{
  "schema_version": 2,
  "issue_date": "2026-09-12",
  "generated_at": "2026-09-12T15:19:31.840Z",
  "insight_context": {
    "schema_version": 2,
    "mode": "current",
    "checked_at": "2026-09-12T15:19:30.501Z",
    "report_date": "2026-09-12",
    "manifest_generated_at": "2026-09-12T11:14:02Z",
    "report_url": "https://ricomanifesto.github.io/SentryInsight/"
  },
  "articles": [
    {
      "id": "reporting-59b3d76728f8",
      "title": "Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent",
      "link": "https://www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent/",
      "date": "2026-09-12T14:14:32.000Z",
      "source": "Bleeping Computer",
      "summary": "The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103…",
      "firstSeen": "2026-09-12T15:19:30.915Z"
    },
    {
      "id": "reporting-d66479afd965",
      "title": "When the Whole Company Adopts AI: What It Does to Your SOC",
      "link": "https://thehackernews.com/2026/09/when-whole-company-adopts-ai-what-it.html",
      "date": "2026-09-12T10:24:44.000Z",
      "source": "The Hacker News",
      "summary": "Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from developers running coding agents and non-technical staff signing consumer AI tools into corporate…",
      "firstSeen": "2026-09-12T15:19:30.915Z"
    },
    {
      "id": "reporting-f05890c0a6ff",
      "title": "OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers",
      "link": "https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html",
      "date": "2026-09-12T09:07:56.000Z",
      "source": "The Hacker News",
      "summary": "The \"major malicious attack\" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the…",
      "firstSeen": "2026-09-12T10:24:23.974Z"
    },
    {
      "id": "reporting-ed5e0e272a95",
      "title": "Hackers abused Claude to extract secrets from 1.8M Android apps",
      "link": "https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/",
      "date": "2026-09-11T20:19:09.000Z",
      "source": "Bleeping Computer",
      "summary": "Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes…",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-9846387cf4d2",
      "title": "Threat Actor Generates 1M Personalized Fraud Emails in 3 Days",
      "link": "https://www.darkreading.com/cyberattacks-data-breaches/1m-personalized-fraud-emails-3-days",
      "date": "2026-09-11T19:21:08.000Z",
      "source": "Dark Reading",
      "summary": "Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-a16d62911725",
      "title": "Florida confirms DMV database breached via stolen police account",
      "link": "https://www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/",
      "date": "2026-09-11T19:00:29.000Z",
      "source": "Bleeping Computer",
      "summary": "The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee…",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-c299141b7513",
      "title": "CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate",
      "link": "https://www.darkreading.com/cyber-risk/cisa-calls-for-more-guidance-less-spin-as-cyber-outages-escalate",
      "date": "2026-09-11T18:44:03.000Z",
      "source": "Dark Reading",
      "summary": "A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols.",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-149efb9377d4",
      "title": "Why AI Is So Good at Scamming Humans",
      "link": "https://www.darkreading.com/cyber-risk/ai-scamming-humans",
      "date": "2026-09-11T18:14:06.000Z",
      "source": "Dark Reading",
      "summary": "Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to influence human behavior and create emotional dependency.",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-82dfd2b2ae38",
      "title": "Passkey-themed phishing attacks lead to Microsoft 365 data theft",
      "link": "https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/",
      "date": "2026-09-11T17:26:50.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services…",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-f232a487313b",
      "title": "AI Governance Can't Wait",
      "link": "https://www.darkreading.com/cyber-risk/ai-governance-cannot-wait",
      "date": "2026-09-11T17:10:56.000Z",
      "source": "Dark Reading",
      "summary": "Adversaries can manipulate AI defensive reasoning to silently compromise target networks.",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-a8b89596a45d",
      "title": "GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure",
      "link": "https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html",
      "date": "2026-09-11T16:30:18.000Z",
      "source": "The Hacker News",
      "summary": "GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under…",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-a9e03aba59c7",
