Cybersecurity Weekly Intelligence Brief — week ending 2026-09-14
7 incidents disclosed · 377 stories reviewed · 17 critical · 5 newly exploited vulnerabilities
Summary
7 incidents were disclosed in the last seven days. The largest is McKesson, with 6,404,340 records affected. CISA added 5 flaws to its list of those used in attacks. On the compliance side, a Federal Communications Commission rule takes effect on 29 September 2026.
Every item below links to its record. Times are UTC.
Top 5 incidents
- 1CENTERPOINT ENERGY INC disclosed a cybersecurity incident
SEC EDGAR · 14 Sept
- 2BOSTON SCIENTIFIC CORP disclosed a material cybersecurity incident
SEC EDGAR · 8 Sept
- 3Veradigm Inc. disclosed a cybersecurity incident
SEC EDGAR · 8 Sept
- 4McKesson: a data breach
6,404,340 recordsHave I Been Pwned · 10 Sept
- 5Chess.com (2026): a data breach
4,653,212 recordsHave I Been Pwned · 13 Sept
Top 5 exploited vulnerabilities
- 1Cisco Asyncos9.8Critical
CVE-2026-76461· added 14 Sept
- 2ConnectWise ScreenConnect9.9Critical
CVE-2026-84869· added 11 Sept
- 3Gitlab10.0Critical
CVE-2026-85706· added 11 Sept
- 4MikroTik RouterOS9.8Critical
CVE-2026-86060· added 10 Sept
- 5Citrix NetScaler9.8Critical
CVE-2026-19490· added 9 Sept
Compliance
Federal Communications Commission · US
Technical details
For each item above: what happened, how an attacker reaches the flaw, the chance of attack, what CISA or the regulator says to do and by when, and the official record.