USA Cybersecurity Status in September 2026
September in the USA was dominated by vulnerabilities and system exposure, with NetScaler, SonicWall, Microsoft, WSO2, and healthcare incidents in focus.
Key findings
- September closed with 53 verified incidents in the USA, fewer than in August, but with a stronger signal of exploited vulnerabilities and relatively less weight from ransomware.
- The leading threat was vulnerabilities, with 23 of 53 incidents and 27 critical CVEs mentioned; NetScaler, SonicWall, Microsoft, WSO2, and Linux drove the agenda.
- There were 9 unclassified incidents and 5 cases with ransomware or extortion as the primary focus, but only 1 was clearly identified as non-encrypting exfiltration.
- The FBI, the DMDC, and federal portals concentrated high-potential-impact incidents due to data exposure and unauthorized access.
- Water and OT remained a sensitive front, with the Colorado cases and the joint CISA-FBI guidance for ICS integrators as the month’s focal points.
- Compared with August, the month showed lower overall volume and less ransomware, but more pressure on patching and urgent mitigations.
- The regulatory response relied on third parties, accelerated notification, NIST, KEV, and greater oversight of critical vendors.
Monthly reference modules
These modules are automatically completed with verified dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-by-month readout, and the analysis that follows develops the cases without repeating this summary.
Indicator window: 53 dated facts in September 2026 · 3 from prior months (comparative frame, not month volume) · 4 without confirmed date (excluded from the indicators). Facts from prior months are used only as a comparative frame in the analysis, never as volume for this period.
Executive monthly summary for the USA
September 2026 was a lighter month in the United States than the one before, but it was more concentrated around exploited vulnerabilities, unauthorized access, and warnings about third-party dependencies. The verified facts for the period total 53, including 9 unclassified incidents and 27 critical CVEs mentioned, while vulnerabilities were the leading threat, accounting for 23 of 53 facts. The month’s risk picture is high, driven by active exploitation, cross-sector reach, and repeated signals affecting critical infrastructure, healthcare, finance, and government.
The most visible campaign was the wave of exploited vulnerabilities in Citrix NetScaler, which ultimately covered two main CVEs and pushed CISA, Citrix, and several response teams to issue urgent advisories in the final week of the month. At the same time, the edge and remote access ecosystem remained under pressure with SonicWall SMA1000, Mikrotik RouterOS, WSO2, Adobe Commerce, SharePoint, and Linux kernel, confirming an operational agenda dominated by patching, KEV prioritization, and perimeter exposure. On the incident side, the public sector and healthcare accounted for the most sensitive cases, although water, energy, transportation, and digital services also appeared.
The most sensitive events in terms of impact were the FBI incident and the Department of Defense DMDC case, both involving possible exposure of large volumes of personal data, though with different levels of confirmation and public scope. That was joined by the investigation into FBI job portals, activity attributed to ShinyHunters, and the OpenAI episode involving unauthorized access to federal government sites, reinforcing a pattern of risk around identity, credentials, and exposed surfaces. In OT and critical infrastructure, the joint CISA and FBI guidance for ICS integrators was one of the month’s most important regulatory and operational milestones.
There were also notable moves on regulation and compliance. The SEC, the OCC, the Fed, CISA, the FTC, the FCC, and federal lawmakers advanced measures on incidents, third parties, telecom, healthcare, banking, and AI governance. The overall picture is of a defense posture reorganizing around vendors, supply chains, remote access, and reporting obligations, with less emphasis on pure ransomware campaigns than in previous months and greater attention to exploitable vulnerabilities as a disruption vector.
Monthly National Overview in the USA
The United States ended September with a more dispersed risk surface, but one with sharper fault lines, remote access, exposed appliances, identity platforms, industrial integrators, and digital services tied to public administration. The combination of 53 verified events, 27 critical CVEs, and 9 unclassified incidents supports a high risk reading, not because of a single major event, but because exposure persisted across multiple sectors and several flaws moved quickly into active exploitation.
The month’s dominant signal was clearly technical. CISA repeatedly added vulnerabilities to the KEV catalog, set aggressive mitigation deadlines, and ordered urgent response in several cases. That sat alongside more traditional incidents in health care, local government, and utilities, where exfiltration, unauthorized access, or partial disruption were reported, but with ransomware less central than in August. Compared with the previous month, the overall volume was lower, ransomware was down, and documented fraud or phishing was less frequent, but more critical CVEs were cited and guidance plus patching became the main defensive mechanism.
In sector terms, the month affected at least eight sectors. Health care, government, water, finance, energy, telecommunications, transportation, and digital services all appeared in documented incidents. Not every case carried the same weight, and several were alerts or advisories without confirmed impact, but the risk pattern was consistent, where exposed systems, connected third parties, or edge appliances existed, exposure followed. That was especially clear in water and OT, where CISA and FBI guidance for ICS integrators was issued in response to real compromises, and in finance, where the regulator focused on third parties, core vendors, and operational resilience.
U.S. period indicators
| Indicator | Value | Note |
|---|---|---|
| Verified events in the period | 53 | Base for all indicators; dated events in September 2026 |
| Time window for the indicators | 53 events dated in September 2026 · 3 from previous months (comparative frame, not monthly volume) · 4 without confirmed date (excluded from the indicators) | Report-declared window |
| Unclassified incidents (breaches or outages) | 9 | Period events |
| Cases with ransomware or extortion as the primary focus | 5 | Period events |
| Exfiltration without encryption (simple extortion) | 1 | Breakdown within ransomware/extortion |
| Cases with undeterminable classification based on the material | 4 | Breakdown within ransomware/extortion |
| Documented fraud or phishing cases | 1 | Period events |
| Documented regulatory moves | 7 | Period events |
| Critical CVEs mentioned | 27 | Period events |
| Sectors with at least one documented event | 8 | One event can affect more than one sector |
| Predominant threat of the month | Vulnerabilities (23 of 53 events) | Dominant category of the period |
| Events with direct source confirmation | 75% | Percentage declared for the period |
Relevant Incidents in the USA
FBIjobs.gov and the ShinyHunters investigation
The FBI confirmed on September 22 that it was investigating unauthorized activity affecting its main job application portal and kept the site offline while the inquiry moved forward. Coverage later in the month added that the intrusion may have exposed personal data belonging to agents and applicants, but the exact scope has not been fully confirmed publicly.
The significance of the case is not only the possible volume of data, but also the surface that was compromised. The incident combines identity, human resources, and sensitive data exposure at one of the country’s most visible federal agencies. It also left open the question of whether the entry point was a third party or internal systems.
Defense Manpower Data Center, more than three million potentially affected
A DMDC system at the Department of Defense exposed personal information from more than three million people linked to the US military sphere, according to an official cited by Federal News Network. The unauthorized access allegedly took place between October 2025 and July 2026, which is why the matter became public this month, but it describes a long-running intrusion.
The key point for September is the structural nature of the compromise. This was not a one-off alert, but a sustained exposure of sensitive data tied to military personnel and others connected to defense. Available material does not allow a final attribution of the vector or the operational scale, but it does confirm the seriousness of the finding.
Astrana Health and the risk of phone impersonation
Astrana Health said a subsidiary detected unauthorized access after an attack in which the actors impersonated company staff using a spoofed corporate phone number. The case shows that social engineering remained effective for opening doors in sensitive environments, even when the intrusion did not rely on sophisticated malware.
The company filed an 8-K with the SEC and classified the incident as material because of the sensitivity of the data involved. In practice, the case ties a classic impersonation vector to a direct regulatory consequence and to an investigation that is still open.
Colorado and the compromise of two water utilities
Two small private drinking water providers in Colorado were compromised in late August, but the case continued to draw attention in September as authorities and the press detailed the technical scope. The attackers changed equipment configurations, disabled remote access and alarms, and altered pumping cycles, although there were no impacts on treatment, water quality, or public safety.
The value of the episode lies in the type of manipulation involved. This was not just access to an administrative network, but interference with OT systems and operating logic. The FBI also advised utilities to disconnect systems from the internet when possible and prepare for manual controls, linking the incident to guidance on third-party ICS issued days later.
Eudora, Douglas County, and the impact on interconnected networks
Eudora suffered an incident that, according to the fired former IT administrator, was foreign ransomware that began through the VPN connecting the police system with Douglas County sheriff servers. Coverage also said the ransomware encrypted police department files and that ransom was demanded to unlock them.
The impact did not remain contained within a single network. Dependence on shared infrastructure caused effects at the Lawrence Police Department, which had to disconnect from certain modules tied to the sheriff. It is a useful case for understanding the fragility of local ecosystems with mutually connected services.
Fort Smith and the exfiltration of municipal data
Fort Smith, Arkansas, said it was reviewing files after a dark web post claimed data copied from its network and the police department’s network. The city said the incident did not affect network security or recovery efforts, and public services continued operating.
The follow-up reporting indicated that the city had not yet publicly confirmed the scope, while the Interlock group claimed to have exfiltrated about 5.7 TB of data. The breach was better characterized as an extortion case with an allegation of information theft than as a verifiable encryption event in the available material.
Sutton, Massachusetts, and the municipality’s early response
The town of Sutton and its public schools reported a cybersecurity incident that affected part of their network environment. Systems were secured immediately, police were notified, and independent forensic specialists were hired, while services continued operating.
This case stands out less for confirmed damage than for the response pattern. The quick handling reduced operational impact and shows a more mature approach to initial containment in local events. Even so, it remains an incident that is not precisely classified in the available material.
CenterPoint Energy and customer data exposure
CenterPoint Energy told the SEC that an unauthorized party obtained personal information from some customers through one of its internet-exposed systems. The company said electricity and gas delivery were not affected and operations continued normally.
The news matters because it links public exposure, customer data, and operational continuity. The case does not describe a service outage, but it does confirm that exposed systems remain an effective entry point for information theft at large utilities.
Threats and active campaigns in the USA
Ransomware and extortion, with separate taxonomy
In September, five cases were recorded in the United States with ransomware or extortion as the primary focus, but the material does not allow them to be treated as one homogeneous set. There was one case of exfiltration without encryption, four publications whose exact classification cannot be determined from the material, and several victim mentions on leak sites that do not, by themselves, prove operational impact.
Exfiltration without encryption: Fort Smith
Fort Smith fits best as simple extortion with a claim of mass data theft. The city acknowledged intrusion and forensic work, and tracking sources speak of data theft and publication on a leak site, but not verified encryption in the consolidated material. The case falls into the realm of disclosure pressure, not confirmed unavailability.
