skip to content

the daily brief

Cyber / Brief — 10 Sep 2026

The week's sharpest threat was state espionage industrialised: researchers found at least four China-linked groups — among them the veteran APT31 — rapidly adopting a shared "BlueMoon" toolkit that chains weaknesses in Chrome and Windows to plant backdoors on fully-updated machines at…

The week's sharpest threat was state espionage industrialised: researchers found at least four China-linked groups — among them the veteran APT31 — rapidly adopting a shared "BlueMoon" toolkit that chains weaknesses in Chrome and Windows to plant backdoors on fully-updated machines at government, defence and commercial targets worldwide, days after the underlying holes came to light. The extortion crews, meanwhile, tore through American healthcare: ShinyHunters began publishing data from the distribution giant McKesson and was blamed for a 4.1-million-person breach at the home-medical provider AdaptHealth, part of a run of intrusions that began, as so many now do, with a single manipulated employee or contractor. Washington answered on the criminal-infrastructure front, sanctioning and disrupting Xinbi Guarantee — a Chinese-language marketplace that had moved tens of billions of dollars for scam syndicates — and freezing $52 million in crypto, even as attackers kept hammering the gateways and VPNs that guard corporate networks. And the AI thread ran through all of it: Anthropic disclosed a fourth case of its own Claude being turned to crime, Europe's Cyber Resilience Act moved toward hard breach-reporting duties, and researchers found that nearly one in ten exposed gateways fronting companies' AI models still accepted the vendor's own example password.

Top Stories


AI & Power

Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6The Hacker News
Why it matters: Anthropic disclosing a fourth case of its own Claude being turned to crime — this time Claude Opus 4.6 — is the safety-first lab repeatedly catching its models in real-world misuse, a running tally that makes the abstract fear of AI-enabled attack concrete and recurring.
Anthropic disclosed a fourth incident of its AI being used in a cyber/criminal operation, this one involving Claude Opus 4.6, continuing the lab's pattern of publicly reporting cases where its models were turned to harmful ends. The disclosures matter because Anthropic — the frontier lab most identified with safety — keeps finding its own models misused in real-world attacks and abuse, a running record that substantiates, from the source, the fortnight's broader evidence that capable AI is now a practical tool for criminals and state actors alike (the PaperCut 'Agents Gone Wild' campaign, the autonomous credential-theft frameworks, the China-distillation advisory). It also raises the question of scale and detection: if Anthropic is catching and disclosing a fourth incident, how many go unseen across the labs that disclose less. For European regulators under the AI Act's systemic-risk and incident-reporting provisions, the steady cadence of lab-disclosed misuse incidents is exactly the data the framework needs — and a reminder that transparency about AI harms is uneven across vendors, making mandatory, consistent incident reporting a live governance priority.

Mythos Vulnerability Firehose Hits a Human Bottleneckdarkreading
Why it matters: The 'Mythos vulnerability firehose' overwhelming human reviewers captures the paradox of AI-for-defence: a model that finds flaws faster than any team can triage them is only as useful as the humans left to sort the flood, and the bottleneck has moved from discovery to judgment.
An analysis describes how Anthropic's Mythos model, turned to vulnerability discovery, produces findings faster than human reviewers can triage them — a 'firehose' that hits a human bottleneck. The observation matters because it captures the double-edged reality of AI-for-security: frontier models can now find vulnerabilities at machine scale (a genuine defensive boon, and the flip side of their offensive capability), but the output overwhelms the human capacity to validate, prioritise and act on it, shifting the constraint from discovery to judgment and response. It is the defensive mirror of the week's offensive-AI story (AI compressing exploit timelines, autonomous-attack frameworks): the same capability that lets attackers move at machine speed lets defenders find flaws at machine speed, but only if they can process the results. For European organisations weighing AI-augmented security, it is a caution that deploying AI to find problems is not enough — the workflow, automation and human expertise to triage and remediate at matching speed are what turn a vulnerability firehose into actual security, and without them AI-for-defence risks drowning teams rather than protecting them.