      "title": "Artifactory flaws chained in attacks deploying backdoor malware",
      "link": "https://www.bleepingcomputer.com/news/security/artifactory-flaws-chained-in-attacks-deploying-backdoor-malware/",
      "date": "2026-09-11T16:29:44.000Z",
      "source": "Bleeping Computer",
      "summary": "Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers…",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-ec242e7e40e9",
      "title": "Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks",
      "link": "https://thehackernews.com/2026/09/anthropic-says-seven-china-based-ai.html",
      "date": "2026-09-11T16:15:29.000Z",
      "source": "The Hacker News",
      "summary": "Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself is a legitimate training method. It refers to a machine learning technique where a large, powerful AI model assumes the role of a \"teacher\" to…",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-3c8d9734ba4d",
      "title": "Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain",
      "link": "https://www.darkreading.com/cyberattacks-data-breaches/papercut-ai-swarm-attack-cyber-kill-chain",
      "date": "2026-09-11T15:48:27.000Z",
      "source": "Dark Reading",
      "summary": "From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI.",
      "firstSeen": "2026-09-11T16:12:08.815Z"
    },
    {
      "id": "reporting-0f8accb03f10",
      "title": "Claude Used to Automate Exploitation and Data Theft Across Multiple Victims",
      "link": "https://thehackernews.com/2026/09/claude-used-to-automate-exploitation.html",
      "date": "2026-09-11T14:29:47.000Z",
      "source": "The Hacker News",
      "summary": "Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial…",
      "firstSeen": "2026-09-11T16:12:08.815Z"
    },
    {
      "id": "reporting-dae251a2004b",
      "title": "Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection",
      "link": "https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html",
      "date": "2026-09-11T14:10:20.000Z",
      "source": "The Hacker News",
      "summary": "Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 (where \"GTG\" stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight…",
      "firstSeen": "2026-09-11T16:12:08.815Z"
    },
    {
      "id": "reporting-4cfe00191671",
      "title": "How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface",
      "link": "https://www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/",
      "date": "2026-09-11T14:01:11.000Z",
      "source": "Bleeping Computer",
      "summary": "Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures…",
      "firstSeen": "2026-09-11T16:12:08.815Z"
    },
    {
      "id": "reporting-336c262bc83e",
      "title": "Your Critical Vulnerabilities Might Not Be Your Biggest Risk",
      "link": "https://thehackernews.com/2026/09/your-critical-vulnerabilities-might-not.html",
      "date": "2026-09-11T11:30:00.000Z",
      "source": "The Hacker News",
      "summary": "Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that prevent an attacker…",
      "firstSeen": "2026-09-11T16:12:08.815Z"
    },
    {
      "id": "reporting-3b1ca1686e68",
      "title": "GitLab urges users to patch max severity path traversal flaw",
      "link": "https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/",
      "date": "2026-09-11T11:15:22.000Z",
      "source": "Bleeping Computer",
      "summary": "GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706…",
      "firstSeen": "2026-09-11T16:12:08.815Z"
    },
    {
      "id": "reporting-726c616a6c1c",
      "title": "Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-teams-outlook-launch-failures-on-arm-windows-pcs/",
      "date": "2026-09-11T09:39:37.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday…",
      "firstSeen": "2026-09-11T10:56:47.636Z"
    },
    {
      "id": "reporting-42df196f2b73",
      "title": "Trezor: 347,000 users targeted in phishing attacks after Brevo breach",
      "link": "https://www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/",
      "date": "2026-09-11T07:55:15.000Z",
      "source": "Bleeping Computer",
      "summary": "Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link…",
      "firstSeen": "2026-09-11T10:56:47.636Z"
    },
    {
      "id": "reporting-6d77d0f66755",
      "title": "Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors",
      "link": "https://thehackernews.com/2026/09/attackers-chain-jfrog-artifactory-flaws.html",
      "date": "2026-09-11T07:31:05.000Z",
      "source": "The Hacker News",
      "summary": "Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had not been updated were open to them.",
      "firstSeen": "2026-09-11T10:56:47.636Z"
    },
    {
      "id": "reporting-11c8b517d375",
      "title": "China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor",
