---
title: "Microsoft Patch Tuesday , GitLab Flaw Exploited, ShinyHunters Used Claude  | AutoSPF"
description: "Stay updated on major cybersecurity threats from September 8–14, 2026, including Microsoft patches, GitLab exploits, AI hacking, and crypto theft."
image: "https://autospf.com/og/blog/microsoft-patch-tuesday-gitlab-flaw-exploited-shinyhunters-used-claude.png"
canonical: "https://autospf.com/blog/microsoft-patch-tuesday-gitlab-flaw-exploited-shinyhunters-used-claude/"
---

Quick Answer

The September 8–14, 2026 cybersecurity roundup highlights major threats, including Microsoft’s record Patch Tuesday, a critical GitLab flaw exploited within 24 hours, AI-assisted credential theft, crypto attacks, malware campaigns, and actively exploited vulnerabilities.

Share 

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fautospf.com%2Fblog%2Fmicrosoft-patch-tuesday-gitlab-flaw-exploited-shinyhunters-used-claude%2F "Share on LinkedIn") [ ](https://twitter.com/intent/tweet?text=Microsoft%20Patch%20Tuesday%20%2C%20GitLab%20Flaw%20Exploited%2C%20ShinyHunters%20Used%20Claude%20&url=https%3A%2F%2Fautospf.com%2Fblog%2Fmicrosoft-patch-tuesday-gitlab-flaw-exploited-shinyhunters-used-claude%2F "Share on X/Twitter") [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fautospf.com%2Fblog%2Fmicrosoft-patch-tuesday-gitlab-flaw-exploited-shinyhunters-used-claude%2F "Share on Facebook") [ ](https://reddit.com/submit?url=https%3A%2F%2Fautospf.com%2Fblog%2Fmicrosoft-patch-tuesday-gitlab-flaw-exploited-shinyhunters-used-claude%2F&title=Microsoft%20Patch%20Tuesday%20%2C%20GitLab%20Flaw%20Exploited%2C%20ShinyHunters%20Used%20Claude%20 "Share on Reddit") [ ](mailto:?subject=Microsoft%20Patch%20Tuesday%20%2C%20GitLab%20Flaw%20Exploited%2C%20ShinyHunters%20Used%20Claude%20&body=Check out this article: https%3A%2F%2Fautospf.com%2Fblog%2Fmicrosoft-patch-tuesday-gitlab-flaw-exploited-shinyhunters-used-claude%2F "Share via Email") 

![Microsoft Patch Tuesday Cybersecurity Developments](https://media.mailhop.org/autospf/spf-lookup-2501-1789564164362.jpg) 

# **Microsoft Patch Tuesday , GitLab Flaw Exploited, ShinyHunters Used Claude**

It was an unusually heavy week for **cybersecurity** teams. Microsoft shipped its largest-ever monthly patch batch, a maximum-severity GitLab flaw went from disclosure to active exploitation in about a day, Anthropic disclosed how criminal and state-linked groups misused its Claude AI models for large-scale credential theft, and a [Bitcoin sidechain lost](https://www.cnbc.com/2026/09/08/crypto-platforms-lost-billions-to-cyberattacks-many-even-after-audits.html) — then partially recovered — **$320 million**. Below are 16 of the developments that mattered most between September 8 and 14, 2026.

Strong [SPF](https://autospf.com/blog/what-is-spf-email-a-guide-to-sender-validation-technology/), [DMARC](https://autospf.com/blog/what-is-dmarc-email-authentication-guide/), and [DKIM](https://autospf.com/blog/dkim-authentication-a-complete-guide-to-secure-email-deliverability/) protections remain essential for improving [email security](https://autospf.com/) and **reducing phishing and spoofing risks**.

