Daily Briefing

Cybersecurity & Geopolitics Briefing — Friday, September 25, 2026

Geopolitical cyber intelligence in 5 minutes
Friday, September 25, 2026 · 20 stories

This briefing covers 20 cybersecurity and geopolitics stories published around Friday, September 25, 2026, including activity involving APT28, Lazarus, Salt Typhoon, China, North Korea, Russia, and 3 disclosed vulnerabilities (CVE-2026-5430, CVE-2026-71362, CVE-2026-97730). Each entry links to the original reporting.

Share this digest:

Google: Threat Actors Systematically Target CI/CD Pipelines and Dev Tools (3 minute read)

Google Threat Intelligence documents campaigns where sophisticated actors compromise security scanners, utility libraries, and AI developer tools to abuse elevated build-pipeline privileges.

Google Threat Intelligence · 22h ago · Read full article →

Anthropic Report: AI Agents Now Industrializing Credential Theft and Espionage (2 minute read)

Anthropic's misuse report across 117 findings shows Claude being weaponized for reconnaissance, phishing, cloud compromise, and propaganda at industrial scale. Human attackers now act as supervisors while AI handles operational execution, marking a structural shift in threat actor workflows.

Schneier on Security · 1h ago · Read full article →

DOJ Arrests Two Executives for Hiding Russian Ownership of Forensics Firm Holding U.S. Federal Contracts (1 minute read)

Two executives at a digital forensics and data extraction company with active U.S. agency contracts were arrested for concealing that the firm's core technology originated in Russia.

The Record · 16h ago · Read full article →

DOJ: Phone-Hacking Firm With U.S. Security Contracts Concealed Russian Ownership (1 minute read)

Two executives of a phone-hacking and data extraction company that won contracts with U.S. security agencies were arrested on conspiracy to commit wire fraud charges for hiding Russian ownership. Russian-engineered extraction tools operating inside U.S.

CyberScoop · 19h ago · Read full article →

Iran Offers White House Seven-Day Hormuz Reopening Proposal Amid War (2 minute read)

Iranian Foreign Minister Araghchi confirmed mediators delivered a seven-day proposal to the White House to reopen the Strait of Hormuz and resume negotiations.

Just Security · just now · Read full article →

Russia Escalates Hybrid Cyber-Physical Sabotage Campaign Across Europe (1 minute read)

Russia is combining cyberattacks, disinformation, and drone strikes against European nations supplying Ukraine, constituting a sustained hybrid warfare campaign below NATO's Article 5 threshold. The pattern signals Moscow is stress-testing European resolve and resilience ahead of any negotiated settlement.

Dark Reading · 5h ago · Read full article →

Russian Drone Strike on Kyiv Data Centers Knocks Out Four ISPs (1 minute read)

Wednesday's Russian drone attack damaged Kyiv data center infrastructure, causing partial connectivity losses across at least four Ukrainian internet providers, per NetBlocks.

The Record · 23h ago · Read full article →

AI Agent Breach, Fairlife Ransomware, and Iran's Water System Attacks Define Summer 2026 (1 minute read)

Summer 2026's defining incidents: AI agents breached Hugging Face, a ransomware attack hit Fairlife, and Iranian-linked actors compromised a dozen U.S. water systems. Iran's simultaneous targeting of water infrastructure across multiple U.S.

Dark Reading · 21h ago · Read full article →

OpenAI Medicare Hack Claims Collapse as Researchers Find Open Endpoint (1 minute read)

Archived code of Australia's Medicare portal reveals it directed users to an unauthenticated endpoint, undermining claims that an OpenAI agent needed to exploit any vulnerability to access it. The episode exposes how AI hacking narratives can outpace technical reality, muddying attribution and policy response.

The Record · just now · Read full article →

Warner and Cruz Bill Offers Voluntary Telecom Cyber Rules After Salt Typhoon (1 minute read)

Sens. Warner and Cruz introduced the Telecommunications Cybersecurity and Resilience Act, creating a government-industry body to develop voluntary best practices following China's Salt Typhoon breach of nearly all major U.S. telecoms.

