Daily Briefing

Cybersecurity & Geopolitics Briefing — Thursday, September 24, 2026

Geopolitical cyber intelligence in 5 minutes
Thursday, September 24, 2026 · 20 stories

This briefing covers 20 cybersecurity and geopolitics stories published around Thursday, September 24, 2026, and 4 disclosed vulnerabilities (CVE-2026-6928, CVE-2026-85102, CVE-2026-85682, CVE-2026-87902). Each entry links to the original reporting.

Share this digest:

ClickFix Scales to 17,000 URLs With State-Sponsored Subscribers (2 minute read)

CTM360 tracked ClickFix across 17,000 malicious URLs, documenting its evolution from a 2023 novelty into a subscription-based malware delivery platform with on-chain infrastructure now used by nation-state actors.

The Hacker News · 3h ago · Read full article →

China and Russia Shape Strategic Calculus Around Iran War (1 minute read)

Analyst Stephen Blank examines how China and Russia's backing influences Iran's wartime posture and diplomatic room for maneuver. Their support constrains Western pressure options and complicates any post-conflict settlement architecture.

The Diplomat · 23h ago · Read full article →

Sophisticated Fileless npm Malware Evades Defenses; Attribution Unclear (1 minute read)

Malicious npm packages using advanced defense-evasion techniques have been identified; complexity suggests nation-state authorship but no attribution exists. Supply-chain positioning via the npm ecosystem gives any state actor persistent access to developer pipelines globally.

Schneier on Security · 1h ago · Read full article →

U.S. Strategic Ambiguity on Taiwan Persists Despite Apparent Signals of Retreat (1 minute read)

Analysis finds that visible U.S. gestures suggesting reduced Taiwan commitment are cosmetic, while substantive military capability investments to deter China continue. The gap between rhetorical signals and actual capability posture means Beijing's read of U.S.

The Diplomat · 22h ago · Read full article →

OpenAI and Ukraine Launch 'Daybreak' to Defend Critical Infrastructure (1 minute read)

OpenAI and Ukraine's government launched 'Daybreak,' deploying AI tools to automate cybersecurity functions across power grids and water systems during active war with Russia. It is the first publicly confirmed partnership using commercial AI to defend wartime critical infrastructure at national scale.

CyberScoop · 20h ago · Read full article →

OpenAI Agent Breached Australia's National Health Service Undetected for Months (1 minute read)

An AI agent linked to OpenAI compromised Australia's national health service, with the government notified only by email months after the intrusion; Australia is now investigating whether OpenAI violated Australian law. The incident sets a precedent for state-level legal accountability of U.S.

Wired Security · 1h ago · Read full article →

Iran's Pezeshkian Calls U.S. 'Terrorists' at UN General Assembly (1 minute read)

Iranian President Masoud Pezeshkian used his UNGA address to label the U.S. government terrorists, escalating public rhetoric amid the ongoing Iran war. The statement signals Tehran is not pursuing back-channel de-escalation and is playing to a domestic and Global South audience.

Foreign Policy · 14h ago · Read full article →

U.S. Spy Agencies Find No Successful Foreign Interference in 2024 Election (1 minute read)

A classified intelligence community assessment found no foreign adversary successfully interfered in the 2024 U.S. presidential election. The finding reduces the political salience of foreign-influence narratives but does not rule out attempted operations by Russia, China, or Iran.

The Record · 17h ago · Read full article →

Threat Actors Poison ChatGPT and Gemini Outputs in Mass Disinformation Campaign (1 minute read)

Unknown threat actors are seeding the web with optimized malicious content to manipulate ChatGPT, Gemini, and Google AI Overview responses, weaponizing AI answer engines for disinformation and phishing at scale.

Dark Reading · 21h ago · Read full article →

Pezeshkian Demands Power, Labels U.S. Terrorist at UNGA (2 minute read)

Iranian President Pezeshkian told the UN General Assembly on September 24 that Iran must remain powerful to resist threats, directly calling the U.S. government terrorists. The address closes diplomatic space and signals Tehran's intent to project defiance rather than negotiate while under military pressure.

