1 min read
CI Bulletin Vol 2, Issue 14 – Sept 23, 2026
Originally Published Sept 23, 2026
43 min read
Cyber Florida
:
Updated on October 5, 2026
This bulletin is produced by USF’s Strategic and Cyber Intelligence Program, in collaboration with Cyber Florida, to deliver timely, actionable insights and recommendations to help Critical Infrastructure owners and operators better protect Florida’s Critical Infrastructure.
Cyber threat activity against critical infrastructure remained elevated during this reporting period, as attackers exploited flaws in internet-facing security equipment, such as firewalls, remote access gateways, and email filters, often before vendors released patches or within hours after. Ransomware attacks reached a 2026 high of 1,073 in August, and new groups now threaten to destroy victims' backups as well as steal data, raising recovery costs for operators without offline copies. Three developments are most likely to shape risk for Florida operators over the next 6 to 18 months. First, criminal phishing services will continue to steal active login sessions rather than passwords, defeating text-message and app-based multi-factor authentication (MFA) unless organizations adopt phishing-resistant methods such as hardware security keys. Second, attackers will increasingly plant malicious code in trusted software updates, developer packages, and artificial intelligence (AI) add-ons that connect assistants to company data, because organizations adopt these tools faster than they vet them. Third, local governments will lose two federal supports, the final year of State and Local Cybersecurity Grant Program funding and the weekly vulnerability bulletins of the Cybersecurity and Infrastructure Security Agency (CISA), with the November 2026 midterm elections as an early test. Florida leaders should prioritize fast patching of internet-facing devices, remove internet exposure from operational technology (OT) systems, and require phishing-resistant MFA for all remote access
Confidence Level: Moderate-High
All Sectors: Attackers exploited previously unknown flaws (zero-days) in Citrix NetScaler remote access gateways, Cisco Secure Email Gateway, and Google Pixel phone modems, and the Cybersecurity and Infrastructure Security Agency (CISA) set federal patch deadlines as short as three days. Microsoft and law enforcement dismantled EvilTokens, a phishing service that compromised more than 12,000 email inboxes at over 10,000 organizations.
Commercial Facilities Sector: Attackers used open-source AI agents to breach at least 27 online retailers in six days, planting payment card skimmers on 19 websites and stealing more than 600,000 card records at about $25 per target. Compromised add-on applications exposed BigCommerce shopper data, and 74 percent of surveyed U.S. security leaders reported a suspected deepfake attack in the past year.
Communications Sector: A distributed denial-of-service (DDoS) attack, which overwhelms a network with junk traffic, cut internet service intermittently for at least two days in Eagle Mountain, Utah, disrupted the provider's upstream carriers, and disabled its own phone and support lines. Florida providers should confirm upstream traffic filtering agreements and backup connectivity.
Critical Manufacturing Sector: Global ransomware attacks reached a 2026 high of 1,073 in August, and industrial firms absorbed 329 of them (31 percent), with North America accounting for 44 percent. New groups such as Aurora break in through virtual private network (VPN) flaws and stolen passwords, then encrypt the virtualization servers that host many systems at once.
Defense Industrial Base Sector: A flaw in a Defense Manpower Data Center file-sharing portal exposed names, Social Security numbers, and service details of military personnel for about nine months; people familiar with the incident estimate four million affected. Fake messages sent through the Army and Air Force Exchange Service (AAFES) app and email also targeted military families. Florida installations and contractors should expect follow-on phishing.
Energy Sector: Texas regulators urged oil and gas operators to treat cybersecurity as an operating risk after the Coast Guard and Federal Bureau of Investigation (FBI) boarded two U.S.-bound tankers following indications that foreign actors had compromised their networks. A pro-Iran hacktivist group claimed attacks on Saudi airports, banks, and media; none are confirmed, and none involved operational technology (OT).
Financial Services Sector: Attackers used a zero-day flaw in an unnamed third-party security product to drain about $388 million from cryptocurrency exchange Bitget; suspected North Korean involvement is unconfirmed. A North Korea-backed group infected more than 30,000 devices through fake job interviews, and a new Android banking trojan targets customers of more than 30 banks.
Government Services and Facilities Sector: Ransomware and intrusions disrupted a county housing authority, a Texas city, a Washington school district, and Arizona's court network, where a phishing email led to theft of protective-order records. A China-aligned group targeted Latin American governments, including Puerto Rico. The Defense Secretary directed the National Security Agency (NSA) and military cyber forces to protect the November midterm election systems, which Florida county election officials should factor into coordination plans.
Healthcare and Public Health Sector: An intrusion at Park Place Behavioral Healthcare in Osceola County, Florida, exposed patient data; the Insomnia ransomware group claimed it. More than 77 percent of active ransomware groups target healthcare, and ShinyHunters is posing as help desk staff by phone to obtain multi-factor authentication (MFA) codes. A cyberattack took Alabama's nursing license portal offline for more than 80,000 nurses.
Information Technology Sector: Attackers exploited more than a dozen newly disclosed flaws in widely used products, including F5 BIG-IP (more than 14,700 exposed systems), Check Point VPN gateways, Cisco Identity Services Engine, and WordPress, which attackers hit the same day the patch shipped. Supply chain attacks through Brevo and GitHub Actions reached as many as 100,000 websites and about 15,000 dependent code repositories.
Transportation Systems Sector: Eighty-seven percent of maritime organizations surveyed reported a significant OT cyber incident in the past year, while only 21 percent of all respondents keep a full OT asset inventory. China-linked Mustang Panda ran sustained espionage against European maritime organizations, and Android spyware posing as freight company apps targeted logistics staff, risks that apply directly to Florida ports and logistics operators.
Water and Wastewater Systems Sector: Water and Wastewater Systems: Intruders accessed internet-exposed control equipment and cellular modems at two Colorado water systems that each serve fewer than 200 residents; reports raised concern about, but did not confirm, Iranian involvement. Related intrusions have reached water OT systems in more than 12 states, a pattern that applies to small Florida utilities that rely on remote monitoring.
No Reporting: No sector-specific findings, advisories, or operationally relevant reporting were identified during this bi-weekly reporting period for the following sectors: Chemical, Dams, Emergency Services, Food and Agriculture, or Nuclear Reactors, Materials, and Waste
CISA Releases Operational Guidance on Using Cyber Decoys to Strengthen Detection and Response The Cybersecurity and Infrastructure Security Agency (CISA) published a detailed operational resource advising critical infrastructure operators on deploying cyber decoys and honeypots within enterprise and operational technology (OT) environments. The guidance outlines positioning strategies for high-interaction decoys, fake credentials, and lure files designed to catch adversary lateral movement, expose living-off-the-land (LOtL) tactics, and generate high-fidelity detection alerts early in the attack chain. CISA emphasized that well-configured decoys provide early warning indicators within Zero Trust architectures while diverting attackers away from mission-critical assets. Florida critical infrastructure owners, utility operators, and enterprise network defenders should review CISA's guidelines to integrate threat deception mechanisms into active operational playbooks.
Bragjack Attack Targets Browser Agentic AI Systems On September 16, 2026, Forever Security disclosed BragJack, a proof-of-concept attack that hijacks the AI assistants built into five agentic browsers, including Google Chrome with Gemini, Microsoft Edge, and Claude in Chrome. BragJack is not a prompt injection technique. It exploits a shared design flaw that lets a browser extension issue commands to the privileged built-in agent, enabling screenshots, file access, and data exfiltration. Google and Microsoft assigned CVE-2026-0628 and CVE-2026-55945, and the vendors have resolved the flaws. Florida enterprise network defenders and information technology (IT) administrators must keep Chromium-based browsers updated and remove unvetted browser extensions.
Google Pixel Phones Target of In-The-Wild Zero-Click Attacks Google and the Cybersecurity and Infrastructure Security Agency (CISA) warned that attackers exploited CVE-2026-58704, a high-severity zero-day improper authorization flaw in Google Pixel cellular modems. The flaw bypasses permission checks and escalates privileges with no user interaction. Google disclosed the flaw in its September 2026 Pixel security bulletin, noted limited, targeted exploitation, and released a fix. CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog with a September 19 federal deadline. Florida critical infrastructure personnel, state agency staff, and mobile enterprise administrators operating Pixel devices must apply the September 2026 Pixel updates immediately and restrict unverified enterprise connectivity.
Hackers Exploit Zero-Day Vulnerability in Cisco Secure Email Gateway Security researchers and federal agencies confirmed active zero-day exploitation targeting CVE-2026-76461, a critical vulnerability in the email parsing function of Cisco AsyncOS software for Secure Email Gateway, affecting physical and virtual appliances regardless of configuration. The flaw allows unauthenticated remote cyber threat actors to execute arbitrary commands with root privileges by sending specially crafted email payloads to exposed gateways, enabling complete device takeover and network pivot opportunities. CISA added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog and gave federal civilian agencies until September 17, 2026, to mitigate it. Florida enterprise network administrators, communications providers, and IT service operators using Cisco Secure Email Gateways must apply Cisco's emergency patches, review gateway logs for anomalous shell activity, and restrict perimeter administrative access.
