September 26, 2026
Why this day matters
- The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active
- OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks. [...]
Enriched source records
Luna-generated claims retained by the evidence and claim-validation gates. Automated validation does not imply human review. A record does not need a CVE to be included.
Luna-enriched source article · the hacker newsKiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
Kiteworks, formerly Accellion, urged customers to shut down their systems for nine hours over a weekend as a precaution after receiving threat intelligence about an imminent cyber attack.
Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
Kiteworks, formerly Accellion, urged customers to shut down their systems for nine hours over a weekend as a precaution after receiving threat intelligence about an imminent cyber attack.
Source published Sep 26, 2026, 7:48 AM UTC · Evidence retrieved Sep 26, 2026, 1:23 PM UTC
What happened
Kiteworks, formerly Accellion, urged customers to shut down their systems for nine hours over a weekend as a precaution after receiving threat intelligence about an imminent cyber attack. [1]
Kiteworks said federal intelligence authorities provided credible threat intelligence indicating that a threat actor may attempt to target some Kiteworks systems. [2]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack.
- [2]
"Kiteworks received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems," said Frank Balonis, Chief
Luna-enriched source article · the hacker newsSharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
CISA added two vulnerabilities affecting Microsoft SharePoint and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation.
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
CISA added two vulnerabilities affecting Microsoft SharePoint and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation.
Source published Sep 26, 2026, 8:49 AM UTC · Evidence retrieved Sep 26, 2026, 1:23 PM UTC
What happened
CISA added two vulnerabilities affecting Microsoft SharePoint and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. [1]
The supplied text identifies CVE-2026-65660 as a CVSS 8.8 code-injection vulnerability in Microsoft Office SharePoint. [2]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
- [2]
The vulnerabilities in question are as follows - CVE-2026-65660 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office SharePoint
Additional source records
Threat and risk signalsElementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
The Hacker News published a source item for review.
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
The Hacker News published a source item for review.
What happened
The Hacker News published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link The Hacker News · Published 2026-09-26T09:55:22Z · Retrieved Sep 26, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsU.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog
Securityaffairs published details for CVE-2026-87902.
U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog
Securityaffairs published details for CVE-2026-87902.
What happened
Securityaffairs published details for CVE-2026-87902.
Why it matters
A reviewed impact interpretation has not been published for this record.
Structured associations
Reviewed next steps
- Check asset inventory and patch status for CVE-2026-87902.
Evidence
- U.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalog Securityaffairs · Published 2026-09-26T07:42:26Z · Retrieved Sep 26, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
AI and model realityOpenAI's AI agents accidentally uploaded user-provided images to third-party sites
Bleepingcomputer published a source item for review.
OpenAI's AI agents accidentally uploaded user-provided images to third-party sites
Bleepingcomputer published a source item for review.
What happened
Bleepingcomputer published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- OpenAI's AI agents accidentally uploaded user-provided images to third-party sites Bleepingcomputer · Published 2026-09-26T12:28:41Z · Retrieved Sep 26, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
AI and model realityNew x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
Securityweek published a source item for review.
New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining Securityweek · Published 2026-09-26T12:00:00Z · Retrieved Sep 26, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
AI and model realityOpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure
Securityweek published a source item for review.
OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure Securityweek · Published 2026-09-26T10:15:41Z · Retrieved Sep 26, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.