~/greenteam/nerd

Saturday, September 12, 2026

Daily digest

Anthropic published a major threat-intelligence disclosure today detailing multiple nation-state and criminal groups abusing Claude for offensive operations — a preview of the AI-enabled attack patterns SOCs will need to detect going forward.

cybersec The Hacker News

GitLab Patches CVSS 10 Path Traversal Flaw, Already Seeing Exploitation Attempts

GitLab released patches for CVE-2026-85706, a maximum-severity path traversal vulnerability in the repository commits API that lets unauthenticated attackers read arbitrary files from a GitLab server. Researchers observed in-the-wild scanning and probing within hours of the public disclosure.

Why it matters: If GitLab is used for internal repos or CI/CD in your environment, this needs immediate patching — unauthenticated file read on a dev platform is a direct path to source code, secrets, and CUI exposure under CMMC L2 configuration management controls.

infrastructure BleepingComputer

JFrog Artifactory Flaws Chained to Deploy Backdoor Malware

Threat actors are actively exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, escalate to admin privileges, and install a Rust-based backdoor on self-hosted servers. All three flaws have available patches.

Why it matters: Self-hosted Artifactory instances used in software supply chains are a prime target for CUI-adjacent compromise; patch immediately and audit for unauthorized admin accounts or unexpected outbound connections.

cybersec The Record

Florida DMV Database Breached Using Stolen Police Officer Credentials

The Florida Department of Highway Safety and Motor Vehicles confirmed a breach of its DAVID driver database, claimed by ShinyHunters, after attackers obtained login credentials stored on a police officer's personal device.

Why it matters: A reminder that personal-device credential theft bypasses MFA and network controls entirely — reinforces the case for strict conditional access and blocking personal-device credential storage/sync for any account with access to sensitive systems.

cybersec BleepingComputer

Passkey-Themed Phishing Campaigns Target Microsoft 365 Accounts

Microsoft reports that threat actors linked to ShinyHunters, Helix, and other extortion groups are using passkey and SSO-themed social engineering lures to trick users into compromising Microsoft 365 accounts and exfiltrating data.

Why it matters: Directly targets the passkey/SSO flows GCC High tenants rely on for phishing-resistant auth — review Conditional Access and Entra ID sign-in logs for anomalous passkey registration attempts.

cybersec The Hacker News

Anthropic Disrupts Russian State-Sponsored Group Using Claude to Rebuild Malware

Anthropic disrupted a Russian state-sponsored cyber-espionage campaign, tracked as GTG-20006 and linked to Midnight Blizzard, that used Claude to develop an AI-assisted workflow for evading detection and rebuilding malware after being flagged.

Why it matters: This actor historically targets government and defense contractors; expect faster malware iteration cycles that could shorten the window between detection signatures and re-emergence in CMMC-scoped environments.

cmmc DefenseScoop

DOD Set to Move All Classified AI Workloads Off Anthropic by October

U.S. defense officials disclosed plans to migrate all classified AI workloads away from Anthropic models by October, shifting to military-tuned frontier models as part of a fast-tracked enterprise AI deployment effort.

Why it matters: Signals a broader federal push toward vetted, purpose-built AI models for sensitive workloads — relevant context if evaluating or justifying a self-hosted AI stack over commercial cloud AI APIs for CUI-touching use cases.

cmmc Federal News Network

White House Quantum Policy Sets Post-Quantum Cryptography Deadline for Civilian Agencies

A new White House policy establishes an accountability deadline for federal civilian agencies to complete migration to post-quantum cryptography, formalizing timelines that had previously been guidance-only.

Why it matters: Contractors handling CUI should expect PQC migration requirements to flow down through DFARS/NIST guidance over the next assessment cycles — start inventorying crypto-dependent systems now.

cmmc The Register

EU Cyber Resilience Act Starts 24-Hour Vulnerability Disclosure Clock

The EU's Cyber Resilience Act now requires manufacturers to report actively exploited vulnerabilities and severe security incidents within 24 hours through ENISA's new reporting platform.

Why it matters: If any software or hardware vendors in your supply chain sell into the EU, expect faster (and more frequent) vulnerability disclosures to track — useful for tightening your own patch-SLA and vendor risk assessments.

cmmc Dark Reading

CISA Pushes for Clearer Guidance, Less Spin, as Cyber Outages Escalate

A new joint government advisory calls for more transparent breach notification and incident response protocols, reflecting growing frustration with vague public communications during major cyber outages.

Why it matters: Points toward stricter incident reporting expectations that could eventually inform CMMC/DFARS incident notification timelines — worth tracking for future compliance updates.

cybersec Ars Technica Security

ClickFix Social Engineering Attacks Spreading Rapidly Across Windows and macOS

ClickFix-style attacks, which trick users into pasting malicious commands into Run dialogs or terminals under the guise of fixing an error, are spreading rapidly across both Windows and Mac systems due to their simplicity and effectiveness.

Why it matters: This technique bypasses many endpoint controls by relying on user execution rather than exploits — worth adding to security awareness training for the Intune-managed fleet and considering PowerShell/Run-command restrictions via policy.

infrastructure BleepingComputer

Microsoft Fixes Teams and Outlook Launch Failures on ARM Windows PCs

Microsoft resolved a bug that prevented Teams and Outlook from launching on ARM-based Windows devices following updates released since the August 2026 Patch Tuesday.

Why it matters: If any ARM-based Windows 11 devices are in the Intune-managed fleet, push the fix update to restore Teams/Outlook functionality post-Patch Tuesday.

cybersec Dark Reading

Threat Actor Generates 1 Million Personalized Fraud Emails in Three Days

Researchers documented a malicious email campaign in which attackers used AI to generate roughly one million individually personalized fraud emails within a three-day span, combining scale with tailored credibility.