Russia’s AI Blueprint Exposes an Authoritarian PlaybookThe Cipher Brief
Why it matters: A look at Russia's AI blueprint as an 'authoritarian playbook' is the geopolitics of AI laid bare — a reminder that how a state builds and wields AI reflects its values, and that the authoritarian model (surveillance, control, propaganda) is a competing vision to the democratic one.
A Cipher Brief analysis argues that Russia's AI blueprint exposes an authoritarian playbook — a vision for AI oriented around state control, surveillance, censorship, propaganda and military-and-security application rather than open innovation or individual empowerment. The framing matters because AI is not a neutral technology: the way a state designs, governs and deploys it encodes political values, and the authoritarian model (China's and Russia's) pursues AI as an instrument of control and power projection, in contrast to (if imperfectly) the democratic world's. Understanding Russia's approach is important for anticipating how it will use AI in information operations, cyber, surveillance and warfare, and for the broader contest over which model of AI governance and deployment shapes the global norm. It connects to the week's state-AI threads (the China-distillation advisory, AI in cyber and influence operations) and to the strategic reality that the AI competition is as much about values and governance models as about raw capability — a contest in which Europe, with its rights-based approach, is trying to offer a third way distinct from both American commercial dominance and authoritarian state control.

AIs Compress Exploit TimelineSchneier on Security
Why it matters: The blunt framing that 'AIs compress the exploit timeline' names the single most consequential security effect of the technology — collapsing the days or weeks defenders once had between a flaw's disclosure and its weaponisation into hours, and stripping away the time defence depends on.
A Schneier commentary distils a core security consequence of AI: it compresses the exploit timeline, shrinking the interval between a vulnerability's disclosure and the availability of a working exploit from the days or weeks defenders historically relied on to a matter of hours. The point matters because so much of defensive practice assumes time — time to assess, prioritise, test and deploy fixes before attackers can weaponise a flaw — and AI that can rapidly understand a vulnerability and generate an exploit erases that buffer, a shift the fortnight's evidence (AI-built malware, autonomous-attack frameworks, the 'machine speed' intrusions) repeatedly confirms. It reframes the defender's challenge: the window to respond to new vulnerabilities is collapsing, which demands faster, more automated detection-and-remediation and a shift from periodic patching to continuous, rapid response. For European organisations and the NIS2-era emphasis on timely remediation, the compression of the exploit timeline is a structural change that makes speed of response — not just diligence — the decisive defensive variable, and a reminder that AI reshapes the tempo of security for attacker and defender alike.


EU & Technology

EU Cyber Resilience Act to Enforce New Reporting Requirementsdarkreading
Why it matters: The EU Cyber Resilience Act moving to enforce hard breach-and-vulnerability reporting duties is the bloc's landmark product-security law reaching its teeth — obliging the makers of connected products to disclose exploited flaws and incidents, with real consequences for a vast swath of the technology market.
The EU Cyber Resilience Act (CRA) is moving to enforce new reporting requirements, obliging manufacturers of products with digital elements to report actively-exploited vulnerabilities and severe incidents to authorities within tight deadlines. The development matters because the CRA is one of the world's most consequential product-security regulations — imposing security-by-design, vulnerability-handling and disclosure obligations across essentially all connected hardware and software sold in the EU — and the activation of its reporting duties is where the law begins to bite, forcing transparency about exploited flaws and incidents that vendors have often preferred to keep quiet. It reshapes the incentives of the entire technology supply chain serving the European market, and its reporting regime (echoed in the week's 'what shipped, and when did you know?' framing) will generate valuable threat intelligence while raising hard questions about disclosure timing, coordination and burden. For the security of European digital products and the global vendors who must comply to sell into the bloc, the CRA's enforcement is a major regulatory milestone — Europe using market access to raise the security baseline of connected technology worldwide, much as the GDPR reshaped data protection.

How ‘Made in Israel’ is powering European securityCybersecurity and Data Protection – POLITICO
Why it matters: A close look at how 'Made in Israel' technology is powering European security is the continent's uncomfortable dependence made visible — Europe leaning on Israeli air-defence, cyber and surveillance capability even as it professes strategic autonomy, a reliance with political as well as technological stakes.
A POLITICO analysis examines how Israeli technology — in air defence, cyber, drones and surveillance — is increasingly powering European security, as the continent rearms and turns to proven systems from a leading defence-tech exporter. The dependence matters because Europe's push for strategic and technological autonomy sits uneasily with its reliance on foreign (American and now prominently Israeli) capability for critical defence needs, and the choice carries political weight given the controversy around Israeli surveillance and spyware (the Pegasus affair, the Serbia-accession friction) and the war in Gaza. It reflects the practical reality that Europe cannot yet supply its own needs across air defence, counter-drone and cyber, and must buy where capability exists — even as it aspires to build sovereign alternatives. For the continent's defence-and-technology-sovereignty agenda, the 'Made in Israel' dependence is a concrete instance of the gap between autonomy aspiration and present capability, and a reminder that sovereignty is built over time and that, in the interim, Europe's security rests partly on suppliers whose politics and practices it does not control.

