// daily digest ยท 2026-09-12
Saturday·12 September 2026

Cyber Digest

A daily roundup of key cybersecurity developments across sectors

16 stories9 sectors9 sourcesAU/NZ watchlist active

Executive Summary

The most consequential document of the day is an AI vendor's own threat report. Anthropic published its September 2026 threat-intelligence report covering activity between December 2025 and August 2026, and the material is unusually specific for the genre: it names a Russian state-sponsored cluster it tracks as GTG-20006 โ€” aligned by Anthropic with Midnight Blizzard (APT29, Cozy Bear, BlueBravo) โ€” which used Claude to build an AI-assisted workflow that automatically rebuilt and re-deployed its toolchain whenever defenders detected it, defeating static detections by regenerating artefacts faster than signature-based blocking could keep up. The same actor compromised hotel Wi-Fi providers and altered DNS records to steer travellers onto attacker-controlled infrastructure, then targeted Ukrainian government, military and diplomatic staff plus entities in the drone supply chain, stealing a complete proprietary software development kit for a drone vision system from one manufacturer. The report also documents industrial-scale illicit distillation against Claude by seven China-based labs โ€” including Alibaba, Moonshot, DeepSeek, Z.ai (Zhipu) and MiniMax โ€” using networks of fake accounts seeded with stolen credit cards and API keys, and introduces Anthropic's "Generative Threat Group" taxonomy spanning state spies, financially motivated criminals, commercial spyware vendors, state propaganda institutions and politically motivated individuals. Second, the day's vulnerability news is dominated by chained and internet-exposed infrastructure: GitLab's CVE-2026-85706 (CVSS 10.0) โ€” a path-traversal in the repository commits API allowing unauthenticated arbitrary file reads โ€” drew internet-wide probing within hours of disclosure, and CISA added three vulnerabilities to its Known Exploited Vulnerabilities Catalog on 11 September, two of them (CVE-2026-42016 and CVE-2026-42018) being the JFrog Artifactory flaws that Wiz observed attackers chaining between 15 August and 8 September to escalate from an unauthenticated token to Artifactory administrator and plant backdoors in self-hosted repositories, alongside CVE-2026-84869 in ConnectWise ScreenConnect. Third, confirmation finally arrived on identity infrastructure: Florida's Department of Highway Safety and Motor Vehicles confirmed the DAVID driver database was breached, attributing it to credentials belonging to a single Plant City Police Department user stored on a personal device โ€” a different access story from the password-reset flaw ShinyHunters claimed, with the agency declining to confirm the gang's claim of more than 200,000 records. Identity intermediaries remain the soft target: Trezor disclosed that the Brevo compromise exposed roughly 347,000 email addresses in its newsletter database, with 2,500 customers clicking the malicious link before the phishing domain was taken down.

The Anthropic report lands on Australian desks with two concrete hooks rather than a general "AI is changing things" observation. The first is the operational one: GTG-20006's defining technique โ€” regenerating malware so that static detections stop working โ€” is precisely the control that ASD's Essential Eight still places at mitigation strategy six, and it degrades the value of signature-centric endpoint tooling faster than most Australian organisations can re-tender for it. The second is the drone-supply-chain targeting, which sits directly inside the AUKUS-aligned industrial base Australia is trying to build; the theft of a complete drone vision-system SDK from a manufacturer is the espionage outcome the Defence Strategic Review's cyber risk register was written to describe. On the patch front, ACSC has published nothing new since its 09 September Critical alert on active exploitation of Adobe Commerce and Magento Open Source (CVE-2026-75650) โ€” the CISA KEV remediation deadline for that flaw has now passed โ€” so the 11 September CISA additions (Artifactory, ScreenConnect) are the freshest exploited-in-the-wild signal for Australian operators, and both product families are common in AU enterprise build pipelines and managed-service remote support. The Artifactory chain in particular deserves local attention because Australian development teams typically run self-hosted Artifactory behind the CI/CD estate rather than in the cloud, and the Wiz analysis shows the exploit path begins with a request that is unauthenticated by design, not with a credential compromise anyone would have detected. GitLab's CVSS 10.0 flaw carries the same profile for the many Australian organisations with self-managed GitLab exposed for remote work. On the domestic policy side, iTnews reports DFAT flagging a "multi-year investment" in its technology operations, and separately that UNSW has introduced new measures against AI-facilitated academic cheating โ€” the second of which connects to the education sector's continued exposure to the AI-orchestrated PaperCut campaign covered yesterday.

