Weekly intelligence brief

Cybersecurity Weekly Intelligence Brief — week ending 2026-09-14

7 incidents disclosed · 377 stories reviewed · 17 critical · 5 newly exploited vulnerabilities

Summary

7 incidents were disclosed in the last seven days. The largest is McKesson, with 6,404,340 records affected. CISA added 5 flaws to its list of those used in attacks. On the compliance side, a Federal Communications Commission rule takes effect on 29 September 2026.

Every item below links to its record. Times are UTC.

Top 5 incidents

  1. 1
  2. 2
  3. 3
  4. 4
    McKesson: a data breach

    6,404,340 recordsHave I Been Pwned · 10 Sept

  5. 5
    Chess.com (2026): a data breach

    4,653,212 recordsHave I Been Pwned · 13 Sept

Top 5 exploited vulnerabilities

  1. 1
    Cisco Asyncos

    CVE-2026-76461· added 14 Sept

    9.8Critical
  2. 2
    ConnectWise ScreenConnect

    CVE-2026-84869· added 11 Sept

    9.9Critical
  3. 3
    Gitlab

    CVE-2026-85706· added 11 Sept

    10.0Critical
  4. 4
    MikroTik RouterOS

    CVE-2026-86060· added 10 Sept

    9.8Critical
  5. 5
    Citrix NetScaler

    CVE-2026-19490· added 9 Sept

    9.8Critical

Compliance

Technical details

For each item above: what happened, how an attacker reaches the flaw, the chance of attack, what CISA or the regulator says to do and by when, and the official record.

The analysis below is for subscribers. Add your email to read it now — the rest of this briefing stays open to everyone.

We send the briefing and nothing else. Unsubscribe in one click.