Threat Intelligence

September Roundup 2026: Threat Intelligence

October 7, 2026Monthly Roundup · September 20264 min read

If you read nothing else

  • Turn off Microsoft's device code sign-in for anyone who does not need it. MFA alone did not stop September's biggest phishing service.
  • Patch Windows and every firewall or VPN box this week. Attackers were already using the flaws.
  • No saved work passwords on personal phones or laptops. One stored login opened a state database.

Six things from September. Each one says what happened, what it means for a small business or a small defense supplier, and one thing to do about it.

1. Phishers got past MFA without stealing a password

On September 22, Microsoft said it disrupted EvilTokens, a phishing service that compromised more than 12,000 inboxes at over 10,000 organizations. Victims typed a code into a real Microsoft page and approved their own MFA prompt, which signed in the attacker's session. Source: Microsoft Security blog.

What this means for you: MFA on its own did not stop this one.

Do this: ask whoever runs your Microsoft 365 to block device code sign-in for everyone who does not need it, and move admin and finance accounts to phishing-resistant FIDO security keys.

2. A trusted website widget showed visitors a fake security check

On September 14, for about five and a half hours, attackers used a stolen Cloudflare key at Brevo, a marketing platform, to alter its embedded forms and scripts in transit. Selected Windows visitors saw a fake "verify you are human" page telling them to press Win+R, paste, and press Enter, which downloaded malware. Source: Brevo incident write-up.

Sansec estimated more than 100,000 websites were likely affected. Source: SecurityWeek, September 18.

What this means for you: the danger came from a site your staff trust, not a strange email.

Do this: tell everyone that a real human check never asks you to paste or run anything. If someone did, treat that computer as compromised.

3. One saved password opened a state driver database

On September 16, Florida's motor vehicle agency said attackers reached its DAVID driver database with the login of one Plant City Police Department employee, saved on a personal device. The ShinyHunters group claimed about 200,000 driver licenses. Source: WCJB.

What this means for you: nothing was broken into. A real login was used by the wrong person.

Do this: keep work passwords in a company password manager, never in browsers or notes apps on personal phones and laptops.

4. Microsoft fixed a record 964 flaws, two already in use

September's Patch Tuesday fixed 964 vulnerabilities, 104 of them rated Critical. Two Windows flaws, CVE-2026-81963 and CVE-2026-85880, were already being exploited; both let an attacker raise their privileges on a PC. Source: Malwarebytes, September 9.

What this means for you: an attacker with a foothold on one PC can use these to take it over.

Do this: on every Windows PC, open Settings, then Windows Update, install, restart, and check again until it says you are up to date.

5. Firewalls and VPN gateways were under active attack

On September 9, CISA added three exploited flaws to its Known Exploited Vulnerabilities list: Cisco Secure Firewall Management Center (CVSS 10.0), Citrix NetScaler ADC and Gateway, and Fortinet FortiOS. Federal agencies had until September 12 to patch. Source: The Hacker News.

What this means for you: the box that guards your network is the door attackers try first.

Do this: ask your IT provider, in writing, whether you run any of these three and the date each one was patched.

6. CMMC is paused, not gone

On July 13, the Department of War paused the CMMC rollout and suspended Phase 2, pending a 60 day review. Level 1 and Level 2 self-assessments, SPRS scores, the annual affirmation, NIST SP 800-171 and DFARS 252.204-7012 all still stand. Source: WilmerHale client alert, July 20.

What this means for you: a defense supplier's obligations today did not change, and your senior official still signs the affirmation.

Do this: check that the score you posted in SPRS still matches your current System Security Plan.

Not sure where you stand? Cyber Grants Alliance offers in-kind CMMC Level 1 and CMMC Level 2 gap assessment grants, at no cost to you. See every program on Grant Programs.

Concerned about your cybersecurity posture?

CGA offers grants to help defense contractors assess and improve their compliance with CMMC and NIST SP 800-171.