ScrutinEyes · 2026-10-04
The tools that manage everything became the way in: The Week in AI-Security, Sep 8–14, 2026
A record Patch Tuesday nobody counts the same way, one exploit kit behind both Chrome zero-days, Anthropic names the crews weaponizing its models — and Revolut hands passports to a fake government request.
Editor’s note: This issue covers Sept 8–14 and is being published late, on Sept 23, as a web-only archive issue. We rechecked the time-sensitive claims on Sept 22 and updated them inline. The RDS bug is now fixed, most of the KEV deadlines mentioned have passed, and Revolut’s count has been reported.
The through-line
Strip out the noise and this week’s incidents share an address: the management plane. The systems whose whole job is to administer other systems — RMM platforms, artifact repositories, routers, firewalls, the patch pipeline itself, even the channel governments use to demand customer data — were where attackers went, because compromising the thing that manages a fleet beats compromising the fleet one box at a time. Running underneath it: the AI layer keeps hardening from speculation into case files. Anthropic published named, numbered abuse campaigns run through its own models; Proofpoint found hints of AI in the exploit kit chaining this month’s Chrome and Windows zero-days; SOCRadar says the new FortiGate RAT was likely AI-written. Notice the sourcing, though — nearly every AI-attribution claim this week is vendor-reported and hedged, and one vendor managed to say “exploited in the wild” and “no confirmations of exploitation” about the same bug in the same week. The capability trend is real. The evidence discipline hasn’t caught up. Both things are worth your attention.
Patch Tuesday sets a record — and nobody agrees what the number is
Microsoft’s September 8 release was the largest Patch Tuesday on record, fixing two actively exploited zero-days: CVE-2026-81963 in the Windows Update Stack (SYSTEM via improper link resolution) and CVE-2026-85880, a heap overflow in Windows ALPC credited to Volexity and Proofpoint — hold that name for the next item. How large is where it gets instructive: BleepingComputer counts 966 flaws, Tenable counts 964 CVEs, and SecurityWeek counts 974 — same release, three totals, because each outlet draws the line differently on republished and third-party CVEs. If the industry can’t count one vendor’s patch cycle consistently, treat every “N vulnerabilities” headline as a methodology choice, not a measurement. One practical wrinkle: the same updates broke Remote Desktop Services on Windows Server 2019–2025 — session hosts froze after disconnects. Microsoft’s September 14 out-of-band updates (KB5129238 for Server 2019, KB5129237 for Server 2022, KB5129235 for Server 2025) fix it, per BleepingComputer. Patch, then apply the out-of-band update; both zero-days are being exploited, and there’s no longer a stability excuse to wait.
BlueMoon: both Chrome zero-days and the ALPC bug turn out to be one weapon
Google shipped Chrome 153 on September 9 fixing 230 vulnerabilities, including CVE-2026-87491 — a V8 out-of-bounds write already exploited in the wild, the seventh Chrome zero-day of 2026 and the second exploited V8 flaw in under five days. Then the other shoe: Proofpoint documented “BlueMoon,” an exploit kit that chains both of those V8 zero-days with the CVE-2026-85880 ALPC escalation from Patch Tuesday — browser in, sandbox out, SYSTEM up, against fully patched machines as of late August. At least four espionage clusters deployed it, led by Violet Typhoon (APT31/TA412) from August 28, with others hitting US aerospace, NGOs, and Southeast Asian manufacturing. Proofpoint says recovered artifacts suggest the kit’s authors used AI to build it while conceding no single artifact confirms it — the right way to state that claim, and rarer than it should be. The asymmetry worth sitting with: the researcher who reported the exploited CVE-2026-87491 earned a $2,500 bounty; the kit exploiting it served at least four state-aligned operations. Update Chrome (153.0.8010.36+) and take September’s Windows cumulative — this chain needs both doors open.
