Microsoft Patch Tuesday, CISA Adds Flaws, Revolut Data Breach – Cybersecurity News [September 07, 2026]
Quick Answer
This cybersecurity roundup covers major threats and incidents, including Microsoft’s 973 patched flaws, actively exploited vulnerabilities, ransomware, phishing campaigns, data breaches, and emerging AI-driven attacks.
Microsoft’s biggest Patch Tuesday ever fixes 973 flaws, including two zero-days already under attack
Microsoft’s September 2026 Patch Tuesday broke previous records, addressing 973 CVEs across its product lineup in a single release, with two of these vulnerabilities already being exploited in the wild before fixes became available. Windows accounted for 723 of the fixed flaws, Office received patches for 222 issues, and SQL Server, SharePoint, Azure, Skype for Business, and Exchange Server all saw fixes too. One of the exploited bugs, an elevation-of-privilege flaw in the Windows Update Stack, is the first Windows Update Stack vulnerability to be exploited in the wild as a zero-day since 2022. Both flaws have been added to CISA’s Known Exploited Vulnerabilities catalog, giving federal agencies a hard patching deadline. Tenable Microsoft Patch Tuesday September 2026 Fixes 974 CVEs +2
CISA adds five actively exploited flaws in Artifactory, ScreenConnect, and RouterOS to its KEV list
The Cybersecurity and Infrastructure Security Agency added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog, following reports of active exploitation in the wild. Separately, security researchers reported that the ConnectWise ScreenConnect bug is being used in worm-like attacks that let attackers push files and run them without authorization through an active remote session, while the JFrog Artifactory flaws are being chained together to deploy backdoors. WIU Cybersecurity Center
Revolut hands sensitive customer data to a hacker posing as a government agency
British fintech Revolut confirmed on September 12 that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain. The exposed data included customers’ birth dates, postal and email addresses, phone numbers, and copies of identity documents including passports and driver’s licenses, with verification selfies, account statements, and transaction histories also potentially involved. The company says a “limited” number of customers were impacted and that Revolut’s systems and customer funds were unaffected. Days later, the attacker began leaking samples of the stolen data and demanding a ransom, according to follow-up reporting. TechCrunch

China-linked hackers turn a popular Chinese typing app into a backdoor delivery system
Researchers at Gen Digital found that a group Google Threat Intelligence ties to China, tracked as UNC3569, exploited a critical one-click remote code execution flaw in Tencent’s Sogou Input Method for Windows to install a backdoor called GrayRabbit. The flaw chained three security weaknesses together: unvalidated command-line argument injection, unrestricted URL navigation, and an outdated, un-sandboxed Chromium browser engine. The group has been tracked since 2021 and has mostly targeted government, education, technology, and finance sectors in East and Southeast Asia. Tencent patched the flaw back in April, but the disclosure only became public this week. The Hacker News
Nation-state hackers and a ransomware gang both exploiting the same Cisco firewall flaws
Cisco disclosed that a nation-state actor and a Qilin ransomware operator are actively exploiting two Secure Firewall Management Center flaws to gain root or credential-based access, steal sensitive data, deploy Sandworm-linked malware, and prepare networks for encryption. The overlap between espionage-grade and financially motivated actors abusing the same bug underscores how quickly exploits get recycled once they’re public. DataBreachToday

Microsoft warns of passkey-themed phishing hijacking cloud accounts
Microsoft disclosed two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign involved sending over a million scam emails in a short window by masquerading as chief executive officers. The passkey angle is notable it shows attackers adapting phishing lures to newer, supposedly phishing-resistant authentication methods. WIU Cybersecurity Center
Email security is critical as phishing threats rise, making SPF, DKIM, and DMARC essential for protecting email communications.
A single prompt injection in ChatGPT could quietly forward a victim’s Gmail data
Check Point Research reported that a single instruction planted in a ChatGPT conversation could be used to send a victim’s Gmail data to another account. The finding adds to a growing list of prompt-injection issues affecting AI assistants that have been granted access to a user’s email or other personal accounts. WIU Cybersecurity Center
Iranian hackers claim credit for a Texas AT&T outage AT&T says it was cable theft
A group calling itself APT IRAN, linked to the Islamic Revolutionary Guard Corps and the CyberAv3ngers hacking group, claimed on Telegram that it had disrupted AT&T internet services across four Texas cities, part of a broader threat against U.S. critical infrastructure. AT&T said its information does not support the claim, adding that its assessment indicates attempted cable theft led to the outage. The same group also claimed it disrupted an unnamed Texas water utility and previously claimed responsibility for attacks on water systems in Minnesota, Michigan, Georgia, New Jersey, South Dakota, and Arkansas. Cybernews
Healthcare vendor breach at Veradigm exposes patient Social Security numbers
BreachNews reported that Veradigm confirmed attackers used credentials stolen from a third-party vendor to download patient data, including Social Security numbers in some cases. Third-party vendor compromise remains one of the most common entry points into healthcare data, since vendors often hold broad access across multiple client systems. BreachNews
Online maths platform Mathspace breached, over a million students and staff affected
Mathspace disclosed that attackers stole data from more than 1 million students, staff, and parents after breaching its internal Metabase reporting system. The breach adds to a string of edtech incidents this year that have exposed student data at scale. Privacy Guides

Adobe pushes emergency fix for a maximum-severity Commerce flaw already under attack
Adobe issued an out-of-band advisory addressing a CVSS 10.0 template-engine injection vulnerability in Adobe Commerce that Adobe says is being exploited in the wild. Given the severity score and confirmed exploitation, security researchers are urging Commerce/Magento store operators to patch immediately rather than wait for a routine cycle. Zero Day Initiative
CISA warns hackers are actively exploiting a maximum-severity GitLab vulnerability
BleepingComputer reported that CISA warned hackers are now exploiting a maximum-severity GitLab vulnerability in attacks. Organizations running self-hosted GitLab instances are being urged to check their version against the advisory and patch without delay, given GitLab’s role as a central repository for source code and CI/CD pipelines. BleepingComputer
AI-driven ransomware milestone: researchers spot an agent running an attack largely on its own
A new industry report found that ransomware disclosures rose to 7,551 victims in the latest tracking period, a 24.9% jump, continuing a four-year climb. More strikingly, researchers described a case called JADEPUFFER as the first documented instance of an AI agent orchestrating attack stages from reconnaissance through encryption with limited human direction during execution. Researchers caution it’s one case, not yet a trend line, but it shows how known vulnerabilities and weak credentials become more dangerous once an agent can test and retry faster than a person can. Black Kite

The Gentlemen ransomware group hits a Canadian airline
A weekly threat roundup from AhnLab’s ASEC noted a ransomware attack by “The Gentlemen” group on a Canadian airline, alongside the LAPSUS$ group resuming activity and teasing a new victim disclosure, and a separate extortion group hitting four organizations across South Korea, Germany, and Argentina. ASEC
White House water-security program for small utilities set to expand nationwide
On a more positive note, DataBreachToday reported that a White House effort called Project Watershed 250, meant to help small or rural water utilities secure their systems against hackers using free technology donated by cybersecurity vendors, will expand nationwide, according to the country’s top cyber official. It’s a rare piece of good news in a sector water utilities that’s been a frequent target this year. DataBreachToday
General Manager
General Manager at DuoCircle. Product strategy and commercial lead across the email security portfolio.
Secure your email infrastructure
Protect, authenticate, and deliver. Contact our team to find the right solution.