Classification cannot be determined: Eudora, Sutton, and other local cases
Eudora had confirmed encryption, according to the former IT administrator, but in other incidents during the month the classification cannot be pinned down with the same certainty. Sutton, Fort Smith, and some notices from hospitals and providers appear as incidents with ongoing activity, group postings, or open investigations, without enough evidence to label them all as encryption, exfiltration, or a simple victim claim.
Leak-site mention only: OnTrac, Electrolux, and other posts
Monitoring from ransomware.live and other platforms added victims such as OnTrac and Electrolux, along with other organizations, but in several of those cases the source only documents the group's post. That does not amount to confirmed operational impact. The distinction matters because a leak-site appearance can be real, doubtful, or inflated, and the material does not always allow that gap to be closed.
Fraud and phishing, with one documented case
The only clearly documented fraud or phishing case in the United States during the period was the prosecution of two former Air Force members, tied to spam and phishing campaigns aimed at U.S. companies to steal credentials and use them in BEC fraud. The sentence was 111 months and 78 months in prison, plus restitution orders.
This confirms that phishing remains a useful entry point for financial fraud and account theft, even though the month was much more dominated by vulnerability exploitation than by mass email campaigns. The signal is smaller in volume, but not in legal sensitivity.
APT, espionage, and advanced intrusion activity
The month's advanced activity centered on the FBI cases, the DMDC, the movements around ShinyHunters, and the OpenAI episode involving federal sites. Not all of that is APT in the strict sense, but it does reflect an intrusion environment closer to reconnaissance, unauthorized access, credential theft, and selective exfiltration than to pure ransomware.
Coverage of NetScaler also showed the use of custom malware and early exploitation before Citrix's public announcement, suggesting campaigns with planning and preparation. In parallel, the OT and ICS front had a different signature, not so much exfiltration as pre-positioning, SCADA hunting, and preparation of compressed files with network schematics and configurations.
Critical vulnerabilities with impact in the USA
September’s technical agenda was defined by active exploitation, KEV additions, and aggressive remediation deadlines. CISA moved against edge appliances, Windows, Linux, collaboration products, commerce platforms, and administration tools that faced real pressure, not just theoretical risk.
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-88771 | Citrix NetScaler ADC and Gateway | Active exploitation, added to KEV | Sygnia, CISA, Cybersecurity Dive |
| CVE-2026-88772 | Citrix NetScaler ADC and Gateway | Active exploitation, added to KEV | Sygnia, Unit 42, CISA |
| CVE-2026-85102 | Check Point Security Gateway and Security Management | Active exploitation observed since September 12 | Check Point |
| CVE-2026-93616 | Check Point Management web service | Zero-day, active exploitation | Check Point |
| CVE-2026-81963 | Microsoft Windows | Active exploitation, added to KEV | SANS, Automox, CISA |
| CVE-2026-85880 | Microsoft Windows | Active exploitation, added to KEV | SANS, CISA |
| CVE-2026-19490 | Citrix NetScaler | Active exploitation, added to KEV | F5 Labs, CISA |
| CVE-2026-83548 | SonicWall SMA1000 | Active exploitation, added to KEV | SonicWall, CISA, Qualys |
| CVE-2026-83549 | SonicWall SMA1000 | Active exploitation, added to KEV | SonicWall, CISA, Qualys |
| CVE-2026-5430 | WSO2 API Control Plane, API Manager, Traffic Manager, Universal Gateway | Active exploitation, added to KEV | CISA, CiberPlaneta |
| CVE-2026-71362 | Adobe Commerce and Magento | Active exploitation, added to KEV | CISA, SecurityAffairs |
| CVE-2026-65660 | Microsoft SharePoint | Active exploitation, added to KEV | CISA, SecurityAffairs |
| CVE-2026-67279 | Mikrotik RouterOS | Active exploitation, added to KEV | CISA, SecurityAffairs |
| CVE-2025-39682 | Linux kernel | Active exploitation, KEV | Dataconomy, TechTimes |
| CVE-2026-53266 | Linux kernel | Active exploitation, KEV | Dataconomy, TechTimes |
| CVE-2025-39964 | Linux kernel | Active exploitation, KEV | Dataconomy, TechTimes |
| CVE-2026-87886 | Acronis Backup for cPanel & WHM and Plesk | Active exploitation in production, KEV | F5 Labs, CISA |
| CVE-2026-21962 | Not detailed in the source material | Active exploitation confirmed | Mishcon de Reya |
| CVE-2026-20079 | Cisco Secure Firewall Management Center | Active exploitation, KEV | CISA, The Hacker News |
| CVE-2026-82329 | JFrog Artifactory self-hosted | Active exploitation, KEV | CISA, JFrog, CiberPlaneta |
| CVE-2026-81578 | PaperCut NG/MF | Active exploitation, KEV | CISA, Cyber Experts |
| CVE-2026-82078 | PaperCut NG/MF | Active exploitation, KEV | CISA, Cyber Experts |
| CVE-2026-59310 | VMware vCenter | Exploited by ransomware groups, KEV | BleepingComputer, CISA |
| CVE-2026-725... | Not reported | Not registered in the analyzed material | n/a |
Regulation and compliance in the U.S.
September ended with a more active regulatory front than August, especially in banking, telecom, healthcare, privacy, and AI governance. Seven documented regulatory moves stood out, with notable intensity in building frameworks for third parties, incidents, and reporting obligations.
The SEC moved beyond the Reg S-P grace period and reminded regulated firms that they must have written incident response programs, notify customers within 30 days at most, and require vendors to report breaches within 72 hours. In parallel, the OCC updated its Cybersecurity Supervision Work Program to align it with NIST CSF 2.0, without creating new regulatory expectations, but making the exam focus for national banks and federal savings associations clear.
The Fed kept pushing the discussion on vendor risk and AI exposure. Michelle Bowman spoke about protecting banks, especially smaller ones, from risks tied to external services and AI. That was joined by the interagency debate over third-party risk management, with greater scrutiny of core providers and critical vendors.
In telecom, senators advanced a voluntary certification bill for providers and suppliers, in response to the debate that followed Salt Typhoon. In healthcare, Warner and Wyden reintroduced the Health Infrastructure Security and Accountability Act, with mandatory minimum standards, audits, continuity plans, and a $1.3 billion allocation to strengthen hospital cybersecurity.
CISA and the FBI also shaped the regulatory agenda with guidance on third-party ICS integrators. The guidance calls for reducing public exposure, logging remote access, maintaining hardware and software inventories, including security requirements in contracts, and preserving independent operating capability. It is a regulatory intervention grounded in a real attack pattern and aimed at lowering systemic risk across the industrial supply chain.
Most affected sectors in the USA
Healthcare was the most pressured sector, although the pressure did not come only through ransomware. There were incidents at hospitals, health providers, a major health tech player, and cases involving medical or sensitive data, alongside regulatory concerns tied to HIPAA, hospital security, and operational continuity. The signal is clear: healthcare remains a high-value target for information theft, extortion, and disruption.
Government and the public sector also had a difficult month. The FBI, the DMDC, local governments such as Fort Smith and Sutton, and the OpenAI episode involving federal portals showed a pattern of risk around identity, access, and administrative data. In this area, the problem was not a single type of attack, but the overlap between intrusion, data exposure, and dependence on vendors or third-party systems.
Water and OT carried disproportionate weight for the month’s total volume. Colorado and alerts about water utilities in other states showed that remote access and PLCs remain a weak point. The CISA and FBI guidance for ICS integrators was not an isolated piece, but a direct response to a problem that had already materialized.
Finance appeared through regulatory pressure and data incidents, but also through pressure on third parties, core vendors, and oversight. The OCC, the Fed, the FTC, and September legislative proposals put banks at the center of a broader debate on operational resilience, consumer protection, and the use of technology vendors.
Energy and transportation saw less volume, but high risk because of their critical nature. The tankers under investigation in the Gulf of Mexico and the CenterPoint Energy case show that vectors affecting OT, IT, and customer data can coexist. In telecommunications, the discussion shifted more toward public policy, although interest in certification and vendor resilience points to sustained concern.
Trends and signals to watch in the USA
Compared with August, volume fell sharply from 92 to 53 verified incidents, but risk did not ease. Unclassified incidents, ransomware or extortion cases, and documented fraud or phishing declined, while critical CVEs mentioned rose from 18 to 27. Last month was dominated by ransomware, this month by vulnerabilities. That reversal is the main tactical signal.
The second signal is the consolidation of the edge and remote access as the most urgent attack surface. SonicWall, Citrix, Mikrotik, WSO2, VMware, Check Point, and Microsoft products appeared with active exploitation or added to the KEV. The market for appliances and internet-exposed software continued to serve as the first line of impact for attackers, with objectives ranging from initial access to positioning for later intrusion.
The third trend is the growing density of incidents in third-party and vendor environments. The FBI case, the debate over ICS integrators, the interagency banking guidance, and regulatory moves on core providers and external service providers point in the same direction. This is not only about vendor audits, but about operational continuity in the face of critical dependency.
In health care and local government, September showed that the combination of exfiltration, ransomware, and administrative exposure remains active, but with fewer mass cases than in August. At the same time, the narrative of AI-assisted attack appeared less as a direct operational fact in the USA and more as a broader risk context, especially in the campaigns described by Anthropic and Unit 42 in other arenas.
The most relevant signal for October is straightforward: the pace of KEV publication and mitigation deadlines will continue to shape the defense agenda. If last month was the warning of a ransomware surge, September was the reminder that vulnerability exploitation remains the fastest path to compromise services, data, and industrial networks.
Security recommendations for teams in the USA
Prioritize patching edge and remote access appliances, with a focus on NetScaler, SonicWall, WSO2, Mikrotik, VMware, Check Point, and Microsoft products that were added to KEV or showed active exploitation. In organizations with public exposure, the remediation window should be measured in hours, not weeks.
Review third-party dependencies immediately, especially ICS integrators, core banking providers, and external services with persistent remote access. Contracts should include session logging, hardware and software inventory, accelerated incident notification, and the ability to operate without the integrator if that third party is compromised.
In government, health care, and utilities, strengthen monitoring for identity, authentication, and exfiltration. The FBI, Astrana, CenterPoint, and Fort Smith cases show that initial access still comes through credentials, impersonation, or exposed systems. Protecting the perimeter is not enough if sensitive data is already reachable internally or through connected portals.