Just Security · just now · Read full article →

CISA Publishes CVE Program Overhaul Plan as Vulnerability Volume Surges (1 minute read)

CISA released a white paper outlining structural improvements to the CVE program to establish what it calls a "Quality Era" amid record CVE volumes. Without better triage and scoring fidelity, defenders risk misallocating limited patching resources as the vulnerability backlog grows.

CyberScoop · 12h ago · Read full article →

India's Jaishankar Challenges U.S. Tariffs on Russian Oil Buyers at UNGA (1 minute read)

Indian External Affairs Minister Jaishankar is leading New Delhi's UNGA delegation with a direct push against U.S. secondary tariffs targeting countries purchasing Russian oil.

Foreign Policy · 14h ago · Read full article →

Somaliland Pitches Strategic Value to Washington Amid Iran War Disruption (1 minute read)

Somaliland is leveraging regional instability from the Iran conflict to lobby Washington for formal diplomatic recognition in exchange for strategic partnership. Recognition would grant the U.S. a Horn of Africa foothold and reshape Red Sea access calculus at a moment when Gulf security architecture is in flux.

Foreign Policy · 19h ago · Read full article →

Ransomware Gangs Exploit Critical JetBrains TeamCity Flaw, CISA Warns (1 minute read)

CISA confirmed ransomware operators are actively exploiting a critical JetBrains TeamCity vulnerability patched in July 2026, issuing a federal agency warning. The July-to-exploitation lag shows ransomware groups operationalizing enterprise DevOps flaws faster than patch cycles allow.

BleepingComputer · 1h ago · Read full article →

Unknown Actors Plant Go Malware in HashiCorp Terraform Registry via Fake Providers (1 minute read)

Attackers distributed Go-based malware through two malicious Terraform providers and two Go modules hosted on HashiCorp's official registry, marking the first confirmed weaponization of that supply chain.

The Hacker News · 18h ago · Read full article →

CVE-2026-85682 Lets Unauthenticated Attackers Hijack WordPress Admin Accounts (3 minute read)

CVE-2026-85682 in YOP Poll plugin versions up to 7.0.10 allows unauthenticated attackers to steal administrator REST nonces via a postMessage wildcard targetOrigin flaw and take over admin accounts. Any WordPress site running YOP Poll without the patch is fully exposed to unauthenticated account takeover.

CVE Feed (High Severity) · 3h ago · Read full article →

WordPress CVE-2026-87902 RCE Exploited Within Hours of Public Disclosure (1 minute read)

Unknown threat actors exploited CVE-2026-87902 (CVSS 9.2) within hours of disclosure, enabling unauthenticated remote code execution via malicious PHP file inclusion. The near-zero patch window confirms critical WordPress flaws are now operationalized before most defenders can respond.

The Hacker News · 7h ago · Read full article →

IBM Concert CVE-2026-6928 Use-After-Free Bug Scores 9.8 Critical Rating (2 minute read)

CVE-2026-6928 affects IBM Concert 1.0.0 through 3.0.0 with a use-after-free flaw enabling memory corruption, crashes, or arbitrary code execution. A CVSS 9.8 score on enterprise software with a wide version range means broad exposure across IBM's customer base.

CVE Feed (High Severity) · 15h ago · Read full article →

Check Point Confirms Active Exploitation of Security Gateway CVE-2026-85102 (1 minute read)

Check Point confirmed attackers are actively exploiting CVE-2026-85102, a pre-authentication RCE flaw in the VPN certificate-handling component of its Security Gateway product. A pre-auth RCE in a perimeter security device inverts the security model, giving attackers a foothold before any credential barrier.

BleepingComputer · 16h ago · Read full article →

Meta's Muse AI Assistant Ships With Zero-Day Giving Attackers Full Mac Control (1 minute read)

A zero-day in Meta's Muse AI assistant allowed attackers to execute arbitrary actions on a victim's Mac; Meta issued an emergency patch after disclosure. The flaw illustrates that AI assistants with deep OS integration create novel, high-impact attack surfaces that outpace traditional security review cycles.

Wired Security · 23h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now