Digital Sovereignty: What It Is, What It Could BeDeeplinks
Why it matters: A careful attempt to define digital sovereignty — what it actually is, and what it could become — is a useful corrective to a term that has grown into a catch-all, pressing past the slogan toward the concrete choices about infrastructure, control and rights the concept should entail.
An EFF analysis works through what 'digital sovereignty' is and what it could be — interrogating a term that has become central to European (and global) technology policy but risks meaning everything and nothing. The exercise matters because digital sovereignty is invoked to justify a wide range of measures (data localisation, sovereign cloud and AI, local-champion industrial policy, platform regulation), not all of which serve the same ends, and some of which can cut against the openness, interoperability and rights the concept ostensibly protects. Distinguishing genuine sovereignty — meaningful control over critical infrastructure, resistance to coercion, and the protection of citizens' rights — from protectionism, surveillance-enabling localisation or mere rhetoric is essential if the agenda is to strengthen rather than fragment the open internet. For Europe, whose whole technology strategy increasingly rests on the sovereignty frame, the clarity matters: the analysis is a reminder that how digital sovereignty is defined and pursued determines whether it produces a more resilient, rights-respecting digital order or simply a more walled and controlled one, a distinction the continent's policymakers must keep in view as they build on the concept.


US & Technology

FTC rescinds policy requiring health apps to notify customers after a breachCyberScoop
Why it matters: The FTC rescinding its policy that required health apps to notify users after a breach is a rollback of consumer data-protection at exactly the wrong moment — stripping away a disclosure duty for the apps holding intimate health data, as breaches of that data proliferate.
The US Federal Trade Commission rescinded a policy that required health apps to notify customers after a data breach, rolling back a consumer-protection-and-transparency obligation for the many health-and-wellness apps that fall outside HIPAA's coverage. The move matters because these apps hold intimate health data (fitness, fertility, mental health, conditions) yet often sit in a regulatory gap, and the rescinded policy (the Health Breach Notification Rule's expanded interpretation) had extended breach-notification duties to them; removing it reduces the transparency users get when their sensitive health data is exposed. It comes amid a wave of health-sector breaches and an active debate over health-data privacy, and it signals a deregulatory turn in US consumer-data protection. For European observers, the contrast is sharp: the EU is tightening breach-reporting (the CRA, NIS2, GDPR), while the US rescinds a health-app notification duty — a divergence that underscores Europe's comparatively stronger posture on data-breach transparency, and a reminder that the protections users receive when their health data leaks depend heavily on jurisdiction and the shifting politics of regulation.

Lawmakers call on Treasury to sanction hackers-for-hireCyberScoop
Why it matters: US lawmakers pressing Treasury to sanction the hackers-for-hire industry is an attempt to bring financial pressure to bear on the mercenary-hacking market — targeting the commercial operators who sell intrusion and surveillance services to whoever pays.
US lawmakers called on the Treasury Department to impose sanctions on hackers-for-hire, pressing the government to use financial measures against the commercial mercenary-hacking-and-surveillance industry that sells offensive cyber and intrusion services. The call matters because the hackers-for-hire market — spanning mercenary spyware vendors, access brokers and offensive-service providers — has become a significant enabler of espionage, repression and cybercrime, and sanctions are a proven (if partial) tool for raising the cost and constraining the operations of such actors, as prior designations of spyware firms have shown. It reflects growing political will to treat the commercial offensive-cyber industry as a target for state pressure rather than tolerating it as a grey-market inevitability. It connects to the broader effort against mercenary spyware and offensive-cyber services (the UK Supreme Court spyware ruling, the European pushback, prior US sanctions and visa restrictions), and for Europe — home to some such vendors and a frequent target of others' services — the push for Treasury sanctions is a reminder that financial measures are a key lever in the transatlantic effort to rein in the commercial market for hacking and surveillance that threatens rights and security alike.

