Daily Briefing

Cybersecurity & Geopolitics Briefing — Tuesday, September 22, 2026

Geopolitical cyber intelligence in 5 minutes
Tuesday, September 22, 2026 · 20 stories

This briefing covers 20 cybersecurity and geopolitics stories published around Tuesday, September 22, 2026, including activity involving Lazarus, North Korea, and 2 disclosed vulnerabilities (CVE-2026-7273, CVE-2026-94493). Each entry links to the original reporting.

Share this digest:

Japan Busts First North Korean Laptop Farm; Allies Detail WaterPlum Campaign (1 minute read)

Japan dismantled its first North Korean IT worker laptop farm as the U.S., Japan, Germany, and Australia jointly exposed the WaterPlum campaign enabling Pyongyang to infiltrate Western tech firms. The joint advisory signals coordinated allied pushback against North Korea's revenue-generating cyber workforce scheme.

SecurityWeek · 3h ago · Read full article →

China-Linked Hackers Exploit Zyxel CVE-2026-7273 Across 1,000 Switches (1 minute read)

A Chinese threat actor exploited CVE-2026-7273 to exfiltrate sensitive data from nearly 1,000 Zyxel GS1900 switches. The scale of compromise confirms state-linked pre-positioning across network infrastructure ahead of potential escalation.

SecurityWeek · just now · Read full article →

SideCopy Expands India Targeting to Academia Using ReverseRAT Spear-Phishing (1 minute read)

Pakistan-linked SideCopy is now deploying ReverseRAT against Indian academic institutions via spear-phishing that abuses mshta.exe, extending beyond its traditional government targets.

The Hacker News · 4h ago · Read full article →

Canadian Inuit Leaders Signal Openness to China Amid Ottawa Tensions (1 minute read)

Some Indigenous leaders in Canada are publicly floating partnerships with Beijing as relations with Ottawa deteriorate over unresolved land and resource disputes. China gains a potential foothold in the Arctic at a moment when Western allies are scrambling to assert sovereignty there.

Foreign Policy · 1h ago · Read full article →

TASK#STOMP PowerShell Backdoor Exfiltrates Documents, Wi-Fi Credentials, Clipboard Data (1 minute read)

A newly disclosed campaign called TASK#STOMP deploys a PowerShell backdoor that harvests business documents, monitors the filesystem in real time, and steals Wi-Fi passwords, clipboard contents, and screenshots.

The Hacker News · 22h ago · Read full article →

Russia's Mobile Internet Shutdowns Block Ukrainian Drone Attack Warnings (1 minute read)

Russia's expanding cellular and mobile internet blackouts are preventing civilians from receiving timely alerts about Ukrainian drone and missile strikes. Moscow's information-control infrastructure is now actively degrading its own population's physical safety during active conflict.

The Record · 13h ago · Read full article →

Iran's IRGC Threatens to 'Change War Geography' If U.S. Escalates (2 minute read)

IRGC spokesman Hossein Mohebbi warned on September 21, 2026 that Iran would 'change the geography of the war' in response to any U.S. escalation. The statement signals Tehran is prepared to widen the conflict beyond current front lines, raising cross-theater risk.

Just Security · just now · Read full article →

China Wins Global South AI Race by Letting Others Build on Its Tools (1 minute read)

Beijing is expanding AI influence across the Global South by offering open, permissive access to Chinese-built models and infrastructure. Dependency on Chinese AI toolchains creates long-term intelligence and supply-chain leverage without requiring direct state presence.

Foreign Policy · 17h ago · Read full article →

House Democrats Demand Audit After 1,000 CISA Employees Depart (1 minute read)

Three senior House Democrats introduced legislation ordering a military-style force structure assessment of CISA following the exit of roughly 1,000 agency personnel. Workforce attrition at the nation's lead civilian cyber defense agency directly degrades federal capacity to respond to ongoing intrusion campaigns.

CyberScoop · 20h ago · Read full article →

Russia Weaponizes Enriched Uranium Dependence Against Washington (1 minute read)

The U.S. remains structurally dependent on Russian enriched uranium for its civilian nuclear fleet, giving the Kremlin durable economic and political leverage. Washington has failed to build domestic enrichment capacity fast enough to neutralize this pressure point.

