Cybersecurity Weekly Intelligence Brief — week ending 2026-09-07
9 incidents disclosed · 193 stories reviewed · 10 critical · 5 newly exploited vulnerabilities
Summary
9 incidents were disclosed in the last seven days. The largest is Manchester Airports Group, with 8,849,657 records affected. CISA added 5 flaws to its list of those used in attacks. On the compliance side, a Federal Communications Commission rule takes effect on 29 September 2026.
Every item below links to its record. Times are UTC.
Top 5 incidents
- 1Park Dental Partners, Inc. disclosed a material cybersecurity incident
SEC EDGAR · 1 Sept
- 2NovoCure Ltd disclosed a cybersecurity incident
SEC EDGAR · 1 Sept
- 3Manchester Airports Group: a data breach
8,849,657 recordsHave I Been Pwned · 2 Sept
- 4Questel: a data breach
1,226,209 recordsHave I Been Pwned · 1 Sept
- 5Beaver County Behavioral Health: a health data breach
501 recordsHHS Office for Civil Rights · 4 Sept
Top 5 exploited vulnerabilities
- 1Sangoma Switchvox9.8Critical
CVE-2026-9586· added 2 Sept
- 2SonicWall SMA1000 Appliances10.0Critical
CVE-2026-83548· added 2 Sept
- 3JFrog Artifactory9.8Critical
CVE-2026-82329· added 2 Sept
- 4Kestra OSS10.0Critical
CVE-2026-49869· added 2 Sept
- 5Google Chromium V88.8High
CVE-2026-85046· added 4 Sept
Compliance
Federal Communications Commission · US
Technical details
For each item above: what happened, how an attacker reaches the flaw, the chance of attack, what CISA or the regulator says to do and by when, and the official record.