In OT and water environments, limit direct internet exposure, log and segment remote access, and keep manual procedures ready. The CISA and FBI guidance on ICS integrators, along with the Colorado case, shows that operational continuity depends on both architecture and operational discipline.
For response teams, distinguish precisely between encryption, simple extortion, and mere publication on a leak site. That distinction is essential to avoid overestimating or underestimating the event, measure the real impact, and communicate with legal, executives, and regulators without mixing unverified claims with confirmed intrusions.
Frequently Asked Questions
What changed between August and September 2026 in the USA?
September saw fewer verified incidents than August, 53 compared with 92, and far less ransomware. At the same time, pressure on critical vulnerabilities increased, with 27 CVEs mentioned versus 18 the month before. The main signal shifted from ransomware to technical exploitation, especially on exposed edge devices and remote access.
Which sectors were most exposed this month in the USA?
Healthcare, government, water, finance, energy, telecommunications, transportation, and digital services all had documented incidents. The most sensitive combination crossed government and defense, with the FBI and the DMDC, while water and OT stood out because of the Colorado cases and the CISA-FBI guidance for ICS integrators.
Which vulnerabilities drove the operational urgency in the USA?
Citrix NetScaler, SonicWall SMA1000, Microsoft Windows, WSO2, Adobe Commerce, SharePoint, Mikrotik RouterOS, and the Linux kernel dominated the agenda. The common thread was active exploitation or inclusion in CISA’s KEV catalog, which forced immediate patching priority in exposed environments.
How should the month’s five ransomware or extortion cases be read?
They should not be grouped as a single block. One is better characterized as exfiltration without encryption, four do not allow the impact type to be determined with certainty, and in several cases the source only records publication on a leak site. That distinction changes the damage assessment completely.
What does the US regulatory front mean for banks and vendors?
It means tighter oversight of third parties, greater documentation demands, and less room for informal responses. Reg S-P already requires rapid notification, the OCC aligned its work with NIST, the Fed strengthened its focus on vendors, and the TPRM debate points to core providers with stricter responsibilities.
Material limitations
This report was prepared exclusively from the material provided for the US and September 2026. The 53 verified facts from the period are the basis for all indicators. The three facts in the comparative frame block were used only for month-over-month trend analysis and do not count toward the month’s volume. The four facts without confirmed dates were excluded from the indicators.
A zero value, especially for CVEs or categories such as fraud, does not mean the phenomenon is absent in the United States or across the region. It means it did not appear in the material analyzed for this period with the level of confirmation required by these rules.
The report’s stated time window includes 53 facts dated in September 2026, plus three facts from earlier months used only for comparison, and four without confirmed dates excluded from the counts. The material does not include aggregated telemetry such as incidents, and any figure for attempts or blocks should be read, if it appears, as operational noise and not as a confirmed intrusion.
Consumer social media posts and sponsored content were also excluded as evidence. When third-party mentions were used, priority was given to official bodies, vendor notices, CISA, FBI, SEC, OCC, Fed, and other primary or directly observed sources. When a claim depended only on attacker attribution or secondary coverage, it was treated as such and not as a closed fact.
Sources
- When remote access reaches the physical worldImprivata
- Reg S-P Compliance Deadlines Have Passed. Is Your Firm Exam Ready?Troutman Pepper
- FBI hunting the hackers who stole its employees' sensitive informationNPR
- Actively Exploited NetScaler VulnerabilitiesSygnia
- FBI sends warning to cybercrime group that hacked it after arrest of alleged memberNBC News
- Citrix NetScaler exploitation began days before public notificationCybersecurity Dive
- Custom malware used in Citrix 0-day attacks targeting govt, banks, professional servicesThe Register
- FBI official tells hackers to get in touch, says 'we know how to find you'Reuters
- Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772Unit 42, Palo Alto Networks
- FBI reportedly declares 'cyber security incident' after hackers steal agents' personal dataTechCrunch
- Citrix Products Multiple VulnerabilitiesHong Kong Computer Emergency Response Team Coordination Centre
- Zero-Day Exploitation of Citrix NetScaler ADC and GatewayRapid7
- Critical vulnerabilities in Citrix NetScaler ADC and Citrix NetScaler Gateway productsAustralian Signals Directorate’s Australian Cyber Security Centre
- FBI, CISA Warn of Third-Party ICS Integrator RisksSecurity Today
- OT Confidence Outpaces Asset VisibilitySecurity Today
- ShinyHunters says it won’t publish FBI dataNextgov/FCW
- 28th September – Threat Intelligence ReportCheck Point Research
- More than 3 million people affected by military data breachFederal News Network
- FBI job portals remain offline after ShinyHunters claims breachHelp Net Security
- CVE-2026-88772 Impact, Exploitability, and Mitigation StepsWiz
- Sept 28 Advisory: Citrix NetScaler ADC and Gateway VulnerabilitiesCensys
- Agentes no autorizados de OpenAI atacaron tres sitios web distintos del Gobierno de EE.UU.CNN en Español
- SpyCloud finds 1787 US water providers exposed to malwareThe Cool Down
- OpenAI Discloses Unauthorized AI Agent Activity Across U.S. Government WebsitesSecurity Boulevard
- Storm-3168: Agentic-driven cloud attacks using compromised service principalsMicrosoft Security
- Cybersecurity & Privacy NewsLaw360
- Biotech: US House and Senate propose 2 bills for CISA to step up the protection of biotechnology infrastructureDigital Watch Observatory
- Alerta de Seguridad: Citrix NetScaler - RCE y denegación de ...CiberPlaneta
- Alerta de Seguridad: WSO2 - Path Traversal y RCE | Boletín de Seguridad CiberPlanetaCiberPlaneta
- WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEVThe Hacker News
- Victim: Electrolux & OnTracRansomware.live
- Hacker claims 7.49M customer records stolen from American utility companyFox News
- Weekly Intelligence Report - 25 Sep 2026CYFIRMA
- Electrolux & OnTrac Listed by Emperador Ransomware GroupGalaxy Warden
- Rogue OpenAI agents accessed US government websitesPolitico
- Autonomous agents attack Azure using compromised identities, destroying resourcesCSO Online
- AI Agents Stole 600,000 Payment-Card Records From 100-Plus Sites for About $25 a ScanGadget Review
- OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS IntegratorsSecurityWeek
- Massive Chinese hack uses AI agents to steal over 600,000 credit cards and hit hundreds of sites with malwareTechRadar
- 617938 cards came from two databases, not skimmed sitesPK Sharma
- Commissioner Christian Urges Texas Energy Industry to Prepare for Evolving Cyber ThreatsRailroad Commission of Texas
- California critical access hospital says files stolen in cyberattackBecker's Hospital Review
- Your ICS Integrator Is a High-Value Target—CISA and FBI Map the RiskMinistry of Cyber Affairs
- Emperador claims U.S. parcel carrier OnTracDaily Dark Web
- House and Senate members propose legislation for CISA to step up cyber defenses for biotechCyberScoop
- Bipartisan Senate leaders introduce bill to bolster telecom cybersecurity in response to Salt Typhoon hacksCyberScoop
- Senators propose voluntary telecom security framework after Salt Typhoon hacksNextgov
- Cruz, Warner Introduce Bipartisan Bill to Strengthen Telecommunications CybersecurityU.S. Senate Committee on Commerce, Science, and Transportation
- S.5529 - 119th Congress (2025-2026)U.S. Congress
- US companies face rise in cyber attacksReuters
- AI agents steal 600,000 credit cards in attacks on online retailersCyber Insider
- More than 90% of energy companies report high levels of cyber attacksEnergy Live News
- This Week in Cyber: September 18 to 24, 2026CrunchAtlas
- FBI investigates breach of jobs website as hackers claim sensitive data stolenThe Guardian
- Daily OT Security News: September 25, 2026SecurityBoulevard
- CISA and FBI Release Fact Sheet to Help Critical Infrastructure Operators Work with Third-Party ICS IntegratorsCISA
- Stolen Passwords Put More Than 1700 U.S. Water ...TechShots
- Considerations for Critical Infrastructure Operators Working With Third-Party ICS IntegratorsCyber ICT
- Victim: OnTracRansomware.live
- OnTrac Listed by Emperador Ransomware GroupGalaxy Warden
- Uno de cada cinco ciberataques en América Latina ya usa inteligencia artificialEl Español / Invertia
- emperador Ransomware: 4 Victims, Tactics & IntelligenceThe Hacker Wire
- Uno de cada cinco ciberataques en América Latina ya usa inteligencia artificialEl Español
- Avance de la IA impulsa debate sobre soberanía digital durante la Asamblea de la ONUInfobae
- September 23, 2026 - 8-K: Current reportAstrana Health / SEC filing
- 258 U.S. Water Organizations Have Credentials Exposed ...eSecurity Planet
- El FBI investiga un presunto ciberrobo de datos personales de sus agentesEFE
- FBI probes cyberattack tied to third-party jobs portalCybersecurity Dive
- Senators Renew Push for Tougher Healthcare Cyber RegsBankInfoSecurity
- Alabama Women's Health Care Data Breach LawsuitClass Action U
- Colorado water utilities hacked by foreign actorCybernews
- Tuesday, Sept. 22, 2026KFF Health News
- FBI investigating apparent breach after hackers claim to have stolen agents’ dataCNN
- Breach Watch Weekly: When the Attacker Is an AI Agent — Sep 20–24CISO Platform
- Colorado Water Utilities Breached in AugustSANS Institute
