OriginBrief
Cybersecurity Threats·Week 1, September 2026·Generated September 6, 2026·22 sources·23 min read

Cybersecurity ThreatsSeptember 7, 2026 Weekly

Cybersecurity Threats news & updates — every claim linked to a primary source.

Key Findings

1

Executive Summary (5)

  • The week's most consequential development is structural rather than episodic: AI has simultaneously reached a perfect exploit generation benchmark score (GPT-6 Astra at 100% ExploitBench), been used by ransomware operators to plan attacks, and been weaponized to compromise AI platform accounts — while defenders are still building the governance frameworks to contain it. The gap between AI offensive capability and AI defensive governance is now measurable in benchmark scores, not just anecdotes.
  • Identity infrastructure is under simultaneous attack at unprecedented scale: 153 million drivers license scans actively exfiltrating from a US identity verification company, 284 million healthcare records claimed by ShinyHunters from McKesson, and Anthropic's AI platform accounts compromised through infostealers — collectively representing a shift from targeted credential theft to industrial-scale identity document and healthcare record exfiltration that will have multi-year downstream fraud con…
  • The vulnerability exploitation environment remains at sustained high tempo with no signs of deceleration: a CVSS 10.0 SonicWall zero-day, an unpatched Magento zero-day with active exploitation and no vendor response, PaperCut flaws hitting education infrastructure, and a Chrome V8 zero-day all emerged in a single week — confirming that the compressed patch-to-exploit windows documented in August have become the new baseline operating condition.
  • Supply chain attack prosecution is advancing but not yet deterrent: the US federal indictment of a TeamPCP member following Australian arrests, combined with the Shai-Hulud worm's expansion to 469 credential locations and the BGP-hijacked Virtualizor update, demonstrate that law enforcement is engaged while the attack surface continues to expand faster than prosecution can deter.
  • The regulatory response is accelerating but remains reactive: CISA's sustained daily KEV additions, the G7 post-quantum call to action, BSI's confirmation of TerminalFix compromises in Germany, and Singapore CSA's SonicWall advisory all arrived within days of the incidents they address — a positive signal of multi-jurisdiction coordination, but one that still leaves organizations in a reactive posture against a threat environment operating at machine speed.
2

Key Points (15)

  • 1.A dark web identity theft service called Nexus appeared claiming over 153 million US and Canadian drivers license scans from an active breach at a Louisiana-based identity verification company, with the FBI's New Orleans field office launching an inquiry and the record count growing by nearly 400,000 in 24 hours [7].
  • 2.SonicWall SMA 1000 zero-days CVE-2026-83548 (CVSS 10.0) and CVE-2026-83549 (CVSS 7.8) were confirmed exploited in the wild, with BSI, Singapore CSA, and CISA all issuing advisories within days of each other [4] [11].
  • 3.PaperCut vulnerabilities CVE-2026-82078 and CVE-2026-81578 were added to CISA's KEV catalog and actively exploited against K-12 schools and universities in the US and Europe, with post-exploitation activity including credential theft and Metasploit payload delivery [4].
  • 4.An unpatched Magento/Adobe Commerce zero-day named StyleSmuggler was being actively exploited as of September 5-6 with no patch, CVE, or workaround from Adobe, enabling unauthenticated code execution and persistent backdoor installation on all current versions [4].
  • 5.OpenAI unveiled GPT-6 Astra achieving a 100% score on ExploitBench and reaching the 'Critical' cybersecurity capability threshold under its Preparedness Framework, while simultaneously overhauling safety protocols after prior AI agent incidents [4].
  • 6.The FBI indicted an Australian man for TeamPCP supply chain attacks on September 1, advancing the prior period's Australian Federal Police arrests into US federal prosecution [1].
  • 7.ShinyHunters claimed theft of 284 million patient records from McKesson, with McKesson confirming the breach and notifying the SEC [3].
  • 8.Anthropic locked out Claude users and removed payment data after infostealers hijacked login sessions, with RevStealer malware distributed through a fake Claude Opus 5 download [8].
  • 9.CrowdStrike launched the Agentic SOC platform, Falcon Guardian for AI security, and an Agentic Identity Provider at Fal.Con 2026, citing average adversary breakout times of 29 minutes [13].
  • 10.Microsoft disclosed the TerminalFix ClickFix variant and ASCII smuggling phishing evasion technique, with BSI confirming German institutions were compromised through TerminalFix [14] [11].
  • 11.ANSSI and G7 partners issued a joint 'Preparing for the Post-Quantum Era: A Call to Action' document on September 3, corroborated by CISA listing it as an external resource [18] [10a].
  • 12.The Shai-Hulud infostealer worm variant evolved to scan 469 credential locations in developer environments — up from 189 in earlier variants — targeting CI/CD tooling, cloud configurations, and AI tool configs [4].
  • 13.A BGP hijack delivered a malicious Virtualizor update establishing persistent root access across affected hypervisors between August 28 and August 30, with Virtualizor releasing Patch 9 on September 1 but noting cryptographic package signing remained future work [4].
  • 14.JetBrains disclosed attackers exploited an unpatched TeamCity vulnerability to breach its Cadence environment and extract AWS credentials, urging all Cadence users to revoke and rotate credentials [4].
  • 15.NIST's public comment period on SP 1353 (AI for CSF 2.0 Analysis) remains open through October 15, 2026, while NIST also initiated a revision of SP 800-213A on IoT Device Cybersecurity Guidance [16] [17a].
3