US Democrats prepare to put AI under a new microscopeCybersecurity and Data Protection – POLITICO
Why it matters: US Democrats preparing to put AI under a new congressional microscope signals the politics of AI oversight sharpening — an opposition gearing up to scrutinise the technology's risks, harms and the companies building it, even amid a broadly deregulatory federal climate.
US congressional Democrats are preparing to intensify scrutiny of AI — through briefings, hearings and oversight efforts (including a Bernie Sanders-hosted AI briefing for senators) — signalling a sharpening of the political debate over the technology's risks and the companies developing it. The development matters because US AI governance has leaned deregulatory at the federal level, and an organised push by the opposition to examine AI's harms (to labour, safety, privacy, competition and security) could shape the policy debate, generate pressure for guardrails, and influence the 2026 political landscape. It reflects the growing salience of AI as a political issue — not only an economic and technological one — and the beginning of a more contested US policy conversation about whether and how to regulate the frontier. It connects to the broader global divergence in AI governance (Europe's AI Act versus the lighter-touch US approach) and to the question of whether the US will develop meaningful AI oversight. For European policymakers and AI companies operating transatlantically, a more active US scrutiny of AI — even from the opposition — is a signal that the American regulatory environment, long the permissive counterpoint to Europe's, may face growing political pressure to change.


Threat Intelligence (CTI)

[P1] Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a WeekThe Hacker News
Why it matters: At least four China-linked espionage groups — among them the veteran APT31 — rapidly adopted a shared 'BlueMoon' exploit kit that chains weaknesses in Chrome and Windows to plant backdoors on fully-updated machines at government, defence and commercial targets worldwide, days after the underlying holes came to light.
Researchers (Proofpoint, with Google's GTIG, Microsoft's MSTIC and Volexity) documented 'BlueMoon,' an exploit kit chaining a Chromium V8 type-confusion flaw (CVE-2026-85046) with a V8 sandbox escape (CVE-2026-87491, identified by Volexity) and a Windows privilege-escalation flaw (CVE-2026-85880 — one of the Windows zero-days exploited in the September Patch Tuesday), achieving remote code execution against fully-updated Chrome users. At least four distinct threat clusters adopted it since late August 2026, the majority China-nexus: TA412 (JungleBamboo/Violet Typhoon/APT31, first on 28 August); UNK_LateNight (China-aligned, targeting US aerospace/defence with fake RFQ emails delivering ShadowPad); UNK_DoubleCheck (a Vietnamese manufacturer, via a compromised Southeast Asian government email, delivering a Rust loader from Cloudflare R2); and UNK_QuietRacket (government, consulting and financial organisations in Indonesia and Singapore). Targets span government, defence and commercial organisations worldwide.
severity high · exploited in the wild · CVE-2026-85046 · EU: NIS2 · actor China-nexus clusters incl. APT31/TA412 (60%), escalation

[P2] ShinyHunters expose 6.4M in attack on medical supplier McKessonwww.theregister.com - Articles
Why it matters: ShinyHunters has begun publishing data from the healthcare-distribution giant McKesson — 6.4 million email addresses already surfaced, against the group's claim of 284 million patient records — a 'pay or leak' extortion of one of the largest companies in American healthcare.
The ShinyHunters extortion group published a corpus of data it attributes to McKesson, a healthcare and pharmaceutical distribution giant, as part of a 'pay or leak' campaign; the published set includes 6.4 million unique email addresses alongside other personal and corporate data. ShinyHunters claims it obtained over 284 million patient records (linked to tens of millions of patients, exact count undetermined) including names, contact information, Social Security numbers, dates of birth, medical record numbers, Medicaid numbers, medication/allergy information and diagnoses. Per an SEC filing, the intrusion was detected on 25 August 2026, roughly 1TB of data was exfiltrated between 21–25 August, and a ransom demand exceeding $55 million was issued. McKesson has confirmed a cyber incident and says the investigation is in its early stages and not yet deemed material.
severity high · exploited in the wild · EU: GDPR, NIS2 · actor ShinyHunters (70%), escalation

[P2] U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in CryptoThe Hacker News
Why it matters: US authorities sanctioned and disrupted Xinbi Guarantee — a Chinese-language marketplace that had moved tens of billions of dollars for scam syndicates, selling stolen data, fake IDs and deepfake tools — seizing its channels and freezing $52 million in crypto in a coordinated blow to the cyber-scam economy.
US authorities took coordinated action against Xinbi Guarantee, a Chinese-language escrow-backed marketplace at the centre of Southeast Asia's cyber-scam economy. OFAC designated Xinbi Guarantee as a significant transnational criminal organisation on 9 September 2026 (alongside tooling developers Anwen Technology, maker of the XinbiPay/NewPay wallet, and SafeW Technology, maker of the SafeW messaging app), while the DOJ seized Telegram channels used to run the service and confiscated cryptocurrency wallets. The Scam Center Strike Force also deployed to Madagascar to help disrupt 13 scam compounds run by Chinese organised-crime syndicates. Roughly $52 million in crypto was restrained in a day (bringing the Strike Force's total to ~$938 million). Xinbi connected scam syndicates with vendors selling stolen data, fake identity documents, deepfake tools and cash-out services, settling primarily in USDT on TRON, with throughput estimated at over $36 billion since around 2022.
severity high · EU: NIS2

