Weekly intelligence brief

Cybersecurity Weekly Intelligence Brief — week ending 2026-09-21

6 incidents disclosed · 333 stories reviewed · 11 critical · 5 newly exploited vulnerabilities

Summary

6 incidents were disclosed in the last seven days. CISA added 5 flaws to its list of those used in attacks. On the compliance side, a Federal Communications Commission rule takes effect on 29 September 2026.

Every item below links to its record. Times are UTC.

Top 5 incidents

  1. 1
    Opportune LLP: a data breach

    California Attorney General · 18 Sept

  2. 2
    Partnership HealthPlan of California: a data breach

    California Attorney General · 17 Sept

  3. 3
    CallonDoc, Inc.: a data breach

    California Attorney General · 17 Sept

  4. 4
  5. 5
    Tarter Krinsky & Drogin LLP: a data breach

    California Attorney General · 15 Sept

Top 5 exploited vulnerabilities

  1. 1
    Cisco Identity Services Engine

    CVE-2026-76460· added 16 Sept

    10.0Critical
  2. 2
    Linux Kernel

    CVE-2026-53266· added 18 Sept

    8.8High
  3. 3
    Google Pixel

    CVE-2026-58704· added 16 Sept

    8.8High
  4. 4
    Linux Kernel

    CVE-2025-39964· added 18 Sept

    7.8High
  5. 5
    Acronis Backup

    CVE-2026-87886· added 16 Sept

    7.8High

Compliance

Technical details

For each item above: what happened, how an attacker reaches the flaw, the chance of attack, what CISA or the regulator says to do and by when, and the official record.

The analysis below is for subscribers. Add your email to read it now — the rest of this briefing stays open to everyone.

We send the briefing and nothing else. Unsubscribe in one click.