// daily digest Β· 2026-09-09
Wednesday·9 September 2026

Cyber Digest

A daily roundup of key cybersecurity developments across sectors

18 stories9 sectors7 sourcesAU/NZ watchlist active

Executive Summary

Microsoft shipped its largest-ever Patch Tuesday on 8 September β€” a record 966 vulnerabilities across its software catalogue, including 81 critical ratings and two actively exploited zero-days (a Windows Update Stack elevation-of-privilege flaw, CVE-2026-81963, and a Windows ALPC heap-buffer-overflow, CVE-2026-85880) β€” the release a step-change up from July's 570 and August's 400, a jump Microsoft attributes to AI-powered vulnerability discovery. Two major data-exposure stories set the breach agenda. The ShinyHunters extortion gang claimed to have breached Florida's "DAVID" driver and vehicle information database β€” over 200,000 driver records allegedly stolen since 3 September via a password-reset flaw, with a screenshot of Jeffrey Epstein's real DMV record published as proof and the state's motor-vehicle agency yet to confirm. Separately, researchers at KinryΕ« Labs disclosed that an Advance Passenger Information System (APIS) in Hanoi, Vietnam, exposed roughly 220 million passenger and crew records (passport numbers, flight data spanning 2017–2026) online through chained misconfigurations until it was secured in June; it remains unclear whether anyone copied the data. On the crypto front, so-called white-hat hackers drained US$320 million from Blockstream's Liquid Network before returning most of the funds and keeping about US$47 million as a negotiated "reward" after claiming the theft stemmed from a bug in the Elements software β€” one of the year's largest crypto thefts.

The defining Australian angle is a fresh intelligence item on internet-exposed Microsoft Exchange. iTnews reports that 382 Australian and 56 New Zealand Exchange servers remain vulnerable to CVE-2026-62911 β€” an unauthenticated authentication-bypass letting attackers potentially take over every mailbox β€” three weeks after Microsoft patched it, with working exploit code now public (NCSC-NL upgraded its advisory to warn of potential arbitrary code execution), and the ASD explicitly urging organisations running legacy Exchange 2016/2019/Subscription Edition to patch or segment; the vulnerability was discovered by Orange Tsai of DEVCORE at Pwn2Own Berlin. This lands directly in the ASD ISM / ACSC Essential Eight remit (patching and internet-exposure control) and should prompt a mailbox-compromise notification assessment under the OAIC Notifiable Data Breaches scheme for any affected body. No fresh ACSC advisory landed in the 48-hour window (the currently operative items β€” the 24 August TeamCity active-exploitation alert and the 4 September critical Citrix NetScaler advisory β€” both predate it), but the record Microsoft patch cycle and the public Exchange PoC together make patching the operational instruction for Australian defenders this week. The autonomous-AI-agent credential-compromise research and the resilient theme of ShinyHunters data-theft campaigns also track directly to the Australian organisations that continue to feature among the gang's victims.

Across the past week's digests, four threads converge again today. First, the patch cadence has become a genuine burden: after July's 570 and August's 400 Microsoft fixes, September's record 966 β€” with GovTech this week reporting cyber leaders framing a "Patch Apocalypse" that forces prioritisation β€” turns volume itself into a defender risk, and the public Exchange PoC (CVE-2026-62911) is the concrete payoff. Second, ShinyHunters is widening its racket from SaaS and Metabase data-theft (Mathspace, Trezor, Framework, Tally over the past month) into government driver-record infrastructure, reportedly via password-reset and social-engineering access, and tells BleepingComputer it expects to announce other states' DMV breaches in coming weeks β€” a new vertical that should put every driver-licence and identity registry on notice. Third, crypto theft remains the defining financial cybercrime β€” today's US$320 million Liquid incident follows April's North Korean-linked US$290 million and US$280 million thefts β€” though the negotiation-style "white-hat return" resolution is a notable and likely contested shift. Fourth, the autonomous-AI-agent narrative is accelerating: after Unit 42's 10-hour autonomous breach (covered 3 September), The Hacker News now reports autonomous AI agents compromising thousands of credentials in under six hours β€” the same trajectory the Five Eyes cyber agencies flagged in their joint AI statement. The European enforcement picture is equally busy: France confirmed the arrest of a suspected ZeroBytes teenage hacker behind the DGFiP tax breach, and Germany's municipal-utility ransomware co-occurred with Berlin blaming Russia for a Leipzig/Halle drone attack and with sabotage of two power substations β€” a reminder that ransomware and physical/hybrid disruption are converging on European critical infrastructure. For the week ahead, watch ShinyHunters for further DMV announcements, the Elements/Liquid vulnerability for follow-on research, and prompt-adoption pressure on the Magento StyleSmuggler patch.