[P2] Passkey-themed social engineering leads to identity and cloud compromiseMicrosoft Security Blog
Why it matters: Attackers are exploiting the confusion around passkeys to break into Microsoft 365: posing as IT helpdesk with urgent 'update your passkey' warnings, they steer victims to fake sign-in pages, steal the session, plant their own MFA, and quietly loot the company's cloud files.
Microsoft detailed a campaign, active since May 2026, in which attackers use passkey-themed social engineering to compromise identities and pivot into cloud environments. Victims receive phone calls, SMS or Microsoft Teams messages from someone impersonating the organisation's IT helpdesk, warning they must urgently update a passkey, MFA or SSO setting to avoid losing access, then are directed to a fake Microsoft sign-in page. After capturing credentials via adversary-in-the-middle or device-code authentication flows, attackers establish persistence by adding their own unauthorised MFA methods, then use the Microsoft Graph API to map users, groups, permissions and resources, culminating in high-volume data collection from SharePoint, OneDrive and Exchange using automated tools. Microsoft linked the initial-access ecosystem to actors tracked as Storm-3121 and Storm-3032.
severity high · exploited in the wild · EU: NIS2, GDPR · actor Storm-3121 / Storm-3032 (60%), escalation

[P2] Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin KeyThe Hacker News
Why it matters: Nearly one in ten internet-facing LiteLLM gateways — the proxies companies put in front of their AI models — still accepted the vendor's own example admin password, 'sk-1234,' handing anyone who tried it the keys to every model API key, prompt and connected cloud credential behind the gateway.
Wiz researchers found that 294 of 3,074 internet-facing LiteLLM gateways accepted the documented default administrator key 'sk-1234' — the example admin key in LiteLLM's own setup guide — while a further 191 had no master-key authentication configured at all (nearly one in ten of the scanned gateways exposed). The sk-1234 key is the gateway's administrator credential: anyone holding it can read every model-provider API key stored on the server, inspect prompts and responses, access MCP-connected tools, and abuse unrestricted pass-through endpoints to query cloud instance-metadata services and obtain IAM credentials. Microsoft documented an August case in which attackers ran commands inside a LiteLLM gateway process, read the container's environment for the master key, provider keys and database connection string, then used that string to reach the underlying PostgreSQL database (matching the CVE-2026-42271 and CVE-2026-48710 chain). Upgrading to LiteLLM 1.84.0+ addresses the flaws.
severity high · exploited in the wild · CVE-2026-42271 · EU: NIS2, GDPR


Defence & National Security

Leipzig Sabotage: Why Transport Underpins NATO and Russia’s DefencesRUSI: Latest Commentary
Why it matters: A study of the Leipzig sabotage argues that transport infrastructure underpins both NATO's defences and Russia's — a reminder that the railways, ports and logistics moving troops and materiel are strategic targets, and that Europe's hybrid-war front now runs through its transport arteries.
A RUSI analysis of the Leipzig sabotage incident argues that transport infrastructure underpins the defences of both NATO and Russia, making railways, ports, airports and logistics networks critical strategic assets — and prime targets in the hybrid campaign unfolding across Europe. The framing matters because military logistics depend on civilian transport infrastructure (moving troops, equipment and supplies), so sabotage of that infrastructure is not mere vandalism but an attack on defence capability, and the wave of such incidents (the Leipzig drone attack among them) represents a deliberate targeting of the arteries that would sustain any NATO response. It connects the hybrid-war thread running through the fortnight (the sabotage campaign, the warnings that Europe is failing to deter Russia) to the concrete vulnerability of transport systems, and it underscores that protecting critical transport-and-logistics infrastructure — physically and via its increasingly digital control systems — is a defence priority, not just a civilian-resilience matter. For European security, the recognition that transport underpins military readiness reframes infrastructure protection as central to deterrence and the ability to respond to aggression.

