Top impactful security developments (2026-09-13 08:12) - 2 days summary
Most Impactful Security Incidents ( 2026‑09‑11 → 2026‑09‑12 )
1️⃣ Critical / High‑Severity Vulnerabilities (CVSS 7‑10)
| CVE | CVSS v3.0 Base | CVSS v2 Base | Affected component (as reported) | Debian releases impacted | Nessus plug‑in (source) |
|---|---|---|---|---|---|
| CVE‑2026‑89550 | 6.5 (Medium) | 9.4 (Critical) | Local privilege‑escalation / remote code execution on Debian Linux | 12, 13, 14 | https://www.tenable.com/plugins/nessus/345440 |
| CVE‑2026‑89560 | 7.1 (High) | 5.6 | Local privilege‑escalation on Debian Linux | 12‑14 | https://www.tenable.com/plugins/nessus/345444 |
| CVE‑2026‑89668 | 7.1 (High) | 5.6 | Local privilege‑escalation on Debian Linux | 12‑14 | https://www.tenable.com/plugins/nessus/345443 |
| CVE‑2026‑89646 | 7.1 (High) | 5.6 | Local privilege‑escalation on Debian Linux | 12‑14 | https://www.tenable.com/plugins/nessus/345426 |
| CVE‑2026‑89636 | 7.8 (Critical) | 5.6 | Local privilege‑escalation on Debian Linux | 12‑14 | https://www.tenable.com/plugins/nessus/345425 |
| CVE‑2026‑89682 | 7.8 (Critical) | 5.6 | Local privilege‑escalation on Debian Linux | 12‑14 | https://www.tenable.com/plugins/nessus/345428 |
| CVE‑2026‑89708 | 7.1 (High) | 5.6 | Local privilege‑escalation on Debian Linux | 12‑14 | https://www.tenable.com/plugins/nessus/345420 |
| CVE‑2026‑89724 | 7.8 (Critical) | 5.6 | Local privilege‑escalation on Debian Linux | 12‑14 | https://www.tenable.com/plugins/nessus/345421 |
| CVE‑2026‑89719 | 7.1 (High) | 5.6 | Local privilege‑escalation on Debian Linux | 12‑14 | https://www.tenable.com/plugins/nessus/345426 |
| CVE‑2026‑89470 | 7.8 (Critical) | 5.6 | Local privilege‑escalation on Debian Linux | 12‑14 | https://www.tenable.com/plugins/nessus/345422 |
| CVE‑2026‑89477 | 7.8 (Critical) | 5.6 | Local privilege‑escalation on Debian Linux | 12‑14 | https://www.tenable.com/plugins/nessus/345415 |
| CVE‑2026‑89533 | 7.1 (High) | 5.6 | Local privilege‑escalation on Debian Linux | 12‑14 | https://www.tenable.com/plugins/nessus/345417 |
| CVE‑2026‑89584 | 7.1 (High) | 5.6 | Local privilege‑escalation on Debian Linux | 12‑14 | https://www.tenable.com/plugins/nessus/345426 |
| CVE‑2026‑80944 | 7.2 (High) | 5.6 | Local privilege‑escalation on Debian Linux | 12‑14 | https://www.tenable.com/plugins/nessus/345411 |
| CVE‑2026‑80968 | 7.1 (High) | 5.6 | Local privilege‑escalation on Debian Linux | 12‑14 | https://www.tenable.com/plugins/nessus/345415 |
| CVE‑2026‑89481 | 5.6 (Medium) – listed for completeness | 5.6 | Local privilege‑escalation on Debian Linux | 12‑14 | https://www.tenable.com/plugins/nessus/345432 |
Why these matter
- All of the above are local privilege‑escalation or remote code execution flaws in the Debian GNU/Linux kernel or core libraries.
- CVSS v3 scores of 7.0 or higher place them in the High severity band; several reach Critical (≥ 9.0 on CVSS v2).
- The affected Debian releases (12, 13, 14) are widely deployed in cloud VMs, containers, and on‑prem servers, making the attack surface large.
