Microsoft released historic record of 974 CVEs in September 2026 Patch Tuesday, including 104 critical and 860 important severity vulnerabilities. Microsoft Office received 22 critical patches, 12 exploitable via Preview Pane without user interaction. This represents over double the CVEs released in August 2026.
Deploy September 2026 cumulative updates across all Microsoft products immediately. Prioritize the two actively exploited zero-days (CVE-2026-81963, CVE-2026-85880), followed by Critical-rated Netlogon, Kerberos, and Office vulnerabilities. Disable Preview Pane in Outlook until patches are deployed. Implement phased rollout starting with internet-facing and critical infrastructure systems.
Source: MSRC • Published: 2026-09-18
Oracle released 673 security patches addressing over 800 vulnerabilities in September 2026 CSPU. More than 100 critical-severity flaws and over 240 remotely exploitable without authentication. E-Business Suite received 159 patches, Fusion Middleware 153 patches (78 unauthenticated remote), and Hyperion 102 patches (50 unauthenticated remote).
Apply Oracle September 2026 Critical Patch Update immediately across all Oracle products. Prioritize internet-facing systems and those with critical-severity or unauthenticated remote vulnerabilities. Focus first on E-Business Suite, Fusion Middleware, and Hyperion deployments. Review Oracle's risk matrices to identify high-priority patches for your environment. Test patches in non-production environments where possible before production deployment.
Source: NVD • Published: 2026-09-18
RSA Conference 2026 research disclosed 24 CVEs across major AI IDEs with 100% of tested environments vulnerable to prompt injection attacks. Combined with legacy IDE features, vulnerabilities enable remote code execution and data exfiltration from developer machines. Represents systemic risk to software supply chain through developer environment compromise.
Update all AI IDEs (Cursor, Windsurf, Copilot, Zed, Roo Code, Junie) to latest patched versions. Implement prompt injection detection and filtering. Restrict AI IDE network access and code execution permissions. Deploy EDR on developer workstations. Conduct security awareness training on prompt injection risks. Review and sanitize all AI-generated code before committing. Implement code review processes specifically for AI-generated contributions. Consider sandboxing AI IDE operations.
Source: GTIG • Published: 2026-09-18
Critical code execution vulnerability in LiteLLM /guardrails endpoint discovered by Obsidian Security. Part of three-vulnerability chain (CVSS 9.9) enabling low-privilege users to achieve admin access and remote code execution. Impacts downstream AI agents through injected tool calls, creating systemic risk in AI infrastructure.
Apply LiteLLM security patches immediately. Disable /guardrails endpoint if not required. Implement strict API authentication and authorization controls. Audit all user permissions and downgrade unnecessary privileges. Deploy API gateway with rate limiting and anomaly detection. Monitor for privilege escalation attempts. Review and validate all guardrail configurations. Implement defense-in-depth with network segmentation and EDR.
Source: GTIG • Published: 2026-09-18
IronWorm represents engineering ceiling for supply chain malware in 2026. Move from JavaScript to compiled 976 KB Rust binary with kernel-level eBPF rootkit, per-call-site string encryption, Tor C2, and OIDC-based self-propagation through 37 npm packages across 9 organizations. Signals professionalizing of supply chain malware toward nation-state implant capabilities. Discovered by JFrog Security Research.
Scan all npm dependencies for IronWorm indicators of compromise. Deploy runtime monitoring to detect eBPF rootkit activity. Implement package integrity verification and signing. Use private npm registry with security scanning. Deploy software composition analysis (SCA) with behavioral analysis capabilities. Monitor for Tor network connections from build/development systems. Audit and restrict OIDC token access. Implement least privilege for CI/CD service accounts. Review suspicious packages across affected organizations.
Source: GTIG • Published: 2026-06-01
TeamPCP and Shai-Hulud lineage represent machine-speed self-propagating supply chain worms. Steal maintainer npm or GitHub tokens, republish trojanized versions, and use stolen credentials to infect next namespace automatically. Represents evolution from human-operated to autonomous supply chain compromise at machine speed.
