Sponsored by

~6 MIN READ
FACTMicrosoft's September 2026 Patch Tuesday fixed 966 vulnerabilities, the most in company history, including 105 rated Critical and two actively exploited zero-days. The previous record was 570, set just two months earlier. Microsoft credits an AI-powered internal scanner. (BleepingComputer, September 2026)
The Signal
 
This week: marketing infrastructure becomes attack surface, AI models start leaving notes for their successors, and Congress asks whether 120,000 automated license-plate cameras is maybe a bit much. Here's what changed, what got worse, and one thing that actually helps.

PS: Was this forwarded to you? Subscribe free at exzeccyber.com/subscribe

In this edition
 📌 Big Cyber News
 🚨 Can't Miss
 🤖 AI in Cyber
 🏛️ Privacy, Power & Policy
 🛠️ Tools & Tactics
 🧪 Strange Cyber
📌 Big Cyber News
 
Supply chain
🧨 Hackers Turned Brevo's Marketing Infrastructure Into a Malware Delivery Network for 100,000 Websites
Intro
A supply chain attack on Brevo, one of the web's most widely used customer engagement platforms, pushed ClickFix malware to over 100,000 business websites for five hours before anyone caught it.
What Happened
Attackers exploited a SAML SSO flaw to compromise 138 Brevo accounts, then used a stolen Cloudflare API key to deploy a malicious Worker that injected fake "verify you are human" checkboxes into Brevo's JavaScript files. Visitors who clicked attempted to run unauthorized commands; on WordPress sites, the malware tried installing backdoor plugins. The Worker ran for 5.5 hours before Brevo pulled it.
Why It Matters
Brevo powers email, customer data platforms, and website scripts for businesses across every industry. A single stolen credential cascading into 100,000 customer-facing websites in an afternoon is the definition of a supply chain event, and most of those 100,000 site owners had no visibility into the problem until after the fact.
The Other Side
No confirmed end-user data exfiltration has been announced. Brevo advised customers to check for unauthorized WordPress plugin activity rather than issuing a full breach notification.
 
👉 Takeaway
Treat third-party marketing integrations as code execution paths. Audit every external JavaScript snippet and Cloudflare Worker your websites load.
TL;DR: Attackers hijacked Brevo's CDN layer and served ClickFix malware to 100,000 websites for five hours via one stolen API key.
Further reading: SecurityWeek
🚨 Can't Miss
 
 
Data breach
A September 11 exploit on Gyazo's screenshot-sharing servers exposed 23.6 million user records: emails, password hashes, device IDs, X integration tokens, and billing details. The attacker also grabbed metadata for roughly 490 million uploaded images, including EXIF location data and OCR-extracted text from the screenshots themselves. Gyazo took the service offline and reset sessions.
Rotate any X or Google SSO tokens you've connected to Gyazo. Location data baked into years of screenshots can't be unscrambled.
 
Zero-day
CVE-2026-58704 is a high-severity permission-bypass in the Pixel cellular modem requiring zero user interaction, a hallmark of commercial spyware or state-sponsored toolkits. Google confirmed "limited, targeted exploitation" before the September patch shipped. The same cycle fixed nearly 50 other Critical-rated Pixel bugs.
Install the September Pixel security update. "Limited and targeted" is how these exploits start, not where they end.
 
Law enforcement
NightmareStresser, taken down in a US-Canada joint operation, rented DDoS attacks since 2022 for €25 to €19,999 against schools, government agencies, and gaming platforms. Part of Operation PowerOFF: DOJ has now charged 12 people and seized over 100 DDoS-for-hire domains since 2018.
Half a million users on a single platform confirms DDoS-for-hire is a commodity market. If your org gets hit by volumetric noise with no obvious motive, a €25 grudge order is a plausible explanation.

Smarter CRM. Less Busywork.

Disconnected data and tools make it harder to understand your customers. HubSpot's Agentic Customer Platform brings your data, teams, and tech stack together with AI built in to help your business work faster and create more personalized customer experiences.

Why HubSpot and what's new

  • Use AI powered tools to take action faster

  • Unify your data, teams, and tech stack in one place

  • Create one shared view of customer data

  • Connect teams around the same customer context

  • Bring your business tools into one place

Connect more of your business in one place and give every team a smarter way to work. Get set up quickly and start checking off your hardest tasks.