- Exploits are not publicly disclosed yet, but the presence of Nessus plugins indicates that attackers could develop exploits quickly.
2️⃣ Actively‑Exploited Zero‑Days / Supply‑Chain Attacks
No zero‑day exploits or supply‑chain compromises were reported in the supplied data for the period.
3️⃣ Massive Ransomware Campaigns (Public‑Facing Blog Posts)
| Ransomware group | Recent “blog” post title (indicates new victim list or data dump) | Date (UTC) | Direct link |
|---|---|---|---|
| Krybit | www.tiflispalace.ge |
2026‑09‑12 18:13:46 | https://bsky.app/profile/cti.fyi/post/3mvdoorgnml2l |
| Krybit | capricornlogistics.com |
2026‑09‑12 18:13:42 | https://bsky.app/profile/cti.fyi/post/3mvdoonm75b2f |
| Krybit | www.ibnsinatrust.com |
2026‑09‑12 18:13:40 | https://bsky.app/profile/cti.fyi/post/3mvdoolwozo2i |
| Krybit | lasultanahotels.com |
2026‑09‑12 18:13:39 | https://bsky.app/profile/cti.fyi/post/3mvdookkrc72y |
| Krybit | eracm.fr |
2026‑09‑12 18:13:37 | https://bsky.app/profile/cti.fyi/post/3mvdoojgdbp2y |
| Krybit | pss.ht |
2026‑09‑12 18:13:35 | https://bsky.app/profile/cti.fyi/post/3mvdooh3rdk2h |
| Krybit | intherpro.com |
2026‑09‑12 18:13:34 | https://bsky.app/profile/cti.fyi/post/3mvdoofwxtr23 |
| Panzer | MDIF VISIT -MEMO.xlsx |
2026‑09‑11 12:20:44 | https://bsky.app/profile/cti.fyi/post/3mvakicv… |
| Panzer | Full Email List.xlsx |
2026‑09‑11 12:20:42 | https://bsky.app/profile/cti.fyi/post/3mvakijlvbi2f |
| Panzer | Photos / E‑PAPERS / Documents / Career / Backups |
2026‑09‑11 12:20:33‑12:17 | Various posts under the Panzer handle (e.g., https://bsky.app/profile/cti.fyi/post/3mvakiai7k32a) |
| BrainCipher | Multiple zip‑file drops (Shared Rec PO.zip, RND.zip, RD.zip, RA.zip, R&D.zip, Quality.zip, IT.zip, DOCS/, Automation/) |
2026‑09‑11 10:11 – 10:12 | https://bsky.app/profile/cti.fyi/post/3mvadc6… |
Implications
- The volume of posts from Krybit, Panzer, and BrainCipher within a single day signals large‑scale data‑exfiltration and victim‑list publishing.
- While the posts do not disclose technical exploit details, the public release of victim data (often in zip archives) is a hallmark of mass ransomware campaigns that can affect any organization whose data appears in the dumps.
- Security teams should monitor the listed domains for leaked data that matches their assets and consider proactive breach‑notification procedures.
Quick Action Checklist (for SOC / Incident‑Response)
- Patch / Update Debian Systems – Apply the latest security updates for Debian 12/13/14 immediately. Verify that the kernel version includes fixes for the CVEs listed above.
- Validate Nessus / OpenVAS Scans – Run the corresponding Nessus plug‑ins (IDs 345440‑345428, etc.) against all Linux assets to confirm exposure.
- Hardening – Enforce least‑privilege for local accounts, disable unnecessary services, and enable SELinux/AppArmor where possible to mitigate privilege‑escalation paths.
- Ransomware Monitoring – Add the listed domains/URLs to threat‑intel feeds; set up file‑hash monitoring for the zip archives (if they become publicly hashed).
- Incident‑Response Playbooks – Review ransomware response procedures (containment, decryption‑key negotiation, public‑disclosure) in light of the new victim‑list publications.
All URLs are directly reachable from the source data; no additional external references were required.
Model=gpt-oss:120b top_k=70 context_window=131072 query_mode=cluster