Anthropic publishes the case files: state espionage, ShinyHunters, and an exploit foundry, all on rented AI
Anthropic’s September threat report is the most detailed public accounting yet of who is actually weaponizing frontier models. Three campaigns stand out: GTG-20006, Russian-speaking operators linked to Midnight Blizzard, used Claude to automate espionage workflows against 20+ organizations — including compromised email across 24+ Ukrainian government entities and the theft of 300,000+ national identity records from a North African government; GTG-50014, tied to ShinyHunters, ran an AI-assisted credential pipeline that decompiled 1.8 million Android APKs for hardcoded secrets and harvested 2,100+ Azure AD tokens across 40+ corporate tenants; and GTG-10007, likely students in Hunan province, operated what amounts to an exploit foundry — autonomous vulnerability research that surfaced more than a dozen possible zero-days against security products in a single month. In a companion finding, Anthropic says seven China-based AI labs — including Alibaba, Moonshot, and DeepSeek — ran industrial-scale distillation against Claude, up to 151 million exchanges from thousands of fake accounts paid for with stolen credit cards. Two honest caveats. First, this is the vendor reporting abuse of its own product — evidence class: reported, not independently verified, though Anthropic published IOCs that let others check. Second, the deeper structural point: right now the public record of AI abuse exists only where a lab chooses to publish it. That’s threat intelligence as editorial discretion, and it’s the actual gap standards bodies should be staring at.
The week’s KEV entries read like an MSP’s toolbar
CISA’s known-exploited additions this week were a tour of remote-management infrastructure. Five entries on September 12: two JFrog Artifactory flaws that attackers chained between August 15 and September 8 — Wiz observed persistent admin accounts, malicious Groovy plugins, and Rust backdoors on the servers that build and distribute software; ConnectWise ScreenConnect CVE-2026-84869 (CVSS 9.9), used in at least three incidents to push malicious payloads through the remote-support channel itself; and two MikroTik RouterOS flaws CERT Polska caught being chained (”MikroTrick”) to seize routers without authentication. Alongside them: N-able N-central CVE-2026-86218, a CVSS 10.0 pre-auth RCE in the platform MSPs use to manage thousands of client networks — the fourth N-central hotfix in five weeks. The epistemics here deserve their own line: N-able’s release notes say there are “no confirmations” of exploitation, its incident notice says the flaw “has been observed being exploited in the wild,” and Huntress — which has tracked N-central attacks since August — says its telemetry can’t definitively attribute new compromises to this CVE. The five September 12 entries carried federal remediation deadlines of September 13–25, per The Hacker News — all now passed except Artifactory’s (September 25) — and N-central landed on the KEV list too (added September 8, per Arctic Wolf). If you run any of these, the deadline is the signal; the narrative will sort itself out later.
PivotC2: patched in January, looted since July — and the RAT was probably AI-written
The pattern we flagged last week with Langflow has a sequel. CVE-2025-25249, a Fortinet heap overflow patched in January, is being exploited to plant “PivotC2” — a Node.js backdoor giving interactive shell, traffic tunneling, and network scanning on FortiGate devices. SOCRadar, which found the campaign, says Russian-speaking actors probed 30,000+ IP addresses and compromised 178 devices since at least July, mostly US targets, with data theft in at least two intrusions; it assesses the malware was “likely developed with the use of AI” — an assessment, note, not a demonstrated fact. CISA added the CVE to the KEV catalog on September 9 with a September 12 federal deadline, now passed (per The Hacker News). The recurring lesson stands: eight months post-patch, this is an inventory failure, not a zero-day problem. A firewall is the management plane for your traffic — an unpatched one is someone else’s.
Revolut: the passports walked out through the front door marked “government”
Revolut confirmed a breach with no malware and no exploited CVE: an attacker sent fraudulent data requests from a legitimate government agency’s email domain, and the fintech’s compliance process answered them — handing over identity documents, dates of birth, addresses, and possibly verification selfies, account statements, and transaction histories for a “limited” number of customers. Revolut’s own statement gives no figure; the Financial Times put it at roughly 680 (as summarized by CybelAngel). Researcher ZachXBT suggests high-net-worth users were targeted; Revolut says systems and funds were untouched. This is the Nexus lesson from last week wearing a different coat: KYC mandates have turned every fintech into a warehouse of exactly the documents identity thieves want most, and the lawful-access channel — built to be answered, staffed to comply, rarely engineered to authenticate — is a standing attack surface. The unanswered questions that matter: which agency’s domain, and how it was usable. Emergency-data-request fraud has been growing for years; this is what it looks like when it works against a bank.
