Daily Briefing

Cybersecurity & Geopolitics Briefing — Monday, September 14, 2026

Geopolitical cyber intelligence in 5 minutes
Monday, September 14, 2026 · 20 stories

This briefing covers 20 cybersecurity and geopolitics stories published around Monday, September 14, 2026, and 9 disclosed vulnerabilities (CVE-2026-12258, CVE-2026-21391, CVE-2026-51990, CVE-2026-89180 and others). Each entry links to the original reporting.

Share this digest:

China-Linked Group Exploits CVE-2026-51990 in Sogou Input to Drop GrayRabbit (1 minute read)

A China-aligned espionage group is exploiting critical CVE-2026-51990 in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. The campaign targets a ubiquitous Chinese-language input tool, expanding the attack surface to any Windows user running the software.

BleepingComputer · 23h ago · Read full article →

Chinese Hackers Weaponize CVE-2026-51990 in Tencent Sogou for One-Click RCE (1 minute read)

Chinese hackers are exploiting a critical flaw in Tencent's Sogou Input Method Editor allowing one-click remote code execution on Windows systems. The attack requires minimal user interaction, dramatically lowering the bar for mass compromise of Chinese-language Windows users globally.

SecurityWeek · 1h ago · Read full article →

Trump Signals U.S. May Seize Iranian Oil After Military Action (2 minute read)

Trump publicly stated the U.S. could remain in Iran and extract oil revenues, framing military presence as an economic windfall. The statement signals potential annexationist intent, setting a precedent that would alarm Gulf partners and complicate post-conflict diplomatic exit strategies.

Just Security · 1h ago · Read full article →

Major Powers Accelerate Strategic Exclusion as Geopolitical Blocs Harden (3 minute read)

Russia, the U.S., and China are systematically locking rivals out of technology, infrastructure, and economic networks through invasion, semiconductor controls, and Belt and Road positioning.

War on the Rocks · 6h ago · Read full article →

NSA Restructures Into Five Mission Centers, Elevating Cyber and AI Directorates (1 minute read)

The NSA is undergoing a sweeping reorganization, creating five mission centers with dedicated cyber and AI pillars to sharpen operational focus. The restructuring signals Washington's intent to institutionalize AI-driven signals intelligence at the agency's core rather than treat it as an adjunct capability.

The Record · 16h ago · Read full article →

Space Economy Hits $600B as AI Blurs Orbital and Terrestrial Infrastructure (3 minute read)

The global space economy exceeds $600B annually, with autonomous mega-constellations and AI integration accelerating toward a projected $1T by the 2030s.

War on the Rocks · 5h ago · Read full article →

India-China Summits Produce Agreements That Rarely Advance Relations (1 minute read)

India-China leadership meetings consistently yield procedural accords timed to multilateral summits but fail to resolve structural territorial and economic disputes. The pattern indicates both governments use summitry for optics while the underlying strategic rivalry deepens.

The Diplomat · 12h ago · Read full article →

Revolut Exposes Customer Financial Data and Passports to Fake Government Agency (1 minute read)

Revolut inadvertently shared financial information and passport data with a threat actor impersonating a government agency, exposing an undisclosed number of customers. The social-engineering vector against a regulated fintech highlights how institutional compliance reflexes can be weaponized for data theft.

BleepingComputer · 4h ago · Read full article →

Revolut Hands Customer Passport and Financial Data to Social-Engineering Actor (1 minute read)

Revolut disclosed it shared personal and financial data—including passports—with a third party that impersonated a government agency. The breach demonstrates that regulatory compliance workflows are a viable social-engineering target against fintechs holding sensitive identity documents.

SecurityWeek · just now · Read full article →

Malicious Twitch Extension Leaks OAuth Tokens From 31,000 Users to Russian Bot Service (1 minute read)

The cross-store Chrome and Firefox extension "Twitch Enhanced Viewer | JeetBot" exfiltrated OAuth tokens from 30,700+ users to proxy servers run by a Russian commercial bot network.

