← September 2026
News 2026-09-12

IAM & Security Weekly Briefing

Microsoft shipped a record 974 patches, including two Windows flaws exploited in the wild, pushing monthly patch volume beyond what most teams can test and deploy.

IAM & Security Weekly Briefing
Open report

IAM & Security Weekly Briefing

Week of: 2026-09-06 to 2026-09-12 Reporting window: Most recently completed Sunday–Saturday (excludes the in-progress week).


1. Executive Summary (TL;DR)

  • Microsoft shipped a record 974 patches, including two Windows flaws exploited in the wild, pushing monthly patch volume beyond what most teams can test and deploy.
  • Anthropic disclosed repeated abuse of Claude by criminal and state-sponsored "Generative Threat Groups," including a Russia-linked espionage operation against 20+ government, defense, and diplomatic organizations.
  • Identity was the entry point in the week's biggest breach: Florida's DMV database was accessed with credentials stolen from a police officer's personal device, in an incident claimed by ShinyHunters.
  • Credential-focused social engineering dominated: passkey/SSO-themed phishing against Microsoft 365, and IT help-desk vishing combined with adversary-in-the-middle token theft and residential-proxy sign-ins aimed at executives.
  • Authentication and authorization bypasses drove exploitation in Check Point VPN, Cisco FMC (CVSS 10.0), JFrog Artifactory, GitLab, FreeIPA, and N-able N-central — several added to CISA's KEV catalog with short federal deadlines.
  • AI gateways and agent identities are an emerging exposure class: nearly 1 in 10 internet-facing LiteLLM servers accepted the example admin key "sk-1234," and infostealer logs are surfacing replayable AI tokens that bypass MFA.
  • Attackers used autonomous, multi-agent frameworks to compromise thousands of credentials in under six hours, and a PaperCut attacker used hundreds of AI agents against 440+ instances.
  • Regulatory pressure is rising: CISA pressed for transparency in breach notification, and the EU Cyber Resilience Act introduced a 24-hour serious-incident reporting requirement.

2. Top IAM & Security News

Microsoft patches record 974 flaws, including two exploited Windows zero-days

  • Source: The Hacker News
  • Link: The Hacker News
  • Date: 2026-09-09
  • What happened: Microsoft released fixes for 974 vulnerabilities — 723 in Windows, 111 in Office/Office 2016, 62 in SQL, and 22 in developer tools, with over 110 rated critical and two actively exploited.
  • Why it matters: Patch volume at this scale exceeds most organizations' testing capacity, so teams must prioritize by real exposure (internet-facing, identity-adjacent, and actively exploited assets) rather than CVSS alone.

Dutch NCSC warns exploitation of critical Check Point VPN flaws is imminent

  • Source: BleepingComputer
  • Link: BleepingComputer
  • Date: 2026-09-12
  • What happened: The Dutch national cyber security center warned of imminent exploitation of two critical Check Point VPN flaws, tracked as CVE-2026-85102 and CVE-2026-85103.
  • Why it matters: VPN gateways are identity chokepoints for remote access — an unpatched gateway can let attackers bypass authentication outright, so emergency patch and access-log review are warranted now.

Cisco FMC authentication bypass exploited to steal credentials and deploy Qilin ransomware

  • Source: The Hacker News
  • Link: The Hacker News
  • Date: 2026-09-11
  • What happened: Cisco said three distinct threat clusters, linked to ransomware and state-sponsored activity, are exploiting Secure Firewall Management Center flaws including CVE-2026-20079 (CVSS 10.0), an unauthenticated authentication bypass in the web interface, to steal credentials and deploy Qilin ransomware.
  • Why it matters: A CVSS 10.0 auth bypass on security management infrastructure gives attackers a trusted foothold for credential theft and lateral movement — treat FMC as a tier-0 asset and verify patch status immediately.

FreeIPA flaw chain lets anonymous clients create administrator credentials

  • Source: The Hacker News
  • Link: The Hacker News
  • Date: 2026-09-08
  • What happened: Red Hat says a flaw in FreeIPA allows a client that has never logged in to create a Kerberos identity of its choosing in the directory and end up in the administrators group, requiring a second flaw in the underlying 389 Directory Server.
  • Why it matters: This is a direct identity-provider compromise path for Linux estates — inventory FreeIPA/389 DS exposure, patch, and audit for unexpected directory objects and admin group membership.

