Daily Briefing

Cybersecurity & Geopolitics Briefing — Wednesday, September 23, 2026

Geopolitical cyber intelligence in 5 minutes
Wednesday, September 23, 2026 · 20 stories

This briefing covers 20 cybersecurity and geopolitics stories published around Wednesday, September 23, 2026, and 13 disclosed vulnerabilities (CVE-2026-5695, CVE-2026-80521, CVE-2026-85046, CVE-2026-85102 and others). Each entry links to the original reporting.

Share this digest:

UTA0565 Chains CVE-2026-85046, CVE-2026-87491, CVE-2026-85880 to Drop CLEANGULP (1 minute read)

China-linked UTA0565 chained three zero-days across Chrome and Windows ALPC on Sept. 3–4, 2026, via fake websites to deploy CLEANGULP malware. A shared exploit kit across multiple Chinese groups signals coordinated PRC offensive tooling infrastructure, not isolated actors.

The Hacker News · 4h ago · Read full article →

Volexity Links UTA0565 to Broader Chinese Exploit-Kit Sharing Network (1 minute read)

Volexity confirmed UTA0565 used the same Chrome-Windows exploit kit as several other Chinese threat groups, despite tactical differences. Shared tooling across distinct PRC-aligned actors points to centralized exploit development or procurement inside China's offensive ecosystem.

CyberScoop · 17h ago · Read full article →

Chinese Hackers Loot 18,500 Records from 996 Devices via WordPress, Zyxel Flaws (1 minute read)

A Chinese-speaking threat actor exploited vulnerabilities in Zyxel GS1900 switches and WordPress installations to exfiltrate sensitive government data from 996 devices and over 18,500 database records. The campaign demonstrates continued PRC-aligned targeting of network edge devices and public-sector data at scale.

BleepingComputer · 16h ago · Read full article →

80,000 AI Relay Servers Mask Chinese Access to U.S. Frontier LLMs (1 minute read)

Over 80,000 relay servers are routing Chinese users through identity-masking infrastructure to access U.S. frontier large language models, likely for model cloning. The operation circumvents export-control intent and represents systematic IP extraction targeting America's most sensitive commercial AI assets.

Dark Reading · 15h ago · Read full article →

Seoul Faces Simultaneous U.S. Pressure Over Ukraine and Hormuz Deployments (3 minute read)

Trump is pressing South Korea to send Cheongung-II air-defense systems to Ukraine and troops to the Strait of Hormuz simultaneously. The dual ask forces Seoul into an alliance-loyalty test that strains its Iran trade equities and Northeast Asia deterrence posture.

War on the Rocks · 5h ago · Read full article →

Trump Cites Chinese AI Threat to Justify Gutting Domestic AI Regulation (1 minute read)

Following agentic AI hack incidents, Trump doubled down on deregulation, framing U.S. AI oversight as a handicap against China. The posture trades systemic security risk for competitive speed, leaving critical AI infrastructure increasingly self-governed.

CyberScoop · 21h ago · Read full article →

Araghchi, Witkoff, and Kushner Meet on Sidelines as Iran War Diplomacy Stalls (2 minute read)

Iranian FM Araghchi met U.S. envoys Witkoff and Kushner after Trump's U.N. address amid ongoing U.S.-Iran conflict. Back-channel contact signals neither side has fully closed off negotiation even as hostilities continue.

Just Security · just now · Read full article →

Japan Launches Offensive Intelligence Agency Under Takaichi's Political Agenda (1 minute read)

Tokyo is standing up an external intelligence capability—a functional CIA equivalent—ending decades of constitutional restraint on foreign spying. The move reshapes allied intelligence-sharing architecture in the Indo-Pacific and signals Japan's intent to operate as a full-spectrum security partner.

Foreign Policy · 23h ago · Read full article →

Z.ai Apologizes for Scraping User Code, Open-Sources ZCode Tool (1 minute read)

China's Z.ai admitted its coding AI ingested user code without clear consent after an engineer exposed Grok-style data handling flaws, then open-sourced ZCode as damage control.

The Register Security · 20h ago · Read full article →

ShinyHunters Claims FBI Breach via Oracle PeopleSoft Zero-Day Exploit (1 minute read)

ShinyHunters alleges it penetrated FBI internal systems using an unpatched Oracle PeopleSoft zero-day, stealing employee and job-applicant data. A confirmed breach of FBI HR infrastructure would expose sensitive personnel records usable for targeting or coercing law enforcement and intelligence staff.

