Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Friday, September 18, 2026

Here are today’s top cybersecurity stories for Friday, September 18, 2026.

Check Point Patches Critical Flaw Letting Unauthenticated Attackers Gain Root Access
Check Point disclosed CVE-2026-91843, a critical vulnerability in Security Management and Log Server products letting an unauthenticated attacker remotely execute arbitrary code with root privileges through the login process. The company reports no evidence of active exploitation but has shared indicators of compromise and urges customers without automatic updates enabled to patch immediately. Tanium and Kaspersky also shipped patches this week for high- and medium-severity flaws in their own security products. SecurityWeek

Compromised Cloudflare API Key Lets Attackers Inject Malware Into 100,000 Websites via Brevo
Hackers who breached customer-engagement platform Brevo earlier this month used a compromised Cloudflare API key on September 14 to deploy a worker script injecting fake “verify you are human” pages into brevo.com, sibforms.com, and JavaScript files embedded on customer sites. Researchers at Sansec estimate more than 100,000 websites served the malicious script during the roughly four-hour window, tricking visitors into running commands through the ClickFix social-engineering technique. Brevo has removed the worker and revoked the compromised credentials and recommends site owners check for unauthorized WordPress plugin installs. SecurityWeek

International Agencies Warn North Korean Hackers Pose as Employers to Steal Crypto From Job Seekers
The FBI, the Department of Defense’s Cyber Crime Center, and agencies in Japan, Germany, and Australia issued a joint advisory on the North Korean hacking group WaterPlum, also known as Contagious Interview, which poses as AI, cryptocurrency, and NFT companies to target software developers and IT professionals with fake job offers. The group has infected more than 30,000 devices across over 100 countries and moved close to $11 million in cryptocurrency from over 7,000 wallets to North Korea. Japanese authorities report dismantling their first “laptop farm” tied to the operation. CyberScoop

New AI-Powered Android Malware Retains Shell Access Even After Uninstall
Zimperium researchers detailed RatHat, an Android malware family assessed to be operated by China-based actors, which pairs Accessibility-permission abuse with self-pairing to the Android Debug Bridge to gain shell-level device control. Distributed through smishing and malvertising campaigns, the malware serializes a device’s on-screen layout and queries a generative AI assistant to direct synthetic taps and navigation, and retains shell access to reinstall itself even after a victim removes the app. The Hacker News

New JavaScript Stealer Spreads Through 13 npm Packages, Shows DPRK Tradecraft Overlap
Researchers at OpenSourceMalware identified WeaselBiscuit, a previously undocumented JavaScript stealer distributed through 13 npm packages, harvesting Chrome extension storage, keystrokes, and clipboard contents on Windows, macOS, and Linux systems. The malware shares infrastructure patterns and coding overlaps with North Korea’s BeaverTail and OtterCookie families tied to the Contagious Interview campaign, though researchers stop short of formal attribution. The Hacker News

AI-Assisted Research Uncovers Widespread Image-Decoder Flaw Affecting Meta, OpenAI, and GitHub Enterprise
Researchers at Hacktron, using Anthropic’s Claude and OpenAI’s Codex to accelerate their work, disclosed “HEIF Heist,” a flaw in the widely used libheif and libde265 image-decoding libraries, letting a malicious image file trigger memory corruption for remote code execution or data theft. The researchers previously chained the flaw with a sign-in issue to compromise OpenAI employee accounts and access internal code repositories, earning a $6,500 bug bounty. The affected libraries have since been patched. CyberScoop

CISA Adds Two Actively Exploited Linux Kernel Flaws to Known Exploited Vulnerabilities Catalog
CISA added CVE-2025-39964, a Linux kernel race condition, and CVE-2026-53266, a Linux kernel out-of-bounds write flaw, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. Both vulnerabilities carry standard federal remediation deadlines and add to a growing list of kernel-level flaws under active attack in 2026. CISA

Microsoft Patches 18 Flaws Across Azure and Copilot AI Products
Microsoft released patches for 18 vulnerabilities spanning Azure ARC, Azure AI Foundry, Azure Cosmos DB, Microsoft Fabric, Dataverse, and Copilot-branded AI products, with privilege-escalation flaws accounting for most of the disclosures. None of the flaws show evidence of exploitation, and Microsoft says the fixes were implemented server-side with no customer action required. SecurityWeek

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.