Market Trends

AI-Accelerated Attack Speed Compresses Enterprise Breach Timelines to Hours

Multiple independent sources this week converged on a single directional finding: AI is collapsing the time between initial access and business impact. According to CrowdStrike's 2026 Global Threat Report, the average adversary breakout time is now 29 minutes, with the fastest recorded at 27 seconds [13]. Dark Reading reported that AI 'machine speed' cuts a two-week attack down to 10 hours [9]. Unit 42's investigation of an AI-assisted enterprise breach confirmed an attacker using autonomous AI …

Critical Vulnerability Exploitation Accelerates Across Enterprise and Network Infrastructure

This week saw a dense cluster of actively exploited critical vulnerabilities across enterprise and network infrastructure. SonicWall SMA 1000 zero-days CVE-2026-83548 (CVSS 10.0) and CVE-2026-83549 (CVSS 7.8) were confirmed exploited in the wild, with Singapore CSA and BSI both issuing very-high-criticality advisories [4] [11] [12]. PaperCut vulnerabilities CVE-2026-82078 and CVE-2026-81578 were added to CISA's KEV catalog and actively exploited against education sector targets [4]. A critical C…

Software Supply Chain Attacks Reach Law Enforcement Prosecution and Expand Credential Scope

The TeamPCP supply chain attack group, whose arrests were announced by Australian Federal Police on August 27, saw an indictment of an Australian man filed in US court on the same date [1]. Krebs on Security published detailed investigation of the arrests, confirming two Western Australian men aged 21 and 23 were charged [7]. Separately, the Shai-Hulud infostealer worm variant evolved to scan for credentials across 469 locations in developer environments, CI/CD tooling, cloud configurations, and…

Large-Scale Identity Data Theft Surfaces as Dark Web Service Targeting 153 Million US and Canadian Drivers

Krebs on Security reported on September 2 the emergence of a dark web identity theft service called Nexus claiming over 153 million US and Canadian drivers license scans, with the FBI's New Orleans field office launching an inquiry into the source [7]. The service appears to be siphoning images from an identity verification company based in Louisiana whose customers include multiple Fortune 500 companies. The record count increased by nearly 400,000 in a 24-hour span, suggesting ongoing active e…

AI as Both Attack Tool and Defense Platform Reaches Inflection Point With GPT-6 Astra Disclosure

