SECURITY // DAILY THREAT INTEL

Cyber Threat Intel — September 22, 2026

A compact daily recap of the threats, breaches and exploitation activity worth paying attention to.

Cyber Threat Intel Recap for September 22, 2026

Top developments

  1. Zyxel GS1900 / CVE-2026-7273: active exploitation moved into CISA KEV. GreyNoise reported 996 switches compromised across 48 countries, with configuration data and hashed credentials taken.
  2. Broader infrastructure campaign: the same or closely related activity has targeted public management surfaces including UniFi, WordPress, Gitea, Zyxel and Proxmox-class infrastructure.
  3. BigCommerce / Ribon: a third-party application credential compromise led to customer-data exposure and malicious script injection on affected merchant storefronts.
  4. Veeam Agent / CVE-2026-32996: exploitation is being observed for SYSTEM-level privilege escalation on vulnerable Windows endpoints.
  5. Control-plane targeting: management interfaces, backup tooling, network devices and trusted SaaS integrations continue to offer attackers more leverage than a single endpoint.

Source set

This recap was built from current vendor, government and threat-intelligence reporting, including CISA, GreyNoise, Zyxel, Arctic Wolf and BigCommerce. Ransomware leak-site claims are kept separate from confirmed victim disclosures.