Major Cyber Attacks, Data Breaches, Ransomware Attacks in September 2026

September’s threat landscape made one thing clear: cyberattacks don’t follow a predictable pattern. Major disruptions hit critical infrastructure, healthcare, law enforcement, and public services alike—including high-profile incidents at CenterPoint Energy reported a cybersecurity incident affecting its corporate systems, while reported incidents and compromises involving the Royal Belgian Table Tennis Federation (FRBTT), FBI systems, Dyfed-Powys Police, an Australian government website, and Aesto Health highlighted how cyber threats continue to affect organizations across widely different sectors. From critical infrastructure and law enforcement to healthcare and public-facing services, the month’s incidents demonstrated the broad and evolving nature of cyber risk.

Beyond system disruptions, massive data exposure remained a dominant theme. Organizations such as Condé Nast, Mathspace, Gyazo, and IDScan.net were thrust into the headlines, alongside a staggering reported exposure involving Vietnam’s APIS database—potentially affecting up to 220 million records. While certain figures and threat actor claims await independent verification, the scope of these compromises underscores an expanding attack surface.

Key Cyber Security Developments in September 2026:

  1. Ransomware Incident Breakdown

  2. Major Data Breaches & Exposures

  3. Key Cyber Attacks Across Sectors

  4. Newly Discovered Malware & Ransomware Strains

  5. Critical Vulnerabilities & Patch Releases

  6. Security Advisories, Reports & Threat Intelligence

Strengthening Your Incident Readiness Navigating today’s threat environment requires preparing for multiple crisis scenarios simultaneously. At Synergy IT Solutions, we help organizations build end-to-end cyber resilience through:

Zero risk doesn’t exist, but operational readiness does. Our goal is to help you spot vulnerabilities early, minimize exposure, and empower your team to contain damage and recover rapidly when an incident strikes.

The goal is not to suggest that every cyberattack can be prevented. Instead, effective preparation helps organizations reduce exposure, identify weaknesses earlier, establish clear response procedures, contain incidents more effectively, and accelerate recovery when a cybersecurity event occurs.

Ransomware Attacks in September 2026

DateVictimSummaryThreat ActorBusiness ImpactSource Link
September 1, 2026Nutex HealthRansomware gang claims Nutex Health data breachUnknown ransomware gangA ransomware group claimed it had breached Nutex Health and stolen sensitive company and patient data, but the company had not publicly confirmed the attackers’ claims or the full scope of the alleged breach.Nutex Health Ransomware Attack
September 5, 2026Berlin state government, specifically two government departmentsBerlin launches crisis response after hackers publish stolen dataUnknown ransomware groupBerlin’s state government launched a high-level crisis response after a ransomware group published stolen data from two government departments, while investigators assessed the extent of the compromise and the impact of the exposed information.Berlin State Government Attack
September 15, 2026Organizations using vulnerable VMware vCenter Server systemsCISA: Critical VMware RCE flaw now exploited by ransomware gangsUnknownRansomware gangs exploited the critical VMware vCenter vulnerability to gain remote code execution on vulnerable systems. The flaw had already been abused by attackers to deploy a reverse SSH tool for persistence and remote access, and CISA later confirmed that ransomware actors had joined the exploitation activity, putting organizations’ networks and sensitive data at risk.Source: Bleeping Computer
September 28, 2026KeioJapan’s Keio confirms ransomware attack disrupted business systemsUnknownThe ransomware attack disrupted Keio’s business systems, including hospitality and payment-related services, while the company shut down its network to contain the incident. Railway operations were not affected, and an investigation is underway to determine whether customer or business-partner data was accessed.Source: Bleeping Computer

 

