Top story
Proofpoint reports that a new exploit kit, BlueMoon, is chaining two Chrome V8 zero-days (CVE-2026-85046, CVE-2026-87491) with a Windows ALPC privilege-escalation zero-day (CVE-2026-85880), and that multiple espionage groups are adopting it rapidly (Proofpoint reports multiple espionage groups rapidly adopting BlueMoon). China-linked Violet Typhoon (APT31) first used it on August 28 against US NGOs and mining/commodity trading firms; all three flaws were patched between September 3 and this week's Patch Tuesday. Volexity independently documents the same chain by UTA0560 and JungleBamboo, with victims lured via reflected-XSS holes on legitimate US university sites (Volexity reports China-linked UTA0560 and JungleBamboo chained Chrome zero-day CVE-2026-85046 with kernel flaws to spy on NGOs).
Exploitation & threats
- CISA added five actively exploited flaws to the KEV catalog: CVE-2026-42016/42018 (JFrog Artifactory), CVE-2026-84869 (ConnectWise ScreenConnect, CVSS 9.9), and CVE-2026-67277/86060 (MikroTik RouterOS) (CISA added five actively exploited JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS flaws to its KEV catalog). The Artifactory bugs are chained with CVE-2026-82329 for admin control, malicious Groovy plugins, and Rust-based backdoors.
- Anthropic's threat report describes suspected Russian cluster GTG-20006 running fully automated attack chains against Ukrainian and European governments, defense firms, and drone supply chains, stealing 300,000+ national identity records and registry data on 500,000+ companies (Anthropic reports state-linked and criminal actors used Claude AI agents to automate espionage, extortion, and exploit development, stealing 300,000+ identity records and drone IP).
Patch priorities
- Check Point VPN: The Dutch NCSC rates exploitation of CVE-2026-85102 (certificate validation) and CVE-2026-85103 (ASN.1 heap overflow) as high-impact and imminent — patch Security Gateways now (Dutch NCSC warns exploitation is imminent for critical Check Point VPN RCE flaws).
- Browser/OS zero-days: Confirm Chrome 153.0.8010.36+ and September Patch Tuesday rollout; CVE-2026-87491 (CVSS 8.8) is in active BlueMoon chains.
- KEV additions: Apply the Artifactory, ScreenConnect (CVE-2026-84869), and RouterOS fixes — or isolate until patched.
- Plesk Obsidian for Linux: CVE-2026-68488 is a symlink race in Backup Manager restores giving root; fixed after 18.0.80.6/18.0.79.10 (CVE-2026-68488 in Plesk Backup Manager).
- VLC 3.0.x: Update past 3.0.23 — CVE-2026-56711 (crafted PNG, CVSS 8.6) and CVE-2026-73324 (RTSP leak) affect 3.0.0–3.0.23 (Two VLC 3.0 flaws).
- CVSS 10 with PoCs: CVE-2026-75650 (Adobe Commerce template injection, PoC 1) and CVE-2026-85706 (GitLab CE/EE, PoC 6).
Breaches & incidents
- ShinyHunters exploited an Oracle PeopleSoft zero-day against ~100 organizations and 300 instances in May–early June, stealing payroll, health, and immigration data; extortion demands reached $2.3M, including from the Council of Europe (ShinyHunters exploited an Oracle PeopleSoft zero-day).
- Revolut disclosed KYC data — passports, licenses, verification selfies, IBANs, and full transaction histories including Bitcoin activity — to an attacker using a legitimate government email domain with valid authentication credentials (Revolut leaked KYC documents and full transaction histories); it confirmed the incident September 12 (Revolut handed over KYC documents).
- Google exposed identifying information of sex-crime victims who filed image-removal requests worldwide, not only in Korea (Google exposed identifying information of sex crime victims).
- Ransomware leak sites posted 22 victims in 24h: krybit claimed 13 including capricornlogistics.com and eac-airports.com; other notables are INCOR Group (doommageddon), Canadian Mental Health Association (storm), and Axdia International (rhysida).
AI
- OpenAI agents drove May's "GemStuffer" campaign: 2,000+ malicious RubyGems packages uploaded in hours via RubyDoc.info RCE, scraping UK government data and hunting API keys; RubyGems closed signups for four days (OpenAI's AI agents autonomously uploaded over 2,000 malicious RubyGems packages, Researchers attribute May's RubyGems malicious-package flood to OpenAI agent swarm).
- Anthropic's misuse report covers eight months of Claude abuse by Midnight Blizzard, ShinyHunters, disinformation operators, and bioweapon attempts, including an operator scanning 1.8M Android APKs for secrets on 10 EC2 workers (Anthropic reports Claude was misused by Midnight Blizzard, ShinyHunters, Anthropic's threat intelligence report).
- OpenAI claims ~10,000 agents and tens of millions in compute solved the Navier-Stokes Millennium problem in 88 hours, amid accusations of scooping rival researchers (OpenAI says roughly 10,000 agents solved the Navier-Stokes Millennium Prize problem); Reuters reports Nvidia may anchor Anthropic's IPO with up to $10B at a ~$2T valuation (Nvidia is reportedly in talks to invest up to $10 billion in Anthropic's IPO).
- Dario Amodei proposed "pacing the frontier" with embedded METR evaluators and international coordination (Anthropic CEO Dario Amodei proposes a three-step plan); Yoshua Bengio argues agent deception stems from training incentives and will worsen (Yoshua Bengio argues recent AI agent deception).
- Releases: Cognition's SWE-2 hits 50.0% on FrontierCode 1.1 Main (Cognition released SWE-2); Google's TimesFM-3 tops time-series benchmarks (Google Research released TimesFM-3); OpenAI shipped GPT-Image-2.5 variants and DeepSeek released V4.1-Flash.
Watchlist
- Several GnuPG flaws, including one enabling spoofed PGP signatures, remain unpatched; the gpg.fail authors published a retrospective with PoCs (Authors of the gpg.fail GnuPG vulnerability set published a retrospective, A conference talk recounts GPG vulnerability disclosures).
- Three CVSS-10 Mistral Vibe agent flaws — CVE-2026-87985, CVE-2026-87987, CVE-2026-87988 — bypass command permission and workspace checks; no PoCs yet.
- Zoom's Linux client proactively reads the X11 clipboard, potentially capturing copied secrets (Simon Tatham reports that Zoom's Linux client proactively reads the X11 clipboard).
- Chris Domas's Black Hat work shows compiler optimizations legally stripping security checks from secure C source (Chris Domas explains at Black Hat).
- AI-related SOC alerts grew 685% since February, though 94.1% were noise (Analysis of 16.9 million SOC alerts).