Daily Briefing

Cybersecurity & Geopolitics Briefing — Saturday, September 19, 2026

Geopolitical cyber intelligence in 5 minutes
Saturday, September 19, 2026 · 20 stories

This briefing covers 20 cybersecurity and geopolitics stories published around Saturday, September 19, 2026, including activity involving Lazarus, North Korea, and 6 disclosed vulnerabilities (CVE-2025-39682, CVE-2025-39964, CVE-2026-53266, CVE-2026-57228 and others). Each entry links to the original reporting.

Share this digest:

NightEagle Espionage Group Expands from China Targets to Russian Firms (1 minute read)

Kaspersky investigated multiple NightEagle intrusions at Russian businesses over the past year, after the group previously focused on China's high-tech sector. The pivot suggests NightEagle is broadening its industrial espionage mandate regardless of geopolitical alignment.

The Record · 22h ago · Read full article →

Pakistan's APT36 Deploys Rust Backdoors via GitHub C2 Against India, Afghanistan (1 minute read)

Transparent Tribe used four new tools—RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH—in Operation targeting Indian and Afghan government and defense entities, per Zscaler ThreatLabz. Private GitHub repositories as C2 infrastructure marks a deliberate shift toward legitimate-service abuse to evade detection.

The Hacker News · 20h ago · Read full article →

Satellite Imagery and IAEA Data Reveal North Korea's 2026 Nuclear Program Status (1 minute read)

Commercial satellite imagery and IAEA assessments indicate continued activity at North Korea's nuclear facilities through 2026. Sustained operations despite maximum-pressure rhetoric confirm Pyongyang is prioritizing warhead and fissile material expansion on its own timeline.

The Diplomat · 23h ago · Read full article →

China Regularizes Naval Patrols Near Taiwan, Deploys Dual-Use Research Vessels (1 minute read)

China is normalizing military-adjacent presence in Taiwan-proximate waters using coast guard patrols and research vessels capable of reconnaissance. Regularization transforms what were once provocative incursions into established facts of maritime geography, compressing Taiwan's strategic warning time.

The Diplomat · 22h ago · Read full article →

China Rewrites Shipki La History, Erasing Tibet's Pre-1951 Agency (1 minute read)

Beijing frames Shipki La as a direct China-India trade route, omitting Tibet's independent role before its 1951 absorption. The historical revision supports China's territorial claims by retroactively eliminating a sovereign intermediary from the record.

The Diplomat · 18h ago · Read full article →

Iran-Oman Strait of Hormuz Deal Collapses Before Salalah Meeting (3 minute read)

Planned Iran-Oman-Gulf state talks on Hormuz management were postponed after provisions failed to hold before the Salalah meeting. A collapsed deal signals Tehran cannot secure maritime legitimacy even through neutral Omani mediation.

War on the Rocks · 17h ago · Read full article →

South Korea Refuses Troop Deployment as U.S.-Iran War Expands (2 minute read)

South Korean President Lee Jae Myung publicly declared Seoul will not commit troops or military assets to support U.S. operations against Iran. The refusal fractures allied burden-sharing assumptions and signals limits of Washington's coalition in a Middle East escalation scenario.

Just Security · 23h ago · Read full article →

AI Actress Tilly Norwood App Face-Scans and Mood-Tracks Every Caller (1 minute read)

Tilly Norwood's viral "Talking Tilly" service requires facial biometric scans for age verification and continuously analyzes callers' emotional state throughout calls before shutting down September 27.

BleepingComputer · just now · Read full article →

Vietnam, Laos, Pakistan, Argentina Act Against North Korean IT Worker Networks (1 minute read)

Four nations took concrete steps to counter North Korean IT worker infiltration following an October UN Panel of Experts report, per a Wednesday assessment. Coordinated host-nation action represents the most tangible multilateral pressure on Pyongyang's sanctions-evasion labor networks to date.

The Record · 21h ago · Read full article →

North Korea's WaterPlum Backdoors 30,000 Devices, Raids 7,000 Crypto Wallets via Fake Job Tests (1 minute read)

Lazarus-linked WaterPlum operatives posed as recruiters, used bogus coding tests to deploy backdoors across 30,000 devices, and drained more than 7,000 cryptocurrency wallets.

