Clear Infosec Threat Intelligence Bulletin – Sep 23rd, 2026

Cyber Security News

Threat Actor Generates 1M Personalized Fraud Emails in 3 Days

Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI. Read more

Chinas FamousSparrow APT Spies on US Politics in Latin America

Amid the US and China’s fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight. Read more

Microsoft Issues Emergency Fixes After Massive Patch Tuesday

You can’t make an omelet without breaking a few eggs, and you can’t patch nearly 1,000 CVEs without a few glitches. Read more

Attackers Pounce on Critical Artifactory Bug Following Disclosure

CVE-2026-82329 is an authentication bypass flaw in JFrog’s repository manager that enables bad actors to gain admin-level access on affected systems. Read more

Cybercriminals Are Hiding New Malware in Torrents for Popular Films

Victims have been identified in Africa, including in Kenya and Uganda. Read more

Best Practices

Attackers use passkey-themed scams to hijack Microsoft 365 accounts

Attackers are using passkey-themed social engineering to trick employees into giving them access to their Microsoft accounts. Microsof… Read more

GhostCode attackers abuse device codes to take over Microsoft 365 accounts

Microsoft 365 users are being tricked into handing over access to their accounts by a new phishing kit, GhostCode, that exploits a weakne… Read more

Cisco patches max-severity ISE flaw the second critical zero-day this week

Cisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform… Read more

Hundreds of OpenAI agents attack RubyGems platform

A swarm of hundreds of OpenAI agents uploaded “malicious packages” to RubyGems and tried to steal API keys, the Ruby community gem hostin… Read more

Critical Cisco Secure Email Gateway zero-day gives attackers root access

Cisco released emergency patches for a critical vulnerability in its Secure Email Gateway appliance that could allow attackers to take ov… Read more

New Threats and Vulnerabilities

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerab… Read more

Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 100) Exploited in Active Attacks

Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability,… Read more

Attacker Hijacks AI Coding Assistant Session Spreads Shai-Hulud Across About 100 Repositories

Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud acro… Read more

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs… Read more

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through … Read more

Patch Management

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severi… Read more

Attacker Hijacks AI Coding Assistant Session Spreads Shai-Hulud Across About 100 Repositories

Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud acro… Read more

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. Th… Read more

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam mess… Read more

Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 46

Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a … Read more

AI and Security

Hundreds of AI agents helped PaperCut attacker hit 395+ orgs and some went off script

An unknown attacker used hundreds of AI agents to exploit two PaperCut MF/NG bugs and break into at least 395 organizations. The victims were concentrated in t… Read more

OpenAIs website-hijacking swarm reached far further than we thought

Getting straight answers out of OpenAI about how many websites and services its agents have hijacked increasingly seems like pulling teeth, as the company seem… Read more

AI uprising postponed after Copilot falls off the web

Fears of an AI takeover remain unfounded after Microsoft demonstrated that Copilot can sometimes struggle to remain upright, let alone march over the remnants … Read more