- PRUDENTIAL REGULATION—OCC updates cybersecurity supervision work program structure and referencesVitalLaw
- UnitedHealth CEO Admits Paying $22 Million to Change Healthcare HackersVCPost
- Here's how the Fed is working to ensure banks protect themselves from AI risksYahoo Finance
- OCC Updates Structure, References in Cybersecurity Program Examiners Use to Evaluate BanksThe CU Daily
- Daily Financial Regulation Update — Tuesday, September 22, 2026Paul Hastings
- Weekly Enforcement & Compliance Insight Digest – September 21, 2026Across Oversight
- Cybersecurity: Cybersecurity Supervision Work ProgramOffice of the Comptroller of the Currency (OCC)
- Senators revive healthcare cybersecurity bill with $1.3B for hospitalsBecker's Hospital Review
- ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New StoriesThe Hacker News
- Two Years After the Change Healthcare Cyberattack, Healthcare Still Has a Clearinghouse Redundancy ProblemMedCity News
- CISA Flags Three Linux Kernel Vulnerabilities Exploited in the WildThe Hacker News
- Foreign hackers targeted Colorado water systems in August, governor’s office saysReuters
- Daily OT Security News: September 19, 2026Security Boulevard
- Fed sat on Silicon Valley Bank flaws because regulators feared being wrong, report findsYahoo Finance
- Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix ...The Hacker News
- Democratic Senators Reintroduce the Health Infrastructure Security and Accountability ActHIPAA Journal
- Initial Findings from Independent Review of Silicon Valley BankBoard of Governors of the Federal Reserve System
- Bill Would Force U.S. Hospitals to Take Cybersecurity SeriouslySecureWorld
- Regulators clear path for verifiable digital credentials in customer identificationMcDermott Will & Emery
- 'Foreign actors' targeted small, private water providers in ColoradoABC News
- AI disclosure and transparency — U.S. AI Laws by Topic (Traveler Privacy Protection Act of 2025, S.1691)AI Laws USA
- GOVERNMENT & CIVIC Q2 2026 : INDUSTRY REPORTCyfirma
- Foreign actors breach Colorado water systemsAxios
- Hacking Group Claims Attack on Cedar County Memorial HospitalHIPAA Journal
- Settra Ransomware Uses MeshAgent Against WindowsCyPro UK
- China's FamousSparrow APT Spies on US Politics in Latin ...DarkReading
- BlackCat: hackers rusos en América Latina y el engaño ...Infobae
- House passes ratepayer protection bill to limit data center cost shiftsYahoo News
- Colorado Water Utilities Hit by Cyberattacks Targeting OT SystemsSecurityWeek
- qilin ransomware group: victims, TTPs, profile · ZeroHourZeroHour
- K3G Solutions Brazil Ransomware Claim (2026) — What’s Alleged & Am I Affected?Recent Breaches
- FBI, Coast Guard boarded hacked oil tankers heading towards US coastTechCrunch
- Cyware Weekly Threat Intelligence - September 12Cyware
- Democrat blocks fast-track passage for data center ratepayer billPolitico
- Representative Don Bacon introduces H.R. 10484Quiver Quantitative News
- What the Agencies' TPRM Overhaul Signals for Bank OversightForvis Mazars
- The Regulators AnsweredCCG Catalyst
- US launches Quantum Readiness Task ForceSemiWiki
- Desarticulan red acusada de abrir al menos 22 cuentas digitales a nombre de las víctimas de estafaLa Prensa Gráfica
- Sed de recursos y datos fragmentados: los riesgos de la IA para LatinoaméricaRT Actualidad
- Warner, Wyden Introduce Bill to Strengthen Cybersecurity Standards for American Health Care SystemUnited States Senate Committee on Finance
- Ransomware Attacks This Week: 179 Victims Across 44 Groups…Scrutex
- QILIN Ransomware Gang: 19 Victims Posted in 72 Hours — Manufacturing & Agri-Food Surge, Detection Rules InsideSecurity Arsenal
- US Tracking Cyber Threats Against Nearly 20 ShipsInsurance Journal
- Microsoft 365 Penetration Testing for Financial InstitutionsMyABT
- OCC bars 2 former bank employees over embezzlement, debiting of customer accountsRegReport
- OCC Announces Enforcement Actions for September 2026OCC
- Information Security Laws: What Organizations Must KnowTerralogic
- US Treasury wants banks to be better at filing cyber scam reports after noting nearly USD13 billion in losses since 2023TechRadar Pro
- Ransomware Payment Reporting Under CIRCIA: Deadlines and PenaltiesFedlaws.org
- Technology Bills (incluyendo AI Incident Reporting Act y proyectos de privacidad para chatbots)OpenRepublic
- Whitepaper links water hacks to telecom cyber riskSecurityBrief
- Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board VesselsSecurityWeek
- US Coast Guard and FBI board oil tanker to investigate cyber attackBitdefender
- Brevo supply-chain attack injected ClickFix scripts on customer sitesBleepingComputer
- Interlock claims responsibility for Fort Smith computer system attackTalk Business & Politics
- H.R.10484 - Covered AI Prohibition Act, 119th Congress (2025–2026)Congress.gov
- Bill to curb AI data center utility costs hits snag in SenateCNBC
- Ratepayer Protection Act Should Apply to All Large Electricity Users, Not Just Data CentersInformation Technology and Innovation Foundation (ITIF) / DataInnovation.org
- House passes bill to shield households from data center energy costsWashington Examiner
- Cedar County Memorial Hospital Data Breach - McShane & BradyMcShane & Brady
- CISA: Critical VMware RCE flaw now exploited by ransomware gangsBleepingComputer
- Weekly Threat Bulletin – September 16th, 2026F5 Labs
- Looming Incident Reporting Mandates: Who Needs To CareThe Legal 500
- Grafton City Hospital Data Breach: What Patients Should KnowWilshire Law Firm
- Ransomware Anubis publica a la tecnológica Quest Group / Ransomware Panzer publica a la consultora brasileña K3G SolutionsKalir Pulse
- Griffith Votes to Protect Ninth District Communities from Footing Bill ...Morgan Griffith (House.gov)
- Daily OT Security News: September 16, 2026Security Boulevard
- CVE-2026-82567: Missing Authentication Allows Unauthorized SMSSecNora
- Federal Banking Agencies Propose Overhaul of Third-Party Risk Management Guidance, Issue Community Bank Guide, and Heighten Focus on Core Service ProvidersWinthrop & Weinstine
- The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functionsGitHub Advisory Database
- Criminals or Terrorists? US Security Policy in Latin AmericaRosa Luxemburg Stiftung
- Coast Guard, FBI boarded tanker after attack by 'foreign cyber actors'The Record
- Beyond the town halls: Getting ready for CIRCIA before the clock starts tickingFederal News Network
- FBI and Coast Guard boarded US-bound oil tankers after suspected cyberattacks on ships’ networksAP News
- Statement Regarding Cyber IncidentTown of Sutton
- Regulatory penalties for global financial institutions surge 31% in H1 2024Fenergo
- Sutton town officials, public school system investigating cybersecurity incidentBoston Globe
- Cybersecurity incident affects Sutton town, school networksWCVB
- House votes to curb AI data center costsAxios
- Fort Smith computer attack investigation nearing an endTalk Business & Politics
- CIRCIA's Looming Deadline Puts Corporate Counsel on the ClockLaw.com / Corporate Counsel
- H.R.10449 - 119th Congress (2025-2026): To establish a prohibition for certain disclosures of personally identifiable information under FERPACongress.gov / Library of Congress
- Unit 42 says hackers used AI tools against LatAm targetsReuters
- VMware vCenter CVE-2026-59310: Ransomware Gangs Join Unauth Syslog RCE - CyberExperts.comCyberExperts.com
- Coast Guard and FBI boarded 2 energy tankers due to cyberattacks. How big is the risk?CBS News
- The Regulatory Gap: Agentic AI Outpaces Federal OversightYahoo News
- What Is SEC Regulation S-P and Who Must Comply?FedLaws
- The FTO Map Is Expanding: Latin America Counterparty RiskSigma360
- Congress in AI deadlock as public fear soars – Live UpdatesPolitico
- Environmental Protection Agency (Organization): news timeline & CVEs · ZeroHourZeroHour
- Siemens S7-1500 F-series (Product): news timeline & CVEs · ZeroHourZeroHour
- Siemens S7-200 (Product): news timeline & CVEs · ZeroHourZeroHour
- Anne Arundel patients sue Luminis Health after cyberattack exposes medical dataThe Banner
- Beneficial Ownership Across the Border: United States Eases Reporting While Mexico Raises the AML BarSnell & Wilmer
- Wednesday, 16 September 2026 - AI Edge BriefingAI Edge Briefing
- Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacksCyberScoop
- The 2026 CCO PlaybookComply
- USCG and FBI Investigate Cyber Compromises on US-Bound Energy TankersShip Universe
- Capitol agenda: Trump's AI demands jam Republicans – Live UpdatesPolitico
- INTERLOCK Ransomware Gang: Education & Municipal Government Hits Posted — Campaign Analysis & Detection RulesSecurity Arsenal
- House takes 'small step' to shield Americans' energy bills from data centersUSA Today
- Every regulatory disclosure rule asks the same question. Each calls it something elseSysdig
- International Transfers of Personal Data in Latin America: From the Brussels Effect to the Washington EffectFordham International Law Journal
- interlock ransomware group: victims, TTPs, profileZeroHour
- Proposed Third-Party Risk Management GuidanceFederal Register
- Workplace Cybersecurity Trends in 2026MTF Institute
- AI Bills Tracked — Restore the FirstRestore the First
- Interlock Strikes Springfield Public Schools in Major Ransomware AttackDexpose
- Springfield Public Schools Listed by Interlock Ransomware GroupGalaxyWarden
- Ne comptez pas sur l'ADPPA et le Privacy Shield 2 pour la conformité RGPDMailgun
- Cyber Resilience Act: 62% verpassen 24h-Frist [2026]Tech Insider
- Cybersecurity · Industry brief — Monday, September 14, 2026MorningMail.ai
- CIRCIA Is Almost Law: What Critical Infrastructure CEOs Must Do Before the Final Rule DropsAdil Karam
- Data Protection Explained: What Your Organization Must DoConsentPixel
- Victim: City of Fort Smith ArkansasRansomware.live
- Ransomware Alert: City of Fort Smith, Arkansas – INTERLOCK ransomwareFalconFeeds.io
- mySCADA myPRO ManagerCybersecurity and Infrastructure Security Agency
- CenterPoint Energy confirms intruder helped themselves to customer informationThe Register
