Cybersecurity Weekly Intelligence Brief — week ending 2026-09-21
6 incidents disclosed · 333 stories reviewed · 11 critical · 5 newly exploited vulnerabilities
Summary
6 incidents were disclosed in the last seven days. CISA added 5 flaws to its list of those used in attacks. On the compliance side, a Federal Communications Commission rule takes effect on 29 September 2026.
Every item below links to its record. Times are UTC.
Top 5 incidents
- 1Opportune LLP: a data breach
California Attorney General · 18 Sept
- 2Partnership HealthPlan of California: a data breach
California Attorney General · 17 Sept
- 3CallonDoc, Inc.: a data breach
California Attorney General · 17 Sept
- 4Leggett & Platt, Incorporated Employee Benefits Plan: a data breach
California Attorney General · 15 Sept
- 5Tarter Krinsky & Drogin LLP: a data breach
California Attorney General · 15 Sept
Top 5 exploited vulnerabilities
- 1Cisco Identity Services Engine10.0Critical
CVE-2026-76460· added 16 Sept
- 2Linux Kernel8.8High
CVE-2026-53266· added 18 Sept
- 3Google Pixel8.8High
CVE-2026-58704· added 16 Sept
- 4Linux Kernel7.8High
CVE-2025-39964· added 18 Sept
- 5Acronis Backup7.8High
CVE-2026-87886· added 16 Sept
Compliance
Federal Communications Commission · US
Technical details
For each item above: what happened, how an attacker reaches the flaw, the chance of attack, what CISA or the regulator says to do and by when, and the official record.