In partnership with

~7 MIN READ
Fact By the time Microsoft patched CVE-2026-85880 in September's Patch Tuesday, four separate Chinese nation-state hacking groups had already been chaining it with two Chrome zero-days into browser-based espionage campaigns across four countries. (BleepingComputer + SecurityWeek, September 2026)
The Signal
 

Four separate Chinese espionage groups adopted the same zero-day exploit kit within days of each other. Microsoft's AI vulnerability scanner is producing patches faster than the industry can absorb them. And a government agency is being sued for turning public housing into a sensor network. Speed and surveillance are this week's themes.

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe

📌 Big Cyber News
 
NATION-STATE
🕷️ China's Hackers Found a New Browser Exploit Kit. Four Separate Groups Were Using It Within Days.
Intro
A new browser exploit kit called BlueMoon chains three zero-days into full system compromise from a single malicious webpage, and China's nation-state hacking community has been sharing it faster than the patches could arrive.
What Happened
Violet Typhoon (APT31) first deployed BlueMoon on August 28, combining two Chrome V8 zero-days (CVE-2026-85046, patched September 3; CVE-2026-87491, patched September 8) with a Windows ALPC privilege escalation flaw (CVE-2026-85880, patched in September's Patch Tuesday) to achieve full sandbox escape and SYSTEM-level access via one page load. Within days, three more distinct Chinese groups followed: UNK_LateNight against US aerospace firms, UNK_DoubleCheck against a Vietnamese manufacturer, and UNK_QuietRacket targeting Indonesian and Singaporean government, consulting, and financial targets.
Why It's Important
Four independent threat actors adopting the same novel exploit chain within days of each other suggests either shared tooling infrastructure or unusually fast distribution inside China's offensive cyber ecosystem. That pace matters because most organizations patch on a monthly cycle.
The Other Side
All three zero-days are now patched. Chrome 152.0.7977.82+ and September's Windows Patch Tuesday close the full chain. Organizations that have applied both updates are no longer at risk from this specific kit.
 
👉 Takeaway
Update Chrome and apply September's Windows patches now. Four APT groups found the same exploit chain useful enough to use immediately. The window to patch ahead of them is already closed for some organizations.
TL;DR: Four separate Chinese nation-state groups are all running the same three-zero-day browser exploit kit that turns one malicious page into full system compromise.
Further reading: SecurityWeek

Some teams never seem to stop moving. They're on Attio, the agentic CRM.

Every customer signal is captured in one shared context layer, always current and compounding. Agents and workflows build pipeline, chase every buying signal, and move deals forward, an always-on revenue engine running alongside your team.

With Attio, you’ll get:

  • Leads automatically prioritised and routed to the right rep

  • Expansion and risk signals caught the moment they land

  • Follow-ups written in your voice, already there when you arrive

Teams like Parallel, Turbopuffer, and Wordsmith build on Attio. Are you one of them?

🚨 Can't Miss
 
 
Vulnerability
Microsoft's September 2026 Patch Tuesday patched 966 vulnerabilities, nearly double July's prior record of 570, after the company deployed an AI-powered scanner across its software portfolio. Two flaws, CVE-2026-81963 (Windows Update Stack elevation of privilege) and CVE-2026-85880 (Windows ALPC heap overflow), were actively exploited before the patches dropped on September 8. CVE-2026-85880 is the same zero-day chained in the BlueMoon exploit kit, confirming real-world usage across multiple threat actors simultaneously. The AI disclosure is the real signal: if Microsoft's scanner keeps surfacing vulnerabilities at this pace, the security industry's capacity to triage and patch them will strain.
Apply September Patch Tuesday now, specifically for the two actively exploited zero-days.
 
Data Breach
Japan's Digital Agency disclosed that attackers exploited a known-but-unpatched VPN vulnerability in its Government Solution Service infrastructure, stealing approximately 246,000 record rows covering 189,000 government employees and 57,000 private-sector contractors. Exposed data includes names, email addresses, phone numbers, and some physical addresses; no My Number IDs, bank details, or pension records were taken. The agency detected unusual activity on June 25 via a maintenance account but has not confirmed misuse of the stolen records. It had already documented the unpatched VPN flaw before the attack occurred.
VPN patch audits matter. Check what known-CVE items are sitting unpatched in your own inventory right now.
 
Supply Chain
Chinese hacker-for-hire group UNC3569 exploited CVE-2026-51990, a one-click RCE in Tencent's Sogou Input Method, to deploy the GRAYRABBIT backdoor via a single crafted link sent to targets. The flaw chained an insecure custom protocol handler, unrestricted embedded-browser navigation, and an unsandboxed outdated Chromium build into a complete single-step compromise. Tencent silently patched in April 2026 via auto-update, but the campaign only surfaced publicly in September 2026, suggesting months of undetected access to government, education, technology, and finance organizations across East and Southeast Asia.
If Sogou Input Method is deployed in your environment, confirm the April 2026 auto-update applied (v16.3.0.3498 or later).
🤖 AI in Cyber
 
 
AI Security
In a formal joint advisory, NSA, CISA, and FBI accused DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of running what they called "industrial-scale knowledge distillation campaigns" against US frontier models since late 2024, extracting billions of tokens from Claude, GPT, Gemini, and Grok to train competing products. Moonshot AI alone allegedly distilled 18 different US frontier models, including Anthropic's Fable 5, to develop its Kimi-K2 and Kimi-K3 systems. The tactics include thousands of fraudulent accounts, metadata-obfuscating proxies, and gray-market API aggregators to evade geographic restrictions and usage safeguards. The agencies framed this not just as IP theft but a strategic economic threat to US AI leadership.
Every publicly accessible AI API is now a target for systematic capability extraction. Usage monitoring and anomaly detection on your AI API keys is not optional.
 
