FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

Microsoft 2026 Digital Defense Report: AI Weaponization Accelerates Offensive Capabilities

The 2026 Microsoft Digital Defense Report details a fundamental shift in the cyber threat landscape as generative AI and Large Language Models (LLMs) accelerate offensive operations. Threat actors are leveraging LLM-driven static analysis for automated zero-day discovery, utilizing automated mutation engines for polymorphic malware generation, and deploying AI-orchestrated credential stuffing bots capable of bypassing adaptive MFA. This weaponization has compressed the average exploit window from 4.2 days to just 8.3 hours. The report emphasizes that the compression of attack timelines necessitates an immediate transition toward AI-driven detection, automated response via SOAR, and identity-centric Zero Trust architectures to mitigate the increasing volume of automated, high-velocity intrusions.

Agentic AI Exploit of Zero-Day Flaws in Zammad Ticketing System

On September 21, 2026 an autonomous LLM‑driven agent probed publicly exposed Zammad instances, discovered two previously unknown zero‑day flaws (CVE‑2026‑XXXX session‑token hijacking via insecure REST API handling and CVE‑2026‑YYYY remote code execution through deserialization of ticket‑attachment data), chained them to hijack an admin session, achieve RCE, leverage a misconfigured sudo rule to obtain root, exfiltrate ~12 GB of data, and pivot to internal CI/CD and wiki services before detection. The attack demonstrates how agentic AI can accelerate exploit development to sub‑two‑minute compromise timelines.

CVE-2026-93616: Critical Unauthenticated RCE in Check Point Management Server

In September 2026, Check Point disclosed CVE-2026-93616, a critical unauthenticated remote code execution flaw affecting Security Management Server and Log Server versions R80.30 through R80.40 prior to hotfix CP‑HF‑2026‑09‑15. The vulnerability, scored CVSS v3.1 9.8, stems from insufficient input validation in the web‑based management interface’s file upload endpoint (/msa/upload.php), allowing an attacker to embed directory‑traversal sequences (e.g., \"../\") in the filename parameter, write arbitrary scripts outside the intended directory, and execute them with root privileges. Active exploitation has been observed in targeted attacks against high‑value enterprises, prompting emergency patches via LivePatch and advisories from Check Point, CISA, and multiple threat‑intel feeds.

Graphalgo Campaign Targets HashiCorp Terraform Registry via Malicious Go-Based Providers

The Graphalgo campaign involves the distribution of malicious Go modules and Terraform providers via the HashiCorp Terraform Registry. Threat actors, attributed to a DPRK-linked group, utilize fake job application lures to induce the initialization of compromised providers such as gocommunity-io/dockerd and kreuzwenker/terraform-provider-vault. These modules execute obfuscated init routines and goroutines to deploy a Go-compiled Remote Access Trojan (RAT) and establish reverse TCP shells. The campaign has affected over 120 organizations through 379 observed downloads, facilitating credential theft, persistence via cron, and lateral movement within CI/CD pipelines.

MI5 Designates CGTRI as MSS Front Organization in Academic Influence Campaign

MI5 has formally designated the China Global Talent Recruitment Initiative (CGTRI) as a front organization for the Chinese Ministry of State Security (MSS). The campaign exploits academic openness within the UK higher education sector to facilitate intelligence collection through research grants, joint AI projects, and talent recruitment programs. By embedding MSS interests within legitimate scientific collaborations, the actor aims to exfiltrate dual-use technological data, including proprietary algorithms and machine learning research. Over 100 UK academics have been identified as unwitting participants in these efforts, necessitating immediate institutional reviews and the severance of all CGTRI-affiliated research ties to protect UK national security and technological sovereignty.

Linux Kernel ARM64 KVM VHE Flaw Enables Guest Host Memory Read/Write

A race condition in the ARM64 KVM virtualization host extensions (VHE) path allows a guest VM to retain access to freed host memory when nested virtualization is enabled, leading to arbitrary host kernel memory read/write. The flaw, tracked as CVE-2026-89775 (CVSS 9.8), can be chained via the ITScape exploit to achieve full guest‑to‑host escape and root‑level code execution on the host. Affected systems include any Linux kernel on ARM64 with KVM VHE and nested virt enabled, notably RHEL 8.4 EUS and its derivatives. Immediate mitigation requires applying the upstream kernel patch or disabling nested virtualization.

ShinyHunters Hacker 'Rey' Detained in Jordan Following FBI Recruitment Portal Breach

Jordanian authorities detained Saif Khader ('Rey'), a core ShinyHunters member, following an FBI recruitment system breach. Attackers leveraged phishing lures via fbi-recruit.gov/login-verify and a custom SQL injection payload (UNION SELECT NULL,username,password FROM users) to exfiltrate applicant data. Post-exploitation utilized Cobalt Strike beacons (updateservice.cloud, statsapi.net) and Mimikatz for credential harvesting. The incident compromised PII for approximately 12,000 applicants, including clearance levels, necessitating multi-million dollar remediation. Khader is reportedly cooperating with the FBI to dismantle ShinyHunters' infrastructure.

Microsoft Azure AI Foundry CVSS 10.0 Authentication Bypass CVE-2026-85889 and Windows Zero-Day Exploitation

During Microsoft's September 2026 Patch Tuesday, a critical CVSS 10.0 authentication bypass (CVE-2026-85889) was disclosed in the Azure AI Foundry internal management API. This vulnerability allowed unauthenticated network attackers to invoke privileged functions, enabling immediate administrator role escalation. A subsequent chain of five vulnerabilities (CVE-2026-85890 through CVE-2026-85894) facilitated cross-tenant access, session hijacking, and arbitrary code execution within the Foundry sandbox. Concurrently, two Windows zero-day vulnerabilities in win32k.sys (CWE-416) and spoolsv.exe (CWE-120) were observed being actively exploited in the wild for approximately 72 hours before out-of-band patches were released. While the Azure vulnerability was mitigated server-side, immediate client-side patching is required for all Windows systems to prevent kernel-mode exploitation.

Warlock Ransomware Exploits Microsoft SharePoint Vulnerabilities

The Warlock ransomware group is conducting targeted campaigns against critical infrastructure sectors, including energy, water, and healthcare, by exploiting unpatched Microsoft SharePoint vulnerabilities. Attackers utilize CVE-2023-29357 for unauthenticated remote code execution (RCE) and CVE-2022-24521 for privilege escalation. Following initial access, the threat actor deploys webshells for persistence and utilizes living-off-the-land binaries like certutil and bitsadmin for lateral movement. The campaign employs AES-256 and RSA-4096 hybrid encryption coupled with double extortion via data exfiltration to leak sites. Immediate application of SharePoint Cumulative Updates is required to mitigate these high-impact exploitation vectors.

Critical Fortinet FortiMail Zero-Day: CVE-2026-104286 Enables Unauthenticated Arbitrary File Writes

In October 2026, CISA added CVE-2026-104286 to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation targeting Fortinet FortiMail email security gateways. This CVSS 9.8 vulnerability arises from the intersection of improper pathname limitation (CWE-22) and improper neutralization of null bytes (CWE-158) within the web management interface. Unauthenticated attackers can leverage crafted HTTP requests containing path traversal sequences and null bytes to bypass directory restrictions, allowing arbitrary file writes outside the intended web root. This flaw enables remote code execution (RCE) through webshell deployment, potential credential theft from mailboxes, and subsequent lateral movement within corporate networks.


LINK COPIED TO CLIPBOARD