Skip to content
Auto-CTI

What has changed?

Comparing 11 September 2026 with the previous day 10 September 2026.

Newly added

41
NEW C3
100

Check Point Patches Critical VPN Vulnerabilities

The alert provides no details on active exploitation, affected versions, or patch urgency , it is a generic patch announcement without context on threat activity or deployment timeline.

Critical CVSS 9.8 EPSS 0%
NEW A2
91

CVE-2026-80469

The vulnerability requires user interaction to upload a malicious driver and is not documented in active attack scenarios to date.

Critical CVSS 8.3 EPSS 0%
NEW Russia-linked cyber-espionage group C3
80

Anthropic caught Russia-linked spies using Claude in hacking operations

Russian state-linked actors are weaponizing commercial AI tools like Claude for targeted cyber-espionage against Western government and defense organizations, signaling strategic escalation of hybrid warfare with DACH implications.

Critical
NEW A2
74

CVE-2026-77490

Pure vulnerability report with no indication of active exploitation, PoC, or attacker TTPs.

High CVSS 6.1 EPSS 0%
NEW Russian-speaking threat actor (unattributed; associated with GreyNoise intelligence) C3
20

PaperCut Flaws Exploited in AI-Powered Attacks

A Russian threat actor group is using AI-generated exploits to automate and scale attacks against hundreds of PaperCut instances worldwide, combined with active post-exploitation for remote code execution and credential harvesting.

High
A3
20

[UPDATE] GNU libc: Multiple Vulnerabilities

The BSI advisory describes multiple vulnerabilities in GNU libc without specific CVE numbers, which may indicate coordinated disclosure or an incompletely documented vulnerability series.

High
NEW A3
20

Intel Processor: Multiple Vulnerabilities

BSI warns of multiple Intel processor vulnerabilities with high risk for local privilege escalation and data loss; specific CVE details are missing from this generic advisory.

High
NEW A3
20

Microsoft Edge: Multiple Vulnerabilities

BSI warns of multiple, partly critical vulnerabilities in Microsoft Edge with potential for code execution and data leaks; exploitation requires user interaction in some cases but remains practical.

High
A3
20

Ubiquiti UniFi: Multiple Vulnerabilities

The BSI report summarises several vulnerabilities in Ubiquiti UniFi but provides no CVE IDs or affected versions, so the vendor advisories are needed for specifics.

High
NEW A3
0

CVE-2026-80981

There is no evidence of active exploitation, threat actors, or strategic implications; the report describes only a single kernel vulnerability with an available patch.

Medium EPSS 0%
NEW A3
0

CVE-2026-89575

Pure patch information with no indication of active exploitation or strategic relevance.

Medium EPSS 0%
NEW A3
0

CVE-2026-89761

The vulnerability is a local out-of-bounds write in the AppArmor parser that can be triggered via /proc/self/attr/apparmor/current, but requires loaded AppArmor profiles and has not been actively exploited so far.

Medium EPSS 0%
NEW A3
0

CVE-2026-89762

The report contains no information beyond the patch details regarding active exploitation, attackers, or affected sectors.

Medium EPSS 0%
NEW A3
0

CVE-2026-89770

The report contains no insights beyond patch information, as it is a pure NVD entry with no indication of active exploitation.

Low EPSS 0%

Newly KEV-listed

0

No changes in this category.

Score moved

0

No changes in this category.

No longer in report

48
NEW A3
95

German institutions compromised via TerminalFix campaign

BSI warns of an active, targeted campaign against German institutions focusing on critical infrastructure and government agencies , a sign of elevated cyber risk in the DACH region for suppliers and partners in these sectors.

Critical
NEW C3
80

EU Cyber Resilience Act to Enforce New Reporting Requirements

EU cybersecurity legislation establishes mandatory reporting obligations for actively exploited vulnerabilities within 24 hours effective immediately, signaling significant regulatory tightening for European organizations with comprehensive enforcement by December 2027.

Critical
NEW Russian-speaking APT (suspected state-sponsored) C3
80

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

A suspected Russian-speaking state actor is leveraging hundreds of AI agents to systematically exploit PaperCut instances and gain enterprise access,exemplifying state-sponsored cyber operations using advanced automated techniques.

Critical
NEW Russian-aligned espionage group; Chinese state-sponsored actors; ShinyHunters C3
80

AI lets small actors run state-level hacking campaigns, Anthropic report finds

Anthropic report demonstrates that AI tools enable smaller actors to conduct state-level hacking campaigns; documented cases include Russian-aligned espionage against 20+ organizations and Chinese exploit development, with relevance to European supply chains and critical infrastructure.

Critical
A3
20

[UPDATE] OpenSSH: Multiple Vulnerabilities

The BSI advisory covers multiple OpenSSH vulnerabilities without specifying CVE numbers or affected versions; precise identification of affected versions and exploitability status is required.

High
NEW A3
20

Ubiquiti UnifiOS: Multiple Vulnerabilities

The BSI warning documents multiple vulnerabilities in UnifiOS without specific CVE numbers; the scope and severity suggest a coordinated disclosure or ongoing patch cycle.

High
NEW A3
20

Google Chrome: Multiple Vulnerabilities

BSI alert on multiple Chrome vulnerabilities without specific CVE numbers or patch date,likely aggregate security notice for regular patch cycle.

High
NEW B3
20

Detect and disrupt AI-themed attacks with Microsoft Defender

Cyberattackers are weaponizing AI platform impersonation (ChatGPT, Copilot, Claude, DeepSeek) at scale (up to 100,000 emails per day) for phishing, credential harvesting, and malvertising, with increasing automation and Teams-based social engineering.

High
NEW Four unnamed espionage groups (nation-state or state-sponsored) C3
17

BlueMoon exploit kit turns Chrome and Windows flaws into attacks

Four espionage groups actively exploit the same BlueMoon exploit chain targeting Chrome/Windows within days of each other; all three vulnerabilities are listed in CISA's KEV catalog and are being exploited in the wild.

High
ESC