Curated cybersecurity briefings on active threats, vulnerabilities, and emerging risks
Daily Cybersecurity Briefing (9 September 2026)
Published: Loading…
At a Glance
- Microsoft released patches for 966 vulnerabilities on September Patch Tuesday, including two actively exploited zero-days in Windows Update Stack and Windows ALPC.
- Threat actors deployed autonomous multi-agent AI frameworks that completed mass credential harvesting campaigns in less than six hours.
- Adobe Commerce and Magento vulnerability CVE-2026-75650 has been actively exploited since September 4 to deploy backdoors and web shells.
- A ChatGPT vulnerability leveraging shared internal Artifactory service enabled attackers to execute hidden tasks accessing victim-connected Gmail data.
- A zero-click WeChat vulnerability in VoIP stack allows account hijacking and worm spread across iOS and Android devices.
- Metabase vulnerability exploitation compromised Mathspace's reporting system, exposing over 1 million student, parent and staff records in Australia and New Zealand.
Editorial Analysis
Microsoft's record 966-patch release and Adobe's 170+ updates highlight the volume of vulnerabilities being disclosed across widely deployed software. The two exploited Windows zero-days were latent flaws rather than novel attack techniques, while AI-assisted analysis is helping identify weaknesses in mature codebases more quickly. The scale of this month's releases also increases the workload for organisations testing and deploying patches, particularly where updates require compatibility checks before rollout.
Third-party infrastructure featured in several unrelated incidents. Mathspace's breach involved an unpatched Metabase instance, ChatGPT's hidden task channel reached a shared JFrog Artifactory service, and Adobe's actively exploited Magento flaw is being used against e-commerce infrastructure. The WeChat vulnerability affects the platform's VoIP stack and potentially more than a billion users. These cases involve different technologies, but each places part of an organisation's or user's security posture in the hands of a third-party service.
Mathspace also holds educational records for more than one million people across Australia and New Zealand. Those individuals do not directly operate or control the systems storing their information, so a breach at the provider can expose data belonging to people and organisations that had no direct role in the security of the affected infrastructure.
Highlights of the Day
Microsoft Fixes 966 Flaws, Including Two Exploited Zero-Days
Microsoft's September 2026 Patch Tuesday addresses 966 vulnerabilities, including 105 rated Critical, with two actively exploited zero-days resolved. One flaw allows attackers to gain SYSTEM privileges through improper link resolution in the Windows Update Stack, while the second is a heap-based buffer overflow in Windows ALPC also exploited for privilege escalation. Microsoft has not disclosed how either vulnerability was exploited in the wild.
Threat Actors Evolve to Agentic AI and Autonomous Attack Frameworks
Google's Threat Intelligence Group observed adversaries transitioning from basic prompting to agentic AI workflows in Q2 2026, with one threat actor completing a mass credential harvesting campaign in under six hours using autonomous agents. Threat actors increasingly target proprietary AI models, source code, and API credentials across healthcare, government, and media sectors. State-sponsored and cybercriminal groups are integrating AI across attack lifecycles—from reconnaissance and social engineering to malware development and post-exploitation—whilst experimenting with model distillation attacks targeting frontier AI capabilities at scales exceeding 100 million prompts.
Grindr Settles £26m UK Privacy Claims Over Sensitive Data Sharing
Grindr agreed to settle UK privacy claims for £26m over data sharing from 2016–2020 whilst owned by Chinese conglomerate Kunlun. The claim alleged the app shared sensitive information—including HIV status, sexual orientation and ethnicity—with third parties without adequate user consent. Grindr disputes the allegations but will pay £13m by December 2026 and £13m by March 2027.
Adobe Patches 170+ Vulnerabilities Including Actively Exploited Commerce Flaw
Adobe patched 170+ vulnerabilities, including CVE-2026-75650, a critical unauthenticated code injection flaw in Commerce and Magento actively exploited as 'StyleSmuggler' for remote code execution. Attackers have exploited it since September 4 by injecting code through payment transaction failures to deploy backdoors and web shells. Adobe also urgently patched CVE-2026-82004 in Campaign Classic and two critical code execution vulnerabilities in ColdFusion.
Researchers Demonstrate Zero-Click WeChat Worm Spreading via VoIP Calls
Researchers at Calif demonstrated WeWorm, a zero-click worm spreading through WeChat calls on iOS and Android by exploiting a memory corruption vulnerability in the application's VoIP stack. The exploit requires the attacker to be on the victim's friend list and achieves full account takeover without user interaction. Tencent deployed server-side mitigations in August 2026 after the vulnerability was reported in July.
Mathspace Reports Breach Affecting 1.08 Million User Records
Mathspace confirmed unauthorised access to its internal reporting system after attackers exploited a Metabase vulnerability disclosed on 6 August 2026. The breach affected 1,079,819 people in Australia and New Zealand, exposing user IDs, names, email addresses and account metadata. Passwords, authentication credentials and academic records were not exposed.
ChatGPT Vulnerability Enables Hidden Cross-Account Data Access
Check Point Research discovered a ChatGPT vulnerability allowing attackers to establish a covert cross-account channel via a shared internal service. Hidden instructions embedded in conversations could execute unauthorised tasks in a victim's session whilst normal requests were processed visibly. The flaw enabled retrieval of data from connected applications such as Gmail without user awareness.
Daily Coverage