Passkey- and SSO-themed phishing campaigns lead to Microsoft 365 data theft

  • Source: BleepingComputer
  • Link: BleepingComputer
  • Date: 2026-09-11
  • What happened: Microsoft said threat actors tied to ShinyHunters, Helix, and other extortion gangs are using passkey- and single sign-on-themed social engineering to compromise corporate Microsoft accounts and steal data from Microsoft 365 services.
  • Why it matters: Attackers are weaponizing the language of stronger authentication to lower user suspicion — phishing-resistant MFA must be paired with user education that covers fake "passkey enrollment" and SSO prompts.

Fake IT calls target executives in Microsoft 365 data theft and extortion

  • Source: The Hacker News
  • Link: The Hacker News
  • Date: 2026-09-07
  • What happened: Researchers detailed a widespread data theft and extortion cluster targeting Microsoft 365 and other SaaS offerings through IT help-desk vishing, adversary-in-the-middle token theft, and residential-proxy sign-ins, focusing on directors, VPs, and other executives.
  • Why it matters: The attack chain defeats standard MFA by stealing session tokens through the help desk — identity teams need hardened help-desk verification procedures and conditional access that detects token replay and proxy-based sign-ins.

Florida confirms DMV database breach via stolen police account credentials

  • Source: The Record
  • Link: The Record
  • Date: 2026-09-11
  • What happened: The Florida Department of Motor Vehicles confirmed a breach claimed by ShinyHunters, saying it originated with the theft of credentials stored on a police officer's personal device.
  • Why it matters: A single set of privileged credentials on an unmanaged personal device exposed a statewide driver database — a clear case for device-bound credentials, phishing-resistant MFA, and strict separation of work access from personal devices.

GitLab maximum-severity file-read flaw exploited one day after disclosure

  • Source: SecurityWeek
  • Link: SecurityWeek
  • Date: 2026-09-11
  • What happened: GitLab patched CVE-2026-85706 (CVSS 10.0), a path traversal flaw in the repository commits API that lets unauthenticated attackers read arbitrary files from the server, and exploitation followed within a day of disclosure.
  • Why it matters: Source control systems concentrate credentials, tokens, and CI/CD secrets — a short patch window here means unauthenticated access to exactly the material attackers use to pivot into cloud and deployment identities.

3. AI, Identity & Emerging Tech

Anthropic disrupts Russia-linked espionage group using Claude in hacking operations

  • Source: The Record
  • Link: The Record
  • Date: 2026-09-11
  • What happened: Anthropic detected and disrupted a Russia-linked cyber-espionage group using Claude in a campaign targeting more than 20 government, intelligence, diplomatic, and defense organizations.
  • Why it matters: AI assistants are now operational tooling for espionage, shortening the time between initial access and post-compromise activity — detection should focus on credential use and access patterns, not only malware.

Infostealer logs expose replayable AI tokens that can bypass MFA

  • Source: The Hacker News
  • Link: The Hacker News
  • Date: 2026-09-09
  • What happened: Cybercriminals are hijacking AI user accounts using information-stealer logs (such as Lumma Stealer and Vidar) that harvest credentials, session tokens, and API keys from model providers including Google and Anthropic.
  • Why it matters: Non-human credentials and long-lived AI API tokens extracted from endpoints are replayable and sidestep MFA — token inventory, rotation, and scope minimization for AI services are now core IAM hygiene.

Autonomous AI agents compromise thousands of credentials in under six hours

  • Source: The Hacker News
  • Link: The Hacker News
  • Date: 2026-09-08
  • What happened: Google Threat Intelligence Group observed a financially motivated group using an autonomous, multi-agent framework to run a large-scale credential harvesting campaign within six hours.
  • Why it matters: Agentic attacks compress the timeline for credential abuse, eroding detection windows built around human-paced intrusion — rate limiting, impossible-travel, and rapid credential revocation matter more than ever.

Nearly 1 in 10 exposed LiteLLM gateways accepted the example admin key "sk-1234"

  • Source: The Hacker News
  • Link: The Hacker News
  • Date: 2026-09-10
  • What happened: Wiz Research found that nearly one in ten internet-facing LiteLLM servers accepted "sk-1234," the example admin key from the project's own setup guide, which grants full gateway administrator access.
  • Why it matters: Default and example credentials on AI gateways are a systemic non-human identity failure — anyone holding that key can read every request and credential passing through the gateway.

'Workflow identity hijacking' bypasses standard controls to reach enterprise data

  • Source: Dark Reading
  • Link: Dark Reading
  • Date: 2026-09-09
  • What happened: Reporting describes an identity-based AI attack technique in which "workflow identity hijacking" bypasses standard security controls and hijacks organizational data via a basic request through an unauthenticated entry point.
  • Why it matters: When AI workflows act with delegated identity and broad data access, unauthenticated entry points become data-exfiltration paths — workflow service accounts need least privilege and authentication at every hop.