British–German Nuclear Cooperation: Joint Support, Not FinancingRUSI: Latest Commentary
Why it matters: Deepening British-German nuclear cooperation — framed as joint support rather than shared financing — is a notable step in European defence integration at the highest level, two major powers drawing closer on the ultimate guarantor of security as the American umbrella looks less certain.
A RUSI commentary examines emerging British-German nuclear cooperation, framing it as joint support rather than shared financing — a nuanced step in which the two powers coordinate on nuclear deterrence without Germany helping fund the UK's arsenal. The development matters because nuclear deterrence is the ultimate pillar of European security, long underwritten by the US, and as confidence in the American guarantee wavers, European powers are exploring how to strengthen the continent's own deterrent posture — with Britain (and France) as Europe's nuclear states and Germany as its industrial and economic heart. Closer British-German nuclear cooperation, even short of financing or sharing, signals movement toward greater European strategic autonomy in the most consequential domain of defence. It connects to the broader European-security reckoning (the unreliable American ally, the rearmament push, the debates over European deterrence) and to the hard questions of how a continent that has relied on the US nuclear umbrella for eighty years might provide for its own ultimate security. For European defence, steps toward coordinating the continent's nuclear deterrent — however incremental — are strategically weighty markers of the autonomy agenda reaching even the nuclear realm.

UK appoints new commander of National Cyber ForceThe Record from Recorded Future News
Why it matters: The UK naming a new commander of its National Cyber Force is a leadership marker for one of Europe's most capable offensive-and-defensive cyber organisations — a reminder that sovereign cyber power is now a core instrument of national security, with real command structures behind it.
The UK appointed a new commander of its National Cyber Force (NCF), the joint military-and-intelligence organisation responsible for Britain's offensive cyber operations (alongside defensive and influence capabilities). The appointment matters as a marker of the institutionalisation and strategic importance of sovereign cyber power: the NCF is among Europe's most developed offensive-cyber organisations, and its leadership shapes how Britain uses cyber capability against adversaries, criminals and threats to national security. Leadership transitions at such organisations signal continuity and priorities in a domain that has become central to statecraft and defence. It connects to the broader picture of states building and wielding offensive-and-defensive cyber capability as a core national-security instrument (the FBI's new cyber strategy, the US offense-driven mindset, the contest with state cyber actors), and for European allies it is a reminder that cyber power — offensive as well as defensive — is now a recognised element of national defence, organised under formal command and integral to how modern states project and protect power in and through cyberspace.

China’s Challenge to Western AlliancesThe Cipher Brief
Why it matters: An examination of China's challenge to Western alliances captures the strategic contest beneath the technology competition — Beijing's effort to divide, outmaneuver and offer alternatives to the US-led alliance system that has underpinned the Western order, technology very much among its instruments.
A Cipher Brief analysis examines China's multifaceted challenge to Western alliances — the economic, technological, diplomatic and military effort by which Beijing seeks to weaken, divide and offer alternatives to the US-led alliance system (NATO, the Indo-Pacific partnerships) that has structured the Western order. The framing matters because the technology competition the brief tracks (AI, chips, open models, digital infrastructure) is one front of a broader strategic contest in which China uses economic leverage, technology diffusion (the 'united front' of open models, infrastructure diplomacy), and the cultivation of non-aligned states to erode Western cohesion and build its own sphere. Understanding China's alliance-challenging strategy is essential context for the technology-and-security decisions facing the US and Europe — from export controls and supply-chain security to whose digital ecosystem the world adopts. For Europe specifically, caught between its largest trading partner and its primary security guarantor, China's effort to challenge and divide Western alliances is a central strategic dynamic shaping its technology, trade and security choices, and a reminder that the contest over technology is inseparable from the larger geopolitical struggle over the shape of the international order.


Digital Sovereignty & Identity

RAND warns security biometrics, digital ID can become tools for targetingBiometric Update
Why it matters: RAND warning that security biometrics and digital ID can become tools for targeting is the sober counterpoint to the identity-infrastructure boom — a reminder that the same systems built to verify and protect people can, in the wrong hands, be turned into instruments to find and persecute them.
A RAND analysis warns that biometric and digital-identity systems deployed for security can become tools for targeting — that the infrastructure built to verify identity, secure services and protect populations can, if misused or compromised, enable the identification, tracking and persecution of individuals and groups. The warning matters because digital identity and biometrics are being rolled out worldwide at speed (the EU's wallets, national ID schemes, biometric borders, the many programs the brief tracks), often framed purely as enablers of security and convenience, while the dual-use risk — that comprehensive identity systems are also comprehensive targeting systems in the hands of a hostile state or attacker — receives less attention. It connects to the fortnight's identity-and-surveillance threads (the spyware cases, the data-broker tracking, the facial-recognition debates) and to the core tension in identity infrastructure between protection and control. For Europe, building rights-based digital identity while promoting it globally, RAND's caution is a reminder that how these systems are designed, governed and safeguarded determines whether they protect people or expose them — and that the targeting risk must be designed against from the start, especially as the systems spread to contexts with weaker rule-of-law protections.

