STRATQUAD
CYBER THREAT INTELLIGENCE BRIEF
Daily Brief · 13 September 2026 · 24h windowRISKCRITICAL
StratQuad CTI Daily Brief, 13 September 2026

Compiled from 52 monitored sources · 1142 articles reviewed

Today’s Briefing

CISA added three vulnerabilities to the Known Exploited Vulnerabilities catalog on evidence of active exploitation: CVE-2026-42016 and CVE-2026-42018 in JFrog Artifactory, both incorrect authorisation flaws, and a third item not fully detailed in today's reporting. Separately, Head Mare is exploiting an unpatched TrueConf server to deliver PhantomCore and PhantomGraph malware to video conference participants, and ShinyHunters is targeting the education sector with an Oracle PeopleSoft exploit.

Top Stories

  1. CISA Adds Three Known Exploited Vulnerabilities to Catalog
  2. CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
  3. Anthropic: AI Misuse Is Entering a New Phase: From Cybercrime to Surveillance, Propaganda and Weapons

Full brief available to subscribers

The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.

All briefs