Cisco Talos warns that advances in AI-driven vulnerability discovery will surface issues that may be difficult—or impossible—to fully patch in every environment. The practical takeaway: invest in strong network segmentation, continuous visibility, and layered protections using NGFW/IPS combinations to reduce blast radius and constrain exploitation paths. Treat “patching” as one control in a broader resiliency strategy rather than the only answer.
Source: Cisco Talos
Ransomware activity in Japan rises as groups evolve operations (Gentlemen, Qilin show AI use)
Cisco Talos reports ransomware incidents in Japan increased 4.7% year over year in the first half of 2026, with The Gentlemen the most active group. Leak-site listings more than doubled from January to July, signaling sustained pressure on victims’ extortion posture. Qilin ranked second and is reported to have used AI, while SMEs with capital under JPY 1 billion made up 80% of victims—highlighting why smaller organizations remain a high-value target segment.
Source: Cisco Talos
Identity/token security guidance lands: NIST and CISA publish a playbook against token theft and forgery
NIST and CISA finalized guidance (NIST IR 8587) aimed at protecting identity and access tokens from forgery, theft, and misuse across federal agencies and cloud service providers. The recommendations focus on key management, token verification, and token lifecycle controls—areas that directly reduce the likelihood that attackers can transform stolen assertions into session access. For security teams, the key insight is that modern breaches increasingly bypass “password-only” thinking and target the token supply chain.
Source: Help Net Security
Exploited in the wild: Acronis backup plugin privilege-escalation flaw (CVE-2026-87886)
Acronis warns that CVE-2026-87886, a Linux privilege escalation issue in its backup plugins for cPanel/WHM, is being exploited in limited, targeted attacks. The problem is rooted in insecure file permissions, enabling escalation beyond the initially compromised context. The immediate operational priority is to patch or mitigate affected plugin deployments quickly and verify integrity around backup-extension installations—since backup tooling is often highly trusted in incident response.
Source: Help Net Security
Google Pixel modem zero-day shows limited targeted exploitation—patch now
Google’s September update addresses a high-severity Pixel cellular modem flaw (CVE-2026-58704) with evidence suggesting limited, targeted exploitation. This matters because modem-layer issues can be harder to detect with traditional endpoint monitoring, and they may affect high numbers of mobile users who assume “automatic updates” are sufficient. The defensive message is straightforward: prioritize installation of the latest Pixel update immediately, and confirm fleet compliance for managed devices where applicable.
Source: Malwarebytes Blog
CISA issues guidance for deploying cyber decoys as a detection and disruption layer
Security Week reports CISA released guidance on deploying cyber decoys to complement Zero Trust models. Decoys are intended to detect, observe, and block malicious activity—useful when attackers blend into normal operations or when telemetry is incomplete. The key takeaway for practitioners: treat decoys as part of an active defense program with clear objectives (what to lure, what to measure, and how to trigger response) rather than as “set and forget” traps.
Source: Security Week
You May Also Be Interested In...
More on ransomware trends from Cisco Talos