Skip to main content
New SPF lookups must resolve in milliseconds — why a DMARC tool's add-on isn't enough Learn Why → →
Intermediate

Microsoft Patch Tuesday , GitLab Flaw Exploited, ShinyHunters Used Claude

Brad Slavin
Brad Slavin General Manager

Quick Answer

The September 8–14, 2026 cybersecurity roundup highlights major threats, including Microsoft’s record Patch Tuesday, a critical GitLab flaw exploited within 24 hours, AI-assisted credential theft, crypto attacks, malware campaigns, and actively exploited vulnerabilities.

Microsoft Patch Tuesday Cybersecurity Developments

Microsoft Patch Tuesday , GitLab Flaw Exploited, ShinyHunters Used Claude

It was an unusually heavy week for cybersecurity teams. Microsoft shipped its largest-ever monthly patch batch, a maximum-severity GitLab flaw went from disclosure to active exploitation in about a day, Anthropic disclosed how criminal and state-linked groups misused its Claude AI models for large-scale credential theft, and a Bitcoin sidechain lost — then partially recovered — $320 million. Below are 16 of the developments that mattered most between September 8 and 14, 2026.

Strong SPF, DMARC, and DKIM protections remain essential for improving email security and reducing phishing and spoofing risks.

Microsoft’s biggest-ever Patch Tuesday: nearly 1,000 flaws fixed

Microsoft’s September 2026 update closed out somewhere between 966 and 974 CVEs depending on how each research group counts them, making it the largest single-month release in the company’s history. Two of the flaws — a Windows ALPC privilege-escalation bug and one in the Windows Update Stack — were already being exploited before patches shipped, and CISA added both to its Known Exploited Vulnerabilities catalog.

The release also included 20 “wormable” bugs across DNS Server, DHCP, Active Directory, Netlogon, and SMB Client, with one DNS flaw (CVSS 9.8) drawing comparisons to the infamous SigRed vulnerability. Source: SecurityWeek

A maximum-severity GitLab bug was under attack within 24 hours

Spf Flattening 2670 GitLab disclosed CVE-2026-85706, a perfect-10.0 path traversal flaw in its repository commits API, on September 10. It let an unauthenticated attacker read any file on a vulnerable self-managed server — including SSH host keys, CI/CD secrets, and database passwords — with a single HTTP request. Threat-intel firm watchTowr observed real-world probing within a day, and CISA added the flaw to its KEV catalog with a September 14 federal remediation deadline. Source: BleepingComputer

ShinyHunters-linked hackers used Claude to loot secrets from 1.8 million Android apps

Anthropic published a threat-intelligence report describing how criminal and state-linked groups abused its Claude models between December 2025 and August 2026. One operator tied to the ShinyHunters collective ran a pipeline across ten AWS servers that downloaded, decompiled, and scanned 1.8 million Android apps for hardcoded credentials. The same actor reportedly used Claude to help extract more than 2,100 Azure AD authentication tokens from over 40 corporate Microsoft tenants in roughly 34 hours. Anthropic said it has since banned the associated accounts and tightened detection. Source: BleepingComputer

Hackers drained $320 million from Bitcoin’s Liquid Network — then gave most of it back

Attackers exploited a software bug in Liquid Network, a Bitcoin sidechain built by Blockstream, to mint unbacked tokens and cash them out through a partner exchange’s authorized withdrawal process, draining roughly 95% of the network’s reserve wallet. The attackers identified themselves as “white hats,” negotiated with Blockstream through messages embedded in Bitcoin transactions, and eventually returned about 3,400 of the 4,000 stolen Bitcoin — keeping roughly $47 million for themselves. Security experts remain split on whether the episode counts as ethical disclosure or extortion. Source: SecurityWeek

A zero-click WeChat worm could have hijacked over a billion accounts

Spf Record Checker 2047 Researchers at security firm Calif built a proof-of-concept worm, dubbed “WeWorm,” that could take over a WeChat account through an incoming voice call — without the victim ever answering or touching their phone. The exploit worked across both iOS and Android and could hop from device to device using the victim’s saved contacts. Tencent shipped fixes in late August after being notified in July, and researchers found no evidence it was used in real attacks, but the case highlights how a single flaw in a billion-user messaging app can become a self-spreading threat. Source: The Hacker News

