
Critical Flaws, AI Abuse, And New AWS Performance Controls
Coverage: 11 Sept 2026 – 13 Sept 2026 (UTC)
< view all daily briefs >Critical enterprise software flaws faced active probing and fresh mitigation deadlines, while national authorities flagged imminent exploitation of VPN gateways. At the same time, Anthropic detailed industrial-scale attempts to siphon model capabilities and automate intrusions, underscoring the dual-use risks of AI. Cloud providers rolled out performance and control enhancements aimed at scaling inference and tuning data access paths. Several campaigns leveraged patch gaps, social engineering, and third‑party exposure to advance data theft and persistence.
Critical Vulnerabilities Under Active Pressure
GitLab released urgent fixes for CVE-2026-85706, a path traversal flaw in the repository commits API rated CVSS 10.0 that allows unauthenticated arbitrary file reads under specific conditions. Affected releases span 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2; patches are available in 19.3.2, 19.2.6, and 19.1.8. WatchTowr observed in‑the‑wild probing beginning at 06:00 UTC on September 11, 2026, with exploitation requiring at least one public project on the instance. Defenders are advised to review logs for POST requests to “/api/v4/projects/{id}/repository/commits/” containing “file.Path” parameters and to restrict public access where possible.
CISA KEV added five actively exploited vulnerabilities involving JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. Reported abuse includes privilege escalation, internal token leakage, and unauthorized file transfer and execution, as well as chains enabling kernel memory disclosure, denial‑of‑service, and policy changes that facilitate privilege escalation. Federal remediation deadlines are set for RouterOS by September 13, ScreenConnect by September 14, and Artifactory by September 25, 2026. Observed post‑exploitation in Artifactory environments includes persistent admin creation, malicious Groovy plugins, and Rust‑based backdoors.
Dutch NCSC warned that exploitation of two critical Check Point VPN vulnerabilities—CVE-2026-85102 and CVE-2026-85103—is imminent. The flaws involve improper validation during VPN negotiation and a heap overflow in the VPN certificate ASN.1 decoder, with remote code execution impact on Security Gateways and Management Servers. Fixes were released on September 9 via advisories sk1000117 and sk1000118, with mitigations available through LivePatch and Jumbo Hotfix/Build releases; R82.20 is not impacted. Administrators are urged to update immediately and, for Site‑to‑Site VPNs, restrict access to trusted IPs.
AI Abuse: Model Distillation and Automated Intrusions
Anthropic reported seven China‑based lab campaigns since February 2026 that illicitly attempted to distill Claude’s capabilities. Operators used proxy networks, thousands of fraudulent accounts, stolen or fake payment methods, and illegally obtained API keys to reroute requests through Claude or to buy harvested conversational transcripts. One campaign linked to Alibaba‑affiliated operators generated roughly 151 million exchanges, peaking near 3 million per day. In response, Anthropic tightened account and region restrictions, banned reseller accounts that fail verification, and adjusted Claude to summarize or encrypt internal reasoning and preserve system prompts to reduce the utility of stolen transcripts.
Anthropic also documented widespread misuse of Claude by state‑aligned actors, cybercriminals, commercial spyware vendors, and politically motivated operators from December 2025 through August 2026. Reported activities span AI‑assisted reconnaissance, exploit development, automated multi‑agent intrusions, credential harvesting, supply‑chain theft, and influence operations. Profiles include a Russian‑aligned cluster with tactics overlapping APT29 and a Chinese‑speaking group that targeted about 50 organizations and developed zero‑day exploits, alongside ShinyHunters affiliates that ran large‑scale credential‑harvesting pipelines. Anthropic states it disrupted many efforts and removed accounts and networks.
BleepingComputer highlighted campaign specifics, including an actor linked to ShinyHunters who orchestrated AWS EC2 pipelines to mass‑download and decompile 1.8 million Android APKs and scan for hardcoded secrets with TruffleHog, then verified and shared results in a Telegram group. Additional activity included harvesting GitHub organization addresses and obtaining PATs used for initial access, extracting over 2,100 Azure AD tokens across 40+ tenants in about 34 hours, and espionage operations attributed to Midnight Blizzard and a Chinese‑speaking cluster (GTG‑10007). Anthropic says it banned offending accounts, disrupted campaigns, updated guardrails, and engaged partners and authorities.
Cloud Platform Updates and Performance Controls
AWS Lambda now allows explicit configuration of direct reads for Amazon S3 Files, giving teams control over whether file I/O is served from high‑performance storage or the underlying S3 bucket. When enabled, files 1 MB or larger are read directly from S3 for higher throughput, while smaller files use the high‑performance layer for lower latency; when disabled, all reads go through the high‑performance storage. The feature is available across AWS commercial Regions and GovCloud (with some regional exceptions) via console, CLI, SDKs, and CloudFormation. In parallel, SageMaker HyperPod added model caching that pre‑loads large model weights and container images on cluster nodes, reducing cold starts and enabling pods to serve in seconds. Benchmarks on 57–145 GB models showed roughly 60% faster scale‑out and a 97% cut in image‑pull time, with automatic fallback to source artifacts if caches are cold.
Bedrock KB now supports TwelveLabs Marengo 3.0 for multimodal embeddings, directly encoding video, audio, and images into 512‑dimensional vectors. The model returns segment start and end times for precise jumps to media moments and offers configurable segmentation, improving retrieval where transcription alone misses meaning. Integration follows the managed knowledge base workflow—ingest from Amazon S3, sync, and search with natural language—without infrastructure management.
Exploit Toolchains and Public‑Sector Breaches
CSO report detailed “BlueMoon,” an exploit toolkit chaining a V8 type confusion bug (CVE-2026-85046), a V8 sandbox escape via WebAssembly (CVE-2026-87491), and a Windows kernel LPE zero‑day (CVE-2026-85880). The two V8 issues were patch‑gap zero‑days—fixed in Chromium source but not yet in stable Chrome—enabling rapid weaponization. Socially engineered lures drove victims to malicious links that delivered the chain and then redirected to legitimate sites. Recommended actions include immediate patching of Chrome and affected Windows builds, applying shared detection rules, and rescanning for persistence artifacts.
FLHSMV confirmed a breach of its DAVID driver database via credentials from a single Plant City Police Department user stored on a personal device. The ShinyHunters group claimed a different access method and a larger scope, but the agency has not disclosed the number of records accessed and is treating the case as an ongoing criminal investigation in coordination with state authorities. The incident underscores risks from credential exposure on personal devices and the need for stronger credential management and multifactor protection.
PaperCut MR releases—NG/MF 26.0.5, 25.0.13, and 24.1.10—replace prior emergency patches for actively exploited CVE-2026-81578 and CVE-2026-82078. The maintenance builds have completed full QA, include additional hardening and regression fixes, and address campaigns that used automated tooling and hundreds of AI agents to compromise at least 395 organizations across 48 countries, with activity concentrated in U.S. education. Customers are advised to move to the maintenance releases for comprehensive protection.
Microsoft described two intertwined campaigns: a large-scale BEC scheme impersonating CEOs and vendors to trigger ACH payments, and identity‑focused social engineering that prompts employees to “update” passkeys, MFA, or SSO. The latter uses adversary‑in‑the‑middle and device‑code flows to enroll attacker‑controlled authentication methods, then scales data theft via Microsoft Graph API calls across SharePoint, OneDrive, and Exchange. Microsoft links facets of the activity to clusters including UNC6671/Cordial Spider and groups labeled Storm‑3121 and Storm‑3032.