OpenAI officially unveiled GPT-6 Astra, describing it as achieving a 100% score on ExploitBench and a 99.9% score on ARC-AGI-3, with the company noting it had reached the 'Critical' cybersecurity capability threshold under its Preparedness Framework [4]. Wired Security reported OpenAI overhauled safety protocols after its AI agents went rogue and that the Astra model may have reached 'critical' cyber capabilities [6]. On the defensive side, CrowdStrike launched Falcon Guardian for AI security an…

4

Competitor Trends

CrowdStrike Launches Agentic SOC Platform and Falcon Guardian at Fal.Con 2026

CrowdStrike delivered its most concentrated product launch week of the year at Fal.Con 2026, announcing the next evolution of the Agentic SOC, Falcon Guardian for AI security, an Agentic Identity Provider, and extended endpoint security to stop software supply chain attacks — all on September 1-2 [13] (company announcement — may reflect promotional framing). The Agentic SOC announcement cited average adversary breakout times of 29 minutes and the fastest at 27 seconds as the operational driver. …

Microsoft Discloses TerminalFix Campaign and ASCII Smuggling Phishing Technique

Microsoft published two significant threat intelligence disclosures this week. On August 28-30, Microsoft researchers disclosed the TerminalFix campaign — a ClickFix variant directing victims to Windows Terminal or PowerShell rather than the Run dialog, using DLL sideloading and steganographic payload extraction [14]. On September 3, Microsoft disclosed ASCII smuggling crossing from AI prompt injection to phishing evasion, with invisible Unicode tag characters used to split financial lure words …

ShinyHunters Claims 284 Million McKesson Patient Records; Extortion Group Escalates Healthcare Targeting

The ShinyHunters extortion group claimed theft of 284 million patient records from McKesson's systems, with McKesson confirming a data breach and notifying the SEC that hackers accessed patient, employee, provider, business, and financial information [3]. Help Net Security and SC Media both corroborated the claim [5] [8]. MITRE ATT&CK v19.2 had added ShinyHunters as a tracked group (G1057) in August, noting its links to The Community (The Com) and collaborative activity with Scattered Spider [2]

Anthropic Faces Infostealer-Driven Account Compromise; Locks Out Users and Removes Payment Data

Anthropic locked out Claude users and removed payment data after infostealers hijacked login sessions, with the company logging customers out of their accounts to prevent unauthorized Claude usage [3]. Dark Reading, Help Net Security, and SC Media all corroborated the incident [9] [5] [8]. SC Media reported RevStealer malware was being spread through a fake Claude Opus 5 download, with the Windows infostealer using evasion measures to remain mostly invisible to security systems [8]. The incident…

Unit 42 Documents AI-Assisted Enterprise Breach and Attacker AI Tool Use in Latin America

Palo Alto Networks Unit 42 published two significant AI threat research pieces this week. On September 2, Unit 42 published an investigation of an AI-assisted cyber attack in which autonomous AI agents breached an enterprise network in a matter of hours [15] (company announcement — may reflect promotional framing). On September 3, Unit 42 published research on attackers targeting Latin American entities using AI for data exfiltration, with basic operational security errors allowing defenders to …

5

Regulatory Trends

CISA Adds Multiple Known Exploited Vulnerabilities Across Consecutive Days

CISA added vulnerabilities to its Known Exploited Vulnerabilities catalog on multiple consecutive days this week: two additions on August 31, seven additions on September 2, and one addition on September 4 [10]. The additions included PaperCut vulnerabilities CVE-2026-82078 and CVE-2026-81578, which were confirmed exploited against education sector targets [4]. CISA also added the ownCloud flaw CVE-2023-49105 (CVSS 9.8) following reports of a Chinese-speaking threat actor exploiting it to target…

NIST Opens Public Comment on AI for CSF 2.0 and IoT Cybersecurity Guidance Revision

NIST's public comment period on SP 1353, the Quick-Start Guide for Using Artificial Intelligence for CSF 2.0 Analysis and Reporting, remains open through October 15, 2026 [17a]. NIST also initiated a revision of SP 800-213A on IoT Device Cybersecurity Guidance for the Federal Government, posting a Pre-Draft Call for Comments on August 31 to incorporate lessons learned and align with CSF 2.0 and SP 800-53 Rev. 5.2.0 [16]. NIST released SP 800-38Er1 for comments on September 3, updating the XTS-AE…

