The Signal
Must Know
Exploitation · Cyberscoop
What happened
Volexity reported that the China-aligned group UTA0565 exploited a three-vulnerability zero-day chain affecting Chrome and Microsoft before the defects were disclosed or patched, during September 3–4. [1]
The chain included CVE-2026-85046 and CVE-2026-87491, remote-code-execution defects in Chromium-based browser JavaScript engines, and CVE-2026-85880, a Windows Advanced Local Procedure Call privilege-escalation zero-day. [1]
Why it matters
Volexity said UTA0565 used multiple fake websites, phishing emails targeting Asian government entities, and spoofed domains impersonating the Center for American Progress and China Digital Times. [1]
The reported chain crosses browser and operating-system boundaries, making the distinction between those layers central to its practitioner relevance. [1]
Identity · The Hacker News
What happened
Attackers are exploiting CVE-2026-94127, a critical flaw in F5 BIG-IP Access Policy Manager (APM) that can allow unauthenticated code execution on a BIG-IP system, according to F5. [2]
The vulnerability affects only systems where APM operates as an OAuth authorization server issuing access tokens to applications. [2]
Why it matters
The reported condition narrows relevance to a specific authorization role rather than all BIG-IP deployments. [2]
Identity · Helpnetsecurity
What happened
Check Point released emergency fixes for critical Management Server vulnerability CVE-2026-93616, which had been exploited as early as July 23, 2026. [5]
Check Point confirmed that CVE-2026-85102, a pre-authentication remote-code-execution vulnerability in Check Point Quantum Security Gateway, was probed a few days after patches were released on September 9, 2026. [5]
Why it matters
The two reported cases distinguish exploitation of a management component from post-patch probing of a gateway defect. [5]
AI & Agents · Theregister Security
What happened
Cisco Talos describes CLOSEDQUORUM as a Windows malware implant that queries up to four LLM providers—Gemini, DeepSeek, Qwen, and Mistral—to select predefined post-compromise actions, including credential and cryptocurrency-wallet theft. [3]
After deployment, CLOSEDQUORUM reportedly operates without continued human commands; Talos calls it, to its knowledge, the first publicly documented Windows implant using this approach for C2. [3]
Why it matters
Talos analyst Ryan Fetterman said transferring an attack phase from a human operator to AI systems can remove a human bottleneck, allowing activity to continue when an operator is not watching; this was presented as a potential speed and scale advantage. [3]
This describes AI-assisted selection of predefined actions after deployment, not an assertion that the model providers performed the intrusion. [3]
Also Worth Knowing
AI & Agents · Cyberscoop
What happened
Rep. Josh Gottheimer introduced the AI Cyber Defense Act to establish a CISA test program giving critical-infrastructure operators access to frontier AI models and technical assistance for protecting, detecting, testing, and remediating cybersecurity vulnerabilities. [4]
The proposal frames AI access and technical assistance as an operator-capacity question, not a funding commitment. [4]
AI & Agents · Malwarebytes Labs
What happened
Researchers testing two inexpensive smart-glasses models found more than a dozen flaws across the glasses, companion app, and associated website. [6]
The reported pairing behavior makes ownership-transfer controls a distinct audit boundary for these devices. [6]
AI & Agents · Malwarebytes Labs
What happened
The article reports that Muse can connect to services and receive macOS permissions for protected resources, including files, microphone, camera, location, and calendars. [7]
This is a review of permission boundaries rather than evidence of a remote-entry path. [7]