StyleSmuggler: Magento zero-day backdoored stores before the patch existed
E-commerce had its own zero-day week. CVE-2026-75650, “StyleSmuggler,” an unauthenticated RCE affecting current Adobe Commerce and Magento versions, was exploited from at least September 4 — three days before Adobe’s September 7 emergency hotfix (APSB26-146). The tradecraft is quietly professional: a backdoor whose C2 traffic masquerades as NTP time-sync, planted via a fake “Payment Transaction Failed Reminder” email template, with Sansec also finding a second, separate actor dropping a 485-byte web shell — two crews in the same window, pre-patch. It’s now on the KEV list (added September 8, with a September 11 federal deadline that has now passed, per AiCybr). If you run Magento or Adobe Commerce: the hotfix alone doesn’t evict anyone already inside — Adobe’s guidance includes rotating passwords, API keys, database credentials, and SSH keys, which only makes sense if you assume compromise until you’ve checked.
Catch-up: the ten-hour, AI-assisted intrusion (published September 2 — we missed it last week)
Filed inside last week’s window but absent from last week’s post, and too instructive to skip: Unit 42’s investigation of an AI-assisted enterprise intrusion in which the attacker used autonomous agents to compress reconnaissance, credential theft from secrets managers, CI/CD compromise, and exfiltration — 50+ MITRE ATT&CK techniques — into under ten hours, work Unit 42 says would typically take two weeks. The attacker even had agents generate an 80-page “security audit” of the victim. Two caveats Unit 42 itself supplies, and coverage mostly dropped: the AI claims rest partly on what the attacker said in negotiations rather than pure forensics, and — after breathless “agentic ransomware” headlines — Unit 42 clarified this was an intrusion, not a ransomware attack. Read against the Anthropic report above, the direction is consistent across independent sources: the throughput of a single operator is rising fast. The marketing gloss on individual incidents still needs grading.
What to watch
The N-central contradiction. One vendor, one CVE, two opposite exploitation claims — and Huntress’s telemetry siding with neither. As of September 22, no independent confirmation of CVE-2026-86218 exploitation has been published; Huntress has said the “actively exploited” label rests entirely on N-able’s own statements (per The Hacker News). It remains a live case study in trusting patch discipline over narratives — the fix (2026.3.1.14) exists either way.
Revolut’s numbers, and the agency’s name. Forum posts already claim stolen Revolut data is being leaked with more promised. Same discipline as the Nexus case: we’ll follow regulator filings and the company’s disclosures, not the sellers’ advertising. Which government domain was impersonated — and why it could send authenticated-looking requests — is the detail that decides how systemic this is. As of September 22 the agency is still unnamed; secondary reports of an Italian domain are unconfirmed (per CybelAngel).
BlueMoon goes downmarket. The kit is documented and both patches exist; the historical pattern is that documented state tooling gets recycled by crimeware within weeks. Watch for the same chain with worse targets.
Who else publishes case files. Anthropic shipped IOCs with named campaigns. If the other labs follow, AI threat intel becomes a field; if they don’t, the public record of AI abuse stays a function of one vendor’s publishing choices. Either outcome tells you something.
Carry-over. NIST SP 1353 (AI for CSF analysis and reporting) comments close October 15 — about three weeks away, and still the right venue to argue that AI-produced compliance artifacts need verification requirements.
ScrutinEyes is independent analysis. Every claim links its source inline; where we rely on secondary reporting, we say so. We don’t sell what we grade.
Reading this because someone's asking about your security? See exactly which rules apply to you and where you stand — check your readiness free. Five minutes, in your browser, nothing stored unless you ask. Readiness, not legal advice.