Data Breaches in September 2026

DateVictimSummaryThreat ActorBusiness ImpactSource Link
September 1, 2026Aesto Health and patients of its healthcare-provider clientsAesto Health says data breach affects over 9.5 million patientsUnknownAesto Health suffered a data breach after an unauthorized actor accessed a portion of its AWS infrastructure between December 2 and December 18, 2025, potentially exposing personal and protected health information belonging to 9,540,683 individuals, including names, dates of birth, medical information, health insurance details, government IDs, financial account information and Social Security numbers.Source: Bleeping Computer
September 1, 2026NovocureNovocure data breach affects more than 1,400 cancer patientsShinyHuntersNovocure suffered unauthorized access to some of its information systems in mid-August 2026, exposing internal patient ID numbers from more than 1,400 U.S. patient records, identifying information for fewer than 50 other patients, healthcare-provider contact details, and employee contact information; the company said its medical treatment devices and operations were not affected.Source: Bleeping Computer
September 2, 2026Dropbox usersDropbox accounts breached through Lenovo email verification flawUnknownAttackers exploited a flaw in Lenovo’s email verification process to create fraudulent Lenovo IDs and use them to access matching Dropbox accounts without passwords; around 5,000 accounts were accessed, with some users’ files viewed and downloaded.Source: Bleeping Computer
September 5, 2026Trezor customersTrezor Says ShipMonk Breach Exposed 67,000 U.S. Customers’ Data It Said Was DeletedUnknownThe ShipMonk breach exposed personal and order information belonging to approximately 67,000 additional U.S. Trezor customers whose older records should have been deleted. The exposed information included names, email addresses, phone numbers, shipping addresses and order numbers, increasing the risk of phishing, scams and potential physical-security concerns.ShipMonk Data Breach
September 5, 2026JetBrains CadenceAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS CredentialsUnknownAttackers exploited an unpatched critical TeamCity vulnerability to breach JetBrains’ Cadence environment, gaining access to the Cadence server and potentially compromising AWS credentials, secrets, backups, and other credentials available to its executions. JetBrains urged Cadence users to revoke and rotate potentially exposed credentials.JetBrains Cadence Attack
September 6, 2026Bimbo Bakeries USABimbo Bakeries USA Confirms Data Breach in Oracle EBS Zero-Day AttackClopBimbo Bakeries USA had employee data stolen after attackers exploited an Oracle E-Business Suite zero-day through a third-party vendor, with one stolen file containing victims’ names and Social Security numbers; the company had not disclosed the total number of affected individuals.Bimbo Bakeries Data Breach
September 7, 2026Condé NastCondé Nast Data of 32.8 Million Users Offered for Sale After WIRED LeakUnknownA database containing data from about 32.8 million Condé Nast user accounts was offered for $15,000 on a Russian-language cybercrime forum; a sample was found to match genuine Condé Nast account data collected in 2025, although Condé Nast had not publicly confirmed the breach. The exposed information reportedly included email addresses, names, postal addresses, dates of birth and phone numbers, but no passwords or payment-card data.Condé Nast
September 7, 2026Microsoft 365 users and organizations, particularly executives and staff across construction, healthcare, finance, real estate, and professional servicesFake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion AttacksPREY-0058, with links to UNC6671 and activity associated with Cinder/Pink-affiliated groupsAttackers impersonated IT help-desk staff in phone calls, tricked executives into handing over Microsoft 365 credentials and MFA approvals, stole session tokens, accessed SharePoint, OneDrive, Exchange and Box data, and then exfiltrated information for extortion.Source: thehackernews.com
September 7, 2026MathspaceMathspace discloses data breach affecting over 1 million peopleUnknownMathspace disclosed that attackers had breached its systems and stolen personal information belonging to more than 1 million students, staff, and parents.Source: Bleeping Computer
September 8, 2026APIS database of 220M passenger and crew records belonging to VietnamMassive data breach sees 220 million traveler records exposed – nine years of airline info leaked including passenger and passport detailsUnknownA misconfigured cloud database exposed around 220 million passenger and crew records, including names, passport and travel-document numbers, nationalities, birth dates, flight details, seat assignments and other travel information; the database was secured after researchers notified Vietnamese authorities and affected airlines.Source: techradar.com
September 8, 2026Florida Department of Highway Safety and Motor Vehicles (FLHSMV), specifically its DAVID driver-information databaseShinyHunters hackers claim breach of Florida “DAVID” DMV databaseShinyHuntersShinyHunters claimed it had breached Florida’s DAVID DMV database and stolen more than 200,000 driver records, which it allegedly obtained from the state’s online driver-information platform. The claim involved stolen personal information, but the breach had not been independently confirmed by Florida authorities.Source: Bleeping Computer
September 9, 2026Veradigm Inc. and a limited group of its healthcare customersVeradigm confirms patient data exposed in third-party data breachUnknownAn unauthorized party used stolen credentials from a third-party vendor to access a Veradigm API and download patient information, including Social Security numbers in some cases; however, clinical data was not compromised and Veradigm’s systems and services were not disrupted.Source: cybersecuritynews.com
September 10, 2026IDScan and more than 150 million individuals whose driver’s license records were stored by the companyID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolenUnknownHackers stole driver’s license records from IDScan’s cloud systems, exposing names, driver’s license numbers, passport and other government-issued identity numbers, with a dark-web database reportedly providing access to more than 150 million records and photos.Source: techcrunch.com
September 10, 2026AdaptHealth4.1 Million Impacted by AdaptHealth Data BreachUnknownAdaptHealth disclosed that an attacker had accessed its systems and stolen personal, health, and insurance information belonging to more than 4.1 million people.Source: securityweek.com
September 10, 2026Greenberg TraurigLaw firm Greenberg Traurig says ‘limited’ data posted to dark web as cyber attacks mountUnknownGreenberg Traurig said an unauthorized actor had accessed and posted a limited number of the firm’s documents on the dark web, affecting a small number of clients; the firm said its own systems had not been compromised, although some exposed information included Social Security details.Source: Reuters
