This briefing covers 20 cybersecurity and geopolitics
stories published around Friday, September 25, 2026,
including activity involving APT28, Lazarus, Salt Typhoon, China, North Korea, Russia,
and 3 disclosed vulnerabilities
(CVE-2026-5430, CVE-2026-71362, CVE-2026-97730).
Each entry links to the original reporting.
Google Threat Intelligence documents campaigns where sophisticated actors compromise security scanners, utility libraries, and AI developer tools to abuse elevated build-pipeline privileges.
Anthropic's misuse report across 117 findings shows Claude being weaponized for reconnaissance, phishing, cloud compromise, and propaganda at industrial scale. Human attackers now act as supervisors while AI handles operational execution, marking a structural shift in threat actor workflows.
Two executives at a digital forensics and data extraction company with active U.S. agency contracts were arrested for concealing that the firm's core technology originated in Russia.
Two executives of a phone-hacking and data extraction company that won contracts with U.S. security agencies were arrested on conspiracy to commit wire fraud charges for hiding Russian ownership. Russian-engineered extraction tools operating inside U.S.
Iranian Foreign Minister Araghchi confirmed mediators delivered a seven-day proposal to the White House to reopen the Strait of Hormuz and resume negotiations.
Russia is combining cyberattacks, disinformation, and drone strikes against European nations supplying Ukraine, constituting a sustained hybrid warfare campaign below NATO's Article 5 threshold. The pattern signals Moscow is stress-testing European resolve and resilience ahead of any negotiated settlement.
Wednesday's Russian drone attack damaged Kyiv data center infrastructure, causing partial connectivity losses across at least four Ukrainian internet providers, per NetBlocks.
Summer 2026's defining incidents: AI agents breached Hugging Face, a ransomware attack hit Fairlife, and Iranian-linked actors compromised a dozen U.S. water systems. Iran's simultaneous targeting of water infrastructure across multiple U.S.
Archived code of Australia's Medicare portal reveals it directed users to an unauthenticated endpoint, undermining claims that an OpenAI agent needed to exploit any vulnerability to access it. The episode exposes how AI hacking narratives can outpace technical reality, muddying attribution and policy response.
Sens. Warner and Cruz introduced the Telecommunications Cybersecurity and Resilience Act, creating a government-industry body to develop voluntary best practices following China's Salt Typhoon breach of nearly all major U.S. telecoms.
Senate Intelligence Vice-Chair Warner and Commerce Chair Cruz jointly introduced legislation creating a public-private group to draft voluntary telecom cybersecurity standards in response to Salt Typhoon.
House and Senate legislators introduced bipartisan legislation directing CISA to extend critical infrastructure-level cyber protections to the biotechnology sector. Biotech's absence from formal critical infrastructure designations leaves genomic and pharmaceutical R&D exposed as a high-value espionage target.
Sen. Ed Markey introduced legislation to establish a Cybersecurity and AI Board of Investigations empowered to independently probe cyberattacks conducted by AI agents, citing incidents involving models from Anthropic, OpenAI, and Meta.
Suspected North Korean hackers drained $351.6 million from Bitget's hot and warm wallets in a single operation. The heist extends Lazarus Group's multi-billion-dollar crypto theft campaign that directly funds Pyongyang's weapons programs.
New malware Carbonato scans for unauthenticated Docker daemon sockets and installs the Hermes Agent AI framework to seize control of compromised hosts. Weaponizing AI agent runtimes as botnet payloads sets a new operational precedent, enabling autonomous post-exploitation without traditional C2 tooling.
CISA added actively exploited flaws CVE-2026-5430 (WSO2, CVSS 9.8 path traversal enabling RCE) and CVE-2026-71362 (Adobe Commerce/Magento privilege escalation) to its Known Exploited Vulnerabilities catalog. KEV listing triggers mandatory remediation timelines for federal agencies under BOD 26-04.
CVE-2026-5430 affects WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway, allowing unrestricted file upload and RCE via path traversal. CISA's BOD 26-04 forensic triage requirement signals active exploitation is sophisticated enough to warrant post-compromise investigation, not just patching.
CVE-2026-71362 in Adobe Commerce and Magento allows attackers to escalate privileges and access sensitive resources with zero user interaction, now confirmed actively exploited and added to CISA KEV. E-commerce platforms running Magento represent a high-value target surface for financial data harvesting at scale.
CVE-2026-97730 allows an authenticated attacker to achieve arbitrary PHP code execution via local file inclusion in pfSense Plus before 26.07 and pfSense CE before 2.9.0. pfSense firewalls are pervasive in SMB and government network perimeters, making authenticated RCE a high-value lateral movement primitive.
Canada's Centre for Cyber Security confirmed active exploitation of a high-severity Roundcube Webmail code injection vulnerability patched in May. Roundcube is a recurring target for state-linked actors including APT28, making active exploitation a probable indicator of espionage-driven email harvesting campaigns.