
Cyber Security News for September 22 2026 - Daily DefSec Brief
Show notes
1. A thousand switches gave up the network map — CVE-2026-7273 — Fixed: 2.90(ABTQ.2)C0 on the 48HPv2 — each model has its own 2.90 build ending .2)C0 — federal due 2026-09-24 — Do: Upgrade the GS1900s and change their passwords — https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-advisory-for-stack-based-buffer-overflow-vulnerability-in-gs1900-series-switches-06-16-2026
2. One admin click plants PHP on WordPress — CVE-2026-93485 — Fixed: 7.1.1 — Do: Automate WordPress updates, alert on failures — https://wordpress.org/news/2026/09/wordpress-7-1-1-maintenance-and-security-release/
3. Signed driver kills 145 security tools — Do: Block NvFsFilter and alert when EDR goes quiet — https://www.bleepingcomputer.com/news/security/fake-lastpass-authenticator-github-repos-push-new-rapuncel-infostealer/
4. A bad npm release with valid provenance — Do: Stop treating npm provenance as a code check — https://www.cloudsek.com/blog/ghappier-malware-loader-npm-supply-chain-attack
5. Ransomware run entirely through Group Policy — Do: Alert on new GPOs and review domain admin — https://securelist.com/tr/payload-ransomware-via-group-policy/121335/
6. Windows COM fix left the hole open — CVE-2026-66804, CVE-2026-50343 — Do: Patch Windows and hunt dangling COM registrations — https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-66804
7. Backdoor exfiltrates each document as you save it — Do: Hunt the fake scheduled tasks on your endpoints — https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html
8. SAML keeps producing authentication bypasses — Do: Take new SSO integrations to OIDC — https://blog.trailofbits.com/2026/09/21/saml-a-fractal-of-bad-design/
9. AWS quarantines leaked keys in ten seconds — Do: Alert when AWS quarantines one of your keys — https://unit42.paloaltonetworks.com/detecting-exposed-aws-iam-credentials/
10. 225 AI-found CVEs, one of them exploited — CVE-2026-26980 — Fixed: 6.19.1 — Do: Upgrade Ghost and rotate its API keys — https://github.com/advisories/GHSA-w52v-v783-gw97
11. ShinyHunters seized Clop's leak site — Do: Revisit a ransom you paid Clop — https://therecord.media/shinyhunters-clop-cyberattack-website