This briefing covers 20 cybersecurity and geopolitics
stories published around Saturday, September 26, 2026,
including activity involving Lazarus, North Korea,
and 7 disclosed vulnerabilities
(CVE-2026-100567, CVE-2026-35273, CVE-2026-5430, CVE-2026-65660 and others).
Each entry links to the original reporting.
China is embedding space infrastructure—ground stations, tracking facilities, data links—into bilateral agreements with Global South states, creating operational advantages independent of Western networks.
Kiteworks CISO Frank Balonis says federal intelligence agencies flagged a credible threat actor targeting Kiteworks customer systems, prompting an unprecedented advisory to suspend platform use.
Jamf Threat Labs identified a new PamStealer variant for macOS that requires a live server-side decryption chain to recover the payload, defeating static analysis and sandbox detonation. The updated JXA dropper mechanism signals an operational security upgrade designed to outlast incident response.
Foreign Policy profiles six Russian-language terms ordinary citizens use to describe repression, absurdity, and power under Putin's system. The linguistic framing reflects how civil society encodes dissent as the state tightens control.
Beijing's official outlets extensively covered Xi Jinping's U.S. visit while suppressing or omitting signals of genuine domestic sentiment. The information gap limits Western analysts' ability to gauge whether Chinese public opinion constrains or enables Xi's negotiating posture.
Over 3,000 Tibetans, Uyghurs, Hong Kongers, and Chinese dissidents rallied in Washington during Xi Jinping's state visit to demand political freedom and human rights accountability. The protest underscores the domestic political cost for the Trump administration of high-profile engagement with Beijing.
Two North Korean soldiers captured fighting for Russia in Ukraine have been transferred to South Korea, triggering an unprecedented legal and intelligence resettlement process. The soldiers represent a live intelligence windfall and a geopolitical liability for Seoul navigating the Russia-North Korea military alliance.
A CISA plan commissioned by DHS Secretary Mullin identifies unpatched systems and voter database integrity as primary election infrastructure threats. The report institutionalizes known gaps, raising accountability pressure ahead of the next electoral cycle.
UNC6240 (ShinyHunters) has relaunched mass exploitation of CVE-2026-35273 in Oracle PeopleSoft, broadening targets from universities to multiple global sectors after modifying its exploit chain. The expansion signals a deliberate pivot from opportunistic academic hits to wide-spectrum enterprise data theft.
Bitget's CEO accused North Korea of stealing $387 million from the platform, with losses to be covered by the exchange's $464 million User Protection Fund. The incident extends Pyongyang's crypto-theft campaign, which has generated hundreds of millions for sanctions evasion and weapons programs.
ShinyHunters compromised and defaced the Clop ransomware gang's Tor leak site by exploiting an unauthenticated path traversal vulnerability in Grav CMS that Clop left unpatched. Clop has migrated to a new Tor address — a rare instance of a criminal group's extortion infrastructure being publicly pwned by rivals.
Bitget detected unauthorized transfers of $351 million on September 24, with some attacker wallets subsequently frozen and North Korea suspected. The theft follows a pattern of DPRK cryptocurrency operations that collectively fund Pyongyang's ballistic missile program.
Kiteworks directed customers worldwide to shut down servers for six hours after federal threat intelligence warned of an imminent attack against its secure file-sharing platform.
CISA warned that attackers are actively exploiting CVE-2026-5430, a critical authentication bypass in WSO2 enterprise products, alongside flaws in Microsoft SharePoint and Adobe Commerce.
CISA added CVE-2026-65660 (CVSS 8.8 SharePoint code injection) and a MikroTik RouterOS flaw to its Known Exploited Vulnerabilities catalog after confirming active in-the-wild exploitation.
Federal intelligence authorities alerted Kiteworks to a credible, imminent attack, prompting the company to order a nine-hour global system shutdown as a precautionary measure. Kiteworks' predecessor Accellion was exploited by Cl0p in 2021, making its managed file-transfer platform a high-value, precedent-laden target.
CVE-2026-67279 in MikroTik RouterOS allows unauthenticated clients to open session channels and chain with CVE-2026-86060 for full unauthenticated exploitation, now listed in CISA's KEV under BOD 26-04.
CVE-2026-65660 allows an authorized network attacker to execute arbitrary code in Microsoft SharePoint, now mandated for remediation under CISA's BOD 26-04.
CISA added CVE-2026-87902 to its KEV catalog — a WordPress Core remote file inclusion flaw enabling unauthenticated RCE by hijacking page-template resolution. Federal agencies face mandatory remediation under BOD 26-04, signaling active exploitation in the wild.
OpenClaw versions 2026.4.5 through 2026.8.1 contain CVE-2026-100567, a DNS rebinding vulnerability where WebSocket and Playwright transports silently bypass gateway-level DNS pinning. Attackers can redirect CDP traffic to attacker-controlled hosts, threatening any environment running the npm 'openclaw' package.