The Daily Zero-Day

Date: SEPTEMBER 22, 2026 Editor-in-Chief: Jose Laurentino III Global Threat Intelligence Edition

Executive Summary

Today's intelligence briefing for September 22, 2026, highlights a massive expansion in global cyber threats, ranging from state-sponsored APT campaigns and software supply chain intrusions to sophisticated AI-weaponized attacks and major data breaches. Notably, Microsoft has plugged nearly 1,000 vulnerabilities in its largest update cycle to date, while attackers continue to exploit generative AI assistants, deploy infostealers, and target critical infrastructure, academic institutions, and financial networks worldwide.

Top Intelligence Briefings

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. issued massive updates addressing at least 974 security holes across its Windows operating systems and other software products, marking by far the company's single largest vulnerability remediation cycle to date.

Actionable Takeaway: Prioritize immediate patching across all Windows environments, focusing on actively exploited vectors and high-severity RCE flaws included in this historic patch batch.

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

The notorious threat actor SideCopy has expanded its strategic focus, deploying spear-phishing lures embedded with ReverseRAT to target academic and research institutions across India.

Actionable Takeaway: Educate academic staff on advanced spear-phishing tactics and monitor network perimeters for anomalous outbound tunneling and ReverseRAT communication signatures.

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

Security researchers discovered that pre-existing malware running locally on a Mac can quietly hijack Meta's Muse assistant, leveraging broad user-granted permissions to convert the AI tool into a persistent system backdoor.

Actionable Takeaway: Audit endpoint permissions granted to local AI assistants and deploy robust EDR solutions to intercept local malware before it can leverage integrated assistant privileges.

ShinyHunters Hacked Clop. Now What About Clop's Victims?

In a dramatic twist within the cybercriminal underworld, ShinyHunters successfully defaced Clop's dark web leak site and claimed to have exfiltrated proprietary victim data, risking secondary extortion for organizations that previously paid ransoms.

Actionable Takeaway: Organizations previously impacted by Clop ransomware should re-evaluate their risk profiles and prepare for potential secondary leaks or extortion attempts by ShinyHunters.

Reverse-Engineering Flock Cameras

Security researchers and hackers successfully captured and reverse-engineered a Flock automated license plate reader camera, unmasking proprietary internal software architectures and shedding light on how the company tracks vehicles.

Actionable Takeaway: Municipalities and law enforcement agencies utilizing automated surveillance tech should account for exposed hardware vulnerability footprints and proprietary tracking logic.

Sources & References

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
https://thehackernews.com/2026/09/sidecopy-broadens-india-targeting-to.html

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html

Data Broker Radaris Loses Domains in Privacy Fight
https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/

Microsoft Plugs Nearly 1,000 Security Holes
https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/

Reverse-Engineering Flock Cameras
https://www.schneier.com/blog/archives/2026/09/reverse-engineering-flock-cameras.html

Friday Squid Blogging: On Squid Egg Sacs
https://www.schneier.com/blog/archives/2026/09/friday-squid-blogging-on-squid-egg-sacs.html

How AI Agents Can Trigger Runaway Costs for Enterprises
https://www.darkreading.com/application-security/how-ai-agents-can-trigger-runaway-costs

ShinyHunters Hacked Clop. Now What About Clop's Victims?
https://www.darkreading.com/cyberattacks-data-breaches/shinyhunters-hacked-clop-what-about-clops-victims

Student Loan Breach Exposes 2.5M Records
https://threatpost.com/student-loan-breach-exposes-2-5m-records/180492/

Watering Hole Attacks Push ScanBox Keylogger
https://threatpost.com/watering-hole-attacks-push-scanbox-keylogger/180490/

The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive
https://www.welivesecurity.com/en/business-security/smb-cybersecurity-squeeze-ai-agents-work-old-attacks-overdrive/

‘Nudify’ apps: What to do if someone makes a fake nude of you
https://www.welivesecurity.com/en/privacy/nudify-apps-fake-nude-you/

Should you care about an “AI slowdown?”
https://blog.talosintelligence.com/should-you-care-about-an-ai-slowdown/

Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use
https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/

The AI plot to scan and destroy books (Lock and Code S07E19)
https://www.malwarebytes.com/blog/podcast/2026/09/the-ai-plot-to-scan-and-destroy-books-lock-and-code-s07e19

The fake sites using a cheap toolkit to sell $2,000 AI subscriptions
https://www.malwarebytes.com/blog/threat-intel/2026/09/the-fake-sites-using-a-cheap-toolkit-to-sell-2000-ai-subscriptions

LimeLeads - 17,838,396 breached accounts
https://haveibeenpwned.com/Breach/LimeLeads

Burger King Russia - 3,155,792 breached accounts
https://haveibeenpwned.com/Breach/BurgerKingRussia

ISC Stormcast For Tuesday, September 22nd, 2026
https://isc.sans.edu/podcastdetail/10104

TerminalFix: PNG Steganography
https://isc.sans.edu/diary/rss/33318

Transforming Bedrock Guardrails events into OCSF with CloudWatch
https://aws.amazon.com/blogs/security/transforming-bedrock-guardrails-events-into-ocsf-with-cloudwatch/

Run open weight models on Amazon Bedrock in AWS European Sovereign Cloud
https://aws.amazon.com/blogs/security/run-open-weight-models-on-aws-bedrock-in-aws-european-sovereign-cloud/

Chatbot Conundrum: Phishing Attempts of OpenAI’s ChatGPT
https://cofense.com/blog/chatbot-conundrum-phishing-attempts-of-openai-s-chatgpt

False Allegations, Real Threats: Sexual Misconduct Claims Used as Phishing Lures
https://cofense.com/blog/false-allegations,-real-threats-sexual-misconduct-claims-used-as-phishing-lures

August 2026 Infostealer Trend Report
https://asec.ahnlab.com/en/95519/

August 2026 Threat Trend Report on APT Groups
https://asec.ahnlab.com/en/95478/

Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor

Fake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams
https://www.bitdefender.com/en-us/blog/labs/fake-shops-europe-samsung-world-cup-scams

Group of Bipartisan Lawmakers Ask US Government to Ban Several Hack-for-Hire Firms
https://citizenlab.ca/group-of-bipartisan-lawmakers-ask-us-government-to-ban-several-hack-for-hire-firms/

U.K. Supreme Court Opens Door for Spyware Victims to Sue Foreign States
https://citizenlab.ca/uk-supreme-court-opens-door-for-spyware-victims-to-sue-foreign-states/

Vulnerabilities in WNC T-Mobile 5G Box IDU routers
https://cert.pl/en/posts/2026/09/CVE-2026-40854/

Vulnerabilities in Alior Bank "raty" module for PrestaShop
https://cert.pl/en/posts/2026/09/CVE-2026-7848/

CIS Community Defense Model v3.0: Turning Threat Intelligence Into Action
https://www.cisecurity.org/insights/blog/cis-community-defense-model-v3-turning-threat-intelligence-into-action

CIS Benchmarks September 2026 Update
https://www.cisecurity.org/insights/blog/cis-benchmarks-september-2026-update

Multiple Vulnerabilities in Oracle Products Could Allow for Arbitrary Code Execution
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-oracle-products-could-allow-for-arbitrary-code-execution_2026-097

Multiple Vulnerabilities in Cisco Secure Email Products Could Allow for Remote Code Execution
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-cisco-secure-email-products-could-allow-for-remote-code-execution_2026-096

Previous editions:
Fort Lauderdale, FL, September 28, 2026
Visitors since September 18th, 2026: 34,862