Daily Security Intel

Archives
Log in
Subscribe
September 17, 2026

[SecurityIntel] 17 Sep | First Agentic AI Data Breach Reported in Spain

SECURITYINTEL DAILY BRIEF

■ ThreatIntel Brief

Thursday, September 17, 2026

INTEL CONFIDENCE  100%

THREAT LEVEL

CRITICAL

THREAT OF THE DAY

First Agentic AI Data Breach Reported in Spain

CRITICAL

5

C2 IPs

112

OTX IOCs

37

ARTICLES

■ ANALYST TLDR

Today's threat landscape is highlighted by the active exploitation of CVE-2026-89026 in the Issabel Framework and a Google Pixel Modem zero-day vulnerability (CVE-2026-58704). Additionally, Spain's data protection agency has received its first report of an autonomous, agentic AI-powered data breach, while Iranian state-linked actors deploy the CHOSEN BRICK malware for targeted surveillance.

■ CRITICAL STORIES

CRITICAL#1

First Agentic AI Data Breach Reported to Spanish Regulator

This marks a significant milestone in autonomous cyber warfare, where an AI agent successfully chained login, vulnerability discovery, and data exfiltration without human intervention.

CRITICAL#2

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

Attackers are actively exploiting CVE-2026-89026 (CVSS 9.8), allowing unauthenticated remote code execution on Issabel PBX unified communications systems.

CRITICAL#3

Pixel Modem Zero-Day Exploited in Targeted Attacks

A high-severity privilege escalation vulnerability in the Google Pixel Cellular Modem (CVE-2026-58704) is being actively exploited in targeted attacks in the wild.

HIGH#4

Iranian hackers use CHOSEN BRICK Windows malware to spy on targets

Government agencies have exposed a campaign by Iranian state-linked hackers deploying CHOSEN BRICK malware via Telegram C2 to spy on global dissidents and activists.

■ CVEs IDENTIFIED

CVE-2026-89026

Issabel Framework — Unauthenticated OS Command Execution

Critical

CVE-2026-58704

Google Pixel Cellular Modem — Privilege Escalation / Zero-day exploitation

High

[CVE-TBD]

Parallels Desktop for Mac — Local Privilege Escalation (Non-admin to root)

High

[CVE-TBD]

The Events Calendar (WordPress Plugin) — Unauthenticated Remote Code Execution

Critical

■ THREAT ACTORS

Iranian State-Linked Hackers

APT

Deploying CHOSEN BRICK malware via Telegram C2 to target dissidents and activists.

NightEagle

Threat Group

Targeting Russian enterprises with backdoors, ransomware, and wipers.

Hacking Cat

Threat Group

Targeting Russian enterprises with backdoors, ransomware, and wipers.

■ ATT&CK TTPs

T1059.003
Command and Scripting Interpreter: Windows Command Shell | Issabel Framework OS command execution (CVE-2026-89026).
T1176
Browser Extensions | KREMLIN toolkit force-installing extensions; researchers demonstrating AI assistant hijacking via extensions.
T1102.002
Web Service: Bidirectional Communication | Iranian hackers using Telegram as a C2 channel for CHOSEN BRICK.
T1068
Exploitation for Privilege Escalation | Google Pixel Modem zero-day (CVE-2026-58704) and Parallels Desktop for Mac privilege escalation.
T1566
Phishing | N0va phishkit targeting US/EU businesses; AI-assisted fake Avast antivirus renewal pages.
T1539
Steal Web Session Information | KREMLIN malware stealing session tokens; hijacking active AI coding-assistant sessions.

■ PATCH PRIORITY

[P1 PATCH NOW]≤24h

Issabel — Issabel Framework CVE-2026-89026 allows unauthenticated OS command execution and is actively exploited — [THN]

[P1 PATCH NOW]≤24h

Google — Pixel Cellular Modem CVE-2026-58704 is a zero-day privilege escalation actively exploited in targeted attacks — [SW]

[P1 PATCH NOW]≤24h

The Events Calendar — WordPress plugin contains unauthenticated RCE vulnerabilities exposing 200,000+ sites — [SW]

[P1 PATCH NOW]≤24h

Parallels — Parallels Desktop for Mac privilege escalation allows non-admin users to gain root access — [THN]

■ RECOMMENDED ACTIONS TODAY

1[P1] Patch Issabel Framework immediately to address CVE-2026-89026 to prevent unauthenticated remote command execution.
2[P1] Apply Google's September security update to Pixel devices to patch the actively exploited Pixel Modem zero-day (CVE-2026-58704).
3[P1] Update "The Events Calendar" WordPress plugin to the latest version to mitigate unauthenticated remote code execution vulnerabilities.
4[P2] Apply the security patch for Parallels Desktop for Mac to prevent local privilege escalation to root (note: Intel Macs may require alternative mitigations as they cannot install the fix).
5[P2] Audit Windows 11 enterprise systems for KB5124008 if experiencing domain trust relationship failures, and consider pausing deployment until Microsoft resolves the issue.
LIVE IOC FEED

C2 IP BLOCKLIST  ·  AbuseCH Feodo  ·  Showing 5 of 5

IP ADDRESS

162.243.103.246

PORT

8080

STATUS

OFFLINE

MALWARE

Emotet

COUNTRY

US

IP ADDRESS

50.16.16.211

PORT

443

STATUS

ONLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

34.204.119.63

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

US

IP ADDRESS

178.62.3.223

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

GB

IP ADDRESS

27.133.154.218

PORT

443

STATUS

OFFLINE

MALWARE

QakBot

COUNTRY

JP

FULL IOC EXPORT — GOOGLE SHEET

All live IOCs with full SHA256 hashes (OTX), IPs, and domains. 2 tabs: C2 IPs · OTX IOCs
Updated daily · Export as CSV to import directly into your tools

■  Open Full IOC Sheet  →

IOC SOURCES: AbuseCH Feodo  ·  AlienVault OTX
NEWS: THN · KRB · SANS · REC · BC · SW · AWS · GCP · MSFT · U42 · SCH · MWB

Don't miss what's next. Subscribe to Daily Security Intel:
← Newer [SecurityIntel] 18 Sep | Active Zero-Day Exploit in Cisco ISE (CVE-2026-76460) Older → [SecurityIntel] 16 Sep | Cisco Secure Email Gateway CVE-2026-76461 Actively Exploited
Powered by Buttondown, the easiest way to start and grow your newsletter.