September 10, 2026Weverse, the South Korean fan community platform operated by HYBEData breach hits Weverse, exposing confidential data of over 420,000 accountsUnknownWeverse confirmed that confidential information linked to 422,584 accounts had been compromised, including internal user IDs and purchase, payment-method, transaction, cancellation and refund details; the company said the exposed internal identifiers could not directly identify users or be used on their own for payment fraud.Source: teiss.co.uk
September 12, 2026RevolutRevolut confirms customer data breach through fake government requestsUnknownRevolut disclosed that an unauthorized party used fraudulent requests sent from a legitimate government agency email domain to obtain sensitive customer information, including birth dates, contact details, passport and driver’s license copies, and potentially verification selfies, account statements and transaction histories; Revolut said its systems and customer funds remained unaffected.Source: techcrunch.com
September 12, 2026Florida Department of Highway Safety and Motor Vehicles (FLHSMV), specifically its DAVID driver and vehicle databaseFlorida says motor vehicle data breach tied to credentials stolen from officer’s personal deviceShinyHuntersShinyHunters claimed access to Florida’s motor vehicle database, and FLHSMV later confirmed that a breach had occurred after attackers used credentials belonging to a Plant City police officer that had been improperly stored on the officer’s personal device; the agency said the breach was quickly contained and was no longer ongoing.Source: The Record Media
September 14, 2026Digital Agency, Government of JapanJapan’s Digital Agency says VPN flaw exposed 246,000 personnel recordsUnknownAn attacker exploited a vulnerability in a VPN device used by Japan’s Government Solution Service to gain unauthorized access to an internal system as the incident potentially exposed around 246,000 records, including names, email addresses, telephone numbers and physical addresses.Source: Bleeping Computer
September 16, 2026Spain’s Data Protection Agency (AEPD)Spain’s data agency gets first report of AI-powered data breachAI-powered autonomous agent; specific operator or threat actor not identifiedThe AI agent reportedly identified vulnerabilities, gained access to the organization’s systems, searched applications for additional weaknesses, modified personal data and accessed financial documents, although the AEPD had not yet independently verified the incident.Source: Bleeping Computer
September 17, 2026Russia’s Central Election Commission and contractors involved in the Vybory election administration platform, including RostelecomHackers claim breach of Russian election systems days before parliamentary voteCikLeakCikLeak claimed it had breached systems linked to Russia’s Central Election Commission and election-system contractors and had stolen internal documents, server configurations, passwords and employee communications; the stolen material was reportedly authenticated, although it remained unclear whether systems directly involved in voting or ballot counting had been accessed.Source: The Record Media
September 18, 2026GyazoGyazo server flaw exploited to steal 23.6 million user recordsUnknownAttackers exploited a vulnerability in Gyazo’s image-upload server to gain unauthorized access and execute commands, stealing approximately 23.62 million user records and metadata from about 490 million images. The exposed information included names, email addresses, password hashes, user and device IDs, login-session IDs, profile details and other account data, while image metadata included IP addresses, EXIF location data, OCR text and hashed passphrases. Gyazo temporarily restricted access to some images because it could not rule out that private images had been viewed.Source: Bleeping Computer
September 22, 2026Federal Bureau of Investigation (FBI)Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ dataShinyHuntersShinyHunters claimed it breached FBI systems and stole sensitive information belonging to thousands of FBI agents and job applicants, including names, home addresses and phone numbers. The group reportedly accessed an Oracle PeopleSoft server before pivoting into an Amazon-hosted government cloud environment and claimed to have taken terabytes of data. The FBI jobs website and special-agent applicant portal were also reportedly disrupted and taken offline for maintenance. The FBI had not independently confirmed the full scope of the alleged data theft at the time of the report.Source: techcrunch.com
September 22, 2026BigCommerce merchants and their customersBigCommerce merchants impacted by third-party app data breachUnknownAttackers compromised credentials belonging to the third-party Ribon and Ribon 1.5 applications and used them between September 13 and September 17, 2026, to access shopper data from affected BigCommerce stores and inject malicious scripts into a small number of merchant storefronts. Exposed information included customers’ names, email addresses, phone numbers and shipping addresses. BigCommerce said its own platform and systems were not breached, and passwords and payment-card information were not exposed.BigCommerce Merchants Data Breach
September 24, 2026AstranaAstrana latest healthcare tech firm to report data breach to SECUnknownThe cyberattack gave hackers unauthorized access to Astrana’s servers, potentially exposing confidential and sensitive information and forcing the company to restore some systems from clean backups.Source: The Record Media
September 29, 2026East Suffolk and North Essex NHS Foundation Trust (ESNEFT)10 NHS staff suspended over data breach involving Noah WoodsUnknownThe data breach led to 10 NHS staff members being suspended amid an investigation into alleged unauthorized access to the medical records of Noah Woods, raising concerns over patient confidentiality and the handling of sensitive health information.Source: The BBC
September 30, 2026Bee Cheng HiangSingapore reports first data breach linked to AI useUnknownAn AI-assisted coding error at Bee Cheng Hiang exposed the email addresses of 95,364 customers through bulk marketing emails, marking Singapore’s first reported AI-related data breach, although no further misuse of the exposed information has been found.Source: Bloomberg.com
September 30, 2026Times Car RentalTimes Car Rental says data breach affected 6.6 million accountsUnknownThe data breach affected approximately 6.6 million Times Car Rental accounts, with about 1.6 million documents accessed, including images used to verify customers’ personal information.Times Car Rental Data Breach
September 30, 2026U.S. Department of Defense / Defense Manpower Data Center (DMDC)Pentagon breach exposed sensitive data on nearly 3 million peopleUnknownA Pentagon Defense Manpower Data Center breach exposed sensitive personal information of 2.76 million living people and 294,000 deceased individuals, including Social Security numbers and military or civilian job details, although officials said there is currently no evidence the data has been misused.Source: abcnews.com

