Daily Briefing

Cybersecurity & Geopolitics Briefing — Friday, September 18, 2026

Geopolitical cyber intelligence in 5 minutes
Friday, September 18, 2026 · 20 stories

This briefing covers 20 cybersecurity and geopolitics stories published around Friday, September 18, 2026, including activity involving Salt Typhoon, China, and 3 disclosed vulnerabilities (CVE-2026-58138, CVE-2026-93371, CVE-2026-93468). Each entry links to the original reporting.

Share this digest:

China's FamousSparrow Hits Latin American Governments With SparroWocky Backdoor (1 minute read)

FamousSparrow, a China-linked APT, is deploying a new backdoor dubbed SparroWocky against government agencies across Latin America. The campaign extends Beijing's espionage reach into a region increasingly contested between Chinese and U.S. influence.

The Record · 19h ago · Read full article →

🇨🇳 Salt Typhoon · China

China's Salt Typhoon Deploys SparroWocky Backdoor Across Latin America (1 minute read)

Salt Typhoon, a China-linked APT, has backdoored Latin American organizations using a newly identified surveillance implant called SparroWocky. The campaign signals Beijing broadening its persistent-access espionage infrastructure beyond traditional targets in North America and Europe.

The Register Security · 18h ago · Read full article →

🇨🇳 Salt Typhoon · China

China-Linked RatHat Android Malware Survives Uninstall via ADB Shell Access (1 minute read)

China-based threat actors are distributing RatHat Android malware via smishing and malvertising, with an AI-powered control system and ADB persistence that survives app removal. Device-level persistence without reinstallation sets a dangerous precedent for mobile compromise longevity.

The Hacker News · 5h ago · Read full article →

Iran's Handala Hack Deploys HEAVYGRAM Telegram Backdoor to Steal Passwords and Sessions (1 minute read)

Iran-linked Handala Hack is attributed to HEAVYGRAM, a Telegram-based backdoor enabling remote execution, credential theft, screenshot capture, and Telegram session hijacking, paired with a Delphi tool called CRUDEEXCLUDE.

The Hacker News · 22h ago · Read full article →

China's FamousSparrow APT Targets US Political Interests Across Latin America (1 minute read)

China-linked FamousSparrow deployed a stealthy backdoor against targets tied to US political and economic interests in Latin America. The campaign signals Beijing is actively contesting Washington's influence operations in the region through cyber espionage.

Dark Reading · 16h ago · Read full article →

🇨🇳 Salt Typhoon · China

Anonymous Hackers Claim Breach of Russian Election Infrastructure Before Parliamentary Vote (1 minute read)

An anonymous group claims to have compromised computer systems tied to Russia's election infrastructure days before parliamentary voting begins. If verified, the breach would mark a significant escalation in offensive cyber operations targeting Russian democratic processes.

The Record · 22h ago · Read full article →

U.S. War Against Iran Drains Munitions and Missile Interceptors, Straining Global Readiness (3 minute read)

Sustained U.S. military operations against Iran are consuming interceptor stockpiles, extending deployments, and diverting forces from the Indo-Pacific and Europe. Analysts warn degraded readiness creates windows of opportunity for China or Russia in other theaters.

War on the Rocks · 18h ago · Read full article →

Post-Maduro Venezuela Forces Latin America into a US-China Geopolitical Pivot (3 minute read)

US forces captured Venezuelan President Maduro on January 3, 2026, secured new oil deals with the successor government, and intensified pressure on Cuba and regional trade partners.

War on the Rocks · 17h ago · Read full article →

US Fails Core Strategic Goals as Iran War Metrics Turn Against Washington (1 minute read)

Foreign Policy cites expert consensus that the US has failed its principal strategic objectives in the Iran conflict by nearly every measurable indicator. The assessment signals a widening gap between US military action and achievable political outcomes, with implications for regional deterrence credibility.

