Microsoft released its September 2026 security updates covering 973 vulnerabilities across its ecosystem, including 113 marked critical. Reporting also highlights that multiple flaws are already being exploited in the wild, increasing pressure on teams to move beyond “patch later” triage. The overall theme: the patch volume is at an all-time high, so organizations need automation, prioritization, and validation pipelines that can keep up.
Source: Cisco Talos
ClickFix campaign uses Google-hosted C2 via Visualization API to steal cryptocurrency
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command-and-control (C2). The technique pulls obfuscated JavaScript from a publicly accessible Google Sheets document and injects it into the victim’s browser session, blending C2 behavior into normal web activity. Defenders should treat “legitimate hosting” abuse as a warning sign and enhance controls around browser-script injection patterns and suspicious Sheets/API usage.
Source: Cisco Talos
ClearFake WebDAV infection chain delivers Amatera stealer and ZigCryptoStealer
Cisco Talos reports on a WebDAV-based infection chain tied to cryptocurrency and credential theft operations. While the activity does not appear narrowly targeted, the chain uses Amatera as a primary payload and follows with additional theft capabilities, indicating a repeatable criminal tradecraft. Organizations should review WebDAV exposure, monitor for unusual WebDAV method usage, and correlate those events with downstream credential-theft indicators.
Source: Cisco Talos
ChatGPT cross-account flaw: attackers can read victims’ Gmail via a hidden channel
Check Point Research demonstrated a method to break the assumed isolation between separate ChatGPT accounts by using an internal service never meant to handle user data. In their proof of concept, a “planted” instruction caused ChatGPT to quietly access a victim’s connected Gmail and route data to another account through the covert channel. Beyond the immediate risk, this is a stark reminder that AI “assistant integration” expands the blast radius of account boundaries.
Source: Check Point Blog
WeChat “zero-click” worm can hijack accounts via a single incoming call
Calif researchers described weaponized behavior they call “WeWorm,” which spreads through WeChat calls without requiring user interaction or the victim answering. The worm can compromise the WeChat account and use saved contacts to propagate rapidly, potentially scaling to large numbers of devices within hours. Because the attack hinges on contact graphs and call behavior, defenders should monitor for unusual account session activity and suspicious outbound contact-based messaging patterns.
Source: Help Net Security
N-able N-central pre-auth auth bypass: remote unauthenticated attackers can create admin accounts
Rapid7 describes two vulnerabilities in N-able N-central that, when chained, allow a remote unauthenticated attacker to bypass authentication and create an attacker-controlled System administrator account. The write-up emphasizes a complex routing/access-control discrepancy involving proxy headers and local-only SOAP interfaces, followed by an authentication weakness in how legacy two-factor logic operates. Patch urgency is high for on-prem deployments: organizations should prioritize N-central hotfixes immediately and hunt for unexpected new admin users or anomalous N-central session activity.
Source: Rapid7
AI threats accelerate: Google reports adversaries moving from prompting to agentic workflows
Google’s Threat Intelligence Group (GTIG) reports that adversaries are transitioning from basic prompting to agentic AI and automation across the attack lifecycle. In Q2 2026, GTIG observed attackers compromising cloud resources and then planning, building, and executing large-scale credential harvesting campaigns in under six hours using multi-agent instruction sets. For defenders, this translates into less “dwell time” for detection and response—so security monitoring, access governance, and incident workflows must be faster and more automated.
Source: Google Cloud TI (GTIG)
You May Also Be Interested In...
September 2026 Microsoft Patch Tuesday: record 973 vulnerabilities
MikroTik router flaws allow takeover without a password
PoisonedRefresh: fileless Linux rootkit injects PHP web shells into F5 BIG-IP memory