 

Cyber Attacks in September 2026

DateVictimSummaryThreat ActorBusiness ImpactSource Link
September 2, 2026Approximately 80,000 freelancers who used an unnamed freelance employment technology companyUS charges Russian for infecting 80,000 freelancers with malwareSearzhudin Tamirlanovich AktulaevAktulaev allegedly used 255 fake accounts to send malicious Excel attachments to around 80,000 freelancers between June 2016 and November 2017, infecting their devices with TVRAT and DarkVNC malware that enabled remote access and the theft of e-commerce credentials and personally identifiable information.Source: Bleeping Computer
September 8, 2026Springfield Public Schools and Everett City Hall, MassachusettsMassachusetts school district, city hall shutter after cyber incidentsUnknownCyber incidents disrupted essential systems at Springfield Public Schools, affecting phone lines and other services and forcing schools to close temporarily, while a separate attack disrupted Everett City Hall’s internal network and systems, leading the city to close the building to the public as officials investigated and worked to restore operations.Source: The Record Media
September 8, 2026Stadtwerke Landsberg, a municipal utility in Bavaria, GermanyCyber attack encrypts systems at Bavarian municipal utilityUnknownHackers encrypted the utility’s central IT network, disrupting office systems and limiting staff communications, while electricity, water and other essential services continued operating; the utility also warned that customer personal and banking data might have been accessed or stolen.Source: The Record Media
September 10, 2026Multiple Crypto Companies via Brevo email providerMultiple crypto companies warn customers of phishing emails after alleged provider breachTrezor, BitBox, CoinTracking, and their cryptocurrency usersAttackers compromised accounts at the email provider Brevo and used legitimate crypto-company mailing infrastructure to send convincing phishing emails to customers, attempting to steal wallet backups and other sensitive information; Brevo later said 138 accounts had been breached and contacts from 43 accounts had been exported.Source: The Record Media
September 13, 2026Users of Tencent’s Sogou Input Method for WindowsHackers exploit Tencent app flaw to deploy GrayRabbit malwareUNC3569, a China-aligned threat groupAttackers exploited a critical Sogou Input Method vulnerability to remotely execute code and install the GrayRabbit backdoor, which allowed them to execute commands, access files, collect system information and establish reverse shells on compromised Windows systems.Source: Bleeping Computer
September 16, 2026CenterPoint Energy and a portion of its customersCenterPoint Energy confirms cyber attack after threat actor claims data theft4d722e4d656f77The threat actor claimed to have stolen roughly 7.49 million CenterPoint Energy customer records through an external-facing API, while the company confirmed that an unauthorized third party had obtained personal information belonging to some customers. The exposed information reportedly included names, Social Security numbers, phone numbers, service and billing addresses, account numbers and billing amounts. CenterPoint said its electricity and gas services remained operational and undisrupted while its investigation continued.Source: TEISS
September 16, 2026Texas-bound foreign-flagged oil tankerUS Coast Guard boarded a Texas-bound oil tanker to investigate a cyber attack, Bloomberg News reportsUnknownThe vessel’s onboard network was suspected to have been compromised by overseas cyber actors, prompting U.S. Coast Guard and FBI personnel to board the tanker on August 21, 2026, and examine its operational technology and IT systems. Authorities investigated the potential security impact, but no operational disruption, vessel instability, danger to the crew, or environmental impact was reported.Source: Reuters
September 16, 2026Dissidents, activists, and journalists worldwideIranian hackers use CHOSEN BRICK Windows malware to spy on targetsIranian state-linked hackersIranian state-linked hackers used the CHOSEN BRICK Windows malware to compromise targeted devices and conduct surveillance against dissidents, activists, and journalists, allowing them to maintain access and monitor victims.Source: Bleeping Computer
September 18, 2026Job seekers and IT professionals, particularly web designers, engineers and cryptocurrency specialists, across more than 100 countriesNorth Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaignWaterPlum — a North Korean-linked cyber actor groupWaterPlum hackers infected at least 30,000 devices between December 2025 and July 2026 and stole cryptocurrency or wallet credentials from around 7,000 cryptocurrency wallets. The attackers posed as recruiters or technology companies, used fake job interviews to trick victims into downloading malicious files, and installed malware and remote-management tools to maintain access to infected devices. The campaign also enabled the attackers to potentially use compromised devices to gain access to companies where victims were later employed.Source: The Record Media