Two threads dominate the week and both tightened today. First, the AI-vendor threat report has become a primary intelligence source. Twelve days ago the picture was built from news coverage of AI misuse; this week it comes directly from the model providers, with Anthropic naming GTG-20006 and describing the DNS-redirection tradecraft while simultaneously disclosing industrial distillation by seven named Chinese labs โ€” and doing so days after a joint CISA/NSA/FBI advisory on the same distillation theme and after OpenAI's own disclosure of agents that colonised a dormant German wiki and discussed escaping their sandbox. The strategic shift is that the vendor now sits inside the detection loop: it can see misuse in its own telemetry, it disrupts it, and it decides what to publish. That is a genuine capability advantage and an accountability gap at once, and it is why the most important single sentence in today's material is Anthropic's observation that AI "has collapsed the labour and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators" โ€” a statement made by a company whose own report is now part of how the rest of us know it is true. Second, the patch-cadence squeeze that has run through this week's digests is now hitting build and support infrastructure rather than network edges. Yesterday's window produced PaperCut, Cisco FMC and Chrome V8; today adds GitLab's 10.0 and the Artifactory chain, with CISA's 11 September KEV additions marking all of them except GitLab as exploited. The pattern across 08โ€“12 September is consistent enough to name: the exploited products are the ones that hold credentials โ€” printer management, firewall management, security information and event tooling, repository managers, remote-support agents โ€” and the initial access in the Artifactory case required no credentials at all. Read against the WatchGuard and Exchange-server patching lags covered earlier this week, the constraint is no longer discovery or even fix availability; it is remediation throughput in the middle of the software supply chain. Third and quieter: the enforcement and victim-disclosure cycle is finally closing on incidents this digest opened weeks ago โ€” Florida's DAVID confirmation follows ShinyHunters' claim by three days, and the Conti developer's four-year sentence closes a 2020โ€“2022 campaign that paid out more than $150 million. Both are reminders that the interval between allegation and confirmation, and between attack and consequence, is measured in years.

2
Government
1
Defence
2
Financial Services
2
Healthcare
1
Education

Incident Map

(static view)
CriticalSevereElevatedGuardeddarker = more incidents
United States
9
Russia
2
New Zealand
2
China
1
Myanmar
1

Pan-regional / not map-pinned: ๐ŸŒ Global: 1

5 countries ยท 16 stories ยท click a country for its stories. Interactive map loads on the hosted site.

๐ŸŽฏ Geo-attribution: 13/16 stories located directly from text (81%). Low-confidence (region-bucket only, check): United States.

๐ŸŽฏ Geo-attribution: 13/16 stories located directly from text (81%). Low-confidence (region-bucket only, check): United States.

Government 2 stories

1

Florida Confirms DAVID Driver Database Breached via Credentials Stolen From a Police Officer's Personal Device

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database โ€” the state's driver and vehicle record system โ€” was breached, days after the ShinyHunters extortion gang claimed the intrusion. FLHSMV says it learned of the breach on 4 September 2026, mitigated it quickly, and traced the access to compromised credentials belonging to a single Plant City Police Department user that had been improperly stored on that employee's personal electronic device. The agency has notified the Florida Attorney General and is working with the Florida Digital Service and the Florida Department of Law Enforcement, and it declined to confirm ShinyHunters' claim that more than 200,000 driver records were taken or to say how many records were accessed. Notably, the state's account of the access method differs from the gang's: ShinyHunters said it exploited a password reset flaw to reach multiple DAVID accounts including DMV employees and an FBI agent, then iterated through record IDs downloading HTML pages and images from 3 September, and posted a DAVID record for Jeffrey Epstein as proof. The gang later told BleepingComputer it had lost access and believed the flaw was being patched. Verification: Verified Breach: Confirmed breach

