The Daily Zero-Day

Date: SEPTEMBER 25, 2026 Editor-in-Chief: Jose Laurentino III Global Threat Intelligence Edition

Executive Summary

Today's edition of The Daily Zero-Day on September 25, 2026, details critical architectural flaws spanning cloud computing, AI-driven command and control frameworks, and mass enterprise patch cycles. Major developments include container isolation vulnerabilities at Cloudflare, the activation of CISA KEV entries for WSO2 and Adobe Commerce, record-breaking patch distributions from Microsoft, and sophisticated new vectors involving autonomous AI agents and evasive npm payloads.

Top Intelligence Briefings

Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data

A severe security flaw discovered in Cloudflare Containers allowed paying customers to read residual data left behind by other customer workloads residing on the same host server.

Actionable Takeaway: Cloudflare has resolved the issue, but multi-tenant cloud operators must rigorously audit instance teardown and block-storage sanitization routines.

The Closed Quorum: Inside the first reported autonomous AI C2 implant

Discovered through Cisco Talos’ CAIRN project, the CLOSEDQUORUM malware binary demonstrates fully autonomous command and control (C2) capabilities, representing a massive paradigm shift in weaponized AI architecture.

Actionable Takeaway: Security teams must establish runtime anomaly detection capable of flagging autonomous behavioral patterns in local asset binaries rather than relying solely on traditional IOC signatures.

Microsoft Plugs Nearly 1,000 Security Holes

In a historic update cycle, Microsoft issued security patches addressing at least 974 distinct vulnerabilities across Windows operating systems and auxiliary software lines.

Actionable Takeaway: Prioritize deployment of these updates across enterprise systems, focusing initially on active remote code execution and elevation of privilege vectors.

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

CISA has officially added two critical vulnerabilities impacting WSO2 and Adobe Commerce to its Known Exploited Vulnerabilities catalog following active in-the-wild campaigns.

Actionable Takeaway: Immediately inventory external-facing WSO2 and Adobe Commerce deployments and apply vendor-supplied patches to block active exploitation vectors.

Russia's Hybrid Cyber-Physical War in Europe Heats Up

European infrastructure providers face an escalating wave of cyber sabotage, coordinated disinformation campaigns, and physical drone actions targeting nations supporting Ukraine.

Actionable Takeaway: Convergence teams across IT and physical security must coordinate monitoring on critical grid nodes and logistical supply chains.

Sources & References

Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
https://thehackernews.com/2026/09/cloudflare-fixes-flaw-that-let-one.html

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
https://thehackernews.com/2026/09/wso2-and-adobe-commerce-flaws-exploited.html

Data Broker Radaris Loses Domains in Privacy Fight
https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/

Microsoft Plugs Nearly 1,000 Security Holes
https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/

Malicious npm Packages That Evade Defenses
https://www.schneier.com/blog/archives/2026/09/malicious-npm-packages-that-evade-defenses.html

Research on Models Engaging in Genie-Like Behavior
https://www.schneier.com/blog/archives/2026/09/research-on-models-engaging-in-genie-like-behavior.html

Russia's Hybrid Cyber-Physical War in Europe Heats Up
https://www.darkreading.com/physical-security/russia-hybrid-cyber-physical-war-europe

'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
https://www.darkreading.com/application-security/salesbleed-exploits-salesforce-agents-slack-phishing

Student Loan Breach Exposes 2.5M Records
https://threatpost.com/student-loan-breach-exposes-2.5m-records/180492/

Watering Hole Attacks Push ScanBox Keylogger
https://threatpost.com/watering-hole-attacks-push-scanbox-keylogger/180490/

Looking for free Robux? Here’s what’s real, and what’s a scam
https://www.welivesecurity.com/en/kids-online/looking-for-free-robux-heres-whats-real-whats-scam/

The SMB cybersecurity squeeze: AI agents at work, old attacks in overdrive
https://www.welivesecurity.com/en/business-security/smb-cybersecurity-squeeze-ai-agents-work-old-attacks-overdrive/

Trust and the enticing consultancy offer
https://blog.talosintelligence.com/trust-and-the-enticing-consultancy-offer/

The Closed Quorum: Inside the first reported autonomous AI C2 implant
https://blog.talosintelligence.com/the-closed-quorum-inside-the-first-reported-autonomous-ai-c2-implant/

That shipping rebate offer may come with a monthly charge
https://www.malwarebytes.com/blog/threat-intel/2026/09/that-shipping-rebate-offer-may-come-with-a-monthly-charge

OpenAI agent breached Australian government site, took months to report it
https://www.malwarebytes.com/blog/ai/2026/09/openai-agent-breached-medicare-statistics-portal-then-took-months-to-report-it

LimeLeads - 17,838,396 breached accounts
https://haveibeenpwned.com/Breach/LimeLeads

Burger King Russia - 3,155,792 breached accounts
https://haveibeenpwned.com/Breach/BurgerKingRussia

A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)
https://isc.sans.edu/diary/rss/33368

ISC Stormcast For Friday, September 25th, 2026 https://isc.sans.edu/podcastdetail/10110, (Fri, Sep 25th)
https://isc.sans.edu/podcastdetail/10110

ICYMI: August 2026 @AWS Security
https://aws.amazon.com/blogs/security/icymi-august-2026-aws-security/

Supporting ASD’s multi-factor authentication campaign: Why MFA matters more than ever
https://aws.amazon.com/blogs/security/supporting-asds-multi-factor-authentication-campaign-why-mfa-matters-more-than-ever/

Cofense Expands AI-Driven Phishing Defense Platform to Advance Secure Behavior Management
https://cofense.com/blog/cofense-expands-ai-driven-phishing-defense-platform-to-advance-secure-behavior-management

Beyond Human Risk: A Better Way to Build Secure Behavior
https://cofense.com/blog/beyond-human-risk-a-better-way-to-build-secure-behavior

Ransom & Dark Web Issues Week 4, September 2026
https://asec.ahnlab.com/en/95545/

August 2026 Infostealer Trend Report
https://asec.ahnlab.com/en/95519/

Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
https://www.bitdefender.com/en-us/blog/labs/fake-xeno-roblox-discord-executor

Fake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams
https://www.bitdefender.com/en-us/blog/labs/fake-shops-europe-samsung-world-cup-scams

UN Reports Citing Citizen Lab Submissions Published
https://citizenlab.ca/un-reports-citing-citizen-lab-submissions-published/

Submission to the Immigration and Refugee Board of Canada
https://citizenlab.ca/submission-to-the-immigration-and-refugee-board-of-canada/

Vulnerability in WEBCON BPS software
https://cert.pl/en/posts/2026/09/CVE-2026-92419/

Inside a multi stage toll fraud operation targeting Poland
https://cert.pl/en/posts/2026/09/tollfraud-analysis/

CIS Community Defense Model v3.0: Turning Threat Intelligence Into Action
https://www.cisecurity.org/insights/blog/cis-community-defense-model-v3-turning-threat-intelligence-into-action

CIS Benchmarks September 2026 Update
https://www.cisecurity.org/insights/blog/cis-benchmarks-september-2026-update

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-google-chrome-could-allow-for-arbitrary-code-execution_2026-101

Multiple Vulnerabilities in IBM Concert Software Could Allow for Remote Code Execution
https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-ibm-concert-software-could-allow-for-remote-code-execution_2026-100

Previous editions:
Fort Lauderdale, FL, September 28, 2026
Visitors since September 18th, 2026: 34,878