September 19, 2026Clop (Cl0p) ransomware leak siteShinyHunters hacks Clop leak site, threatens to extort ransomware gangShinyHuntersShinyHunters exploited an alleged unauthenticated file-upload flaw in Clop’s leak-site infrastructure, defaced the site and claimed to have stolen server data and private keys used for its onion service. The group then demanded an eight-figure payment from Clop and threatened to publish the allegedly stolen information, while Clop later responded through the hijacked site.Source: Bleeping Computer
September 21, 2026Ludwig Maximilian University of Munich (LMU Munich), GermanyCyber attack hits University of Munich, potentially exposing student financial dataUnknownAn unauthorized attacker accessed an LMU IT system containing student enrollment data, and the university believed the information had been retrieved. The potentially exposed data included names, dates of birth, contact details, LMU email addresses, bank account information, health insurance numbers, student financial-aid identifiers and education records. LMU isolated the affected server and temporarily took some other systems offline as a precaution, which made some internal services unavailable and briefly interrupted student registration, although teaching and studies were not disrupted.Source: The Record Media
September 21, 2026Royal Belgian Table Tennis Federation (FRBTT) and its French-speaking branch, Association Francophone de Tennis de Table (AFTT)Belgian table tennis, gymnastics federations hit by cyber attacksVenus1337Venus1337 claimed to have breached the Belgian table tennis federations and stolen nearly 1.7 GB of data linked to more than 66,800 members and 17,400 users, along with club administrative accounts. The attacker posted samples online, but the federation had not independently verified the claimed volume or categories of stolen data. The AFTT said its checks had not found evidence that its infrastructure or members’ phone numbers and email addresses had been compromised, and it strengthened security measures while the investigation continued.Source: The Record Media
September 22, 2026Windows users and organizations whose systems were infected with the malwareNew ClosedQuorum Windows malware uses AI for attack decisionsUnknownClosedQuorum malware autonomously used multiple AI models to decide its next actions on infected Windows systems, including stealing browser credentials, LSASS credentials and cryptocurrency-wallet data, injecting code and establishing persistence. The stolen information was sent to the operators through a Discord webhook, allowing the attack chain to operate with little or no human intervention.Source: Bleeping Computer
September 24, 2026Australian governmentOpenAI agent hacked an Australian government website, CNBC saysOpenAI AI agentThe incident exposed non-public aggregated Medicare health statistics and internal files through unauthorized access, while authorities said there was no evidence that individual Medicare or patient records were accessed.Source: CNBC
September 25, 2026Dyfed-Powys PoliceCyber attack on Dyfed-Powys Police may have accessed staff informationUnknownThe cyber attack disrupted some non-emergency police systems and may have exposed staff information, while there was no evidence at the time that members of the public had their personal data compromised.Source: The Guardian

 

New Ransomware/Malware Discovered in September 2026

New Ransomware / MalwareSummary
NodeRabbitPreviously undocumented Node.js/JavaScript remote access trojan (RAT) attributed to Iranian-linked Nimbus Manticore activity. The malware is delivered through fake coding-test archives designed to trick users into executing malicious files.
BraZetsuA Python-based framework designed to turn compromised Windows systems into commercially valuable access that can potentially be sold or transferred to initial-access brokers.
RatHatNew Android malware that uses AI-assisted device navigation while abusing Accessibility Services and Android Debug Bridge (ADB) capabilities to maintain extensive control over infected devices.
SettraA newly reported ransomware variant observed in retail and manufacturing attacks. The operation uses remote monitoring and management (RMM) tools, disrupts recovery mechanisms, and employs Bring Your Own Vulnerable Driver (BYOVD) techniques to weaken security defenses.
RemControlA new Android malware-as-a-service platform targeting users through fake IPTV applications and malvertising. It provides attackers with banking-related capabilities and extensive device-control functions after infection.

