[Cybersecurity Digest] 500 breaches and two active zero-days
Patch Tuesday brought 973 fixes this week, two of them for bugs attackers were already using. Chrome had its own actively exploited hole. And one ransomware crew just quietly racked up 500 victims across US critical infrastructure. Here's what actually matters.
The Big 3
Two Windows zero-days were live before Microsoft had a patch
September's Patch Tuesday fixed 973 vulnerabilities, the largest batch Microsoft has shipped in a while, but the two that matter are CVE-2026-85880 and CVE-2026-81963, both privilege escalation bugs in the Windows ALPC component and Update Stack respectively. Both were already being exploited before the fix landed, and both are now on CISA's Known Exploited Vulnerabilities list with a federal patch deadline of 22 September 2026, 23:59 EDT.
Why it matters: these aren't the way attackers get in, they're the way attackers already inside turn a limited foothold into full SYSTEM control, which is exactly the step that turns a contained incident into a disaster.
Chrome's JavaScript engine had a hole attackers found first
Google shipped an emergency fix for CVE-2026-85046, a type confusion bug in Chrome's V8 engine rated 8.8 on CVSS, after confirming it was exploited in the wild before the patch existed. V8 powers every Chromium browser, so Edge, Brave and Opera users need the same update, not just Chrome users.
Why it matters: a rendering engine bug that gets weaponised before disclosure usually means a well-resourced attacker, and it only takes a booby-trapped web page to trigger, no download required.
One ransomware crew has now hit 500 critical infrastructure targets
Fresh threat intelligence this week puts Medusa ransomware's US critical infrastructure victim count at roughly 500, spanning healthcare, manufacturing, education and government facilities. The group runs the usual double extortion playbook, encrypt the network and threaten to leak stolen data regardless of whether the ransom gets paid.
Why it matters: critical infrastructure keeps getting hit because it can't easily go offline, and that pressure to stay running is exactly what ransomware affiliates are counting on.
Quick Hits
Deadline day for N-able: CISA's federal patch deadline for the maximum-severity N-able N-central flaw landed today, 11 September 2026, if you run N-central and haven't patched, do it now. Read more
LAPSUS$ is back: the extortion group resumed activity this week teasing new victim disclosures, part of a wider wave that includes ZaWoo, Black X and the newly active AUDIT TEAM running data extortion campaigns across South Korea, Germany and Argentina. Read more
Brussels wants to simplify GDPR: the EU's Digital Omnibus package proposes streamlined breach reporting and AI compliance rules, while Vermont became the latest US state to join the Consortium of Privacy Regulators. Read more
Stolen logs, stolen AI access: criminals are harvesting infostealer logs to hijack AI provider accounts at Google, Anthropic and others, turning saved credentials into resellable access to paid AI tools. Read more
Tool of the Week
YubiKey 5C NFC
A physical security key that stops account takeover cold, even when your password has already leaked. Plug it into USB-C or tap it over NFC and it satisfies two-factor authentication without a code to phish or a push notification to fatigue-click through. Given this week's stories about stolen credential logs turning into hijacked accounts, a hardware key is the cheapest insurance going. Good for anyone who wants to lock down email, cloud storage or AI provider accounts properly.
Protect Yourself
If you use ChatGPT, Claude, Gemini or any other AI tool with a saved API key or browser-stored password, rotate that key today and turn on hardware-key two-factor authentication on the account specifically. Infostealer logs are now being harvested and resold precisely to hijack AI accounts, and a rotated key plus a physical second factor closes that door even if your password is already floating around on a criminal forum.
Forwarded this? Get your own cybersecurity briefing at futuretechnologyhq.com/newsletter
Stay safe out there.
Nath, Future Technology
Some links in this newsletter may be affiliate links. We only recommend products we genuinely think are worth your time.