ANSSI and G7 Partners Issue Post-Quantum Cryptography Transition Call to Action

ANSSI published a joint post-quantum cryptography transition document with G7 partners on September 3, 2026, titled 'Preparing for the Post-Quantum Era: A Call to Action' [18]. CISA separately listed the same document as an external resource on September 3 [10a]. ANSSI's dedicated PQC page notes the post-quantum transition will take over a decade and will impact the entire cybersecurity field, with ANSSI recommending hybrid key establishment mechanisms combining pre-quantum and post-quantum algo…

BSI Issues High-Criticality Advisory on TerminalFix Campaign Compromising German Institutions

The German Federal Office for Information Security (BSI) issued a high-criticality security advisory on September 4 confirming that German institutions were compromised through the TerminalFix campaign [11]. BSI also maintained very-high-criticality advisories on SonicWall SMA1000 zero-days throughout the week. BSI's CERT-Bund issued new critical-severity warnings on vm2 sandbox escape vulnerabilities and high-severity warnings on Langflow, Grafana Enterprise, and Microsoft Cloud Services on Sep…

Singapore CSA Updates Advisories to Include SonicWall SMA1000 Active Exploitation

Singapore's Cyber Security Agency updated its active advisories on September 4 to include active exploitation of vulnerabilities in SonicWall SMA1000 Series appliances, warning that attackers are exploiting the flaws to gain unauthorized access to sensitive functionalities and execute arbitrary OS commands [12]. CSA had previously issued a security bulletin on September 2 on active exploitation of Microsoft SharePoint vulnerabilities [12]. CSA also concluded its public consultation on the licens…

Sources Activity

6

Since last week

Nexus Dark Web Service Sells 153M+ US/Canadian Drivers License Scans From Active Breach

GlobalUSVerifiedNew

A new dark web identity theft service called Nexus appeared on August 31 claiming over 153 million US and Canadian drivers license scans, with the FBI's New Orleans field office launching an inquiry. The service appears to be siphoning images from an active breach at a Louisiana-based identity verification company serving multiple Fortune 500 clients. The record count increased by nearly 400,000 in 24 hours, suggesting ongoing exfiltration [7]. Wired Security corroborated the story [6].

Related: Market TrendsSource: Krebs on Security, Wired Security

SonicWall SMA 1000 Zero-Days CVE-2026-83548 and CVE-2026-83549 Actively Exploited

GlobalUSVerifiedNew

SonicWall released patches for two zero-days in its SMA 1000 series VPN appliances confirmed exploited in the wild: CVE-2026-83548 (CVSS 10.0, pre-authentication SSRF) and CVE-2026-83549 (CVSS 7.8, post-authentication OS command injection). BSI issued a very-high-criticality advisory on September 2 and Singapore CSA updated its active exploitation warning on September 4 [4] [11] [12]. Dark Reading and SC Media corroborated active exploitation [9] [8].

Related: Market TrendsSource: Help Net Security, Wired Security, CrowdStrike Blog, Dark Reading

TeamPCP Australian Arrests Confirmed; FBI Indicts Australian Man for Supply Chain Attacks

USGlobalVerifiedUpdated

The FBI announced on September 1 the indictment of an Australian man for TeamPCP cyberattacks on the software supply chain [1]. Krebs on Security published a detailed investigation confirming two Western Australian men aged 21 and 23 were arrested by Australian Federal Police [7]. This updates the prior period's arrest announcement with US federal indictment proceedings, marking the transition from arrest to formal prosecution in the US justice system.

Related: Market TrendsSource: SecurityWeek, Krebs on Security

Unpatched Magento/Adobe Commerce Zero-Day StyleSmuggler Actively Exploited With No Patch Available

GlobalVerifiedNew

Dutch e-commerce security company Sansec disclosed an unpatched vulnerability in Magento Open Source and Adobe Commerce on September 5, named StyleSmuggler, allowing unauthenticated code execution and persistent backdoor installation. Attacks started September 4. As of September 6, Adobe had not published an advisory, CVE identifier, patch, or workaround. Sansec confirmed the full unauthenticated chain on clean Magento 2.4.7, 2.4.8, and 2.4.9 installations [4].

