ITSECURITY.GURU WHAT HAPPENED · DOES IT AFFECT YOU · WHAT TO DO
Board › Daily Briefing › 25 Sept 2026

ITSECURITY.GURU

Daily Briefing

Today's outlook

Kiteworks tells customers to power down servers Saturday over warning of a potential attack

Good morning. Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window, BleepingComputer reported, after the secure file-sharing company received threat intelligence warning of a potentially imminent cyberattack. Frank Balonis, CISO at Kiteworks, told Recorded Future News the company "received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers." If you run Kiteworks, treat the vendor's six-hour shutdown window as the stated mitigation and plan for it now.

CISA added one new vulnerability to its Known Exploited Vulnerabilities Catalog based on evidence of active exploitation: CVE-2026-87902, a WordPress Core Remote File Inclusion vulnerability, per CISA's alert. CISA notes this class of flaw is a frequent attack vector, and points to Binding Operational Directive 26-04 for prioritising updates. Match your estate against the affected product and prioritise accordingly.

Separately, BleepingComputer reported a cross-site request forgery vulnerability in the Elementor plugin for WordPress that could allow an unauthenticated attacker to create administrator accounts. If you run WordPress with Elementor, review your admin account list.

On the criminal side, BleepingComputer reported the Clop ransomware gang moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer learned is an unauthenticated path traversal vulnerability. The Register reported that ShinyHunters told it the group hacked the FBI to "protect our business."

Two accountability stories closed the day. Krebs on Security reported a U.S. Army soldier who pleaded guilty to hacking multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison and ordered to pay nearly $300,000 in restitution. The Record reported Labcorp will overhaul its data security practices and pay a $2.3 million fine over cybersecurity failings, including creating an incident response plan for vendor security failings and limiting how much data it shares with vendors.

Two social-engineering trends are worth briefing staff on. The Register reported crooks are using fake desktop apps to fool HR staff into granting remote access, noting none of the impersonated HR and payroll providers actually offers a desktop app — a useful tell for your teams. The Register also reported a voice-phishing operation running fake Google Security Team ads.

For supply-chain watchers, The Hacker News reported two actions-cool GitHub Actions — actions-cool/issues-helper and actions-cool/maintain-one-comment — were disabled a second time after the repositories became accessible last week, months after being compromised in the May 2026 Mini Shai-Hulud campaign. Check your workflows for those actions. Finally, Help Net Security reported research from Conifers, which assessed 14,652 detections across its customer base, finding a detection rule can show as deployed on a coverage dashboard yet never fire against the technique it was built to catch.

Zoom out: Two of the day's headline items — the KEV addition and the Elementor flaw — sit in the WordPress ecosystem, alongside separate extortion-crew activity.

What we're tracking

  • Krebs on Security: U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions Read it
  • BleepingComputer: Kiteworks urges 6-hour server shutdown over potential zero-day attacks Read it
  • Schneier on Security: Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee Read it
  • The Record: Kiteworks urges customers to stop using platform after warning from federal intelligence agencies Read it

Sources

Summarized from the linked reports and the advisory record by the desk. Verify against the original sources before citing.

All briefings →