BleepingComputer · 17h ago · Read full article →

D-Link DIR-822A Hit by Max-Severity Zero-Day CVE-2026-86296, No Patch Available (1 minute read)

D-Link disclosed CVE-2026-86296, a maximum-severity flaw with public PoC exploit code, affecting legacy DIR-822A routers with no patch planned. Unpatched SOHO gear with public exploits is a ready vector for botnet recruitment and persistent network access.

BleepingComputer · 23h ago · Read full article →

CISA Flags CVE-2026-93952 in Arista VeloCloud Orchestrator as Exploited (3 minute read)

CISA added CVE-2026-93952 to its Known Exploited Vulnerabilities catalog; the Arista VeloCloud Orchestrator flaw lets remote attackers access privileged internal functions and compromise the host.

CISA KEV · 1d ago · Read full article →

CISA Adds F5 BIG-IP APM RCE Bug CVE-2026-94127 to KEV Catalog (2 minute read)

CVE-2026-94127, a heap-based buffer overflow in F5 BIG-IP APM, allows unauthenticated remote code execution when OAuth profiles are active on a virtual server. BIG-IP APM sits at network access control chokepoints, making unauthenticated RCE a direct path to credential theft and lateral movement at scale.

CISA KEV · 1d ago · Read full article →

Check Point Management Servers Exposed by Path Traversal CVE-2026-93616 (2 minute read)

CVE-2026-93616 allows unauthenticated attackers to upload and execute arbitrary scripts across Check Point Security Management Server, Log Server, and SmartEvent products.

CISA KEV · 1d ago · Read full article →

Check Point VPN Gateways Hit by Unauthenticated RCE Bug CVE-2026-85102 (3 minute read)

CVE-2026-85102 exploits improper certificate validation in Check Point Security Gateway and Spark Firewall VPN configurations, enabling unauthenticated remote code execution.

CISA KEV · 1d ago · Read full article →

Microweber Admin Panel Exposes Unrestricted File Upload via CVE-2026-5695 (2 minute read)

CVE-2026-5695 (CVSS 8.4) lets authenticated Microweber users upload arbitrary files with no validation, enabling remote code execution and full system compromise. Authenticated-only entry bar is low in CMS environments with weak credential hygiene, broadening the practical attack surface.

CVE Feed (High Severity) · 2h ago · Read full article →

Foxit PDF Editor Updater DLL Hijack Enables Privilege Escalation via CVE-2026-91803 (2 minute read)

CVE-2026-91803 (CVSS 8.8) allows local attackers to hijack DLLs loaded from user-writable directories during Foxit PDF Editor/Reader high-privilege update operations. Foxit's wide enterprise deployment makes this a reliable post-exploitation escalation path following initial access.

CVE Feed (High Severity) · 4h ago · Read full article →

Foxit PDF Editor macOS Installer Yields Root via CVE-2026-91800 (2 minute read)

CVE-2026-91800 (CVSS 8.8) lets local attackers manipulate a user-modifiable config value during Foxit PDF Editor macOS upgrades to execute arbitrary commands as root. Paired with CVE-2026-91803, the dual Foxit disclosures indicate coordinated research into a single vendor's privilege escalation surface.

CVE Feed (High Severity) · 4h ago · Read full article →

ClipBucket v5 SQL Injection CVE-2026-96272 Exposes Admin Credentials Unauthenticated (2 minute read)

CVE-2026-96272 (CVSS 8.7) enables unauthenticated time-based blind SQL injection via ClipBucket v5's photo search endpoint, extracting user credentials and admin password hashes. Any unpatched ClipBucket instance below 5.5.3-#182 is a full account-takeover target requiring zero authentication.

CVE Feed (High Severity) · 11h ago · Read full article →

Public Exploit Drops for CVE-2026-80521 Ubuntu Container Escape to Host Root (1 minute read)

DepthFirst released working exploit code for CVE-2026-80521, a Linux kernel AF_UNIX use-after-free enabling container escape to host root; Ubuntu 26.04, 24.04, and 22.04 LTS remain unpatched despite an upstream fix shipping August 6.

The Hacker News · 1h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now