rethinking Advanced threat actors are wea\n- [ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories](https://cyberwiredaily.net/article/2026-09-11-threatsday-200-android-flaws-browser-bui/): Google Play researchers discovered 200 Android malware variants circulating through the official app store, highlighting\n- [Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key](https://cyberwiredaily.net/article/2026-09-11-nearly-1-in-10-exposed-litellm-gateways-/): Wiz Research discovered a severe misconfiguration affecting LiteLLM deployments across the internet. Nearly 10 percent o\n- [Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6](https://cyberwiredaily.net/article/2026-09-11-anthropic-discloses-fourth-ai-hacking-in/): Anthropic disclosed the fourth documented case of its Claude AI model successfully breaching real third-party systems, w\n- [Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed](https://cyberwiredaily.net/article/2026-09-11-researcher-drops-new-microsoft-defender-/): Security researcher Chaotic Eclipse released a working proof-of-concept exploit demonstrating that Microsoft's patch for\n- [SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution](https://cyberwiredaily.net/article/2026-09-11-sap-patches-cvss-100-kernel-flaw-enablin/): SAP released critical security patches this week to address CVE-2026-44756, a memory corruption vulnerability in SAP Ext\n- [Indonesia Hit by Android Banking App-Cloning Campaign](https://cyberwiredaily.net/article/2026-09-11-indonesia-hit-by-android-banking-app-clo/): # Indonesia Hit by Android Banking App-Cloning Campaign Indonesian users face twin threats from sophisticated banking t\n- [Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data](https://cyberwiredaily.net/article/2026-09-11-voice-callers-exploit-byod-to-reach-micr/): Voice-based social engineering attacks are evolving into a coordinated threat against Microsoft 365 environments, with a\n- [Google Play Early Access Abused to Push Thousands of Deceptive Android Apps](https://cyberwiredaily.net/article/2026-09-10-google-play-early-access-abused-to-push-/): Threat actors have weaponized Google Play's Early Access program to distribute thousands of deceptive Android applicatio\n- [Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE](https://cyberwiredaily.net/article/2026-09-10-check-point-discloses-two-98-rated-vpn-c/): Check Point disclosed two critical vulnerabilities affecting its widely-deployed firewall and management products. Both \n- [PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances](https://cyberwiredaily.net/article/2026-09-10-papercut-attacker-uses-hundreds-of-ai-ag/): A Russian-speaking threat actor deployed hundreds of AI agents to exploit critical vulnerabilities in PaperCut NG and Pa\n- [Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks](https://cyberwiredaily.net/article/2026-09-10-gigabud-creates-android-work-profiles-to/): Gigabud banking trojan operators deployed a novel evasion technique that exploits Android's work profile feature to bypa\n- [CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline](https://cyberwiredaily.net/article/2026-09-10-cisa-flags-exploited-cisco-citrix-fortin/): CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on Wednesday, imposin\n- [Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit](https://cyberwiredaily.net/article/2026-09-10-nightmare-eclipse-strikes-again-with-shi/): # Nightmare-Eclipse Publishes 'ShieldCrash' Windows Defender Zero-Day Exploit A researcher operating under the name Nig\n- [EU Cyber Resilience Act to Enforce New Reporting Requirements](https://cyberwiredaily.net/article/2026-09-10-eu-cyber-resilience-act-to-enforce-new-r/): The European Union's Cyber Resilience Act enters into force this week, imposing a 24-hour mandatory reporting window for\n- [U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto](https://cyberwiredaily.net/article/2026-09-10-us-disrupts-xinbi-guarantee-scam-marketp/): The U.S. Department of Justice dismantled Xinbi Guarantee, a sophisticated online scam operation that facilitated fraud \n- [Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week](https://cyberwiredaily.net/article/2026-09-10-four-spy-groups-used-the-same-chrome-and/): Four distinct state-sponsored espionage groups weaponized the same previously unknown exploit kit within days of each ot\n- [Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox](https://cyberwiredaily.net/article/2026-09-10-chrome-v8-zero-day-exploited-in-the-wild/): Google patched a zero-day vulnerability in Chrome's V8 JavaScript engine that attackers have already weaponized