France expands digital identity access in overseas territoriesBiometric Update
Why it matters: France extending digital-identity access to its overseas territories is the practical, inclusive edge of the identity rollout — ensuring citizens far from the metropole are not left outside the digital-services infrastructure the state is building, a reminder that identity systems must reach everyone to serve their purpose.
France is expanding access to its digital-identity system in its overseas territories, extending the reach of the national identity infrastructure to citizens in regions often underserved by central-state digital services. The development matters as an instance of the inclusion-and-access dimension of digital identity: a national identity system only delivers on its promise (access to services, secure transactions, participation in the digital economy) if it reaches all citizens, including those in geographically distant or less-connected territories, and extending it to overseas territories addresses a real equity gap. It connects to the broader build-out of European digital identity (France's approach within the eIDAS framework, the continent's wallet rollout) and to the practical challenges of deploying identity infrastructure universally. For European digital-identity policy, the extension is a reminder that the success of these systems depends not only on their design and security but on their inclusive reach — that leaving populations outside the identity infrastructure undermines both its utility and its fairness, and that universal access is part of what distinguishes a rights-respecting identity system from one that deepens digital exclusion.


Cybersecurity & Threats

[P1] Critical NetScaler Vulnerability Exploited in AttacksSecurityWeek
Why it matters: Attackers are exploiting a critical authentication-bypass in Citrix NetScaler — the remote-access gateway that fronts thousands of corporate networks — letting an unauthenticated intruder slip past login protections on the very appliance meant to guard the perimeter, with tens of thousands of instances exposed online.
CISA added Citrix NetScaler flaw CVE-2026-19490 (CVSS 9.3) to its Known Exploited Vulnerabilities catalogue after observing in-the-wild attacks. The authentication-bypass affects all NetScaler ADC and NetScaler Gateway appliances configured as a gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or as an AAA virtual server, letting a remote, unauthenticated attacker bypass login protections and reach functionality that normally requires valid credentials. Citrix released fixes on 19 August 2026; exploitation followed a credible public proof-of-concept, with honeypot attack attempts logged from 3 September (56 by 8 September). Over 22,000 NetScaler ADC instances and ~1,700 Gateway instances are internet-reachable. Affected: 14.1 before 14.1-73.32 and 13.1 before 13.1-63.21. As an edge remote-access gateway, a NetScaler compromise is a direct foothold into internal networks (the CitrixBleed lineage).
severity critical (CVSS 9.3) · exploited in the wild · CVE-2026-19490 · EU: NIS2, DORA

[P1] Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCEThe Hacker News
Why it matters: Check Point disclosed two maximum-severity flaws in the certificate handling of its own VPN gateways — each able to let an unauthenticated attacker run code on the Security Gateway that is supposed to protect the network — a pointed reminder that the security vendors' own products are not immune.
Check Point disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both CVSS 9.8 and both allowing unauthenticated remote code execution under specific conditions. CVE-2026-85102 is an improper certificate-trust-validation flaw during VPN negotiation: failing to properly validate a presented certificate lets an unauthenticated attacker push VPN negotiation far enough to execute code on the Security Gateway (Check Point's firewall appliances). CVE-2026-85103 is a heap-based buffer overflow during ASN.1 decoding of VPN certificates, affecting both Security Gateways and the Security Management Server. Check Point disclosed the flaws on 9 September in a customer notice and began delivering fixes the same day; it found no evidence of active exploitation or public PoC as of disclosure. Remediation: Live Patch (auto) or the relevant Jumbo Hotfix Accumulator (R82.10 Take 44+, R82 Take 126+, R81.20 Take 166+) plus Spark Firewall builds.
severity critical (CVSS 9.8) · CVE-2026-85102 · EU: NIS2, DORA

