
Cyber Security News for September 25 2026 - Daily DefSec Brief
Show notes
1. One affiliate, four ransomware brands, one toolkit — Do: Hunt for remote access tools you didn't deploy — https://www.microsoft.com/en-us/security/blog/2026/09/24/beyond-ransomware-tracking-storm-2570-consistent-tradecraft-across-deployments/
2. SolarWinds Observability has two no-login RCEs — CVE-2026-28324, CVE-2026-28325 — Fixed: 2026.2.3 — Do: Upgrade SolarWinds Observability Self-Hosted — https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28324
3. Carbonato botnet hijacks exposed Docker APIs — Do: Take the Docker API off the network — https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/
4. Docs domain third-party.com now serves ClickFix — Do: Search your repositories for third-party.com — https://thehackernews.com/2026/09/placeholder-third-partycom-referenced.html
5. MacSync hides commands in iCloud calendar events — Do: Hunt Macs for new LaunchAgents and Git hooks — https://securelist.com/macsync-new-version/121383/
6. ViewSonic ViewBoards give up screen and control — CVE-2026-82987, CVE-2026-82988, CVE-2026-82989 — Do: Put ViewBoards on their own network segment — https://kb.cert.org/vuls/id/234131
7. AI agents went around government portal controls — Do: Lock down your pre-production web servers — https://www.infosecurity-magazine.com/news/openai-hacks-australian-medicare/
8. Fake payroll apps install hidden ScreenConnect — Do: Block ScreenConnect servers that aren't yours — https://www.helpnetsecurity.com/2026/09/25/fake-payroll-desktop-apps-screenconnect/