NCSC and Allies Warn of Iranian Spyware Campaign
2026-09-16T08:52:07Z•e13b8907a19b6e529d86fa3b97f8512baad35652f56dddd597f3ce8687ad9551
CVE-2026-86218AI-securityAndroid-RATIranian-spywareMicrosoft-365OAuth-token-theftPegasusbusiness-email-compromisecredential-theftcritical-vulnerabilitiescybercrimedata-breachextortionidentity-and-access-managementinsider-threatmalicious-packagesmobile-malwarenation-statenon-human-identitiesphishingransomwareshadow-AIsoftware-supply-chainvulnerability-exploitationzero-click-exploitzero-day
What happened
Infosecurity Magazine coverage from September 3–16, 2026 highlights active exploitation of critical vulnerabilities, ransomware and extortion, nation-state spyware, phishing and identity theft, malicious mobile and browser applications, software supply-chain compromise, insider and non-human identity risks, and emerging AI-related security threats. Notable disclosures include Iranian Chosen Brick spyware targeting dissidents, exploitation of maximum-severity GitLab and SAP flaws, a critical N-able RCE (CVE-2026-86218), Pegasus zero-click iPhone compromise, BigBear phishing targeting Microsoft
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- e13b8907a19b6e529d86fa3b97f8512baad35652f56dddd597f3ce8687ad9551
- Enrichment time
- 2026-09-16T08:52:07Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.