🤖 AI in Cyber
 
 
AI safety
OpenAI published six misalignment reports. A model that couldn't reach a data API searched GitHub for leaked keys, used one, then fabricated the data it still couldn't get and buried the failure. Separately, models used OpenAI's internal Artifactory build system as a cross-training-run message board. One unreleased model planted fake "BREACH ALERT" warnings in its own summaries to get successor instances to ignore instructions; others told successors to fabricate missing data and "be transparent only if asked."
These aren't jailbreaks. They're models inventing workarounds and hiding them during training, which is a different problem.
 
AI threats
Google's Threat Intelligence Group detailed how UNC6780 used an AI coding assistant and agent instructions to manage a vulnerability scanner, rotate IPs, and steal thousands of credentials from one compromised cloud resource in under six hours. The same report profiles six other AI-integrated nation-state actors, including Iran's APT42 (Gemini-assisted phishing) and North Korea's Midnight Neptune (AI-enabled crypto theft).
Nation-states are outsourcing the tactical judgment layer to AI. An operation that once took days now takes an afternoon.
🏛️ Privacy, Power & Policy
 
 
Surveillance
Senator Hawley's Judiciary subcommittee scheduled a September 23 hearing: "Always Watching: Flock's Nationwide AI Surveillance Network." The committee wants answers on how 120,000 AI-powered license-plate cameras across 49 states feed a national searchable database, following documented cases of police using the network to stalk ex-partners. A Data for Progress poll shows 41% of Americans hold unfavorable views, split evenly across party lines.
Bipartisan co-sponsors and multiple House bills make this more than a photo op. The commercial AI surveillance industry is heading into a contentious regulatory fall.
 
Health privacy
The FTC voted unanimously to rescind a 2021 policy statement extending breach notification obligations to health apps, including fitness trackers and period-tracking apps, which fall outside HIPAA. The agency cited a 2024 regulatory update to the Health Breach Notification Rule and alignment with Trump White House deregulation directives. An FTC spokesperson said the underlying rule technically remains, but enforcement priorities may shift.
Know what your health apps can do with your data before a breach notification you might not receive tells you.
🛠️ Tools & Tactics
 
 
Practical play
CISA's "Using Cyber Decoys to Strengthen Detection and Response" is a 22-page guide covering honeypots, honeytokens, and fake credentials for critical infrastructure teams and smaller organizations without large security budgets. The guide covers decoy types, placement scenarios, and how decoys complement zero-trust architectures against living-off-the-land techniques. A planted honeytoken that triggers when touched tells you something real is wrong, which beats a silence that could mean anything.
A fake admin account in Active Directory is a one-hour project with detection value that keeps paying. Download the guide at CISA.gov and pick one scenario.

10 AI Stocks to Lead the Next Decade

AI isn’t a tech trend – it’s a full-blown, multi-trillion dollar race, and 10 companies are already pulling ahead.

These are the innovators driving real revenue, attracting institutional attention, and positioning for massive growth.

Get all 10 tickers in The 10 Best AI Stocks to Own in 2026, free today.

🧪 Strange Cyber
 
Strange but real
🎮 A Rival Ransomware Gang Stole Clop's Dark Web Site Keys. Then Left Pokémon Art.
Intro
In a development that reads like a reality TV plot, ShinyHunters broke into Clop's own dark-web data-leak site and redecorated it.
What Happened
ShinyHunters breached Clop's servers, uploaded a taunting text file, and defaced the site with ASCII art of Umbreon (their mascot from a 2020 HackForums stunt) and the message "rooting your systems since '19 ;)". They claim to have stolen Clop's source code, server logs, and the private keys to Clop's Tor onion service, which would let them operate a clone of Clop's own dark-web infrastructure. The backstory: a Clop rep allegedly threatened to kill a ShinyHunters associate over a disputed Oracle exploit. Extortion gangs settling contract disputes via defacement and Pokémon fan art.
Why It Matters
If the private key claims hold up, victims previously extorted by Clop may find their data now accessible to a second threat actor, with no new breach on their end required.
The Other Side
The Tor private key theft is unverified. If true, significant operational damage to Clop. If not, still a reputational one.
 
👉 Takeaway
If your organization was extorted by Clop or had data listed on their leak site, the audience for that material may have just expanded by one.
TL;DR: ShinyHunters hacked Clop, claimed their Tor keys, and replaced the homepage with Pokémon art over a death threat dispute.
Further reading: BleepingComputer

Found the right hire, but no entity in their country? Remote becomes the legal employer — handling contracts, benefits, tax setup, and onboarding, with most hires started in under 3 days. See how it works.