[P2] CISA: WatchGuard RCE flaw now exploited in ransomware attacksBleepingComputer
Why it matters: A critical flaw in WatchGuard Firebox firewalls — long available to fix but left exposed on thousands of appliances — is now being used by ransomware gangs to break into networks through the VPN, a reminder that an unremediated edge device is an open door that eventually gets kicked in.
CISA's September 2026 update confirmed that ransomware gangs are now exploiting CVE-2025-14733, a critical remote-code-execution flaw in WatchGuard Firebox firewalls' Fireware OS, in their attacks. The flaw affects appliances configured for IKEv2 VPN or Branch Office VPN (BOVPN) and is low-complexity to exploit (no specialised access or high skill required), allowing remote code execution on the Firebox. It was patched in December 2025, but adoption has lagged: over 115,000 unpatched Firebox firewalls were internet-visible in December, and roughly 9,000 remained unsecured nine months later. Affected Fireware OS versions span 11.x (incl. 11.12.4_Update1), 12.x (incl. 12.11.5) and 2025.1 through 2025.1.3. The ransomware adoption of this known, fixable flaw turns lingering exposed appliances into active intrusion points.
severity high · exploited in the wild · CVE-2025-14733 · EU: NIS2, DORA

[P2] Fortinet Code Execution Flaw Exploited in PivotC2 RAT AttacksSecurityWeek
Why it matters: Attackers are exploiting a FortiGate flaw to plant 'PivotC2,' a post-exploitation implant that gives them shell access, traffic tunneling and reconnaissance from inside the firewall — having probed tens of thousands of internet-facing FortiGates and compromised over a hundred, mostly in the US.
Attackers are exploiting Fortinet flaw CVE-2025-25249 (CVSS 7.4), a heap-based buffer overflow in FortiOS/FortiSwitchManager patched in January 2026, to deploy 'PivotC2,' a FortiGate post-exploitation RAT. PivotC2 provides interactive shell access, traffic tunneling, network scanning and configuration harvesting on the compromised firewall. The campaign has targeted over 30,000 internet-exposed FortiGate IP addresses and compromised at least 178 devices since July 2026, mainly US entities, with at least two intrusions resulting in data exfiltration; researchers attribute it to a likely Russian-speaking cybercrime actor. CISA added CVE-2025-25249 to its KEV catalogue with a three-day federal remediation deadline (BOD 26-04). Fixes: FortiOS 7.6.4/7.4.9/7.2.12/7.0.18 and FortiSwitchManager 7.2.7/7.0.6.
severity high (CVSS 7.4) · exploited in the wild · CVE-2025-25249 · EU: NIS2, DORA

[P2] AdaptHealth confirms 4.1 million people exposed in July cyberattackBleepingComputer
Why it matters: The home-medical-equipment provider AdaptHealth confirmed that a breach exposed the data of 4.1 million people — health and insurance details taken after attackers socially engineered their way into a contractor's privileged account, another healthcare intrusion tied to the prolific ShinyHunters.
AdaptHealth, a US home-medical-equipment and healthcare-services company, confirmed that a cyberattack exposed the data of 4.1 million people, in an incident attributed to the ShinyHunters threat group. The compromise occurred on 5 June 2026; AdaptHealth disclosed it in an SEC filing on 2 July, and on 15 June an unnamed actor demanded a ransom to prevent leaking the stolen data. The breach was achieved through social engineering that compromised the privileged account of a third-party contractor, giving access to cloud-based business applications including internal patient-management systems, document-storage platforms and electronic-health-record portals. The exposed data includes personal, health and insurance information but excludes Social Security numbers and financial data; AdaptHealth is offering 12 months of credit monitoring and identity protection.
severity medium · exploited in the wild · EU: GDPR, NIS2 · actor ShinyHunters (60%)

[P2] New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as RootThe Hacker News
Why it matters: A critical flaw in cPanel — the control panel running a huge share of the world's web-hosting accounts — lets any customer who merely holds a mailbox escalate to full root control of the whole server, a boundary break that threatens every tenant on a shared host.
cPanel patched CVE-2026-67401 (CVSS 9.9), a SQL-injection flaw in cPanel's EmailTrack mail-delivery-report feature that culminates in code execution as root. Exploitation requires only an authenticated hosting account holding mail privileges — not a reseller or administrator, just a mailbox — which can then create files anywhere and run code with root privileges, giving complete control of the host. Every supported version of cPanel and WHM was affected; the advisory was published on 8 September 2026, with fixes in builds 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4 and WP Squared 11.138.1.9. No confirmed in-the-wild exploitation is noted. The flaw poses a severe risk to shared-hosting providers and multi-tenant servers, where one low-privileged mailbox account reaching root can compromise every tenant on the machine.
severity high (CVSS 9.9) · CVE-2026-67401 · EU: NIS2, GDPR

newsletter

subscribe to cyber/verso

subscribe to receive cyber/verso's articles by email. Free, no tracking pixels, no tracked links. You can unsubscribe at any time. privacy notice.