Weekly intelligence brief

Cybersecurity Weekly Intelligence Brief — week ending 2026-09-07

9 incidents disclosed · 193 stories reviewed · 10 critical · 5 newly exploited vulnerabilities

Summary

9 incidents were disclosed in the last seven days. The largest is Manchester Airports Group, with 8,849,657 records affected. CISA added 5 flaws to its list of those used in attacks. On the compliance side, a Federal Communications Commission rule takes effect on 29 September 2026.

Every item below links to its record. Times are UTC.

Top 5 incidents

  1. 1
  2. 2
  3. 3
    Manchester Airports Group: a data breach

    8,849,657 recordsHave I Been Pwned · 2 Sept

  4. 4
    Questel: a data breach

    1,226,209 recordsHave I Been Pwned · 1 Sept

  5. 5
    Beaver County Behavioral Health: a health data breach

    501 recordsHHS Office for Civil Rights · 4 Sept

Top 5 exploited vulnerabilities

  1. 1
    Sangoma Switchvox

    CVE-2026-9586· added 2 Sept

    9.8Critical
  2. 2
    SonicWall SMA1000 Appliances

    CVE-2026-83548· added 2 Sept

    10.0Critical
  3. 3
    JFrog Artifactory

    CVE-2026-82329· added 2 Sept

    9.8Critical
  4. 4
    Kestra OSS

    CVE-2026-49869· added 2 Sept

    10.0Critical
  5. 5
    Google Chromium V8

    CVE-2026-85046· added 4 Sept

    8.8High

Compliance

Technical details

For each item above: what happened, how an attacker reaches the flaw, the chance of attack, what CISA or the regulator says to do and by when, and the official record.

The analysis below is for subscribers. Add your email to read it now — the rest of this briefing stays open to everyone.

We send the briefing and nothing else. Unsubscribe in one click.