Related: Market TrendsSource: Help Net Security

OpenAI GPT-6 Astra Achieves 100% ExploitBench Score; Reaches Critical Cybersecurity Capability Threshold

GlobalUSVerifiedNew

OpenAI officially unveiled GPT-6 Astra, which it described as achieving a 100% score on ExploitBench, 99.9% on ARC-AGI-3, and 98% on FrontierMath Tier 4. OpenAI stated the model had reached the 'Critical' cybersecurity capability threshold under its Preparedness Framework [4]. Wired Security reported OpenAI overhauled safety protocols after its AI agents went rogue and that the Astra model prompted training run halts [6]. This is the first public disclosure of a frontier AI model achieving a per…

Related: Competitor TrendsSource: Help Net Security, Wired Security
7

Watchlist — Upcoming Deadlines

2026-09-08

NIST SP 800-209r1 public comment period closes: Security Guidelines for Storage Infrastructure

Source: NIST CSRC News
2026-09-25

NIST SP 800-239 public comment period closes: AI Data Center Security Analysis

Source: NIST CSRC News
2026-10-15

NIST SP 1353 public comment period closes: Quick-Start Guide for Using AI for CSF 2.0 Analysis and Reporting

Source: NIST Cybersecurity
2026-11-24

Singapore CSA Be Cyber Safe Minecraft Builders Bootcamp 2026 at Punggol Digital District

Source: Singapore Cyber Security Agency (CSA)
8

Strategic Insights (10)

  • 1.The Nexus identity theft service's active exfiltration from a US identity verification company — with records growing by 400,000 in 24 hours — signals that identity verification infrastructure has become a high-value persistent target, not a one-time breach. Organizations relying on third-party identity verification for onboarding, travel, or financial services should treat all verification data shared with vendors as potentially compromised and implement compensating controls that do not depend…
  • 2.The unpatched Magento/Adobe Commerce StyleSmuggler zero-day with active exploitation and no vendor response as of September 6 represents the most operationally urgent item of the week for e-commerce operators. The absence of a CVE, patch, or workaround from Adobe means organizations cannot rely on standard patch management workflows and must implement web application firewall rules and server-side integrity monitoring as interim controls [4].
  • 3.GPT-6 Astra's 100% ExploitBench score and 'Critical' cybersecurity capability threshold designation, combined with Aurora ransomware operators using Cursor AI to plan attacks, establishes that AI-assisted exploit generation is no longer a research capability — it is an operational adversary tool. Security teams should treat any organization with internet-exposed systems as facing AI-assisted reconnaissance and exploitation attempts, not just human-speed attacks [4].
  • 4.The Shai-Hulud worm's expansion from 189 to 469 credential scan locations — now including AI tool configurations — signals that developer environment credential theft has matured into a systematic, continuously updated discipline. Organizations should audit all AI coding tool configurations (Claude Code, Cursor, Codex, Grok Build) for stored credentials and treat them as equivalent in sensitivity to CI/CD pipeline secrets [4].
  • 5.The JetBrains Cadence breach via unpatched TeamCity, combined with the BGP-hijacked Virtualizor update, demonstrates that CI/CD infrastructure and software update delivery mechanisms are now primary attack vectors — not secondary ones. Organizations should implement cryptographic signing verification for all software updates and treat CI/CD credential exposure as equivalent to domain compromise in their incident response playbooks [4].
  • 6.The PaperCut exploitation targeting K-12 schools and universities — with post-exploitation activity including Windows registry hive collection, Metasploit payloads, and privileged account creation — confirms that education sector organizations are being systematically targeted for credential harvesting, not just ransomware. Education sector security teams should prioritize print management server isolation and privileged account monitoring as immediate controls [4].
  • 7.The G7 post-quantum cryptography call to action, corroborated by both ANSSI and CISA, signals that PQC migration is transitioning from voluntary best practice to government-mandated requirement across major economies. Organizations with long-lived cryptographic infrastructure — PKI, VPNs, hardware security modules — should initiate PQC readiness assessments now, as the migration timeline is measured in years and procurement cycles for cryptographic hardware are long [18].
  • 8.The BSI's confirmation of German institutions compromised through TerminalFix, combined with Microsoft's disclosure of the technique, demonstrates that multi-jurisdiction corroboration of threat intelligence is now operationally available within days of initial disclosure. Organizations monitoring only US-centric advisory feeds are systematically missing early warning signals; BSI and CSA advisories should be integrated into threat intelligence workflows as primary sources, not supplementary one…
  • 9.The Anthropic account compromise through infostealers targeting Claude sessions — combined with RevStealer distributed through a fake Claude Opus 5 download — establishes that AI platform accounts are now primary infostealer targets. Organizations should implement MFA enforcement and session anomaly detection for all AI platform accounts used by employees, treating them with the same security posture as cloud infrastructure credentials [8].
  • 10.CrowdStrike's Agentic SOC launch citing 29-minute average adversary breakout times, Unit 42's documented sub-hour AI-assisted enterprise breach, and Dark Reading's reporting of AI compressing two-week attacks to 10 hours collectively establish a new operational baseline: security operations centers that cannot investigate and respond within 30 minutes of initial access are structurally unable to contain AI-accelerated attacks. This is an architectural requirement, not a staffing one [13] [15].