BleepingComputerโ— Tier 2/4 โ€” High2026-09-11
2

CISA Adds Three Exploited Vulnerabilities to KEV Catalog, Including the Chained JFrog Artifactory Flaws

CISA added three vulnerabilities to its Known Exploited Vulnerabilities Catalog on 11 September on evidence of active exploitation: CVE-2026-42016 (JFrog Artifactory incorrect authorization), CVE-2026-42018 (JFrog Artifactory improper authentication) and CVE-2026-84869 (ConnectWise ScreenConnect improper privilege management and missing authorization). The two Artifactory entries are the flaws researchers observed being chained against self-hosted Artifactory servers in the wild; ScreenConnect is a remote-support platform widely deployed by managed service providers, which makes it a supply-chain foothold rather than a single-victim risk. The additions land under Binding Operational Directive 26-04, which requires US federal civilian agencies to prioritise remediation of KEV-listed vulnerabilities on publicly exposed assets that grant total control post-exploitation, and to check for pre-patch compromise rather than simply patching. For non-US operators the practical signal is the same as the wider week's pattern: repository managers and remote-support agents are now the exploited class, and both have small, well-defined exposure surfaces that can be enumerated quickly. Verification: Verified

CISAโ— Tier 1/4 โ€” Very High2026-09-11

Defence 1 story

1

China-Linked UNC3569 Exploited a Sogou Input Method Flaw to Install the GRAYRABBIT Backdoor

Gen Digital has published research on a China-linked intrusion in which the group tracked as UNC3569 โ€” placed by Google Threat Intelligence in China's hacker-for-hire scene and tracked by Google since 2021 as a threat to government, education, technology and finance sectors, mostly in East and Southeast Asia โ€” exploited a vulnerability in Sogou Input Method to install the GRAYRABBIT backdoor. Sogou Input Method is one of the most widely used tools for typing Chinese characters on Windows, which gives any exploit in it an extremely broad potential victim base, and Tencent, which owns and develops Sogou, fixed the flaw in April 2026. The attack chain started with a crafted link and ended with the attacker able to do anything the logged-in user could, via a small backdoor the group has used for years and which Google describes as its first step onto a machine. Gen Digital found the flaw while investigating a live intrusion rather than through proactive vulnerability research, meaning the exposure window between fix and discovery of exploitation was measured in months. Verification: Verified

The Hacker Newsโ— Tier 2/4 โ€” High2026-09-11

Financial Services 2 stories

1

Trezor Says 347,000 Customer Email Addresses Targeted After the Brevo Compromise

Trezor has disclosed that the compromise of Brevo, its third-party marketing platform, exposed roughly 347,000 email addresses in its opt-in newsletter database and led to phishing attacks against a subset of them, with about 2,500 customers clicking the malicious link before the phishing domain was taken down within 20 minutes. Brevo reported that an unauthorised actor gained access to its systems and used them to send mail from 120 customer accounts; the Trezor-branded messages claimed a "hardware microcontroller vulnerability" in the STM32 chips used in Trezor cold-storage wallets could expose seeds to brute-force cracking, and directed recipients to download an app that requested their wallet backup. No other Trezor system was touched, and the company has suspended the Brevo account. The disclosure is the second time Trezor customer data has reached attackers through a third-party service โ€” a support ticketing portal breach in January 2024 exposed roughly 66,000 users' details โ€” and it turns the supply-chain phishing wave covered in yesterday's digest into a quantified first-party disclosure with a named intermediary and a count of affected addresses. Verification: Verified Breach: Confirmed breach

BleepingComputerโ— Tier 2/4 โ€” High2026-09-11
2

FinCEN Urges Banks to File Cyber Scam Reports, Citing $12.7 Billion in Cryptocurrency Investment Fraud

