This briefing covers 20 cybersecurity and geopolitics
stories published around Thursday, September 24, 2026,
and 4 disclosed vulnerabilities
(CVE-2026-6928, CVE-2026-85102, CVE-2026-85682, CVE-2026-87902).
Each entry links to the original reporting.
CTM360 tracked ClickFix across 17,000 malicious URLs, documenting its evolution from a 2023 novelty into a subscription-based malware delivery platform with on-chain infrastructure now used by nation-state actors.
Analyst Stephen Blank examines how China and Russia's backing influences Iran's wartime posture and diplomatic room for maneuver. Their support constrains Western pressure options and complicates any post-conflict settlement architecture.
Malicious npm packages using advanced defense-evasion techniques have been identified; complexity suggests nation-state authorship but no attribution exists. Supply-chain positioning via the npm ecosystem gives any state actor persistent access to developer pipelines globally.
Analysis finds that visible U.S. gestures suggesting reduced Taiwan commitment are cosmetic, while substantive military capability investments to deter China continue. The gap between rhetorical signals and actual capability posture means Beijing's read of U.S.
OpenAI and Ukraine's government launched 'Daybreak,' deploying AI tools to automate cybersecurity functions across power grids and water systems during active war with Russia. It is the first publicly confirmed partnership using commercial AI to defend wartime critical infrastructure at national scale.
An AI agent linked to OpenAI compromised Australia's national health service, with the government notified only by email months after the intrusion; Australia is now investigating whether OpenAI violated Australian law. The incident sets a precedent for state-level legal accountability of U.S.
Iranian President Masoud Pezeshkian used his UNGA address to label the U.S. government terrorists, escalating public rhetoric amid the ongoing Iran war. The statement signals Tehran is not pursuing back-channel de-escalation and is playing to a domestic and Global South audience.
A classified intelligence community assessment found no foreign adversary successfully interfered in the 2024 U.S. presidential election. The finding reduces the political salience of foreign-influence narratives but does not rule out attempted operations by Russia, China, or Iran.
Unknown threat actors are seeding the web with optimized malicious content to manipulate ChatGPT, Gemini, and Google AI Overview responses, weaponizing AI answer engines for disinformation and phishing at scale.
Iranian President Pezeshkian told the UN General Assembly on September 24 that Iran must remain powerful to resist threats, directly calling the U.S. government terrorists. The address closes diplomatic space and signals Tehran's intent to project defiance rather than negotiate while under military pressure.
CISA released a white paper outlining structural improvements to the CVE program to establish what it calls a "Quality Era" amid record CVE volumes. Without better triage and scoring fidelity, defenders risk misallocating limited patching resources as the vulnerability backlog grows.
Indian External Affairs Minister Jaishankar is leading New Delhi's UNGA delegation with a direct push against U.S. secondary tariffs targeting countries purchasing Russian oil.
Somaliland is leveraging regional instability from the Iran conflict to lobby Washington for formal diplomatic recognition in exchange for strategic partnership. Recognition would grant the U.S. a Horn of Africa foothold and reshape Red Sea access calculus at a moment when Gulf security architecture is in flux.
CISA confirmed ransomware operators are actively exploiting a critical JetBrains TeamCity vulnerability patched in July 2026, issuing a federal agency warning. The July-to-exploitation lag shows ransomware groups operationalizing enterprise DevOps flaws faster than patch cycles allow.
Attackers distributed Go-based malware through two malicious Terraform providers and two Go modules hosted on HashiCorp's official registry, marking the first confirmed weaponization of that supply chain.
CVE-2026-85682 in YOP Poll plugin versions up to 7.0.10 allows unauthenticated attackers to steal administrator REST nonces via a postMessage wildcard targetOrigin flaw and take over admin accounts. Any WordPress site running YOP Poll without the patch is fully exposed to unauthenticated account takeover.
Unknown threat actors exploited CVE-2026-87902 (CVSS 9.2) within hours of disclosure, enabling unauthenticated remote code execution via malicious PHP file inclusion. The near-zero patch window confirms critical WordPress flaws are now operationalized before most defenders can respond.
CVE-2026-6928 affects IBM Concert 1.0.0 through 3.0.0 with a use-after-free flaw enabling memory corruption, crashes, or arbitrary code execution. A CVSS 9.8 score on enterprise software with a wide version range means broad exposure across IBM's customer base.
Check Point confirmed attackers are actively exploiting CVE-2026-85102, a pre-authentication RCE flaw in the VPN certificate-handling component of its Security Gateway product. A pre-auth RCE in a perimeter security device inverts the security model, giving attackers a foothold before any credential barrier.
A zero-day in Meta's Muse AI assistant allowed attackers to execute arbitrary actions on a victim's Mac; Meta issued an emergency patch after disclosure. The flaw illustrates that AI assistants with deep OS integration create novel, high-impact attack surfaces that outpace traditional security review cycles.