2
Government
2
Legal Services
2
Healthcare
1
Education
1
Energy & Utilities

Incident Map

(static view)
CriticalSevereElevatedGuardeddarker = more incidents
United States
7
Australia
2
Russia
1
United Kingdom
1
France
1
Germany
1
New Zealand
1
Dem. Rep. Korea
1
Brazil
1

Pan-regional / not map-pinned: 🌐 Global: 2

9 countries Β· 18 stories Β· click a country for its stories. Interactive map loads on the hosted site.

🎯 Geo-attribution: 10/18 stories located directly from text (56%). Low-confidence (region-bucket only, check): United States.

🎯 Geo-attribution: 10/18 stories located directly from text (56%). Low-confidence (region-bucket only, check): United States.

Government 2 stories

1

ShinyHunters Claims Breach of Florida "DAVID" DMV Database

The ShinyHunters extortion gang added the Florida Highway Safety and Motor Vehicles (FLHSMV) "DAVID" driver and vehicle information database to its leak site, claiming to have stolen over 200,000 driver records since 3 September through a password-reset flaw that let it compromise accounts allegedly belonging to DMV employees and an FBI agent, then iterate records by ID. As proof it released a screenshot of Jeffrey Epstein's real DAVID record including address, Social Security number and registered vehicles. ShinyHunters told BleepingComputer it has since lost access (the flaw is being patched) and expects to announce other states' DMV breaches, with a source confirming the gang is attacking other states' DMV platforms via social engineering. FLHSMV and the FBI had not responded to BleepingComputer's queries at publication. Verification: Reported Breach: Probable breach

BleepingComputer● Tier 2/4 β€” High2026-09-08
2

Hundreds of Old, Vulnerable Exchange Servers Remain in Australia

iTnews reports that ShadowServer counted 382 Australian and 56 New Zealand Exchange servers still vulnerable to CVE-2026-62911 as of 31 August β€” three weeks after Microsoft's fix for an unauthenticated authentication-bypass that allows an attacker to intercept and replay authentication traffic and gain elevated privileges, potentially taking control of every mailbox on the server. Working proof-of-concept code is now public, and the Netherlands' NCSC-NL upgraded its advisory to warn an unauthenticated attacker could achieve arbitrary code execution, though Microsoft has not confirmed in-the-wild exploitation and the flaw is not yet in the CISA KEV catalogue. The ASD told iTnews that legacy Exchange is an easy target and urged organisations to patch or, where replacement is not possible, segment legacy networks. Verification: Verified

iTnews● Tier 3/4 β€” Moderate2026-09-08

Healthcare 2 stories

1

OneTouchPoint Agrees to Multi-Million Dollar Data Breach Settlement

Wisconsin mailing and printing vendor OneTouchPoint Corp has agreed to settle consolidated class action litigation (Dusterhoft v. OneTouchPoint, Inc.) over a 2022 ransomware attack that encrypted its network and reportedly exposed the data of 2,651,396 individuals, including diagnoses, medications and other protected health information reported to the HHS Office for Civil Rights. Under the settlement OneTouchPoint pays up to US$1.5 million in legal fees, plus administration costs, and will fund credit monitoring and monetary benefits (with up to US$500 for ordinary documented losses and a US$75 alternative cash payment), while also implementing about US$2 million in security enhancements maintained for at least five years. Claims must be submitted by 16 November 2026 and final approval is scheduled for 18 November. Verification: Verified

