Skip to content
Auto-CTI

What has changed?

Comparing 12 September 2026 with the previous day 11 September 2026.

Newly added

10
NEW C3
17

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

Bundling several already-patched zero-days into a circulating exploit kit lets even less skilled espionage-motivated actors exploit them, making the window between patch availability and patch deployment the decisive risk factor.

High
NEW Armored Likho, Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore) B3
0

Threat landscape for industrial automation systems. Q2 2026

The report provides a quarterly overview of the threat landscape for industrial automation systems and documents new APT malware attributed to Mirage Kitten, which is strategically relevant for production environments.

Medium
NEW A3
0

Google Chrome: Multiple Vulnerabilities

The report summarizes multiple vulnerabilities in Google Chrome without specific CVEs or exploit details; timely patch management remains necessary.

Medium
A3
0

7-Zip: Vulnerability allows code execution

The vulnerability requires user interaction and affects widely used compression software installed in many corporate environments; a CVE ID is not yet available.

Medium

Newly KEV-listed

0

No changes in this category.

Score moved

0

No changes in this category.

No longer in report

41
NEW C3
100

Check Point Patches Critical VPN Vulnerabilities

The alert provides no details on active exploitation, affected versions, or patch urgency , it is a generic patch announcement without context on threat activity or deployment timeline.

Critical CVSS 9.8 EPSS 0%
NEW A2
91

CVE-2026-80469

The vulnerability requires user interaction to upload a malicious driver and is not documented in active attack scenarios to date.

Critical CVSS 8.3 EPSS 0%
NEW Russia-linked cyber-espionage group C3
80

Anthropic caught Russia-linked spies using Claude in hacking operations

Russian state-linked actors are weaponizing commercial AI tools like Claude for targeted cyber-espionage against Western government and defense organizations, signaling strategic escalation of hybrid warfare with DACH implications.

Critical
NEW A2
74

CVE-2026-77490

Pure vulnerability report with no indication of active exploitation, PoC, or attacker TTPs.

High CVSS 6.1 EPSS 0%
NEW Russian-speaking threat actor (unattributed; associated with GreyNoise intelligence) C3
20

PaperCut Flaws Exploited in AI-Powered Attacks

A Russian threat actor group is using AI-generated exploits to automate and scale attacks against hundreds of PaperCut instances worldwide, combined with active post-exploitation for remote code execution and credential harvesting.

High
A3
20

[UPDATE] GNU libc: Multiple Vulnerabilities

The BSI advisory describes multiple vulnerabilities in GNU libc without specific CVE numbers, which may indicate coordinated disclosure or an incompletely documented vulnerability series.

High
NEW A3
20

Intel Processor: Multiple Vulnerabilities

BSI warns of multiple Intel processor vulnerabilities with high risk for local privilege escalation and data loss; specific CVE details are missing from this generic advisory.

High
NEW A3
20

Microsoft Edge: Multiple Vulnerabilities

BSI warns of multiple, partly critical vulnerabilities in Microsoft Edge with potential for code execution and data leaks; exploitation requires user interaction in some cases but remains practical.

High
A3
20

Ubiquiti UniFi: Multiple Vulnerabilities

The BSI report summarises several vulnerabilities in Ubiquiti UniFi but provides no CVE IDs or affected versions, so the vendor advisories are needed for specifics.

High
NEW A3
0

CVE-2026-80981

There is no evidence of active exploitation, threat actors, or strategic implications; the report describes only a single kernel vulnerability with an available patch.

Medium EPSS 0%
NEW A3
0

CVE-2026-89575

Pure patch information with no indication of active exploitation or strategic relevance.

Medium EPSS 0%
NEW A3
0

CVE-2026-89761

The vulnerability is a local out-of-bounds write in the AppArmor parser that can be triggered via /proc/self/attr/apparmor/current, but requires loaded AppArmor profiles and has not been actively exploited so far.

Medium EPSS 0%
NEW A3
0

CVE-2026-89762

The report contains no information beyond the patch details regarding active exploitation, attackers, or affected sectors.

Medium EPSS 0%
NEW A3
0

CVE-2026-89770

The report contains no insights beyond patch information, as it is a pure NVD entry with no indication of active exploitation.

Low EPSS 0%
ESC