 

Vulnerabilities/Patches Discovered in September 2026

DateNew Flaws/FixesSummary
September 1, 2026CVE-2026-81578 and CVE-2026-82078Attackers exploited recently patched PaperCut vulnerabilities to bypass authentication and steal database data from vulnerable servers in ongoing attacks.
September 2, 2026CVE-2026-82329Hackers had exploited a critical JFrog Artifactory authentication-bypass flaw to forge administrator tokens and gain administrative access, potentially allowing them to read or tamper with trusted software packages used by downstream systems.
September 4, 2026CVE-2026-11645Google had patched another Chrome zero-day that attackers were actively exploiting in the wild, with the flaw affecting Chrome’s V8 JavaScript engine and potentially allowing malicious code to execute through specially crafted web content.
September 7, 2026CVE-2026-67276 and CVE-2026-86060Attackers exploited two MikroTik RouterOS vulnerabilities to bypass SSH authentication and hijack vulnerable routers, giving them full administrative control.
September 13, 2026CVE-2026-76461Attackers actively exploited a critical Cisco Secure Email Gateway zero-day to send malicious emails that enabled unauthenticated remote command execution with root privileges on affected appliances.
September 22, 2026CVE-2026-7273Attackers actively exploited a high-severity Zyxel GS1900 switch flaw to execute OS commands and steal sensitive data, with GreyNoise finding 996 compromised switches across 48 countries.
September 23, 2026CVE-2026-87902Hackers are actively exploiting a critical WordPress flaw to write malicious PHP files and execute shell commands on vulnerable websites, with attack activity reportedly surging after the vulnerability was disclosed.
September 24, 2026CVE-2026-63077Ransomware gangs are now exploiting a critical JetBrains TeamCity vulnerability to bypass authentication and execute arbitrary operating-system commands, potentially exposing credentials, configurations, and CI/CD pipelines.
September 26, 2026CVE-2026-35273ShinyHunters has resumed attacks against vulnerable Oracle PeopleSoft servers by using a URL-encoding technique to bypass Web Application Firewall protections, allowing exploitation of the critical flaw and deployment of web shells across organizations in sectors including education, healthcare, government, technology, and transportation.
September 27, 2026CVE-2026-88771 and CVE-2026-88772Citrix confirmed that two critical NetScaler ADC and Gateway zero-day vulnerabilities were actively exploited in the wild, prompting urgent warnings for administrators to secure or temporarily take internet-exposed appliances offline and apply the released security updates.
September 29, 2026CVE-2026-86950Apple has patched a CoreGraphics zero-day actively exploited in highly targeted attacks, where specially crafted files could trigger arbitrary code execution on vulnerable iPhone, iPad, and Mac devices.
September 29, 2026CVE-2026-88772Hackers exploited a Citrix NetScaler zero-day to gain root access, deploy web shells and tunneling malware, steal credentials, and potentially move deeper into internal networks, with attacks reported against organizations across government, finance, education, legal, and professional services sectors.
September 30, 2026CVE-2026-92370, CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371TeamViewer has urged users to update immediately after fixing five high-severity vulnerabilities that could allow attackers to bypass remote-session access controls, execute code, write files with elevated privileges, or escalate system privileges on vulnerable Windows, Linux, and macOS systems.
September 30, 2026CVE-2026-67279CISA has warned about a critical pre-authentication vulnerability in MikroTik RouterOS that could allow unauthenticated remote attackers to execute arbitrary code or disrupt vulnerable routers, urging organizations to secure exposed devices and apply available security updates.

