STRATQUAD
CYBER THREAT INTELLIGENCE BRIEF
Daily Brief · 10 September 2026 · 24h windowRISKCRITICAL
StratQuad CTI Daily Brief, 10 September 2026

Compiled from 52 monitored sources · 1415 articles reviewed

Today’s Briefing

Cisco Talos reports active exploitation of two vulnerabilities in Secure Firewall Management Center, one of which (CVE-2026-20079) CISA added to the KEV catalogue today alongside CVE-2026-19490 in Citrix NetScaler, CVE-2025-25249 in Fortinet FortiOS, and CVE-2026-87491 in Chrome V8. Microsoft's September update addresses 974 vulnerabilities including two exploited zero-days, and Google patched 230 flaws in Chrome including the KEV-listed V8 issue. Proofpoint published analysis of the BlueMoon exploit kit, a Chrome and Windows chain adopted by four nation-state espionage groups within twelve days of first use, with researchers assessing AI-assisted development as a likely factor in the rapid proliferation.

Top Stories

  1. Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
  2. CC-4847 - Google Releases Security Update for Chrome
  3. CC-4846 - Microsoft Releases September 2026 Security Updates
  4. Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
  5. CISA Adds Four Known Exploited Vulnerabilities to Catalog

Full brief available to subscribers

The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.

All briefs