Daily Security Intel

Archives
Log in
Subscribe
September 11, 2026

[SecurityIntel] 11 Sep | AI-driven agents and zero-days fuel global exploitation.

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Friday, September 11, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

AI-driven agents and zero-days fuel global exploitation.

CRITICAL

5

C2 IPs

2

OTX IOCs

39

ARTICLES

■ ANALYST TLDR

Active exploitation of critical enterprise infrastructure is surging, highlighted by Citrix NetScaler's CVE-2026-19490 and Check Point VPN certificate flaws enabling unauthenticated remote code execution. Threat actors are also leveraging advanced automation, including a Russian-speaking group utilizing hundreds of AI agents to compromise PaperCut instances, and the "BlueMoon" exploit kit leveraging zero-days in Windows and Chrome. Organizations must also contend with operational disruptions from Microsoft's September updates and a massive data exposure of 153 million driver's license scans at IDScan.

■ CRITICAL STORIES

CRITICAL#1

Critical NetScaler Vulnerability Exploited in Attacks

Citrix NetScaler CVE-2026-19490 authentication bypass is being actively exploited in the wild, posing an immediate threat to enterprise perimeter security.

CRITICAL#2

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

Check Point patched two critical flaws in its firewall and management products that allow unauthenticated remote code execution via VPN certificate handling.

HIGH#3

AI-powered attack exploited PaperCut flaws to hack 395 organizations

A Russian-speaking threat actor deployed hundreds of automated AI agents to orchestrate a rapid, global exploitation campaign targeting PaperCut NG/MF servers.

HIGH#4

IDScan confirms breach tied to 153 million stolen driver’s licenses

Identity verification firm IDScan confirmed a cloud platform breach that exposed over 153 million driver's license scans, highlighting severe supply chain and identity theft risks.

■ CVEs IDENTIFIED

CVE-2026-19490

Citrix NetScaler ADC / Gateway — Authentication bypass exploited in the wild.

Critical

[CVE-TBD]

Check Point Firewall and Management Products — Unauthenticated remote code execution via VPN certificate handling.

Critical

[CVE-TBD]

Google Chrome — Actively exploited V8 engine vulnerability and zero-days.

Critical

[CVE-TBD]

Cisco Secure Firewall Management Center (FMC) — Vulnerabilities exploited by ransomware and state-sponsored groups.

High

■ THREAT ACTORS

BlueMoon Exploit Kit Operators

Cyber-espionage groups

Deploying exploit kit leveraging Windows and Chrome zero-day flaws.

Russian-speaking AI Operator

Advanced Persistent Threat (APT)

Utilizing hundreds of AI agents to automate and scale attacks on PaperCut servers.

Gigabud Operators

Cybercriminals

Deploying Android banking trojans that leverage Work Profiles to evade security checks.

■ ATT&CK TTPs

T1190
Exploit Public-Facing Application | Exploitation of Citrix NetScaler, Check Point VPN, and PaperCut flaws.
T1588.006
Obtain Capabilities: Vulnerabilities | Use of BlueMoon exploit kit leveraging zero-day flaws.
T1624
Sandbox Evasion | Gigabud trojan creating Android Work Profiles to bypass security checks.
T1486
Data Encrypted for Impact | Mantax Otax Android ransomware encrypting user files.
T1566
Phishing | AI-assisted BEC campaigns using executive impersonation and fake invoices.
T1078
Valid Accounts | Exploiting default "sk-1234" admin keys on exposed LiteLLM gateways.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Citrix — NetScaler ADC / Gateway authentication bypass (CVE-2026-19490) actively exploited in the wild — SecurityWeek

[P1 PATCH NOW]≤24h

Check Point — Firewall and Management VPN certificate flaws (9.8 rating) enabling unauthenticated RCE — The Hacker News

[P1 PATCH NOW]≤24h

Google — Chrome V8 and zero-day vulnerabilities actively exploited by exploit kits — Malwarebytes

[P2 PATCH NOW]≤72h

Cisco — Secure Firewall Management Center (FMC) vulnerabilities exploited by ransomware/state-sponsored actors — BleepingComputer

■ RECOMMENDED ACTIONS TODAY

1[P1] Apply immediate security patches to Citrix NetScaler to remediate CVE-2026-19490 and prevent active authentication bypass attacks.
2[P1] Deploy Check Point's hotfixes for the critical 9.8-rated VPN certificate vulnerabilities to block unauthenticated RCE.
3[P1] Update Google Chrome across all enterprise endpoints to patch the actively exploited V8 vulnerability and prevent BlueMoon exploit kit execution.
4[P2] Audit all LiteLLM AI Gateway deployments and ensure the default "sk-1234" admin key is disabled or changed.
5[P2] Apply the latest security patches to PaperCut NG/MF servers to defend against automated AI-agent exploitation campaigns.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 14 Sep | Tencent Sogou Flaw Exploited to Deploy GrayRabbit Older → [SecurityIntel] 10 Sep | Cisco Secure FMC Auth Bypass Actively Exploited
Powered by Buttondown, the easiest way to start and grow your newsletter.