The 5-Minute Cyber Brief
Good morning. Start with the newly exploited vulnerabilities most likely to reshuffle patch queues today, then move through the supporting developments that deserve attention.
Lead Story
CISA Adds One Known Exploited Vulnerability to Catalog

This is not just another catalog update. CISA is effectively telling defenders that these flaws have crossed from known problem into active exploitation territory, which means affected environments now belong in the patch queue's front row. The signal here sits at the intersection of kev, advisories, critical infrastructure.
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for new policy moves, CISA actions, and risk developments this article could not cover when it was published.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters: KEV additions matter because they turn patching debates into exposure decisions. Once CISA adds a flaw here, slower teams lose room to treat it like routine backlog.
Read more on CyberExperts: Read more on CyberExperts
Original source: CISA
Also Worth Your Attention
Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy

A technical analysis of three chained zero-day vulnerabilities in Siemens ROX II OT switches that allow privilege escalation and persistent root access.
Why it matters: This matters because exploit-chain research is most useful when it shows defenders exactly how smaller weaknesses combine into privileged access, persistence, and a bigger operational blast radius.
Read more on CyberExperts: Read more on CyberExperts
The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version

Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic.
Why it matters: This matters because developer-toolchain malware turns normal build activity into a supply-chain risk, and many teams still monitor production far more closely than their build environments.
Read more on CyberExperts: Read more on CyberExperts
Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE).
Reading an older article? Use the brief to stay current.
This Article Gives You the Background. The Brief Gives You What Changed Next.
Get the weekday cyber brief for the developments, risk shifts, and new signals that changed the picture after this article was published.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
Why it matters: This matters because a file-read flaw in a common upload path can quickly become a credential and server-trust problem if exposed application secrets are reachable.
Read more on CyberExperts: Read more on CyberExperts
Amgen says cloud data breach exposed patient health, proprietary info

Pharmaceutical company Amgen says it suffered a data breach after threat actors stole corporate data and patient information stored in multiple cloud systems operated by third-party service providers.
Why it matters: This matters because third-party cloud exposure can turn one provider-side compromise into a messy mix of patient impact, regulatory reporting, and uncertain downstream scope.
Read more on CyberExperts: Read more on CyberExperts
Go Deeper
Editorial Promise
CyberExperts should help you get the signal fast, understand what actually matters, and know where to go deeper before the day gets noisy.
Newer CyberExperts coverage on this topic
This article still works as background. If you want the current picture, start with the freshest related coverage below and today's brief.
Coder’s registry infrastructure compromised to push malicious modules
The Coder incident is a supply-chain lesson in miniature: once attackers can tamper with trusted module distribution, defenders are no longer verifying...
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
The useful lesson in this campaign is not that Node.js is bad. It is that adversaries keep choosing legitimate runtimes defenders already...
HPE patches critical ArubaOS-CX remote code execution flaw
ArubaOS-CX deserves attention because switching software rarely gets treated with the same urgency as identity or edge security until exploitation arrives. A...
The 5-Minute Cyber Brief: September 18, 2026
The fastest way to catch up on what changed after this article was published.
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.