## Microsoft’s biggest-ever Patch Tuesday: nearly 1,000 flaws fixed

Microsoft’s September 2026 update closed out somewhere between 966 and [974 CVEs](https://www.darkreading.com/application-security/microsoft-emergency-fixes-patch-tuesday) depending on how each research group counts them, making it the largest single-month release in the company’s history. _Two of the flaws — a Windows ALPC privilege-escalation bug and one in the Windows Update Stack — were already being exploited before patches shipped, and CISA added both to its Known Exploited Vulnerabilities catalog._

The release also included 20 “wormable” bugs across [DNS Server](https://www.digicert.com/blog/best-dns-north-america), [DHCP](https://efficientip.com/glossary/what-is-dhcp-and-why-is-it-important/), Active Directory, Netlogon, and SMB Client, with one DNS flaw (CVSS 9.8) drawing comparisons to the infamous SigRed vulnerability. Source: [SecurityWeek](https://www.securityweek.com/microsoft-patches-record-974-vulnerabilities-including-two-exploited-zero-days/)

## A maximum-severity GitLab bug was under attack within 24 hours

![Spf Flattening 2670](https://media.mailhop.org/autospf/spf-flattening-2670-1789560858276.jpg) [GitLab disclosed CVE-2026-85706](https://www.theregister.com/security/2026/09/14/perfect-10-gitlab-bug-under-attack-days-after-patch-lands/5296176), a perfect-10.0 path traversal flaw in its repository commits API, on September 10\. It let an unauthenticated attacker read any file on a vulnerable self-managed server — including **SSH host keys**, [CI/CD secrets](https://nhimg.org/glossary/cicd-secret/), and database passwords — with a single HTTP request. Threat-intel firm watchTowr observed real-world probing within a day, and CISA added the flaw to its KEV catalog with a September 14 federal remediation deadline. Source: [BleepingComputer](https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploit-max-severity-gitlab-flaw-in-attacks/)

## ShinyHunters-linked hackers used Claude to loot secrets from 1.8 million Android apps

Anthropic published a threat-intelligence report describing how criminal and state-linked groups abused its Claude models between December 2025 and August 2026\. One operator tied to the ShinyHunters collective ran a pipeline across ten AWS servers that downloaded, decompiled, and scanned [1.8 million Android apps](https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/) for hardcoded credentials. The same actor reportedly used Claude to help extract more than **2,100 Azure** AD authentication tokens from over 40 corporate Microsoft tenants in roughly 34 hours. Anthropic said it has since banned the associated accounts and tightened detection. Source: [BleepingComputer](https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/)

## Hackers drained $320 million from Bitcoin’s Liquid Network — then gave most of it back

Attackers exploited a software bug in [Liquid Network](https://www.ibtimes.com/bitcoin-network-lost-320-million-hack-attackers-say-theyre-good-guys-3807199), a Bitcoin sidechain built by Blockstream, to mint unbacked tokens and cash them out through a partner exchange’s authorized withdrawal process, draining roughly 95% of the network’s reserve wallet. The attackers identified themselves as “white hats,” negotiated with Blockstream through messages embedded in Bitcoin transactions, and eventually returned about **3,400 of the 4,000 stolen Bitcoin** — keeping roughly $47 million for themselves. Security experts remain split on whether the episode counts as ethical disclosure or extortion. Source: [SecurityWeek](https://www.securityweek.com/hackers-return-263-million-stolen-from-liquid-network/)

## A zero-click WeChat worm could have hijacked over a billion accounts

![Spf Record Checker 2047](https://media.mailhop.org/autospf/spf-record-checker-2047-1789560890379.jpg)Researchers at security firm Calif built a proof-of-concept worm, dubbed “WeWorm,” that could take over a [WeChat account](https://www.infosecurity-magazine.com/news/wechat-zeroclick-worm-hijack/) through an incoming voice call — without the victim ever answering or touching their phone. The exploit worked across both **iOS and Android** and could hop from device to device using the victim’s saved contacts. _Tencent shipped fixes in late August after being notified in July, and researchers found no evidence it was used in real attacks, but the case highlights how a single flaw in a billion-user messaging app can become a self-spreading threat._ Source: [The Hacker News](https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html)

## CISA flags active exploitation of JFrog Artifactory, ScreenConnect, and RouterOS flaws

**CISA** added five actively exploited vulnerabilities to its [KEV catalog](https://www.cybersecurity-insiders.com/cisa-kev-catalog-seven-exploited-flaws/) this week: two in JFrog Artifactory being chained to gain administrator control and plant Rust-based backdoors on self-hosted servers, one in ConnectWise ScreenConnect (CVSS 9.9) letting attackers execute files through a remote session without authorization, and two in MikroTik RouterOS being exploited in a campaign CERT Polska dubbed “MikroTrick.” Source: [The Hacker News](https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html)

