View all sources for this day →

The Signal

The strongest operational items pair reported active exploitation with boundary-specific deployment conditions, while the AI material spans post-compromise automation and capacity-focused research rather than a single unified risk category. [1][2][3][4]

Must Know

Exploitation · Cyberscoop

Exploitation · Vulnerability

What happened

Volexity reported that the China-aligned group UTA0565 exploited a three-vulnerability zero-day chain affecting Chrome and Microsoft before the defects were disclosed or patched, during September 3–4. [1]

The chain included CVE-2026-85046 and CVE-2026-87491, remote-code-execution defects in Chromium-based browser JavaScript engines, and CVE-2026-85880, a Windows Advanced Local Procedure Call privilege-escalation zero-day. [1]

Why it matters

Volexity said UTA0565 used multiple fake websites, phishing emails targeting Asian government entities, and spoofed domains impersonating the Center for American Progress and China Digital Times. [1]

The reported chain crosses browser and operating-system boundaries, making the distinction between those layers central to its practitioner relevance. [1]

Identity · The Hacker News

Vulnerability · Exploitation

What happened

Attackers are exploiting CVE-2026-94127, a critical flaw in F5 BIG-IP Access Policy Manager (APM) that can allow unauthenticated code execution on a BIG-IP system, according to F5. [2]

The vulnerability affects only systems where APM operates as an OAuth authorization server issuing access tokens to applications. [2]

Why it matters

The reported condition narrows relevance to a specific authorization role rather than all BIG-IP deployments. [2]

Identity · Helpnetsecurity

Vulnerability · Exploitation

What happened

Check Point released emergency fixes for critical Management Server vulnerability CVE-2026-93616, which had been exploited as early as July 23, 2026. [5]

Check Point confirmed that CVE-2026-85102, a pre-authentication remote-code-execution vulnerability in Check Point Quantum Security Gateway, was probed a few days after patches were released on September 9, 2026. [5]

Why it matters

The two reported cases distinguish exploitation of a management component from post-patch probing of a gateway defect. [5]

AI & Agents · Theregister Security

AI & Agents · Exploitation

What happened

Cisco Talos describes CLOSEDQUORUM as a Windows malware implant that queries up to four LLM providers—Gemini, DeepSeek, Qwen, and Mistral—to select predefined post-compromise actions, including credential and cryptocurrency-wallet theft. [3]

After deployment, CLOSEDQUORUM reportedly operates without continued human commands; Talos calls it, to its knowledge, the first publicly documented Windows implant using this approach for C2. [3]

Why it matters

Talos analyst Ryan Fetterman said transferring an attack phase from a human operator to AI systems can remove a human bottleneck, allowing activity to continue when an operator is not watching; this was presented as a potential speed and scale advantage. [3]

This describes AI-assisted selection of predefined actions after deployment, not an assertion that the model providers performed the intrusion. [3]

Also Worth Knowing

AI & Agents · Cyberscoop

AI & Agents · Policy

What happened

Rep. Josh Gottheimer introduced the AI Cyber Defense Act to establish a CISA test program giving critical-infrastructure operators access to frontier AI models and technical assistance for protecting, detecting, testing, and remediating cybersecurity vulnerabilities. [4]

The proposal frames AI access and technical assistance as an operator-capacity question, not a funding commitment. [4]

AI & Agents · Malwarebytes Labs

AI & Agents · Vulnerability

What happened

Researchers testing two inexpensive smart-glasses models found more than a dozen flaws across the glasses, companion app, and associated website. [6]

The reported pairing behavior makes ownership-transfer controls a distinct audit boundary for these devices. [6]

AI & Agents · Malwarebytes Labs

AI & Agents · Platform

What happened

The article reports that Muse can connect to services and receive macOS permissions for protected resources, including files, microphone, camera, location, and calendars. [7]

This is a review of permission boundaries rather than evidence of a remote-entry path. [7]

Sources (7)
  1. [1] Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects

    cyberscoop · September 22, 2026

  2. [2] F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

    the hacker news · September 23, 2026

  3. [3] Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions

    theregister security · September 22, 2026

  4. [4] After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program

    cyberscoop · September 22, 2026

  5. [5] Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances

    helpnetsecurity · September 23, 2026

  6. [6] Some cheap smart glasses are a security disaster

    malwarebytes labs · September 22, 2026

  7. [7] Meta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor

    malwarebytes labs · September 22, 2026

Security Daily · September 23, 2026 · Baitaphish