Threat Intel Bi-Weekly + AI Vuln Monitor | Coverage: September 21, 2026 - September 21, 2026 | Sources: NVD • CISA KEV • Microsoft MSRC • Google GTIG • Palo Alto PSIRT • BleepingComputer • OWASP LLM | Published: Monday, September 21, 2026 +0% vs prior run
[!!] ALERT THRESHOLD BREACHED

CVEs & Exploits

[CRITICAL]

MS-Patch-Tuesday-Sept-2026 — Microsoft Windows and Server products

Microsoft's September 2026 Patch Tuesday established a new record with 973 vulnerabilities, more than doubling any previous year's full tally. The release includes 104 Critical CVEs, 860 Important CVEs, and fixes for two actively exploited zero-days. Unauthenticated network-reachable RCE vulnerabilities span at least 17 CVEs across core infrastructure services including DNS, DHCP, MSMQ, NFS, and SSTP VPN.

REMEDIATION

Organizations must treat this as an extraordinary patching event requiring extended deployment windows. Prioritize the two zero-days (CVE-2026-81963 and CVE-2026-85880) for immediate deployment, then systematically address the 118 Critical severity vulnerabilities. Plan additional time and resources for testing and deployment given the unusually large volume. Focus on core infrastructure services (DNS, DHCP, domain controllers) and identity platform components (Netlogon, Kerberos) first.

Source: MSRC  •  Published: 2026-09-08

[CRITICAL]

Apple-Security-Update-Sept-2026 — Apple iOS, iPadOS, macOS, watchOS, tvOS, visionOS, Safari, Xcode

Apple released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities across iPhone, iPad, Mac, Apple Watch, Apple TV, Vision Pro, Safari, and Xcode. This includes the actively exploited CVE-2026-65400 Screen Sharing Server vulnerability with CVSS 9.8. The updates span iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27, and Xcode 27.

REMEDIATION

Deploy updates immediately across all Apple devices and platforms: iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27, and Xcode 27. For devices not yet on version 27, deploy iOS/iPadOS 26.7, macOS Tahoe 26.7, and macOS Sequoia 15.8. Given the scope of 273 vulnerabilities including an actively exploited zero-day, prioritize devices with Screen Sharing enabled and internet-facing systems. Implement automated update deployment where possible to ensure rapid coverage.

Source: Apple  •  Published: 2026-09-14

AI & Supply Chain

[CRITICAL]

MCP-Supply-Chain-SANDWORM-2026 — Model Context Protocol (MCP) implementations

In February 2026, the SANDWORM_MODE worm campaign targeted developers' local workspaces through Model Context Protocol (MCP) released by Anthropic in November 2024. Attackers deployed rogue MCP servers and injected malicious configurations into code assistants, systematically extracting AWS environment keys and SSH credentials. MCP became a primary supply-chain vector in 2026 for AI development environments.

REMEDIATION

Audit all MCP server deployments and configurations for unauthorized modifications. Implement strict validation and signing requirements for MCP server connections. Rotate all AWS environment keys and SSH credentials potentially exposed to compromised development environments. Monitor for unusual MCP server connections and data exfiltration attempts. Consider implementing network isolation for MCP servers and restricting connections to verified, trusted servers only.

Source: Threat Intelligence  •  Published: 2026-02-01

Threat Actors & Dark Web

[CRITICAL]

Cisco-FMC-2026 — Cisco Secure Firewall Management Center

Two actively exploited vulnerabilities in Cisco Secure Firewall Management Center enabling authentication bypass and static credential abuse. Cisco Talos confirmed three separate intrusion clusters exploiting these flaws, including one with tooling overlapping Sandworm APT and one using tactics consistent with Qilin ransomware operators.

REMEDIATION

Deploy Cisco security patches immediately for all 18 vulnerabilities affecting Firewall Management Center, ASA, and Threat Defense software. Organizations should assume compromise if patches were not applied before September 4, 2026. Conduct forensic investigation for indicators of Sandworm APT or Qilin ransomware activity, including unauthorized firewall rule changes and lateral movement.

Source: CISA  •  Published: 2026-09-16

[HIGH]

Bitter-APT-Diplomatic-2026 — Diplomatic Entities (Embassy targeting)

Bitter APT is conducting sustained long-term espionage campaign against diplomatic targets. The threat actor reused specific infrastructure including BDarkRAT command-and-control domain (hannahsgpsapp[.]com) from previous campaign targeting the same embassy in October 2025. This consistency demonstrates calculated and persistent effort rather than opportunistic attacks.

REMEDIATION

Diplomatic entities should implement enhanced monitoring for BDarkRAT indicators of compromise, specifically the hannahsgpsapp[.]com domain and related infrastructure. Deploy network segmentation to isolate sensitive diplomatic communications. Implement email security controls to detect and block targeted phishing attempts. Conduct regular security awareness training focused on APT tactics targeting diplomatic personnel. Review and harden access controls for all diplomatic communication systems.

Source: Threat Intelligence  •  Published: 2026-09-01

Priority Action Matrix

01DO NOWCisco-FMC-2026 (Cisco Secure Firewall Management Center): Deploy Cisco security patches immediately for all 18 vulnerabilities affecting Firewall Management Center, ASA, and Threat Defense software. Organizations should assume compromise if patches were not ...
02DO NOWMCP-Supply-Chain-SANDWORM-2026 (Model Context Protocol (MCP) implementations): Audit all MCP server deployments and configurations for unauthorized modifications. Implement strict validation and signing requirements for MCP server connections. Rotate all AWS environment keys and...
03DO NOWMS-Patch-Tuesday-Sept-2026 (Microsoft Windows and Server products): Organizations must treat this as an extraordinary patching event requiring extended deployment windows. Prioritize the two zero-days (CVE-2026-81963 and CVE-2026-85880) for immediate deployment, then ...
04DO NOWApple-Security-Update-Sept-2026 (Apple iOS, iPadOS, macOS, watchOS, tvOS, visionOS, Safari, Xcode): Deploy updates immediately across all Apple devices and platforms: iOS 27, iPadOS 27, macOS Golden Gate 27, watchOS 27, tvOS 27, visionOS 27, Safari 27, and Xcode 27. For devices not yet on version 27...
05TODAYBitter-APT-Diplomatic-2026 (Diplomatic Entities (Embassy targeting)): Diplomatic entities should implement enhanced monitoring for BDarkRAT indicators of compromise, specifically the hannahsgpsapp[.]com domain and related infrastructure. Deploy network segmentation to i...

Biggest Risk This Period

BIGGEST RISK

Cisco-FMC-2026: Two actively exploited vulnerabilities in Cisco Secure Firewall Management Center enabling authentication bypass and static credential abuse. Cisco Talos confirmed three separate intrusion clusters exploiting these flaws, including one with tooling overlapping Sandworm APT and one using tactics consistent with Qilin ransomware operators.