Current Threat
Landscape

Active threats, critical vulnerabilities, and emerging attack patterns -- monitored continuously and summarized for security practitioners and business leaders.

LIVE FEED
UPDATED: September 10, 2026 at 7:01 AM
THREATS: 7
This has been one of the most operationally intense patch weeks in recent memory. Microsoft's September 2026 Patch Tuesday addressed a record-breaking 974 CVEs, including two actively exploited Windows privilege-escalation zero-days (CVE-2026-85880 and CVE-2026-81963) that CISA has already added to its Known Exploited Vulnerabilities catalog, with federal agencies given until September 22 to remediate. Simultaneously, Adobe rushed an emergency hotfix for CVE-2026-75650 (StyleSmuggler), a CVSS 10.0 unauthenticated remote code execution zero-day in Magento and Adobe Commerce that attackers exploited for three days before a patch existed, dropping Rust-based Linux backdoors and PHP web shells on compromised storefronts. Security teams should treat any Magento or Adobe Commerce instance running versions 2.4.4 through 2.4.9 as potentially compromised rather than simply unpatched, and credential rotation is mandatory alongside applying the hotfix. On the data breach front, two developments demand board-level attention. Aesto Health, a healthcare data migration and archiving vendor, has disclosed that a December 2025 intrusion into its AWS infrastructure exposed the protected health information of 9,540,683 individuals across at least 36 covered-entity healthcare clients, making it the second-largest confirmed U.S. healthcare breach of 2026. Separately, the ShinyHunters extortion group is claiming it abused a password-reset vulnerability in Florida's DAVID law-enforcement driver records platform to steal over 200,000 records, with a public release deadline set for September 11. Florida authorities have not confirmed the breach as of this writing, but the group's documented technical access method is specific and credible enough to warrant treating the claim seriously. Beyond individual incidents, two systemic trends require strategic attention. Device code phishing volume is up 1,500% in 2026 according to Dark Reading analytics, and vishing campaigns targeting Microsoft 365 and SaaS platforms have doubled, underscoring that identity-based attacks remain the primary initial access vector. The EU Cyber Resilience Act's vulnerability reporting requirements formally take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws, a compliance trigger that will require immediate process changes at many organizations. CISOs should confirm their incident response runbooks and vendor communication procedures are updated before the business day begins tomorrow.
FILTER:
CRITICAL
CVE-2026-75650 (StyleSmuggler) - Adobe Commerce / Magento Open Source RCE Zero-Day
A CVSS 10.0 unauthenticated remote code execution zero-day in Adobe Commerce and Magento Open Source (versions 2.4.4 through 2.4.9), dubbed StyleSmuggler by Dutch e-commerce security firm Sansec, was actively exploited starting September 4, three days before Adobe released emergency hotfix APSB26-146. Attackers abuse Magento's template-processing engine to inject malicious PHP via a failed-payment email flow, requiring no credentials or user interaction, and have deployed a self-updating Rust-based Linux backdoor and PHP web shells on compromised storefronts. CISA added the CVE to its KEV catalog on September 8 with a federal remediation deadline of September 11; because the hotfix does not clean an already-compromised store, patching must be accompanied by full forensic investigation and rotation of all protected credentials.
AFFECTS: Adobe Commerce 2.4.4-2.4.9, Adobe Commerce B2B 1.3.3-1.5.3, Magento Open Source 2.4.4-2.4.9; approximately 111,000+ active Magento stores globally, including roughly one in five of the top-1,000 U.S. retailers running Adobe Commerce SOURCE: BleepingComputer / SecurityWeek / CISA KEV 2026-09-07
Vulnerability
CRITICAL
Microsoft September 2026 Patch Tuesday - CVE-2026-85880 and CVE-2026-81963 Exploited Zero-Days
Microsoft's September 2026 Patch Tuesday addressed a record 974 CVEs, including two actively exploited Windows privilege-escalation zero-days confirmed by CISA. CVE-2026-85880 is a heap buffer overflow in Windows Advanced Local Procedure Call (ALPC) allowing AppContainer sandbox escape to SYSTEM-level privileges, while CVE-2026-81963 is an improper link-resolution flaw in the Windows Update Stack that also elevates to SYSTEM. Security researchers note that CVE-2026-81963 is already being used as the privilege-escalation step in ransomware chains following phishing-based initial access. The release also includes 20 potentially wormable vulnerabilities and patches for over 22,000 unpatched corporate Exchange servers, making this the highest-priority Patch Tuesday in years.
AFFECTS: All supported Windows client and server versions; Windows Update Stack; Windows ALPC; Microsoft Exchange Server; Microsoft Office 2016 and later; SharePoint Server SOURCE: SecurityWeek / The Record / BleepingComputer 2026-09-09
Vulnerability
CRITICAL
Aesto Health AWS Data Breach - 9.54 Million Patient Records Exposed
Aesto Health, a Birmingham, Alabama-based healthcare data migration and archiving vendor, disclosed that unauthorized access to a portion of its Amazon Web Services infrastructure between December 2 and December 18, 2025, exposed the protected health information of 9,540,683 individuals across at least 36 covered-entity healthcare clients. Exposed data includes names, dates of birth, medical records, health insurance information, driver's license numbers, financial account details, taxpayer IDs, and Social Security numbers for a subset of individuals. The breach is the second-largest confirmed U.S. healthcare data breach of 2026, behind only the 15-million-record DentaQuest incident, and illustrates the cascading risk when a single vendor holds data on behalf of dozens of downstream healthcare providers.