- Estafas con IA: cómo protegerte de las voces clonadas y los deepfakesSeguidores.online
- Cybersecurity expert assesses Interlock claim to Fort Smith city dataSouthwest Times Record
- Consumer protection — U.S. AI Laws by Topic (438 tracked)AI Laws USA
- City of Fort Smith Arkansas Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- H.Res.1530 - Providing for consideration of several bills including H.R.10326 on fraud detection and privacy protectionCongress.gov / Library of Congress
- Addressing Cyber Risk in Water & Wastewater OperationsExponent
- City of Fort Smith Arkansas data breach — Interlock ransomware leak (2026)Darkfield
- Ransomware group claims Fort Smith attack as city nears end of probeKUAF (Ozarks at Large)
- US federal frontier-AI regulationTakeoff.watch
- NYDFS Issues Extensive Guidance on Cybersecurity Risk AssessmentsMayer Brown
- H.R.9925 - 119th Congress (2025-2026): FRONTIER ActCongress.gov
- Eudora's just-terminated IT administrator says foreign ransomware is behind 'big mess' with city's and sheriff's computer systemsLawrence Journal-World
- Bank Fraud Detection Systems: Where the Voice Channel Fits.VoiceSecurity
- H.J. Res. 210 – Providing for congressional disapproval ... (agenda que incluye H.R.10326, PROOF Act)House of Representatives (docs.house.gov)
- RST Cloud on X: "#threatreport #LowCompleteness SETTRA RANSOMWARE | 14-09-2026 ...RST Cloud
- The prescient threat: Why CISA's water advisory demands process-level visibilityWaterWorld
- US Water Utility Cyberattacks: What the Exposure Data RevealsBrightTalk
- Daily OT Security News: September 14, 2026Security Boulevard
- China-nahe Hackergruppe späht Regierungen in ...Presseportal / ESET Research
- Trust Issues: September 2026Davis Wright Tremaine LLP – Privacy & Security Law Blog
- NYDFS Issues Extensive Guidance on Cybersecurity Risk AssessmentsMayer Brown
- Grafton City Hospital Data Breach Affects 1,215 UsersClaimDepot
- 25 Principles: U.S. Critical Infrastructure Cybersecurity PoList25
- How Banks and Credit Unions Handle Compliant Data Destruction During IT RefreshesTAMS Solutions
- Active Exploitation Alert: Brevo CDN Supply-Chain Compromise — ClickFix Injection via Stolen Cloudflare API KeyRESCANA
- Brevo Supply Chain Attack Injects Malware Into 100,000 WebsitesSecurityWeek
- Casbaneiro Banking Trojan Uses Distributed C2 ServersSocPrime
- Security Incident - ClickFixBrevo Status
- Weekly Threat Bulletin – September 23rd, 2026F5 Labs
- AI Pulse Daily Brief | 2026-09-14Horizonscan
- US senators weigh requiring AI giants to commit to preventing catastropheReuters
- 医療分野 週次セキュリティニュース|あめむAmenomu
- Panamá alerta sobre auge de robo de celulares y fraude bancarioPrensa Latina
- Bank Regulators Draw the Lines on AI Governance in 2026AI-Policy.org
- The Senate Wants Power to Block Unsafe Frontier AISantage AI
- Anthropic's startling revelations on misuse of its AI models. From State-sponsored hackers to spy opsThe Print
- Ransomware Group global Hits: TOWN OF SUTTONHookPhish
- PPD-21 Explained: Sectors, CIRCIA Reporting, and NSM-22FedLaws.org
- Global Ransomware Group Attacks Town of Sutton, MassachusettsDexpose
- Daily OT Security News: September 12, 2026Security Boulevard
- OCC and FDIC Adopt Final Rule Defining 'Unsafe or ...Sullivan & Cromwell LLP
- Incident Response PrioritiesSecurity Arsenal
- Thune, Cruz, And Klobuchar Move AI Safety From Voluntary ...TechTimes
- H.R. 10326 – PROOF ActTheBillRoom
- Google alerta por ciberataques con IA: vulnerabilidades y credenciales en menos de seis horasInfobae
- Anthropic afirma que Irán y Rusia usaron Claude para desarrollar armasBloomberg
- Irán utilizó la IA Claude para planificar posibles ataques contra Estados Unidos, según AnthropicEcuavisa
- Anthropic blocks possible attempt to use AI to make biological weaponsBBC
- EXPLAINER - Anthropic threat intelligence report: What to knowAnadolu Agency
- What Are the Five Pillars of an AML Compliance Program?SphinxHQ
- Weapons, spyware and AI scams: Anthropic exposes Claude misuseAFP
- Anthropic says Iran-linked accounts used Claude for propaganda, US naval targetingIran International
- Claude Used to Automate Exploitation and Data Theft Across Multiple VictimsThe Hacker News
- joint statement on community banks' engagement with core service providersBoard of Governors of the Federal Reserve System / FDIC / OCC (vía InsuranceNewsNet)
- Congress Considers Expanding AI Security Information ...Govly
- Beyond ransomware: 5 healthcare cyber risks to knowBecker's Hospital Review
- State authorities warn they lack resources to address cyber threat to water utilitiesYahoo News
- 100+ U.S. Water Systems Attacked: What Happened and Why Zero Trust MattersIllumio
- Anthropic Documents Spies, Scammers and Rival Labs Misusing ClaudeStreamlinefeed
- AT&T Outage: Thousands in Texas were left without internet and TV after outage; Iranian hackers say "we did it", AT&T says "no we"Times of India
- New York tells banks to find their single points of failureAmerican Banker
- Lawmakers push for AI safety legislation amid extinction fearsCryptoBriefing
- Senate AI safety bill's path forward remains unclearPolitico
- The Hike That Finally Landed, The Rulebook The Agencies Just WroteButler Brief
- OCC, Fed Reserve, FDIC, NCUA Propose 3rd Party Risk Management GuidanceNational Law Review
- Ukrainian hacker gets four years in US prison over ContiThe Record
- Ukrainian National Sentenced to Four Years in Prison for Conti Ransomware RoleGround News
- Ukrainian Conti ransomware member gets 4 years for hospital-linked attacksBecker's Hospital Review
- 2026-09-11 Briefing – Ukrainian Conti ransomware coder sentenced to 4 yearsalobbs.com
- Banking Agencies Propose More Prescriptive Third-Party Risk Management FrameworkConsumer Finance Monitor
- CISA Cyber Storm exercise offers blueprint for enterprise CISOsTechTarget – Cybersecurity
- Abogado ucraniano que programó para Conti recibe cuatro años de prisión en EE. UU.DiarioBitcoin
- NYDFS Part 500 AI Compliance Checklist for Covered EntitiesDeepInspect
- RBI asks fintechs, payment firms to start 'quantum-proofing' systemsMoneycontrol
- Why Post-Quantum Cryptography Is Important For Financial InstitutionsForbes
- Post-quantum cryptography becomes mandatory for financial ...CryptoBriefing
- US regulators propose bank third-party risk guidelinesCryptoNews.net
- OCC Delivers on Community Bank Comeback, Reduces Burden for Community BanksOffice of the Comptroller of the Currency (OCC)
- Banking agencies pledge more scrutiny of core provider business practicesABA Banking Journal
- Interagency Statement: Risk-Based Supervision of Certain Services Provided by Core Providers to Community Banking OrganizationsOffice of the Comptroller of the Currency (OCC)
- 美国监管机构发布银行第三方风险管理拟议指引Sina Finance / 格隆汇
- Fed, FDIC, OCC Unveil Bank Third-Party Risk Management ProposalBloomberg
- News in Systemic Risk: September 11, 2026 (9:45 a.m.)Yale School of Management
- US Federal Banking Agencies Propose Revised Third-Party Risk Management GuidanceSkadden
- WordPress plugin fires, SonicWall zero-days, and a KEV avalanche · Perimeter · 09-11-2026Fruition
- FinCEN’s $13 Billion Scam Center Alert: What Banks Need to Know About the Fastest-Growing Financial Crime ThreatNatLawReview
- Threat Intelligence / AnthropicAnthropic
- Treasury urges banks to file cyber scam reports, noting ...The Record
- AI Agents Are Hacking Online Retailers for $25 a CompanyGambit Security
- Four extortion gangs add care providers to their leak sitesMedRisk
- Anthropic disrupts bioweapons research efforts, Russian hacking, Chinese Claude misuseReuters
- Preventing Rip-offs and Obtaining Oversight of Funds ActThe Capitol Wire
- Form 8-K filing by Nutex Health Inc. dated September 10, 2026SEC
- Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US PrisonSecurityWeek
- ID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolenTechCrunch
- Consumers Bancorp posts $11.2M profit for 2026 (incluye descripción de la regla de incidentes de seguridad informática de 36 horas)StockTitan
- FBI investigating hospital IT disruption that took EHR offline for 2 weeksBecker's Hospital Review
- Luminis Health MyChart, phones remain offline amid cyberattackBecker's Hospital Review
- Inside AI Policy: Gottheimer-Lawler bill rejects self-attestation aloneU.S. House of Representatives (Office of Rep. Mike Lawler)
- Nutex Health updates on cyber incident data post - NUTXStockTitan
- Descubren que usaban Claude para el estudio y diseño de una gripe aviar en humanosLa Nación
- Revelan cómo hacía la red de estafa por phishing en San Pedro Sula y TegucigalpaLa Prensa Honduras
- Luminis is the latest health system hacked: 'Everybody's at risk'WTOP News
- Revelan cómo la IA Claude fue utilizada en ciberespionaje, armas autónomas y campañas de manipulación globalContrapunto
- CHAOS Ransomware Gang: 4 New US Victims Posted — Manufacturing & Healthcare Targeting Analysis With Detection RulesSecurity Arsenal
- What to know about the Luminis Health cyberattackThe Banner
- Stop Rogue AI Act、AI台帳を連邦請負要件へQuasa.io
- FBI investigating hospital IT disruption that took EHR offline for 2 weeksBecker's Hospital Review
- Delitos con IA figuran este año en el paísDiario Extra
- The BR Privacy, Security & AI Download: September 2026JD Supra
- Ransomware claim follows Missouri hospital IT outageDysruptionHub
- Casbaneiro: A Banking Trojan with Distributed Data-Receiving ServersFortinet
- Governments are turning to Claude to automate spyingAxios
- AI Governance in Banking: What Regulators Require (2026)BankingNewsAI
- Unit 42 on X: "We saw attackers using commercial AI tools..."Unit 42 on X
- Cybersecurity Information Sharing Provisions Face Expiration in 2026Legis1.com
- Treasury Urges Banks to Report Cyber Scams as Losses ...Verisq.ai
- Anthropic: Irán usó la IA Claude para planificar posibles ataques contra Estados UnidosEFE
- Cybersecurity Information Sharing Act of 2015 Temporarily ExtendedSecurity Magazine
- CVE-2026-67277: fuga de memoria del kernel y DoS no autenticado en MikroTik RouterOSCiberPlaneta
- Hospital operator Nutex Health says data stolen in cyberattackWestern Networks Inc.
