Security News
AI-orchestrated PaperCut NG/MF campaign β 395 orgs, 440 instances across 48 countries β Russian-speaking threat actor used OpenAI Codex and DeepSeek to develop and deploy exploits for CVE-2026-81578 and CVE-2026-82078. WatchTowr honeypot: full RCE, in-memory payload, config restored in under 5 seconds post-patch. Emergency patching required for self-hosted PaperCut. (GreyNoise)
BlueMoon exploit kit: multiple China-aligned actors chaining Chrome and Windows zero-days β CVE-2026-85046 (V8 type confusion), CVE-2026-87491 (V8 sandbox escape), and CVE-2026-85880 (Windows kernel LPE) chained into a browser-based exploit kit. First seen with TA412/APT31 on 28 Aug; rapidly adopted by multiple Chinese state clusters. Both V8 bugs were patch-gap zero-days β patched in upstream Chromium but not yet in stable Chrome. Update all Chromium-based browsers immediately. (Proofpoint)
McKesson: ShinyHunters publish 6.4 million healthcare records after extortion β HIBP added the McKesson breach this week. ShinyHunters "pay or leak" model: demand unmet, data published. Healthcare identity data at this scale is high-value for insurance fraud and prescription abuse.
Revolut breach via fake government legal demands β Attackers submitted fraudulent law enforcement requests to obtain customer data. Technical controls bypassed entirely through procedural trust. All organisations handling legal requests should implement independent callback verification. (TechCrunch)
Infostealers now systematically targeting AI agent credential stores β CallbackBeaver added Claude and Cursor; 5,000+ samples in 30 days. On macOS, Djinn Stealer collects from Claude, Codex, Gemini, Cline, OpenCode, and Kilo. A new stealer adds AI agent collection scope almost daily. Treat AI agent credential stores as equivalent to SSH keys. (Gen Digital)
Rockwell PLC web interface access at POWERGRID India (Ranchi) listed for sale β Live ICS access openly sold on criminal marketplace. No OT management interface should be internet-exposed. Enumerate via Shodan and enforce IT/OT segmentation.
CISA KEV: 4 added 11 Sep β ConnectWise ScreenConnect, JFrog Artifactory (Γ2), GitLab CE/EE β ConnectWise: improper privilege management and missing authorisation. JFrog Artifactory: incorrect authorisation and improper authentication. GitLab: path traversal. All four confirmed exploited in the wild. (CISA)
Cisco Secure Firewall Management Center: active exploitation of CVE-2026-20079 and CVE-2026-20316 β Authentication bypass granting root access (CVE-2026-20079) and low-privilege account bypass (CVE-2026-20316). Cisco Talos actively tracking. Patch or network-isolate FMC instances immediately. (Cisco Talos)
Dario Amodei (Anthropic) calls for coordinated global AI slowdown β 3,800-word essay follows similar signals from OpenAI's Altman. Two leading lab CEOs expressing this position simultaneously is unusual. (Slashdot)
Ransomware β week ending 13 Sep 2026
31 confirmed victims across 15 groups in the 48h daily briefing window.
Krybit β 12 victims in a single burst across 8 countries β UAE, Kenya, South Africa, Mexico, Morocco, Georgia, France, Canada, Haiti, India. Sectors: healthcare, transport, government, manufacturing, professional services. Volume bursts typically indicate delayed posting from a bulk access campaign or marketplace acquisition.
direwolf β Port of Tanjung Pelepas (Malaysia) β οΈ CNI/Transport β Major regional container port. Transport and port CNI listings warrant elevated attention for logistics chain impact.
Panzer β Agencia Estatal de MeteorologΓa AEMET (Spain) β οΈ Gov & Defence β Spanish national meteorological agency.
Qilin β Imperial Healthcare Solutions (US) β οΈ Healthcare β Continued focus on US healthcare targets.
NCSC CTO Weekly Deep Dive β week ending 13 Sep 2026
Ollie Whitehouse, NCSC CTO, published his weekly Substack on Saturday 12 September. The headline research finding this week should recalibrate defender prioritisation: full summary here
Only 1.48% of all published CVEs have ever been exploited in the wild. Root Evidence analysed 253,912 CVEs and 3,769 confirmed exploited vulnerabilities. Of those, only 711 CVEs (0.28%) were exploited before a patch existed. AI is filling the CVE catalogue at record speed; adversaries are still working the same narrow slice they always have. A prioritised patch programme focused on CISA KEV and actively exploited CVEs covers the vast majority of real-world risk.
Whitehouse flags the PaperCut AI-orchestrated campaign as the operationally significant story of the week β and specifically that it was detected by existing tradecraft despite novel AI-powered attack development. That's an important data point for defenders worried about AI obsoleting current detection approaches.
APT28 (Russian GRU) weaponised CVE-2026-21509, a Microsoft Office OLE security feature bypass, within 24 hours of public disclosure β targeting European defence and government entities. Trellix also detailed a separate DarkSword iOS spear-phishing campaign impersonating the Atlantic Council president against NATO-aligned officials.
CERT Poland confirmed active exploitation of MikroTrick β a two-vulnerability chain in MikroTik RouterOS allowing full unauthenticated takeover via SSH. A working proof of concept is now public. Update MikroTik devices immediately if SSH is internet-exposed.
Anthropic disclosed alignment incidents from cybersecurity evaluations where Claude, due to misconfiguration, took real-world actions it believed were simulated. Whitehouse contextualises this alongside the broader AI agent security picture β infostealers targeting agent credential stores, AI-assisted malware development (Chinese Robobox C2 framework), and the RUSI assessment that AI lowers criminal barriers less than commonly claimed.
Korea has raised data breach fines to 10% of total revenue for leaks of 10M+ records through gross negligence, effective this week β a significant change to the regulatory risk calculus for large data holders.
Whitehouse's closing reflection: unbiased science, empirical evidence, and assessment discipline are key to navigating a noisy AI era. The finding that adversary exploitation hasn't expanded despite a dramatic CVE volume increase is exactly the kind of signal that should temper hyperbolic threat assessments.