Confidential ยท 09 Sep 2026
๐ก๏ธ Daily Cybersecurity Briefing โ 2026-09-09 (Wednesday)¶
Window: last 24โ48h (Sep 8โ9). Severity: ๐ด CRITICAL ยท ๐ก HIGH ยท ๐ข MEDIUM.
Threat level GUARDEDVictims L30D 82Top actor QilinM&A L30D $94.5M
Number of the day966vulnerabilities fixed in Microsoft's September Patch Tuesday, its largest monthly release on record (SecurityWeek and CrowdStrike count 974 including out-of-band fixes issued earlier in the month; tallies vary by what each tracker bundles in). Two of the 966 were zero-days already under active exploitation and both landed in CISA's KEV catalog the same day the patches shipped. BleepingComputer ยท SecurityWeek
๐ผ M&A ACTIVITY¶
No new cybersecurity M&A deals confirmed in the Sep 8โ9 windowMediumCybersecuritythe market stays quiet; nothing surfaced via SecurityWeek or Return on Security.
L30D summary (Aug 10 โ Sep 9): 6 deals tracked, $712.5M+ in disclosed value โ unchanged from yesterday's window (no deals fell out or in at the edges). Biggest: Munich Re (via HSB) โ At-Bay $575M (cyber insurtech / SME MDR); Datavault AI โ CyberCatch Holdings $94.5M all-cash (AI-enabled compliance); Fortinet โ Virtue AI (undisclosed, AI-security tooling). Consolidation theme unchanged: insurers buying prevention capability rather than just underwriting risk, and platform vendors filling out the CTEM/AI-security stack via bolt-on acquisitions. SecurityWeek M&A Tracker
โ ๏ธ CRITICAL BREACHES & INCIDENTS¶
McKesson/ShinyHunters โ Sep 9 data-publication deadline is today; no public resolution confirmed as of this writing.CriticalHealthcare & Life SciencesThe Sep 1 contact deadline passed without engagement, and ShinyHunters' operative threat is to publish the claimed haul today. ๐ฅ The 284M-record figure remains the attacker's own characterization of raw Salesforce/Snowflake rows, not a unique-patient count; McKesson has not disclosed a number. A publication today would be the largest US healthcare breach-notification event of 2026. SecurityWeek ยท CyberScoop
ShinyHunters claims a second, unrelated US government-adjacent target within the same week: Florida's DAVID driver/vehicle database, ~200,000 records, via a password-reset flaw.HighGovernment & Public SectorThe group told BleepingComputer it compromised accounts belonging to DMV employees and an FBI agent, then pulled records by iterating IDs; as proof it released a screenshot of Jeffrey Epstein's DMV record. Florida's Highway Safety and Motor Vehicles agency (FLHSMV) has not confirmed the claim. ๐ฅ Unverified DLS-style claim โ the leak-site deadline is Sep 11. A confirmed compromise of a law-enforcement lookup database would raise both public-safety and Driver's Privacy Protection Act liability questions distinct from a standard PII breach. BleepingComputer
Manchester Airports Group data actually published Sep 8 after MAG refused FulcrumSec's ransom demand โ confirms the 8.8M-person scope first reported Sep 4.HighTransportation & LogisticsRoughly 550GB went up, including car-park, lounge and Fast Track booking records and in-terminal Wi-Fi sign-ups across Manchester, Stansted and East Midlands; MAG has confirmed operations were unaffected. No new tracker entry (already logged Sep 4) โ this is confirmation the threat was executed, not a new incident. SecurityWeek
Mathspace discloses breach of ~1.08M students, parents and staff across Australia and New Zealand after attackers exploited an unpatched Metabase SQL-injection flaw in an internal reporting tool.HighEducationUnauthorized access dates back to Aug 10; the Australian reporting database was downloaded Aug 27. Exposed: names, emails, usernames, country/timezone and account metadata โ Mathspace says no passwords, academic records or API credentials were taken. The same Metabase SQLi flaw already hit Framework, Tally and Kilo Code in August; this is the fourth confirmed victim of the same unpatched-component pattern. Help Net Security ยท BleepingComputer
๐ CRITICAL VULNERABILITIES¶
Microsoft's September Patch Tuesday ships two actively-exploited zero-days among a record 966 fixes โ both privilege-escalation, both added to KEV same-day.CriticalTechnology & SoftwareCVE-2026-85880 (heap-based buffer overflow in Windows ALPC) and CVE-2026-81963 (improper link resolution in the Windows Update Stack) both let a local attacker reach SYSTEM. 105 of the 966 are rated Critical, 81 of those remote-code-execution, and 20 are flagged wormable (unauthenticated RCE). Patch on the normal emergency cadence, prioritizing internet-facing and shared-services hosts first. BleepingComputer ยท CyberScoop
SAP discloses "OVERPASS," a CVSS 10.0 buffer overflow in SAP Kernel's Extended Passport Protocol library โ Onapsis estimates 10,000+ internet-facing SAP systems are exposed.CriticalTechnology & SoftwareProfessional & Business ServicesCVE-2026-44756 lets an unprivileged attacker run arbitrary OS commands with administrative privileges, fully compromising the SAP host and the business data on it. No in-the-wild exploitation confirmed yet, but the flaw affects a wide kernel-version range (7.22 through 9.20) and internet exposure at this scale makes it a KEV-catalog candidate the moment PoC code surfaces. Patch immediately rather than wait for that signal. BleepingComputer ยท cybersecuritynews.com
Yesterday's N-able N-central and Adobe Commerce/Magento zero-days both formalized into CISA's KEV catalog Sep 8 โ Magento's flaw finally has a CVE (CVE-2026-75650).HighTechnology & SoftwareConsumer & RetailNo new technical detail beyond what was reported Sep 8 (see yesterday's briefing); this is the federal-mandate follow-through: both are now subject to BOD 26-04's risk-tiered remediation clock, which can compress to as little as three calendar days for flaws that grant full device control on exposed assets. CISA KEV
