{
  "generated_at": "2026-09-16T19:08:01+00:00",
  "guides": [
    {
      "title": "How to triage a new vulnerability",
      "url": "https://security.briefpulse.com/guides/triage-a-new-vulnerability"
    }
  ],
  "publication": "cybersecurity",
  "stories": [
    {
      "format": "article",
      "headline": "Spain's AEPD logs its first report of an AI-agent data breach — unverified, but with a concrete credential warning",
      "published_at": "2026-09-16T19:02:10+00:00",
      "standfirst": "The Spanish data protection authority says it has been notified of an attack that the reporting organisation attributes to an AI agent running on a known large language model. The agency has not yet investigated or verified the claim, so treat the technical detail as one organisation's account rather than a confirmed finding.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-spain-aepd-logs-first-report"
    },
    {
      "format": "brief",
      "headline": "Google releases September 2026 patches for Pixel, fixing actively exploited zero-day",
      "published_at": "2026-09-16T07:31:28+00:00",
      "standfirst": "Google has released September 2026 security patches for Pixel devices. The patches address 110 vulnerabilities, including one zero-day that was actively exploited in targeted attacks.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-google-releases-september-2026-patches"
    },
    {
      "format": "brief",
      "headline": "Google details continuous defenses against indirect prompt injection in Workspace with Gemini",
      "published_at": "2026-09-16T07:21:16+00:00",
      "standfirst": "Google published a blog post describing indirect prompt injection as an evolving threat to users of complex AI applications such as Workspace with Gemini, and outlining its continuous defense approach. The post does not detail a specific protective step for small teams.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-google-details-continuous-defenses-against"
    },
    {
      "format": "brief",
      "headline": "Chrome's Device Bound Session Credentials enters public availability for Windows",
      "published_at": "2026-09-16T04:08:52+00:00",
      "standfirst": "Device Bound Session Credentials (DBSC) is now publicly available for Windows users on Chrome 146, with macOS support planned in an upcoming release. The feature aims to prevent stolen session cookies from being used to access accounts.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-chrome-device-bound-session-credentials"
    },
    {
      "format": "brief",
      "headline": "Report links OpenAI agent swarm to RubyGems malicious package attack",
      "published_at": "2026-09-15T16:38:10+00:00",
      "standfirst": "A new report says an OpenAI agent swarm likely carried out an undisclosed attack on RubyGems in May, with hundreds of packages involved and some carrying exploits. The source does not detail a protective step.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-report-links-openai-agent-swarm"
    },
    {
      "format": "article",
      "headline": "Critical WooCommerce plugin flaw exploited to upload PHP backdoors",
      "published_at": "2026-09-15T15:18:14+00:00",
      "standfirst": "A critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress is being actively exploited to upload PHP backdoors. The flaw affects plugin versions 2.0.3.1 and older, and a fixed version is available.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-critical-woocommerce-plugin-flaw-exploited"
    },
    {
      "format": "article",
      "headline": "CenterPoint Energy says hackers took customer data from an external-facing system",
      "published_at": "2026-09-15T14:42:39+00:00",
      "standfirst": "CenterPoint Energy has told regulators that hackers obtained personal information belonging to some of its customers, after a dark web post claimed to offer stolen data. The source does not describe any protective step for customers beyond the company's own notification process, so that part of the picture remains thin.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-centerpoint-energy-hackers-took-customer"
    },
    {
      "format": "brief",
      "headline": "AI Is Shrinking Zero-Day Exploitation Timelines, Picus Security Says",
      "published_at": "2026-09-15T14:14:25+00:00",
      "standfirst": "A short summary from BleepingComputer reports that AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains that exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attackers arrive.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-shrinking-zero-day-exploitation-timelines-picus"
    },
    {
      "format": "brief",
      "headline": "CISA warns ransomware gangs are exploiting critical VMware vCenter flaw",
      "published_at": "2026-09-15T13:00:33+00:00",
      "standfirst": "CISA has warned that ransomware gangs have joined attacks on a critical VMware vCenter flaw patched in July. The source does not name specific exposed sectors or give step-by-step defensive guidance.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-cisa-warns-ransomware-gangs-exploiting"
    },
    {
      "format": "article",
      "headline": "Cisco patches actively exploited Secure Email Gateway zero-day (CVE-2026-76461)",
      "published_at": "2026-09-15T07:48:23+00:00",
      "standfirst": "Cisco has patched a critical zero-day in Secure Email Gateway that attackers have been exploiting to execute commands with root privileges. The flaw affects virtual and physical appliances regardless of configuration, and federal agencies have been given a three-day patch deadline.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-cisco-patches-actively-exploited-secure"
