THE DAILY BRIEFING

A clearer view of today.

The stories that matter. The context you need.

INDEPENDENT PERSPECTIVEFree to read.
Every day.

Cybersecurity

Your briefing

3 min read

AI-assisted briefingHow we put it together ↗
Active exploitation hits Cisco Secure Firewall Management Center (FMC) (CVE-2026-20079 and CVE-2026-20316)

Multiple reports highlight that threat actors are actively exploiting high-impact Cisco FMC vulnerabilities, including an authentication bypass (CVE-2026-20079) and another flaw (CVE-2026-20316). Cisco and CISA have issued warnings consistent with real-world compromise, including clusters tied to ransomware and nation-state activity. The key takeaway for defenders: prioritize patching and verification on internet-facing management interfaces and scrutinize administrative access paths, not just perimeter devices.

Source: Help Net Security


CISA sets KEV deadline and expands known-exploited list for Cisco, Citrix, and Fortinet

CISA added multiple vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog and issued a September 12 patch deadline for affected federal agencies. The update includes critical/authentication-bypass style issues across major networking vendors, underscoring how attackers continue to target widely deployed management and access-control surfaces. For enterprises, KEV should be treated as a “stop digging—move to patching and validation” directive.

Source: The Hacker News


Microsoft 365 compromise via social engineering calls to employees’ personal phones

A tracked campaign uses calls or texts to employees’ personal numbers, impersonating internal IT staff to extract credentials for Microsoft 365 accounts. Once access is gained, attackers pull data from Microsoft 365 apps, SharePoint, OneDrive, and email—often persisting for weeks. Organizations should tighten out-of-band identity verification for account recovery and implement stronger “caller not on the corporate phone system” controls.

Source: Help Net Security


“ShieldCrash” zero-day targets Microsoft Defender on patched Windows systems

Security reporting describes a new “ShieldCrash” zero-day exploit that targets Microsoft Defender, providing full system privileges on affected Windows machines running September 2026 patches. Even with patching, this illustrates the cat-and-mouse reality for endpoint security: defenders may close one gap while new exploitation techniques emerge against the remaining attack surface. The practical urgency is to confirm you’re covered by the latest vendor guidance and to hunt for post-exploitation indicators in endpoints where protection layers were bypassed.

Source: Security Week


PaperCut NG/MF: AI-powered exploitation scales across hundreds of organizations

Reports tie PaperCut exploitation campaigns to the use of hundreds of AI agents, with attackers rapidly compromising many instances—at times gaining domain admin in minutes. The operational point is sobering: automated exploitation + agentic iteration reduces attacker dwell time and increases the likelihood of widespread scanning and compromise before patch adoption catches up. Defenders should verify PaperCut exposure across all environments (including less-obvious internal deployments) and confirm mitigation steps are actually in effect, not just “patched in theory.”

Source: SCMagazine


Prompt injection “hiding in plain sight” with PuzzleMask-style techniques

A newly disclosed prompt-injection method (“PuzzleMask”) embeds policy-violating payloads inside fluent prose, aiming to bypass LLM gatekeepers designed to detect obvious obfuscation. This shifts the defensive challenge from “spot weird characters” to “assess semantic intent and downstream tool consequences.” The takeaway: strengthen evaluation against injection-by-meaning, add tool-use constraints, and test filters with adversarial, natural-language payloads.

Source: Check Point Blog


AI dev + cybersecurity policy: CISA warns of malicious knowledge distillation campaigns

Beyond traditional malware and vulnerability management, CISA is highlighting AI-specific threat activity, including malicious knowledge distillation campaigns targeting AI companies. The risk is that adversaries can extract capabilities or steer model behavior through training-time attacks or data manipulation—creating downstream security and integrity issues even if classic software vulnerabilities are patched. Organizations using or building AI systems should treat model governance as a security control set, not an afterthought.

Source: AFCEA


You May Also Be Interested In...

Critical NetScaler authentication-bypass flaw exploited in the wild

WordPress adds automated security checks to block risky plugin releases

CISA expands KEV to include Microsoft Windows, N-able N-central, and Adobe flaws

Cybersecurity — September 11, 2026 | Briefing24