Research Deep Dives · 2026-W37
Strategic analyses
In-depth analyses from the Auto-CTI pipeline: full-text articles from vendor and researcher blogs, summarised by Claude Sonnet and annotated with key findings for your stack. Click a card for the unabridged version.
Week 37
07 Sept – 13 Sept 2026Benchmaxxing: When the Benchmark Becomes the Target
The report "Benchmaxxing: When the Benchmark Becomes the Target" examines how companies in the DACH region increasingly optimize cybersecurity benchmarks as an end in itself instead of achieving genuine security improvem
Protecting organizations from AI-assisted executive impersonation and invoice fraud
Microsoft observed a campaign of over one million fraudulent emails using generative AI to impersonate executives and commit invoice fraud. The attackers impersonated CEOs to convince accounts payable departments to proc
Detect and disrupt AI-themed attacks with Microsoft Defender
Microsoft Threat Intelligence has observed a growing set of campaigns impersonating popular AI platforms such as ChatGPT, Microsoft Copilot, DeepSeek, and Claude. Attackers use phishing, search-driven malware, and malver
BlueMoon exploit kit turns Chrome and Windows flaws into attacks
The BlueMoon exploit kit combines two Chrome V8 JavaScript engine vulnerabilities and a Windows vulnerability to execute code with elevated privileges after phishing clicks. Proofpoint observed four espionage groups usin
Update Chrome now to protect against an actively exploited vulnerability
Chrome 153.0.8010.36/.37 patches one actively exploited medium-severity vulnerability and five critical flaws, including four in WebGL, enabling remote code execution.
Passkey-themed social engineering leads to identity and cloud compromise
Targeted social engineering campaign exploits passkey themes to compromise cloud identities, establishes MFA persistence, and systematically extracts data via Microsoft Graph, SharePoint, and REST APIs , typical pattern
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Critical authentication bypass vulnerability (CVSS 10.0) is actively exploited by ransomware operators (UAT-11988) who gain initial access via static credentials and abuse legitimate tooling for reconnaissance and latera
Microsoft fixes record 964 flaws, including 2 exploited zero-days
Microsoft's September 2026 Patch Tuesday fixes 964 CVEs, the largest release on record, including 104 rated critical and 860 rated important. The update addresses two actively exploited zero day vulnerabilities that allo
Microsoft Patch Tuesday for September 2026 , Snort rules and prominent vulnerabilities
Microsoft's September 2026 Patch Tuesday includes 973 vulnerabilities, 113 of which are critical, including 82 remote code execution flaws. Two vulnerabilities are already exploited in the wild: CVE-2026-81963 and CVE-20
Patch Tuesday - September 2026
On September 2026 Patch Tuesday, Microsoft published 999 vulnerabilities total: 974 in its own products including 723 Windows vulnerabilities, plus fixes for 25 non-Microsoft CVEs. This is the largest single-day CVE rele
Microsoft's September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
The largest Patch Tuesday release with 964 CVEs, including 104 critical vulnerabilities, addresses privilege escalation in Windows Update Stack and authentication bypass in Exchange Server, requiring immediate evaluation
Week 36
31 Aug – 06 Sept 2026ASCII smuggling crosses over from AI prompt injection to phishing evasion
The report describes how the ASCII smuggling technique, originally known from AI prompt injection attacks, is now being used in phishing campaigns to evade email filters. Attackers use invisible Unicode tag characters to
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Microsoft Threat Intelligence observed a campaign that abuses Microsoft Teams external collaboration to impersonate IT support and trick users into granting an interactive remote session. After remote access is establish
Two critical Chrome flaws put users at risk on malicious websites
A V8 flaw (CVE-2026-85046) is already being actively exploited in the wild, enabling arbitrary code execution within the Chrome sandbox via crafted HTML pages.
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software download websites to impersonate trusted vendors and distribute malicious installers. The campaign primarily affects China-
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Organized social engineering campaign uses external Microsoft Teams accounts to impersonate IT help desk personnel for credential theft; 150+ employees across 10+ companies targeted between January and April 2026.
Week 35
24 Aug – 30 Aug 2026TerminalFix campaign deploys a reverse tunnel through multistage intrusion
The TerminalFix campaign, a ClickFix variant, uses compromised websites with fake Cloudflare CAPTCHA overlays to trick users into executing a malicious PowerShell command. The attack employs multi-stage techniques such a
Threat landscape for industrial automation systems. Q2 2026
The report provides a quarterly overview of the threat landscape for industrial automation systems and documents new APT malware attributed to Mirage Kitten, which is strategically relevant for production environments.
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
RCE vulnerability in Microsoft SharePoint allows authenticated attackers to execute arbitrary code; exploit details reveal XML-based Business Data Catalog manipulation as the attack vector.
Week 34
17 Aug – 23 Aug 2026Frequently asked questions about the active threat to Siemens S7 Series PLCs
Unattributed threat actors are using AI-generated exploits to target known weaknesses in Siemens S7 controllers and potentially pre-position for disruptive attacks against critical infrastructure.
BTR Reforged: Weaponizing Defender's Remediation Driver as a Kernel Operation Primitive
The report provides the first complete reverse engineering of the Microsoft-signed Windows Defender driver BTR.sys. It demonstrates that this driver can perform arbitrary file and registry operations in kernel mode throu
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
The combination of a Linux kernel rootkit, BYOVD EDR neutralisation and cross-platform C2 in a single, widely deployed implant shows that kernel-level evasion techniques are no longer reserved for top-tier state actors.
Week 33
10 Aug – 16 Aug 2026The Good, the Bad and the Ugly in Cybersecurity , Week 33 (2026)
The report covers the sentencing of a member of the cybercrime collective "The Com" for blackmail and sextortion, as well as warnings about Gunra ransomware. A UK court sentenced Justin Swaddle to two years in prison aft
The August 2026 Security Update Review
Exchange Server Elevation of Privilege (CVE-2026-62911) enables authentication bypass and takeover of all mailboxes; demonstrated as proof-of-concept at Pwn2Own Berlin.
Rapid7 Analysis: Microsoft SharePoint JWT Token Authentication Bypass (CVE-2026-55040)
On July 14, 2026, Rapid7 and Microsoft disclosed CVE-2026-55040, a critical authentication bypass in Microsoft SharePoint Server Subscription Edition. A remote unauthenticated attacker can bypass JWT token validation and
CVE-2026-63520: Microsoft SharePoint Remote Code Execution (FIXED)
Rapid7 Labs discovered CVE-2026-63520 during zero-day research on Microsoft SharePoint; it affects all supported versions. The vulnerability enables remote code execution with SharePoint Site service account privileges d
Week 28
06 Jul – 12 Jul 2026No more deep dives.