SECURITYINTEL DAILY BRIEF ■ ThreatIntel BriefThursday, September 17, 2026 INTEL CONFIDENCE 100% | THREAT LEVEL CRITICAL |
|
THREAT OF THE DAY First Agentic AI Data Breach Reported in Spain | CRITICAL |
|
5 C2 IPs | 112 OTX IOCs | 37 ARTICLES |
|
■ ANALYST TLDR Today's threat landscape is highlighted by the active exploitation of CVE-2026-89026 in the Issabel Framework and a Google Pixel Modem zero-day vulnerability (CVE-2026-58704). Additionally, Spain's data protection agency has received its first report of an autonomous, agentic AI-powered data breach, while Iranian state-linked actors deploy the CHOSEN BRICK malware for targeted surveillance. |
|
■ CRITICAL STORIES First Agentic AI Data Breach Reported to Spanish Regulator This marks a significant milestone in autonomous cyber warfare, where an AI agent successfully chained login, vulnerability discovery, and data exfiltration without human intervention. |
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution Attackers are actively exploiting CVE-2026-89026 (CVSS 9.8), allowing unauthenticated remote code execution on Issabel PBX unified communications systems. |
Pixel Modem Zero-Day Exploited in Targeted Attacks A high-severity privilege escalation vulnerability in the Google Pixel Cellular Modem (CVE-2026-58704) is being actively exploited in targeted attacks in the wild. |
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets Government agencies have exposed a campaign by Iranian state-linked hackers deploying CHOSEN BRICK malware via Telegram C2 to spy on global dissidents and activists. |
|
■ CVEs IDENTIFIED CVE-2026-89026 Issabel Framework — Unauthenticated OS Command Execution |
CVE-2026-58704 Google Pixel Cellular Modem — Privilege Escalation / Zero-day exploitation |
[CVE-TBD] Parallels Desktop for Mac — Local Privilege Escalation (Non-admin to root) |
[CVE-TBD] The Events Calendar (WordPress Plugin) — Unauthenticated Remote Code Execution |
|
■ THREAT ACTORS Iranian State-Linked Hackers | APT |
Deploying CHOSEN BRICK malware via Telegram C2 to target dissidents and activists. |
Targeting Russian enterprises with backdoors, ransomware, and wipers. |
Targeting Russian enterprises with backdoors, ransomware, and wipers. |
|
|
|
■ ATT&CK TTPs | T1059.003 | | Command and Scripting Interpreter: Windows Command Shell | Issabel Framework OS command execution (CVE-2026-89026). |
| T1176 | | Browser Extensions | KREMLIN toolkit force-installing extensions; researchers demonstrating AI assistant hijacking via extensions. |
| T1102.002 | | Web Service: Bidirectional Communication | Iranian hackers using Telegram as a C2 channel for CHOSEN BRICK. |
| T1068 | | Exploitation for Privilege Escalation | Google Pixel Modem zero-day (CVE-2026-58704) and Parallels Desktop for Mac privilege escalation. |
| T1566 | | Phishing | N0va phishkit targeting US/EU businesses; AI-assisted fake Avast antivirus renewal pages. |
| T1539 | | Steal Web Session Information | KREMLIN malware stealing session tokens; hijacking active AI coding-assistant sessions. |
|
■ PATCH PRIORITY Issabel — Issabel Framework CVE-2026-89026 allows unauthenticated OS command execution and is actively exploited — [THN] |
Google — Pixel Cellular Modem CVE-2026-58704 is a zero-day privilege escalation actively exploited in targeted attacks — [SW] |
The Events Calendar — WordPress plugin contains unauthenticated RCE vulnerabilities exposing 200,000+ sites — [SW] |
Parallels — Parallels Desktop for Mac privilege escalation allows non-admin users to gain root access — [THN] |
|
|
|
■ RECOMMENDED ACTIONS TODAY | 1 | [P1] Patch Issabel Framework immediately to address CVE-2026-89026 to prevent unauthenticated remote command execution. |
| 2 | [P1] Apply Google's September security update to Pixel devices to patch the actively exploited Pixel Modem zero-day (CVE-2026-58704). |
| 3 | [P1] Update "The Events Calendar" WordPress plugin to the latest version to mitigate unauthenticated remote code execution vulnerabilities. |
| 4 | [P2] Apply the security patch for Parallels Desktop for Mac to prevent local privilege escalation to root (note: Intel Macs may require alternative mitigations as they cannot install the fix). |
| 5 | [P2] Audit Windows 11 enterprise systems for KB5124008 if experiencing domain trust relationship failures, and consider pausing deployment until Microsoft resolves the issue. |
|
|
|
C2 IP BLOCKLIST · AbuseCH Feodo · Showing 5 of 5 IP ADDRESS 162.243.103.246 | PORT 8080 | STATUS OFFLINE | MALWARE Emotet | COUNTRY US |
IP ADDRESS 50.16.16.211 | PORT 443 | STATUS ONLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 34.204.119.63 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY US |
IP ADDRESS 178.62.3.223 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY GB |
IP ADDRESS 27.133.154.218 | PORT 443 | STATUS OFFLINE | MALWARE QakBot | COUNTRY JP |
|
FULL IOC EXPORT — GOOGLE SHEET All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs Updated daily · Export as CSV to import directly into your tools ■ Open Full IOC Sheet → |
|
IOC SOURCES: AbuseCH Feodo · AlienVault OTX NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB |