Daily Briefing

Cybersecurity & Geopolitics Briefing — Tuesday, September 15, 2026

Geopolitical cyber intelligence in 5 minutes
Tuesday, September 15, 2026 · 20 stories

This briefing covers 20 cybersecurity and geopolitics stories published around Tuesday, September 15, 2026, including activity involving Sandworm, Russia, and 5 disclosed vulnerabilities (CVE-2026-76461, CVE-2026-90843, CVE-2026-90847, CVE-2026-91001 and others). Each entry links to the original reporting.

Share this digest:

China's UTA0560 Chains Chrome-Windows Zero-Days to Backdoor NGOs (1 minute read)

UTA0560 hit multiple NGOs on September 1, 2026, chaining patched Chrome and Windows zero-days to deploy the GRIMWEDGE JavaScript backdoor via spear-phishing. Targeting civil society organizations signals intelligence-gathering against groups monitoring Chinese government activity.

The Hacker News · 7h ago · Read full article →

Unknown Attacker Backdoors Thailand's 3BB ISP, Harvests Subscriber Credentials (1 minute read)

An unattributed threat actor embedded MeshCentral remote-management software inside 3BB's network to maintain persistent root access and collect subscriber credentials. ISP-level compromise enables bulk credential harvesting and potential traffic interception affecting millions of Thai broadband users.

The Hacker News · 18h ago · Read full article →

China-Linked Red Heron Exploits Gitea RCE to Hit 13 Orgs in Six Countries (1 minute read)

Red Heron scanned 1,386 Gitea instances across seven countries and compromised 13 organizations in six, with 477 Taiwan-based systems tracked separately in a dedicated dataset. The Taiwan-specific targeting list indicates pre-positioning for contingency operations beyond opportunistic exploitation.

The Hacker News · 19h ago · Read full article →

Japan's Digital Agency VPN Flaw Exposes 246,000 Government Personnel Records (1 minute read)

A VPN vulnerability in Japan's Digital Agency systems exposed approximately 246,000 rows of government employee personal data. The breach raises counterintelligence concerns, as personnel records from a national digital infrastructure agency are high-value targeting data for state actors.

BleepingComputer · 15h ago · Read full article →

Rogue AI Agents, WeChat Worm, and PaperCut Attacks Mark Threat-Heavy Week (2 minute read)

The week's incidents spanned AI-assisted exploit automation, a WeChat worm, active PaperCut attacks, AI-enabled espionage, and new rootkit deployments. The convergence of AI tooling with conventional exploit chains is compressing attacker timelines across multiple threat actor categories simultaneously.

The Hacker News · 21h ago · Read full article →

Declassified: NSA's IBM-Built Harvest Supercomputer Cracked Cold War Codes (1 minute read)

Newly detailed historical records reveal the NSA's Harvest system, a specialized IBM-built codebreaking supercomputer operational in the 1960s, was a cornerstone of Cold War signals intelligence. The disclosure illustrates the decades-long U.S.

Schneier on Security · 2h ago · Read full article →

Russia's Sandworm Chains Cisco Flaws to Revive Cyclops Blink Botnet (1 minute read)

Sandworm is chaining Cisco vulnerabilities to deploy an upgraded Cyclops Blink variant, resurrecting infrastructure the FBI dismantled in 2022. The revival signals Russia's intent to rebuild strategic botnet capacity despite prior Western disruption operations.

Dark Reading · 14h ago · Read full article →

🇷🇺 Sandworm · Russia

Pro-Ukraine Hacking Cat Escalates to Destructive Malware Against Russian Targets (1 minute read)

Hacktivist group Hacking Cat has shifted from defacements and leaks to deploying novel destructive malware against Russian infrastructure targets. The escalation blurs the line between hacktivism and state-aligned offensive operations in the Ukraine conflict.

The Record · 20h ago · Read full article →

U.S. Needs China, India, Russia to Broker Iran Peace (1 minute read)

Foreign Policy argues Washington lacks the leverage to end the Iran war alone and must enlist geopolitical rivals as intermediaries. The framing exposes how U.S. military action has created a diplomatic dependency on adversaries.

Foreign Policy · 5h ago · Read full article →

Schneier and Cohn Demand End to 25 Years of U.S. Mass Surveillance (2 minute read)

Bruce Schneier and EFF's Cindy Cohn argue post-9/11 mass surveillance architecture—backbone taps, bulk metadata collection—has outlived any legitimate security justification. The op-ed lands as Congress faces recurring reauthorization fights over Section 702.