## Chess.com data tied to 4.6 million email addresses surfaces on Have I Been Pwned

A dataset containing **7.3 million rows** and roughly [4.6 million](https://www.technadu.com/chess-com-user-data-surfaces-online-after-suspected-scraping-incident-over-4-5-million-emails-exposed-reportedly-from-previous-breaches/636779/) unique email addresses linked to Chess.com accounts — including usernames, names, countries, and account details — was indexed by Have I Been Pwned on September 13\. Analysts believe the data was scraped rather than pulled from a direct breach, since 99% of the exposed emails had already appeared in earlier leaks, but the details could still fuel targeted phishing against affected users. Source: [Have I Been Pwned](https://haveibeenpwned.com/Breach/Chess2026)

## Attackers chained JFrog Artifactory bugs in a 24-day backdoor campaign

![Spf Record Example 3551](https://media.mailhop.org/autospf/spf-record-example-3551-1789560969722.jpg)Separately from the KEV listing above, cloud security firm Wiz detailed how multiple [threat actors](https://cybermagazine.com/news/how-russian-threat-actors-use-dns-hijacking-to-spy-on-you) chained authentication flaws in [JFrog Artifactory](https://www.securityweek.com/three-jfrog-artifactory-flaws-exploited-for-backdoor-deployment/) between August 15 and September 8 to mint forged administrator tokens, create persistent admin accounts, and install Rust-based backdoors that can survive patching. Fastly recorded roughly **406,000 exploitation attempts** against the flaw on a single day after a public exploit appeared. Source: [SecurityWeek](https://www.securityweek.com/three-jfrog-artifactory-flaws-exploited-for-backdoor-deployment/)

## Rogue AI agents linked to a major RubyGems supply-chain attack

The Hacker News’ weekly recap highlighted new research attributing the “major malicious attack” on the [RubyGems](https://tech-insider.org/openai-rubygems-rogue-ai-attack-2026/) package registry back in May 2026 to a swarm of autonomous **OpenAI agents** rather than human operators, who mass-published thousands of malicious packages. _Researchers say the swarm’s behavior closely resembles other AI-driven attack clusters previously identified, raising fresh concerns about autonomous agents being used to scale supply-chain attacks._ Source: [The Hacker News](https://thehackernews.com/2026/09/weekly-recap-rogue-ai-agents-wechat.html)

## Windows Remote Desktop Services destabilized by September’s security updates

Microsoft confirmed that its September 2026 Windows security updates can cause instability in [Remote Desktop Services](https://betanews.com/article/microsoft-september-update-rds-windows-server/), potentially disrupting remote administration across enterprise environments — an added complication for **IT teams** already racing to deploy the month’s record-breaking patch load. Source: [Cyber Security News](https://cybersecuritynews.com/)

## GitHub pays $100,000 bounty for a critical remote code execution flaw

GitHub awarded security researcher Saif Ghani a $100,000 bug bounty after he disclosed **CVE-2026-3854**, a critical [RCE vulnerability affecting the platform’s](https://cybersecuritynews.com/n-able-released-hotfix/) Git push pipeline — one of the largest publicly disclosed bounty payouts of the year and a sign of how highly source-control infrastructure is now valued as an attack target. Source: [IT Security News](https://www.itsecuritynews.info/it-security-news-weekly-summary-37-2) ![Spf Record Checker 1021](https://media.mailhop.org/autospf/spf-record-checker-1021-1789560711082.jpg)

## Dutch NCSC warns of critical Check Point VPN flaws

The **Netherlands’ National Cyber Security Centre** issued a warning about critical vulnerabilities in [Check Point VPN](https://www.computing.co.uk/news/2026/security/attacks-on-critical-check-point-vpn-flaws-imminent-warning) products that could put connected networks at risk, urging organizations running affected gateways to patch immediately given how frequently VPN appliances are targeted as an initial-access point into corporate networks. Source: [IT Security News](https://www.itsecuritynews.info/it-security-news-weekly-summary-37-2)

## Hackers abuse YouTube gaming channels and SEO poisoning to spread RATs

_Researchers documented a campaign in which attackers compromise or spoof YouTube gaming channels and use SEO poisoning techniques to trick users searching for game cheats or cracks into downloading remote access trojans and a Chrome-hijacking payload — a reminder that search and video platforms remain popular malware-distribution channels._ Source: [IT Security News](https://www.itsecuritynews.info/it-security-news-weekly-summary-37-2)