Rotate all npm and GitHub tokens immediately. Implement hardware security keys (YubiKey, etc.) for npm and GitHub authentication. Enable 2FA/MFA on all package management and code repository accounts. Deploy automated package security scanning in CI/CD pipelines. Implement package signing and verification. Monitor for unauthorized package publishes or updates. Use private registries with security controls. Implement rate limiting and anomaly detection for package operations. Review and minimize token permissions (principle of least privilege).
Source: GTIG • Published: 2026-09-18
Role escalation vulnerability in LiteLLM /user/update endpoint discovered by Obsidian Security. Enables low-privilege users to elevate to administrator privileges, forming part of CVSS 9.9 vulnerability chain leading to full system compromise and AI infrastructure control.
Patch LiteLLM immediately. Audit all user accounts for unauthorized privilege escalations. Implement strict role-based access control (RBAC) with regular audits. Deploy API monitoring to detect privilege escalation attempts. Separate user management functions with additional authentication. Enable comprehensive API logging and alerting. Review and revoke unnecessary administrative privileges. Implement principle of least privilege across LiteLLM deployments.
Source: GTIG • Published: 2026-09-18
Devils Angels ransomware group received highest ransom payment on record at $75 million. Represents escalation in ransom demands and willingness of organizations to pay unprecedented amounts, potentially encouraging future attacks and higher demands across ransomware ecosystem.
Organizations should NOT pay ransoms as it funds criminal operations and encourages attacks. Instead: Implement prevention-focused security controls. Deploy comprehensive, tested backup and disaster recovery. Ensure offline, immutable backups that ransomware cannot reach. Implement network segmentation to contain ransomware spread. Deploy EDR with behavioral ransomware detection. Conduct regular security assessments and penetration testing. Develop and test incident response plans. Consider cyber insurance with clear ransomware coverage terms. Report ransomware incidents to FBI IC3 and CISA.
Source: GTIG • Published: 2026-09-18
DPRK-linked 'Contagious Interview' campaign targeting developers through fake job offers delivering OtterCookie and BeaverTail RATs via npm and PyPI packages. Human-in-the-loop espionage and financial operation using social engineering to compromise developer environments and gain access to corporate infrastructure.
Educate developers about fake job offer phishing targeting tech workers. Scan systems and package managers for OtterCookie and BeaverTail RAT indicators. Implement security awareness training on social engineering tactics. Deploy EDR on developer workstations. Verify legitimacy of recruiting contacts and job opportunities. Monitor for suspicious package installations from unfamiliar sources. Implement application whitelisting where feasible. Review network connections for RAT command-and-control indicators.
Source: GTIG • Published: 2026-09-18
Bitter APT conducting sustained long-term espionage campaign against diplomatic missions. Reused BDarkRAT C2 infrastructure (hannahsgpsapp[.]com) from October 2025 campaign targeting same embassy in 2026. Demonstrates calculated, persistent targeting of specific diplomatic entities rather than opportunistic operations.
Block BDarkRAT C2 domain (hannahsgpsapp[.]com) and related infrastructure. Conduct forensic investigation of diplomatic mission networks for BDarkRAT indicators. Implement enhanced monitoring for diplomatic communications and classified systems. Deploy advanced persistent threat detection focused on Bitter APT TTPs. Harden email security against targeted spear-phishing. Implement network segmentation for classified and sensitive diplomatic systems. Review and strengthen access controls for embassy networks. Coordinate with national CERT/CISA for threat intelligence sharing.
Source: GTIG • Published: 2026-09-18
September 2026 Week 37 recorded 33 concurrent APT clusters (new historic high), marking third consecutive elevated week and confirming durable baseline shift in global APT activity. APT category contributed 795 IOCs from 17 named adversaries. Total threat actor supertype generated 972 IOCs from 33 concurrent clusters. One operator alone contributed 53,277 C2 IOCs, indicating massive infrastructure concentration.