Foreign Policy · 21h ago · Read full article →

Trump Iran Sanctions Threaten to Ignite U.S.-China Trade War (1 minute read)

Washington's new maximum-pressure sanctions on Iran risk triggering a secondary-sanctions confrontation with Beijing, which continues buying Iranian oil. A U.S.-China trade rupture over Iran would fracture the coalition needed to enforce any nuclear deal.

Foreign Policy · 2h ago · Read full article →

Lazarus Contagious Interview Hits 30,000 Devices, Drains $10.71M Crypto (1 minute read)

North Korea's Contagious Interview campaign compromised 30,000 devices across 100+ countries and looted over 7,000 crypto wallets for $10.71M, per a new joint advisory. The scale confirms Pyongyang's crypto theft operations are maturing into a persistent, industrialized revenue stream.

The Hacker News · 19h ago · Read full article →

🇰🇵 Lazarus · North Korea

CISA Mandates Patch for Zyxel CVE-2026-7273 Stack Overflow Bug (3 minute read)

CISA added CVE-2026-7273, a CVSS 8.8 stack-based buffer overflow in Zyxel GS1900 switches, to its KEV catalog under BOD 26-04, requiring federal remediation. Unauthenticated LAN attackers can execute arbitrary OS commands via crafted HTTP requests.

CISA KEV · 1d ago · Read full article →

CISA Orders Federal Agencies to Patch Actively Exploited Zyxel Switch Flaw (1 minute read)

CISA confirmed active exploitation of the high-severity Zyxel GS1900 vulnerability and ordered federal agencies to apply vendor mitigations immediately. Ongoing exploitation for data theft elevates risk to government and critical infrastructure networks running affected switches.

BleepingComputer · 3h ago · Read full article →

CVE-2026-7273 and Veeam Flaws Actively Exploited for Full System Access (1 minute read)

CISA added CVE-2026-7273, a CVSS 8.8 Zyxel GS1900 buffer overflow enabling arbitrary OS command execution, alongside a Veeam flaw to its KEV catalog amid confirmed active exploitation. Simultaneous KEV listings for two enterprise infrastructure products indicate a coordinated or opportunistic multi-vector campaign.

The Hacker News · 6h ago · Read full article →

Gigatech PDV5701 CVE-2026-94493 Goes Public With No Vendor Response (2 minute read)

CVE-2026-94493, a missing-authentication flaw in Gigatech PDV5701 WebSocket Service, is now publicly exploitable after the vendor ignored disclosure contact. An unpatched, remotely exploitable authentication bypass with a public exploit and no vendor patch is a ready tool for opportunistic attackers.

CVE Feed (High Severity) · 11h ago · Read full article →

Researcher Drops Windows Defender Zero-Day That Blocks Antivirus Updates (1 minute read)

Security researcher Abdelhamid Naceri publicly released an unpatched Windows Defender zero-day exploit that prevents Microsoft antivirus from receiving updates. Blocking AV updates on unpatched systems clears the path for follow-on malware deployment across any Windows environment running Defender.

BleepingComputer · 2h ago · Read full article →

Patrick Wardle Demo Turns Meta Muse Into Attacker-Controlled Backdoor (2 minute read)

Researcher Patrick Wardle showed a PoC where malware already on a Mac redirects Meta Muse's microphone input to an attacker by flipping a hidden app setting. Any app with broad user-granted permissions becomes a pivot point once the host is compromised.

The Hacker News · 5h ago · Read full article →

CISA Flags Active Exploitation of Three Linux Kernel Vulnerabilities (1 minute read)

CISA confirmed threat actors are actively exploiting three Linux kernel flaws, one rated critical, and added them to its Known Exploited Vulnerabilities catalog. Active in-the-wild exploitation of kernel-level bugs signals elevated risk to enterprise and government Linux infrastructure.

BleepingComputer · 16h ago · Read full article →

Click2Shell WordPress CSRF Flaw Enables Remote PHP Execution on Servers (1 minute read)

A published PoC for 'Click2Shell,' a CSRF vulnerability in WordPress Core, lets attackers execute arbitrary PHP on victim servers by tricking authenticated admins. Public exploit code dramatically shortens the window before mass exploitation begins across millions of WordPress sites.

BleepingComputer · 18h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now