CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
2026-09-18T02:51:33Z•eb7207c00b8e26e38307e36afe0a766ca483971549d5a73b059ff12f2c0b99fb
CVE-2026-85706AI securityAI-enabled attacksAPTAndroid malwareCISAChina-linked threat actorsClickFixCyclops BlinkGigabudGraph APILinux espionage toolkitMicrosoft 365North KoreaSandwormVectraRATagentic AIbrowser securitybusiness email compromisecybersecurity newsfraudmalware-as-a-servicephishingsocial engineeringstate-sponsored threatsvulnerability management
What happened
Dark Reading feed covering September 2026 cybersecurity developments, including state-sponsored espionage, malware-as-a-service, phishing and fraud campaigns, AI-enabled attacks, major vulnerability disclosures, and regulatory changes. Notable items include critical GitLab path traversal CVE-2026-85706, active exploitation reported in Microsoft's September Patch Tuesday release, Sandworm exploitation of Cisco vulnerabilities to deploy Cyclops Blink, and attacks targeting Microsoft 365, Android banking users, browser-based AI agents, and enterprise supply chains.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- eb7207c00b8e26e38307e36afe0a766ca483971549d5a73b059ff12f2c0b99fb
- Enrichment time
- 2026-09-18T02:51:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.