Skip to content
Auto-CTI

What has changed?

Comparing 10 September 2026 with the previous day 3 September 2026.

Newly added

48
NEW A3
95

German institutions compromised via TerminalFix campaign

BSI warns of an active, targeted campaign against German institutions focusing on critical infrastructure and government agencies , a sign of elevated cyber risk in the DACH region for suppliers and partners in these sectors.

Critical
NEW C3
80

EU Cyber Resilience Act to Enforce New Reporting Requirements

EU cybersecurity legislation establishes mandatory reporting obligations for actively exploited vulnerabilities within 24 hours effective immediately, signaling significant regulatory tightening for European organizations with comprehensive enforcement by December 2027.

Critical
NEW Russian-speaking APT (suspected state-sponsored) C3
80

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

A suspected Russian-speaking state actor is leveraging hundreds of AI agents to systematically exploit PaperCut instances and gain enterprise access,exemplifying state-sponsored cyber operations using advanced automated techniques.

Critical
NEW Russian-aligned espionage group; Chinese state-sponsored actors; ShinyHunters C3
80

AI lets small actors run state-level hacking campaigns, Anthropic report finds

Anthropic report demonstrates that AI tools enable smaller actors to conduct state-level hacking campaigns; documented cases include Russian-aligned espionage against 20+ organizations and Chinese exploit development, with relevance to European supply chains and critical infrastructure.

Critical
A3
20

[UPDATE] OpenSSH: Multiple Vulnerabilities

The BSI advisory covers multiple OpenSSH vulnerabilities without specifying CVE numbers or affected versions; precise identification of affected versions and exploitability status is required.

High
NEW A3
20

Ubiquiti UnifiOS: Multiple Vulnerabilities

The BSI warning documents multiple vulnerabilities in UnifiOS without specific CVE numbers; the scope and severity suggest a coordinated disclosure or ongoing patch cycle.

High
NEW A3
20

Google Chrome: Multiple Vulnerabilities

BSI alert on multiple Chrome vulnerabilities without specific CVE numbers or patch date,likely aggregate security notice for regular patch cycle.

High
NEW B3
20

Detect and disrupt AI-themed attacks with Microsoft Defender

Cyberattackers are weaponizing AI platform impersonation (ChatGPT, Copilot, Claude, DeepSeek) at scale (up to 100,000 emails per day) for phishing, credential harvesting, and malvertising, with increasing automation and Teams-based social engineering.

High
NEW Four unnamed espionage groups (nation-state or state-sponsored) C3
17

BlueMoon exploit kit turns Chrome and Windows flaws into attacks

Four espionage groups actively exploit the same BlueMoon exploit chain targeting Chrome/Windows within days of each other; all three vulnerabilities are listed in CISA's KEV catalog and are being exploited in the wild.

High

Newly KEV-listed

0

No changes in this category.

Score moved

0

No changes in this category.

No longer in report

0

No changes in this category.

ESC