September 2026 in review
Across the tracker, 7 claims carry no disclosure date and are counted in no month.
Prior-month comparison withheld until this month is complete.
- vulnerabilities12 sources
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Microsoft released security updates on September 8, 2026 addressing 966 vulnerabilities, including two zero-day flaws that are actively exploited. This marks a record volume of flaws addressed in a single Patch Tuesday cycle.
Why it matters: Organizations running Microsoft products must prioritize patching these updates immediately, particularly the two actively exploited zero-days, to prevent ongoing attacks.
Grouped: similar headlines.
- vulnerabilities8 sources
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
SonicWall disclosed two zero-day vulnerabilities in SMA1000 devices that can be chained together to achieve unauthenticated remote code execution (RCE). CVE-2026-83549 and CVE-2026-83548 are reportedly being exploited in active attacks.
Why it matters: Organizations running SonicWall SMA1000 appliances face immediate risk of compromise without authentication; patch or disable affected devices now.
Grouped: similar headlines.
- ransomware6 sources
Conti ransomware crew member sentenced to four years in prison
A Ukrainian national pleaded guilty to conspiracy and wire fraud for his role as a malware developer and intruder within the Conti ransomware group, which victimized over 1,000 organizations before disbanding in 2022. Oleksii Oleksiyovych Lytvynenko was sentenced to four years in prison on September 10, 2026, after being arrested in Ireland in July 2023 and extradited to the United States in October 2025. He participated in attacks that extracted approximately $634,000 in Bitcoin and compromised multiple critical infrastructure assets, including law enforcement and emergency services in Tennessee.
Why it matters: Organizations and government entities already attacked by Conti should monitor for ongoing extortion attempts from successor groups like BlackSuit, as Lytvynenko continued ransomware operations after Conti disbanded; practitioners should review whether their organization was among the 1,000+ victims and assess residual access risks.
Grouped: similar headlines.
- ai security5 sources
Feds accuse China of ‘systematic’ distillation of U.S. AI models
U.S. federal agencies, including the National Security Agency, Cybersecurity and Infrastructure Security Agency, and Federal Bureau of Investigation, have released a joint advisory accusing Chinese artificial intelligence (AI) companies of conducting systematic, industrial-scale distillation of U.S. frontier AI models since late 2024. Named targets include DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, which the agencies say have spent billions of tokens querying models from Anthropic, OpenAI, Google, and xAI to extract proprietary capabilities and train competing systems. The Chinese firms employ sophisticated evasion tactics, including distributed requests across accounts and platforms, proxies, and third-party aggregators to avoid detection and circumvent usage safeguards.
Why it matters: U.S. AI vendors and cloud providers must implement detection systems and usage monitoring to identify large-scale distillation campaigns, and coordinate with government and international partners to defend model intellectual property and capabilities from extraction at industrial scale.
Grouped: similar headlines.
- vulnerabilities4 sources
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
Cisco confirmed that CVE-2026-20079, a maximum-severity authentication bypass vulnerability in Secure Firewall Management Center (FMC), is being actively exploited in attacks. The flaw carries a CVSS score of 10.0 and has been added to the known exploited vulnerabilities list.
Why it matters: Organizations running Cisco Secure FMC must prioritize patching immediately, as this critical authentication bypass is under active attack and poses direct risk to firewall management infrastructure.
Grouped: the same Common Vulnerabilities and Exposures (CVE) record (CVE-2026-20079) and the same name (SECURE FIREWALL MANAGEMENT CENTER).
- threat intel4 sources
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
A previously undocumented exploit kit named BlueMoon chains multiple vulnerabilities in Microsoft Windows and Google Chrome and has been deployed by multiple state-sponsored espionage groups. The first in-the-wild use was attributed to APT31, a China-aligned group.
Why it matters: Organizations face active exploitation of Windows and Chrome by state-sponsored adversaries using a new multi-vulnerability attack chain; practitioners should prioritize patching for both platforms and monitor for BlueMoon indicators of compromise (IOCs).