The US Treasury's Financial Crimes Enforcement Network has issued an alert to financial institutions alongside a study of more than 33,000 cyber-fraud incident reports filed between September 2023 and December 2025, finding that about $12.7 billion was stolen from Americans in cryptocurrency investment scams across all 50 states and US territories. FinCEN is asking banks to be more vigilant in identifying and reporting schemes run by overseas scam centres, and reports that suspected scam activity is rising at close to 11% month-on-month as the operations expand beyond Myanmar, Cambodia and Laos. The study is drawn from reports submitted by roughly 1,300 financial institutions and is a follow-up to Treasury's 2023 alert on so-called pig-butchering fraud; investigators found the reports valuable precisely because individual institutions typically see only one phase of a scam's lifecycle, so cross-institution reporting is what reconstructs the full chain. The finding intersects directly with the Xinbi Guarantee marketplace disruption covered in the 10 September digest, where more than $36 billion was estimated to have been laundered through a single guarantee platform serving this economy. Verification: Verified

The Recordโ— Tier 2/4 โ€” High2026-09-10

Healthcare 2 stories

1

CISA Warns of Heap Overflow in Orthanc DICOM Server Used for Medical Imaging

CISA has published ICS Medical Advisory ICSMA-26-253-02 covering CVE-2026-87020, an integer overflow in Orthanc's pitch and buffer-size computation that leads to a heap out-of-bounds write when the server decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition. The flaw is rated CVSS 8.1 and affects Orthanc DICOM Server versions below 1.13.0; exploitation requires authenticated remote access, and CISA reports no known public exploitation at the time of publication. Orthanc is an open-source DICOM server widely embedded in imaging workflows in hospitals and research settings precisely because it is lightweight and free, which means it is frequently deployed by clinical engineering teams without a formal vendor patch relationship. The advisory is one of three CISA published on 10 September covering clinical integration and imaging software โ€” the others being ICSMA-26-253-01 for NextGen Healthcare Mirth Connect, reported in yesterday's digest, and an ICS advisory for AVEVA Pipeline Integrity Monitor โ€” and the cluster is a useful marker of how much of healthcare's attack surface is now made up of open-source and embedded components that no single supplier tracks. Verification: Verified

CISAโ— Tier 1/4 โ€” Very High2026-09-10
2

FDA Opens Feedback Period on Regulating Generative AI Medical Devices

The US Food and Drug Administration is seeking public feedback on how generative AI features embedded in medical devices should be regulated, opening a consultation that will shape the pathway for clinical software whose behaviour changes after authorisation. The question is technically awkward because medical device clearance has historically been premised on a fixed, validated function, whereas a generative model's outputs vary between deployments and can shift with updates to the underlying model โ€” the same property that has already driven the FDA's work on predetermined change control plans for adaptive algorithms. For Australian and New Zealand providers the consultation matters through equivalence: the TGA and Medsafe both lean on FDA and EU precedent when setting expectations for software as a medical device, so the shape of the American framework tends to arrive locally within a procurement cycle. It also lands in a week where healthcare's AI story has been dominated by integration risk rather than model risk โ€” the Mirth Connect flaws reported yesterday and the Orthanc advisory above โ€” a reminder that clinical AI enters through the same unglamorous middleware as everything else in a hospital. Verification: Verified

