Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Wednesday, September 23, 2026

Here are today’s top cybersecurity stories for Wednesday, September 23, 2026.

Attackers Exploit Critical WordPress Core Flaw Hours After Patch
Threat actors began probing sites for CVE-2026-87902, an unauthenticated path traversal flaw in WordPress core rated 9.2, less than five hours after WordPress 7.1.2 shipped the fix. Patchstack reports a tenfold jump in malicious traffic, with payloads now writing files to disk to execute shell commands on access. WordPress backported fixes to every branch down to 4.7. BleepingComputer

F5 Patches BIG-IP APM Zero-Day Exploited for Unauthenticated Code Execution
F5 released engineering hotfixes for CVE-2026-94127, a heap-based buffer overflow rated 9.8 in BIG-IP Access Policy Manager systems acting as an OAuth authorization server. CISA added the flaw to its Known Exploited Vulnerabilities catalog on September 22 and gave federal agencies until September 25 to apply mitigations. Restricting access to the management interface does not block the attack. The Hacker News

AI Agent Framework Steals More Than 600,000 Payment Cards From Online Retailers
Researchers at Gambit report a financially motivated actor using open-source AI agent tools to scan, exploit, and plant card skimmers on retail websites at scale. The campaign compromised at least 119 websites and stole more than 600,000 valid card records from two companies, at an estimated average cost of about $25 per target. BleepingComputer

Chinese Actor UTA0565 Uses Chrome-Windows Zero-Day Chain to Deploy CLEANGULP
Volexity attributes a new wave of attacks against Asian government entities to UTA0565, a China-based actor using fake media and NGO websites to deliver the BlueMoon exploit chain. The chain combines two Chrome flaws with a Windows ALPC flaw and drops a new backdoor named CLEANGULP. UTA0565 is the latest of several China-linked groups using the same kit. The Hacker News

cPanel Flaw Lets Any Hosting Account Run Code as Root
cPanel fixed CVE-2026-87899, a flaw in its CalDAV and CardDAV service letting any logged-in account holder run code as root and take full control of the server. The same release fixes a WP Toolkit bug allowing changes to other accounts’ databases and a calendar data exposure flaw. No exploitation has been reported. The Hacker News

Critical Next.js ImageResponse Flaw Enables Server Code Execution
Vercel patched CVE-2026-94545, rated 9.5, in Next.js 16.2.0 through 16.3.5 when ImageResponse runs on the Node.js runtime and receives attacker-controlled values. The root cause sits in the Satori SVG library. Next.js 16.3.6 is the only fixed release. The Hacker News

Cisco Talos Details CLOSEDQUORUM, Malware Taking Orders From AI Model Votes
Cisco Talos documented CLOSEDQUORUM, a Windows implant built to let up to four commercial AI models vote on whether to steal credentials, inject code, or establish persistence. The public build is nonfunctional, and Talos has not observed the full chain in use. Talos released an open-source tool named CAIRN to hunt for AI-integrated malware. The Hacker News

InfraTrust Report Flags Management Consoles as Top Infrastructure Target
Eclypsium’s InfraTrust Pulse tracked 158 advisories covering 1,699 vulnerabilities across 17 vendors between August 25 and September 17. For the second month in a row, the most valuable exploited infrastructure flaws sat in administrative software such as Cisco Secure Firewall Management Center and Identity Services Engine. BleepingComputer

Sweden Fines Miljödata Over Breach Affecting 2.2 Million People
Sweden’s privacy regulator IMY fined IT systems provider Miljödata SEK 1.8 million, about $183,000, for inadequate security leading to an August 2025 breach. The attack disrupted services across more than 200 Swedish regions and municipalities. IMY continues separate investigations into two municipalities and one region. BleepingComputer

Ryuk Ransomware Operator Sentenced to Two Years in US Prison
Armenian national Karen Vardanyan received a two-year sentence and an order to pay about $1.2 million in restitution for his role in Ryuk ransomware attacks during 2019 and 2020. Prosecutors say the group collected about 1,160 bitcoins in ransom payments. CyberScoop

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.