- PART 53—COMPUTER-SECURITY INCIDENT NOTIFICATION (12 CFR)GovRegs
- SEC Regulation S-P Is Now Fully in Effect: How Financial Institutions Must AdaptAdil Karam
- Novo golpe alterar QR Code do Pix em lojas online; saiba como se prevenirUOL Tilt
- VEXY Ransomware Gang: 3 Technology Sector Victims in 5 Days ...Security Arsenal
- Weekly Threat Bulletin – September 9th, 2026F5 Labs
- Banking supervision and enforcement reform — early themes emerging from new standardsReuters
- OCC and FDIC change the rules for supervisionDavis Polk
- Does becoming a federal bank protect crypto from Washington—or give Washington more control?CryptoSlate
- Will S. 3097 Finally Close Digital Health Privacy Gaps?HealthPoint
- Fulcher co-sponsors privacy bill with guardrails for Flock camerasIdaho State Journal
- Active Exploitation of Vulnerability in Adobe ProductsCyber Security Agency of Singapore
- CISO Application Risk Intel Briefing for Week of September 9Veracode
- Attackers Use AI-Assisted Intrusions and Data Exfiltration to Target Latin American OrganizationsVarutra
- Live Ransomware TrackerTheSolutioners.ca
- Gottheimer Introduces Bipartisan Bill to Stop Rogue AI Agents and Keep People in ControlU.S. House of Representatives
- Standard Tool & Die Listed by Storm Ransomware Group (includes WindRose Health Network context)GalaxyWarden
- CIRCIA 72-Hour Rule: What SMBs Need to KnowBryceStreet.net
- HVNC Backdoor Targets LATAM Organizations with Fake Tax LuresANY.RUN
- Daily OT Security News: September 08, 2026Security Boulevard
- incransom - Dragons Eye Ransomware TrackerDragons Eye Ransomware Tracker
- Ransomware Groups - Tracked Threat Actors | Invaders CybersecurityInvaders Cybersecurity
- Ransomware Wing — víctimas, grupos y patronesKalir.io Pulse
- Krybit ransomware group: victims, status, activityRansomnews
- Bitdefender Ransomware Threat Debrief | September 2026Bitdefender
- Bank Secrecy Act/Anti-Money Laundering: Frequently Asked Questions on the Use of Mobile Driver’s Licenses and Other Government-Issued Verifiable Digital CredentialsOffice of the Comptroller of the Currency (OCC)
- Google alerta que los cibercriminales usan sistemas de IA cada vez más autónomos y rápidosEFE
- Bank Secrecy Act/Anti-Money Laundering: Frequently Asked Questions Regarding Treatment of Verifiable Digital Credentials Under the Customer Identification Program RuleOffice of the Comptroller of the Currency (OCC)
- GLBA Breach Notice Rules: 7 Steps for CFOsPhoenix Strategy Group
- CISA's CIRCIA Is Finalizing This Month. Here's What the New 72-Hour Reporting Clock Means for Your Financial Services Incident Response Program.RiskTemplates
- Jack Henry Cybersecurity Incident: What Banks and Credit Unions Need to KnowNetBankAudit
- SonicWall SMA1000 WorkPlace - Unauthenticated SSRFProjectDiscovery
- SonicWall customers face actively exploited zero-days (X post)CyberScoop
- Text - H.R.9716 - PRIVACY Act, 119th Congress (2025-2026)Congress.gov
- Unauthentifizierte SSRF im SMA1000 Work-Place-InterfaceArgos Security
- Congress Is Building the Scaffolding: The First Federal Bill Mandating Agent Security StandardsForkast
- H.R.9619 - To require artificial intelligence chatbot providers to provide data privacy and security, and for other purposesCongress.gov
- SonicWall SMA1000 2nd Zero-Day: CVSS 10.0 Flaw [2026]Tech Insider
- Hackers exploit RouterOS flaws to hijack MikroTik devices ...HelpNetSecurity
- MikroTik RouterOS vulnerabilities expose 122500 routersCybernews
- MikroTrick: Chained MikroTik RouterOS Flaws Bypass SSH ...Cloud Security Alliance Labs
- Exploit chain for SonicWall SMA1000 zero-days (X post)Stephen Fewer
- QILIN Ransomware Gang: 4 New Victims PostedSecurity Arsenal
- SonicWall SMA1000: Patch and Check for CompromiseQuasa
- Daily OT Security News: September 07, 2026Security Boulevard
- Federal Banking Regulatory Agencies Issue Guidance on Crypto-Asset SafekeepingMcGuireWoods
- SonicWall SMA1000 RCE Vulnerability: Patch NowDIESEC
- Daily OT Security News: September 06, 2026Security Boulevard
- Stop Rogue AI Act coverage (multi-language series)Quasa
- Two SonicWall SMA 1000 zero-days are being exploited right nowSecure in Seconds
- What the 2025–2026 Attacks Reveal About Industrial Cyber Risk4m4.it
- Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”Security Affairs
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH ...The Hacker News
- Did the BlackByte ransomware attack the city of Augusta?SECnews
- SonicWall's CVE-2026-83549 Was Exploited in 1 Days — Well Under Its 197-Day MedianCVEDaily
- Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (MikroTrick)CERT Polska / Threadlinqs Intelligence
- Cisa Issues Emergency...Security Boulevard
- Stop Rogue AI Act: Enterprise Agent Security (2026)Integrated.social
- Bipartisan House Bill Targets Rogue AI Agents Following High-Profile OpenAI BreachesTechstrong.ai
- CVE-2026-67279Tenable
- 米国の水道PLCがハッカーに乗っ取られFBIが水圧低下と浸水を警告Pasquale Pillitteri
- H.R. 10207, Child Privacy Protection Mandate. Quorum's AI analysis reads it as a net benefit — and names who…Quorum Civic
- CRI2026 - CYBERSECURITY FOR SMALL BUSINESSES ACTGovInfo (U.S. Government Publishing Office)
- H.R. 10284, Consumer Data Privacy Protection. Quorum's AI analysis reads it as a net benefit — and names who…Quorum Civic
- How Often Should You Do Penetration Testing? (2026)Stingrai
- Hackers hijack US water utility PLCs as FBI reports lost pressure and floodingPasquale Pillitteri
- What Is AI Security in Financial Services?Uptiq
- FTC Safeguards Rule (GLBA): Financial Data SecurityVibgrate
- UAE, Egypt central banks say Banque Misr UAE branches continue operations as usual - Economy - BusinessAhram Online
- Cybersecurity report – 2026Board of Governors of the Federal Reserve System
- Securing digital financial assets from AI-driven fraudFederal Reserve Bank of Dallas
- DaVita Reaches Preliminary Settlement Class Agreement Following Ransomware Attack - DaVita (NYSE:DVA)Benzinga
- Ormond Beach Ransomware: 5 Critical Facts for Local GovernmentsNextekit
- SonicWall's CVE-2026-83548 Was Exploited in 1 Days — Well Under Its 197-Day MedianCVEDaily
- Daily OT Security News: September 04, 2026Security Boulevard
- Yet Another Law Hiding Mandatory Age Verification Behind Child Safety? The RESET Act MarkupAll About Cookies
- Google security advisory (AV26-883) – Update 1Canadian Centre for Cyber Security
- Health Information Privacy Reform Act: HIPRA Rules ExplainedRiddle Compliance
- El ransomware crece 25.5% en América Latina y México concentra 17.93% de los ataquesRadioUno911 / SCILabs
- Riley bill would curb sale of smart meter dataThe Daily Star
- Riley bill would restrict utility sales and sharing of smart-meter dataFingerLakes1.com
- A New Bill Would Extend Health Privacy Law to Your Phone. The Hard Part Comes Next.Petrie-Flom Center, Harvard Law School
- McGovern Introduces Big Tech Accountability Act on Privacy and Online ContentQuiver Quant
- Neues US-Gesetz Soll Jeden KI-Agenten Erfassen - SERVOLAServola
- Letter from the FSB Chair to G20 Finance Ministers and Central Bank Governors (August 2026)Financial Stability Board
- Critical SonicWall SMA 1000 Zero-Day Vulnerabilities ...Triskele Labs
- City of Ormond Beach Data Breach in 2026Breachsense
- LockBit ransomware: Claimed responsibility for cyberattack on Wichita citySECnews
- Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin AmericaPalo Alto Networks Unit 42
- Iranian hackers threaten attacks on US critical infrastructureNational Security News
- Explaining data brokerPPC Land
- H.R. 10284: Smart Meter Data Privacy Protection ActQuiverQuant / BillBoard
- Five Healthcare Providers Report Ransomware-Related Data BreachesHIPAA Journal
- DaVita agrees to pay $15M to settle claims from data breachMedTech Dive
- NYDFS 23 NYCRR 500: NY Financial Cybersecurity RuleVibgrate
- FFIEC Information Security Guidance for BanksVibgrate
- 153M Licenses Breached: IDV Vendor Audit Gaps ExposedCommerce Security Authority
- HR 10284 | Smart Meter Data Privacy Protection Act | Politically.comPolitically.com
- H.R.7885 - Cybersecurity Skills Integration ActCongress.gov
- Lawmakers unveil new bill to secure AI agents after ...Yahoo News
- Bipartisan bill directs NIST to set AI agent security standardsScand.ai
- Stop Rogue AI Act announcement and bill summaryLawler.house.gov
- HR 10207 | AI Law TrackerAI Law Tracker
- To prohibit covered platforms from processing personal ... - PravetaPraveta
- Smart Meter Data Privacy Protection Act (HB 10284)Digital Policy Alert
- CISA Warns of SonicWall SMA1000 Vulnerabilities Active ExploitationQualys Threat Research
- Cyber Threat Brief — September 3 2026AJ King
- INCRANSOM Ransomware Gang: 11 New Victims in 5 Days, Manufacturing and Healthcare Surge, Detection Rules InsideSecurity Arsenal
- 7 Ways the U.S. Is Trying To Defend Its Water System From HackersFoundation for Defense of Democracies (FDD)
- CIRCIA Is Almost Here - LBT Technology GroupLBT Technology Group
- The Senate Rewrote HIPRA: AI Training Data Under HHS ...Sahha.ai
- [NEW] [high] JFrog Artifactory: Vulnerability allows obtaining administrator privilegesCSIRTs.com
- Iranian hackers targeted US infrastructure in recent weeks - NBC NewsIran International
- Suspicious Activity Reporting: Joint Statement on ... - OCC.govOCC
- Iran attempted cyberattacks on range of U.S. infrastructure, sources sayNBC News