The Hacker News · 6h ago · Read full article →

Revolut Hands Customer Data to Fraudsters Abusing Legitimate Government Email (1 minute read)

Revolut confirmed it disclosed sensitive customer data after fraudsters submitted emergency data requests using a compromised legitimate government email account.

The Record · 1h ago · Read full article →

CISA Confirms Active Exploitation of Max-Severity GitLab Vulnerability (1 minute read)

CISA added a maximum-severity GitLab flaw to its Known Exploited Vulnerabilities catalog after confirming active in-the-wild attacks. GitLab's widespread use in software development pipelines makes this a supply-chain-adjacent risk at scale.

BleepingComputer · 6h ago · Read full article →

CVE-2026-90703: Critical OS Command Injection Hits D-Link DWR-M921 Remotely (2 minute read)

A CVSS 9.1 OS command injection flaw in D-Link DWR-M921 1.1.52 via the formDiskCreateShare function allows remote unauthenticated code execution; exploit is publicly available. D-Link edge devices have a persistent patch-lag problem, making public exploit disclosure an immediate threat to exposed routers.

CVE Feed (High Severity) · 3h ago · Read full article →

CVE-2026-90691: Public Path Traversal Exploit Drops for HexStrike AI Platform (3 minute read)

A remotely exploitable path traversal vulnerability in 0x4m4 HexStrike AI's API Files Endpoint allows attackers to manipulate file paths via the filename argument; exploit is publicly disclosed. AI development tooling with unauthenticated file-access flaws represents an emerging and underprioritized attack surface.

CVE Feed (High Severity) · 6h ago · Read full article →

CVE-2026-90699: CVSS 9.9 Command Injection in D-Link DWR-M920 Exposed Publicly (2 minute read)

A near-perfect CVSS 9.9 OS command injection flaw in D-Link DWR-M920 1.1.7 via formPinManageSetup allows remote attackers to inject commands through the newPin argument; exploit is public.

CVE Feed (High Severity) · 4h ago · Read full article →

CVE-2026-90919: LightLLM Unauthenticated RCE via Pickle Deserialization, CVSS 9.8 (2 minute read)

LightLLM through v1.2.0 exposes an unauthenticated WebSocket endpoint that passes raw client frames to pickle.loads(), enabling full remote code execution with process-level privileges.

CVE Feed (High Severity) · 1h ago · Read full article →

CVE-2026-21391: PingAM OIDC Flaw Allows Authentication Bypass via Token Claim Spoofing (2 minute read)

CVE-2026-21391 (CVSS 9.5) allows attackers to set or override arbitrary ID Token claims in PingAM's OIDC provider, enabling authentication bypass and privilege escalation in affected configurations.

CVE Feed (High Severity) · 1h ago · Read full article →

CVE-2026-12258: Hiperdino REST API Leaks Customer PII With Static Bearer Token (3 minute read)

CVE-2026-12258 exposes Hiperdino's customer/check endpoint, allowing any attacker with a static bearer token to enumerate emails and phone numbers with no rate limiting. The absence of real authentication on a customer-lookup endpoint constitutes a bulk-harvesting risk for fraud and phishing operations.

CVE Feed (High Severity) · 1h ago · Read full article →

CVE-2026-90707: Open5GS AMF Use-After-Free Enables Remote Code Execution on 5G Core (2 minute read)

CVE-2026-90707 is a remotely exploitable use-after-free in Open5GS's AMF discovery fallback handler, affecting all versions through 2.7.x.

CVE Feed (High Severity) · 2h ago · Read full article →

CVE-2026-89180: EFence SQL Injection Exposes Database to Unauthenticated Remote Attackers (1 minute read)

Thinking Software Technology's EFence contains an unauthenticated SQL injection flaw (CVSS 8.7) allowing full database read access remotely. EFence is positioned as a security product, meaning its compromise would directly expose the protected environments and logged data it was deployed to defend.

CVE Feed (High Severity) · 2h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now