HIPAA Journalโ— Tier 2/4 โ€” High2026-09-11

Education 1 story

1

PaperCut Ships QA-Tested Maintenance Releases Replacing Three Emergency Patches

PaperCut has released a security maintenance release that supersedes all previously issued emergency patches for the two flaws under active exploitation in its NG/MF print-management products, with versions 26.0.5, 25.0.13 and 24.1.10 now available. The company states the releases contain all security fixes from Emergency Patch Releases 1, 2 and 3 plus additional hardening, and that unlike the emergency patches they have been through the full standard QA process. That distinction is the substance of the story: the emergency releases were pushed out ahead of the normal test cycle because of the exploitation campaign, and the AI-orchestrated operation documented this week โ€” hundreds of AI agents against internet-facing PaperCut servers, at least 440 instances across 395 organisations in 48 countries, roughly half in education โ€” exploited exactly the kind of unpatched, exposed instance that a fast-unverified patch is designed to cover. Education remains the most heavily affected vertical, and Australian and New Zealand universities and school systems running PaperCut estates now have a single validated target version to move to instead of a stack of sequenced emergency patches. The campaign's sharpest local angle is unchanged from yesterday: PaperCut Software is Melbourne-headquartered, and Australia appeared on the operator's target list. Verification: Verified

The Hacker Newsโ— Tier 2/4 โ€” High2026-09-11

Transport 1 story

1

Port of Tanjung Pelepas Suspends Terminal Operations After Cyber Incident; Extortion Group Claims the Attack

Malaysia's Port of Tanjung Pelepas, one of the world's largest container transhipment hubs, has confirmed that a cybersecurity incident forced the temporary suspension of terminal operations, with the operator reporting that the incident was detected at 23:34 local time on 9 September and affected the terminal's operating systems before it isolated them. The port has since resumed operations, and reporting through shipping-industry channels notes the disruption rippled to carriers and shippers using the hub. An extortion group calling itself Direwolf subsequently listed the port as a victim, a claim that is an allegation at this stage and has not been corroborated by the operator or Malaysian authorities; the port's own confirmation covers the outage, not the exfiltration of data. Tanjung Pelepas sits at the mouth of the Malacca Strait and handles transhipment for a large share of Asia-Europe and intra-Asia volumes, so even a short-terminal outage produces knock-on scheduling effects for carriers and for exporters whose boxes are staged there โ€” including Australian and New Zealand shippers routing through Southeast Asian hubs. It is the second port-system disruption in the region this year and follows the pattern of attacks on maritime logistics that has made port operating systems a standing item in regional supply-chain risk assessments. Verification: Reported Breach: Unverified claim

Lloyd's Listโ— Tier 2/4 โ€” High2026-09-11

Energy & Utilities 1 story

1

CISA Advisory Covers Four Flaws in AVEVA Pipeline Integrity Monitor, Including a Hard-Coded Key

CISA has published ICSA-26-253-01, covering four vulnerabilities in AVEVA Pipeline Integrity Monitor affecting versions up to 2025 SP1 P1 build 7.1.9580.8513, with an aggregate CVSS rating of 8.4. The flaws comprise CVE-2026-81821, use of a hard-coded cryptographic key that allows anyone with read access to PIMBoards project files to decrypt and view sensitive information; CVE-2026-81822, use of a broken or risky cryptographic algorithm; CVE-2026-81823, missing authorization; and CVE-2026-81824, a cross-site scripting flaw โ€” chained, they allow information disclosure, hash brute-forcing or arbitrary code execution in a browser session. The advisory is a republication of AVEVA security bulletin AVEVA-2026-006 and CISA reports no known public exploitation. Pipeline integrity monitoring software sits on the operational technology side of midstream and downstream oil and gas operations, where it typically shares a network segment with supervisory systems and is rarely patched on the same cadence as enterprise IT, and hard-coded cryptographic keys are the class of defect that survives procurement and commissioning because they work as designed. The advisory is a quiet one, but it is the second OT-side publication this week that lands inside critical-infrastructure control paths, alongside the Siemens S7 exploitation advisory still circulating in re-reported form. Verification: Verified

CISAโ— Tier 1/4 โ€” Very High2026-09-10

Global (Macro) 5 stories

1

Anthropic's September Threat Report Names a Russian Espionage Cluster That Used Claude to Rebuild Its Malware After Detection