BIND 9 Updates Fix 14 Security Vulnerabilities Including DoS Flaws The Internet Systems Consortium (ISC) released BIND 9.20.29 and 9.21.26 to fix 14 vulnerabilities. They include CVE-2026-77692, which lets an unauthenticated sender crash the named process on any server answering DNS-over-HTTPS (DoH) with a single request carrying an invalid SIG(0) signature. Other flaws enable resolver crashes, resource exhaustion, and cache poisoning. ISC reports no active exploitation, and the end-of-life 9.18 branch receives no fix for 12 of the flaws. Florida network defenders, internet service providers (ISPs), and critical infrastructure IT administrators running BIND 9 must upgrade to 9.20.29 or 9.21.26 immediately, migrate from 9.18, and restrict public DoH endpoint access.
CISA Discontinues Weekly Vulnerability Bulletins in Pivot to Risk-Based Vulnerability Management The Cybersecurity and Infrastructure Security Agency (CISA) announced the discontinuation of its weekly vulnerability bulletins, effective September 28, transitioning toward a risk-based focus. The agency will prioritize actionable intelligence through its KEV catalog rather than maintaining comprehensive weekly listings. Security analysts noted that while the KEV catalog is vital for emergency response, defenders still require proactive vulnerability management tools to identify emerging software defects before active exploitation occurs. Florida critical infrastructure defenders, technology providers, and enterprise administrators should adjust vulnerability management workflows to integrate CISA KEV feeds, threat intelligence sources, and automated patch prioritization tools.
Microsoft and Law Enforcement Partners Disrupt EvilTokens AI Phishing Platform Microsoft announced the successful disruption of EvilTokens, a subscription-based phishing service that compromised over 12,000 corporate email inboxes across more than 10,000 organizations. Operating under a Crime-as-a-Service model since February 2026, the platform charged cybercriminals $1,500 initially and $500 monthly to conduct automated device-code phishing attacks that bypassed traditional authentication controls. Working with the Health Information Sharing and Analysis Center (Health-ISAC) and private-sector partners, including Cloudflare, Coinbase, OpenAI, and The Shadowserver Foundation, Microsoft obtained an order from the U.S. District Court for the Eastern District of Virginia to seize 50 core operational websites and neutralize over 150 connected domains. On September 11, 2026, London's Metropolitan Police Service arrested two men on suspicion of operating EvilTokens and released them on bail pending investigation. Microsoft warned that attacker access can persist after a password reset unless the associated sessions and tokens are revoked. Florida critical infrastructure operators, healthcare networks, and enterprise cloud administrators must enforce multi-factor authentication (MFA), restrict device-code authentication flows, and continuously monitor cloud sign-in logs for unexpected session approvals.
Dark Sourcery Campaign Manipulates AI Chatbots in Mass Disinformation and Phishing Attack Vigilance Security researchers disclosed Dark Sourcery, a campaign that manipulates answers from OpenAI's ChatGPT, Google Gemini, and Google AI Overview. Attackers flood the web with search-optimized posts, Portable Document Format (PDF) files, reviews, and fake support pages. The campaign has affected at least 374 companies, causing chatbots to present fraudulent support numbers and login pages as trusted answers. Unlike prompt injection, the technique gives the AI no instructions. Researchers cited a study finding that 91 percent of chatbot users do not verify answers. Florida enterprise security operations teams and commercial organizations must verify AI-supplied contact details against official records and monitor AI agent sources at runtime.
Emerging n0n Ransomware Gang Uses Backup Destruction Threats to Extort Victims CyberXTron researchers reported n0n, a double-extortion ransomware group first observed on September 18, 2026, whose leak site listed more than a dozen victims by September 22. The group threatens to encrypt or destroy victims' backups and shadow copies if ransoms go unpaid; researchers have not confirmed that it actually wipes backups. Attacks begin with credentials stolen by infostealer malware. Financial services accounts for 23 percent of victims, and the United States is the most targeted country. Florida enterprise security directors, IT administrators, and cloud managers must enforce multi-factor authentication (MFA) across external access points, isolate offline immutable backups, and restrict administrative access to backup consoles.
CISA Orders Federal Agencies to Patch Actively Exploited Citrix NetScaler Vulnerabilities On September 27, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-88771 and CVE-2026-88772, two actively exploited zero-days in Citrix NetScaler Application Delivery Controller and Gateway, to its Known Exploited Vulnerabilities (KEV) catalog. CISA ordered federal civilian agencies to patch by September 30 under Binding Operational Directive 26-04. Both flaws allow unauthenticated remote code execution; the second requires Datagram Transport Layer Security (DTLS), which is enabled by default on virtual private network (VPN) servers. Fixed releases include 14.1-73.37 and 13.1-64.23. Florida operators running NetScaler must apply updates immediately, check Citrix indicators of compromise, and preserve forensic evidence before patching.
Niche Artificial Intelligence Tools Present Severe Security Risks to Critical Infrastructure Operators Cybersecurity research published by TrendAI warned that niche, bespoke AI software applications pose severe cybersecurity risks to critical infrastructure operators. The report highlighted that traditional security vetting tools and Cloud Access Security Broker (CASB) products are engineered to evaluate mainstream frontier models rather than obscure, custom AI utilities. Unvetted AI tools frequently lack basic security governance reviews, exposing organizations to misconfigured Model Context Protocol (MCP) servers, insecure local inference engines, and supply chain vulnerabilities embedded in open-source repositories. Florida critical infrastructure defenders, utility operators, and enterprise technology managers must expand software vetting protocols, establish strict AI governance frameworks, and isolate custom AI models from core operational networks.
All Sectors Recommendations:
No sector-specific findings, advisories, or operationally relevant reporting were identified during this reporting period.
Hackers Stole Flock's Camera Software, Revealing How the Company Tracks Cars and People On September 16, 2026, investigative reporting disclosed that hackers physically extracted hardware from a Flock Safety automated license plate recognition (ALPR) camera, bypass-extracted its internal storage, and obtained proprietary system software and cryptographic keys. Analysis of the exfiltrated software revealed internal tracking mechanics, data-logging behaviors, and vehicle movement analysis capabilities utilized across thousands of law enforcement and commercial surveillance deployments nationwide. The physical side-channel extraction highlights significant physical security and storage encryption vulnerabilities present in distributed edge hardware deployed in public spaces. Florida law enforcement agencies, municipal security directors, and commercial facility operators utilizing physical surveillance edge hardware must enforce secure boot routines, audit hardware physical tamper controls, and encrypt local storage media.
Network Segmentation Failures Expand Corporate Attack Surface Across Critical Infrastructure On September 22, 2026, cybersecurity research published by Forescout revealed that widespread network segmentation failures are significantly expanding the attack surface across corporate and critical infrastructure networks. Analyzing 47,700 network segments, Forescout found that nearly half of the segments containing operational technology (OT) or medical devices also contain IT and Internet of Things (IoT) devices, and that IP cameras commonly share segments with workstations and servers. Forescout also tracked over 300 instances in 2026 of hacktivists, including pro-Russian group NoName057(16), gaining control of exposed IP cameras. Forescout emphasized that segmentation drift occurs as new devices are onboarded without proper policy validation, enabling localized breaches to cascade into catastrophic operational disruptions. Florida critical infrastructure asset owners, enterprise administrators, and information technology (IT) teams must continuously audit network boundaries, validate device isolation policies, and deploy zero trust micro-segmentation controls.
BigCommerce Alerts Merchants of Data Breach Linked to Compromised Ribon Applications After confirming the compromise on September 17, 2026, e-commerce platform BigCommerce notified merchants of a third-party data breach stemming from compromised application keys associated with the Ribon and Ribon 1.5 applications operated by developer Be A Part Of. Cyber threat actors utilized the stolen credentials to access merchant environments and exfiltrate shoppers' personal information, including full names, email addresses, phone numbers, and shipping addresses, between September 13 and 17, and to inject malicious scripts into a small number of merchant storefronts. Affected retailer Master of Malt warned that the incident could extend to hundreds of other stores. BigCommerce confirmed that its core platform infrastructure was not breached and that customer account passwords and payment card details remained unexposed in separate secure environments. BigCommerce removed the affected applications to revoke attacker access and provided server logs to assist in forensic investigations. Florida retail merchants, commercial facility operators, and e-commerce vendors must review installed third-party applications, audit API access permissions, and monitor customer communication channels for potential spear-phishing follow-ups.
Open-Source AI Agents Breach 27 Companies and Steal 600,000 Credit Card Records Gambit Security researchers found that a financially motivated actor used three open-source AI harnesses, Strix, Cairn, and Hermes, to automate attacks on online retailers, compromising at least 27 companies between September 10 and 15, 2026. The agents exploited web application flaws such as Structured Query Language (SQL) injection, uploaded web shells, stole cloud credentials, and installed payment skimmers, confirmed on 19 websites. The operation exfiltrated more than 600,000 credit card records from two companies at an average cost of about $25 per target and wiped Magento databases after the theft. Florida retail merchants and e-commerce platforms must patch web applications, audit checkout scripts for unauthorized code, and monitor for web shells.