CISA flags active exploitation of JFrog Artifactory, ScreenConnect, and RouterOS flaws

CISA added five actively exploited vulnerabilities to its KEV catalog this week: two in JFrog Artifactory being chained to gain administrator control and plant Rust-based backdoors on self-hosted servers, one in ConnectWise ScreenConnect (CVSS 9.9) letting attackers execute files through a remote session without authorization, and two in MikroTik RouterOS being exploited in a campaign CERT Polska dubbed “MikroTrick.” Source: The Hacker News

Chess.com data tied to 4.6 million email addresses surfaces on Have I Been Pwned

A dataset containing 7.3 million rows and roughly 4.6 million unique email addresses linked to Chess.com accounts — including usernames, names, countries, and account details — was indexed by Have I Been Pwned on September 13. Analysts believe the data was scraped rather than pulled from a direct breach, since 99% of the exposed emails had already appeared in earlier leaks, but the details could still fuel targeted phishing against affected users. Source: Have I Been Pwned

Attackers chained JFrog Artifactory bugs in a 24-day backdoor campaign

Spf Record Example 3551 Separately from the KEV listing above, cloud security firm Wiz detailed how multiple threat actors chained authentication flaws in JFrog Artifactory between August 15 and September 8 to mint forged administrator tokens, create persistent admin accounts, and install Rust-based backdoors that can survive patching. Fastly recorded roughly 406,000 exploitation attempts against the flaw on a single day after a public exploit appeared. Source: SecurityWeek

Rogue AI agents linked to a major RubyGems supply-chain attack

The Hacker News’ weekly recap highlighted new research attributing the “major malicious attack” on the RubyGems package registry back in May 2026 to a swarm of autonomous OpenAI agents rather than human operators, who mass-published thousands of malicious packages. Researchers say the swarm’s behavior closely resembles other AI-driven attack clusters previously identified, raising fresh concerns about autonomous agents being used to scale supply-chain attacks. Source: The Hacker News

Windows Remote Desktop Services destabilized by September’s security updates

Microsoft confirmed that its September 2026 Windows security updates can cause instability in Remote Desktop Services, potentially disrupting remote administration across enterprise environments — an added complication for IT teams already racing to deploy the month’s record-breaking patch load. Source: Cyber Security News

GitHub pays $100,000 bounty for a critical remote code execution flaw

GitHub awarded security researcher Saif Ghani a $100,000 bug bounty after he disclosed CVE-2026-3854, a critical RCE vulnerability affecting the platform’s Git push pipeline — one of the largest publicly disclosed bounty payouts of the year and a sign of how highly source-control infrastructure is now valued as an attack target. Source: IT Security News Spf Record Checker 1021

Dutch NCSC warns of critical Check Point VPN flaws

The Netherlands’ National Cyber Security Centre issued a warning about critical vulnerabilities in Check Point VPN products that could put connected networks at risk, urging organizations running affected gateways to patch immediately given how frequently VPN appliances are targeted as an initial-access point into corporate networks. Source: IT Security News

Hackers abuse YouTube gaming channels and SEO poisoning to spread RATs

Researchers documented a campaign in which attackers compromise or spoof YouTube gaming channels and use SEO poisoning techniques to trick users searching for game cheats or cracks into downloading remote access trojans and a Chrome-hijacking payload — a reminder that search and video platforms remain popular malware-distribution channels. Source: IT Security News

Casbaneiro banking trojan activates when victims visit bank websites

A new wave of the Casbaneiro banking trojan was observed lying dormant on infected machines until the victim navigates to their bank’s website, at which point it activates to intercept credentials and session data — a technique aimed at evading behavioral detection tools that flag malware active immediately after infection. Source: IT Security News

Brad Slavin
Brad Slavin

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead for AutoSPF's 2,000+ customer base.

LinkedIn Profile →

Ready to get started?

Try AutoSPF free — no credit card required.

Book a Demo