olivLaw · Threat Intelligence

Cyber Daily

Daily cybersecurity briefing: active vulnerabilities, supply-chain incidents, ransomware trends. Generated daily around 08:00 from primary sources.

Cyber briefing

Friday, 11 September 2026

HIGH2 min

Executive Summary

The reporting period is dominated by the active exploitation of Cisco FMC vulnerabilities by ransomware groups and state-sponsored actors, as well as a massive AI-agent-based campaign that compromised 395 organizations through vulnerable PaperCut servers. On the data front, IDScan confirmed a breach involving 153 million driver's license scans, and ShinyHunters exposed 6.4 million individuals in the attack on McKesson. The "BlueMoon" exploit kit, which uses Windows and Chrome zero-days, raises the overall risk level to HIGH.

Critical Threats

  • Active Cisco FMC exploitation — Two recently patched vulnerabilities in Secure Firewall Management Center are being exploited by three distinct clusters linked to ransomware and state-sponsored attacks. Action: immediately verify FMC versions and apply the patches.
  • AI campaign against PaperCut NG/MF — A likely Russophone actor used hundreds of AI agents to exploit vulnerable PaperCut servers globally, compromising 395 organizations. Action: inventory PaperCut servers and remediate exposed versions.
  • "BlueMoon" exploit kit — Cyber espionage groups used zero-days in Microsoft Windows and Google Chrome. Action: keep browsers and Windows systems fully updated.
  • IDScan breach — 153 million license scans — Massive identity data offered for sale; the company confirmed hackers' access to customer data from the cloud platform. High identity fraud impact.
  • ShinyHunters / McKesson — 6.4 million individuals affected in the attack on the healthcare provider; continued extortion of the healthcare sector.

Vulnerabilities & Patches

Windows Defender zero-days published by the researcher "Nightmare-Eclipse" ("ShieldCrash" exploit). Cisco FMC vulnerabilities actively exploited — patches available, urgent application required. PaperCut NG/MF flaws remain priority targets. Operational warning: the September 2026 Windows Server updates break Remote Desktop Services on Server 2019/2022/2025, and KB5002914 breaks copy-paste in Excel — test patches before deployment.

Trends & Observations

AI automation is becoming an offensive tool (the PaperCut AI-agent campaign). Extortion via phone voices and abuse of BYOD/Microsoft Graph API targets Microsoft 365 access. Android malware is evolving: GoldFactory (banking app cloning) and Mantax Otax (ransomware + spyware + harassment). Abuse of the Google Play Early Access program allows bypassing reviews. The healthcare and financial sectors are preferred targets; cyber fraud losses reported by the US Treasury exceed USD 13 billion since 2023.

Recommendations

  • Patch exposed Cisco FMC and PaperCut servers immediately; verify the associated indicators of compromise.
  • Test the September 2026 Windows Server updates in staging environments before deployment (RDS risk).
  • Implement MFA and identity monitoring — nearly half of confirmed malicious activity targets identities.
  • Educate users about vishing attacks that exploit BYOD and Microsoft 365 access.
  • Verify whether the organization is affected by the IDScan breach and intensify anti-fraud controls.
articles
50
sources
12
critical
1
high
1

Top threats

  • CISA: WatchGuard RCE flaw now exploited in ransomware attacks
  • New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
  • Critical NetScaler Vulnerability Exploited in Attacks
  • CISA Adds Two Known Exploited Vulnerabilities to Catalog
  • New Android malware encrypts files, steals data, and harasses victims

Archive