Cambodia Expands Cyber Scam Investigation to Networks Supporting Online Fraud Cambodian authorities expanded their cyber fraud investigation beyond raiding scam compounds to target the people and networks that direct, enable, or protect the operations. The investigation includes the financial network of the Prince Group conglomerate, whose founder was deported to China. The shift follows analyst reports that many large compounds and their money-laundering networks remain active despite a year-long crackdown. Industrial-scale compounds rely on trafficked workers forced to defraud people online, and U.S. officials estimate regional scam compounds stole $10 billion from Americans in 2024. Florida financial compliance officers and anti-money laundering (AML) specialists should monitor wire transfers tied to high-risk foreign corridors and maintain rigorous vendor auditing.
Deepfake Social Engineering Attacks Drive Escalating Financial Losses for Enterprise Businesses On September 28, 2026, Pindrop published its 2026 Deepfake Readiness Index, a survey of more than 250 U.S. security leaders. In the survey, 74 percent reported a suspected deepfake attack in the past 12 months, and one in four of those reported losses exceeding $1 million from a single incident. Cyber threat actors utilize real-time synthetic voice and video cloning to impersonate corporate executives, tricking staff into authorizing fraudulent wire transfers and releasing sensitive corporate records. The total financial impact includes direct fraudulent transfers, external forensic remediation expenses, and operational downtime required for incident containment. Security experts urged Chief Information Security Officers (CISOs) to deploy phishing-resistant multi-factor authentication (MFA), establish out-of-band transaction verification protocols, and train financial authorization personnel. Florida commercial facilities, corporate enterprises, and hospitality organizations must update executive authorization playbooks and enforce strict identity controls.
Commercial Facilities Sector Recommendations:
Cyberattack Prompts Internet Outages Across Eagle Mountain Utah telecommunications provider Direct Communications reported that a distributed denial-of-service (DDoS) attack beginning September 19, 2026, caused slow speeds, packet loss, and complete internet outages across Eagle Mountain, Utah. The attack also affected the company's upstream network providers. An upstream provider's fix briefly restored stability, but service failed again on September 20. The outage disabled internet and phone service at the company's own offices, closing its Eagle Mountain office and customer support lines. Florida telecommunications providers, municipal internet service providers (ISPs), and critical communications operators should maintain upstream DDoS mitigation agreements, redundant connectivity, and out-of-band communication channels for emergency operations.
Communications Sector Recommendations:
Ransomware Activity Hits 2026 High With Industrial Sector Bearing 31 Percent of Total Attacks NCC Group reported that global ransomware activity reached a 2026 high in August with 1,073 attacks, a 12 percent increase from July. The industrials sector bore 329 attacks, or 31 percent of the total, and North America accounted for 44 percent. Qilin led all groups with 15 percent of attacks. The emerging Aurora ransomware-as-a-service group used virtual private network (VPN) exploitation, credential harvesting, and hypervisor encryption against manufacturing targets. Florida manufacturing plant managers, industrial control operators, and supply chain directors must enforce multi-factor authentication (MFA) across remote gateways, segment business networks from operational technology (OT) assets, and maintain isolated offline backups.
Critical Manufacturing Sector Recommendations:
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
AAFES Investigating Suspicious Messages Sent to Military Customers The Army and Air Force Exchange Service (AAFES) announced an active investigation into unauthorized, suspicious messages sent to military personnel and their families via email and the official retail mobile application. The messages included a wish list link attributed to an AAFES Security Team, and AAFES warned recipients not to click links or provide personal, account, or payment information. AAFES issued warnings across official communication channels advising active-duty service members, veterans, and defense personnel to avoid clicking unverified links and report anomalous account activity to customer support. AAFES has not said where the messages originated or whether its systems were breached, and it confirmed that only emails and My Exchange app push notifications, not text messages, were affected. Florida defense contractors, military installations, and Department of Defense (DoD) partner facilities must alert personnel to retail-themed phishing lures, enforce multi-factor authentication (MFA) on enterprise accounts, and monitor mobile application gateways for unauthorized message pushes.
Military Personnel Personal Information Exposed in Defense Manpower Data Center Breach The Defense Manpower Data Center (DMDC) issued breach notification letters confirming that a software vulnerability in a file-sharing portal allowed unauthorized users to access files containing unencrypted personal information of United States military personnel. The compromised records included full names, Social Security numbers (SSNs), and military service details. DMDC discovered the vulnerability on July 16, 2026, and determined that unauthorized users accessed the files between October 2025 and July 16, 2026. Two people familiar with the incident said approximately four million Department of Defense personnel may be affected. Officials confirmed that technical teams patched the system vulnerability and restored normal operations while launching a forensic assessment to evaluate data exfiltration risks. Florida defense contractors, military partner organizations, and defense industrial base (DIB) suppliers must enforce strict data encryption standards for sensitive file transfers, apply vendor security patches promptly, and alert personnel regarding targeted spear-phishing risks.
Defense Industrial Base Sector Recommendations:
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
Pro-Iran Hackers Claim Cyber Missiles Campaign Targeting Saudi Critical Infrastructure The pro-Iran hacktivist group Islamic Cyber Resistance in Iraq, 313 Team, claimed a September campaign it called cyber-missiles against Saudi online services. Claimed targets include the Qiwa workforce platform, the Saudi Press Agency, King Abdulaziz International Airport, Saudi National Bank, and education platforms, as Iran-backed Houthis escalated physical strikes. None of these claims has been independently confirmed, and the article reports no operational technology (OT) targeting. The group previously claimed attacks on U.S. targets, including the National Weather Service and United Airlines. Florida government agencies, financial institutions, and airport operators should maintain distributed denial-of-service (DDoS) protection for public-facing services and treat hacktivist claims as unverified until confirmed.
Texas Railroad Commission Warns Oil and Gas Operators of Escalating Cyber Threats Railroad Commission of Texas (RRC) Commissioner Wayne Christian urged oil and gas producers and pipeline operators to strengthen cybersecurity defenses. His warning followed August incidents in which the Coast Guard and Federal Bureau of Investigation (FBI) boarded two U.S.-bound foreign-flagged energy vessels, including the Galveston-bound tanker VL Prosperity, after indications that foreign actors had compromised the vessels' networks. Christian cited federal warnings that foreign-linked actors are targeting internet-facing operational technology (OT) and industrial control systems (ICS). The RRC urged operators to consider cybersecurity as a direct operating risk, recommending immediate perimeter hardening and remote access auditing. Florida energy grid operators, natural gas pipeline managers, and petroleum distribution facilities must segment business information technology (IT) from field OT networks, disable default administrative credentials, and enforce MFA across remote maintenance gateways.
Energy Sector Recommendations:
North Korean Threat Groups Steal Millions in Crypto via Fake Job Schemes On September 18, 2026, Japan's National Police Agency (NPA) and National Cyber Directorate, working with the U.S. Federal Bureau of Investigation (FBI), the Department of Defense Cyber Crime Center, and Australian and German agencies, detailed the methods of WaterPlum. This North Korea-backed group infected over 30,000 devices between December 2025 and July 2026 and stole about 1.7 billion yen (14.5 billion won) in cryptoassets across roughly 100 countries. Cyber threat actors targeted developers, information technology (IT) specialists, and cryptocurrency executives through social engineering campaigns masquerading as employment interviews and recruitment offers. Once victims downloaded fake technical assessment files or joined compromised video calls, embedded malware harvested private key material and credentials. Florida financial services organizations, digital asset custodians, and fintech firms must conduct employee awareness training regarding recruitment-based social engineering and enforce strict endpoint software controls.
RemControl Android Trojan Targets Over 30 Banking Apps to Steal Credentials A newly identified Android banking trojan actively targets customers of over 30 financial institutions across Europe, North America, and the Middle East. Distributed via fake Google Play pages impersonating the TVTap Internet Protocol television (IPTV) app, likely promoted through malvertising, the malware dropper abuses virtual private network (VPN) configurations to block communication with Google Play Protect during installation. Once granted Accessibility Service permissions, RemControl establishes WebSocket connections to stream real-time screen imagery, remotely control the device, and display malicious overlay screens to harvest login credentials and personal identification number (PIN) codes. Florida financial institutions, mobile banking application developers, and credit unions must alert customers to side-loading risks, enforce out-of-band transaction verification, and monitor mobile application integrity.
Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M Cryptocurrency exchange Bitget said an attacker exploited a zero-day flaw in an unnamed third-party security product to obtain high-level internal credentials. On September 24, 2026, the attacker inserted fraudulent withdrawal commands that drained about $388 million from hot and warm wallets; cold wallets were unaffected. Bitget isolated affected systems, revoked credentials, and disabled the vulnerable functionality, but it has not said whether the vendor released a fix. Bitget suspects North Korean actors, and TRM Labs found unconfirmed overlaps with TraderTraitor. Bitget published attacker wallet addresses for screening. Florida financial institutions and digital asset custodians must audit third-party integrations, enforce privileged access management (PAM), and screen deposits against published attacker addresses.
Rapid Deployment of Autonomous AI Agents Introduces Unprecedented Systemic Risks to Banks On September 29, 2026, financial regulatory reporting published by Politico warned that the rapid integration of autonomous artificial intelligence (AI) agents across commercial banking networks introduces severe systemic risks. Financial regulators emphasized that granting AI agents authority to execute automated trades, manage client accounts, and adjust risk models creates novel vulnerabilities, including algorithmic manipulation and prompt injection exploitation. Furthermore, the lack of standardized audit trails complicates compliance and incident response when autonomous systems execute unauthorized transactions. Florida financial institutions, banking executives, and wealth management firms must implement strict human-in-the-loop approval controls, restrict autonomous agent execution privileges, and conduct continuous risk audits on automated financial tools.
