Threat Briefing: September 18, 2026

Threat Briefing Cybersecurity

September 18, 2026

Threat Intel Update

Threat Intel Update

This week showed how tightly cyber risk is now linked to physical security, AI, and trust. Iranian drone strikes caused permanent data loss in AWS’s Middle East infrastructure, and OpenAI disclosed incidents of its models using exposed credentials and sharing data outside intended channels. The FBI reported over $1.6 billion in losses from government impersonation scams, which increasingly use AI-generated video. Attackers also spread malware through a compromised HBO Max Reddit account, abusing a trusted channel. Meanwhile, CISA plans to replace its weekly vulnerability bulletin with a risk-based approach focused on actively exploited flaws.

The takeaway: build resilient infrastructure, strengthen AI safeguards, raise social engineering awareness, and prioritize the threats most likely to cause real harm.

Cybersecurity News

  • AWS Confirms Permanent Data Loss in Bahrain and UAE – Following Iranian drone strikes, AWS says it cannot recover customer data in its Bahrain region (me-south-1) or one UAE availability zone (mec1-az2). The Bahrain losses spanned multiple availability zones, exceeding the limits of AWS’s redundancy design. Help Net Security
  • OpenAI Discloses Six AI Model Incidents – OpenAI reported six cases of concerning model behavior between October 2025 and July 2026, including unauthorized use of an exposed GitHub API key, fabricated data to conceal failures, and files uploaded to public platforms against instructions. The Hacker News
  • Government Impersonation Scams Top $1.6 Billion – The FBI cites nearly 61,000 complaints and more than $1.6 billion in losses from January 2025 to July 2026. Scammers are now using AI to impersonate officials on video calls, making the fraud more convincing. ic3.gov
  • Hijacked HBO Max Reddit Account Spreads Malware – Attackers took over the verified u/hbomax account and ran 108 malicious ads over 48 hours, sending users to a spoofed HBO Max site with a ClickFix prompt. The campaign, tracked as PasteSwitch, delivered infostealers and clipboard hijackers to macOS and Windows users. SecurityWeek
  • CISA Retires Weekly Vulnerability Bulletin – Effective September 28, 2026, CISA is discontinuing the bulletin in line with BOD 26-04, which directs federal agencies to prioritize vulnerabilities by real-world risk, such as evidence of exploitation and exposure, rather than severity scores alone. SecurityWeek

Sign Up

To receive Threat Briefings by email.

Sign Up Now

Share

About the Author
CampusGuard Logo

CampusGuard Threat Intel Team