Daily Briefing

Cybersecurity & Geopolitics Briefing — Saturday, September 26, 2026

Geopolitical cyber intelligence in 5 minutes
Saturday, September 26, 2026 · 20 stories

This briefing covers 20 cybersecurity and geopolitics stories published around Saturday, September 26, 2026, including activity involving Lazarus, North Korea, and 7 disclosed vulnerabilities (CVE-2026-100567, CVE-2026-35273, CVE-2026-5430, CVE-2026-65660 and others). Each entry links to the original reporting.

Share this digest:

China Builds Dual-Use Space Infrastructure Across Global South Nations (1 minute read)

China is embedding space infrastructure—ground stations, tracking facilities, data links—into bilateral agreements with Global South states, creating operational advantages independent of Western networks.

The Diplomat · 20h ago · Read full article →

Kiteworks Warns Customers to Halt Platform Use After Federal Threat Alert (1 minute read)

Kiteworks CISO Frank Balonis says federal intelligence agencies flagged a credible threat actor targeting Kiteworks customer systems, prompting an unprecedented advisory to suspend platform use.

The Record · 15h ago · Read full article →

PamStealer macOS Malware Adds Server-Side Decryption and Multi-Layer Persistence (1 minute read)

Jamf Threat Labs identified a new PamStealer variant for macOS that requires a live server-side decryption chain to recover the payload, defeating static analysis and sandbox detonation. The updated JXA dropper mechanism signals an operational security upgrade designed to outlast incident response.

The Hacker News · 22h ago · Read full article →

Foreign Policy Maps Six Russian Words Defining Life Under Putin's Authoritarianism (1 minute read)

Foreign Policy profiles six Russian-language terms ordinary citizens use to describe repression, absurdity, and power under Putin's system. The linguistic framing reflects how civil society encodes dissent as the state tightens control.

Foreign Policy · 17h ago · Read full article →

China's State Media Covers Trump-Xi Summit; Domestic Opinion Remains Opaque (1 minute read)

Beijing's official outlets extensively covered Xi Jinping's U.S. visit while suppressing or omitting signals of genuine domestic sentiment. The information gap limits Western analysts' ability to gauge whether Chinese public opinion constrains or enables Xi's negotiating posture.

The Diplomat · 19h ago · Read full article →

3,000 Protesters Confront Xi's Washington State Visit Over Human Rights (1 minute read)

Over 3,000 Tibetans, Uyghurs, Hong Kongers, and Chinese dissidents rallied in Washington during Xi Jinping's state visit to demand political freedom and human rights accountability. The protest underscores the domestic political cost for the Trump administration of high-profile engagement with Beijing.

The Diplomat · 21h ago · Read full article →

North Korean POWs Captured in Ukraine Arrive in South Korea for Resettlement (1 minute read)

Two North Korean soldiers captured fighting for Russia in Ukraine have been transferred to South Korea, triggering an unprecedented legal and intelligence resettlement process. The soldiers represent a live intelligence windfall and a geopolitical liability for Seoul navigating the Russia-North Korea military alliance.

The Diplomat · 19h ago · Read full article →

CISA Election Security Plan Identifies Voter Database Attacks, Patching Gaps (1 minute read)

A CISA plan commissioned by DHS Secretary Mullin identifies unpatched systems and voter database integrity as primary election infrastructure threats. The report institutionalizes known gaps, raising accountability pressure ahead of the next electoral cycle.

SecurityWeek · 23h ago · Read full article →

ShinyHunters Expands CVE-2026-35273 Exploitation Beyond Academia to Global Sectors (3 minute read)

UNC6240 (ShinyHunters) has relaunched mass exploitation of CVE-2026-35273 in Oracle PeopleSoft, broadening targets from universities to multiple global sectors after modifying its exploit chain. The expansion signals a deliberate pivot from opportunistic academic hits to wide-spectrum enterprise data theft.

Google Threat Intelligence · 22h ago · Read full article →

North Korea's Lazarus Suspected in $387 Million Bitget Crypto Theft (1 minute read)

Bitget's CEO accused North Korea of stealing $387 million from the platform, with losses to be covered by the exchange's $464 million User Protection Fund. The incident extends Pyongyang's crypto-theft campaign, which has generated hundreds of millions for sanctions evasion and weapons programs.