Foreign Policy · 15h ago · Read full article →

Compromised Brevo API Key Triggers Supply Chain Attack Hitting 100,000 Websites (1 minute read)

Attackers used a stolen Brevo API key to deploy a Cloudflare Worker that injected malicious scripts across roughly 100,000 websites. A single compromised API key achieving six-figure reach underscores how marketing-platform credentials now constitute critical supply chain attack surface.

SecurityWeek · 2h ago · Read full article →

UN Self-Immolation Exposes Beijing's Real Fear: Domestic Awareness on Tibet (1 minute read)

A self-immolation protest at the UN highlights that Beijing's primary vulnerability on Tibet is not international diplomatic pressure but growing awareness among China's own population. As information controls face stress, internal legitimacy—not foreign censure—is Beijing's strategic exposure.

The Diplomat · 19h ago · Read full article →

Eurasia's Pipelines and Swing States Now Define the Real Taiwan Deterrence Contest (3 minute read)

Analysts argue U.S. Taiwan deterrence strategy is misaligned, focusing on Indo-Pacific naval power while China consolidates Eurasian influence through energy corridors and alignment shifts along Silk Road routes. Losing Eurasia's swing states to Beijing could undermine deterrence before any strait crisis materializes.

War on the Rocks · 4h ago · Read full article →

China Outmaneuvers Washington on Every Front in 19 Months Under Trump (1 minute read)

In 19 months, the U.S. has conceded ground to Beijing across trade, alliances, technology, and regional influence on every measurable front. The Iran focus has functioned as strategic distraction, accelerating China's consolidation of advantage.

Foreign Policy · 20h ago · Read full article →

US-Controlled Venezuela Runs on Chinese AI Surveillance Firms Washington Banned (1 minute read)

A think tank warns that Chinese technology companies sanctioned by Washington are embedded in Venezuela's surveillance infrastructure now under de facto US control post-Maduro.

The Register Security · 9h ago · Read full article →

Congress Moves to Boost Cyber Command Support After Personnel Suicide Deaths (1 minute read)

Congressional sources cite recent suicide deaths of US Cyber Command personnel as an inflection point prompting review of service member support, amid expanded cyber operations against Iran and Venezuela.

The Record · 22h ago · Read full article →

North Korea's Contagious Interview Campaign Spreads WeaselBiscuit Stealer via 13 npm Packages (1 minute read)

Thirteen malicious npm packages deliver WeaselBiscuit, a JavaScript stealer overlapping functionally with North Korea's BeaverTail malware from the Contagious Interview campaign targeting Chrome extension storage.

The Hacker News · 1h ago · Read full article →

Authorities Seize NightmareStresser DDoS-for-Hire Domains After Hundreds of Thousands of Attacks (1 minute read)

Law enforcement seized domains for NightmareStresser, a Russia-affiliated DDoS-for-hire platform that facilitated hundreds of thousands of attacks since 2022.

CyberScoop · 22h ago · Read full article →

CVE-2026-93371: yt-dlp-web-ui v4 Exposes Remote Command Injection Flaw (2 minute read)

A publicly disclosed command injection vulnerability in marcopiovanello's yt-dlp-web-ui (CVE-2026-93371) allows remote attackers to execute arbitrary commands via the NewGenericDownload function.

CVE Feed (High Severity) · 8h ago · Read full article →

CVE-2026-93468: HGiga OAKlouds Arbitrary File Read Hits Unauthenticated Attackers (1 minute read)

CVE-2026-93468 (CVSS 8.7) allows unauthenticated remote attackers to read arbitrary system files on HGiga OAKlouds via relative path traversal. Unauthenticated exploitation with no credentials required elevates risk for enterprise deployments that have not patched.

CVE Feed (High Severity) · 8h ago · Read full article →

CVE-2026-58138: Orkes Conductor RCE Vulnerability Actively Exploited in the Wild (1 minute read)

Attackers are actively exploiting CVE-2026-58138, an unauthenticated remote code execution flaw in Orkes Conductor triggered via inline workflow definitions. Active exploitation of an unauthenticated RCE in a workflow orchestration platform puts CI/CD pipelines and cloud-native infrastructure at direct risk.

SecurityWeek · 3h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now