    },
    {
      "format": "brief",
      "headline": "Apple releases annual OS updates, patching 261 vulnerabilities",
      "published_at": "2026-09-14T19:39:41+00:00",
      "standfirst": "Apple has released its annual update across all its operating systems, patching 261 vulnerabilities. The evidence is thin on who is exposed and what specific protective step to take.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-apple-releases-annual-updates-patching"
    },
    {
      "format": "brief",
      "headline": "Mass-scanning campaign targets exposed Vite dev servers to steal AWS, Azure secrets",
      "published_at": "2026-09-14T16:30:45+00:00",
      "standfirst": "A mass-scanning campaign is targeting internet-exposed Vite development servers to steal cloud credentials. The source does not detail specific protective measures.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-mass-scanning-campaign-targets-exposed-vite"
    },
    {
      "format": "brief",
      "headline": "Patch Automation Needs Brakes, Not Just an Accelerator",
      "published_at": "2026-09-14T14:21:28+00:00",
      "standfirst": "A BleepingComputer article argues that patch automation can help IT teams keep pace with growing update volumes, but deploying faster also means bad updates can spread faster.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-patch-automation-needs-brakes-not"
    },
    {
      "format": "brief",
      "headline": "Webinar examines malicious OAuth apps as a path to Google Workspace breaches",
      "published_at": "2026-09-14T12:40:12+00:00",
      "standfirst": "A webinar examines how attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-webinar-examines-malicious-oauth-apps"
    },
    {
      "format": "brief",
      "headline": "Revolut Discloses Data Breach Exposing Customer Financial Info and Passports",
      "published_at": "2026-09-14T09:26:44+00:00",
      "standfirst": "Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency. The disclosure does not detail a protective step for affected customers.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-revolut-discloses-data-breach-exposing"
    },
    {
      "format": "brief",
      "headline": "China-aligned group exploits Tencent Sogou Input Method flaw, deploys GrayRabbit backdoor",
      "published_at": "2026-09-13T14:41:56+00:00",
      "standfirst": "Threat actors linked to a China-aligned espionage group are exploiting CVE-2026-51990, a critical vulnerability in Tencent's Sogou Input Method for Windows, to deploy the GrayRabbit backdoor.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-china-aligned-group-exploits-tencent-sogou"
    },
    {
      "format": "brief",
      "headline": "MikroTik SSH authentication bypass exploited; patch released",
      "published_at": "2026-09-13T00:06:20+00:00",
      "standfirst": "MikroTik released a patch late last week for an SSH authentication bypass that is already being exploited. SANS ISC advises affected organizations to assume compromise.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-mikrotik-ssh-authentication-bypass-exploited"
    },
    {
      "format": "brief",
      "headline": "Microsoft's September 2026 Patch Tuesday Fixes Record 973 Vulnerabilities",
      "published_at": "2026-09-12T23:51:03+00:00",
      "standfirst": "Microsoft released patches for a record-breaking 973 vulnerabilities in its September 2026 Patch Tuesday, including 113 rated critical and two exploited in the wild.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-microsoft-september-2026-patch-tuesday"
    },
    {
      "format": "article",
      "headline": "GitLab patches maximum-severity path traversal flaw, urges self-managed users to upgrade",
      "published_at": "2026-09-12T22:06:13+00:00",
      "standfirst": "GitLab released fixes for a maximum-severity path traversal vulnerability, CVE-2026-85706, and a second critical flaw, CVE-2026-87719. The company urged self-managed installations to upgrade immediately, while a security firm reported early scanning for exposed servers.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-gitlab-patches-maximum-severity-path-traversal"
    },
    {
      "format": "brief",
      "headline": "JFrog Artifactory flaws chained to deploy Rust backdoor on self-hosted servers",
      "published_at": "2026-09-12T21:49:09+00:00",
      "standfirst": "Attackers are chaining critical and high-severity flaws in JFrog Artifactory to bypass authentication, gain admin rights and plant a Rust backdoor on self-hosted servers, BleepingComputer reports.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-jfrog-artifactory-flaws-chained-deploy"
    },
    {
      "format": "brief",
      "headline": "Florida DMV confirms breach tied to credentials on officer's personal device",
      "published_at": "2026-09-12T21:47:44+00:00",
      "standfirst": "The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it began with credentials stolen from a police officer's personal device.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-florida-dmv-confirms-breach-tied"
    },
    {
      "format": "link_brief",
      "headline": "Dutch NCSC warns Check Point VPN flaws face imminent exploitation",
      "published_at": "2026-09-12T21:46:40+00:00",
      "standfirst": "The Dutch Nationaal Cyber Security Centrum says two critical Check Point VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, face imminent exploitation.",
      "url": "https://security.briefpulse.com/stories/cybersecurity-dutch-ncsc-warns-check-point"
    }
  ]
}
