Weekly Threat Intelligence Brief, 7–11 September 2026

From the Desk of Melissa Irace, CISO

The threats this week reinforce a simple truth: attackers are focusing on the technologies that keep organizations connected and protected. The question isn’t if these systems will be targeted — it’s whether your organization can detect and respond quickly enough to limit the impact.

Weekly executive summary

This week’s cyber activity highlights a clear trend: attackers are targeting the very systems organizations rely on to stay secure — firewalls, VPNs, and management platforms. Active exploitation of Cisco Secure FMC, NetScaler, and WatchGuard devices shows that security infrastructure has become a high-value entry point for ransomware and espionage.

We’re also seeing increased browser exploitation with a new BlueMoon exploit kit, and AI-powered attacks being used to rapidly compromise vulnerable PaperCut systems.

The takeaway for leaders: it’s not just about patching. Organizations must validate whether their defenses are working, detect compromise early, and ensure critical systems can continue operating if technology is disrupted.

Melissa’s perspective

“The biggest risk this week isn’t just new vulnerabilities — it’s the targeting of the systems we trust most. Security platforms, remote access, and management tools are now prime targets. Organizations should prioritize visibility, validate their defenses, and assume a breach could happen even after patching.”

This week’s top threats

01 · Severe

Cisco Secure FMC under active exploitation

Attackers are actively targeting Cisco’s firewall management platform, which controls and manages network security devices. A successful attack can give criminals broad access to internal networks, security configurations, and sensitive data.

How Intuitus helps

  • External Attack Surface Assessments
  • Penetration Testing as a Service (PTaaS)
  • Network Security Assessments
  • Security Architecture Reviews
  • Vulnerability Assessments

Source: BleepingComputer, “Cisco confirms Secure FMC flaw exploited in attacks”

02 · High

NetScaler authentication bypass exploited

Attackers are exploiting a critical vulnerability in NetScaler appliances, which are commonly used for secure remote access. This can allow unauthorized access to internal systems, putting sensitive data and business operations at risk.

How Intuitus helps

  • Penetration Testing as a Service (PTaaS)
  • Identity Security Assessments
  • Network Security Assessments
  • Vulnerability Assessments
  • Managed Detection & Response (MDR)

Source: SecurityWeek, “Critical NetScaler Vulnerability Exploited in Attacks”

03 · High

WatchGuard Firebox RCE used in ransomware attacks

Cybercriminals are actively exploiting a vulnerability in WatchGuard Firebox devices to gain unauthorized access. This is now being used in ransomware attacks, which can lead to data loss, operational disruption, and significant financial impact.

How Intuitus helps

  • Network Security Assessments
  • Vulnerability Assessments
  • Penetration Testing as a Service (PTaaS)
  • Ransomware Readiness Assessments
  • Managed Detection & Response (MDR)

Source: BleepingComputer, “CISA: WatchGuard RCE flaw now exploited in ransomware attacks”

04 · High

BlueMoon exploit kit targets Chrome and Windows

A new exploit kit is being used to target web browsers, including Chrome, to gain control of computers. This can lead to credential theft, unauthorized access, and espionage, with government, defense, and other organizations among the targets.

How Intuitus helps

  • Endpoint Security Assessments
  • Penetration Testing as a Service (PTaaS)
  • Vulnerability Assessments
  • Security Awareness Training
  • Managed Detection & Response (MDR)

Source: BleepingComputer, “New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws”

05 · Medium

AI-powered PaperCut campaign compromises hundreds of organizations

Threat actors are using AI to automate and scale attacks against vulnerable PaperCut systems. Hundreds of organizations have been compromised, showing how quickly attackers can now find and exploit weaknesses.

How Intuitus helps

  • Application Security Assessments
  • External Attack Surface Assessments
  • Vulnerability Assessments
  • Internal Infrastructure Reviews
  • Managed Detection & Response (MDR)

Source: BleepingComputer, “AI-powered attack exploited PaperCut flaws to hack 395 organizations”

Our approach

We don’t simply report threats. We help organizations understand their business impact, validate their defenses, and build resilience before an incident occurs. Our intelligence-driven approach transforms emerging cyber threats into practical, prioritized actions that strengthen security, improve operational resilience, and support informed executive decisions.

Five actions to take this week

  • Patch priority. Immediately patch firewalls, VPNs, and other exposed systems.
  • Check for compromise. Review logs and activity on security appliances and critical systems for signs of unauthorized access.
  • Strengthen access controls. Enforce multi-factor authentication and review administrative access across key systems.
  • Update endpoints. Ensure browsers, operating systems, and enterprise applications are fully updated.
  • Prepare and respond. Validate incident response plans and test recovery procedures for ransomware and service disruptions.

Start the conversation

Talk to a cybersecurity engineer — not a sales rep.

Tell us your industry and where you are today. We’ll route you to the right specialist and a practical next step — no pressure, no jargon.