Skip to content
Auto-CTI

What has changed?

Comparing 10 September 2026 with the previous day 9 September 2026.

Newly added

48
NEW A3
95

German institutions compromised via TerminalFix campaign

BSI warns of an active, targeted campaign against German institutions focusing on critical infrastructure and government agencies , a sign of elevated cyber risk in the DACH region for suppliers and partners in these sectors.

Critical
NEW C3
80

EU Cyber Resilience Act to Enforce New Reporting Requirements

EU cybersecurity legislation establishes mandatory reporting obligations for actively exploited vulnerabilities within 24 hours effective immediately, signaling significant regulatory tightening for European organizations with comprehensive enforcement by December 2027.

Critical
NEW Russian-speaking APT (suspected state-sponsored) C3
80

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

A suspected Russian-speaking state actor is leveraging hundreds of AI agents to systematically exploit PaperCut instances and gain enterprise access,exemplifying state-sponsored cyber operations using advanced automated techniques.

Critical
NEW Russian-aligned espionage group; Chinese state-sponsored actors; ShinyHunters C3
80

AI lets small actors run state-level hacking campaigns, Anthropic report finds

Anthropic report demonstrates that AI tools enable smaller actors to conduct state-level hacking campaigns; documented cases include Russian-aligned espionage against 20+ organizations and Chinese exploit development, with relevance to European supply chains and critical infrastructure.

Critical
A3
20

[UPDATE] OpenSSH: Multiple Vulnerabilities

The BSI advisory covers multiple OpenSSH vulnerabilities without specifying CVE numbers or affected versions; precise identification of affected versions and exploitability status is required.

High
NEW A3
20

Ubiquiti UnifiOS: Multiple Vulnerabilities

The BSI warning documents multiple vulnerabilities in UnifiOS without specific CVE numbers; the scope and severity suggest a coordinated disclosure or ongoing patch cycle.

High
NEW A3
20

Google Chrome: Multiple Vulnerabilities

BSI alert on multiple Chrome vulnerabilities without specific CVE numbers or patch date,likely aggregate security notice for regular patch cycle.

High
NEW B3
20

Detect and disrupt AI-themed attacks with Microsoft Defender

Cyberattackers are weaponizing AI platform impersonation (ChatGPT, Copilot, Claude, DeepSeek) at scale (up to 100,000 emails per day) for phishing, credential harvesting, and malvertising, with increasing automation and Teams-based social engineering.

High
NEW Four unnamed espionage groups (nation-state or state-sponsored) C3
17

BlueMoon exploit kit turns Chrome and Windows flaws into attacks

Four espionage groups actively exploit the same BlueMoon exploit chain targeting Chrome/Windows within days of each other; all three vulnerabilities are listed in CISA's KEV catalog and are being exploited in the wild.

High

Newly KEV-listed

0

No changes in this category.

Score moved

0

No changes in this category.

No longer in report

122
KEV NEW B1
95

Patch Tuesday - September 2026

Two Windows EoP zero-days (ALPC, Update Stack) with active exploitation are addressed in Microsoft Patch Tuesday September 2026; CVSS 7.8 may understate operational risk for systems vulnerable to locally-exploitable privilege-escalation vectors.

Critical CVSS 7.8 EPSS 1%
KEV NEW B1
61

The August 2026 Security Update Review

Exchange Server Elevation of Privilege (CVE-2026-62911) enables authentication bypass and takeover of all mailboxes; demonstrated as proof-of-concept at Pwn2Own Berlin.

Medium CVSS 7.0 EPSS 6%
A3
47

[UPDATE] GNU libc: Multiple Vulnerabilities

This is a BSI advisory on multiple GNU libc vulnerabilities without specific CVE identification; the 'UPDATE' designation suggests a follow-up notification and requires verification of specifically affected versions in the production environment.

Critical
NEW A3
47

[UPDATE] GNU libc: Multiple Vulnerabilities

BSI warning on multiple critical GNU libc vulnerabilities without specific CVE disclosure suggests coordinated release or ongoing patch cycle , urgency depends on patch status.

Critical
NEW B3
42

Passkey-themed social engineering leads to identity and cloud compromise

Targeted social engineering campaign exploits passkey themes to compromise cloud identities, establishes MFA persistence, and systematically extracts data via Microsoft Graph, SharePoint, and REST APIs , typical pattern of state-sponsored APT operations with long-term persistence objectives.

Critical
NEW A3
37

VMware Products: Multiple Vulnerabilities

BSI warning of multiple critical vulnerabilities in VMware virtualization products with direct impact on hypervisor and vCenter infrastructure used by European organizations.

Critical
NEW A3
20

Microsoft Office Products: Multiple Vulnerabilities

BSI warning regarding multiple Microsoft Office vulnerabilities with potential for privilege escalation and code execution; specific CVE details and patch status require consultation of the full BSI advisory.

High
A3
20

[UPDATE] OpenSSL: Multiple Vulnerabilities

BSI warning on multiple OpenSSL vulnerabilities with broad impact on encryption, authentication, and availability , requires verification of deployed OpenSSL versions in the infrastructure.

High
NEW Spring Ring C3
20

Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users

The 'Spring Ring' operation uses vishing techniques specifically targeting Microsoft Teams users to enable remote access and malware distribution,not just email phishing, but direct VoIP-based social engineering against collaboration platforms.

High
NEW A3
20

Fortinet FortiProxy and FortiOS: Multiple Vulnerabilities

BSI warning on multiple unnamed vulnerabilities in FortiOS/FortiProxy with DoS and information disclosure potential , specific CVE numbers and CVSS scores are missing, making patch prioritization difficult.

High
NEW A3
20

Google Chrome: Multiple Vulnerabilities

BSI warning on multiple Chrome vulnerabilities without specific CVE numbers or active exploitation mentioned; standard patch management requirement.

High
NEW C2
17

Google warns of new Chrome zero-day bug exploited in attacks

Google has documented multiple Chrome zero-days in active attacks, including iterator invalidation in CSSFontFeatureValuesMap and out-of-bounds write in Skia , indicating targeted browser-based attack campaigns against unidentified threat actors.

High
ESC