Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Sep 14, 2026·6m

Cyber Security News for September 14 2026 - Daily DefSec Brief

Show notes

1. GitLab path traversal at CVSS 10, now exploited — CVE-2026-85706 — Do: Upgrade GitLab, then grep for file.path — https://watchtowr.com/resources/rapid-reaction-gitlab-critical-path-traversal-vulnerability-cve-2026-85706/
2. ScreenConnect file-transfer flaw now has a patch — CVE-2026-84869 — Do: Upgrade ScreenConnect to 26.6.5 — https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin
3. Artifactory chain mints admins, drops a backdoor — CVE-2026-42018, CVE-2026-42016 — Do: Patch Artifactory, audit admin accounts — https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201
4. Metasploit weaponizes five KEV flaws at once — CVE-2026-20079, CVE-2026-83549, CVE-2026-63077, CVE-2026-82078, CVE-2026-19295 — Do: Patch the five KEV flaws now weaponized — https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-goes-to-sixteen
5. Plesk restore race gives a customer root — CVE-2026-68488 — Do: Upgrade Plesk to 18.0.80.7 — https://support.plesk.com/hc/en-us/articles/43248932867351-Vulnerability-in-Plesk-s-Backup-Manager-symlink-race-during-restore-allows-root-privilege-escalation
6. Dell ObjectScale unauth RCE at CVSS 10 — CVE-2026-70416 — Do: Upgrade ObjectScale to 4.4.0.0 — https://securityonline.info/dell-objectscale-vulnerabilities-cve-2026-70416/
7. Direct Send phishing lands as internal mail — Do: Set RejectDirectSend to true in M365 — https://www.infosecurity-magazine.com/news/hackers-us-business-hours-m365/
8. Malware hosted on AI vendors' own domains — Do: Filter AI share links as user content — https://www.huntress.com/blog/ai-attack-surface
9. Fake agency request passed every email check — Do: Verify agency data requests out of band — https://www.bleepingcomputer.com/news/security/revolut-discloses-data-breach-exposing-financial-info-passports/
10. 1.8 million APKs mined for hardcoded secrets — Do: Scan your shipped mobile apps for secrets — https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/
11. Stolen police login opened a state DMV database — Do: Inventory external accounts into your systems — https://therecord.media/florida-shiny-hunters-motor-vehicle
12. Kiro wrote the edit before you approved it — CVE-2026-89332 — Do: Upgrade Kiro to 0.8.135, rotate creds — https://aws.amazon.com/security/security-bulletins/rss/2026-111-aws/
13. 76% deployed Copilot, 43% reviewed permissions — Do: Review M365 oversharing before Copilot — https://www.infosecurity-magazine.com/news/organizations-skip-permissions-ai/
14. IT staff clicked more than any other team — Do: Include IT in phishing simulations — https://www.securityweek.com/phishing-research-challenges-conventional-security-awareness-testing/
15. OpenAI agent swarm ran the RubyGems attack — Do: Rotate RubyGems API keys from May — https://www.infosecurity-magazine.com/news/openai-agent-swarm-hacks-rubygems/