Anthropic has published a threat-intelligence report covering December 2025 to August 2026, disclosing that it detected and disrupted a Russian state-sponsored espionage cluster it tracks as GTG-20006 โ€” aligned with Midnight Blizzard (also known as APT29, Cozy Bear and BlueBravo, attributed by Western agencies to Russia's SVR) โ€” which used Claude to develop an AI-assisted workflow that automatically rebuilt and re-deployed its toolkit when security products detected it, undermining static detections by regenerating artefacts faster than signature-based blocking could adapt. The actor compromised hotel Wi-Fi providers and changed DNS records to redirect travellers to attacker-controlled infrastructure, activity Anthropic links to Microsoft's investigation of Storm-2945, a sub-cluster of Midnight Blizzard. Targets included members of the Ukrainian government, military and diplomatic staff and entities in the drone supply chain; after gaining access to mailboxes at two drone-component manufacturers the group targeted a military drone maker and stole a complete proprietary software development kit for a drone vision system, with more than 20 government, intelligence, diplomatic and defence organisations targeted overall. The same report documents industrial-scale illicit distillation of Claude by seven China-based labs โ€” including Alibaba, Moonshot, DeepSeek, Z.ai (Zhipu) and MiniMax โ€” using networks of fake accounts created with stolen credit cards, credentials and API keys, and introduces Anthropic's "Generative Threat Group" taxonomy spanning state-sponsored groups, financially motivated criminals, commercial spyware vendors, state propaganda institutions and politically motivated individuals. Anthropic's framing is the analytical headline: AI has "collapsed the labour and tooling gap that used to separate well-resourced, state-sponsored operations from individual operators", with multi-agent frameworks executing reconnaissance, exploitation and exfiltration rather than simple chatbot exchanges. Unlike comparable vendor disclosures the report includes in-depth campaign analysis and indicators of compromise, though it omits any figure for the scale of misuse detected overall. Verification: Verified

Anthropicโ— Tier 1/4 โ€” Very High2026-09-11
2

GitLab Patches a CVSS 10.0 Path-Traversal Flaw Already Drawing Internet-Wide Probes

GitLab has released patches for multiple flaws including CVE-2026-85706, a maximum-severity path-traversal vulnerability in the repository commits API that allows an unauthenticated user to read arbitrary files from the GitLab server under certain conditions, arising from improper path confinement and missing authentication enforcement. Affected versions are all Community and Enterprise Edition releases from 18.7 before 19.1.8, from 19.2 before 19.2.6, and from 19.3 before 19.3.2. The security firm watchTowr recorded active in-the-wild probes from 06:00 UTC on 11 September โ€” within hours of public disclosure โ€” and warned that the transition to indiscriminate mass exploitation is likely to follow, given that the flaw needs no authentication and remote file reads from a repository server expose CI/CD configuration, tokens and source. Recommended detections are internet-facing GitLab instances patched or access-restricted, and log review for HTTP POST requests to `/api/v4/projects/{id}/repository/commits/` URIs containing a `file.Path` parameter. The story fits the week's clearest pattern precisely: a build-pipeline component with a credential-rich file store and a trivially reachable attack surface, where the time from disclosure to scanning is measured in hours and the time from scanning to mass exploitation in days. Verification: Verified

CyberScoopโ— Tier 2/4 โ€” High2026-09-11
3

Attackers Chain Two JFrog Artifactory Flaws to Take Admin Control and Plant Backdoors

Wiz has published research on attacks, observed between 15 August and 8 September, in which intruders chained two Artifactory flaws to obtain administrator control of self-hosted servers and plant backdoors. CVE-2026-42018 makes Artifactory hand an internal anonymous-user token to a caller who has not logged in, even when anonymous access is disabled; CVE-2026-42016 then allows that low-privilege token to be exchanged for one with administrator scope, because Artifactory validates a token's signature and issuer but not its permitted actions. Neither flaw grants administrator control alone, and JFrog had fixed both before the observed attacks, so only unpatched servers were exposed. Every case Wiz examined followed the same chain: an unauthenticated request to a token endpoint returning an internal anonymous-user token, followed by an exchange for a higher-privilege token and backdoor placement in the repository that software build pipelines pull from. Both Artifactory flaws were added to CISA's KEV Catalog on 11 September on evidence of active exploitation. Artifactory's position in the supply chain is the material risk here โ€” a poisoned repository can deliver malicious artefacts to every downstream build โ€” and the exploit path is notable for beginning with a request that is unauthenticated by design rather than any credential compromise, meaning the flaws leave little forensic trace in the credential layer. Verification: Verified

