ZeroHour Weekly Recap — 2026-W38 (Sep 7–14)
1. The week in five bullets
- IDScan.net confirmed a breach after the "Nexus" dark web service advertised 153M+ US and Canadian driver's licenses, allegedly siphoned continuously for over a year; the FBI is investigating and at least four class-actions are already filed in Louisiana (story, Krebs follow-up, lawsuits).
- Adobe Commerce/Magento zero-day CVE-2026-75650 ("StyleSmuggler", CVSS 10.0) was exploited from September 4 to plant a Rust backdoor and PHP web shells on e-commerce servers (Sansec, hotfix).
- Microsoft shipped a record Patch Tuesday — 974 CVEs (999 including non-Microsoft), with two exploited Windows privilege-escalation zero-days, CVE-2026-85880 (ALPC) and CVE-2026-81963 (Update Stack) (story, breakdown).
- A GitLab CVSS 10.0 path traversal (CVE-2026-85706) was probed in the wild within 24 hours of disclosure and added to CISA's KEV catalog (story).
- Proofpoint documented "BlueMoon," a new exploit kit chaining two Chrome V8 zero-days with Windows ALPC escalation, adopted by multiple espionage groups including APT31 (story).
2. Exploitation & threat activity
The dominant trend is speed and chaining. watchTowr saw in-the-wild probes of CVE-2026-85706 one day after disclosure; Wiz tracked attackers chaining CVE-2026-42018 and CVE-2026-42016 in self-hosted JFrog Artifactory (Aug 15–Sep 8) to create admin accounts and install a custom Rust backdoor (story). Rust payloads also appeared in the Magento campaign — a notable tooling shift.
BlueMoon chains CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880, all patched in early September; China-linked Violet Typhoon (APT31) was first observed using it, and Proofpoint reports rapid adoption by other espionage operators.
Elsewhere: SOCRadar assesses actors are exploiting CVE-2025-25249 in FortiGate firewalls to deploy PivotC2, a Node.js RAT that decrypts VPN and admin credentials (story). Cisco Talos tied three clusters — including Qilin ransomware and a Sandworm-overlapping group deploying Cyclops Blink — to exploitation of CVE-2026-20079 and CVE-2026-20316 in Secure Firewall Management Center (story). Hunt.io linked a UK council breach to mass exploitation of SonicWall SMA1000 CVE-2026-15409 with credential and Active Directory theft (story).
AI-powered offense matured: GreyNoise tracked a likely Russian-speaking actor using hundreds of AI agents (OpenAI Codex and DeepSeek) to build and refine PaperCut exploits, compromising 440 servers at 395 organizations in 48 countries (story), and Anthropic disrupted Midnight Blizzard campaigns where AI agents automatically rebuilt malware until it evaded detection across 20+ government and defense targets (story).
KEV additions (14): CVE-2026-85046 story (Chrome V8); CVE-2026-42018, CVE-2026-42016, CVE-2026-84869, CVE-2026-85706, CVE-2026-86060, CVE-2026-67277 (MikroTik RouterOS), CVE-2026-87491, CVE-2026-19490 (Citrix NetScaler), CVE-2026-20079, CVE-2025-25249, CVE-2026-81963, CVE-2026-75650, CVE-2026-86218, CVE-2026-85880.
3. Patch priorities
- CVE-2026-75650 — Adobe Commerce/Magento 2.4.4–2.4.9: apply emergency hotfix VULN-39341 now; hunt for Rust backdoor and PHP shells.
- CVE-2026-85706 — GitLab CE/EE: upgrade to 19.1.8, 19.2.6, or 19.3.2; assume SSH keys and CI/CD secrets exposed on unpatched instances.
- CVE-2026-85880 / CVE-2026-81963 — Windows: deploy September Patch Tuesday; both enable SYSTEM-level escalation and are chained by BlueMoon.
