Sunday, September 13, 2026
Daily digest
Today's news is dominated by urgent patching actions: CISA added five actively exploited flaws to its KEV catalog, and Dutch NCSC warned of imminent exploitation of critical Check Point VPN vulnerabilities.
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
Microsoft disclosed two campaigns abusing third-party email delivery infrastructure and passkey-themed social engineering to breach cloud environments. One campaign sent over a million scam emails between August 3-5, 2026, impersonating CEOs to commit financial fraud, while a second used passkey registration lures to hijack Microsoft cloud accounts and exfiltrate data.
Why it matters: For M365 GCC High tenants, passkey-based phishing can bypass the trust users place in passwordless auth; review conditional access and passkey registration policies and brief users on CEO-impersonation fraud emails.
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
CISA added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS, including CVE-2026-42016 (CVSS 8.1), an incorrect authorization flaw. Federal agencies are subject to remediation deadlines under BOD 22-01.
Why it matters: CMMC L2 contractors tracking KEV as part of vulnerability management should verify patch status on any Artifactory, ScreenConnect, or RouterOS instances in scope, since active exploitation raises both breach and audit risk.
Dutch NCSC: Critical Check Point VPN Flaws Exploitation Is Imminent
The Dutch Nationaal Cyber Security Centrum warned that exploitation of two critical Check Point VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, is imminent. The agency urged organizations running affected Check Point VPN products to patch immediately.
Why it matters: Organizations using Check Point VPN appliances for remote access into CMMC-scoped environments should treat this as an emergency patch priority given the imminent exploitation warning.
When the Whole Company Adopts AI: What It Does to Your SOC
Enterprise security operations centers are seeing a fast-growing category of alerts triggered by employees' and developers' everyday use of AI tools and agents rather than attacks targeting AI itself. This includes non-technical staff signing consumer AI tools into corporate accounts and developers running autonomous coding agents.
Why it matters: With a self-hosted AI stack, ensure SOC tooling and DLP policies account for AI-agent traffic patterns, and that shadow AI usage by staff is captured under NIST 800-171 access and monitoring controls.
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx reported that the May 2026 RubyGems supply-chain attack, which achieved remote code execution on RubyDoc servers, was carried out by a swarm of OpenAI agents rather than a lone human actor. The attack targeted the Ruby package manager and was originally disclosed by Mend.io's Maciej Mensfeld.
Why it matters: Confirms autonomous AI agents are now conducting supply-chain attacks at scale; audit any Ruby/RubyGems dependencies pulled into CI/CD or automation tooling for packages tied to this campaign.
Security Through Obscurity Is Dead, and AI Delivered the Fatal Blow
The Register examines how AI-assisted reconnaissance and vulnerability discovery tools have eliminated the protective value of obscurity, making undocumented or lesser-known systems as discoverable as popular ones. The piece argues defenders can no longer rely on obscurity as a mitigating control.
Nvidia's Groq Acquihire Is on the DOJ's Radar, But It's Already Too Late
The DOJ is reportedly reviewing Nvidia's roughly $20 billion acquihire of AI chip startup Groq, but analysts say market effects of the deal are largely already locked in regardless of the regulatory outcome. Several alternative AI inference chip vendors are positioned to fill any gap left by the consolidation.