Future TechnologyFuture Technology
← Back to archive
Security Digest

[Cybersecurity Digest] 500 breaches and two active zero-days

11 September 2026

Patch Tuesday brought 973 fixes this week, two of them for bugs attackers were already using. Chrome had its own actively exploited hole. And one ransomware crew just quietly racked up 500 victims across US critical infrastructure. Here's what actually matters.


The Big 3

Two Windows zero-days were live before Microsoft had a patch

September's Patch Tuesday fixed 973 vulnerabilities, the largest batch Microsoft has shipped in a while, but the two that matter are CVE-2026-85880 and CVE-2026-81963, both privilege escalation bugs in the Windows ALPC component and Update Stack respectively. Both were already being exploited before the fix landed, and both are now on CISA's Known Exploited Vulnerabilities list with a federal patch deadline of 22 September 2026, 23:59 EDT.

Why it matters: these aren't the way attackers get in, they're the way attackers already inside turn a limited foothold into full SYSTEM control, which is exactly the step that turns a contained incident into a disaster.

Read more

Chrome's JavaScript engine had a hole attackers found first

Google shipped an emergency fix for CVE-2026-85046, a type confusion bug in Chrome's V8 engine rated 8.8 on CVSS, after confirming it was exploited in the wild before the patch existed. V8 powers every Chromium browser, so Edge, Brave and Opera users need the same update, not just Chrome users.

Why it matters: a rendering engine bug that gets weaponised before disclosure usually means a well-resourced attacker, and it only takes a booby-trapped web page to trigger, no download required.

Read more

One ransomware crew has now hit 500 critical infrastructure targets

Fresh threat intelligence this week puts Medusa ransomware's US critical infrastructure victim count at roughly 500, spanning healthcare, manufacturing, education and government facilities. The group runs the usual double extortion playbook, encrypt the network and threaten to leak stolen data regardless of whether the ransom gets paid.

Why it matters: critical infrastructure keeps getting hit because it can't easily go offline, and that pressure to stay running is exactly what ransomware affiliates are counting on.

Read more


Quick Hits

Deadline day for N-able: CISA's federal patch deadline for the maximum-severity N-able N-central flaw landed today, 11 September 2026, if you run N-central and haven't patched, do it now. Read more

LAPSUS$ is back: the extortion group resumed activity this week teasing new victim disclosures, part of a wider wave that includes ZaWoo, Black X and the newly active AUDIT TEAM running data extortion campaigns across South Korea, Germany and Argentina. Read more

Brussels wants to simplify GDPR: the EU's Digital Omnibus package proposes streamlined breach reporting and AI compliance rules, while Vermont became the latest US state to join the Consortium of Privacy Regulators. Read more

Stolen logs, stolen AI access: criminals are harvesting infostealer logs to hijack AI provider accounts at Google, Anthropic and others, turning saved credentials into resellable access to paid AI tools. Read more


Tool of the Week

YubiKey 5C NFC

A physical security key that stops account takeover cold, even when your password has already leaked. Plug it into USB-C or tap it over NFC and it satisfies two-factor authentication without a code to phish or a push notification to fatigue-click through. Given this week's stories about stolen credential logs turning into hijacked accounts, a hardware key is the cheapest insurance going. Good for anyone who wants to lock down email, cloud storage or AI provider accounts properly.

Check it out on Amazon


Protect Yourself

If you use ChatGPT, Claude, Gemini or any other AI tool with a saved API key or browser-stored password, rotate that key today and turn on hardware-key two-factor authentication on the account specifically. Infostealer logs are now being harvested and resold precisely to hijack AI accounts, and a rotated key plus a physical second factor closes that door even if your password is already floating around on a criminal forum.


Forwarded this? Get your own cybersecurity briefing at futuretechnologyhq.com/newsletter

Stay safe out there.
Nath, Future Technology

Some links in this newsletter may be affiliate links. We only recommend products we genuinely think are worth your time.