- CVE-2026-19490 — NetScaler ADC/Gateway (gateway or AAA vServers): Citrix patched August 19; upgrade and audit sessions.
- CVE-2025-25249 — FortiOS 6.4–7.6.3 / FortiSwitchManager: patch and rotate VPN/admin credentials; check for fortirun.bin and PivotC2.
- CVE-2026-84869 — ScreenConnect: update to stop file transfer/execution abuse through active sessions.
- CVE-2026-86060 / CVE-2026-67277 — MikroTik RouterOS: patch edge routers immediately.
- CVE-2026-86218 — N-able N-central: apply Hotfix 4 to all deployments (pre-auth RCE, actively exploited).
- WordPress CVE-2026-63030 + CVE-2026-60137: update to 6.9.5 or 7.0.2 — the chain gives unauthenticated RCE on default installs (story).
- LiteLLM CVE-2026-59822/CVE-2026-59821: rotate default master keys (sk-1234) and patch — 9.6% of ~3,074 exposed deployments are effectively unauthenticated (Wiz).
4. Breaches & ransomware
The IDScan.net incident dominated: 170M+ people's records advertised (153M+ driver's licenses, 10M+ ID cards, 3M+ travel documents, 579,000 medical records), unauthorized cloud access detected around September 1, FBI investigation, and four class-actions in the Eastern District of Louisiana (breach notice). Separately, Kinryū Labs found an exposed Elasticsearch cluster in Hanoi holding 220M airline passenger and crew records (2017–2026) with passport numbers (story).
Most active ransomware groups: storm (41 victims), the gentlemen (21), kazu (17), krybit (13), black nevas (13), safepay (11), audit team (11), qilin (8). Qilin's footprint includes the Cisco FMC intrusions noted above.
5. AI
OpenAI released GPT-6 Astra, with major gains in 3D rendering, animation, and computer use, and 99.9% on ARC-AGI-3 versus 7.8% for GPT-5.6 Sol (review). OpenAI also claimed an unreleased model solved the Navier-Stokes existence and smoothness problem (a $1M Millennium Prize problem); NYU's Tristan Buckmaster disputes the result (story).
On the security front, NSA, CISA, and FBI reported Chinese firms including DeepSeek, Moonshot, Alibaba, MiniMax, StepFun, and Z.AI distilled billions of tokens from US frontier models since late 2024 (advisory). Agentic-tooling CVEs deserve attention: Mistral Vibe shipped four CVSS 10.0 command-permission bypasses (CVE-2026-87985, CVE-2026-87986, CVE-2026-87987, CVE-2026-87988), and the MySQL MCP Server's CVE-2026-59971 enables unauthenticated SQL execution via DNS rebinding.
New models (15): GPT-Image-2.5 Sunburst/Flare, ChatGPT Images 2.5, DeepSeek-V4.1-Flash, Nex-N2.5-mini/Pro, YuE2-3B, Agnes-3.0-Flash, Edge0-35B-A3B-preview, OUI-1, and community fine-tunes.
6. By the numbers
| Metric | Count |
|---|---|
| Stories | 1,674 |
| CVEs | 3,842 |
| KEV additions | 14 |
| Leaks | 220 |
| Breaches | 2 |
| New models | 15 |
7. Outlook
- Expect BlueMoon-driven exploitation of unpatched Chrome and Windows endpoints as APT31-style tooling spreads to more espionage groups.
- Watch for follow-on intrusions from StyleSmuggler (payment data theft) and GitLab CVE-2026-85706 (credential exposure) as attackers weaponize harvested secrets.
- The record 974-CVE Patch Tuesday will strain change windows; prioritized remediation failures will surface as incident reports in coming weeks.
- IDScan fallout — further litigation, regulatory action, and Nexus dataset abuse for identity fraud — is likely to escalate.
- Agentic-AI vulnerabilities (Mistral Vibe, LiteLLM, MCP servers) are an emerging, under-patched attack surface; expect more CVSS 10.0 disclosures here.