AFFECTS: U.S. healthcare sector; 36+ covered-entity healthcare providers including VillageMD, Everside Health, Marana Health, and Together Women's Health; 9,540,683 patients SOURCE: BleepingComputer / The Record / HIPAA Journal 2026-09-02
Data Breach
HIGH
ShinyHunters Claims Breach of Florida DAVID DMV Law Enforcement Database
The ShinyHunters extortion group claims it exploited a password-reset vulnerability in DAVID, Florida's Driver and Vehicle Information Database used by law enforcement and criminal justice officials, to compromise accounts belonging to DMV employees and reportedly an FBI agent, then enumerate and exfiltrate over 200,000 driver records starting September 3. The group set a public data release deadline of September 11, 2026, and published a record as proof. The alleged attack vector, a credential takeover via a broken password-reset function, has not been confirmed by Florida authorities or the FBI as of September 8, but the specificity of the claimed method and the nature of the exfiltrated data, including photos, signatures, license details, and vehicle records, makes the threat credible and high-urgency.
AFFECTS: Florida Department of Highway Safety and Motor Vehicles (FLHSMV); DAVID law enforcement driver records platform; approximately 200,000 Florida drivers; state and federal law enforcement agencies with DAVID access SOURCE: BleepingComputer / CyberInsider 2026-09-07
Data Breach
HIGH
PEEP Post-Exploitation Toolkit Converts Chrome and Edge into OS-Level Backdoors
SOCRadar researchers disclosed PEEP, a Chromium-based post-exploitation framework disguised as a benign 'Smart Bookmarks' browser extension that, once an attacker has initial access to a Windows or Linux system, installs silently into Chrome and Edge profiles by forging Chromium's own Secure Preferences integrity values and bypassing Web Store validation entirely. A native-messaging bridge extends the toolkit from the browser into host-level command execution, file management, session hijacking, credential theft, and browsing-history exfiltration, with the agent polling a C2 server every 30 seconds. PEEP is derived from the open-source RedExt red-teaming framework and adds five independent persistence mechanisms, making it resistant to standard extension removal and positioning it as a powerful second-stage tool in enterprise intrusions.
AFFECTS: Enterprises running Google Chrome or Microsoft Edge on Windows and Linux; any environment where an attacker achieves initial access, including through phishing, credential theft, or exploitation of other vulnerabilities SOURCE: The Hacker News / WIU Cybersecurity Center 2026-09-07
Malware
HIGH
Device Code Phishing Up 1,500% and Vishing Doubles in 2026 Targeting Microsoft 365 and SaaS
Dark Reading analytics confirm that device code phishing has surged 1,500% in 2026, and vishing attacks using fake IT help desk calls to steal Microsoft 365 session tokens have doubled over the same period. Threat hunters have detailed a widespread campaign cluster combining IT help desk vishing, adversary-in-the-middle token theft, and residential-proxy sign-ins to compromise Microsoft 365 and other SaaS platforms, bypassing MFA and enabling immediate data theft and extortion. The campaign specifically targets executives, using AitM proxies to intercept authentication flows in real time, meaning traditional password-based controls and even standard MFA provide insufficient protection without phishing-resistant authentication methods.
AFFECTS: Microsoft 365 tenants across all sectors; SaaS platforms using OAuth-based authentication; organizations relying on push-notification MFA or SMS-based second factors; C-suite executives and high-value account holders SOURCE: Dark Reading / WIU Cybersecurity Center 2026-09-07
Phishing
INFO
EU Cyber Resilience Act Vulnerability Reporting Requirements Take Effect September 11
The EU Cyber Resilience Act's mandatory vulnerability reporting requirements formally take effect September 11, 2026, requiring software manufacturers and vendors selling into the EU market to report actively exploited vulnerabilities to ENISA within 24 hours of discovery and to submit a more detailed notification within 72 hours. Organizations that have not updated their vulnerability disclosure processes, PSIRT workflows, and vendor communication chains to meet these timelines face potential regulatory action. The requirements land at the same moment NIST is scaling back NVD enrichment to focus only on KEV-listed, U.S. government, and critical-software CVEs, widening the gap between what is publicly enriched and what organizations must report, and increasing dependence on internal vulnerability intelligence capabilities.
AFFECTS: All software vendors, manufacturers, and importers selling products with digital elements into the EU market; security operations and PSIRT teams globally; organizations relying on NVD as a primary enrichment source SOURCE: BleepingComputer / aikido.dev / Black Duck Blog 2026-09-10
Compliance