## Casbaneiro banking trojan activates when victims visit bank websites

A new wave of the [Casbaneiro banking trojan](https://gbhackers.com/casbaneiro-banking-trojan/) was observed lying dormant on infected machines until the victim navigates to their **bank’s website**, at which point it activates to intercept credentials and session data — a technique aimed at evading behavioral detection tools that flag malware active immediately after infection. Source: [IT Security News](https://www.itsecuritynews.info/it-security-news-weekly-summary-37-2)

![Brad Slavin](https://media.mailhop.org/autospf/images/authors/brad-slavin.jpg) 

[ Brad Slavin ](/authors/brad-slavin/) 

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead for AutoSPF's 2,000+ customer base.

[LinkedIn Profile →](https://www.linkedin.com/in/bradslavin) 

## Ready to get started?

Try AutoSPF free — no credit card required.

[ Book a Demo ](/book-a-demo/) 

Scan Your Domain Now

Instantly scan your domain for DKIM, SPF, and DMARC issues

Check My Domain 

Share this article

[ ](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fautospf.com%2Fblog%2Fmicrosoft-patch-tuesday-gitlab-flaw-exploited-shinyhunters-used-claude%2F) [ ](https://twitter.com/intent/tweet?text=Microsoft%20Patch%20Tuesday%20%2C%20GitLab%20Flaw%20Exploited%2C%20ShinyHunters%20Used%20Claude%20&url=https%3A%2F%2Fautospf.com%2Fblog%2Fmicrosoft-patch-tuesday-gitlab-flaw-exploited-shinyhunters-used-claude%2F) [ ](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fautospf.com%2Fblog%2Fmicrosoft-patch-tuesday-gitlab-flaw-exploited-shinyhunters-used-claude%2F) Copy 

Related Articles

- [ ![DIY-ing SPF](https://media.mailhop.org/autospf/images/2024/04/spf-record-example-5874.jpg)  10 Reasons Why DIY-ing SPF isn’t a Good Choice for Companies Intermediate ](/blog/10-reasons-diy-ing-spf-isnt-good-choice-for-companies/)
- [ ![phishing actors](https://media.mailhop.org/autospf/images/2025/11/spf-record-checker-0096.jpg)  The 12.4 billion shield for your email communications: Why DMARC software is the unsung hero in the war against phishing actors! Intermediate ](/blog/12-4-billion-dmarc-software-shield-protecting-email-from-phishing-actors/)
- [ ![421 Error SMTP Guide](https://media.mailhop.org/autospf/spf-lookup-1607-1785756872932.jpg)  421 Error SMTP Survival Guide: Fix the 4.4.2 Connection Dropped Issue Intermediate ](/blog/421-error-smtp-survival-guide-fix-connection-dropped-email-issue/)
- [ ![Sender Policy Framework](https://media.mailhop.org/autospf/images/2024/11/spf-checker-4785.jpg)  5 key contributors to the development of the Sender Policy Framework Intermediate ](/blog/5-key-contributors-to-sender-policy-framework-development/)