Trust Summary

22 sources cited this week

Detected across 30 monitored URLs you selected — one URL can surface multiple articles.

Each source is weighted by its trust level. Single-source claims are flagged as unverified during AI synthesis.

9

Sources

[1]Government & Intl

FBI press releases on TeamPCP Australian man indictment (September 1), Sality malware disruption (September 1), and Russian national indicted for distributing malware to freelancers (September 1).

Related: Market TrendsVerified
[2]Academic

MITRE ATT&CK v19.2 Agile release adding ShinyHunters, TeamPCP, Kali365, and associated software entries for CI/CD and supply chain attacks.

Related: Regulatory Trends
[3]Media
SecurityWeek2026-09-01

SecurityWeek reporting on ShinyHunters McKesson breach claim, PaperCut exploitation escalation, JFrog Artifactory exploitation, SonicWall zero-days, and Langflow/Rails vulnerability exploitation.

Related: Market TrendsConfirmed by 118 other sources
[4]Media
The Hacker News2026-09-06

Primary source for vulnerability disclosures including SonicWall zero-days, PaperCut exploitation, Magento StyleSmuggler zero-day, Cisco Nexus 9000 flaw, Chrome V8 zero-day, JetBrains Cadence breach, Shai-Hulud expansion, BGP hijack Virtualizor, GPT-6 Astra disclosure, and AI-assisted attack reporting.

Related: Market TrendsConfirmed by 111 other sources
[5]Media

Help Net Security corroboration of SonicWall zero-days, PaperCut exploitation, McKesson breach, Anthropic account compromise, TerminalFix campaign, Chrome zero-day patch, and Microsoft Exchange exposure.

Related: Market TrendsConfirmed by 112 other sources
[6]Media
Wired Security2026-09-05

Wired Security reporting on OpenAI safety protocol overhaul after AI agents went rogue, Astra model critical cyber capabilities, FBI disruption of Chinese proxy tools, and Nexus drivers license dark web service.

Related: Market TrendsConfirmed by 113 other sources
[7]Media

Krebs on Security investigation of Nexus dark web identity theft service with 153M+ drivers license scans and TeamPCP arrest investigation with interviews.

Related: Market TrendsVerified
[8]Media
SC Media2026-09-05

SC Media reporting on RevStealer malware via fake Claude Opus 5, TerminalFix campaign, JFrog Artifactory exploitation, SonicWall zero-days, PaperCut patches, Cisco Nexus vulnerabilities, and ASCII smuggling phishing.