Financial Services Sector Recommendations:
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
Clay County Housing Authority Suffers Disruptive Ransomware Incident Officials confirmed that the Clay County (Minnesota) Housing and Redevelopment Authority (HRA) fell victim to a ransomware attack that encrypted administrative servers and disrupted public housing operations. External forensic specialists were engaged to isolate affected networks, assess potential data exposure, and restore core systems from secure backups. The incident forced staff to process tenant records and housing assistance documentation manually while investigation efforts continued. Florida municipal government agencies, regional housing authorities, and public administration facilities must enforce MFA across all remote access entry points, maintain isolated offline backups, and review third-party administrative privileges.
China-Aligned FamousSparrow Deploys Custom SparroWocky Backdoor ESET researchers reported that FamousSparrow, a China-aligned state-sponsored group that overlaps with Salt Typhoon, has deployed SparroWocky, a new modular C++ backdoor, against government entities across Latin America since at least August 2025. The targets include entities in Puerto Rico. SparroWocky executes commands, exfiltrates files, takes screenshots, and uses call-stack spoofing and in-memory plugins to evade security products. It launches through dynamic-link library (DLL) sideloading and communicates with the command and control (C2) server 216.238.110[.]120. The initial access vector is unknown. Florida state agencies and municipal offices should block the listed C2 address, hunt for DLL sideloading, and monitor process memory for unbacked code execution.
Princeton Calls Emergency Session Following Municipal Cybersecurity Intrusion The City of Princeton, Texas, called an emergency City Council session for September 21, 2026, after confirming an active cybersecurity incident involving an intrusion into critical city information technology (IT) and communication systems. The council planned to consider emergency contracts, expenditures, and remediation measures in executive session. The city is working with cybersecurity experts and law enforcement to determine whether any information was accessed or acquired, and it has not identified any affected data. Florida municipal governments, county administrative offices, and public facilities must maintain offline backup repositories, enforce multi-factor authentication (MFA) across administrative portals, and maintain tested continuity plans for municipal IT networks.
SideCopy Broadens Cyber Espionage Campaign to Academia Using ReverseRAT Spear Phishing Threat intelligence researchers at Trellix disclosed that SideCopy, a Pakistan-origin cyber espionage group, has expanded its targeting beyond Indian government entities to include academic institutions in India. The campaign uses spear-phishing emails delivering weaponized compressed archive files containing malicious Windows shortcut (LNK) files designed as document lures. When opened, the LNK file fetches an HTML Application (HTA) via mshta.exe to reflectively load ReverseRAT in memory, establishing an encrypted C2 channel to exfiltrate research files and system credentials. Trellix identified indicators of compromise, including the payload host docsportal[.]in and exfiltration over port 5863 to dns.educationportals[.]biz (45.61.157[.]22). Florida government facilities, state university research centers, and academic partners must block unapproved HTA execution, audit Windows shortcut file behavior, and enforce email gateway filtering.
Spokane Public Schools Disconnect Systems Following Severe Districtwide Cybersecurity Incident Spokane Public Schools in Washington state took several online systems offline after a cybersecurity incident on the night of September 20, 2026, including its PowerSchool attendance system and its payroll system. A third-party technical expert is investigating, and the systems will remain offline until investigators deem restoration safe. The superintendent said only district staff appear affected so far and that it is too early to determine the extent of compromised information or who is responsible. Schools continued operating without technology. Florida public school districts, county offices, and municipal facilities must establish offline continuity playbooks, maintain isolated network backups, and enforce multi-factor authentication (MFA) across administrative portals.
Nebraska Establishes Statewide State-Focused ISAC and Expands Federal Cybersecurity Grant Usage Nebraska Chief Information Security Officer (CISO) Bryce Bailey said the state is planning a state-focused Information Sharing and Analysis Center (ISAC) that would combine the Nebraska Information Analysis Center and the Joint Security Operations Center. The ISAC would share tailored threat intelligence with local governments. For fiscal year 2026, the final year of the State and Local Cybersecurity Grant Program (SLCGP), the state may shift from individual jurisdiction projects to multijurisdictional purchases, such as aggregated endpoint detection and response licensing. Florida county administrators, municipal information technology (IT) directors, and regional public safety agencies should leverage state grant opportunities, join regional threat-sharing groups, and implement shared security baselines.
FBI Investigates Alleged Jobs Portal Data Breach and Employee Information Exposure The Federal Bureau of Investigation (FBI) confirmed an active investigation into claims by the ShinyHunters extortion group that it stole employee and applicant records from the FBIJobs.gov recruitment portal. Federal officials clarified that technical teams are working to determine whether the unauthorized access originated within internal bureau infrastructure or through a third-party software vendor. ShinyHunters claims the data covers nearly all FBI agents and applicants. A sample shared with Reuters reportedly included names, home addresses, Social Security numbers (SSNs), and assignments. A retired FBI agent, not the bureau, noted there is no indication that classified systems were accessed. Florida state agencies, law enforcement organizations, and government facilities must conduct vendor risk audits for public recruitment portals, enforce least-privilege database access, and monitor credentials on dark web forums.
Military Cyber Forces and NSA Mobilized to Protect Midterm Election Infrastructure On September 28, 2026, Defense Secretary Pete Hegseth announced that the National Security Agency (NSA) and military cybersecurity forces will actively protect the United States' election infrastructure during the upcoming November midterm elections. In a directive issued to defense intelligence officials, the Department of Defense (DoD) ordered the mobilization of military intelligence resources to counter foreign malign influence, protect voting systems from cyber threats, and safeguard election integrity. The federal directive emphasizes defending state and local election infrastructure without interfering with lawful voting procedures. Florida election officials, county administrators, and municipal government IT teams should review coordination channels with federal cybersecurity partners and maintain robust system logging.
Phishing Cyberattack Hits Arizona Judicial Network Exposing Sensitive Court Data Arizona Supreme Court officials disclosed a severe cyberattack that compromised judicial network systems after an employee succumbed to a phishing email lure. The resulting breach enabled an automated bot to execute unauthorized data downloads, potentially exposing sensitive personal records and protective order files containing home addresses of vulnerable individuals. Local IT personnel detected the anomalous outbound data volume and immediately shut down judicial servers, engaging the FBI to assess whether exfiltrated files were encrypted or readable. Florida court administrators, judicial officers, and municipal government IT staff must enforce mandatory phishing-resistant multi-factor authentication (MFA), restrict database access privileges, and monitor network egress traffic for anomalous data transfers.
Government Services and Facilities Sector Recommendations:
Cyberattack Keeps Alabama Nursing License System Offline During Critical Renewal Window State officials reported that a major cyberattack forced the Alabama Board of Nursing online licensing and regulatory portal offline, creating widespread administrative disruption for more than 80,000 registered and practical nurses entering a key renewal period. The systemic outage forced the agency to pivot to manual paper processing, physical application intake at community colleges, and alternative verification workarounds to validate healthcare credentials. Employers must verify licenses through the national Nursys database or the board's daily-updated applicant list. The board also warned of fraudsters using spoofed phone numbers and forged documents to impersonate its communications. Florida healthcare systems, hospital administrative teams, and state licensing boards should implement robust network segmentation, maintain paper-based verification contingencies, and enforce strict access controls on public-facing regulatory portals.
McKesson Cyber Intrusion Exposes Over 6.4 Million Email Addresses Healthcare security reporting confirmed that pharmaceutical distributor McKesson suffered a data breach exposing 6.4 million email addresses in an August 2026 data theft. Cyber threat actors accessed external marketing databases and web application interfaces, harvesting contact records used across pharmacy networks and medical supply systems. The theft also potentially exposed patient health information, and the exfiltrated dataset significantly increases spear-phishing risks for impacted healthcare organizations and patients. Florida healthcare systems, retail pharmacies, and medical supply operators should alert staff to potential social engineering campaigns, monitor incoming email gateways for spoofed domain activity, and enforce strict Health Insurance Portability and Accountability Act (HIPAA) administrative security controls.
Department of Veterans Affairs Notifies Over 30,000 Veterans of Baylor Genetics Data Breach On September 21, 2026, the United States Department of Veterans Affairs (VA) informed congressional staff that a cybersecurity breach at vendor Baylor Genetics compromised the protected health information (PHI) and personally identifiable information (PII) of 30,263 veterans. The mid-June breach occurred within Baylor Genetics systems, exposing veteran names, dates of birth, specialized medical testing results, lab reports, health insurance data, and partial Social Security numbers. The VA confirmed that 29,483 affected individuals will receive formal mailed notifications regarding identity monitoring services. The VA found Baylor's initial notification untimely and requested that the company rotate its Amazon Web Services (AWS) S3 storage access keys. Florida healthcare providers, hospital systems, and medical testing facilities using third-party genetic or laboratory vendors must conduct rigorous third-party vendor risk assessments, enforce strict data encryption standards, and ensure contractual reporting requirements for security incidents.
