Executive Summary
Today's edition of The Daily Zero-Day on September 25, 2026, details critical architectural flaws spanning cloud computing, AI-driven command and control frameworks, and mass enterprise patch cycles. Major developments include container isolation vulnerabilities at Cloudflare, the activation of CISA KEV entries for WSO2 and Adobe Commerce, record-breaking patch distributions from Microsoft, and sophisticated new vectors involving autonomous AI agents and evasive npm payloads.
Sources & References
Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
https://thehackernews.com/2026/09/cloudflare-fixes-flaw-that-let-one.html
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
https://thehackernews.com/2026/09/wso2-and-adobe-commerce-flaws-exploited.html
Data Broker Radaris Loses Domains in Privacy Fight
https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/
Microsoft Plugs Nearly 1,000 Security Holes
https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/
Malicious npm Packages That Evade Defenses
https://www.schneier.com/blog/archives/2026/09/malicious-npm-packages-that-evade-defenses.html
Research on Models Engaging in Genie-Like Behavior
https://www.schneier.com/blog/archives/2026/09/research-on-models-engaging-in-genie-like-behavior.html
Russia's Hybrid Cyber-Physical War in Europe Heats Up
https://www.darkreading.com/physical-security/russia-hybrid-cyber-physical-war-europe
'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
https://www.darkreading.com/application-security/salesbleed-exploits-salesforce-agents-slack-phishing
Student Loan Breach Exposes 2.5M Records
https://threatpost.com/student-loan-breach-exposes-2.5m-records/180492/
Watering Hole Attacks Push ScanBox Keylogger
https://threatpost.com/watering-hole-attacks-push-scanbox-keylogger/180490/
Looking for free Robux? Here’s what’s real, and what’s a scam
https://www.welivesecurity.com/en/kids-online/looking-for-free-robux-heres-whats-real-whats-scam/
The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive
https://www.welivesecurity.com/en/business-security/smb-cybersecurity-squeeze-ai-agents-work-old-attacks-overdrive/
Trust and the enticing consultancy offer
https://blog.talosintelligence.com/trust-and-the-enticing-consultancy-offer/
The Closed Quorum: Inside the first reported autonomous AI C2 implant
https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/
That shipping rebate offer may come with a monthly charge
https://www.malwarebytes.com/blog/threat-intel/2026/09/that-shipping-rebate-offer-may-come-with-a-monthly-charge
OpenAI agent breached Australian government site, took months to report it
https://www.malwarebytes.com/blog/ai/2026/09/openai-agent-breached-medicare-statistics-portal-then-took-months-to-report-it
LimeLeads - 17,838,396 breached accounts
https://haveibeenpwned.com/Breach/LimeLeads
Burger King Russia - 3,155,792 breached accounts
https://haveibeenpwned.com/Breach/BurgerKingRussia
A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)
https://isc.sans.edu/diary/rss/33368
ISC Stormcast For Friday, September 25th, 2026 https://isc.sans.edu/podcastdetail/10110, (Fri, Sep 25th)
https://isc.sans.edu/podcastdetail/10110
ICYMI: August 2026 @AWS Security
https://aws.amazon.com/blogs/security/icymi-august-2026-aws-security/
Supporting ASD’s multi-factor authentication campaign: Why MFA matters more than ever
https://aws.amazon.com/blogs/security/supporting-asds-multi-factor-authentication-campaign-why-mfa-matters-more-than-ever/
Cofense Expands AI-Driven Phishing Defense Platform to Advance Secure Behavior Management
https://cofense.com/blog/cofense-expands-ai-driven-phishing-defense-platform-to-advance-secure-behavior-management
Beyond Human Risk: A Better Way to Build Secure Behavior
https://cofense.com/blog/beyond-human-risk-a-better-way-to-build-secure-behavior
Ransom & Dark Web Issues Week 4, September 2026
https://asec.ahnlab.com/en/95545/
August 2026 Infostealer Trend Report
https://asec.ahnlab.com/en/95519/
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor
Fake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams
https://www.bitdefender.com/en-us/blog/labs/fake-shops-europe-samsung-world-cup-scams
UN Reports Citing Citizen Lab Submissions Published
https://citizenlab.ca/un-reports-citing-citizen-lab-submissions-published/
Submission to the Immigration and Refugee Board of Canada
https://citizenlab.ca/submission-to-the-immigration-and-refugee-board-of-canada/
Vulnerability in WEBCON BPS software
https://cert.pl/en/posts/2026/09/CVE-2026-92419/
Inside a multi stage toll fraud operation targeting Poland
https://cert.pl/en/posts/2026/09/tollfraud-analysis/
CIS Community Defense Model v3.0: Turning Threat Intelligence Into Action
https://www.cisecurity.org/insights/blog/cis-community-defense-model-v3-turning-threat-intelligence-into-action
CIS Benchmarks September 2026 Update
https://www.cisecurity.org/insights/blog/cis-benchmarks-september-2026-update
Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-101
Multiple Vulnerabilities in IBM Concert Software Could Allow for Remote Code Execution
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-ibm-concert-software-could-allow-for-remote-code-execution_2026-100
Fort Lauderdale, FL, September 28, 2026
Visitors since September 18th, 2026: 34,868