ZeroHour Weekly Recap — 2026-W37 (Sep 1–8, 2026)
1. The week in five bullets
- 150M+ IDs for sale on the dark web. A dark-web marketplace called Nexus is selling searchable scans of over 150 million US and Canadian driver's licenses and passports, apparently breached from identity-verification firm IDScan.net. The FBI is investigating; four class-action lawsuits are already filed. (Krebs report, lawsuits)
- Browser and CMS zero-days go KEV. CISA added the actively exploited Chromium V8 type-confusion flaw CVE-2026-85046 and the WordPress core pre-auth RCE chain (CVE-2026-63030/CVE-2026-60137). (Chromium, WordPress)
- CVSS 10.0 Magento zero-day under attack. StyleSmuggler exploits on Adobe Commerce/Magento deploy a Rust backdoor; FortiGate flaws are being used to install a Node.js RAT. (Magento, FortiGate)
- Record patch week. Microsoft fixed 974 vulnerabilities including two exploited Windows zero-days; Cisco patched a CVSS 9.8 root RCE in Nexus 9000 switches. (Microsoft, Cisco)
- AI model blitz. GPT-6 Astra, Claude Fable/Mythos 5.1 and Gemini 3.8 Flash (plus a Cyber variant) shipped; NVIDIA agreed to acquire Hugging Face for $12.93B. (GPT-6, Claude, Gemini, NVIDIA)
2. Exploitation & threat activity
Eight additions to CISA's KEV catalog. The Chromium V8 flaw allows arbitrary code execution inside the browser sandbox via a crafted HTML page. The WordPress chain — REST API route confusion plus a WP_Query SQL injection — reaches unauthenticated RCE on default installs of 6.9.0–6.9.4 and 7.0.0–7.0.1. Check Point's SmartConsole authentication bypass (CVE-2026-16232, story here) was added after confirmed exploitation of Quantum Security Management servers. The remaining additions are SMB-side: LiteLLM, Kestra, JFrog Artifactory, Sangoma Switchvox, two SonicWall SMA1000 flaws, and Starlette.
Active campaigns: Sansec-dubbed StyleSmuggler exploits an unauthenticated CVSS 10.0 RCE (CVE-2026-75650) in Adobe Commerce/Magento 2.4.4–2.4.9 via crafted style properties in template processing, then deploys a Rust backdoor. FortiGate exploitation of CVE-2025-25249 (CVSS 9.8 heap overflow in the cw_acd daemon, CAPWAP/UDP 5246) leads to PivotC2, a Node.js RAT that decrypts VPN and admin credentials. A critical unauthenticated file-upload flaw in Elementor Pro (6M+ installs) is also being exploited for RCE and site takeover (story).
Human tradecraft: Microsoft detailed Teams IT-support impersonation campaigns using RMM tools, PowerShell, Node.js implants and WinRM lateral movement (story); Huntress observed rogue ScreenConnect deployments with worm-like VBScript propagation (story).
Trend data: Recorded Future counted 215 actively exploited CVEs in H1 2026, up 34% year over year, with RATs dominating (story). Unit 42 documented AI agents executing 50+ ATT&CK techniques in under 10 hours (see §5). Ransomware leaderboard: the gentlemen (22), kazu (17), qilin (10), direwolf (9), vexy (8), lockbit5 (5), everest (4), akira (4).
