📰 DAILY THREAT BRIEFING
Tuesday, September 15, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of September 15, 2026.

  1. 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
    — Dark Reading

    The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.
  2. Microsoft releases emergency Windows updates to fix RDS failures
    — Bleeping Computer

    Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates…
  3. Japan's Digital Agency says VPN flaw exposed 246,000 personnel records
    — Bleeping Computer

    Japan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of gove…
  4. Maximum Severity GitLab Flaw Puts Supply Chains at Risk
    — Dark Reading

    CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edit…
  5. Homebrew 7.0.0 gets built-in GUI, better security controls
    — Bleeping Computer

    Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full rel…
  6. Apple Updates Everything, (Mon, Sep 14th)
    — SANS ISC

    Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 2…
  7. New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
    — The Hacker News

    Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by…
  8. 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
    — The Hacker News

    An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of interna…
  9. Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
    — The Hacker News

    A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers …
  10. Anthropic CEO: Time to Shift From Improving to Controlling AI
    — Dark Reading

    Dario Amodei says it's time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What doe…
  11. Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection
    — Unit 42

    We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard S…
  12. ISC Stormcast For Monday, September 14th, 2026 https://isc.sans.edu/podcastdetail/10092, (Mon, Sep 14th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (13293 in last 30 days).
Critical: 0 · High: 4 · Medium: 10 · Low: 6. View full dashboard →

  1. CVE-2026-90842
    — CVSS 3.7 (LOW)

    A weakness has been identified in PHPGurukul Blood Donor Management System 1.0. Affected by this issue is some unknown functionality of the file application/models/admin/Login_Model.php. This manipulation of the argument…
  2. CVE-2026-90841
    — CVSS 7.3 (HIGH)

    A security flaw has been discovered in PHPGurukul Blood Donor Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /application/controllers/admin/Report.php of the component Repor…
  3. CVE-2026-90840
    — CVSS 7.3 (HIGH)

    A vulnerability was identified in PHPGurukul Blood Donor Management System 1.0. Affected is the function __construct of the file /application/controllers/admin/Dashboard.php of the component Admin Controllers. The manipu…
  4. CVE-2026-91201
    — CVSS 5.4 (MEDIUM)

    DocsGPT through 0.20.0 posts OAuth connector session tokens to a wildcard target origin in the callback-status endpoint without validating sender origin. Attackers can obtain session tokens and provider account emails by…
  5. CVE-2026-91200
    — CVSS 8.8 (HIGH)

    DevSpace through 6.3.21 fails to reject parent-directory segments in tar entry names from the in-pod sync stream. Attackers operating a malicious container can stream tar entries with traversal sequences to write arbitra…
  6. CVE-2026-91199
    — CVSS 5.0 (MEDIUM)

    Refly through 1.1.0 contains a server-side request forgery vulnerability in the POST /v1/misc/scrape endpoint that fetches caller-supplied URLs without validating the scheme, host, or resolved address. Authenticated atta…
  7. CVE-2026-91198
    — CVSS 5.3 (MEDIUM)

    GrowthBook through 5.0.1 returns unredacted fact table definitions including raw warehouse SQL in payloads served by unauthenticated public report and experiment endpoints. Attackers with knowledge of a publicly shared r…
  8. CVE-2026-91197
    — CVSS 6.5 (MEDIUM)

    Flowable flowable-engine through 8.0.0 contains an XML external entity injection vulnerability in ProcessDiagramLayoutFactory.parseXml() that fails to disable external entity resolution when parsing deployed BPMN resourc…
  9. CVE-2026-90835
    — CVSS 3.5 (LOW)

    A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the file Markdown.java of the component Page Content Rendering. This manipulation causes cross site scri…
  10. CVE-2026-90831
    — CVSS 5.3 (MEDIUM)

    A vulnerability was detected in GNU Binutils 2.47. The affected element is the function _bfd_elf_strtab_delref of the file bfd/elf-strtab.c of the component ELF String Table. The manipulation results in memory corruption…
  11. CVE-2026-90830
    — CVSS 5.3 (MEDIUM)

    A security vulnerability has been detected in GNU Binutils 2.47. Impacted is the function _bfd_write_merged_section of the file bfd/merge.c of the component Section Merge. The manipulation leads to null pointer dereferen…
  12. CVE-2026-90829
    — CVSS 5.3 (MEDIUM)

    A weakness has been identified in GNU Binutils 2.47. This issue affects the function bfd_elf_set_group_contents of the file bfd/elf.c of the component SHT_GROUP Section Handler. Executing a manipulation can lead to null …
  13. CVE-2026-77191
    — CVSS 2.6 (LOW)

    An authenticated supplicant on an adjacent network may bypass intended network authorization policy and send unrestricted traffic during a brief window (milliseconds to seconds) between the completion of the authenticati…
  14. CVE-2026-75945
    — CVSS 2.6 (LOW)

    A race condition may cause a supplicant to remain in an authorized state after a clear dot1x host all command is issued.
  15. CVE-2026-75944
    — CVSS 2.6 (LOW)

    A race condition during supplicant re-authentication may leave a stale ACL entry that persists in the system. If the AclAgent subsequently restarts, this stale entry may be applied to new supplicants, resulting in incorr…
  16. CVE-2026-75943
    — CVSS 2.6 (LOW)

    A brief (milliseconds to seconds) traffic leak may occur when an authenticated supplicant is removed, either via the clear dot1x host all CLI command or due to a supplicant timeout. During this window, the supplicant's t…
  17. CVE-2026-14986
    — CVSS 6.8 (MEDIUM)

    The ITE it51xxx I2C driver, when operating as an I2C target (slave) in buffer mode (CONFIG_I2C_TARGET + CONFIG_I2C_TARGET_BUFFER_MODE), copies host-supplied write data into the fixed-size data->target_in_buffer inside it…
  18. CVE-2026-91181
    — CVSS 6.5 (MEDIUM)

    Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7.7, 10.11.x <= 10.11.22 Fail to sanitize Team objects returned by the data retention teams endpoint which allows an authenticated user holding only th…
  19. CVE-2026-91146
    — CVSS 6.1 (MEDIUM)

    Takahe through 0.11.0 fails to restrict URL schemes in link hrefs within federated post content and profile summaries, allowing remote actors to inject javascript: links. Attackers can deliver federated content with mali…
  20. CVE-2026-91145
    — CVSS 7.1 (HIGH)

    Activiti through 7.1.0.M6 fails to validate hash-brace deferred expressions in process variables, allowing attackers to bypass expression filtering. Attackers can inject expressions beginning with #{ that are stored and …

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · September 15, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com