Medical Imaging Archive Vulnerabilities Put Patient Scans at Risk Health security researchers disclosed critical software vulnerabilities impacting picture archiving and communication system (PACS) platforms and digital imaging archives deployed across clinical facilities. The security defects allow cyber threat actors to manipulate medical image databases, exfiltrate sensitive patient diagnostic scans, and execute arbitrary code on connected health systems. Because medical imaging servers directly interface with electronic health record platforms and Digital Imaging and Communications in Medicine (DICOM) routers, unpatched vulnerabilities create severe patient privacy and operational availability risks. Florida hospital networks, diagnostic imaging centers, and clinical healthcare providers must isolate PACS environments behind internal firewalls, enforce strict access controls under Health Insurance Portability and Accountability Act (HIPAA) guidelines, and apply vendor patches immediately.
Astrana Health Data Breach Exposes Private Patient Information Following Employee Impersonation Healthcare provider Astrana Health submitted a regulatory filing to the Securities and Exchange Commission confirming that cyber threat actors exfiltrated certain private and confidential information from the servers of its subsidiary, Astrana Health Management, following a targeted social engineering campaign. Attackers spoofed the organization's primary telephone number and impersonated internal support staff to trick employees into providing administrative access credentials to corporate servers. The company is still assessing whether patient, employee, provider, or financial information was accessed. It has rotated credentials, restricted remote access tools, and rebuilt certain systems from clean backups. Astrana Health initiated emergency containment measures and engaged external forensic specialists to evaluate the full scope of compromised records. Florida healthcare networks, hospital administrative staff, and medical service groups must implement multi-factor authentication (MFA) across all corporate portals, mandate phone call verification for help desk resets, and train personnel regarding caller spoofing risks.
Over 77 Percent of Ransomware Groups Target the Healthcare Sector Threat intelligence firm Anomali's US Ransomware Industry Targeting Report revealed that more than 77 percent of active ransomware groups intentionally target healthcare organizations and hospital systems. The study highlighted that cybercriminals view healthcare entities as high-value targets due to the critical requirement for uninterrupted operational continuity, legacy infrastructure dependencies, and vast stores of valuable patient data. Successful intrusions frequently result in delayed surgical procedures, ambulance diversions, and forced transitions to manual paper workflows, amplifying organizational pressure to negotiate ransom demands. Florida healthcare providers, emergency medical centers, and clinical facilities must enforce strict network segmentation, maintain immutable offline backups, and deploy MFA across all external entries.
New Galago Ransomware Operation Emerges With Shared Infrastructure Ties to Panzer Group CyberXTron researchers reported Galago, a new ransomware operation first flagged on September 9, 2026, after an unverified claim of an attack on an Icelandic healthcare organization. Galago claims a partnership with the Panzer group, a ransomware-as-a-service operation that listed 32 victims between August 5 and September 23. The two groups' Tor leak-site addresses share a pnzr prefix, but researchers caution that this does not prove shared operators or tooling. Galago's leak site listed no victims when checked. Florida healthcare organizations and hospital networks must enforce phishing-resistant multi-factor authentication (MFA), segment backup and virtualization management systems, and maintain immutable offline backups.
California Critical Access Hospital Announces Network Security Incident Modoc Medical Center, a 12-bed critical access hospital in Alturas, California, is notifying patients of a breach in which an unknown actor accessed its network between January 19 and 27, 2026. The actor downloaded files containing Social Security numbers, financial account and payment card information, and medical and health insurance information. The Worldleaks extortion group claimed responsibility. The same report covers Park Place Behavioral Healthcare in Osceola County, Florida, where an intrusion detected July 23, 2026, exposed patient data; the Insomnia ransomware group claimed that attack. Florida hospital networks and behavioral health providers must enforce multi-factor authentication (MFA), deploy endpoint detection and response, and secure remote access methods.
Threat Groups Surge Social Engineering and Voice Phishing Attacks Against Healthcare Sector The Health Information Sharing and Analysis Center (Health-ISAC) warned that the ShinyHunters group is using voice phishing and medical-themed impersonation domains to target healthcare organizations, and ReliaQuest confirmed a sustained cluster of related phishing infrastructure. Cyber threat actors impersonate internal help desk technicians or corporate IT managers during phone calls, tricking health system employees into providing MFA passcodes or installing remote access tools. More than a dozen Health-ISAC member organizations have been hit by social engineering attacks in recent months. Palo Alto Networks Unit 42 identified the domain my-passkeys[.]com, likely linked to The Com cybercrime network, as phishing infrastructure targeting healthcare and pharmaceutical organizations. Florida healthcare administrators, hospital IT teams, and pharmaceutical firms must enforce strict identity verification protocols for call center requests and train staff regarding voice phishing mechanics.
Healthcare and Public Health Sector Recommendations:
GhostCode Phishing Kit Hijacks Microsoft 365 Accounts by Bypassing MFA Controls Cybersecurity researchers at eSentire disclosed details regarding GhostCode, a sophisticated phishing kit abusing Microsoft Open Authorization (OAuth) device flows to hijack enterprise accounts. The kit tricks victims into completing legitimate authentication prompts, allowing cyber threat actors to capture multi-factor authentication (MFA) tokens and register three devices in Microsoft Entra ID and complete a Microsoft Intune enrollment within 78 seconds of the victim authenticating. The eSentire Threat Response Unit traced the lure to the lookalike domain bjssourcing[.]com and identified more than 30 similar domains registered in August that impersonate U.S. distributors, manufacturers, and other companies. Florida enterprise cloud administrators, IT service providers, and municipal tenants must implement device-bound conditional access rules, require compliant managed devices for single sign-on access, and monitor Microsoft Intune for unexpected device enrollments.
Cisco Patches Critical Zero-Day Vulnerability in Identity Services Engine Cisco released security patches addressing CVE-2026-76460, a maximum-severity zero-day flaw in Cisco Identity Services Engine (ISE). The vulnerability allows cyber threat actors to bypass authentication mechanism checks through a defect in an Application Programming Interface (API), enabling a remote attacker to gain full control of the appliance. Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog after attackers exploited the flaw before Cisco disclosed and patched it. Cisco reports no workarounds and published indicators of compromise (IOCs) to support threat hunting. Florida IT infrastructure operators, communications service providers, and enterprise administrators running Cisco ISE must apply vendor software updates immediately, isolate administrative web portals, and review access logs for anomalous API activity.
Critical Orkes Conductor Vulnerability Exploited in Active Attacks Empirical Security identified in-the-wild exploitation, and Fortinet blocked about 1,300 attempts on September 8 and 9, 2026, targeting CVE-2026-58138, a critical Remote Code Execution (RCE) vulnerability in Orkes Conductor workflow orchestration servers. Because the open-source server enforces no authentication on its workflow Application Programming Interface (API) by default, a single unauthenticated request can submit task expressions that execute operating system commands as the Conductor process, which often runs with root privileges. Although Orkes released a patch in version 3.30.2 in June 2026, public proof-of-concept exploit code published in August triggered a wave of automated attack campaigns. Florida cloud architects, enterprise software developers, and IT service vendors operating Orkes Conductor must upgrade installations to version 3.30.2 or later, restrict public internet access to workflow endpoints, and inspect server execution logs for unauthorized process spawns.
Brevo Supply Chain Compromise Injects Malicious Scripts Across 100,000 Websites On September 18, 2026, security reporting confirmed that customer engagement platform Brevo suffered a supply chain attack that likely impacted over 100,000 websites, per Sansec. Attackers exploited a Brevo single sign-on (SSO) flaw to access 138 accounts, then used a compromised Cloudflare application programming interface (API) key to deploy a malicious worker. For about 5.5 hours, injected scripts showed selected visitors fake Cloudflare checks, urging them to run a command, and tried to install plugins for logged-in WordPress administrators. Florida entities using Brevo integrations should inspect the website source code for unauthorized scripts, audit WordPress plugins, and rotate API keys.
Critical pgAdmin Authentication Bypass Flaw Grants Unauthenticated Root Access A security advisory warned of CVE-2026-86863, a critical authentication bypass vulnerability in pgAdmin 4 deployments that use the webserver authentication source. Rated 9.8 on the Common Vulnerability Scoring System (CVSS) scale, the flaw lets unauthenticated attackers supply a username in request headers and assume the pgAdmin session of an administrator or other privileged user without a password or multi-factor authentication (MFA). Successful exploitation enables cyber threat actors to view, alter, or delete database objects and data accessible through that account. Florida database administrators (DBAs), web hosting providers, and IT infrastructure operators running pgAdmin 4 versions 6.2 through 9.17 must upgrade immediately to pgAdmin 4 version 9.18 and restrict web access to administrative interfaces.
Researchers Escape OpenAI Codex Sandbox to Execute Host Commands On September 20, 2026, Accomplish AI researcher Oren Yomtov detailed two OpenAI Codex sandbox escapes, Heapjack and Overpatch, which OpenAI fixed in August. Heapjack lets untrusted code in Codex Desktop, even in read-only sandbox mode, steal a token from shared Node.js memory and issue commands to unsandboxed host processes. Overpatch abuses the Codex command-line interface (CLI) apply_patch tool to write outside the workspace and modify shell configuration files. No in-the-wild exploitation has been reported. Florida software development firms and enterprise IT teams must update Codex Desktop to build 26.818.21641 and Codex CLI to version 0.149.0 or later.
ClickFix Lures Deploy ChainScript RAT Using Polygon Blockchain for C2 Routing On September 21, 2026, Blackpoint researchers detailed a campaign using ClickFix lures to deliver ChainScript, a previously undocumented remote access trojan (RAT). Masquerading as Spotify, Zoom Workplace, and Microsoft Teams software, the lure leads victims to run a malicious installer (ComponentTask33-4d14e6ac.msi) through msiexec.exe, which installs a Node.js runtime and scheduled-task persistence. ChainScript queries a Polygon smart contract to locate its active command and control (C2) infrastructure, evading takedowns, and stealing cryptocurrency wallets. Florida enterprise network administrators and IT service providers must block unapproved installer execution, restrict traffic to unverified blockchain endpoints, and train personnel to reject command prompts.
Cache Key Injection Technique Allows Access Control Bypass and Nginx Cache Poisoning On September 21, 2026, YesWeHack researchers unveiled Cache Key Injection, a cache poisoning technique that bypasses access controls on Nginx proxy caches. When cache keys concatenate variables without separators, attackers split values across the request path and keyed Hypertext Transfer Protocol (HTTP) headers so different requests collide, exposing restricted cached pages, causing denial of service, or storing cross-site scripting payloads. The issue is a configuration weakness with no CVE or patch. Florida web hosting operators and enterprise IT service providers using Nginx should add separators to cache key rules, validate Host headers, and exclude authenticated requests from shared caches.
Settra Ransomware Variant Deployed via Compromised VPN Credentials and RMM Tools Huntress and MoxFive warned of Settra, a newly discovered ransomware variant used against a retail organization in July and a manufacturing firm in September. Cyber threat actors likely gained initial access through compromised virtual private network (VPN) credentials, then deployed the MeshAgent remote monitoring and management (RMM) tool, renamed mvtcs.exe. Operators used vulnerable drivers to disable security tools, named payloads after victim domains, cleared Windows Event Logs, disabled the Windows Recovery Environment, and encrypted files. Florida IT service providers, managed service providers (MSPs), and enterprise administrators must secure VPN credentials, audit RMM agent installations, and isolate offline backup repositories.
Attackers Abuse npm Trusted Publishing Mechanism in GHAPPIER Supply Chain Campaign CloudSEK researchers disclosed the GHAPPIER campaign, a supply chain attack that abused npm Trusted Publishing to distribute a malicious version of the @dforge-core/dforge-mcp package. Using a stolen maintainer key on September 9, 2026, cyber threat actors modified the GitHub Actions release workflow, which used OpenID Connect (OIDC) trusted publishing to release version 0.2.21 with authentic provenance metadata. The payload executes during the Model Context Protocol (MCP) server launch. Florida software development organizations and enterprise IT teams should pin the package to version 0.2.22, treat lockfiles referencing 0.2.21 as compromised, and monitor release workflow modifications.
New TASK#STOMP Windows Backdoor Enables Continuous Business Document Theft On September 22, 2026, security researchers at Securonix published details regarding TASK#STOMP, a stealthy Windows backdoor designed for persistent document theft. Initiated via a Visual Basic Script (VBScript) installer that masquerades as a Windows service directory named WinDefendSvc, the malware uses PowerShell and Task Scheduler to establish multiple persistence mechanisms. TASK#STOMP executes hidden PowerShell scripts to decode Base64 payloads stored in configuration files, scanning local drives for Word documents, spreadsheets, PDFs, and compressed archives before exfiltrating matching files to command and control (C2) servers. The malware also compiles C# code at runtime to bypass Transport Layer Security (TLS) certificate validation checks. Indicators include the C2 domains corecloudfileshare[.]xyz and attachmentsharingdrive[.]xyz, the LocalAppData\WinDefendSvc folder, and the scripts sys_loader.ps1 and win_conn.ps1.Florida enterprise IT managers, software vendors, and MSPs should monitor user-writable folders for unapproved PowerShell scripts, audit Task Scheduler entries, and inspect runtime C# compilation activity.
CISA Orders Federal Agencies to Patch Actively Exploited Zyxel Switch Vulnerability The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-7273, a high-severity stack-based buffer overflow in Zyxel GS1900 series switches, to its Known Exploited Vulnerabilities (KEV) catalog on September 21, 2026. The flaw lets unprivileged attackers on the local network execute operating system commands through crafted HTTP requests. GreyNoise reported that a suspected Chinese-speaking actor exploited 996 switches across 48 countries and exfiltrated data starting September 17. CISA ordered federal civilian agencies to remediate by September 24. Florida network administrators and critical infrastructure operators using GS1900 switches must install model-specific fixed firmware (versions ending in .2)C0) and restrict switch administrative access.
Hackers Exploit Veeam Agent Vulnerability to Gain SYSTEM Privileges on Windows On September 22, 2026, security reporting highlighted public proof-of-concept exploit code, released September 14, for CVE-2026-32996, a local privilege escalation flaw in Veeam Agent for Microsoft Windows. The flaw affects version 13 builds through 13.0.1.2067, and the researcher states builds through 13.0.2.1102 remain vulnerable, letting low-privileged local users execute commands with NT AUTHORITY\SYSTEM privileges. Exploitation requires an existing foothold. Veeam fixed the flaw in Veeam Backup & Replication 13.0.2.29, which updates the agent to build 13.0.3.1220. Florida system administrators and managed service providers (MSPs) must update Veeam Agent installations immediately and restrict administrative access to backup servers.
Graphalgo Supply Chain Attack Uses Fake Terraform Providers and Go Modules to Deploy RAT Aikido researchers reported that the Graphalgo supply chain campaign expanded to malicious Terraform providers (gocommunity-io/dockerd and kreuzwenker/docker, a typosquat of kreuzwerker/docker) and Go modules (gocommunity.io/orderedbtree and gogets.dev/btreex), using deceptive GitHub organizations, fake vanity domains, and forged commit timestamps. When a hard-coded check matches a selected victim, the code decrypts and launches a Go-based remote access trojan (RAT) that collects system details and runs further payloads, polling Slack and Arbitrum Sepolia smart contracts for command and control (C2). Florida software developers and DevOps teams must audit Terraform lock files and Go caches for these packages.
Novel ClosedQuorum Windows Malware Queries Public AI Models to Direct Post-Compromise Actions Cisco Talos disclosed ClosedQuorum, a novel Windows malware strain that leverages public AI models to autonomously determine post-compromise actions. Discovered using the open-source CAIRN tracking toolkit, the malware issues Application Programming Interface (API) queries to Google Gemini, DeepSeek, Qwen, and Mistral models to analyze host system telemetry and select secondary attack modules. Based on AI response payloads, ClosedQuorum dynamically executes process hollowing, Early Bird asynchronous procedure call (APC) injection, persistence routines, or credential and cryptocurrency wallet theft without operator commands, and sends stolen data to operators through a Discord webhook. Talos has not confirmed in-the-wild deployment. Florida technology vendors, enterprise security operations centers, and cloud managers must restrict outbound HTTPS traffic to public AI API endpoints from non-whitelisted developer workstations and monitor endpoint logs for anomalous process injection routines.
F5 Patches Critical BIG-IP APM Zero-Day Vulnerability Exploited in Remote Code Execution Attacks F5 released emergency security updates addressing CVE-2026-94127, a critical zero-day vulnerability in BIG-IP Access Policy Manager (APM) actively exploited in remote code execution attacks. Impacting instances configured as OAuth Authorization Servers on virtual servers, the flaw allows cyber threat actors to execute code remotely. The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-94127 to its Known Exploited Vulnerabilities (KEV) catalog on September 22, 2026, and ordered federal agencies to secure systems by Friday, September 25, 2026. Shadowserver telemetry identified over 14,700 internet-exposed BIG-IP APM instances worldwide. Florida enterprise network defenders, IT service providers, and cloud data center operators running BIG-IP APM must apply vendor patches immediately, deploy F5 iRule mitigations if patching is delayed, and inspect logs for TMM SIGABRT crash events.
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape On September 22, 2026, DepthFirst released proof-of-concept exploit code for CVE-2026-80521, a use-after-free flaw in the Linux kernel AF_UNIX socket garbage collector. Upstream fixes shipped August 6 in kernels 7.2 and 7.1.10, but Ubuntu has not patched 26.04, 24.04 LTS, or 22.04 LTS. The flaw lets code inside Docker or Kubernetes containers, where default seccomp profiles allow AF_UNIX sockets, gain host root. No active exploitation has been confirmed. Florida cloud hosting providers and Linux administrators must apply kernel updates when available, isolate untrusted workloads in microVMs such as Firecracker or Kata Containers, and monitor containers for host-level process spawning.
Adobe Patches 36 Security Defects Including Critical Flaws in Connect and AEM Forms Adobe released security updates resolving 36 vulnerabilities across its software suite, including nine flaws in Adobe Connect (six critical) and six flaws in Experience Manager (AEM) Forms (three critical). The fixed vulnerabilities include Structured Query Language (SQL) injection, cross-site scripting, improper input validation, incorrect authorization, and server-side request forgery flaws that cyber threat actors can exploit to execute arbitrary code or escalate system privileges. While Adobe reported no active zero-day exploitation in the wild, the vendor assigned a Priority 2 rating, advising enterprise administrators to deploy updates within 30 days. Florida commercial entities, educational institutions, and IT service providers operating Adobe Connect or AEM Forms enterprise servers must apply vendor patches immediately and restrict external access to administrative forms portals.