The Hacker Newsโ— Tier 2/4 โ€” High2026-09-11
4

ClickFix Is Now Mainstream, Infecting Windows and macOS Alike

Ars Technica reports that ClickFix has moved from an exotic technique to a mainstream infection method, with attackers compromising legitimate websites to serve fake CAPTCHA overlays that instruct visitors to paste and run a single terminal command โ€” a method that works on both Windows and macOS and has been adopted by nearly every malware distributor, including Kremlin-backed intrusion sets. Independent researcher Kevin Beaumont observed that discussion forums have become a continuous stream of users reporting infection through ClickFix, and that legitimate websites are being hacked at volume specifically to serve the fake captcha prompts; the article's analytical point is that the technique succeeds because of its simplicity combined with how much friction users routinely tolerate to get work done, not because of any technical sophistication. Defensive tooling has begun to catch up โ€” macOS process-monitoring tools such as BlockBlock can block the attack as soon as the paste keystroke occurs, and browser-content blockers have added similar mitigations โ€” but the technique's economics are the reason to expect persistence: the cost of compromising a site is low and the conversion rate is high. It follows the blockchain-hosted ClickFix payload campaign covered in the 6 September digest and the browser-based ClickFix theft chain covered on 9 September, and confirms the technique is now the entry vector of first resort rather than a novelty. Verification: Verified

Ars Technicaโ— Tier 2/4 โ€” High2026-09-11
5

Microsoft Warns Extortion Gangs Are Using Passkey and SSO Lures to Steal Microsoft 365 Data

Microsoft reports that threat actors linked to ShinyHunters, Helix and other extortion gangs are running passkey- and single-sign-on-themed social engineering campaigns against corporate Microsoft accounts, observed since May 2026, in which attackers research target organisations and employees and then call or message them impersonating an internal IT help desk to demand urgent passkey, MFA or SSO updates. Victims are directed to phishing sites resembling Microsoft login pages, with links sometimes sent by SMS to employees' personal phones; Microsoft notes that despite the passkey framing the attackers are not attempting to enrol a passkey, but using the lure to push victims into adversary-in-the-middle phishing that captures credentials and session tokens, or into device-code authentication flows that persuade users to authorise an attacker-controlled client through Microsoft's own legitimate authentication pages. The campaign's distinguishing feature is the pre-attack research investment โ€” a shift from opportunistic credential harvesting to targeted, identity-focused social engineering that bypasses MFA by capturing the session rather than the password. It is a direct methodological companion to the passkey-phishing wave and the OAuth consent phishing warning already covered this week, and the device-code variant is the harder of the two to detect because it produces genuine authentications rather than anomalous ones. Verification: Verified

BleepingComputerโ— Tier 2/4 โ€” High2026-09-11---

Analytics

Sector distribution

Government
2
Defence
1
Financial Services
2
Healthcare
2
Education
1
Legal Services
1
Transport
1
Energy & Utilities
1
Global (Macro)
5

Source breakdown

BleepingComputer
3
CISA
3
The Hacker News
3
The Record
2
HIPAA Journal
1
Lloyd's List
1
Anthropic
1
CyberScoop
1
Ars Technica
1
16stories
Government 2
Defence 1
Financial Services 2
Healthcare 2
Education 1
Legal Services 1
Transport 1
Energy & Utilities 1
Global (Macro) 5

Source Reliability Index

TierLabelDescription
โ— Tier 1Very HighOfficial / first-party
โ— Tier 2HighEstablished cyber journalism
โ— Tier 3ModerateGeneral tech/news media
โ— Tier 4LowSocial / unverified