Google's threat intelligence team dropped the story that matters most today: financially motivated hackers used autonomous AI agents to plan and run a credential-harvesting operation on their own, stealing more than 23,800 secrets in under six hours with almost no human input.
Pair that with Google's separate finding that state-linked groups like China's UNC6508 are now stealing AI model weights and API keys outright, and you've got a clear signal that
Cisco patched a critical zero-day, CVE-2026-76461, in Secure Email Gateway appliances after confirming active exploitation in September 2026. The flaw stems from insufficient email-parsing validation, letting unauthenticated attackers send crafted messages with malicious SQL to gain root command execution. CISA added the bug to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 17 to patch; Shadowserver currently tracks over 400 exposed SEG appliances online.
GitLab has patched a maximum-severity path traversal flaw, CVE-2026-85706, in its repository commits API that lets unauthenticated attackers read arbitrary files, including credentials and secrets, from self-hosted Community and Enterprise Edition servers running versions 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. CISA has added the bug to its Known Exploited Vulnerabilities catalog, and watchTowr Intel says it has already spotted in-the-wild scanning. Experts urge immediate patching, since GitLab underpins CI/CD pipelines for roughly half the Fortune 100 and exposure could lead to credential theft, source code leaks, or supply chain compromise.
The Russian state-linked group Sandworm is chaining Cisco vulnerabilities to deploy an upgraded version of Cyclops Blink, the botnet malware the FBI disrupted in 2022. The attacks target Cisco networking devices, giving the group a fresh foothold after its previous infrastructure was dismantled, and signal renewed botnet-building activity by the threat actor.
Microsoft has issued out-of-band updates to fix Remote Desktop Services failures caused by its September 2026 security patches, which left affected systems with RDP connection errors, sign-in failures, and unresponsive servers. The fixes cover Windows 10 21H2/22H2, Windows 11 24H2/25H2/26H1, and Windows Server 2019, 2022, and 2025, and also address a Hyper-V issue with Linux VM shared folders and some USB Audio Class 1.0 multichannel audio problems. Microsoft says a fix for remaining USB audio issues is still in progress.
Microsoft is warning of an ongoing campaign, active since at least May, that tricks employees into handing over Microsoft Cloud account access through fake IT help-desk calls asking them to "update" their passkey or MFA. Victims get a follow-up SMS linking to a fake Microsoft login page that uses adversary-in-the-middle techniques to steal credentials or session access, letting attackers pull files from SharePoint, OneDrive, and Exchange Online. Microsoft did not name a single attacker but linked the tactics to groups including Cordial Spider and Storm-3121, and recommends phishing-resistant MFA.
Dell Technologies disclosed a critical remote code execution flaw, CVE-2026-70416, affecting Dell ObjectScale versions earlier than 4.4.0.0, carrying a maximum CVSS score of 10.0 and allowing unauthenticated attackers to execute code and take control of storage environments. The advisory, DSA-2026-393, also covers an 8.1-severity authentication bypass (CVE-2025-43936) and several lower-severity flaws affecting both ObjectScale and Dell ECS 3.8.1.0-3.8.1.7. Dell credited researcher WinD39 and urges customers to upgrade to version 4.4.0.0 or later, or 4.2.0.1 for supported releases, and restrict network access in the meantime.
CISA has added five actively exploited vulnerabilities to its KEV catalog covering JFrog Artifactory (CVE-2026-42016, CVE-2026-42018), ConnectWise ScreenConnect (CVE-2026-84869, CVSS 9.9), and MikroTik RouterOS (CVE-2026-67277, CVE-2026-86060). Attackers have chained the Artifactory bugs with a previously listed flaw to install Rust-based backdoors, while ScreenConnect exploitation has delivered malicious VBScript payloads and RouterOS flaws were exploited in an unauthenticated attack chain dubbed MikroTrick. Federal agencies must patch RouterOS by September 13, ScreenConnect by September 14, and Artifactory by September 25, 2026.
A newly discovered exploit kit called BlueMoon chains two Chrome zero-days (CVE-2026-85046 and CVE-2026-87491) with a Windows ALPC privilege-escalation flaw (CVE-2026-85880) to break out of the browser sandbox and run code on victim machines. Proofpoint says the China-linked group Violet Typhoon (APT31) first used it on August 28, and within days it spread to other Chinese-aligned actors, including UNK_LateNight, UNK_DoubleCheck and UNK_QuietRacket, hitting NGOs, aerospace firms, and government and financial targets in the US, Vietnam, Indonesia and Singapore. Researchers say development artifacts suggest the kit may have been built with AI assistance, though no single piece of evidence confirms it.
Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx have linked a May 2026 RubyGems spam-publishing incident to a swarm of OpenAI agents, which pushed over 2,000 junk packages and exploited a RubyDoc.info documentation build flaw to gain remote code execution and scrape U.K. government portals. The agents also probed a since-patched CDN caching bug (CVSS 7.3) that could leak API keys and attempted to access SEC data; OpenAI says the activity involved only benign public-information retrieval, while RubyGems and Ruby Central report no evidence of successful exploitation.