Critical cPanel Vulnerability Allows Low-Privilege Mail Accounts to Execute Root Code Security reporting highlighted CVE-2026-87899, a critical vulnerability in the CalDAV and CardDAV service of cPanel and WebHost Manager (WHM) version 120 and later that allows any logged-in account holder with valid cPanel credentials to run code as root and take full server control. cPanel fixed the flaw in builds 11.134.0.57, 11.136.0.41, 11.138.0.8, and WP Squared 11.138.1.11 or later. cPanel also fixed CVE-2026-68490 in the same service and CVE-2026-87900 in the WP Toolkit plugin, which requires a separate update to WP Toolkit 6.11.3. Florida web hosting providers, cloud service vendors, and enterprise IT administrators running cPanel must execute /usr/local/cpanel/scripts/upcp --force immediately to upgrade to secure software builds.
China-Aligned Group UTA0565 Exploits Chrome and Microsoft Zero-Day Chain in Espionage Campaign Volexity reported that China-aligned espionage group UTA0565 exploited three zero-days: CVE-2026-85046 and CVE-2026-87491 in the Chromium JavaScript engine, and CVE-2026-85880, a Windows Advanced Local Procedure Call (ALPC) privilege escalation flaw. Observed on September 3 and 4, before patches, the actor sent phishing emails to Asian government entities and used spoofed domains and decoy sites copying legitimate content to deliver CLEANGULP malware. Volexity assessed that the core exploit kit was likely shared among multiple Chinese groups. Florida technology providers and enterprise network administrators must patch Chromium browsers and Windows, including Microsoft's September 8 fix for CVE-2026-85880.
MikroTrick Exploit Chain Allows Full Takeover of MikroTik Routers Without Authentication CERT Polska analyzed "MikroTrick," an exploit chain giving unauthenticated attackers full administrative control of MikroTik RouterOS devices with reachable Secure Shell (SSH) services. It combines CVE-2026-67279, an SSH key renegotiation flaw, and CVE-2026-86060, a login argument injection flaw triggered by the username "-2." Exploitation began by September 2, 2026, before September 3 patches, and the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-86060 to its Known Exploited Vulnerabilities (KEV) catalog. Attackers created an "ops" full-privilege account and exfiltrated configurations. Florida network operators must update to RouterOS 6.49.21, 7.23.4, or 7.24.2, restrict SSH exposure, and factory reset compromised devices.
GitLab Incoming Email Addresses Weaponized for Supply Chain Attacks Aikido Security researchers disclosed a supply chain risk in GitLab: each user's private incoming email address contains a non-expiring token. Anyone holding the address can push code to main branches, open merge requests, and run continuous integration and continuous delivery (CI/CD) jobs in projects the owner can access, bypassing IP address restrictions. Researchers found about a dozen addresses exposed in README and support files; no exploitation has been reported. GitLab considers this intended behavior and issued no patch. Florida software engineering firms must scan repositories for exposed GitLab email addresses, rotate the embedded tokens, and restrict email-based repository interactions.
Check Point Warns of Hackers Exploiting Security Gateway VPN RCE Vulnerability Check Point warned that attackers have exploited CVE-2026-85102, a pre-authentication remote code execution (RCE) flaw in the Security Gateway virtual private network (VPN) certificate-handling function, since September 12, 2026, and CVE-2026-93616, a management web service path traversal flaw exploited as a zero-day since July 23. Federal agencies must remediate by September 25. Fixes include LivePatch Take 26 for R81.20, R82, and R82.10, and Jumbo Hotfixes R81.10 Take 190, R81.20 Take 166, R82 Take 126, and R82.10 Take 44. Florida network defenders must patch immediately or disable VPN implied rules and restrict Site-to-Site VPN peers.
Attackers Exploit WordPress Vulnerability CVE-2026-87902 Within Hours of Disclosure WordPress patched CVE-2026-87902, a critical core flaw, on September 22, 2026, and attackers began exploiting it the same day. The flaw lets unauthenticated attackers trigger local file inclusion and write malicious Hypertext Preprocessor (PHP) files into /tmp and /var/tmp when the active theme has a "page-" directory and a readable file such as pearcmd.php exists. Fixed releases are 7.1.2, 7.0.6, 6.9.9, and 6.8.10. The Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog with a September 28 federal deadline. Florida website managers must update immediately and inspect temporary directories for unauthorized PHP scripts.
Roundcube Webmail Flaw Allows Unauthenticated SQL Injection Exploitation On September 21, 2026, the Canadian Centre for Cyber Security updated an advisory warning of active exploitation of CVE-2026-48842, a high-severity vulnerability in Roundcube Webmail. The flaw stems from an unauthenticated SQL injection defect within the virtuser_query plugin, enabling cyber threat actors to execute arbitrary database queries without login credentials. Exploitation can expose user data, mailbox details, contacts, and application configurations, or modify and delete database content. Roundcube released fixed versions 1.6.16 and 1.7.1 on May 24, 2026. Florida IT administrators and enterprise email managers running Roundcube Webmail must upgrade immediately and inspect database logs for anomalous SQL queries.
Carbonato Malware Uses AI Framework to Hijack Exposed Unauthenticated Docker Hosts On September 24, 2026, ThreatDown researchers warned of Carbonato, a worm-like botnet targeting Docker daemons exposed on port 2375 without authentication. Carbonato deploys a privileged container to gain host access, opens reverse Secure Shell (SSH) tunnels, and persists through cron and systemd timers. It installs the Hermes Agent artificial intelligence (AI) framework with a "GH0ST" persona that takes Telegram commands to steal application programming interface (API) keys and credentials, while scripts scan for other exposed daemons. Indicators include a CARBONATO_API_KEY setting and unexpected Telegram traffic. Florida container administrators must remove public access to Docker daemon APIs and mandate registry authentication.
Salesbleed Flaws Abuse Salesforce Agentforce to Enable Slack Internal Phishing Researchers at Zenity disclosed Salesbleed, three weaknesses in Salesforce Agentforce that allow cyber threat actors to manipulate AI agents into launching internal phishing attacks inside corporate Slack channels. By injecting indirect prompt injection payloads into public Web-to-lead registration forms, external attackers induce Salesforce AI agents to post malicious messages and phishing links directly into internal company Slack threads. Because the automated messages originate from trusted corporate bots, employees are likely to execute the phishing links without suspicion. Salesforce issued default configuration updates requiring user confirmation before agents post Slack messages. Salesforce also adopted standards-compliant URL parsing to close a filter bypass. No CVE identifier was assigned, and there is no evidence of exploitation in the wild. Florida enterprise technology leaders, cloud administrators, and software vendors must audit Salesforce Agentforce permissions, enforce message confirmation prompts, and train staff regarding bot-delivered phishing lures.
ServiceNow Discloses Five Vulnerabilities Allowing Unauthenticated SQL Injection and Data Modification ServiceNow released updates resolving five ServiceNow AI Platform vulnerabilities. Critical flaws CVE-2026-13016 (Structured Query Language injection) and CVE-2026-86860 (missing authorization) let unauthenticated attackers access or modify data and escalate privileges. High-severity flaws CVE-2026-86857, CVE-2026-86858, and CVE-2026-86859 enable authorization bypass and unauthenticated data creation, modification, or deletion. ServiceNow reported no evidence of exploitation and confirmed patches reached cloud customers in its August Patching Program. Florida IT service providers and administrators operating self-hosted ServiceNow instances must apply September 2026 remediations (Yokohama Patch 13 HF5a, Zurich Patch 11 HF3, or Australia Patch 5) to prevent unauthorized database access.
Kiteworks Urges Customers to Temporarily Shutdown Servers Following Zero-Day Threat Warnings Secure file transfer provider Kiteworks advised customers to shut down their systems during a six-hour window on Saturday after federal intelligence authorities warned that a threat actor may attempt to target some Kiteworks systems. Kiteworks said it knows of no compromise and called the advisory preventative; a support official cited a potential zero-day vulnerability, but no CVE or technical details were disclosed. Kiteworks said all known vulnerabilities are addressed in release 9.5.1. Florida technology vendors, managed service providers, and enterprise IT teams must upgrade to Kiteworks 9.5.1, follow vendor shutdown guidance, and restrict public access to file transfer gateways.
Model Context Protocol Creates Major Enterprise Security and Governance Gaps On September 28, 2026, Ox Security researchers warned of governance gaps after analyzing 15,465 Model Context Protocol (MCP) servers. Nearly 16 percent of hostnames resolve outside the U.S., including Russia and China, and over 2 percent no longer resolve, leaving purchasable domains that attackers could use to impersonate servers. A malicious MCP server obtained credentials from a coding agent granted always-allow permissions. Earlier Ox research found that design choices in official MCP Software Development Kit (SDK) libraries can enable command execution. Florida enterprise cloud administrators and AI architects must audit deployed MCP servers, enforce network isolation, and restrict agent execution privileges.
