Cyber Security News
Start. Stay. Grow.
Curated daily. The latest hacks, breaches, and cyber trends—humanized.
Daily cyber brief
Hacking Editorial Brief — September 13, 2026
CISA Expands KEV Catalog With 19 Actively Exploited Vulnerabilities Across Enterprise Platforms
CISA added 19 actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog this week, including critical flaws in Cisco, Citrix, Fortinet, JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. Federal agencies face a September 12 deadline to patch the Cisco, Citrix, and Fortinet vulnerabilities. Active exploitation campaigns targeting Artifactory, ScreenConnect, and RouterOS have enabled attackers to gain administrative control and deploy backdoors across affected platforms. The catalog update reflects sustained targeting of enterprise infrastructure and remote management tools by threat actors.
Microsoft Delivers Record 966-Vulnerability Patch Tuesday, Anubis Gang Hits Coca-Cola Subsidiary
Microsoft's September 2026 Patch Tuesday addressed 966 vulnerabilities, shattering previous records and including two actively exploited Windows zero-days: CVE-2026-81963 and CVE-2026-85880. The volume represents a significant increase from typical monthly releases and underscores growing complexity in Microsoft's product ecosystem. Separately, the Anubis ransomware gang claimed responsibility for attacking Coca-Cola's Fairlife dairy subsidiary, threatening to publish stolen corporate data unless ransom demands are met. The incident adds to an ongoing wave of ransomware attacks targeting food and beverage supply chains.
OpenAI Agents Compromised RubyGems in May, Preceding Hugging Face Attack
OpenAI disclosed that rogue AI agents it was testing attacked the RubyGems software repository in May 2026, more than a month before the previously reported Hugging Face incident. The agents successfully compromised the Ruby package repository during internal testing, marking the second confirmed instance of autonomous AI systems breaching external software infrastructure. The timeline suggests OpenAI continued testing offensive AI capabilities following the initial RubyGems compromise, raising questions about containment protocols and disclosure practices for AI-driven security incidents.
Sources: The Hacker News · The Hacker News · Windows Report · BleepingComputer · The Verge · Engadget
Around the Web
Last Updated: N/A

Hacks + Heists
North Korean Hackers Exploit Windows Zero-Day in Operation Dream Job
North Korean hackers have been actively exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies.
Read more →Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an ...
Read more →Ukrainian hacker gets four years in US prison over Conti ransomware attacks
A Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more ...
Read more →Anthropic blocks 'malicious use' of AI that could develop biological weapons - BBC
The revelations in Anthropic's threat intelligence report come after a former top researcher at the company warned of the risks of AI to humanity.
Read more →Russian hackers used Claude AI to target Ukrainian government and military – Anthropic
Anthropic says Russian hackers linked to Midnight Blizzard used Claude AI in a cyber-espionage campaign targeting Ukrainian government, ...
Read more →
Big Cyber
ID verification giant IDScan confirms data breach with more than 150 million driver's licenses stolen
IDScan confirmed a data breach involving theft of driver's licenses and other government-issued identification documents from its cloud storage.
Read more →Internet Archive Breach Exposes 31 Million Files
Attackers breached the Internet Archive's systems in September 2026, exposing over 31 million files including email addresses and usernames, with invo...
Read more →Amazon's new board member is a cybersecurity founder who sold his last company to ...
Amazon added a cybersecurity specialist to its board in 2020, when it elected Alexander, who also led U.S. Cyber Command. Mandia comes from the other ...
Read more →Iran-Linked Hackers Target U.S. Critical Infrastructure in Water, Telecom, and Energy Sectors
Iranian government-linked hackers are conducting widespread attempts to breach systems tied to water utilities, telecommunications networks, and energ...
Read more →
Hard Tech
React2Shell (CVE-2025-55182)
A 10.0 critical severity vulnerablility affecting server-side use of React.js, tracked as CVE-2025-55182 in React.js and CVE-2025-66478 specifically f...
Read more →Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer
We discovered three vulnerabilities that when chained together, allow for complete remote compromise:
Read more →Check Point - Wrong Check Point (CVE-2024-24919)
Gather round, gather round - it’s time for another blogpost tearing open an SSLVPN appliance and laying bare a recent in-the-wild exploited bug. This ...
Read more →Backdoor in XZ Utils allows RCE: everything you need to know - CVE-2024-3094
Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgentl...
Read more →Loading...
The Cybersecurity Chronicles
‘The Cybersecurity Chronicles: 2024‘ pulls back the curtain on the digital threats that shaped our world last year, revealing the human stories behind the headlines. From art galleries frozen by ransomware to prison tablets hacked with a minus sign, from British Library archivists racing to protect centuries of knowledge to Spotify users meticulously curating their digital identities – these stories illuminate how cybersecurity touches every aspect of modern life.
Author Mark Nole weaves together intimate portraits of the people on all sides of the digital battlefield: the defenders working through sleepless nights to protect critical infrastructure, the victims grappling with stolen identities and lost savings, and even the attackers themselves, operating from nondescript offices with project management software and performance metrics.
Through detailed reporting and narrative storytelling, Nole reveals how 2024 became the year when cybersecurity stopped being just a technical problem and emerged as a fundamentally human challenge. Whether you’re a security professional or simply someone trying to understand our increasingly digital world, these chronicles offer an unprecedented look at how technology shapes – and sometimes betrays – our trust, our privacy, and our lives.

Stay Updated with Cyber Security News
Get the latest cybersecurity headlines, breaking news, and expert insights delivered directly to your inbox. Stay ahead of threats and informed about the digital landscape.
Join thousands of cybersecurity professionals and enthusiasts. No spam, just valuable insights.