| Date | Source | Type | Title | Author |
|---|---|---|---|---|
| Sep 24, 2026 | ASD/ACSC | Alert | HIGH ALERT: Risks of AI misalignment to Australian organisations This alert is relevant to all Australian organisations with public-facing websites or applications. The Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC) is aware of instances of artificial intelligence (AI) misalignment, in which AI agents have undertaken unexpected actions that were not intended or authorised by its operators. | ASD/ACSC |
| Sep 23, 2026 | CISA | Advisory | Considerations for Critical Infrastructure Operators Working With Third-Party ICS Integrators The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)—hereafter referred to as the “authoring agencies”—have published this fact sheet to highlight considerations for critical infrastructure entities to reduce risk and minimize vulnerabilities when working with third-party industrial control system (ICS) integrators. | CISA, FBI |
| Sep 22, 2026 | CERT-EU | Advisory | 2026-013: Critical Vulnerability in F5 BIG-IP APM CERT-EU recommends taking appropriate actions as soon as possible. The vulnerability CVE-2026-94127, with a CVSS score of 9.8, is a heap-based buffer overflow vulnerability and allow unauthenticated attacker to achieve remote code execution (RCE) The vulnerability affects the following versions of BIG-IP APM if configured with an access policy and an OAuth profile on a virtual server [1]: CERT-EU recommends taking the following actions as soon as… | CERT-EU |
| Sep 21, 2026 | NCSC | Guidance | One does not simply defend agentically Defenders can’t use AI in the same way attackers can, but there’s much they can do to unlock the potential of agentic One of my favourite cyber security maxims is Halvar Flake’s observation that “All offensive problems are technical problems, and all defensive problems are political problems”. For an attacker conducting offensive cyber actions, the problems that need to be solved are largely technical. | NCSC-UK |
| Sep 18, 2026 | ASD/ACSC | Advisory | North Korean "WaterPlum," commonly referred to as “Contagious Interview,” cyber actor group targeting IT professionals The National Police Agency of Japan (NPA), the National Cybersecurity Office of Japan (NCO), the US Federal Bureau of Investigation (FBI) and the US Department of Defense Cyber Crime Center (DC3), Australian Signals Directorate's Australian Cyber Security Centre (ASD's ACSC), Germany Federal Intelligence Service (BND) and Germany Federal Office for the Protection of the Constitution (BfV) have determined the following: The North Korean "WaterPlum… | ASD/ACSC |
| Sep 17, 2026 | ASD/ACSC | Guidance | Network segmentation and segregation – Anti-patterns New dependencies, inherited access, vendor connectivity, network address reuse and shared management platforms can gradually introduce communication paths that were not part of the original design. Over time, organisations may settle into recurring arrangements that appear workable but no longer provide the intended logical separation between systems and business functions. | ASD/ACSC |
| Sep 17, 2026 | NCSC | Guidance | Adversary simulation: what you need to know Adversary simulation ('red teaming') tests your ability to prevent, detect and respond to cyber attacks. This guidance is for organisations wanting to understand if adversary simulation (sometimes known as ‘red teaming’) is right for them. It is designed for system owners and security professionals within medium to large-sized organisations. | NCSC-UK |
| Sep 17, 2026 | NCSC | Guidance | Cyber Adversary Simulation (CyAS): scheme documents now available Cyber adversary simulation is one of the most effective ways for organisations to understand how they would fare against a capable cyber attacker. Yet, the quality of services available across the market can vary significantly. | NCSC-UK |
| Sep 16, 2026 | CISA | Advisory | Using Cyber Decoys to Strengthen Detection and Response This guidance explains how organizations can strengthen their cyber defenses by deploying realistic decoy systems and information assets to quickly detect and disrupt malicious activity inside their networks. It uses the MITRE Engage™ and MITRE ATT&CK® frameworks to provide practical, low-complexity steps for planning, implementing, and refining decoy operations that reduce time to detection and improve use of defensive resources. | CISA |
| Sep 15, 2026 | CISA | Advisory | Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with guidelines to protect the identity assertions, access tokens, and cryptographic mechanisms that support modern authentication and authorization. | CISA |
| Sep 15, 2026 | NCSC | Guidance | UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists state actors to target dissidents, activists and GCHQ’s National Cyber Security Centre and international partners issue warning over Iranian cyber actors’ spearphishing and spyware campaign ‘CHOSEN BRICK’ malware family used to collect information, including screen captures and messaging history, from UK and allies provide advice to help organisations and individuals at risk detect malicious activity and reduce chances of their devices falling vi… | AIVD, FBI, NCSC-UK |
| Sep 15, 2026 | NCSC | Guidance | Iranian cyber targeting of dissidents, activists and journalists Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect CHOSEN BRICK is a malware family that has been used to target individuals around the world including in the UK, US and the Netherlands from at least 2025. | AIVD, FBI, NCSC-UK |
| Sep 14, 2026 | ASD/ACSC | Guidance | Updated guidance on detecting and mitigating Active Directory compromises Microsoft Active Directory is a core identity and access management system that controls access to critical systems and data, making it a prime target for malicious cyber threats. It acts as an organisation's digital gatekeeper, verifying users, managing permissions, and enabling single sign-on. Because Active Directory controls access to so many systems, it is a highly attractive target for malicious actors. | ASD/ACSC |
