CYBERSECURITYTRACKER
TRACKING7,283 stories in this site build1,521 vulnerability news stories in this site build
Permanent story citation

14th September - Threat Intelligence Report

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 7213

As cited

Copy frozen at (site build).

vulnerabilities

14th September - Threat Intelligence Report

Check Point Research published a threat intelligence summary covering major breaches, artificial intelligence (AI) security threats, and vulnerabilities from the week of September 14, 2026. Notable incidents included data exposures at IDScan.net, Mathspace (leveraging CVE-2026-72898 in Metabase), Revolut, and Florida's Department of Motor Vehicles, alongside attacks on ChatGPT and Claude sandbox environments. Microsoft released 974 patches in September 2026 Patch Tuesday addressing two actively exploited zero-days, while critical flaws emerged in GitLab and MikroTik RouterOS.

Why it matters: Security teams must patch Microsoft zero-days CVE-2026-85880 and CVE-2026-81963, apply GitLab CVE-2026-85706 and MikroTik fixes, and monitor for passkey-phishing attacks and Android banking fraud targeting user credentials and financial systems. Organizations using Metabase and ChatGPT should review their configurations for unauthorized access and implement controls to prevent AI model sandbox escapes.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

14th September – Threat Intelligence Report

Check Point Research published a threat intelligence summary covering major breaches, artificial intelligence (AI) security threats, and vulnerabilities from the week of September 14, 2026. Notable incidents included data exposures at IDScan.net, Mathspace (leveraging CVE-2026-72898 in Metabase), Revolut, and Florida's Department of Motor Vehicles, alongside attacks on ChatGPT and Claude sandbox environments. Microsoft released 974 patches in September 2026 Patch Tuesday addressing two actively exploited zero-days, while critical flaws emerged in GitLab and MikroTik RouterOS.

Why it matters: Security teams must patch Microsoft zero-days CVE-2026-85880 and CVE-2026-81963, apply GitLab CVE-2026-85706 and MikroTik fixes, and monitor for passkey-phishing attacks and Android banking fraud targeting user credentials and financial systems. Organizations using Metabase and ChatGPT should review their configurations for unauthorized access and implement controls to prevent AI model sandbox escapes.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary