Microsoft and Google released security updates this week to fix a record-breaking number of vulnerabilities across their products (Microsoft - over 900 flaws, Google - more than 200 issues), including three zero-day vulnerabilities actively exploited in the wild.
Two exploited Windows flaws are CVE-2026-81963 and CVE-2026-85880, both of which are privilege escalation issues that allow a local attacker to execute code with SYSTEM privileges.
The third zero-day is CVE-2026-87491 in the Chrome browser, described as an out-of-band issue in the V8 engine.
Neither Microsoft nor Google provided any details about attacks exploiting the aforementioned flaws.
Separately, cybersecurity firm Proofpoint published a report detailing BlueMoon, a previously undocumented exploit kit chaining the above-mentioned Chrome and Windows vulnerabilities. Researchers said they found several different builds of the BlueMoon exploit kit used by different threat actors. The first incident involving the exploit kit was observed in August and is likely linked to a Chinese-sponsored threat actor.
It’s worth mentioning that US cybersecurity and intelligence agencies warned that six Chinese AI companies have carried out large-scale efforts to copy knowledge from major American AI models. They allegedly used millions of API requests and billions of tokens to extract information from models made by Anthropic, OpenAI, Google, and xAI.
The companies reportedly used shared or fake accounts, cloud services, and proxy systems to bypass restrictions and detection. DeepSeek and Moonshot AI were named as the biggest offenders, with other companies including MiniMax, Alibaba, StepFun, and Z.AI also accused of targeting US AI models to improve their systems.
A threat actor, likely Russian-speaking, used hundreds of AI agents to exploit vulnerable PaperCut servers worldwide. The campaign, which began on August 31, compromised at least 440 servers across 48 countries and affected 395 organizations. The attacks exploited CVE-2026-81578 and CVE-2026-82078, both patched in August.
The attackers stole credentials from many victims and gained administrator access at some organizations. Education was the most targeted sector, with the United States experiencing the most attacks.
Cisco Talos said that three threat groups it tracks as tracked as UAT-12197, UAT-11823, and UAT-11988 exploited two critical Cisco Secure Firewall Management Center (FMC) vulnerabilities, namely CVE-2026-20079 (an authentication bypass) and CVE-2026-20316 (use of hard-coded password), to deploy web shells, steal credentials, create reverse shells and proxies. Some intrusions also deployed the Qilin ransomware and the Cyclops Blink malware. Talos linked one cluster to Qilin ransomware affiliates and another to the Sandworm (aka APT44) state-backed threat actor linked to Russia’s military intelligence agency known for its destructive attacks on Ukraine.
The US Cybersecurity and Infrastructure Security Agency (CISA) warned that ransomware groups are exploiting a critical vulnerability (CVE-2025-14733) in WatchGuard Firebox firewalls. The flaw allows attackers to remotely execute malicious code without authentication. It impacts firewalls running Fireware OS 11.x and later (including 11.12.4_Update1), 12.x or later (including 12.11.5), and 2025.1 through 2025.1.3.
The agency also added Cisco (CVE-2026-20079), Citrix NetScaler (CVE-2026-19490), and Fortinet FortiOS (CVE-2025-25249) flaws to its list of actively exploited vulnerabilities. According to SOCRadar, the latter is being exploited to deliver an AI-assisted Node.js RAT called PivotC2, designed for post-exploitation on compromised FortiGate firewalls.
N-able has released an emergency hotfix for a high-severity RCE flaw (CVE-2026-86218) affecting its N-central remote monitoring and management (RMM) platform. The vendor said that it has no evidence that the flaw is being abused, however, cybersecurity firm Huntress has flagged the vulnerability as potentially exploited.
A zero-day vulnerability in Adobe Commerce and Magento is being actively exploited to install backdoors in online stores. The vulnerability (CVE-2026-75650), dubbed StyleSmuggler, allows attackers to inject PHP code into Magento’s template system and execute it without user interaction. The attack begins by triggering a failure report, after which Magento runs the malicious code through a failed-payment email.
Threat actors are actively exploiting vulnerabilities in MikroTik RouterOS to gain full administrative control of routers with SSH services exposed to the internet. CERT-Polska said the exploitation chain combines multiple vulnerabilities. The most important flaws, according to the agency, include CVE-2026-67276 (an SSH authentication bypass), CVE-2026-86060, which allows privilege manipulation through a specially crafted username and CVE-2026-67277, which can cause memory disclosure and crashes through the bandwidth-test service.
Hackers are targeting F5 BIG-IP Access Policy Manager (APM) devices with a Linux rootkit that can hide a web shell inside running Apache processes. The implant, called ‘PoisonedRefresh,’ appears to be a second-stage payload deployed after attackers exploited a critical RCE flaw (CVE-2025-53521) affecting F5 BIG-IP systems.