## Related Articles

[  Intermediate 6m  10 Reasons Why DIY-ing SPF isn’t a Good Choice for Companies  Apr 4, 2024 ](/blog/10-reasons-diy-ing-spf-isnt-good-choice-for-companies/)[  Intermediate 5m  The 12.4 billion shield for your email communications: Why DMARC software is the unsung hero in the war against phishing actors!  Nov 19, 2025 ](/blog/12-4-billion-dmarc-software-shield-protecting-email-from-phishing-actors/)[  Intermediate  421 Error SMTP Survival Guide: Fix the 4.4.2 Connection Dropped Issue  Aug 3, 2026 ](/blog/421-error-smtp-survival-guide-fix-connection-dropped-email-issue/)[  Intermediate 3m  5 key contributors to the development of the Sender Policy Framework  Nov 12, 2024 ](/blog/5-key-contributors-to-sender-policy-framework-development/)

```json
{"@context":"https://schema.org","@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138897474","https://www.linkedin.com/company/autospf","https://x.com/autospf01","https://www.g2.com/products/autospf/reviews"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://autospf.com/contact-us/"},"knowsAbout":["SPF Record Flattening","Sender Policy Framework","Email Authentication","DNS Management","DMARC","DKIM"]}
```

```json
{"@context":"https://schema.org","@type":"WebSite","name":"AutoSPF","url":"https://autospf.com","description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","publisher":{"@type":"Organization","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]}}}
```

```json
{"@context":"https://schema.org","@type":"BlogPosting","headline":"Microsoft Patch Tuesday , GitLab Flaw Exploited, ShinyHunters Used Claude ","description":"Stay updated on major cybersecurity threats from September 8–14, 2026, including Microsoft patches, GitLab exploits, AI hacking, and crypto theft.","url":"https://autospf.com/blog/microsoft-patch-tuesday-gitlab-flaw-exploited-shinyhunters-used-claude/","datePublished":"2026-09-16T00:00:00.000Z","dateModified":"2026-09-16T00:00:00.000Z","dateCreated":"2026-09-16T00:00:00.000Z","author":{"@type":"Person","@id":"https://autospf.com/authors/brad-slavin/#person","name":"Brad Slavin","url":"https://autospf.com/authors/brad-slavin/","jobTitle":"General Manager","description":"Brad Slavin is the founder and General Manager of DuoCircle, the company behind AutoSPF, DMARC Report, Phish Protection, and Mailhop. He founded DuoCircle in 2014 to solve the SPF 10-DNS-lookup problem at scale and has led the company's growth to 2,000+ customers. Brad's focus is product strategy, customer relationships, and the commercial and compliance side of email authentication (DPAs, SLAs, enterprise procurement) rather than hands-on DNS engineering.","image":"https://media.mailhop.org/autospf/images/authors/brad-slavin.jpg","knowsAbout":["Email Security Strategy","SaaS Product Management","Enterprise Compliance","Customer Success","Email Deliverability Business"],"worksFor":{"@type":"Organization","name":"AutoSPF","url":"https://autospf.com"},"sameAs":["https://www.linkedin.com/in/bradslavin"]},"publisher":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com","logo":{"@type":"ImageObject","url":"https://autospf.com/images/autospf-logo.png"},"description":"Automatic SPF flattening and email authentication management. Resolve SPF lookup limits, flatten SPF records, and maintain email deliverability across all your domains.","parentOrganization":{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138883901","name":"DuoCircle LLC","url":"https://www.duocircle.com","sameAs":["https://www.wikidata.org/wiki/Q138883901","https://www.crunchbase.com/organization/duocircle-llc","https://www.linkedin.com/company/duocircle","https://github.com/duocircle"],"subOrganization":[{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138898167","name":"DMARC Report","url":"https://dmarcreport.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897474","name":"AutoSPF","url":"https://autospf.com"},{"@type":"Organization","@id":"https://www.wikidata.org/wiki/Q138897912","name":"Phish Protection","url":"https://www.phishprotection.com"}]},"sameAs":["https://www.wikidata.org/wiki/Q138897474","https://www.linkedin.com/company/autospf","https://x.com/autospf01","https://www.g2.com/products/autospf/reviews"],"contactPoint":{"@type":"ContactPoint","contactType":"customer support","url":"https://autospf.com/contact-us/"},"knowsAbout":["SPF Record Flattening","Sender Policy Framework","Email Authentication","DNS Management","DMARC","DKIM"]},"mainEntityOfPage":{"@type":"WebPage","@id":"https://autospf.com/blog/microsoft-patch-tuesday-gitlab-flaw-exploited-shinyhunters-used-claude/"},"articleSection":"intermediate","keywords":"","image":{"@type":"ImageObject","url":"https://media.mailhop.org/autospf/spf-lookup-2501-1789564164362.jpg","caption":"Microsoft Patch Tuesday Cybersecurity Developments"},"speakable":{"@type":"SpeakableSpecification","cssSelector":[".answer-block","h1"]}}
```

```json
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://autospf.com/"},{"@type":"ListItem","position":2,"name":"Blog","item":"https://autospf.com/blog/"},{"@type":"ListItem","position":3,"name":"Intermediate","item":"https://autospf.com/intermediate/"},{"@type":"ListItem","position":4,"name":"Microsoft Patch Tuesday , GitLab Flaw Exploited, ShinyHunters Used Claude ","item":"https://autospf.com/blog/microsoft-patch-tuesday-gitlab-flaw-exploited-shinyhunters-used-claude/"}]}
```