Schneier on Security · 1h ago · Read full article →

Pentagon Watchdog Issues Special Report on U.S. Iran War Since February (2 minute read)

The DoD Inspector General released a special report covering U.S. military operations in the Iran war from its February 28, 2026 start through mid-September. An IG report this early in an active conflict signals congressional and oversight pressure on the administration's war management.

Just Security · just now · Read full article →

China's Intelligence Chief Warns AI Poses Existential Risk to Beijing (1 minute read)

China's top intelligence official publicly flagged AI as a civilizational threat and called for 'technological sovereignty' and sweeping regulatory control. The statement signals Beijing is framing AI governance as a national security imperative, not merely an economic one.

The Register Security · 7h ago · Read full article →

CISA Confirms Ransomware Gangs Now Exploiting Critical VMware vCenter RCE (1 minute read)

CISA warned that ransomware operators have joined active exploitation of a critical VMware vCenter RCE flaw patched in July, widening the threat beyond initial targeted attacks. Mass ransomware exploitation of a widely deployed hypervisor platform raises enterprise-wide exposure across critical sectors.

BleepingComputer · just now · Read full article →

CVE-2026-90843: Public Exploit Drops for WebMap Nmap OS Command Injection (3 minute read)

CVE-2026-90843 enables unauthenticated remote OS command injection via the nmap_newscan function in SabyasachiRana WebMap through commit 8b95fe4. A public exploit is already available, putting any internet-exposed WebMap instance at immediate risk of full system compromise.

CVE Feed (High Severity) · 11h ago · Read full article →

CVE-2026-76461: Unauthenticated Root RCE Hits Cisco Secure Email Gateway (1 minute read)

Attackers are actively exploiting CVE-2026-76461, a SQL injection flaw in Cisco AsyncOS that grants unauthenticated remote root execution on Secure Email Gateways. Email security infrastructure at enterprise scale is now a live attack surface.

SecurityWeek · 7h ago · Read full article →

CISA Adds CVE-2026-76461 Cisco Email Gateway Flaw to KEV Catalog (2 minute read)

CISA added CVE-2026-76461, an unauthenticated root-level SQL injection in Cisco Secure Email Gateway, to its Known Exploited Vulnerabilities catalog, mandating remediation under BOD 26-04. Federal agencies face binding deadlines; private sector exposure remains broad given SEG deployment prevalence.

CISA KEV · 1d ago · Read full article →

CVE-2026-90847: Critical OS Command Injection Disclosed in EFM ipTIME C200E (2 minute read)

A CVSS 9.1 OS command injection vulnerability in EFM ipTIME C200E firmware 1.094 via iux_set.cgi is publicly disclosed and exploitable remotely with no authentication barrier noted. Public exploit availability accelerates the window to mass exploitation of a device common in South Korean home and SMB networks.

CVE Feed (High Severity) · 11h ago · Read full article →

Human Attacker Pivots from Marimo RCE to SSH Bastion in Eight Seconds (1 minute read)

A skilled threat actor exploited a Marimo notebook RCE vulnerability and reached an SSH bastion host in eight seconds, per Sysdig research. The timeline collapses traditional detection windows and challenges cloud security dwell-time assumptions.

The Hacker News · just now · Read full article →

CVE-2026-91003: Critical Stack Overflow in D-Link DI-8300 CGI Service Disclosed (2 minute read)

A CVSS 9.1 stack-based buffer overflow in D-Link DI-8300 firmware 16.07 via rzgl.asp is publicly exploitable remotely. Public exploit release for end-of-life D-Link hardware historically precedes rapid mass scanning and botnet recruitment.

CVE Feed (High Severity) · 6h ago · Read full article →

CVE-2026-91001: CVSS 9.9 Stack Overflow in D-Link DI-8400 DDNS Configuration (2 minute read)

A CVSS 9.9 stack-based buffer overflow in D-Link DI-8400 firmware 16.07 via ddns.asp is publicly released and remotely exploitable across multiple DDNS configuration arguments. Near-perfect severity score on a publicly disclosed exploit for widely deployed SOHO hardware signals imminent weaponization.

CVE Feed (High Severity) · 6h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now