HIPAA Journal● Tier 2/4 β€” High2026-09-08
2

NFI North Data Breach Affects Almost 50,000 Individuals

HIPAA Journal aggregates four new US healthcare breach notifications: NFI North, a New Hampshire human-services nonprofit, notified HHS OCR of a breach of 49,540 individuals' protected health information (names, dates of birth, Social Security numbers, driver's licence and financial and medical data) with suspicious activity first seen around 6 September 2025; Nephrology Associates clinics in Kansas and Missouri reported a 24,088-person incident from a network intrusion between January and April 2026, which appears to have been conducted by the group The Gentlemen with data offered for sale; a Hawaii union health fund disclosed email-account access affecting 8,319 people; and AI-software vendor Indico Data Solutions reported a 4,840-person incident. The items underscore the slow-moving disclosure and notification cadence in the US healthcare sector. Verification: Reported

HIPAA Journal● Tier 2/4 β€” High2026-09-08

Education 1 story

1

Springfield, Mass., Schools Close After Cyber Incident

Springfield (Massachusetts) Public Schools cancelled classes on 8 September after a "cyber incident" left its network without phones, email or reliable access to curriculum and records for its 24,000 students; the problem worsened through the weekend, and IT staff are repairing systems while the district determines whether the outage was caused by an electronic failure or an attack. Students and staff have been told to stay off school-issued devices, law enforcement has been notified, and Superintendent Sonia Dinnall said the exact scope of the breach remains under investigation, while a newly launched multilingual texting system (EDVA) proved the one working channel to reach families. The incident strikes at the start of the school year, disrupting bus routes and attendance systems as well as instruction. Verification: Reported

GovTech● Tier 2/4 β€” High2026-09-08

Energy & Utilities 1 story

1

Cyberattack Encrypts Systems at Bavarian Municipal Utility

Stadtwerke Landsberg, a municipal utility in Bavaria, told customers on Monday that hackers encrypted its central IT network in an attack beginning overnight on 1 September, forcing it to disconnect affected systems from the internet, activate its crisis team and bring in external cyber specialists. The operator stressed that electricity, water and other essential services were not affected, but could not rule out that attackers accessed or stole personal data including names, addresses, phone numbers, email and bank details; it has not identified a ransomware group or confirmed an extortion demand. The incident co-occurred with Germany formally blaming Russia for a drone attack at Leipzig/Halle airport and with sabotage of two power substations, though there is no indication the Landsberg hack is connected to either. Verification: Verified

The Record● Tier 2/4 β€” High2026-09-08

Transport 1 story

1

220 Million Traveler Records Exposed in Vietnam-Linked APIS Leak

Researcher KinryΕ« Labs discovered on 3 June an Elasticsearch cluster named "pax-info" hosted in Viettel-assigned IP space in Hanoi holding 210,318,069 passenger and 10,465,631 crew records (about 220 million combined, roughly 107 GB) spanning January 2017 to April 2026, including names, dates of birth, nationalities, passport numbers and issuing countries plus flight numbers, seat assignments and timings. The cluster was reachable through a chain of two misconfigurations (the open endpoint returned 401, but a cloud-based path accepted default credentials), and KinryΕ« Labs verified legitimacy by matching records against researchers' own Vietnam travel; the data covered airlines across Asia-Pacific, Europe and the Middle East with sample records including Korean, Chinese, Canadian and New Zealand travellers. The database was remediated by 8 June, but KinryΕ« Labs could not confirm whether anyone downloaded or ransomed it before it was secured, and the findings identify several major airlines whose passenger records appeared without any indication their own networks were breached. Verification: Reported Breach: Probable breach

