Microsoft’s September 2026 security update for Windows 11 is causing connectivity problems for organizations using Always On VPN, with reports indicating that certificate-based VPN configurations can stop connecting after the update is installed.
A Russia-aligned threat actor has embedded an adversarial prompt inside malicious code to manipulate AI-powered malware analysis systems, attempting to trigger safety protections and prevent automated tools from examining the actual payload.
Threat actors are exploiting vulnerabilities in Cisco Secure Firewall Management Center (FMC) to gain access to enterprise environments, steal credentials and ultimately deploy Qilin ransomware, turning vulnerable security infrastructure into an entry point for broader network compromise.
Cybercriminals are exploiting Google Play's Early Access program to distribute deceptive Android applications, including fake gambling platforms, financial scams, game clones and potentially malicious utilities, while taking advantage of the lack of public ratings and reviews.
Zentrya One Desk7d ago8 min read
criticalCVE-2026-20316 and CVE-2026-20079Vulnerabilities
Threat actors are actively exploiting a critical vulnerability in Cisco firewall software to obtain elevated privileges and deploy malicious payloads, highlighting the growing risk posed by compromised internet-facing security appliances.
A Russian-speaking threat actor has reportedly used hundreds of autonomous AI agents to exploit vulnerable PaperCut NG and MF servers, compromising at least 440 instances belonging to 395 organizations across 48 countries.
The Android banking malware known as Gigabud is using a previously documented Android enterprise feature in an unusual way—creating work profiles to conceal malicious activity from security checks performed by banking applications.
Zentrya One Desk10 Sept 20266 min read
criticalCVE-2026-85102 and CVE-2026-85103Vulnerabilities
Check Point has disclosed two critical vulnerabilities in its Quantum security products that could allow unauthenticated remote attackers to execute arbitrary code by exploiting weaknesses in VPN certificate processing. Both flaws carry a CVSS score of 9.8.
Zentrya One Desk10 Sept 20266 min read
criticalCVE-2018-13379 and CVE-2023-4966Vulnerabilities
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added actively exploited vulnerabilities affecting Cisco, Citrix and Fortinet products to its Known Exploited Vulnerabilities (KEV) catalog.
Zentrya One Desk10 Sept 20267 min read
The Daily Brief
Stay informed. Stay prepared. Stay one step ahead.
One brief each morning: the advisories that matter, the noise removed.
Double opt-in. One-click unsubscribe in every email. We never sell addresses.