JADEPUFFER-Linked Threat Actors Abuse Compromised Service Principals to Delete Azure Resources Microsoft reported that cyber threat actors linked to JADEPUFFER, tracked as Storm-3168, abused two compromised Azure service principals, whose credentials were exposed in a public GitHub issue, to delete resources in one tenant in early June 2026. In an 18-hour intrusion, attackers deleted most targeted storage accounts plus a Key Vault, Function App, and backup resources; SQL database deletions failed, and resource locks blocked some actions. Microsoft assessed the activity as ransomware-aligned but observed no ransom note. Florida cloud architects and security operations teams must enforce least-privilege service principals, implement cloud deletion alerts, and enable resource locks.
Lunex Stealer Abuses Signed AMD Driver to Disable Security Controls and Steal Credentials Researchers revealed that the Lunex malware-as-a-service platform distributes a stealer targeting Ukrainian-speaking users through compromised Ukrainian websites. Fake CAPTCHA prompts deliver malicious Microsoft Installer (MSI) packages. The loader bypasses User Account Control, then abuses the vulnerable AMD driver PDFWKRNL.sys (CVE-2023-20598) to blind security processes while leaving them running, which the Microsoft vulnerable driver blocklist does not stop. The malware persists through Run keys, a scheduled task named psychedelicloveUtils, and a Google Chrome native messaging host, and contacts 193.178.159[.]128. Florida enterprise IT managers and security teams must block unapproved installers, detect PDFWKRNL.sys loading, and monitor for these indicators.
Google Warns of Fresh ShinyHunters Campaign Exploiting Oracle PeopleSoft Vulnerabilities Google Threat Intelligence Group warned of a renewed mass-exploitation campaign by ShinyHunters (UNC6240) targeting Oracle PeopleSoft. Attackers modified exploits for CVE-2026-35273, an unauthenticated remote code execution flaw, using URL encoding in the /PSEMHUB path to evade web application firewall (WAF) rules, then deployed web shells, the SideEye backdoor, and MeshCentral to steal data for extortion. After compromising over 100 customers in June, the campaign expanded to government, healthcare, transportation, and technology. Florida network defenders and IT service providers running Oracle PeopleSoft must apply Oracle's patches for CVE-2026-35273, normalize URLs before WAF matching, and hunt for compromise indicators.
GitHub Actions Re-Enabled With Malicious Mini Shai-Hulud Supply Chain Payload Still Active On September 26, 2026, security reporting revealed that two GitHub Actions compromised in May by the Mini Shai-Hulud attack, actions-cool/issues-helper and actions-cool/maintain-one-comment, became accessible again on September 16 without cleaned release tags. Workflows referencing them by mutable tags could run a payload that steals developer tokens, credentials, and continuous integration and continuous delivery (CI/CD) secrets. About 15,000 repositories depend on issues-helper, though the number exposed is unknown. GitHub disabled both actions again on September 25. Florida software developers and DevOps teams must remove or pin these actions to verified commits, review runs since September 16, and rotate exposed secrets.
Microsoft Dissects NeedyMantis Malware Framework Used for Long Term Network Access Microsoft Threat Intelligence published an analysis of NeedyMantis, a modular malware framework used by Storm-3069, a developing group whose activity appears to originate in China. Active since at least October 2025, NeedyMantis uses legitimate programs such as Poedit, curl, and TightVNC to sideload a malicious DLL that unpacks encrypted payloads. Operators already inside networks deploy it with Impacket against telecommunications, university, medical nonprofit, intergovernmental, and government contractor targets. Indicators include corp.tripswithengine[.]com and the user agent firefox/21.0. Florida enterprise IT managers, telecommunications operators, and managed service providers (MSPs) should block these indicators and monitor for DLL sideloading.
Apple Issues Emergency Patches for CoreGraphics Zero-Day Vulnerability Exploited in Targeted Attacks Apple released iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1 to address CVE-2026-86950, an out-of-bounds write vulnerability in CoreGraphics that could allow arbitrary code execution when a device processes a maliciously crafted file. Apple stated it is aware of a report that the flaw may have been exploited in an extremely sophisticated attack against specific targeted individuals on iOS versions before iOS 27. The Cybersecurity and Infrastructure Security Agency (CISA) added the flaw to its Known Exploited Vulnerabilities (KEV) catalog with an October 2, 2026, federal deadline. Florida enterprise mobile device managers, government personnel, and IT administrators operating iOS devices must apply Apple firmware updates immediately and restrict unverified file processing across mobile endpoints.
Information Technology Sector Recommendations:
No sector-specific incidents, advisories, or operationally relevant reporting were identified during this reporting period.
China-Linked Threat Actors Escalating Cyber Espionage Campaigns Against European Maritime Shipping The European Union Agency for Cybersecurity (ENISA) Threat Landscape 2026 report found that China-linked group Mustang Panda (Earth Preta) ran continuous espionage campaigns during 2025 against maritime-related organizations in at least seven EU member states. The group used spear-phishing, compromised USB drives, and customized PlugX malware, potentially reaching shipboard systems considered isolated. Korean cyber specialist CYTUR found vulnerabilities requiring risk treatment in the overwhelming majority of shipboard systems it examined. Florida port authorities, maritime logistics operators, and terminal managers must segment shipboard information technology (IT) from operational technology (OT), control removable media, and patch routers and edge devices.
Corp MDM Spyware Targets Logistics Firms to Steal SMS Data and Redirect Calls On September 24, 2026, researcher Ben Folland revealed Corp MDM (com.corp.mdm), Android spyware targeting logistics and freight firms. Fake Google Play pages impersonating CEVA Logistics and TKW Logistics, including playgoogle.ceva-app[.]help and playgoogle.logisticstkwcargo[.]com, trick personnel into sideloading malicious Android application package (APK) files. Corp MDM hides its launcher icon, exfiltrates incoming Short Message Service (SMS) messages, including one-time passcodes, enables unconditional call forwarding, and contacts 69.55.61[.]82. Researchers suspect an Armenian or Russian nexus. Florida logistics companies and freight operators must enforce mobile device management (MDM) policies, restrict sideloading, block these indicators, and mandate hardware security tokens.
Nearly Nine in Ten Maritime Organizations Report Major OT Cyber Incident in Past Year Honeywell's 2026 Operational Technology Cybersecurity Benchmark Report, a cross-sector survey of more than 600 leaders, found that 87 percent of maritime respondents suffered a significant operational technology (OT) cyber incident during the past 12 months, second only to energy and utilities at 91 percent. Only 21 percent of respondents maintain a full OT asset inventory. Separately, NAVTOR patched high-severity vulnerabilities in legacy NavBox shipboard data gateways. Florida port authorities, commercial shipping operators, and maritime logistics companies must apply NAVTOR NavBox updates, segment shipboard information technology (IT) from OT systems, and enforce multi-factor authentication (MFA) across remote management portals.
Keio Railway Group Servers Hit by Ransomware Attack Disrupted Business Systems Japanese transit operator Keio Corporation confirmed that a ransomware attack hit server infrastructure across its group companies, disrupting internal business software and hotel reservation systems. Keio Corporation immediately disconnected affected network segments and engaged cybersecurity specialists to isolate infected servers while preserving passenger train operations across its 85-kilometer transit network. The incident follows a separate concurrent cyber breach targeting Tokyo Metro, highlighting heightened threat activity against Japanese transportation infrastructure. Florida transit authorities, passenger rail operators, and transportation logistics companies must enforce strict network segmentation between OT transit controls and corporate IT infrastructure, enforce MFA across remote maintenance portals, and maintain isolated data backups.
Transportation Systems Sector Recommendations:
Hackers Target Small Colorado Water Systems Raising Iran Link Concerns Public reports disclosed cyber intrusions targeting two small municipal water systems in Colorado, each serving fewer than 200 residents. Reports raised concerns that Iranian cyber threat actors may be involved; the intruders gained unauthorized access to internet-exposed operational technology (OT) assets and cellular modems connected to field programmable logic controllers (PLCs). Federal authorities, including CISA, emphasized that low-resource utility providers remain primary targets for opportunistic compromise due to unpatched perimeter devices and default administrative credentials. Florida water and wastewater utility directors, municipal public works departments, and plant operators must remove direct internet exposure from field controllers, enforce MFA on cellular gateways, and maintain manual operational failover procedures.
Strengthening Critical Infrastructure Cybersecurity Following State-Level System Breaches Industry analysis evaluated cybersecurity postures across municipal water utilities following a series of network intrusions impacting operational technology (OT) systems across more than 12 states. The report emphasized that municipal water treatment facilities remain vulnerable due to legacy programmable logic controller (PLC) hardware, direct internet connectivity for remote monitoring, and shared administrative credentials. Industry experts urged utility directors to implement comprehensive security baselines established by the Cybersecurity and Infrastructure Security Agency (CISA), prioritize network segmentation between business information technology (IT) and plant OT environments, and maintain manual operational overrides. Florida water utility directors, municipal public works departments, and treatment plant operators must remove direct public access from field PLCs, enforce multi-factor authentication (MFA) on remote maintenance portals, and conduct regular offline operational drills.
Water and Wastewater Systems Sector Recommendations:
1 min read
Originally Published Sept 23, 2026
1 min read
Originally Published Sept 9, 2026
1 min read
Originally Published August 31, 2026