in real-\n- [New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root](https://cyberwiredaily.net/article/2026-09-10-new-cpanel-flaw-lets-a-hosting-account-w/): cPanel released a security patch on September 8 addressing a privilege escalation vulnerability affecting all supported \n- [F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans](https://cyberwiredaily.net/article/2026-09-10-f5-big-ip-apm-malware-injects-a-php-web-/): Sophos researchers uncovered a sophisticated memory-based evasion technique in malware targeting F5 BIG-IP Access Policy\n- [Mythos Vulnerability Firehose Hits a Human Bottleneck](https://cyberwiredaily.net/article/2026-09-10-mythos-vulnerability-firehose-hits-a-hum/): # Mythos Vulnerability Firehose Hits a Human Bottleneck Project Glasswing, a large-scale vulnerability discovery initia\n- [US Government Accuses Chinese AI Firms of Distilling Frontier Models](https://cyberwiredaily.net/article/2026-09-10-us-government-accuses-chinese-ai-firms-o/): US government officials have accused Chinese artificial intelligence companies of systematically extracting billions of \n- [Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites](https://cyberwiredaily.net/article/2026-09-10-cybercriminals-hack-brazilian-government/): A Chinese-language cybercriminal group has compromised multiple Brazilian government and educational institution servers\n- [Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA](https://cyberwiredaily.net/article/2026-09-09-infostealer-logs-expose-replayable-ai-to/): Infostealer malware campaigns are now targeting AI platform credentials and API tokens, creating a direct pipeline for t\n- [Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE](https://cyberwiredaily.net/article/2026-09-09-webinar-learn-how-to-answer-are-we-expos/): Security teams face a widening gap between vulnerability disclosure and exposure assessment. When a critical CVE lands, \n- [DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval](https://cyberwiredaily.net/article/2026-09-09-deepseek-harness-flaw-let-ai-agents-disa/): DeepSeek Harness, an open-source framework for executing AI coding agents locally, contained a sandbox escape vulnerabil\n- [Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets](https://cyberwiredaily.net/article/2026-09-09-alby-hub-critical-flaw-could-let-attacke/): Alby, a Bitcoin wallet provider, disclosed a critical vulnerability in Alby Hub that could enable attackers to seize con\n- [U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok](https://cyberwiredaily.net/article/2026-09-09-us-agencies-accuse-china-ai-firms-of-dis/): U.S. intelligence and cybersecurity agencies have formally accused Chinese artificial intelligence companies of systemat\n- [Identity-Based AI Attack Threatens Security of Enterprise Data](https://cyberwiredaily.net/article/2026-09-09-identity-based-ai-attack-threatens-secur/): # Identity-Based AI Attack Threatens Security of Enterprise Data A newly documented attack technique called "workflow i\n- [OpenAI Agents Took Over Wiki Site Before Hugging Face Attack](https://cyberwiredaily.net/article/2026-09-09-openai-agents-took-over-wiki-site-before/): OpenAI's autonomous agents accessed a wiki site without authorization before attackers compromised Hugging Face infrastr\n- [ClickFix Campaigns Abuse Legitimate Services for Persistent Access](https://cyberwiredaily.net/article/2026-09-09-clickfix-campaigns-abuse-legitimate-serv/): # ClickFix Campaigns Abuse Legitimate Services for Persistent Access Threat actors are weaponizing ClickFix, a legitima\n- [N-able N-central Pre-Auth RCE Flaw Exploited in the Wild](https://cyberwiredaily.net/article/2026-09-09-n-able-n-central-pre-auth-rce-flaw-explo/): # N-Able N-Central Zero-Day Under Active Exploitation, CISA Orders Federal Fix The U.S. Cybersecurity and Infrastructur\n\n## Categories\n- [Vulnerabilities](https://cyberwiredaily.net/category/vulnerabilities/)\n- [General](https://cyberwiredaily.net/category/news/)\n- [Malware](https://cyberwiredaily.net/category/malware/)\n- [Regulation](https://cyberwiredaily.net/category/regulation/)\n- [Espionage](https://cyberwiredaily.net/category/espionage/)\n- [Breaches](https://cyberwiredaily.net/category/breaches/)\n- [Tools](https://cyberwiredaily.net/category/tools/)\n- [Cloud](https://cyberwiredaily.net/category/cloud/)\n- [Ransomware](https://cyberwiredaily.net/category/ransomware/)\n- [General](https://cyberwiredaily.net/category/opinion/)\n\n## More\n- [Archive](https://cyberwiredaily.net/archive/) — full article history\n- [Search](https://cyberwiredaily.net/search/) — search all articles