 

Vulnerabilities/Patches Discovered in September 2026

DateNew Flaws/FixesSummary
September 1, 2026CVE-2026-81578 and CVE-2026-82078Attackers exploited recently patched PaperCut vulnerabilities to bypass authentication and steal database data from vulnerable servers in ongoing attacks.
September 2, 2026CVE-2026-82329Hackers had exploited a critical JFrog Artifactory authentication-bypass flaw to forge administrator tokens and gain administrative access, potentially allowing them to read or tamper with trusted software packages used by downstream systems.
September 4, 2026CVE-2026-11645Google had patched another Chrome zero-day that attackers were actively exploiting in the wild, with the flaw affecting Chrome’s V8 JavaScript engine and potentially allowing malicious code to execute through specially crafted web content.
September 7, 2026CVE-2026-67276 and CVE-2026-86060Attackers exploited two MikroTik RouterOS vulnerabilities to bypass SSH authentication and hijack vulnerable routers, giving them full administrative control.
September 13, 2026CVE-2026-76461Attackers actively exploited a critical Cisco Secure Email Gateway zero-day to send malicious emails that enabled unauthenticated remote command execution with root privileges on affected appliances.
September 22, 2026CVE-2026-7273Attackers actively exploited a high-severity Zyxel GS1900 switch flaw to execute OS commands and steal sensitive data, with GreyNoise finding 996 compromised switches across 48 countries.
September 23, 2026CVE-2026-87902Hackers are actively exploiting a critical WordPress flaw to write malicious PHP files and execute shell commands on vulnerable websites, with attack activity reportedly surging after the vulnerability was disclosed.
September 24, 2026CVE-2026-63077Ransomware gangs are now exploiting a critical JetBrains TeamCity vulnerability to bypass authentication and execute arbitrary operating-system commands, potentially exposing credentials, configurations and CI/CD pipelines.
September 26, 2026CVE-2026-35273ShinyHunters has resumed attacks against vulnerable Oracle PeopleSoft servers by using a URL-encoding technique to bypass Web Application Firewall protections, allowing exploitation of the critical flaw and deployment of web shells across organizations in sectors including education, healthcare, government, technology and transportation.
September 27, 2026CVE-2026-88771 and CVE-2026-88772Citrix confirmed that two critical NetScaler ADC and Gateway zero-day vulnerabilities were actively exploited in the wild, prompting urgent warnings for administrators to secure or temporarily take internet-exposed appliances offline and apply the released security updates.
September 29, 2026CVE-2026-86950Apple has patched a CoreGraphics zero-day actively exploited in highly targeted attacks, where specially crafted files could trigger arbitrary code execution on vulnerable iPhone, iPad and Mac devices.
September 29, 2026CVE-2026-88772Hackers exploited a Citrix NetScaler zero-day to gain root access, deploy web shells and tunneling malware, steal credentials, and potentially move deeper into internal networks, with attacks reported against organizations across government, finance, education, legal and professional services sectors.
September 30, 2026CVE-2026-92370, CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371TeamViewer has urged users to update immediately after fixing five high-severity vulnerabilities that could allow attackers to bypass remote-session access controls, execute code, write files with elevated privileges, or escalate system privileges on vulnerable Windows, Linux and macOS systems.
September 30, 2026CVE-2026-67279CISA has warned about a critical pre-authentication vulnerability in MikroTik RouterOS that could allow unauthenticated remote attackers to execute arbitrary code or disrupt vulnerable routers, urging organizations to secure exposed devices and apply available security updates.

 

Warnings/Advisories/Reports/Analysis

News TypeSummary
WarningSonicWall had warned administrators that attackers were actively exploiting two zero-day vulnerabilities in SMA 1000 appliances, urging them to apply the available fixes and check their systems for signs of compromise.
WarningSAP warned that the maximum-severity OVERPASS vulnerability in the SAP Kernel could allow unprivileged attackers to execute arbitrary commands with administrative privileges and fully compromise affected SAP systems and business data.
WarningConnectWise had warned that a new ScreenConnect vulnerability affecting file-transfer functionality impacted both cloud and on-premises deployments, while no patch was yet available and temporary mitigations had been provided.
ReportCybercriminals had created more than 360 fake government and news websites across Central Asia to lure users with bogus financial offers, steal personal information, and in some cases trick victims into installing malware that gave attackers access to their devices.
WarningChina’s top intelligence official had warned that advanced U.S. AI models could significantly lower the barriers to vulnerability discovery and malware development, potentially increasing cyber risks to China’s critical infrastructure.
WarningAcronis warned that attackers had actively exploited a high-severity local privilege-escalation flaw in its cPanel/WHM and Plesk backup plugins in limited, targeted attacks, allowing low-privileged users to gain elevated access on vulnerable Linux servers.
WarningCisco warned that attackers had actively exploited a maximum-severity Cisco Identity Services Engine (ISE) zero-day to bypass authentication and gain unauthorized access to affected devices through a vulnerable API.
WarningD-Link warned that a critical zero-day in DIR-822A routers could be remotely exploited without authentication to crash the DHCP service or execute commands, while a public proof-of-concept was already available and no patch had been released.
WarningCheck Point patched a critical Security Management Server zero-day that attackers had actively exploited to upload and execute arbitrary scripts on vulnerable systems, with a handful of customers already affected.
ReportThe U.S. Department of Veterans Affairs criticized Baylor Genetics for delaying and inadequately sharing information about a June cybersecurity breach that exposed sensitive data of 30,263 veterans, including medical and insurance information and partial Social Security numbers.
WarningAttackers are increasingly exploiting critical vulnerabilities in network-management platforms to gain remote control of enterprise infrastructure, with some attacks leading to credential theft, system compromise and ransomware deployment.
ReportU.S. lawmakers have introduced a bipartisan bill proposing voluntary cybersecurity standards and an optional certification program for telecom companies, following the major Salt Typhoon attacks that exposed weaknesses across the sector.
ReportKiteworks urged customers to temporarily shut down its platform after receiving credible intelligence about a possible cyber attack, although the company said it had found no evidence of a confirmed compromise.
ReportAttackers exploited zero-day vulnerabilities in third-party security products to breach Bitget’s internal systems, steal high-privilege credentials and execute fraudulent withdrawal commands, resulting in the theft of approximately $388 million from hot and warm wallets, while cold wallets and customer account balances remained unaffected.

