This briefing covers 20 cybersecurity and geopolitics
stories published around Tuesday, September 22, 2026,
including activity involving Lazarus, North Korea,
and 2 disclosed vulnerabilities
(CVE-2026-7273, CVE-2026-94493).
Each entry links to the original reporting.
Japan dismantled its first North Korean IT worker laptop farm as the U.S., Japan, Germany, and Australia jointly exposed the WaterPlum campaign enabling Pyongyang to infiltrate Western tech firms. The joint advisory signals coordinated allied pushback against North Korea's revenue-generating cyber workforce scheme.
A Chinese threat actor exploited CVE-2026-7273 to exfiltrate sensitive data from nearly 1,000 Zyxel GS1900 switches. The scale of compromise confirms state-linked pre-positioning across network infrastructure ahead of potential escalation.
Pakistan-linked SideCopy is now deploying ReverseRAT against Indian academic institutions via spear-phishing that abuses mshta.exe, extending beyond its traditional government targets.
Some Indigenous leaders in Canada are publicly floating partnerships with Beijing as relations with Ottawa deteriorate over unresolved land and resource disputes. China gains a potential foothold in the Arctic at a moment when Western allies are scrambling to assert sovereignty there.
A newly disclosed campaign called TASK#STOMP deploys a PowerShell backdoor that harvests business documents, monitors the filesystem in real time, and steals Wi-Fi passwords, clipboard contents, and screenshots.
Russia's expanding cellular and mobile internet blackouts are preventing civilians from receiving timely alerts about Ukrainian drone and missile strikes. Moscow's information-control infrastructure is now actively degrading its own population's physical safety during active conflict.
IRGC spokesman Hossein Mohebbi warned on September 21, 2026 that Iran would 'change the geography of the war' in response to any U.S. escalation. The statement signals Tehran is prepared to widen the conflict beyond current front lines, raising cross-theater risk.
Beijing is expanding AI influence across the Global South by offering open, permissive access to Chinese-built models and infrastructure. Dependency on Chinese AI toolchains creates long-term intelligence and supply-chain leverage without requiring direct state presence.
Three senior House Democrats introduced legislation ordering a military-style force structure assessment of CISA following the exit of roughly 1,000 agency personnel. Workforce attrition at the nation's lead civilian cyber defense agency directly degrades federal capacity to respond to ongoing intrusion campaigns.
The U.S. remains structurally dependent on Russian enriched uranium for its civilian nuclear fleet, giving the Kremlin durable economic and political leverage. Washington has failed to build domestic enrichment capacity fast enough to neutralize this pressure point.
Washington's new maximum-pressure sanctions on Iran risk triggering a secondary-sanctions confrontation with Beijing, which continues buying Iranian oil. A U.S.-China trade rupture over Iran would fracture the coalition needed to enforce any nuclear deal.
North Korea's Contagious Interview campaign compromised 30,000 devices across 100+ countries and looted over 7,000 crypto wallets for $10.71M, per a new joint advisory. The scale confirms Pyongyang's crypto theft operations are maturing into a persistent, industrialized revenue stream.
CISA added CVE-2026-7273, a CVSS 8.8 stack-based buffer overflow in Zyxel GS1900 switches, to its KEV catalog under BOD 26-04, requiring federal remediation. Unauthenticated LAN attackers can execute arbitrary OS commands via crafted HTTP requests.
CISA confirmed active exploitation of the high-severity Zyxel GS1900 vulnerability and ordered federal agencies to apply vendor mitigations immediately. Ongoing exploitation for data theft elevates risk to government and critical infrastructure networks running affected switches.
CISA added CVE-2026-7273, a CVSS 8.8 Zyxel GS1900 buffer overflow enabling arbitrary OS command execution, alongside a Veeam flaw to its KEV catalog amid confirmed active exploitation. Simultaneous KEV listings for two enterprise infrastructure products indicate a coordinated or opportunistic multi-vector campaign.
CVE-2026-94493, a missing-authentication flaw in Gigatech PDV5701 WebSocket Service, is now publicly exploitable after the vendor ignored disclosure contact. An unpatched, remotely exploitable authentication bypass with a public exploit and no vendor patch is a ready tool for opportunistic attackers.
Security researcher Abdelhamid Naceri publicly released an unpatched Windows Defender zero-day exploit that prevents Microsoft antivirus from receiving updates. Blocking AV updates on unpatched systems clears the path for follow-on malware deployment across any Windows environment running Defender.
Researcher Patrick Wardle showed a PoC where malware already on a Mac redirects Meta Muse's microphone input to an attacker by flipping a hidden app setting. Any app with broad user-granted permissions becomes a pivot point once the host is compromised.
CISA confirmed threat actors are actively exploiting three Linux kernel flaws, one rated critical, and added them to its Known Exploited Vulnerabilities catalog. Active in-the-wild exploitation of kernel-level bugs signals elevated risk to enterprise and government Linux infrastructure.
A published PoC for 'Click2Shell,' a CSRF vulnerability in WordPress Core, lets attackers execute arbitrary PHP on victim servers by tricking authenticated admins. Public exploit code dramatically shortens the window before mass exploitation begins across millions of WordPress sites.