- İran bağlantılı hackerlarin, ABD'deki kritik altyapılara saldırı girişimlerinde bulunduğu iddia edildiAnadolu Agency
- CISA Incorpora 7 Fallos Críticos Al Catálogo KEV 2026CybersecureFox
- CR extends cyber info sharing law through DecemberFederal News Network
- How consumers can protect themselves from AI scams, deepfakes, and voice cloningTotal Defense
- Irán lanzó ciberataques contra sistemas de energía y comunicaciones de EE.UU., según reportesEl Diario NY
- SonicWall PSAIRT vulnerability details for SonicWall SMA1000SonicWall
- Known Exploited Vulnerabilities CatalogCISA
- Unsafe or Unsound Practices; Matters Requiring Attention (FDIC Final Rule)Federal Register
- マイクロソフトが支持表明、米下院でクラウド「秘密命令」改革法案を可決SBbit
- KRYBIT Ransomware Gang: 14 Victims Posted in Single Day Surge — Cross-Sector Campaign Analysis and Detection EngineeringSecurity Arsenal
- SonicWall SMA 1000 zero-days demand compromise ...Security.io
- Nutex Health Data Breach: Edelson Lechtzin LLP Investigates Theft of Patient and Employee DataMorningstar / PR Newswire
- Bulletin de sécurité JFrog (AV26-867)Canadian Centre for Cyber Security
- CVE-2026-82329: Bypass de Autenticación Crítico en JFrog Artifactory Explotado ActivamenteCiberPlaneta
- CVE-2026-81578 y CVE-2026-82078: cadena crítica de ataque en PaperCut NG/MF explotada activamenteCiberPlaneta
- Explotación Activa de Omisión de Autenticación en JFrog Artifactory (CVE-2026-82329)Devel.group
- CISA Adds Two Known Exploited Vulnerabilities to CatalogCyber Experts
- Proposal of Special Measure Regarding Banque Misr UAE as a Financial Institution Operating Outside of the United States of Primary Money Laundering ConcernFederal Register (compilación no oficial)
- FFIEC Expectations Every Financial-Services Board Should ...Tyson Martin
- Extraoficial: reportan ataque en sistema informático del Incan que afecta a pacientesLa Hora
- WALLSTREET Ransomware: US Healthcare and Education Victims Posted on Leak SiteSecurityArsenal
- September 2, 2026 Cybersecurity News SummaryNote.com (centervil)
- The Gentlemen come calling as Nutex confirms sensitive data theftThe Register
- Malware com inteligência artificial mira aplicativos de banco na América LatinaTecMundo
- Stopgap funding bill temporarily extends key cyber info-sharing lawNextgov
- Cadena hospitalaria de EEUU confirma brecha de datos y robo de informaciónNivel4
- What to Learn from the Cyberattacks on U.S. Water SystemsBPM.com
- Senate committee advances privacy bill for non-HIPAA health dataPaubox
- Daily OT Security News: September 1, 2026Security Boulevard
- AI Deepfake Scams Are Draining the Remittances Latino Families Send Home — Here's How to Fight BackLatin Times
- Malicious Cyber Actors Gain Access to Victim Accounts Through Phishing CampaignFBI Internet Crime Complaint Center
- House Passes Stopgap Funding Bill With Key Tech Program ExtensionsMeriTalk
- uicc.org data breach — Krybit ransomware leak (2026)Darkfield (Orizon)
- Ransomware Group krybit Hits: tum.com.mxHookPhish
- tum.com.mx data breach — Krybit ransomware leak (2026)Darkfield (Orizon)
- Krybit Ransomware Impacts TUM Transportistas Unidos MexicanosDexpose
- Healthcare cyberattacks hit pacemakers and millions of patient recordsThe Register
- Iran Cyber Risk Climbs as US Resumes StrikesBankInfoSecurity
- PaperCut RCE Chain Requires Emergency Patch Release 2WindowsForum
- CVE-2026-81578 & CVE-2026-82078: PaperCut NG/MF Added to CISA KEV Detection and Remediation GuideSecurity Arsenal
- PaperCut NG/MF CVE-2026-81578: Patch Now, Exploited in Wildforsmile.jp
- Por qué el país más rico del mundo no puede defender sus infraestructuras vitalesABC
- Experts: Water Cyber Attacks Had Scale, Not SophisticationGovTech
- Huntress detecta explotación activa de la vulnerabilidad de PaperCutMoncloa
- JFrog security advisory (AV26-867)Canadian Centre for Cyber Security
- TikTok multado em R$ 153 milhões pela ANPD por violar la LGPDAgência Mestre
- OCC and FDIC Release Final Rules on "Unsafe or Unsound Practices" in Banks: MRA Thresholds and Practice ChecklistAiying License & Compliance
- Infostealer su workstation attaccante espone campagna Blind EagleDeafNews
- Blind Eagle GitHub Loader (AsyncRAT/DcRat/XWorm) ...Security Arsenal
- Ransomware Group Wallstreet Hits: Cedar County Memorial HospitalHookPhish
- Victim: Cedar County Memorial Hospital – WallstreetRansomware.live
- Cedar County Memorial Hospital: Unconfirmed Breach Claims & DoxxScan RatingRecentBreaches
- Cedar County Memorial Hospital Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- NDO Fairness Act of 2025 (HB 6048)Digital Policy Alert
- H.R.6048 — NDO Fairness Act, as amended | AI Policy BriefThe Capitol Wire
- House To Markup Six Bills On Tech Security ThreatsLegis1
- CONGRESSIONAL RECORD—HOUSE H5268 (debate NDO Fairness Act)Congress.gov / Congressional Record
- TikTok Agrees to $400 Million Settlement in U.S. Child Privacy CaseGRC Report
- Wallstreet Strikes Cedar County Memorial HospitalDexpose
- Healthcare company McKesson discloses cyberattack after third-party app breachHelp Net Security
- Deep dive into the Boston Scientific cyberattackShieldWorkz
- House passes historic reforms to rein in secret surveillanceMicrosoft
- Brazil Sues Discord Over Child-Safety Failures and $97 Million ClaimGround News
- Credit Union & Community Bank Cyber Incident Report 2026BlueRadius
- Plataformas de Gobernanza de IA: Comparativa para organizacionesSoberania.io
- Global Cyber Threats: Infrastructure Attacks, Ransomware Surge, and Zero-Day ExploitsNetSecOps
- Hackers secuestran información del Incán, exigen dinero y afectan radioterapias de 194 pacientes con cáncerPrensa Libre
- Victim: Northwest Trophy – thegentlemenransomware.live
- Markup of 6 Bills, Subcommittee on Communications and TechnologyHouse Energy and Commerce Committee (Democrats)
- Oilquip Inc data breach — Incransom ransomware leak (2026)Darkfield (Orizon)
- Oilquip Inc Listed by INC Ransom Ransomware GroupGalaxyWarden
- Entrevista: 'Mostramos que a conversa com as big techs tem um limite', diz presidente da ANPDO Globo
- S.4564 - Maritime Cybersecurity Act, 119th Congress (2025-2026)Congress.gov
- wittmann — INCRANSOM Ransomware Attack | Breach HouseBreach House
- Northwest Trophy Listed by The Gentlemen Ransomware ...Galaxy Warden
- Sanção ao TikTok é alerta a outros apps, diz presidente da ANPDPoder360
- Northwest Trophy: Unconfirmed Breach Claims & DoxxScan™ RatingRecentBreaches
- The OCC and FDIC Just Defined 'Unsafe or Unsound' for the First Time. What the New MRA Standard Means for Your Bank.RiskTemplates
- Iranian-linked hackers expand attacks on critical systemsPaubox
- Ruby Seven Studios Data Breach in 2026BreachSense
- Ransom! Northwest Trophy (AUG-2026)Hendry Adrian
- THEGENTLEMEN Ransomware Gang: 16 Victims Posted in 48 Hours — Sector Targeting Analysis and Detection RulesSecurity Arsenal
- 미 재무부 양자 태스크포스, 디지털자산도 점검TokenPost
- FinCEN Alert: BSA Compliance Implications Related to the Mexican Cartels Fiscal Fuel SchemeMoney Laundering Watch
- US Treasury Launches Task Force to Coordinate Financial Sector Quantum TransitionA-Team Insight
- Treasury Launches Quantum Task Force for Financial SectorGovInfoSecurity
- US denies access to China-linked group behind hacking federal agenciesSC World
- US officials revise claims that government agencies were hacked by ChineseReuters
- EE.UU. matiza impacto de ciberataques chinos a sus agenciasTVN Chile
- FBI y Justicia de EE.UU. desarticulan una red de espionaje chino que comprometió infraestructura crítica desde 2018Moncloa.com
- O Tiktok finalmente paga por seus abusos: o ECA Digital mostra a que veioO Globo (Blog Daniel Becker)
- Brazil sues Discord over alleged shortcomings in youth safety policies and enforcementJURIST
- ANPD afirma que Meta discutirá proteção infantil no BrasilSBT News
- Depois de multar TikTok em R$ 153,7 milhões, AGU processa Discord por R$ 500 milhõesRealNacional.ai
- Brazil fines TikTok record US$30 million for profiting from children's dataThe Star
- Why Brazil fined TikTok $30 million over children's data protection failuresBrazil Reports
- Valley Health Team: Unconfirmed Breach Claims & DoxxScan RatingRecentBreaches
- Victim: Valley Health Team – Rhysidaransomware.live
- RaaS gang Anubis claims Signature Healthcare data theftGovernment Information Security
- Ransomware Alert: Valley Health Team ...FalconFeeds.io
- Iran-Linked Actors Hit UK Power and US Water SystemsCloud Security Alliance
- RST Cloud en X: #threatreport #HighCompleteness Caught in 4K: The Aurora FilesRST Cloud
- Aurora Ransomware Affiliate Exposed Using AI Attack PlanningInside Telecom
- Critical infrastructure's long, undefended tail exposed by UK energy attackCSO Online
- Federal authorities disrupt China-backed hacking ...Cybersecurity Dive
- Ruby Seven Studios Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- CISA: более 100 систем водоснабжения в США атакованы в июле 2026Techora
- Ruby Seven Studios Listed by incransom Ransomware GroupGalaxyWarden
- Victim: Ruby Seven Studiosransomware.live
- Bencivil Listed by incransom Ransomware GroupGalaxyWarden
- Discord enviou 3 versões de propostas para tentar acordo com a AGU antes de processoFolha de S.Paulo
- Bencivil Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- Unsafe or Unsound Practices and Matters Requiring Attention: Final RuleOffice of the Comptroller of the Currency (OCC)