| Sep 10, 2026 | CERT-EU | Advisory | 2026-012: Critical Vulnerabilities in Check Point Products Both vulnerabilities carry a CVSS score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary code on affected appliances [1,2]. CERT-EU strongly recommends applying the available hotfixes as soon as possible, prioritising internet-facing and perimeter appliances. | CERT-EU |
| Sep 10, 2026 | ASD/ACSC | Guidance | Agentic AI harnesses This publication explains the concept of the Agentic AI harness (referred to hereafter as the harness), the software layer that enables a large language model (LLM) to interact with data, tools and systems to perform agentic tasks. It examines how harness design influences the security, governance, reliability and operational risks of agentic AI systems. | ASD/ACSC |
| Sep 10, 2026 | ASD/ACSC | Guidance | ASD releases new guidance on the agentic AI harnesses We have released a new publication, Agentic AI Harnesses, to help organisations better understand the security, governance and operational considerations associated with agentic AI systems. As organisations increasingly explore agentic AI, attention is often focused on large language models (LLMs). | ASD/ACSC |
| Sep 9, 2026 | JPCERT/CC | Alert | Alert Regarding Vulnerabilities in Adobe Acrobat and Reader (APSB26-141) Vulnerabilities exist in Adobe Acrobat, PDF file creation and conversion software, and Adobe Acrobat Reader, PDF file viewing software. As a result, an attacker may execute arbitrary code by convincing a user to open contents leveraging the vulnerability. | JPCERT/CC |
| Sep 9, 2026 | JPCERT/CC | Alert | Microsoft Releases September 2026 Security Updates Microsoft has released September 2026 Security Updates to address the vulnerabilities in their products. Attackers leveraging these vulnerabilities may be able to execute arbitrary code remotely without authentication or elevate privileges locally after authentication, etc. According to Microsoft, among the vulnerabilities, the following vulnerability has been confirmed to be exploited in the wild. | JPCERT/CC |
| Sep 9, 2026 | ASD/ACSC | Alert | CRITICAL ALERT: Active exploitation of Adobe Commerce and Magento Open Source vulnerability ASD’s ACSC is aware of a substantial number of potentially vulnerable instances within the Australian economy and encourage system owners to follow the mitigation advice from the vendor. This alert is relevant to all Australian organisations that utilise Adobe Commerce and Magento Open Source. | ASD/ACSC |
| Sep 9, 2026 | CERT-EU | Advisory | 2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server Critical Vulnerabilities in SAP Kernel On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products [1][3]. The most severe, CVE-2026-44756 (CVSS 10. | CERT-EU |
| Sep 8, 2026 | ASD/ACSC | Advisory | Digital camouflage: crypters make malware undetectable Cybercriminals are increasingly using crypters to disguise malware and make it harder for antivirus software to detect. | ASD/ACSC |
| Sep 8, 2026 | CISA | Advisory | China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. | CISA, FBI, NSA |
| Sep 7, 2026 | NCSC | Guidance | The hidden risks of shadow AI Understanding why staff use unapproved AI tools is key to managing the security challenges they can create. Over the past few years, the use of artificial intelligence (AI) has grown rapidly in many workplaces with employees increasingly exploring how such tools can be incorporated into their jobs. AI can help people complete tasks more quickly, improve decision-making, save costs and increase productivity. | NCSC-UK |
| Sep 4, 2026 | ASD/ACSC | Alert | CRITICAL ALERT: Critical vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and Citrix NetScaler Gateway products Alert on critical vulnerabilities affecting Citrix NetScaler ADC and Gateway products. Assess exposure and update all affected products. | ASD/ACSC |
| Sep 3, 2026 | NSA | Guidance | CSI: Best Practices for Cyber Hygiene Mission-focused strategies for securing networks against advanced threats Effective cyber hygiene remains essential for defending networks against advanced persistent threats (APTs), including those leveraging artificial intelligence (AI) for computer network exploitation (CNE). | NSA |
| Sep 3, 2026 | CISA | Advisory | Preparing for the Post-Quantum Era: A Call to Action The G7 Cyber Security Working Group’s call to action outlines five priorities for a successful transition to PQC: Raising awareness of quantum risks and the importance of PQC; Developing national strategies that support PQC adoption and integration; Advancing research and development for quantum-safe technologies; Fostering public-private partnerships to share expertise and resources; and Integrating PQC into cybersecurity requirements and procur… | CISA |
| Sep 2, 2026 | CISA | Advisory | Communicating Under Pressure: Best Practices for Service Providers Service outages impacting IT and operational technology (OT) systems can be damaging and disruptive for customers, network defenders, critical infrastructure owners and operators, and the general public. During incidents that reach or exceed established thresholds, whether caused by malicious activity or a nonmalicious event, service providers must communicate effectively so end users can minimize operational impact. | ASD/ACSC, CCCS, CISA, FBI, NCSC-NZ, NCSC-UK |
| Sep 1, 2026 | ASD/ACSC | Guidance | Multi-factor Authentication: Switch it on This September, it is time to switch on multi-factor authentication (MFA) to help reduce the chances of cyber compromise. | ASD/ACSC |