The Register Security · 18h ago · Read full article →

🇰🇵 Lazarus · North Korea

TanStack Supply Chain Attack Hands Attacker 170 CrowdSec Private Repos (1 minute read)

An attacker used credentials stolen via malicious TanStack npm packages in May to copy approximately 170 private CrowdSec GitHub repositories on May 22 through a departed employee's unrevoked account.

The Hacker News · 4h ago · Read full article →

Gyazo Server Vulnerability Exploited to Steal 23.6 Million User Records (1 minute read)

Attackers exploited a server-side vulnerability in the Gyazo image-sharing platform to exfiltrate 23.6 million user records.

BleepingComputer · 19h ago · Read full article →

CISA Adds Three Exploited Linux Kernel CVEs, Including CVE-2025-39682 CVSS 9.8 (1 minute read)

CISA added CVE-2025-39682 (CVSS 9.8, TLS receive-path flaw) and two other Linux kernel vulnerabilities to its KEV catalog following confirmed active exploitation.

The Hacker News · 5h ago · Read full article →

CISA Orders Patch for Linux Kernel Race Condition CVE-2025-39964 (2 minute read)

CISA added CVE-2025-39964, a Linux kernel AF_ALG socket race condition enabling unpredictable data interleaving, to its Known Exploited Vulnerabilities catalog. Federal agencies must remediate under BOD 26-04, signaling active exploitation in the wild.

CISA KEV · 1d ago · Read full article →

Linux Kernel CVE-2026-53266 Out-of-Bounds Write Hits End-of-Life Systems (3 minute read)

CVE-2026-53266 allows attackers to write out-of-bounds via ebtables SNAT into splice-imported file pages on Linux kernel installs, many of which are EoL. CISA's KEV listing means exploitation is confirmed; unpatched legacy deployments face no vendor support path.

CISA KEV · 1d ago · Read full article →

Linux Kernel TLS Flaw CVE-2025-39682 Added to CISA Exploit Catalog (3 minute read)

CVE-2025-39682 lets a zero-length TLS record bypass recvmsg() type checks, corrupting subsequent record processing on end-of-life Linux versions. Active exploitation of a TLS-layer kernel bug raises risk for any infrastructure running unpatched network stacks.

CISA KEV · 1d ago · Read full article →

Public Exploit Released for Critical Totolink CVE-2026-93741 Buffer Overflow (2 minute read)

CVE-2026-93741, a CVSS 10.0 buffer overflow in Totolink A3002MU's formWlWds function, is remotely exploitable and has a public exploit. Consumer-grade routers with published exploits are prime pivot points for botnet recruitment and lateral movement into home-office networks.

CVE Feed (High Severity) · 5h ago · Read full article →

SAP Critical Flaw, Plugin4Shell AI Attack, Ransomware Dev Sentenced (1 minute read)

A WordPress plugin vulnerability is being actively exploited, an AI-assisted attack technique dubbed Plugin4Shell has emerged, and a ransomware developer received a prison sentence. Mandiant's 2026 AI risk report frames the Plugin4Shell technique as an early indicator of AI-accelerated exploitation pipelines.

SecurityWeek · 21h ago · Read full article →

Critical CVE-2026-93742 Command Injection in Totolink Routers Goes Public (2 minute read)

CVE-2026-93742, scoring 9.9, allows remote command injection via the formWsc localPin argument on Totolink A3002MU routers; a public exploit is already available. Back-to-back critical CVEs with public exploits on the same router model signals coordinated research or pre-attack reconnaissance against this device line.

CVE Feed (High Severity) · 2h ago · Read full article →

Suricata CVE-2026-57228 Heap Read Bug Lets Crafted SMTP Blind IDS Sensors (3 minute read)

CVE-2026-57228 causes a one-byte heap out-of-bounds read in Suricata 7.0.13–7.0.17's SMTP MIME quoted-printable decoder via split traffic chunks, crashing or destabilizing the IDS.

CVE Feed (High Severity) · 14h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now