Cyber briefing
Friday, 11 September 2026
Executive Summary
The reporting period is dominated by the active exploitation of Cisco FMC vulnerabilities by ransomware groups and state-sponsored actors, as well as a massive AI-agent-based campaign that compromised 395 organizations through vulnerable PaperCut servers. On the data front, IDScan confirmed a breach involving 153 million driver's license scans, and ShinyHunters exposed 6.4 million individuals in the attack on McKesson. The "BlueMoon" exploit kit, which uses Windows and Chrome zero-days, raises the overall risk level to HIGH.
Critical Threats
- Active Cisco FMC exploitation — Two recently patched vulnerabilities in Secure Firewall Management Center are being exploited by three distinct clusters linked to ransomware and state-sponsored attacks. Action: immediately verify FMC versions and apply the patches.
- AI campaign against PaperCut NG/MF — A likely Russophone actor used hundreds of AI agents to exploit vulnerable PaperCut servers globally, compromising 395 organizations. Action: inventory PaperCut servers and remediate exposed versions.
- "BlueMoon" exploit kit — Cyber espionage groups used zero-days in Microsoft Windows and Google Chrome. Action: keep browsers and Windows systems fully updated.
- IDScan breach — 153 million license scans — Massive identity data offered for sale; the company confirmed hackers' access to customer data from the cloud platform. High identity fraud impact.
- ShinyHunters / McKesson — 6.4 million individuals affected in the attack on the healthcare provider; continued extortion of the healthcare sector.
Vulnerabilities & Patches
Windows Defender zero-days published by the researcher "Nightmare-Eclipse" ("ShieldCrash" exploit). Cisco FMC vulnerabilities actively exploited — patches available, urgent application required. PaperCut NG/MF flaws remain priority targets. Operational warning: the September 2026 Windows Server updates break Remote Desktop Services on Server 2019/2022/2025, and KB5002914 breaks copy-paste in Excel — test patches before deployment.
Trends & Observations
AI automation is becoming an offensive tool (the PaperCut AI-agent campaign). Extortion via phone voices and abuse of BYOD/Microsoft Graph API targets Microsoft 365 access. Android malware is evolving: GoldFactory (banking app cloning) and Mantax Otax (ransomware + spyware + harassment). Abuse of the Google Play Early Access program allows bypassing reviews. The healthcare and financial sectors are preferred targets; cyber fraud losses reported by the US Treasury exceed USD 13 billion since 2023.
Recommendations
- Patch exposed Cisco FMC and PaperCut servers immediately; verify the associated indicators of compromise.
- Test the September 2026 Windows Server updates in staging environments before deployment (RDS risk).
- Implement MFA and identity monitoring — nearly half of confirmed malicious activity targets identities.
- Educate users about vishing attacks that exploit BYOD and Microsoft 365 access.
- Verify whether the organization is affected by the IDScan breach and intensify anti-fraud controls.
- articles
- 50
- sources
- 12
- critical
- 1
- high
- 1