Cybersecurity Weekly Intelligence Brief — week ending 2026-09-28
9 incidents disclosed · 355 stories reviewed · 24 critical · 5 newly exploited vulnerabilities
Summary
9 incidents were disclosed in the last seven days. The largest is LimeLeads, with 17,838,396 records affected. CISA added 5 flaws to its list of those used in attacks. On the compliance side, a Federal Communications Commission rule takes effect on 29 September 2026.
Every item below links to its record. Times are UTC.
Top 5 incidents
- 1Astrana Health, Inc. disclosed a material cybersecurity incident
SEC EDGAR · 23 Sept
- 2LimeLeads: a data breach
17,838,396 recordsHave I Been Pwned · 22 Sept
- 3HILT-Trust 2020-A and its underlying trusts and affiliates ("HILT"): a data breach
California Attorney General · 24 Sept
- 4NSE Insurance Agencies: a data breach
California Attorney General · 24 Sept
- 5Blanchard Training & Development, Inc.: a data breach
California Attorney General · 24 Sept
Top 5 exploited vulnerabilities
- 1WSO2 Multiple Products10.0Critical
CVE-2026-5430· added 24 Sept
- 2F5 BIG-IP APM9.8Critical
CVE-2026-94127· added 22 Sept
- 3Arista VeloCloud Orchestrator10.0Critical
CVE-2026-93952· added 22 Sept
- 4Check Point Multiple Products9.8Critical
CVE-2026-85102· added 22 Sept
- 5Check Point Multiple Products9.8Critical
CVE-2026-93616· added 22 Sept
Compliance
Federal Communications Commission · US
Technical details
For each item above: what happened, how an attacker reaches the flaw, the chance of attack, what CISA or the regulator says to do and by when, and the official record.
Fastnexa security experts
Which of these actually affect your company?
Send us what you run and a Fastnexa security expert will tell you which items in this briefing matter for you, and what to fix first.
Think you’ve already been hit? Don’t wait on a form: call or WhatsApp +1 (732) 454 2616. We reply within 1 hour, 24/7. Emergency help →