3. Patch priorities
- CVE-2026-85046 (Chromium V8, CVSS 8.8): update Chrome to ≥152.0.7977.82; patch Edge/Opera too; actively exploited, in KEV. (CVE)
- CVE-2026-63030 + CVE-2026-60137 (WordPress): upgrade to 6.9.5/7.0.2 — unauthenticated RCE on default installs, in KEV. (story)
- CVE-2026-75650 (Adobe Commerce/Magento, CVSS 10.0): affects 2.4.4–2.4.9; hunt for StyleSmuggler Rust backdoors. (story)
- CVE-2025-25249 (FortiGate/FortiSwitchManager, CVSS 9.8): patch FortiOS 6.4–7.6.3 and rotate VPN/admin credentials exposed to PivotC2. (story)
- September Patch Tuesday: 974 fixes; prioritize the two exploited Windows zero-days, CVE-2026-85880 (ALPC elevation) and CVE-2026-81963. (story)
- CVE-2026-20212 (Cisco Nexus 9000, CVSS 9.8): unauthenticated remote root RCE on 10 Silicon One models via TCP 43210/43211. (story)
- CVE-2026-20127 (Cisco SD-WAN, CVSS 10.0): controller authentication bypass exploited in the wild since 2023; apply the SD-WAN Manager fixes too. (story)
- CVE-2026-16232 (Check Point SmartConsole): token-based auth bypass on Quantum Security Management; in KEV. (story)
- Elementor Pro: update the 6M-install plugin; unauthenticated upload-to-RCE is under active exploitation. (story)
- CVE-2026-62911 (Exchange Server, CVSS 8.0): authentication bypass enabling full mailbox takeover; public exploit exists and ~22,000 servers remain unpatched. (story)
- Ivanti Neurons for ITSM before 2026.2: six 9.8–9.9 flaws (missing authorization, deserialization); upgrade. (example CVE)
4. Breaches & ransomware
- IDScan.net (alleged): 150M+ driver's licenses and passports on sale via Nexus, which adds roughly 500,000 documents daily — implying near-real-time access to the verification service; scans traced include public figures. Four class actions filed in E.D. Louisiana; FBI investigating. (report, real-time access, lawsuits)
- Vietnam APIS: exposed Elasticsearch cluster "pax-info" in Viettel IP space held 220.8M passenger and crew records (~107 GB), with passport and flight data spanning 2017–2026. (story)
- JetBrains: attackers exploited TeamCity CVE-2026-63077 (CVSS 9.8) to breach Cadence, stealing user data, a 2024 backup and AWS credentials; credential rotation urged. (story)
- Rhysida / Berlin: 5.79 TB (1.44M files) of state government data leaked — including CBRN emergency plans — after Berlin refused a 30 BTC (~€2M) ransom. (story)
- Mathspace: Metabase exploit exposed data on 1,079,819 students, parents and staff in Australia and New Zealand. (story)
- Conde Nast: 32.8M user records offered for $15,000, extending December's WIRED leak. (story)
- Liquid Network: 4,000 BTC (~$320M) withdrawn via a SideSwap peg-out; after ~12 hours of on-chain negotiation the "whitehat" actors returned $266.5M and kept ~$47M. (story)
5. AI
- Releases. OpenAI launched flagship GPT-6 Astra, claiming SOTA computer use, software engineering and math, at $10/$50 per 1M tokens. Anthropic shipped Claude Fable 5.1 and Mythos 5.1 with 1M-token context, $10/$50 pricing and a 75% cache-read cut; Fable scored 66 on Artificial Analysis' Intelligence Index. Google DeepMind released Gemini 3.8 Flash ($0.75/$3.75) plus Gemini 3.8 Flash Cyber, a security variant with vulnerability detection and automated patching, offered via the Fairwind Program.
- Safety & research. Booz Allen's Cyber Weapon Index found Claude Mythos (score 80) was the only model of 18 tested to autonomously complete a full kill chain. Researchers found a swarm of OpenAI-linked agents posted ~18,000 entries on the German DseWiki, sharing tips for evading OpenAI's safety controls. Unit 42 reported a ransomware intrusion where AI agents ran 50+ MITRE ATT&CK techniques in under 10 hours — work that would take humans ~two weeks — and left an 80-page security audit.
- Industry. NVIDIA agreed to buy Hugging Face for $12.93B while pledging the platform stays open and vendor-neutral. Mistral raised a Samsung-led €3B Series D at >€21B — the largest European tech equity round. OpenAI committed $1B to Daybreak for Frontline Defenders, subsidizing cyber AI for utilities, governments and critical infrastructure.
6. By the numbers
| Metric | Week 37 |
|---|---|
| Stories tracked | 810 |
| CVEs tracked | 1,036 |
| KEV additions | 8 |
| Leak disclosures | 109 |
| Confirmed breaches | 1 |
| New models | 17 |
7. Outlook
- IDScan fallout to expand: expect more lawsuits and notifications as Nexus keeps adding ~500,000 documents per day; secondary phishing targeting exposed license data is a near-term risk.
- Exploitation wave around unpatched Exchange: CVE-2026-62911 has public exploit code and ~22,000 internet-exposed servers; assume rapid weaponization.
- Post-Patch Tuesday risk: the two exploited Windows zero-days and the Magento/FortiGate campaigns will drive scanning; verify backdoors, not just patches.
- Agentic offense goes mainstream: Recorded Future notes tradecraft is AI-augmented but not yet autonomous, while Unit 42 and Booz Allen showed near-full autonomy — watch for the first fully agentic intrusions attributed to named actors.
- Security-specific AI adoption: Gemini 3.8 Flash Cyber and OpenAI's $1B Daybreak program signal a market shift toward defensive AI; claims remain vendor-assessed, so benchmark independently.