CyberSecBrief

Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks


Daily Cybersecurity Briefing (9 September 2026)

Published: Loading…

At a Glance

  • Microsoft released patches for 966 vulnerabilities on September Patch Tuesday, including two actively exploited zero-days in Windows Update Stack and Windows ALPC.
  • Threat actors deployed autonomous multi-agent AI frameworks that completed mass credential harvesting campaigns in less than six hours.
  • Adobe Commerce and Magento vulnerability CVE-2026-75650 has been actively exploited since September 4 to deploy backdoors and web shells.
  • A ChatGPT vulnerability leveraging shared internal Artifactory service enabled attackers to execute hidden tasks accessing victim-connected Gmail data.
  • A zero-click WeChat vulnerability in VoIP stack allows account hijacking and worm spread across iOS and Android devices.
  • Metabase vulnerability exploitation compromised Mathspace's reporting system, exposing over 1 million student, parent and staff records in Australia and New Zealand.

Editorial Analysis

Microsoft's record 966-patch release and Adobe's 170+ updates highlight the volume of vulnerabilities being disclosed across widely deployed software. The two exploited Windows zero-days were latent flaws rather than novel attack techniques, while AI-assisted analysis is helping identify weaknesses in mature codebases more quickly. The scale of this month's releases also increases the workload for organisations testing and deploying patches, particularly where updates require compatibility checks before rollout.

Third-party infrastructure featured in several unrelated incidents. Mathspace's breach involved an unpatched Metabase instance, ChatGPT's hidden task channel reached a shared JFrog Artifactory service, and Adobe's actively exploited Magento flaw is being used against e-commerce infrastructure. The WeChat vulnerability affects the platform's VoIP stack and potentially more than a billion users. These cases involve different technologies, but each places part of an organisation's or user's security posture in the hands of a third-party service.

Mathspace also holds educational records for more than one million people across Australia and New Zealand. Those individuals do not directly operate or control the systems storing their information, so a breach at the provider can expose data belonging to people and organisations that had no direct role in the security of the affected infrastructure.

Highlights of the Day

Microsoft Fixes 966 Flaws, Including Two Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday addresses 966 vulnerabilities, including 105 rated Critical, with two actively exploited zero-days resolved. One flaw allows attackers to gain SYSTEM privileges through improper link resolution in the Windows Update Stack, while the second is a heap-based buffer overflow in Windows ALPC also exploited for privilege escalation. Microsoft has not disclosed how either vulnerability was exploited in the wild.

Threat Actors Evolve to Agentic AI and Autonomous Attack Frameworks

Google's Threat Intelligence Group observed adversaries transitioning from basic prompting to agentic AI workflows in Q2 2026, with one threat actor completing a mass credential harvesting campaign in under six hours using autonomous agents. Threat actors increasingly target proprietary AI models, source code, and API credentials across healthcare, government, and media sectors. State-sponsored and cybercriminal groups are integrating AI across attack lifecycles—from reconnaissance and social engineering to malware development and post-exploitation—whilst experimenting with model distillation attacks targeting frontier AI capabilities at scales exceeding 100 million prompts.

Grindr Settles £26m UK Privacy Claims Over Sensitive Data Sharing

Grindr agreed to settle UK privacy claims for £26m over data sharing from 2016–2020 whilst owned by Chinese conglomerate Kunlun. The claim alleged the app shared sensitive information—including HIV status, sexual orientation and ethnicity—with third parties without adequate user consent. Grindr disputes the allegations but will pay £13m by December 2026 and £13m by March 2027.

Adobe Patches 170+ Vulnerabilities Including Actively Exploited Commerce Flaw

Adobe patched 170+ vulnerabilities, including CVE-2026-75650, a critical unauthenticated code injection flaw in Commerce and Magento actively exploited as 'StyleSmuggler' for remote code execution. Attackers have exploited it since September 4 by injecting code through payment transaction failures to deploy backdoors and web shells. Adobe also urgently patched CVE-2026-82004 in Campaign Classic and two critical code execution vulnerabilities in ColdFusion.

Researchers Demonstrate Zero-Click WeChat Worm Spreading via VoIP Calls

Researchers at Calif demonstrated WeWorm, a zero-click worm spreading through WeChat calls on iOS and Android by exploiting a memory corruption vulnerability in the application's VoIP stack. The exploit requires the attacker to be on the victim's friend list and achieves full account takeover without user interaction. Tencent deployed server-side mitigations in August 2026 after the vulnerability was reported in July.

Source: Calif

Mathspace Reports Breach Affecting 1.08 Million User Records

Mathspace confirmed unauthorised access to its internal reporting system after attackers exploited a Metabase vulnerability disclosed on 6 August 2026. The breach affected 1,079,819 people in Australia and New Zealand, exposing user IDs, names, email addresses and account metadata. Passwords, authentication credentials and academic records were not exposed.

Source: Mathspace

ChatGPT Vulnerability Enables Hidden Cross-Account Data Access

Check Point Research discovered a ChatGPT vulnerability allowing attackers to establish a covert cross-account channel via a shared internal service. Hidden instructions embedded in conversations could execute unauthorised tasks in a victim's session whilst normal requests were processed visibly. The flaw enabled retrieval of data from connected applications such as Gmail without user awareness.

Daily Coverage

Developments
Microsoft Record Patch ReleaseExploited Windows Zero-DaysAutonomous Ai HarvestingMagento Exploitation Active
Vulnerabilities
CVE-2026-75650Adobe Commerce (Critical)CVE-2026-81963Windows 11 Version 23H2 10.0.22631.0 (High)CVE-2026-85880Windows 10 Version 1607 10.0.14393.0 (High)CVE-2026-86206N-Central (Medium)CVE-2026-86207N-Central (High)CVE-2026-18577N-Central (High)CVE-2026-69676Windows 10 Version 1607 10.0.14393.0 (High)CVE-2026-82004Adobe Campaign Classic (Critical)CVE-2026-18851Missing Authorization In Ivanti Endpoint Manager Mobile Before Version 12.10.0.0, 12.9.0.2, And 12.8.0.4 Allows A Remote Authenticated Attacker To Escalate Their Privileges To Admin.CVE-2026-83527An Authentication Bypass Vulnerability In Sentry Before R10.8.2, R10.7.3 And R10.6.4 Allows A Remote Unauthenticated Attacker To Gain Administrative Level Access.
Threat Groups
CHROMIUMEarth Lusca is a suspected Chinabased cyber espionage group that has been active since at least April 2019. Earth Lusca has targeted organizations in Australia, China, Hong Kong, Mongolia, Nepal, the Philippines, Taiwan, Thailand, Vietnam, the United Arab Emirates, Nigeria, Germany, France, and the United States. Targets included government institutions, news media outlets, gambling companies, educational institutions, COVID19 research organizations, telecommunications companies, religious movements banned in China, and cryptocurrency trading platforms; security researchers assess some Earth Lusca operations may be financially motivated. Earth Lusca has used malware commonly used by other Chinese threat groups, including APT41 and the Winnti Group cluster, however security researchers assess Earth Lusca's techniques and infrastructure are separate.