BleepingComputer● Tier 2/4 β€” High2026-09-08

Financial Services 2 stories

1

"White Hat" Hackers Take $47 Million Bounty After $320 Million Crypto Theft

On 7 September, hackers using the handle of purported white-hats withdrew 4,000 BTC (about US$320 million) from the wallet of Liquid Network, a Blockstream-run bitcoin sidechain, and over roughly twelve hours negotiated publicly on the blockchain with the company's representatives, demanding that Blockstream fix an alleged vulnerability in the Elements software before returning funds. The attackers returned US$266.5 million worth of bitcoin on Monday and kept about 598.5 BTC (US$47 million) as a "reward", with Blockstream confirming updated software was deployed as it ramped to restart. Blockchain security experts including CertiK traced the issue to an Elements vulnerability, and the incident β€” one of the largest crypto thefts of 2026 after April's North Korean-linked US$290 million and US$280 million thefts β€” has ignited debate over the source of the flaw and the propriety of a negotiated bounty. Verification: Verified

The Record● Tier 2/4 β€” High2026-09-08
2

Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

The Hacker News reports that a threat actor tracked as Slim Spider has stolen cryptocurrency-custody secrets from a Brazilian financial institution, indicating a targeted intrusion aimed at the private keys or custody infrastructure underpinning digital-asset holdings rather than a retail-facing breach. The incident reinforces the pattern of financially motivated actors concentrating on custody and exchange infrastructure, where a single private-key or access compromise can be worth far more than scattered credential theft. Verification: Reported

The Hacker News● Tier 2/4 β€” High2026-09-08

Retail & Entertainment & Sport 1 story

1

Adobe Patches Critical Magento Zero-Day Exploited to Backdoor Servers

Adobe has released a security update for a maximum-severity, actively exploited Adobe Commerce (Magento) vulnerability dubbed "StyleSmuggler", the first scheduled patch window for a zero-day previously reported as exploited to deploy Linux backdoors and PHP web shells on e-commerce servers. The patch is an escalation of the StyleSmuggler disclosure that the Sunday and Friday digests first carried, now with an official fix available; administrators running Adobe Commerce are urged to apply it immediately given confirmed in-the-wild exploitation by attackers installing persistent backdoors. Verification: Verified

The Hacker News● Tier 2/4 β€” High2026-09-08

Global (Macro) 6 stories

1

Microsoft September 2026 Patch Tuesday Fixes 966 Flaws, 2 Zero-Days

Microsoft shipped its largest-ever Patch Tuesday on 8 September, covering a record 966 vulnerabilities including 105 rated Critical (81 of them remote code execution), with the totals split across 438 elevation-of-privilege, 258 RCE, 173 information-disclosure, 56 denial-of-service, 19 security-feature-bypass and 16 spoofing flaws; a further 204 were fixed earlier in the month across Azure, Copilot Studio, Entra ID and other services. The two actively exploited zero-days are CVE-2026-81963, a Windows Update Stack elevation-of-privilege vulnerability credited to Romain Deperne and MSTIC, and CVE-2026-85880, a heap-based buffer overflow in Windows ALPC discovered by Volexity and Proofpoint researchers; both let an attacker escalate to SYSTEM privileges. The volume marks a step-change from July's 570 and August's 400 fixes, a climb Microsoft ties to its AI-powered vulnerability discovery system, and arrives alongside large updates from Adobe, Cisco, SAP, SonicWall and others. Verification: Verified

BleepingComputer● Tier 2/4 β€” High2026-09-08
2

WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

Researchers have documented a zero-click WeChat worm that could take over accounts on both iPhone and Android devices through malicious incoming calls, with no user interaction required beyond answering a call. The reported capability β€” if confirmed β€” would constitute a severe mobile-account-takeover risk for the messaging platform's large user base, raising questions about the underlying signalling or platform vulnerability and prompting users to treat unsolicited WeChat calls with caution. Verification: Reported