PaperCut attacker used hundreds of AI agents to compromise 440+ instances

  • Source: The Hacker News
  • Link: The Hacker News
  • Date: 2026-09-10
  • What happened: A suspected Russian-speaking actor used AI to devise exploits against recently disclosed PaperCut NG/MF flaws, compromising hundreds of instances (440+ per independent reports from Blackpoint Cyber and GreyNoise) from a single IP address.
  • Why it matters: AI-assisted exploit development plus mass scanning turns a single unpatched, internet-facing application into a fleet-wide compromise — asset inventory and rapid patch verification are the only reliable controls.

DeepSeek Harness flaw let AI agents disable their own file sandbox without approval

  • Source: The Hacker News
  • Link: The Hacker News
  • Date: 2026-09-09
  • What happened: A flaw in DeepSeek Harness, the open-source tool for running AI coding agents locally, let a sandboxed agent turn off its own sandbox with a single command by calling the tool's own web interface.
  • Why it matters: Agent guardrails that the agent itself can remove are not security boundaries — agent execution permissions should be enforced by the host OS and infrastructure, not by the agent's own tooling.

4. Cyber Threats & Attack Trends

Attackers chain JFrog Artifactory flaws to gain admin control and plant backdoors

  • Source: The Hacker News
  • Link: The Hacker News
  • Date: 2026-09-11
  • What happened: Wiz reported attackers chaining two JFrog Artifactory flaws between August 15 and September 8 to take administrator control of self-hosted servers and plant backdoors; CISA subsequently added related Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS flaws to its KEV catalog.
  • Why it matters: Build artifact repositories concentrate deployment credentials — an authorization/authentication bypass there lets attackers poison what every pipeline pulls, so unpatched self-hosted instances should be treated as potentially compromised.

Trezor: 347,000 users targeted in phishing after Brevo breach

  • Source: BleepingComputer
  • Link: BleepingComputer
  • Date: 2026-09-11
  • What happened: Trezor disclosed that phishing attacks after a Brevo breach targeted 347,000 email addresses, with 2,500 users clicking an embedded malicious link.
  • Why it matters: Third-party marketing and communications vendors are identity-adjacent suppliers — a vendor compromise converts into branded, high-credibility phishing against your users.

BlueMoon exploit kit chains recent Chrome and Windows zero-days across spy groups

  • Source: SecurityWeek
  • Link: SecurityWeek
  • Date: 2026-09-12
  • What happened: Multiple espionage-motivated threat actors adopted a previously undocumented exploit kit called BlueMoon, which chains vulnerabilities in Windows and Google Chrome, in opportunistic and rushed deployments.
  • Why it matters: Shared exploit kits lower the skill barrier for browser-based credential theft and session hijacking — browser patch SLAs and credential isolation on endpoints are the practical defenses.

Gigabud trojan creates Android work profiles to evade banking app checks

  • Source: The Hacker News
  • Link: The Hacker News
  • Date: 2026-09-10
  • What happened: Group-IB reported that the Gigabud banking trojan now installs a second Android app that creates a work profile and drops a tampered banking app inside it, hiding it from the personal-space checks banking apps rely on.
  • Why it matters: Attackers are abusing OS-level identity and isolation features — mobile threat models must account for work-profile abuse rather than assuming container separation equals safety.

Attackers use multi-hop Google redirects for phishing campaign

  • Source: Dark Reading
  • Link: Dark Reading
  • Date: 2026-09-08
  • What happened: Threat actors abused multiple Google services in chained redirects to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.
  • Why it matters: Trusted-domain redirects defeat domain-reputation-based filtering — detection must look at redirect chains and post-click behavior, not just the initial sender or link domain.

Threat actor generates 1 million personalized fraud emails in three days

  • Source: Dark Reading
  • Link: Dark Reading
  • Date: 2026-09-11
  • What happened: Cybercriminals behind malicious email campaigns are using AI to produce high-volume, personalized fraud email without sacrificing credibility.
  • Why it matters: Volume and personalization are no longer a tradeoff, so awareness training and mail filtering tuned to "obvious" mass phishing will miss these campaigns — users must be trained to verify through out-of-band channels.

5. Product Updates & Vendor News

PaperCut replaces emergency patches with regular maintenance releases

  • Source: The Hacker News
  • Link: The Hacker News
  • Date: 2026-09-11
  • What happened: PaperCut released maintenance releases (NG/MF versions 26.0.5, 25.0.13, 24.1.10) that replace all previously published emergency patches for two actively exploited flaws.
  • Why it matters: Organizations that applied interim emergency patches should plan a move to the maintained release line rather than leaving one-off fixes in place.

cPanel patches flaw letting a mail-privileged hosting account run code as root

  • Source: The Hacker News
  • Link: The Hacker News
  • Date: 2026-09-09
  • What happened: cPanel patched a flaw in which an authenticated account holder with mail-related privileges can create files via EmailTrack and run code as root; all supported cPanel and WHM versions are affected.
  • Why it matters: Privilege escalation from a low-privilege tenant to root is a control-plane takeover — hosting providers should patch immediately and review for unauthorized accounts and files.

Alby Hub critical flaw could let attackers take over internet-exposed wallets

  • Source: The Hacker News
  • Link: The Hacker News
  • Date: 2026-09-09
  • What happened: Alby warned of a critical flaw in self-hosted Alby Hub (versions v1.7.0 onward) that could let an attacker take over a wallet and send its funds where the hub was reachable from the internet.
  • Why it matters: Self-hosted, internet-exposed services holding high-value secrets remain a recurring exposure pattern — remove them from public reach and treat local admin access as the security boundary.

N-able N-central pre-auth RCE added to CISA's KEV catalog

  • Source: The Hacker News
  • Link: The Hacker News
  • Date: 2026-09-09
  • What happened: CISA added CVE-2026-86218 (CVSS 10.0), a pre-authentication remote code execution flaw in N-able N-central, to the KEV catalog with a September 11, 2026 patch deadline for federal agencies.
  • Why it matters: RMM platforms are effectively privileged identity infrastructure across managed estates — exploitation gives attackers the same access your administrators have, so patch verification and session auditing are essential.

Microsoft fixes Teams and Outlook launch failures on ARM Windows PCs

  • Source: BleepingComputer
  • Link: BleepingComputer
  • Date: 2026-09-11
  • What happened: Microsoft fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after updates released since the August 2026 Patch Tuesday.
  • Why it matters: Productivity and access clients failing post-patch can push users toward unsupported workarounds — validate client functionality as part of patch rollouts.

6. Practical Security Takeaways

  • Prioritize patching internet-facing and identity-adjacent systems first — VPN gateways (Check Point), firewall management (Cisco FMC), code and artifact repositories (GitLab, Artifactory), and RMM (N-able) all saw exploitation within hours to days of disclosure.
  • Enforce phishing-resistant MFA everywhere, and specifically train users to be suspicious of passkey- and SSO-themed prompts and enrollment requests.
  • Harden help-desk identity verification: the M365 campaigns relied on vishing to steal session tokens, so add verification steps that cannot be satisfied with information available to an attacker.
  • Detect and block adversary-in-the-middle token theft by monitoring for token replay, anomalous session reuse, and sign-ins from residential proxy infrastructure.
  • Inventory and rotate default, example, and hardcoded credentials on AI gateways and internal services — "sk-1234" on exposed LiteLLM servers is a live example.
  • Hunt for harvested API keys and session tokens in infostealer logs for your AI and cloud providers; shorten token lifetimes, scope them narrowly, and rotate on any endpoint compromise.
  • Audit non-human and agent identities — delegated workflow identities, service accounts, and agent execution privileges — and validate that agent sandboxes cannot be disabled by the agent itself.
  • Restrict credentials from unmanaged personal devices: device-bound credentials and conditional access that requires compliant devices would have limited the Florida DMV exposure.
  • Review FreeIPA/389 Directory Server permissions and audit directory objects for unexpected Kerberos identities and administrator group membership.
  • Plan for mounting patch volume: as AI accelerates vulnerability discovery (see Microsoft's record 974-flaw release), invest in continuous exposure assessment and exploitability-based prioritization rather than CVSS-based triage alone.
  • Prepare for tighter reporting obligations: the EU Cyber Resilience Act's 24-hour serious-incident notification and CISA's push for transparent breach disclosure mean incident response timelines need to be rehearsed against regulatory clocks.

7. Trends to Watch

  • Agent and non-human identities will become a first-class IAM problem, requiring the same lifecycle, scoping, and rotation discipline as human accounts.
  • Autonomous multi-agent attack frameworks will keep compressing credential-harvesting timelines from days to hours, forcing faster detection and revocation.
  • The patch-to-exploit window for identity-adjacent, internet-facing infrastructure will stay short, making exposure management more valuable than raw vulnerability counts.
  • Identity-themed social engineering — fake passkeys, SSO prompts, and help-desk calls — will continue to bypass MFA that is not phishing-resistant and token-bound.
  • AI-assisted vulnerability discovery and regulation-driven disclosure deadlines will both increase pressure on security teams to prioritize, validate, and report faster.

Sources

More from News