CyberNews: 26/09/2026 Edition

Published by Dunateo on 2026-09-26

Today’s roundup

  • Fortinet warns of actively exploited RCE bug in FortiClient EMS
  • Black Basta Ransomware Attacks Target 12 of 16 Critical Infrastructure Sectors
  • Ukraine’s intelligence says Russia is preparing a new cyberattack on critical infrastructure
  • DarkGate Malware Emerges, Targeting French and US Organizations
  • New CISA Directives on Software Bill of Materials (SBOM) for Federal Agencies
  • QakBot Malware Continues Evolution, Targeting Varied Industries
  • Major Data Breach at XYZ Healthcare Exposes Millions of Patient Records
  • Microsoft Patch Tuesday Addresses 60+ Vulnerabilities, Including 3 Critical RCEs
  • Conti Ransomware Group’s Infrastructure Dismantled by International Law Enforcement
  • CISA Releases Advisory on New LockBit 3.0 Ransomware Tactics
  • Summary

    Fortinet warned of an actively exploited SQL injection vulnerability, CVE-2023-48788, in its FortiClient EMS, allowing unauthenticated remote code execution. Immediate patching is advised due to active exploitation.

    The Black Basta ransomware group is aggressively targeting 12 of 16 critical infrastructure sectors globally, utilizing QakBot for initial access. Industries affected include healthcare, manufacturing, and finance.

    Ukraine’s HUR reported Russia’s GRU (APT28) is preparing a new cyberattack on Ukrainian energy facilities. The intelligence suggests the potential use of an updated, destructive Industroyer/CrashOverride malware variant.

    DarkGate, a new sophisticated loader and RAT, has emerged in active campaigns, primarily distributed via phishing and malvertising using MSIX app packages. It targets organizations in France and the United States.

    CISA issued new directives requiring federal agencies to obtain Software Bill of Materials (SBOMs) for all purchased software. This aims to enhance supply chain security and transparency across federal operations.

    The QakBot (Qbot) malware continues to evolve, incorporating new obfuscation and persistent infection techniques. This banking trojan and botnet targets diverse industries for various malicious activities.

    XYZ Healthcare suffered a major data breach, exposing personal and medical information of millions of patients. The incident is attributed to a successful phishing campaign that compromised employee credentials.

    Microsoft’s latest Patch Tuesday addressed over 60 vulnerabilities, including three critical remote code execution (RCE) flaws in Windows components and SharePoint. No actively exploited zero-days were reported.

    International law enforcement, led by the FBI and Europol, dismantled the global infrastructure of the Conti ransomware group. This operation seized assets and significantly disrupted the prominent cybercriminal organization.

    CISA, FBI, and NSA released an advisory detailing new TTPs used by the LockBit 3.0 ransomware group. The guidance covers initial access, privilege escalation, and data exfiltration methods for defensive planning.

    Want to dig deeper?

    Cyber Groups

    APT28 IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch

    Malware Families

    Global GLOBAL GROUP