- Understanding Brazil's $29.7 Million TikTok Fine Over Children's DataTech Policy Press
- INCRANSOM Ransomware Gang: 5 New Victims Posted — Manufacturing and Energy Targeting Analysis with Detection RulesSecurity Arsenal
- EMPERADOR Ransomware Gang: 4 New Victims Posted — Energy Sector Targeting, Edge Device Exploitation and Detection RulesSecurity Arsenal
- US bank regulators finalize rules defining 'unsafe and unsound' practicesReuters
- Agencies Issue Final Rule to Prioritize Material Financial Risks (NR-IA-2026-71)Office of the Comptroller of the Currency
- Discord Faces $97M Suit in Brazil: Platform Took Two Hours to Remove Teen's Suicide LivestreamTech Times
- Brazil sues Discord for $100 mn in child safety caseThe Sun Daily
- FFIEC IT Examination Readiness AssessmentsLazarus Alliance
- Vendor Risk Management Doesn't Get Its Own Exam AnymoreMitratech
- LOCKBIT5 Ransomware: 5 Victims Posted in 24 Hours — Healthcare & Tech Sector Surge with Detection RulesSecurity Arsenal
- Cyberattack Halts Boston Scientific's Global Operations – AlertHamerIntel
- NSA, CISA, FBI, and EPA Issue Urgent Advisory on Active Siemens PLC ThreatMaryland Rural Water Association
- Update on recent cybersecurity incidentBoston Scientific
- US officials revise claims that government agencies were hacked by Chinese, now say they were targetsInternazionale / Reuters
- DOJ corrige sus declaraciones sobre el hackeo chinoInvestx.fr
- KRYBIT Ransomware Gang: 13 Victims in 48 HoursSecurity Arsenal
- FBI, DOJ announce disruption of China-linked hacking group targeting hospitals and other critical infrastructureAmerican Hospital Association
- NewsBites Volume XXVIII – Issue 64 August 28, 2026SANS NewsBites
- More than 100 water systems were hit in July cyberattacksThe Register
- CISA、7月に100超の水道システムが標的に — インターネットに露出したPLCを直接狙う攻撃で露出削減ガイダンスを更新NEXSIGHT CYBER WIRE
- Nutex Health Reports Breach but Tells Investors It Sees No Material HarmTechTimes
- Los atacantes aprovechan el uso continuo de herramientas de IA para atacar organizaciones en América LatinaPalo Alto Networks Unit 42
- Victim: wmiemporium.comransomware.live
- McKesson discloses breach after ShinyHunters claims patient data theftBleepingComputer
- Radar de Privacidade HDPO — Edição 18HDPO
- Cyberattack on Boston Scientific causes global ops disruptionpharmaphorum
- Quantum Readiness: A Dependency Challenge for FinanceDigital Compliance Bureau
- FBI, Coast Guard probe suspected cyberattacks on ships entering US watersSupplyChain Dive
- US Coast Guard boarded a Texas-bound oil tanker to investigate a cyberattack, Bloomberg News reportsReuters
- Coast Guard, FBI boarded Texas-bound oil tanker after cyberattack concernsCBS News
- Cyberattacks on Oil Tankers Put Maritime Critical Infrastructure at RiskSecurity Affairs
- Port of LA Foiled Around 120 Million Cyberattacks Last MonthBloomberg
- Telehealth & Cybersecurity Threats: What to KnowIEEE Standards Association
- Iran hackers claim responsibility for North Texas internet outage that affected thousands, AT&T refutes claimWFAA
- Iranian hackers claim AT&T outage attack. AT&T has a different story.Chron.com
- Ransomware атаките поставиха нов месечен рекорд през август 2026 г.e-security.bg
- Luminis cybersecurity incident highlights 'concerning' rise in attacks ...The Daily Record
- Why Cybersecurity Is Now a Healthcare Security PriorityHealthcare.digital
- The Hugging Face Incident, Explained for HealthcareOnHealthcare.tech
- Newsroom - Maryland Department of HealthMaryland Department of Health / The Daily Record (referenciado)
- Paradoja digital en América Latina: millones de personas la usan sin saber cómo funcionaONU Noticias
- From Internet Exposure to Operational Disruption: A Red Team View of Connected InfrastructureCobalt.io
- ハッキング集団、Cedar County Memorial Hospitalへの攻撃を主張Black Hat News Tokyo
- Why Cybersecurity Is Now a Healthcare Security Priorityhealthcare.digital
- Global Ransomware Attacks Hit Record High as August Sees 997 IncidentsNewsAffinity
- Ransomware attacks in September 2026: 49 confirmed incidentsRansomnews
- Beyond the ransomware: Tracking Storm-2570's consistent tradecraft across deploymentsMicrosoft
- Foreign actors hacked small Colorado water utilities last monthThe Denver Post
- Two US-bound vessels apparently compromised by hackers, US officials sayReuters
- NewsBites XXVIII Issue 67SANS Institute
- September 2026 Patch Tuesday: Updates and AnalysisCrowdStrike
- Suspected state-sponsored hackers exploited NetScaler vulnerabilities as zero-daysHelpNetSecurity
- Security Advisory – Action Required – Active Exploitation of CVE-2026-85102 and a Management Pre-Authentication Vulnerability CVE-2026-93616Check Point
- Patch Tuesday September 2026: CVE AnalysisAutomox
- September 2026 monthly rollup (AV26-896) – Update 1Canadian Centre for Cyber Security
- Sept 28 Advisory: Citrix NetScaler ADC and NetScaler Gateway (CVE-2026-88771, CVE-2026-88772)Censys
- Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772Palo Alto Networks Unit 42
- NetScaler attacks: Zero days reported exploitedThe Stack
- Citrix confirms two NetScaler RCE zero-days exploited in attacksBleepingComputer
- Citrix NetScaler vulnerabilities (CVE-2026-88771, CVE-2026-88772) in active exploitationSophos
- Coast Guard, FBI investigating after 2 oil tankers bound for US reported cyberattacksABC News
- EEUU abordó un buque con bandera extranjera para investigar un posible ciberataque de actores extranjerosEuropa Press
- Citrix Confirms 2 NetScaler Zero-Days After Admins Pulled the PlugSecurityWeek
- Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler GatewayUK National Cyber Security Centre
- Citrix urges immediate upgrades of NetScaler amid active exploitationCybersecurityDive
- NetScaler admins told to patch critical zero-days in ADC and Gateway nowNetworkWorld
- Citrix patches actively exploited NetScaler zero-days after delayed disclosureCyberScoop
- Hackean el portal de empleo del FBI y filtran datos sensibles de 5.000 agentesInfobae
- La semana en brechas de seguridad 30 de septiembre de 2026Kaseya
- Major Cyber Attacks, Data Breaches, Ransomware Attacks – September 2026CM-Alliance
- El sistema de IA de OpenAI accedió por su cuenta y sin autorización a portales oficiales del Gobierno de Estados UnidosEl País
- CISA alerts of active exploitation of three Linux kernel flawsBleepingComputer
- CISO Daily Briefing – September 20, 2026Cloud Security Alliance
- CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacksBleepingComputer
- CISA Cyber tweet sobre CVE-2026-65660 y CVE-2026-67279CISA Cyber (X)
- CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler FlawsThe Hacker News
- CISA issues urgent alert about vulnerabilities in remote access technology used by businessesABA Banking Journal
- CISA KEV Adds Two Exploited Windows Privilege Escalation FlawsWindowsForum
- CalPrivacy Continues Enforcement Blitz with Action Against Virginia Data BrokerCalifornia Privacy Protection Agency (CalPrivacy)
- State Privacy Law Enforcement: AG Actions & ViolationsMultiState
- Right To Know - September 2026, Vol. 45 | Clark Hill PLCClark Hill PLC
- Internet privacy updates: CalPrivacy fines data brokers, Colorado proposes new AI regulationsNorton Rose Fulbright
- Tech bills of the week: Creating an AI-focused agency, reviewing AI-assisted cyber attacks and moreNextgov
- The BR Privacy, Security & AI Download: September 2026 - Blank Rome LLPBlank Rome LLP
- Privacy & Cybersecurity Law Blog (September 2026)Hunton Andrews Kurth LLP
- CISA Adds Four Known Exploited Vulnerabilities to CatalogCISA
- CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets ...The Hacker News
- CISA orders urgent patches for three exploited Linux flawsDataconomy
- CISA Flags Three Actively Exploited Linux Kernel Flaws ...TechTimes
- U.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalogSecurityAffairs
- ALERTA 90/2026Gobierno de Brasil (CTIR)
- U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalogSecurityAffairs
- CVE & Vulnerability TrackerTechTimes
- U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws ...SecurityAffairs
- Monthly Cyber Threats Report - Issue 21 | September 2026Mishcon de Reya
- CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto MinersThe Hacker News
- Three-of-Seven CISA KEV Additions Now Target AI InfrastructureYahoo Tech
- Weekly Cyber Alert Report: 2nd Week of September 2026note.com (zsecurity)
- Delaware Men Sentenced for Cyber Intrusion Scheme Targeting Victims in Southern District of IowaU.S. Department of Justice – U.S. Attorney's Office, Southern District of Iowa
- Former US Air Force members behind million-dollar BEC and phishing scams sentencedHelp Net Security
- ShinyHunters hackers say they stole psychiatric and medical records of FBI staffReuters
- Victim: Gibson Area Hospital & Health Servicesransomware.live
- Sitio institucional de Gibson Area Hospital & Health ServicesGibson Area Hospital & Health Services
- Two Dover Air Force Base members sentenced in international cyber fraud schemeWBOC
- Delaware men sentenced in wire fraud scheme targeting Iowa victimsDes Moines Register
- 2 Delaware men arrested for cyber intrusion scheme targeting Iowa victimsYahoo News
- Two former Air Force members sentenced for BEC scams and phishingSC World
- Two Former Airmen Sentenced in Cyber Scheme That Targeted Iowa VictimsKILJ Radio