 

Strengthen Your Cybersecurity Readiness with Synergy IT

September’s cyber incidents demonstrate that organizations need a proactive cybersecurity strategy that addresses vulnerabilities, data exposure, ransomware, identity threats, cloud risks, and incident response. Synergy IT provides comprehensive cybersecurity services for businesses, helping organizations identify security gaps, strengthen defenses, monitor threats, and respond effectively when incidents occur.

Our cybersecurity solutions include Cybersecurity Assessments, Vulnerability Management, Penetration Testing, Managed Detection and Response (MDR), 24/7 Security Monitoring, Security Operations Center (SOC) Services, Incident Response, Identity and Access Management (IAM), Multi-Factor Authentication (MFA), Data Security, Third-Party Risk Assessments, Compliance and Governance, Cloud Security, Microsoft Security, and Cyber Resilience Services.

Whether your organization is preparing for a potential cyberattack, responding to an existing security concern, or strengthening its overall security posture, Synergy IT can help you identify risks and implement practical security controls aligned with your business requirements.

Ready to identify your cybersecurity gaps? Contact Synergy IT for a cybersecurity assessment and speak with a security expert about protecting your organization.

 

FAQs:

What are the most common types of cybersecurity incidents affecting businesses?

Common cybersecurity incidents include ransomware attacks, phishing and credential theft, data breaches, malware infections, vulnerability exploitation, business email compromise, insider threats, denial-of-service attacks, and unauthorized access to systems or cloud environments.

How can businesses prepare for a cybersecurity incident?

Businesses can prepare by conducting regular cybersecurity assessments, identifying and prioritizing vulnerabilities, implementing strong identity and access controls, maintaining secure backups, monitoring systems for suspicious activity, developing an incident response plan, and regularly testing their response procedures.

What is a cybersecurity assessment?

A cybersecurity assessment evaluates an organization’s systems, networks, applications, identities, data, configurations, and security controls to identify vulnerabilities and potential security gaps. The assessment helps organizations understand their current risk exposure and prioritize security improvements.

How does vulnerability management help prevent cyberattacks?

Vulnerability management helps organizations identify, assess, prioritize, remediate, and continuously monitor security weaknesses across their IT environment. Addressing critical vulnerabilities before attackers exploit them can reduce the organization’s overall attack surface.

What is Managed Detection and Response (MDR)?

Managed Detection and Response (MDR) is a cybersecurity service that combines continuous security monitoring, threat detection, investigation, and response. MDR helps organizations identify suspicious activity and respond to potential threats without relying entirely on an internal security team.

Why is 24/7 cybersecurity monitoring important?

Cyber threats can occur outside normal business hours. 24/7 cybersecurity monitoring helps detect suspicious activity, security alerts, and potential threats continuously so that incidents can be investigated and addressed as quickly as possible.

What should a business do after discovering a cyberattack?

Organizations should activate their incident response procedures, isolate affected systems when appropriate, preserve relevant evidence, assess the scope of the incident, secure compromised accounts and systems, and coordinate recovery activities. Organizations may also need to address legal, regulatory, contractual, and customer notification requirements depending on the incident.

How can Synergy IT help with cybersecurity?

Synergy IT provides cybersecurity services including security assessments, vulnerability management, penetration testing, MDR, SOC services, incident response, IAM, MFA, cloud security, data security, compliance, and cybersecurity monitoring. These services help businesses identify security weaknesses, strengthen defenses, monitor threats, and improve cyber resilience.

 

Leave A Comment

This site uses Akismet to reduce spam. Learn how your comment data is processed.