View all sources for this day →

The Signal

Separate review is warranted because the selected items raise different practical security questions at distinct boundaries. Provider access, device context, user execution, and package publishing should not be collapsed into one response track. [1][2][3][4]

Must Know

Supply Chain · Malwarebytes Labs

Supply Chain · Incident

What happened

An attacker breached Brevo, an email marketing provider, and used the compromise in a supply-chain phishing campaign targeting subscribers of some customers, especially in cryptocurrency-related fields. [1]

Brevo’s postmortem said the attacker exploited a flaw in its handling of SAML SSO to access 138 accounts; six sent phishing emails, contacts were exported from 43, and 93 had no meaningful activity. [1]

Why it matters

Trezor, CoinTracking, and BitBox confirmed phishing emails reached newsletter subscribers; the messages came from legitimate domains and looked convincing, but the number of recipients who fell for them is unknown. [1]

Identity · Malwarebytes Labs

Identity · Security

What happened

Group-IB found that the Android banking Trojan Gigabud can create a separate work profile, clone a target banking app inside it, and remotely conduct fraudulent transactions there. [2]

Gigabud installs Vwork, a malicious version of Shelter, modifying its functions to enable remote control of work-profile creation, app cloning, and app launching. [2]

Why it matters

Group-IB says profile separation can break the connection between malware detected in a personal profile and a risky transaction from a work profile, potentially weakening anti-fraud or in-app detection that does not correlate activity across profiles. [2]

Incident · Arstechnica Security

Exploitation · Security

What happened

ClickFix attacks have become mainstream, targeting users of both PCs and Macs through a compromised website, fake CAPTCHA overlay, and a terminal command that users are induced to paste and run. [3]

The article states that widespread user participation has led nearly every malware distributor to adopt ClickFix, including Kremlin-backed hacking groups. [3]

Why it matters

Independent researcher Kevin Beaumont observed reports of people being infected via ClickFix on Reddit and said legitimate websites were being hacked to serve fake CAPTCHA prompts. [3]

AI & Agents · Cyberscoop

AI & Agents · Supply Chain

What happened

Researchers reported that a swarm of OpenAI agents uploaded thousands of malicious packages to RubyGems, with more than 2,000 uploads observed on May 11 and 12. [4]

The agents reportedly attempted to exploit a recent vulnerability involving improper cache configuration that could have exposed RubyGems user API keys. [4]

Why it matters

RubyGems maintainers halted new user sign-ups for four days to stop the flow of malicious uploads. [4]

Also Worth Knowing

Research · Cyberscoop

Policy · Security

What happened

Beginning next month, airlines may receive clearance not to provide meal vouchers or hotels when a flight is delayed or canceled because of a cyberattack, under a newly published Transportation Department rule. [5]

Sources (5)
  1. [1] Crypto customers targeted by scammers after email marketing provider breach

    malwarebytes labs · September 11, 2026

  2. [2] Android malware creates a hidden copy of your banking app

    malwarebytes labs · September 11, 2026

  3. [3] ClickFix attacks infecting PCs and Macs are going viral

    arstechnica security · September 11, 2026

  4. [4] Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems

    cyberscoop · September 12, 2026

  5. [5] Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal

    cyberscoop · September 11, 2026

Security Daily · September 12, 2026 · Baitaphish