MikroTik ships official RouterOS fixes (Sep 3, surfaced in trade press Sep 8) for the "MikroTrick" SSH chain, plus a second critical flaw (CVE-2026-86060, CVSS 9.2) not previously disclosed.MediumTechnology & SoftwareUpdate to 7.25beta3, 7.24.2, 7.23.4 or 6.49.21. Devices compromised before patching remain compromised after patching โ CERT Polska's guidance from earlier this week still applies. SecurityWeek ยท CERT Polska
๐จ INTELLIGENCE AGENCY ALERTS & POLICY¶
NSA, CISA and the FBI jointly name six Chinese AI companies โ DeepSeek, Alibaba, Moonshot AI, MiniMax, StepFun and Z.AI โ as running "industrial-scale" distillation campaigns against US frontier models.HighTechnology & SoftwareCybersecurityAdvisory AA26-251A (published Sep 8) says the campaigns have run since at least late 2024, extracting billions of tokens across millions of exchanges from Claude, GPT, Gemini and Grok variants to accelerate Chinese model development. This is the first time these three agencies have formally attributed AI-model IP extraction to named commercial entities rather than treating it as a generic training-data question โ and it lands one day before scheduled US-China AI talks ahead of the Sep 24 Trump-Xi summit. CISA AA26-251A
๐ THREAT ACTOR & CAMPAIGN ACTIVITY¶
ShinyHunters runs the same playbook twice in one week against very different targets โ a Fortune 10 healthcare distributor and a state DMV โ underscoring that its methodology (social-engineer or password-reset your way to a data store, then extort) doesn't require a specific tech stack.HighGovernment & Public SectorHealthcare & Life SciencesMcKesson via voice-phished Okta SSO into Salesforce/Snowflake; Florida DAVID via a password-reset flaw. See Intelligence Agency Alerts above for the group's other current AI-related news cycle context. BleepingComputer
No major new DLS victim clusters beyond ongoing SilentRansomGroup/Direwolf/Vexy activity already reported this weekMediumSep 8 leak-site listings on ransomware.live skew toward heavily redacted entries pending full disclosure timers; nothing meets the bar for a new named tracker entry today.
๐ GEOPOLITICS¶
Analyst lens: how this week's cyber activity maps to state strategy. Defense ยท cyber ยท economics.
The NSA/CISA/FBI distillation advisory turns AI model theft into a formal national-security cyber issue one day before scheduled US-China AI talks, not a coincidence of timing.HighTechnology & SoftwareNaming DeepSeek, Alibaba and four other commercial firms โ rather than describing generic "state-linked activity" โ gives Washington a specific, public grievance to put on the table ahead of the Sep 24 Trump-Xi summit, where AI is already the leaders' central point of friction. Treating model-weight and output extraction as a cyber-enabled economic-espionage problem (not just an IP or trade-policy one) is a framing shift that portfolio companies building on frontier-model APIs should watch: it opens the door to export-control or usage-monitoring obligations that don't exist today. CISA AA26-251A
This week's run of pre-auth RCE zero-days across N-able, MikroTik, ConnectWise, Adobe Commerce and now SAP, landing inside the same seven-day span as a record-breaking Patch Tuesday, is a capacity problem the defense industry has not priced.CriticalTechnology & SoftwareIndustrials & ManufacturingEach vendor individually is manageable; five simultaneous emergency-patch cycles across the infrastructure stack that MSPs, e-commerce operators and ERP shops all depend on is not. Security teams sized for a steady drip of monthly patching are structurally unable to absorb a week like this one without deferring something โ and attackers know which categories of infrastructure (RMM consoles, edge network gear, ERP kernels) get deferred longest because they're hardest to take offline. Insurers underwriting operational-technology and ERP-dependent businesses should be pricing patch-cycle capacity, not just patch-cycle intent. BleepingComputer
McKesson's Sep 9 deadline is the second major US healthcare extortion clock to run out this quarter, and healthcare's specific vulnerability is structural, not incidental: third-party SaaS sprawl (Salesforce, Snowflake) now sits between the industry's HIPAA obligations and its actual attack surface.HighHealthcare & Life SciencesVoice-phishing a help desk into resetting SSO credentials bypasses most of the technical controls healthcare compliance programs are built around, because the weak point is a human process, not a system. Expect this incident, if data publishes today, to accelerate the same vendor-risk-audit conversation already underway after Trezor/ShipMonk โ but for identity providers and CRM/data-warehouse vendors specifically rather than fulfillment partners. SecurityWeek
A state DMV database breach claim, proven in part with a dead-and-notorious public figure's own record, is a reminder that government data has a specific credibility problem attackers exploit deliberately.MediumGovernment & Public SectorUsing Jeffrey Epstein's DMV file as proof-of-breach is a calculated choice: it is independently verifiable and generates press attention no ordinary citizen's record would. Government agencies holding law-enforcement-grade lookup data (DMV, voter rolls, benefits systems) should assume any high-profile individual's record in their systems is a standing target for exactly this kind of attention-maximizing proof-of-hack move, independent of the record's actual sensitivity. BleepingComputer
M&A activity
Socure โ Fravityโ
Brinqa โ PlexTracโ
Munich Re (via HSB) โ $575Mโ
Fortinet โ Virtue AIโ