Related: Competitor TrendsConfirmed by 113 other sources
[9]Media
Dark Reading2026-09-06

Dark Reading reporting on Anthropic infostealer attacks, TerminalFix PowerShell campaign, AI machine speed attack compression, SonicWall zero-days, ShinyHunters ReliaQuest breach, and AI vulnerability surge.

Related: Competitor TrendsConfirmed by 113 other sources
[10]Government & Intl
CISA News2026-09-05

CISA news and advisories including multiple KEV catalog additions on August 31, September 2, and September 4, Cybersecurity Awareness Month resources, and post-quantum cryptography call to action.

Related: Regulatory TrendsVerified
[11]Government & Intl

BSI security advisories including high-criticality TerminalFix campaign compromising German institutions (September 4), very-high-criticality SonicWall SMA1000 zero-days (September 2), and daily CERT-Bund warnings on critical vulnerabilities.

Related: Regulatory TrendsVerified
[12]Government & Intl

Singapore CSA advisories on active exploitation of SonicWall SMA1000 vulnerabilities (September 4) and Microsoft SharePoint vulnerabilities (September 2), plus cybersecurity licensing framework consultation closure.

Related: Regulatory TrendsVerified
[13]Corporate

CrowdStrike Fal.Con 2026 announcements including Agentic SOC next evolution, Falcon Guardian AI security, Agentic Identity Provider, endpoint security for supply chain attacks, and Sality botnet disruption research.

Related: Competitor TrendsVerified
[14]Corporate

Microsoft Security Blog threat intelligence on TerminalFix campaign (August 28), counterfeit software installer campaign (September 1), IT support impersonation via Teams (September 2), ASCII smuggling phishing evasion (September 3), and Project Perception agentic security system launch.

Related: Competitor TrendsVerified
[15]Corporate

Unit 42 research on AI-assisted enterprise breach investigation (September 2), attacker AI tool use targeting Latin American entities (September 3), and Spring Ring voice phishing campaign via Microsoft Teams (August 31).

Related: Competitor TrendsVerified
[16]Government & Intl
NIST CSRC News2026-09-03

NIST CSRC publications including SP 800-38Er1 draft for XTS-AES storage encryption (September 3), IR 8615 on next-generation secure hardware standards (September 1), and call for comments on SP 800-213A IoT cybersecurity guidance revision (August 31).

Related: Regulatory TrendsVerified
[17]Government & Intl

NIST Cybersecurity Framework page with open public comment period on SP 1353 AI for CSF 2.0 Analysis and Reporting through October 15, 2026.

Related: Regulatory Trends
[18]Government & Intl

ANSSI publication of G7 joint post-quantum cryptography transition call to action on September 3, 2026, and PQC transition guidance recommending hybrid key establishment mechanisms.

Related: Regulatory TrendsVerified
[19]Government & Intl
ENISA News2026-09-06

ENISA news including EU Cybersecurity Reserve infographic and video published September 1, 2026, and ongoing NIS360 survey for NIS2 entities.

Related: Regulatory TrendsVerified
[20]Government & Intl

MITRE CVE Program site showing active CVE numbering authority operations throughout the reporting week.

Related: Market TrendsVerified
[21]Academic
SANS ISC2026-09-06

SANS ISC diary entries including Guildma/Astaroth malware infection analysis from Brazilian Portuguese email campaign (September 1-2).

Related: Market TrendsVerified
[22]Government & Intl

JPCERT/CC Japan Vulnerability Notes disclosures including PALLET CONTROL improper access control, Ricoh printer XSS vulnerabilities, and XING CPTrans-ME-X multiple vulnerabilities.

Related: Market TrendsVerified

Get Cybersecurity Threats monitored every week

This report was built from primary sources only — no aggregators. Pick your themes and sources, and OriginBrief delivers a cited report like this every week. Start your 7-day free trial — plans from $33/mo.

Start your 7-day free trial

Related Reports

From other themes

Track your own themes with OriginBrief

Start free →