Enhance threat intelligence consumption and correlation capabilities. Deploy advanced threat hunting programs focused on APT TTPs. Implement comprehensive IOC blocking across network perimeter and endpoint. Strengthen security operations center (SOC) staffing and capabilities. Deploy deception technologies to detect APT lateral movement. Implement zero-trust architecture to limit APT impact. Conduct purple team exercises simulating concurrent APT scenarios. Enhance log collection and SIEM correlation rules. Coordinate with sector ISACs for APT intelligence sharing.
Source: GTIG • Published: 2026-09-18
Medusa ransomware reached 500+ victim milestone. Emerged mid-2022 and has hit hundreds of critical infrastructure organizations. Represents sustained, successful ransomware operation targeting high-value infrastructure across multiple sectors.
Implement comprehensive backup strategy with offline, immutable backups. Deploy ransomware-specific EDR detection rules. Harden RDP and remote access with MFA and network access controls. Implement application whitelisting to prevent ransomware execution. Segment networks to contain lateral movement. Deploy email security with anti-phishing and attachment sandboxing. Conduct regular restoration testing of backups. Implement privileged access management with just-in-time access. Train staff on ransomware awareness and reporting. Develop and test incident response playbooks for ransomware scenarios.
Source: BleepingComputer • Published: 2026-09-18
August 2026 recorded largest number of active ransomware groups on record. Week 37 September 2026 showed 540 ransomware IOCs from 33 operators across 23 TTPs, representing 5.5× volume increase week-over-week. Indicates unprecedented ransomware operational tempo and ecosystem growth.
Accelerate deployment of ransomware defenses across all environments. Implement behavioral detection for ransomware encryption activity. Deploy network segmentation to limit ransomware spread. Ensure comprehensive, tested backup and recovery capabilities. Implement email and web security with advanced threat protection. Deploy EDR with ransomware-specific detection rules. Harden privileged access and disable unnecessary administrative privileges. Implement application control and least privilege. Conduct tabletop exercises for ransomware response. Subscribe to ransomware threat intelligence feeds and implement IOC blocking.
Source: GTIG • Published: 2026-08-31
LAPSUS$ threat group resumed operations as 'Chapter II' in September 2026, teasing new victim disclosures. Group previously known for high-profile breaches using social engineering, SIM swapping, and insider recruitment tactics to compromise major technology and telecommunications companies.
Implement comprehensive insider threat program. Deploy behavioral analytics to detect anomalous privileged user activity. Harden authentication with phishing-resistant MFA (FIDO2/WebAuthn). Implement SIM swap protections and out-of-band verification for critical operations. Deploy privileged access management with session recording. Conduct background checks and security awareness training emphasizing social engineering. Implement strict access controls with principle of least privilege. Monitor for unusual data access and exfiltration patterns. Deploy deception technologies to detect unauthorized access.
Source: GTIG • Published: 2026-09-18
CenterPoint Energy suffered massive data breach exposing 6.7 million customer records. As critical energy infrastructure provider, breach creates risks of targeted attacks against customers and potential for social engineering using exposed data.
For CenterPoint: Notify affected customers per state breach notification laws. Conduct forensic investigation to determine breach vector and scope. Implement enhanced security monitoring for customer systems. Offer credit monitoring services to affected customers. Review and harden customer data protection controls. Implement data minimization to reduce stored customer information. Deploy DLP to prevent future large-scale exfiltration. Conduct security assessment of customer data systems. Implement encryption for customer data at rest and in transit. Enhance access controls and monitoring for customer databases.
Source: BleepingComputer • Published: 2026-09-18
MSFT-PATCH-SEP-2026: Microsoft released historic record of 974 CVEs in September 2026 Patch Tuesday, including 104 critical and 860 important severity vulnerabilities. Microsoft Office received 22 critical patches, 12 exploitable via Preview Pane without user interaction. This represents over double the CVEs released in August 2026.