336 US Highway 46, Fairfield, NJ 07004  ·  (888) 711-4521 intelamation.com
Cyber Shield Weekly
Cybersecurity Intelligence  ·  Powered by AI
■  September 14, 2026 Weekly Cyber Situational Awareness
◢ This Week's Threat Picture  ·  September 14, 2026
CRITICAL
6 of 36 tracked stories involve active exploitation
5Global
5National
5Regional
🇺🇸
5
National Alerts
📍
5
Regional Alerts
🎙 Now Available as a Podcast
Subscribe on Spotify, Apple Podcasts & more — new episode every Monday.
▶ Spotify 🍎 Apple More
Find this useful?   Forward to a colleague →  |  Subscribe free →
🎧  Audio Edition Available
Prefer to listen? An AI-generated audio overview of this edition is available — ideal for your commute or workday background.
▶  Listen Now
🎙  Subscribe to Podcast
👁  From our other show · All Eyes
One question the industry is arguing about, two people who genuinely disagree, and nobody gets let off easy. A new debate every Tuesday.
Every voice on All Eyes is AI-generated, and we say so in every episode.
▶  Listen
🎙  Subscribe
INTEL

Cyber Threat Intelligence

Cybersecurity threats are intensifying across both technical and human vectors, with attackers now leveraging sophisticated passkey phishing techniques to compromise enterprise cloud accounts, exploiting actively targeted vulnerabilities in widely-used platforms like Artifactory, ScreenConnect, and RouterOS, and deploying malicious browser extensions to harvest credentials at scale. Simultaneously, the rapid enterprise-wide adoption of AI is fundamentally reshaping the threat exposure landscape and straining Security Operations Center capabilities, demanding that organizations evolve their validation strategies and governance frameworks to keep pace with an attack surface that is growing faster than traditional defenses can address.

The Hacker News
AI Changed the Exposure Problem. Validation Needs to Change With It.

There's a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have to work out which findings actually deserve their action. In the first half of 2026, a whopping 35,853 CVEs w...

Read Full Article →
The Hacker News
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named "Twitch Enhanced Viewer | JeetBot," lists HISHIMIRO/jeetbot.cc as its developer and has the following identifiers on the Google Chrome Web Store and Mozilla ...

Read Full Article →
The Hacker News
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 202...

Read Full Article →
The Hacker News
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Details of the vulnerabilities are as follows - CVE-2026-42016 (CVSS ...

Read Full Article →
The Hacker News
When the Whole Company Adopts AI: What It Does to Your SOC

Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from developers running coding agents and non-technical st...

Read Full Article →
INNOVATION

Cybersecurity Advancements

The latest in defensive technologies, AI-driven threat detection, security research, and industry developments shaping the future of cybersecurity.

Security Week
New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate

Concerns over the potential risks of the technology are rising as new AI models become more powerful, heightening both the potential for misuse by people with criminal aims. The post New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate appeared first on SecurityWeek .

Read Full Article →
Security Week
Personal, Financial Info Exposed in Revolut Data Breach

The company unintentionally disclosed users’ information to a third party impersonating a government agency. The post Personal, Financial Info Exposed in Revolut Data Breach appeared first on SecurityWeek .

Read Full Article →
Security Week
The Race to Control AI and Protect What Makes Us Human

As researchers warn that misaligned AI could threaten human survival, even beneficial systems may erode the critical thinking that defines our humanity. The post The Race to Control AI and Protect What Makes Us Human appeared first on SecurityWeek .

Read Full Article →
SMB SPOTLIGHT

Small Business Spotlight

Small businesses are navigating an increasingly complex threat landscape, from the hidden dangers of unsanctioned AI tools creeping into daily workflows to vulnerabilities in internet-exposed systems and edge devices that can leave operations wide open to attack. As agentic AI adds another layer of risk to manage, SMBs are finding that staying ahead of cyber threats requires more vigilance — and smarter strategies — than ever before.

NCSC UK
The hidden risks of shadow AI

Understanding why staff use unapproved AI tools is key to managing the security challenges they can create.

Read Full Article →
NCSC UK
Disruptive cyber activity highlights risk from internet-exposed systems and edge devices

Owners of operational technology encouraged to address avoidable vulnerabilities, and build long-term cyber resilience.

Read Full Article →
NCSC UK
Managing the cyber risk of agentic AI

Use safeguards, sandboxing and active oversight to realise the benefits of autonomous systems while limiting the unintended activity.

Read Full Article →
💡
From the CTO's Desk
Daniel Ramos  — CTO — Intelligent Automation  LinkedIn

Happy Monday, cyber-warriors. Grab your coffee, because this week's threat landscape reads like a Netflix drama where every character is making terrible decisions — and somehow, we're the ones who have to fix it.

First up: attackers are now phishing passkeys to hijack Microsoft cloud accounts. Yes, the thing we sold everyone as "unhackable" has a phishing bypass. It's giving "the call is coming from inside the house" energy. Takeaway: enforce Conditional Access policies with device compliance checks — passkeys alone aren't a magic shield.

Speaking of "we thought this was safe," a malicious Twitch browser extension quietly leaked OAuth tokens from nearly 31,000 users. Browser extensions are essentially interns with admin access — audit yours today and remove anything you didn't personally vet.

Meanwhile, CISA added five actively exploited flaws in Artifactory, ScreenConnect, and RouterOS to the Known Exploited Vulnerabilities catalog. If you're running any of these, patch them faster than you skip a Spotify ad.

On the AI front — and there's always an AI front now — enterprise-wide AI adoption is quietly overwhelming SOC teams with alert noise while simultaneously expanding your attack surface. The fix isn't fewer AI tools; it's smarter validation workflows and exposure management that actually keeps pace with how fast AI moves.

Stay patched, stay paranoid, and for the love of all things holy, audit your browser extensions.

— Daniel Ramos, CTO — Intelligent Automation

THREATS

Threat Landscape Overview

Top active threats across global, national, and Fairfield, New Jersey levels. Click any item to read the full advisory or source article.

Intelligent Automation, LLC

Your Managed Cybersecurity Services Provider
(888) 711-4521
+ Subscribe Unsubscribe

This newsletter is compiled weekly by the Intelligent Automation cybersecurity team using live feeds from CISA, The Hacker News, Krebs on Security, Bleeping Computer, Security Week, and other authoritative sources. All article links direct to original publishers.

© 2026 Intelligent Automation, LLC  ·  336 US Highway 46, Fairfield, NJ 07004  ·  https://intelamation.com
Newsletter generated automatically every Tuesday at 12:00 PM Eastern.