Grouped: the same names (GOOGLE CHROME, MICROSOFT WINDOWS).
- breaches incidents4 sources
Russian suspect in bank account takeovers is extradited to US
A Russian web developer implicated in a scheme that compromised multiple bank accounts was extradited to the United States to stand trial. The individual faces charges related to the large-scale financial fraud operation.
Why it matters: Financial institutions and their customers should monitor for account takeover tactics and review incident response procedures, as organized cybercriminals continue targeting banking systems across borders.
Grouped: similar headlines.
- threat intel4 sources
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
A phishing-as-a-service framework called BigBear 2.0 targeted 258 organizations to bypass multifactor authentication (MFA) and harvest more than 5,000 Microsoft 365 credentials. The campaign demonstrates the continued risk of credential theft despite MFA deployment.
Why it matters: Security teams managing Microsoft 365 should review authentication logs and phishing detection rules, as this attack bypassed MFA and affected hundreds of organizations across multiple sectors.
Grouped: similar headlines.
- breaches incidents4 sources
Mathspace discloses data breach affecting over 1 million people
Mathspace, an online mathematics learning platform, disclosed a data breach affecting over 1 million students, staff, and parents. Attackers compromised the company's Metabase internal reporting system to access the data.
Why it matters: Schools and families using Mathspace face potential identity theft and privacy exposure; security teams should determine if their organizations are affected and notify users if required by regulation.
Grouped: similar headlines.
- vulnerabilities4 sources
Hackers exploit new MikroTik RouterOS flaws to hijack routers
Threat actors are exploiting a pair of recently disclosed vulnerabilities in MikroTik RouterOS to gain control of routers that expose SSH services to the internet. The attack chain leverages the flaws to achieve unauthorized access to affected devices.
Why it matters: Organizations operating MikroTik routers with internet-exposed SSH are at immediate risk of compromise and should apply patches or disable external access now.
Grouped: similar headlines.
- CVE-2026-19490Citrix NetScalerfederal fix deadline
- CVE-2026-85880Microsoft Windowsfederal fix deadline
- CVE-2026-81963Microsoft Windowsfederal fix deadline
- CVE-2026-20079Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Managementfederal fix deadline
- CVE-2026-83548SonicWall SMA1000 Appliancesfederal fix deadline
- CVE-2026-82329JFrog Artifactoryfederal fix deadline
- CVE-2026-75650Adobe Commerce and Magentofederal fix deadline
- CVE-2026-49869Kestra Kestra OSSfederal fix deadline
- CVE-2026-9586Sangoma Switchvoxfederal fix deadline
- CVE-2026-83549SonicWall SMA1000 Appliancesfederal fix deadline
- CVE-2026-85706GitLab Community Edition and Enterprise Editionfederal fix deadline
- CVE-2026-85046Google Chromium V8federal fix deadline
- CVE-2026-86218N-able N-centralfederal fix deadline
- CVE-2025-25249Fortinet Multiple Productsfederal fix deadline
- CVE-2026-48710Kludex Starlettefederal fix deadline
- CVE-2026-86060MikroTik RouterOSfederal fix deadline
- CVE-2026-84869ConnectWise ScreenConnectfederal fix deadline
- CVE-2026-87491Google Chromium V8federal fix deadline
- CVE-2026-67277MikroTik RouterOSfederal fix deadline
- CVE-2026-59822BerriAI LiteLLMfederal fix deadline
- CVE-2026-42018JFrog Artifactoryfederal fix deadline
- CVE-2026-42016JFrog Artifactoryfederal fix deadline
| KryBit | 27 claims |
| The Gentlemen | 25 claims |
| Qilin | 19 claims |
| Direwolf | 17 claims |
| Akira | 15 claims |
| INC Ransom | 12 claims |
| Storm | 12 claims |
| Vexy Ransomware | 11 claims |
| Safepay | 11 claims |
| Auditteam | 10 claims |
Leak-site claim data is unverified: RansomLook (CC BY 4.0).