HomeCybersecurity NewsCybersecurity news weekly roundup September 14, 2026
September 14, 2026

Cybersecurity news weekly roundup September 14, 2026

San Mateo, CA, September 14, 2026 — Developments, threats, and responses in the news last week

STORIES LAST WEEK

Hundreds of AI agents compromise 440 PaperCut servers

GreyNoise traced a likely Russian-speaking actor using hundreds of AI agents to compromise 440 PaperCut instances at 395 organizations across 48 countries. Defenders now face machine-speed exploitation that can move from research to domain compromise within hours. GreyNoise, September 9, 2026

Attackers complete AI-assisted cloud credential campaign in under six hours

Google observed attackers using agentic AI to compromise cloud resources and complete a mass credential-harvesting operation in under six hours. The compressed timeline sharply reduces defenders’ response window and raises the priority of identity monitoring, automation controls, and rapid containment. Google Cloud, September 8, 2026

Four espionage groups rapidly adopt BlueMoon Chrome and Windows exploit chain

Proofpoint found four espionage groups using BlueMoon, which chains two Chromium flaws with a Windows kernel privilege escalation. Two browser bugs were patch-gap zero-days, showing how public upstream fixes can create exploitable windows before stable browser releases. Proofpoint, September 9, 2026

Microsoft patches record 972 vulnerabilities, including two exploited zero-days

Microsoft’s September release fixed roughly 972 vulnerabilities, 112 rated critical, including two exploited zero-days and numerous potentially wormable flaws. The volume makes prioritization essential, especially for internet-facing Windows, Remote Desktop, Exchange, SharePoint, and authentication systems. Ars Technica, September 8, 2026

Passkey lures lead to Microsoft 365 identity persistence and data theft

Microsoft observed fake IT support using passkey and SSO pretexts to capture sessions, add attacker-controlled authentication methods, enumerate Microsoft Graph, and collect SharePoint, OneDrive, and Exchange data. Identity teams should correlate sign-ins with authentication changes and cloud-access spikes. Microsoft, September 9, 2026

Cisco confirms active exploitation of critical Secure FMC authentication bypass

Cisco updated CVE-2026-20079 after confirming exploitation of the CVSS 10.0 flaw, which can give unauthenticated remote attackers root access to Secure Firewall Management Center. There is no workaround, and suspected compromises require recovery steps beyond installing the hotfix. Cisco, September 9, 2026

Attackers chain two RouterOS flaws to take over MikroTik routers

Attackers are chaining an SSH authentication bypass with a crafted-username privilege escalation to gain full control of exposed MikroTik routers. Administrators should patch promptly, restrict internet-facing management services, and rebuild devices from trusted configurations when compromise is suspected. BleepingComputer, September 7, 2026

Modified ScreenConnect clients show worm-like spread across remote sessions

Huntress found rogue ScreenConnect clients automatically transferring and executing a four-stage VBScript chain on newly connected endpoints. The behavior can propagate through remote-support sessions, making ScreenConnect audit logs, script execution, and affected-host reimaging immediate priorities. Huntress, September 9, 2026

Known Shai-Hulud npm worm payload bypasses publish-time malware scanning

Aikido found four npm packages carrying the exact Shai-Hulud payload seen 111 days earlier, despite npm’s newer publish-time malware scanning. The unchanged hash slipping through highlights the need for independent package screening and tighter controls around install-time execution. Aikido Security, September 7, 2026

SloppyRAT adds blockchain-based backup command and control to ransomware tooling

Zscaler detailed a new RAT delivered through ClickFix that uses encrypted code, certificate pinning, and Polygon smart-contract infrastructure for backup command-and-control resolution. Those features complicate TLS inspection and domain-focused disruption, while built-in commands support lateral movement. Zscaler, September 10, 2026

Phishing pages generated inside browsers evade static site blocking

A Barracuda-observed campaign uses trusted Microsoft services and blob URLs to build phishing pages inside victims’ browsers, leaving no static malicious site to block. Defenders need browser telemetry, OAuth monitoring, and full click-path inspection rather than URL reputation alone. SecurityWeek, September 9, 2026

Invisible Unicode characters hide phishing keywords from email filters

Attackers are inserting non-rendering Unicode tag characters inside finance-themed lure words, repurposing an AI prompt-injection technique to evade email filtering. Microsoft telemetry previously saw 2.37 million daily messages, making Unicode normalization an important control before content matching. BleepingComputer, September 6, 2026

Compromised maintainer system pushes XCSSET into Flutter package repository

Aikido found XCSSET malware inside a pub.dev Flutter package after an infected maintainer machine contaminated the release. The malicious files mainly threatened developers who cloned and built the example project, illustrating how endpoint infections can silently become supply-chain artifacts. Aikido Security, September 8, 2026

Lawmakers seek U.S. sanctions on three hack-for-hire firms

A bipartisan group asked the Commerce Department to add three Indian hack-for-hire companies to the Entity List over alleged attacks on Americans. A designation would restrict access to U.S. technology, creating compliance and supplier-screening implications for technology providers. TechCrunch, September 9, 2026

More cybersecurity news

About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles