The Daily Zero-Day

Buy me a coffee    @ Cafeteria One      | or |      @ Cafeteria Two
Date: SEPTEMBER 23, 2026 Editor-in-Chief: Jose Laurentino III Global Threat Intelligence Edition

Executive Summary

Today's edition of The Daily Zero-Day (September 23, 2026) highlights a rapidly evolving threat landscape where autonomous AI malware frameworks, cloud supply chain attacks, and sophisticated social engineering converge. With Microsoft issuing a massive patch cycle covering nearly 1,000 vulnerabilities, and critical supply chain surfaces like HashiCorp and GitLab facing active abuse, organizations face unprecedented pressure. Autonomous C2 implants, AI chatbot poisoning campaigns, and sprawling infostealer trends underscore the urgent need for robust telemetry, strict access management, and proactive posture management across enterprise infrastructure.

Top Intelligence Briefings

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors have leveraged this specific cloud deployment vector at scale to target infrastructure pipelines.

Actionable Takeaway: Audit third-party Terraform providers and Go modules in your deployment pipelines; restrict downloads to pinned, verified internal registries.

The Closed Quorum: Inside the first reported autonomous AI C2 implant

CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a critical paradigm shift in how AI-integrated malware operates independently in compromised environments.

Actionable Takeaway: Implement advanced behavioral anomaly detection to catch self-governing routines and unexpected internal C2 traffic loops.

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

The private email address GitLab provides for filing issues by email acts as a functional credential. Anyone who intercepts or discovers it can email a patch that GitLab automatically commits in your name and triggers associated CI/CD pipelines.

Actionable Takeaway: Rotate personal GitLab issue email tokens immediately and enforce branch protection rules alongside strict commit verification.

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, representing one of its single largest coordinated software patch deployments to date.

Actionable Takeaway: Prioritize deployment based on active exploitation telemetry, focusing heavily on critical remote code execution vectors across Windows components.

Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign

Threat actors are actively poisoning ChatGPT, Gemini, and Google AI Overview answers by seeding the web with malicious links and data, optimizing content to trick users into trusting fabricated guidance.

Actionable Takeaway: Educate employees on AI-generated hallucinations and poisoned reference links, implementing web filtering to block known malicious sources.

Sources & References

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
https://thehackernews.com/2026/09/attackers-use-malicious-terraform.html

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html

Data Broker Radaris Loses Domains in Privacy Fight
https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/

Microsoft Plugs Nearly 1,000 Security Holes
https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/

Research on Models Engaging in Genie-Like Behavior
https://www.schneier.com/blog/archives/2026/09/research-on-models-engaging-in-genie-like-behavior.html

GPT-6 Astra Breaks an Old Enigma Message
https://www.schneier.com/blog/archives/2026/09/gpt-6-astra-breaks-an-old-enigma-message.html

UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks
https://www.darkreading.com/threat-intelligence/uae-saudi-arabia-face-onslaught-of-increasingly-sophisticated-automated-cyberattacks

Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign
https://www.darkreading.com/threat-intelligence/attackers-manipulate-ai-chatbots-mass-disinformation-phishing-campaign

Student Loan Breach Exposes 2.5M Records
https://threatpost.com/student-loan-breach-exposes-2-5m-records/180492/

Watering Hole Attacks Push ScanBox Keylogger
https://threatpost.com/watering-hole-attacks-push-scanbox-keylogger/180490/

Looking for free Robux? Here’s what’s real, and what’s a scam
https://www.welivesecurity.com/en/kids-online/looking-for-free-robux-heres-whats-real-whats-scam/

The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive
https://www.welivesecurity.com/en/business-security/smb-cybersecurity-squeeze-ai-agents-work-old-attacks-overdrive/

The Closed Quorum: Inside the first reported autonomous AI C2 implant
https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/

Introducing CAIRN: Frontier tracking for AI-integrated malware
https://blog.talosintelligence.com/introducing-cairn-frontier-tracking-for-ai-integrated-malware/

How device code phishing gives scammers access to your account
https://www.malwarebytes.com/blog/how-to/2026/09/how-device-code-phishing-gives-scammers-access-to-your-account

Fake Claude Max giveaway hides a Google account phishing trap
https://www.malwarebytes.com/blog/threat-intel/2026/09/fake-claude-max-giveaway-hides-a-google-account-phishing-trap

LimeLeads - 17,838,396 breached accounts
https://haveibeenpwned.com/Breach/LimeLeads

Burger King Russia - 3,155,792 breached accounts
https://haveibeenpwned.com/Breach/BurgerKingRussia

Macfinger ClickFix campaign, (Tue, Sep 22nd)
https://isc.sans.edu/diary/rss/33360

ISC Stormcast For Wednesday, September 23rd, 2026
https://isc.sans.edu/podcastdetail/10106

Supporting ASD’s multi-factor authentication campaign: Why MFA matters more than ever
https://aws.amazon.com/blogs/security/supporting-asds-multi-factor-authentication-campaign-why-mfa-matters-more-than-ever/

Transforming Bedrock Guardrails events into OCSF with CloudWatch
https://aws.amazon.com/blogs/security/transforming-bedrock-guardrails-events-into-ocsf-with-cloudwatch/

Cofense Expands AI-Driven Phishing Defense Platform to Advance Secure Behavior Management
https://cofense.com/blog/cofense-expands-ai-driven-phishing-defense-platform-to-advance-secure-behavior-management

Beyond Human Risk: A Better Way to Build Secure Behavior
https://cofense.com/blog/beyond-human-risk-a-better-way-to-build-secure-behavior

Ransom & Dark Web Issues Week 4, September 2026
https://asec.ahnlab.com/en/95545/

August 2026 Infostealer Trend Report
https://asec.ahnlab.com/en/95519/

Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor

Fake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams
https://www.bitdefender.com/en-us/blog/labs/fake-shops-europe-samsung-world-cup-scams

UN Reports Citing Citizen Lab Submissions Published
https://citizenlab.ca/un-reports-citing-citizen-lab-submissions-published/

Submission to the Immigration and Refugee Board of Canada
https://citizenlab.ca/submission-to-the-immigration-and-refugee-board-of-canada/

Vulnerability in WEBCON BPS software
https://cert.pl/en/posts/2026/09/CVE-2026-92419/

Inside a multi stage toll fraud operation targeting Poland
https://cert.pl/en/posts/2026/09/tollfraud-analysis/

CIS Community Defense Model v3.0: Turning Threat Intelligence Into Action
https://www.cisecurity.org/insights/blog/cis-community-defense-model-v3-turning-threat-intelligence-into-action

CIS Benchmarks September 2026 Update
https://www.cisecurity.org/insights/blog/cis-benchmarks-september-2026-update

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-adobe-products-could-allow-for-arbitrary-code-execution_2026-099

A Vulnerability in F5 BIG-IP Access Policy Manager Could Allow for Remote Code Execution
https://www.cisecurity.org/advisory/a-vulnerability-in-f5-big-ip-access-policy-manager-could-allow-for-remote-code-execution_2026-098

Previous editions:
Fort Lauderdale, FL, September 28, 2026
Visitors since September 18th, 2026: 34,874