      "link": "https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html",
      "date": "2026-09-11T07:14:09.000Z",
      "source": "The Hacker News",
      "summary": "A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday. The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns…",
      "firstSeen": "2026-09-11T10:56:47.636Z"
    },
    {
      "id": "reporting-07c0f38a80ce",
      "title": "Conti ransomware gang member sentenced to 4 years in prison",
      "link": "https://www.bleepingcomputer.com/news/security/conti-ransomware-gang-member-sentenced-to-four-years-in-prison/",
      "date": "2026-09-11T06:48:37.000Z",
      "source": "Bleeping Computer",
      "summary": "A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022…",
      "firstSeen": "2026-09-11T10:56:47.636Z"
    },
    {
      "id": "reporting-af3b87dfbf9c",
      "title": "PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws",
      "link": "https://thehackernews.com/2026/09/papercut-replaces-emergency-patches.html",
      "date": "2026-09-11T06:46:18.000Z",
      "source": "The Hacker News",
      "summary": "PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. \"These are Regular Maintenance Releases (MR) that…",
      "firstSeen": "2026-09-11T10:56:47.636Z"
    },
    {
      "id": "reporting-788925358fae",
      "title": "Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware",
      "link": "https://thehackernews.com/2026/09/cisco-fmc-flaws-exploited-to-steal.html",
      "date": "2026-09-11T06:19:59.000Z",
      "source": "The Hacker News",
      "summary": "Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass…",
      "firstSeen": "2026-09-11T10:56:47.636Z"
    },
    {
      "id": "reporting-133227570f5c",
      "title": "Indonesia Hit by Android Banking App-Cloning Campaign",
      "link": "https://www.darkreading.com/mobile-security/indonesia-android-banking-app-cloning-campaign",
      "date": "2026-09-11T01:00:00.000Z",
      "source": "Dark Reading",
      "summary": "The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.",
      "firstSeen": "2026-09-11T03:57:25.671Z"
    },
    {
      "id": "reporting-b8fb164281cc",
      "title": "New Android malware encrypts files, steals data, and harasses victims",
      "link": "https://www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/",
      "date": "2026-09-10T21:40:43.000Z",
      "source": "Bleeping Computer",
      "summary": "A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims…",
      "firstSeen": "2026-09-10T23:01:19.108Z"
    },
    {
      "id": "reporting-432786c4f1ef",
      "title": "Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data",
      "link": "https://www.darkreading.com/threat-intelligence/voice-callers-exploit-byod-microsoft-365-corporate-data",
      "date": "2026-09-10T20:36:03.000Z",
      "source": "Dark Reading",
      "summary": "Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.",
      "firstSeen": "2026-09-10T23:01:19.108Z"
    },
    {
      "id": "reporting-5125040d57bf",
      "title": "September Windows Server updates break Remote Desktop Services",
      "link": "https://www.bleepingcomputer.com/news/microsoft/september-windows-server-updates-break-remote-desktop-services/",
      "date": "2026-09-10T20:34:37.000Z",
      "source": "Bleeping Computer",
      "summary": "Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality…",
      "firstSeen": "2026-09-10T20:40:15.245Z"
    },
    {
      "id": "reporting-1b1eebcbc6b8",
      "title": "Surfshark VPN says hackers breached internal testing, proxy servers",
      "link": "https://www.bleepingcomputer.com/news/security/surfshark-vpn-says-hackers-breached-internal-testing-proxy-servers/",
      "date": "2026-09-10T19:15:07.000Z",
      "source": "Bleeping Computer",
      "summary": "Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet…",
      "firstSeen": "2026-09-10T20:40:15.245Z"
    },
    {
      "id": "reporting-627a6cdeb049",
      "title": "Microsoft Excel KB5002914 update breaks copy and paste for some users",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-excel-kb5002914-update-breaks-copy-and-paste-for-some-users/",
      "date": "2026-09-10T19:07:33.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft Excel users report that this week's KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality…",
      "firstSeen": "2026-09-10T20:40:15.245Z"
    },
    {
      "id": "reporting-69cf1fb2ff89",
      "title": "ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories",
      "link": "https://thehackernews.com/2026/09/threatsday-200-android-flaws-browser.html",
      "date": "2026-09-10T17:47:38.000Z",
      "source": "The Hacker News",
      "summary": "A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already…",
      "firstSeen": "2026-09-10T20:40:15.245Z"
    }
  ]
}
