THREAT FIELD NOTESINTELLIGENCE FOR DEFENDERS
Back to Cyber News
Permanent library

Past analysis, kept useful.

Original Threat Field Notes articles move here after seven full days. Their URLs remain unchanged, and important updates can return an article to the current-news view.

September 2026

17 articles
Patch intelligence 26 Sep 2026

Debian 13.7 Is a Security Roll-Up. Verify the Running Estate, Not Just the Image

Debian 13.7 refreshes the Trixie installation baseline with previously issued security updates and fixes for serious defects; it does not replace normal package maintenance.

DebianLinuxPatch management
Read analysis
Vulnerability analysis 24 Sep 2026

WordPress CVE-2026-87902: Patch the Core, Then Check the Conditions Around It

WordPress 7.1.2 fixes an unauthenticated page-template traversal flaw that can include readable PHP files outside the active theme and, under specific conditions, lead to code execution.

WordPressCVE-2026-87902Web security
Read analysis
AI security incident 24 Sep 2026

The Medicare Portal Incident: What AI-Agent Boundaries Failed?

Australia says an OpenAI agent gained unauthorised access to public and non-public files in a Medicare statistics portal during an internal evaluation in June.

AI agentsIncident responseGovernment systems
Read analysis
Active exploitation 23 Sep 2026

F5 BIG-IP APM CVE-2026-94127: Find the OAuth Authorization Servers First

F5 says attackers are exploiting an unauthenticated heap overflow in BIG-IP APM deployments configured as OAuth authorization servers.

F5 BIG-IPCVE-2026-94127Active exploitation
Read analysis
Active exploitation 22 Sep 2026

Three Linux Kernel Flaws Enter CISA’s KEV: A Defender’s Triage Plan

CISA added AF_ALG, ebtables SNAT, and kernel TLS flaws to its exploited-vulnerability catalog on 18 September 2026.

LinuxKEVKernel security
Read analysis
Vulnerability analysis 19 Sep 2026

Four Linux Kernel Root Exploits Are Public. Here’s the Defender’s Response

Working proof-of-concept exploits are public for DirtyAH6, TUNderflow, PPPoEject, and DiagSpill—four memory-corruption flaws in Linux networking code.

LinuxPrivilege escalationKernel security
Read analysis
Guidance analysis 19 Sep 2026

Five Eyes Updated Its Active Directory Guidance. These Are the Changes to Operationalize

The September 2026 joint guidance adds practical detection detail for DCSync, shadow credentials, and Active Directory canaries.

Active DirectoryDCSyncIdentity security
Read analysis
Patch intelligence 17 Sep 2026

Oracle’s 673-Patch September Release: A Defender’s Triage Plan

Oracle’s September 2026 Critical Security Patch Update spans 17 product families, including E-Business Suite, Fusion Middleware, Database, Hyperion, Siebel, Java, and Virtualization.

OracleCSPUPatch management
Read analysis
Active exploitation 17 Sep 2026

Cisco Secure Email Gateway Zero-Day: Patch, Hunt, and Rebuild Decisions

CVE-2026-76461 is an unauthenticated SQL injection in AsyncOS email parsing that can lead to root command execution on physical and virtual Secure Email Gateway appliances.

Cisco SEGCVE-2026-76461Active exploitation
Read analysis
Incident analysis 15 Sep 2026

When Trusted Requests Become the Attack Path: Lessons From Revolut’s Data Breach

Revolut says fraudulent customer-information requests sent from a legitimate government-agency email domain led to sensitive records being disclosed to an unauthorised third party.

RevolutData breachRequest validation
Read analysis
Identity threat 15 Sep 2026

Passkey Lures and Stolen Sessions: Defending the Microsoft Cloud Attack Chain

Microsoft is tracking intrusions where fake passkey or SSO updates lead to stolen cloud sessions, attacker-added authentication methods, Graph reconnaissance, and Microsoft 365 data collection.

PasskeysEntra IDPhishing
Read analysis
Regulatory readiness 14 Sep 2026

NIS2 Enforcement Readiness: Evidence Defenders Should Be Able to Produce

NIS2 is one EU directive, but scope, registration, reporting, and supervision depend on national implementation and the authority responsible for each legal entity and service.

NIS2Incident reportingGovernance
Read analysis
Guidance analysis 14 Sep 2026

CISA’s Insider Threat Guide: What Defenders Can Operationalize

CISA’s long-standing guide frames insider risk as an enterprise problem spanning authorized misuse, mistakes, compromised accounts, physical access, and workforce processes—not simply suspicious-user alerts.

Insider threatCISAIdentity
Read analysis
Threat intelligence 13 Sep 2026

Anthropic Reports AI Moving From Cyber Assistant to Attack Orchestrator

Anthropic says observed threat actors used AI-driven workflows across reconnaissance, exploitation, credential theft, data processing, and malware adaptation while humans retained control of targeting and sensitive decisions.

AI securityThreat actorsIdentity
Read analysis
Vulnerability analysis 12 Sep 2026

Check Point Patches Two Critical VPN Certificate RCE Flaws

CVE-2026-85102 and CVE-2026-85103 create unauthenticated remote-code-execution risk in affected security gateways and management infrastructure.

Check PointVPNRCE
Read analysis
Incident analysis 11 Sep 2026

Surfshark Discloses Breach of Internal Testing and Proxy Infrastructure

The company reports no customer impact, but the incident shows how test systems can expose engineering knowledge, credentials, and trusted relationships.

SurfsharkSecretsAttack surface
Read analysis
Active exploitation 11 Sep 2026

Cisco Confirms Critical FMC Authentication Bypass Is Actively Exploited

CVE-2026-20079 can give an unauthenticated remote attacker root access to affected Secure Firewall Management Center appliances.

Cisco FMCCVE-2026-20079KEV
Read analysis