WEEKLY TOP TEN: September 14, 2026, 16:00 GMT
- Dutch Agency Warns Of Imminent Check Point VPN Attacks
The Dutch National Cyber Security Centrum issued an urgent warning that two critical flaws in Check Point VPN, tracked as CVE-2026-85102 and CVE-2026-85103, are likely to be exploited imminently. The vulnerabilities could allow remote code execution against affected appliances. No public proof-of-concept has surfaced yet, but the agency assessed the probability of near-term exploitation as high given the severity and the history of VPN gateways being targeted by ransomware and espionage actors alike. Organizations running Check Point VPN were urged to apply vendor patches immediately rather than wait for confirmed in-the-wild activity, since edge devices of this type have repeatedly served as initial access points in major intrusions. - CISA Adds Cisco, Citrix, MikroTik Flaws To KEV Catalog
CISA made a string of additions to its Known Exploited Vulnerabilities catalog this week, including a maximum-severity Cisco Secure Firewall Management Center authentication bypass, a Citrix NetScaler ADC and Gateway authentication bypass exploited since early September, a Fortinet heap-based buffer overflow tied to a Node.js remote access trojan campaign, and two MikroTik RouterOS flaws. Earlier in the week the agency also added Adobe Commerce and Magento, Microsoft Windows, and N-able N-central vulnerabilities based on confirmed active exploitation. Federal civilian agencies faced patch deadlines as tight as September 12 for the Cisco, Citrix, and Fortinet flaws given evidence of ongoing attacks. - Threat Actors Turn Trusted AI Platforms Into Attack Surface
Huntress detailed how threat actors are abusing trusted AI platforms, including weaponized Claude Artifacts, shared AI conversation links, sponsored search results, and ClickFix-style lures, to host malicious content and trick users into installing malware. The research found that attackers are exploiting the inherent trust users place in mainstream AI tools to poison search results and distribute payloads that bypass conventional web filtering. Huntress noted that campaigns targeting AI platform users are increasing as adoption grows across both consumer and enterprise environments. The findings add to mounting evidence that AI products themselves are becoming a distribution vector for cybercrime. - AI-Generated Fraud Emails Impersonate ServiceNow At Scale
Microsoft tracked a campaign in which a threat actor used AI to generate and send more than one million personalized phishing emails in roughly 48 hours, impersonating ServiceNow with fake invoices and forged executive email threads. The emails targeted IT, consumer goods, and real estate companies, with 87.7 percent of recipients based in the United States, attempting to trick accounts payable staff into paying fraudulent invoices. Researchers said the campaign demonstrates how AI is industrializing existing fraud techniques like business email compromise rather than introducing entirely new attack types, making volume and personalization far cheaper for attackers to achieve simultaneously. - BigBear Phishing Kit Bypassed MFA At 258 Organizations
Researchers at CloudSEK gained administrator access to the control panel of a phishing-as-a-service framework called BigBear 2.0 and found it had bypassed multi-factor authentication at 258 organizations, stealing more than 5,000 Microsoft 365 credentials. The service uses an Evilginx2-based adversary-in-the-middle proxy to intercept passwords and session cookies, and custom JavaScript that disables FIDO2 and WebAuthn support to force victims toward weaker authentication methods. Geo-matched residential proxies spanning 69 countries helped the operation evade Microsoft’s location-based fraud detection. CloudSEK reported its findings to law enforcement and affected organizations as part of a responsible disclosure process. - F5 BIG-IP Malware Hides Web Shell In Apache Memory
Researchers at Sophos discovered Linux malware targeting F5 BIG-IP Access Policy Manager deployments that injects a PHP web shell directly into Apache’s memory space rather than writing it to disk, helping the malware evade traditional file-based detection tools. The technique allows attackers to maintain a persistent, difficult-to-detect foothold on compromised BIG-IP appliances, which are widely deployed at the network edge of large enterprises for load balancing and access control. Because BIG-IP devices sit at a critical chokepoint in many corporate networks, a successful compromise can provide attackers with a durable staging point for further lateral movement and data exfiltration. - Revolut Gave Customer Data To Scammers Posing As Agency
Revolut disclosed that it handed over highly sensitive customer data, including passports, identity verification selfies, IBANs, and Bitcoin transaction records, to scammers who submitted fraudulent requests through what appeared to be a legitimate government agency email domain. The incident stemmed from a failure to adequately verify the authenticity of the requesting party before releasing regulated financial data, a process typically relied upon for legitimate law enforcement and regulatory inquiries. The exposure gives attackers everything needed to attempt account takeover or identity theft against affected customers. Revolut has not disclosed how many customers were impacted by the disclosure. - Fake Misconduct Emails Target Universities With Zoho RAT
Cofense detailed a phishing campaign targeting healthcare-linked universities using fraudulent sexual misconduct allegation emails designed to pressure recipients into clicking through in a panic. The emails direct victims to Google Drive links that ultimately lead to installation of a remote access trojan built on the legitimate Zoho platform, giving attackers persistent access to compromised university systems. The lure’s emotionally charged subject matter is intended to override normal caution around unsolicited attachments and links. Higher education institutions remain frequent targets for this kind of social engineering because of the sensitive research, financial, and personal data housed across decentralized campus IT environments. - Malicious Extensions Steal Crypto Traders Wallet Data
Socket researchers identified malicious Chrome and Firefox extensions designed to steal session data and wallet credentials from cryptocurrency traders. The extensions masqueraded as legitimate trading or porfolio-tracking tools while covertly harvesting browser session tokens and wallet seed information in the background. Once captured, the stolen data can give attackers direct access to victims’ exchange accounts and self-custody wallets, often resulting in irreversible fund theft. The campaign reflects a continuing trend of threat actors targeting cryptocurrency users through browser extension marketplaces, which frequently lack the same level of vetting applied to mobile app stores. - Hackers Abused Claude To Extract Secrets From Android Apps
Anthropic disclosed that multiple threat groups, including financially motivated criminals and state-sponsored espionage clusters linked to Russia and China, attempted to abuse its Claude AI model to extract secrets from roughly 1.8 million Android applications. The attackers reportedly used the model to accelerate reverse engineering and credential-hunting tasks that would otherwise require significant manual effort. Anthropic said it has since strengthened detection and enforcement measures to identify and shut down this kind of misuse. The disclosure adds to a growing body of evidence that AI coding assistants are being weaponized to speed up reconnaissance and vulnerability discovery at scale across mobile app ecosystems.
Our Threat Operations and Intelligence team compiles a daily digest of the most recent online cybersecurity risks. The previous 10 stories were determined to be most significant during the course of the week, ranked by highest risk, and using multiple sources when available.