AI Risk
Team8's 2026 CISO Village survey of global enterprise security leaders found 78% rank AI and agent security as their top pain point, exactly double the second-ranked concern at 39%. 71% of those same leaders are already deploying or experimenting with AI agents despite that anxiety. Team8 CISO Tim Brown: "an AI agent is not just another employee; it's a very resourceful employee that will do whatever it takes to accomplish the task it believes it has been given." The survey reflects a growing gap between how fast organizations are adopting AI agents and how well they understand those agents' actual capabilities when operating autonomously.
If you haven't scoped what your deployed AI agents can do when operating without human oversight, that is the gap most security leaders are working on right now.

Smarter CRM. Less Busywork.

Disconnected data and tools make it harder to understand your customers. HubSpot's Agentic Customer Platform brings your data, teams, and tech stack together with AI built in to help your business work faster and create more personalized customer experiences.

Why HubSpot and what's new

  • Use AI powered tools to take action faster

  • Unify your data, teams, and tech stack in one place

  • Create one shared view of customer data

  • Connect teams around the same customer context

  • Bring your business tools into one place

Connect more of your business in one place and give every team a smarter way to work. Get set up quickly and start checking off your hardest tasks.

🏛️ Privacy, Power & Policy
 
 
Surveillance
The ACLU and New Hampshire Legal Assistance filed a class-action suit against the Concord Housing and Redevelopment Authority for installing approximately 300 Minut Monitor sensors in public housing apartments, ostensibly to detect smoking and noise complaints. The devices logged sound readings roughly every 60 seconds and motion continuously, accumulating over 134 million sound readings and 19 million motion events across the properties in 7 months; one unit alone logged 140,000+ motion events over that period. The authority did not disclose the occupancy-tracking capability to tenants, denied a resident's data request, and warned tenants who objected that they risked fines or eviction. The lawsuit specifically notes that domestic violence survivors' patterns of daily life could be exposed to abusers through this data.
Government surveillance of tenants inside their private homes, with eviction as the enforcement backstop, is the kind of story that sets legal precedent.
 
Regulation
Texas District Judge Cory Liu found TikTok liable via summary judgment for misrepresenting its Restricted Mode feature, which the company marketed to parents as filtering out graphic content including drugs, nudity, alcohol, and violence from minors' feeds. TikTok's own internal moderation instructions directed reviewers to classify rule-breaking material as "hard to find" rather than remove it, allowing harmful content to remain accessible. This is the first state liability ruling on this specific "you told parents it was safe and it wasn't" legal theory; a trial on damages and potential operational remedies is expected next month. Note: this is distinct from the August 2026 federal DOJ COPPA $400M settlement, which involved data collection practices.
Every state attorney general is watching this case. So should every edtech or parental-control vendor making similar safety assurances to parents.
🛠️ Tools & Tactics
 
 
Patch Now
CVE-2026-84869 in ConnectWise ScreenConnect lets an attacker push and execute files through an active remote-support session without the host confirming the action. Huntress confirmed active exploitation has been ongoing since August 20, with a modified ScreenConnect client deploying VBScript payloads that self-propagate to other connected ScreenConnect clients via social-engineered rogue installs. ConnectWise released version 26.6.5 on September 8 with the fix. CISA added CVE-2026-84869 to the Known Exploited Vulnerabilities catalog on September 12 under the 3-day BOD 26-04 federal deadline. If you cannot patch immediately, disabling the TransferFiles permission in ScreenConnect's admin settings is the documented interim mitigation.
🧪 Strange Cyber
 
Strange but real
🔑 Manchester Airports Said Getting Hacked Was Sophisticated. The Hacker Read Their Page Source.
Intro
Security researcher Scott Helme wanted to understand how extortion group FulcrumSec actually stole data on 8.8 million Manchester Airports Group customers. The answer was: they viewed page source.
What Happened
Overprivileged Iterable API keys had been sitting in plain-sight JavaScript served by Manchester Airports Group's three airport websites since June 2022, four uninterrupted years. The keys had read access to 8.8 million customer profiles, parking and lounge bookings, and travel records, plus write access sufficient to delete or overwrite the entire database. Nobody at MAG apparently noticed, and nobody external apparently thought to look until FulcrumSec did. Researcher Helme's conclusion: "FulcrumSec just happen to be the ones who told us."
Why It's Important
MAG described the incident as "a sophisticated hack." This pattern, calling a basic security failure sophisticated in post-breach communications, obscures what actually went wrong and makes remediation of the same class of mistake less likely elsewhere.
The Other Side
Finding and removing exposed API keys from legacy JavaScript bundles across multiple production sites is genuinely difficult. These things slip through for years without triggering any alert. The process failure here predates most of MAG's current security team.
 
👉 Takeaway
Run a client-side JavaScript scanner against your public-facing web properties. Exposed API keys in browser-readable code are not rare. This particular failure ran for four years undetected.
TL;DR: An extortion group stole 8.8 million airport records using API keys that had been readable in public JavaScript for four years. The company called it sophisticated.
Further reading: The Register

Ava is the first AI BDR to run outbound end to end, from finding leads to booking meetings, autonomously or on copilot. She's SOC 2 audited and trusted by companies like DoorDash and Grammarly. Book a demo.