Modified ScreenConnect clients are being used in attacks to spread malware to other computers. The attacks began in late August and appear to start with social engineering. In one incident, a hacker posing as tech support convinced a victim to use Windows Quick Assist, giving the attacker remote access to the machine.
Security researchers at Elastic Security Labs have discovered four previously undocumented Windows tools linked to the new Revstealer info-stealing malware family. The tools, named ProManager, WinUpdate, SoftManager, and LockAppHost, remain on infected computers even after Revstealer deletes itself. The malware is mainly spread through game-cheat websites and fake or pirated software. Researchers also found evidence of the malware being promoted through hijacked YouTube channels using AI-generated videos.
Malicious actors are abusing Google Play’s Early Access feature to promote fake apps that promise money, rewards, casino winnings, or premium content. The apps are often advertised on social media, like TikTok and Facebook, with misleading ads, including AI-generated celebrity deepfakes.
A security analysis found that nearly 1 in 10 publicly accessible LiteLLM servers had weak or no authentication. Out of 3,074 servers scanned, 294 accepted a default or empty master key, potentially allowing unauthorized access.
Check Point Research has discovered a security issue that could allow attackers to use a victim’s ChatGPT session to carry out hidden tasks using the victim’s data, tools and connected apps. In a proof of concept, researchers used the method to access email data from a victim’s connected Gmail account and send the information back to an attacker. The victim could still receive a normal answer to their question without seeing the hidden activity.
Threat actors are increasingly using artificial intelligence (AI) to speed up cyberattacks, with one financially motivated group carrying out a large-scale credential harvesting campaign in less than six hours. Google said that threat actors are targeting proprietary AI research, models, and related intellectual property and experimenting with LLMs to enhance vulnerability research, exploit development, reconnaissance, social engineering, intelligence gathering, and operational automation.
Anthropic reported a fourth incident where an AI model broke into real third-party systems. The incident happened in January 2026 and involved an early version of Claude Opus 4.6 that continued its task instead of stopping. Anthropic notified the affected organizations but did not provide more details. The disclosure follows three similar incidents reported in July 2026. Anthropic said it reviewed about 481 million AI transcripts afterward but found no other cases of similar or worse severity.
VPN service provider Surfshark said hackers accessed an internal test server because of a configuration error. The server exposed some system configurations, code history, and build credentials, but no customer data or sensitive VPN information was accessed. Production systems and customer privacy were not affected, the provider said.
JetBrains disclosed that attackers breached its environment by exploiting a critical TeamCity vulnerability (CVE-2026-63077) that can allow unauthenticated attackers to bypass authentication and execute commands on vulnerable TeamCity servers. JetBrains said the threat actors accessed a 2024 Cadence server backup containing credentials, configuration data, logs and other information. They may also have accessed user data, AWS credentials, S3 storage and source code synchronized from PyCharm projects.
Oleksii Lytvynenko, a 44-year-old Ukrainian national, was sentenced in the US to four years in prison for his involvement in the Conti ransomware scheme. From 2020 to 2022, Conti attacked more than 1,000 victims worldwide, stealing data and demanding ransom payments. The FBI estimates that victims paid more than $150 million. Lytvynenko admitted to helping the group develop malware and was found with stolen data from both US and foreign victims.
36-year-old Russian web developer Sergei Filimonov is facing charges in the US after being extradited from Georgia. He is accused of participating in a large-scale cyber-fraud scheme that used fake bank websites and sponsored search links to steal customers’ login credentials. Prosecutors allege the stolen information was used to access bank accounts and make unauthorized wire transfers, with Filimonov allegedly maintaining the infrastructure and databases containing more than 5,000 stolen credentials.
French authorities arrested two people suspected of cyber-attacks against the tax agency and other French organizations. An 18-year-old was placed in pretrial detention, while a second suspect under 16 was released after his devices were examined. The investigation concerns the theft of tax and personal data from more than 600,000 people.
Malone Lam, a Singaporean citizen, pleaded guilty in the US to helping lead a cybercrime group that stole more than $245 million in cryptocurrency. The group used social engineering to access victims’ accounts and wallets, then spent the stolen money on luxury goods and entertainment. Lam is awaiting further court proceedings.
US authorities disrupted Xinbi Guarantee, a Telegram marketplace linked to cyber scams, money laundering and human trafficking. The marketplace helped criminals buy scam services and move illegal funds. Authorities seized or froze more than $52 million in cryptocurrency. In addition, the US Treasury Department announced sanctions against Xinbi and two businesses accused of helping support the marketplace.