The Record · 20h ago · Read full article →

🇰🇵 Lazarus · North Korea

ShinyHunters Hacks Clop's Leak Site via Unpatched Grav CMS Path Traversal (1 minute read)

ShinyHunters compromised and defaced the Clop ransomware gang's Tor leak site by exploiting an unauthenticated path traversal vulnerability in Grav CMS that Clop left unpatched. Clop has migrated to a new Tor address — a rare instance of a criminal group's extortion infrastructure being publicly pwned by rivals.

BleepingComputer · 15h ago · Read full article →

North Korea Suspected in $351 Million Bitget Heist; Wallets Partially Frozen (1 minute read)

Bitget detected unauthorized transfers of $351 million on September 24, with some attacker wallets subsequently frozen and North Korea suspected. The theft follows a pattern of DPRK cryptocurrency operations that collectively fund Pyongyang's ballistic missile program.

SecurityWeek · 21h ago · Read full article →

Kiteworks Orders 6-Hour Global Server Shutdown Ahead of Imminent Zero-Day Attack (1 minute read)

Kiteworks directed customers worldwide to shut down servers for six hours after federal threat intelligence warned of an imminent attack against its secure file-sharing platform.

BleepingComputer · 14h ago · Read full article →

CISA Flags WSO2 CVE-2026-5430 Auth Bypass, SharePoint, and Adobe Commerce Exploits (1 minute read)

CISA warned that attackers are actively exploiting CVE-2026-5430, a critical authentication bypass in WSO2 enterprise products, alongside flaws in Microsoft SharePoint and Adobe Commerce.

BleepingComputer · 18h ago · Read full article →

CISA Adds SharePoint CVE-2026-65660 and MikroTik RouterOS to KEV Catalog (1 minute read)

CISA added CVE-2026-65660 (CVSS 8.8 SharePoint code injection) and a MikroTik RouterOS flaw to its Known Exploited Vulnerabilities catalog after confirming active in-the-wild exploitation.

The Hacker News · 3h ago · Read full article →

Kiteworks Halts Systems 9 Hours After Feds Warn of Imminent Threat Actor Attack (1 minute read)

Federal intelligence authorities alerted Kiteworks to a credible, imminent attack, prompting the company to order a nine-hour global system shutdown as a precautionary measure. Kiteworks' predecessor Accellion was exploited by Cl0p in 2021, making its managed file-transfer platform a high-value, precedent-laden target.

The Hacker News · 4h ago · Read full article →

CISA KEV: MikroTik RouterOS CVE-2026-67279 Enables Unauthenticated Remote Execution (3 minute read)

CVE-2026-67279 in MikroTik RouterOS allows unauthenticated clients to open session channels and chain with CVE-2026-86060 for full unauthenticated exploitation, now listed in CISA's KEV under BOD 26-04.

CISA KEV · 1d ago · Read full article →

CISA KEV: Microsoft SharePoint CVE-2026-65660 Code Injection Demands Immediate Patch (2 minute read)

CVE-2026-65660 allows an authorized network attacker to execute arbitrary code in Microsoft SharePoint, now mandated for remediation under CISA's BOD 26-04.

CISA KEV · 1d ago · Read full article →

CVE-2026-87902 Lets Unauthenticated Attackers Execute Code on WordPress Sites (3 minute read)

CISA added CVE-2026-87902 to its KEV catalog — a WordPress Core remote file inclusion flaw enabling unauthenticated RCE by hijacking page-template resolution. Federal agencies face mandatory remediation under BOD 26-04, signaling active exploitation in the wild.

CISA KEV · 1d ago · Read full article →

CVE-2026-100567 DNS Rebinding Flaw Exposes OpenClaw Agent Gateway (4 minute read)

OpenClaw versions 2026.4.5 through 2026.8.1 contain CVE-2026-100567, a DNS rebinding vulnerability where WebSocket and Playwright transports silently bypass gateway-level DNS pinning. Attackers can redirect CDP traffic to attacker-controlled hosts, threatening any environment running the npm 'openclaw' package.

CVE Feed (High Severity) · 8h ago · Read full article →

Get this in your inbox

Free daily briefing. No spam. Unsubscribe anytime.

Subscribe Now