The Record · 16h ago · Read full article →

🇨🇳 Salt Typhoon · China

Senate Intelligence and Commerce Chairs Unite on Telecom Cybersecurity Bill (1 minute read)

Senate Intelligence Vice-Chair Warner and Commerce Chair Cruz jointly introduced legislation creating a public-private group to draft voluntary telecom cybersecurity standards in response to Salt Typhoon.

CyberScoop · 22h ago · Read full article →

🇨🇳 Salt Typhoon · China

Bipartisan Bill Pushes CISA to Treat Biotech as Critical Infrastructure (1 minute read)

House and Senate legislators introduced bipartisan legislation directing CISA to extend critical infrastructure-level cyber protections to the biotechnology sector. Biotech's absence from formal critical infrastructure designations leaves genomic and pharmaceutical R&D exposed as a high-value espionage target.

CyberScoop · 15h ago · Read full article →

Sen. Markey Bill Would Create Federal Board to Investigate AI-Driven Cyberattacks (2 minute read)

Sen. Ed Markey introduced legislation to establish a Cybersecurity and AI Board of Investigations empowered to independently probe cyberattacks conducted by AI agents, citing incidents involving models from Anthropic, OpenAI, and Meta.

CyberScoop · 18h ago · Read full article →

North Korea's Lazarus Steals $351.6 Million from Bitget Crypto Exchange (1 minute read)

Suspected North Korean hackers drained $351.6 million from Bitget's hot and warm wallets in a single operation. The heist extends Lazarus Group's multi-billion-dollar crypto theft campaign that directly funds Pyongyang's weapons programs.

BleepingComputer · 4h ago · Read full article →

🇰🇵 Lazarus · North Korea

Carbonato Botnet Deploys AI Agent Framework to Hijack Exposed Docker Hosts (1 minute read)

New malware Carbonato scans for unauthenticated Docker daemon sockets and installs the Hermes Agent AI framework to seize control of compromised hosts. Weaponizing AI agent runtimes as botnet payloads sets a new operational precedent, enabling autonomous post-exploitation without traditional C2 tooling.

BleepingComputer · 16h ago · Read full article →

CISA Adds CVE-2026-5430 and CVE-2026-71362 to KEV After Active Exploitation (1 minute read)

CISA added actively exploited flaws CVE-2026-5430 (WSO2, CVSS 9.8 path traversal enabling RCE) and CVE-2026-71362 (Adobe Commerce/Magento privilege escalation) to its Known Exploited Vulnerabilities catalog. KEV listing triggers mandatory remediation timelines for federal agencies under BOD 26-04.

The Hacker News · 7h ago · Read full article →

CISA: CVE-2026-5430 WSO2 Path Traversal Enables Remote Code Execution (2 minute read)

CVE-2026-5430 affects WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway, allowing unrestricted file upload and RCE via path traversal. CISA's BOD 26-04 forensic triage requirement signals active exploitation is sophisticated enough to warrant post-compromise investigation, not just patching.

CISA KEV · 1d ago · Read full article →

CISA: CVE-2026-71362 Adobe Commerce Flaw Grants Elevated Access Without Interaction (2 minute read)

CVE-2026-71362 in Adobe Commerce and Magento allows attackers to escalate privileges and access sensitive resources with zero user interaction, now confirmed actively exploited and added to CISA KEV. E-commerce platforms running Magento represent a high-value target surface for financial data harvesting at scale.

CISA KEV · 1d ago · Read full article →

CVE-2026-97730: pfSense Dashboard LFI Enables Authenticated RCE Before 26.07 (3 minute read)

CVE-2026-97730 allows an authenticated attacker to achieve arbitrary PHP code execution via local file inclusion in pfSense Plus before 26.07 and pfSense CE before 2.9.0. pfSense firewalls are pervasive in SMB and government network perimeters, making authenticated RCE a high-value lateral movement primitive.

CVE Feed (High Severity) · 9h ago · Read full article →

Attackers Actively Exploit Critical Roundcube Webmail Code Injection Flaw (1 minute read)

Canada's Centre for Cyber Security confirmed active exploitation of a high-severity Roundcube Webmail code injection vulnerability patched in May. Roundcube is a recurring target for state-linked actors including APT28, making active exploitation a probable indicator of espionage-driven email harvesting campaigns.

BleepingComputer · 23h ago · Read full article →

🇷🇺 APT28 · Russia

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now