The Hacker News● Tier 2/4 β€” High2026-09-08
3

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

A chain of vulnerabilities in FreeIPA β€” the open-source identity, policy and authentication system used widely in enterprise and government Linux environments β€” allows anonymous clients to create reusable administrator credentials, effectively granting remote privileged access without a valid login. The flaw chain is critical for anyone operating FreeIPA as their identity backbone, as it undermines the trust boundary between unauthenticated clients and the directory's administrative tier. Verification: Reported

The Hacker News● Tier 2/4 β€” High2026-09-08
4

Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

The Hacker News reports fresh research in which autonomous AI agents compromised thousands of credentials in under six hours, an escalation of the autonomous-agent attack thread Unit 42 documented last week (a frontier-AI agent breaching an enterprise in under ten hours during a ransomware attack). The finding sharpens the Five Eyes and ASD warning that AI is rapidly increasing cyber risk, and argues that defenders must assume automated, AI-driven credential-stuffing and access claims at machine speed rather than human speed. An adjacent datapoint the same day: researchers also described a ChatGPT flaw in which a planted prompt could instruct the model to forward a victim's Gmail data to an attacker-controlled account, underscoring the exfiltration risk of granting conversational agents access to connected email. Verification: Reported

The Hacker News● Tier 2/4 β€” High2026-09-08
5

ClearFake WebDAV Infection Chain Delivers Amatera Stealer, ZigCryptoStealer and NetSupport Manager

Cisco Talos reconstructed a ClearFake infection chain observed executing a disguised DLL ("verification.google") from WebDAV at a Ukrainian government organisation, finding two parallel delivery chains in which a Cloudflare Worker injects JavaScript stored on the BNB Smart Chain (EtherHiding) and a fake Google CAPTCHA ClickFix prompt tricks victims into running a WebDAV roundll32 command. The chains deliver the Amatera credential-and-crypto stealer with different secondary payloads per C2: one arm deployed a NativeAOT loader running ZigCryptoStealer and a Go reverse proxy, while the other installed an unauthorised NetSupport Manager RAT configured with a Russia-based IP, which Talos assesses with moderate confidence indicates a Russian threat actor in that branch. Verification: Verified

Cisco Talos● Tier 1/4 β€” Very High (vendor technical analysis)2026-09-08
6

ClickFix Moves Into the Browser: Cryptocurrency Theft With Google-Hosted C2

Cisco Talos details a months-long cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control, retrieving obfuscated JavaScript from a public Google Sheets document and injecting it into victims' browser sessions via a ClickFix-style lure that poses as a leaked "API vulnerability" in cryptocurrency swap services (SwapZone, SimpleSwap). Victims are tricked into pasting JavaScript into the Chrome address bar or installing it into the Tampermonkey extension for persistence; the injected script hooks the browser's fetch API, replaces crypto deposit addresses in responses and the clipboard, and renders counterfeit bonus elements β€” a web-skimming takedown that quietly redirects funnel withdrawals to attacker wallets. Talos urges organisations to limit browser extension use, monitor for unexpected docs.google.com requests from browsers, and sanitise third-party dependencies. Verification: Verified

Cisco Talos● Tier 1/4 β€” Very High (vendor technical analysis)2026-09-08

Analytics

Sector distribution

Government
2
Legal Services
2
Healthcare
2
Education
1
Energy & Utilities
1
Transport
1
Financial Services
2
Retail & Entertainment & Sport
1
Global (Macro)
6

Source breakdown

The Hacker News
6
BleepingComputer
3
The Record
3
HIPAA Journal
2
Cisco Talos
2
iTnews
1
GovTech
1
18stories
Government 2
Legal Services 2
Healthcare 2
Education 1
Energy & Utilities 1
Transport 1
Financial Services 2
Retail & Entertainment & Sport 1
Global (Macro) 6

Source Reliability Index

TierLabelDescription
● Tier 1Very HighOfficial / first-party
● Tier 2HighEstablished cyber journalism
● Tier 3ModerateGeneral tech/news media
● Tier 4LowSocial / unverified