Monday, September 14, 2026
Daily digest
Microsoft's September Patch Tuesday is the dominant infrastructure story today — a record 972 vulnerabilities fixed, with the update itself introducing new bugs in RDS and audio subsystems.
Microsoft ships record 972-vulnerability Patch Tuesday
Microsoft's September 2026 security update fixes approximately 972 vulnerabilities, a new monthly record, with 112 rated critical severity. This surpasses the previous record of 620 set the prior month and 570 two months prior.
Why it matters: This volume strains patch validation and testing windows for Intune-managed fleets under CMMC L2 timelines (SI.L2-3.14.1); prioritize triage of the 112 critical CVEs before broad deployment.
CISA warns of active exploitation of max-severity GitLab flaw
CISA issued an alert confirming active exploitation of a maximum-severity vulnerability in GitLab. The agency added the flaw to its Known Exploited Vulnerabilities catalog, indicating attacks are already underway in the wild.
Why it matters: If GitLab is used anywhere in the CI/CD pipeline supporting Ansible automation or container builds, this KEV listing triggers a mandatory remediation timeline under CISA BOD 22-01 and CMMC-aligned vulnerability management practices.
September updates cause RDS failures on Windows Server
Microsoft confirmed that its September 2026 security updates are causing Remote Desktop Services failures on Windows Server systems. The company acknowledged the issue but has not yet detailed a fix or workaround.
Why it matters: Any Windows Server VMs on Nutanix AHV providing RDS/RDP gateway access should hold this update in a test ring before production rollout to avoid remote access outages.
September updates break USB audio on some Windows PCs
Microsoft confirmed that USB audio devices may fail on Windows systems after installing the KB5124008 and KB5124012 September 2026 security updates. No permanent fix has been issued yet.
Why it matters: Minor but worth flagging to helpdesk before pushing this month's cumulative update to the Intune-managed Windows 11 fleet, particularly for conferencing/headset-dependent users.
Revolut discloses breach after fraudsters impersonated government agency
Fintech company Revolut disclosed a data breach after sharing customer financial information, passports, selfies, and transaction histories with a threat actor who submitted fraudulent data requests using a legitimate government email account. The attackers are reportedly demanding a ransom of 10,000 Bitcoin.
Why it matters: This illustrates how compromised or spoofed government email accounts can be used to socially engineer legitimate data disclosures — a relevant scenario for validating any 'law enforcement request' or CUI-related data requests against verified channels.
Attackers use passkey phishing to hijack Microsoft cloud accounts
Microsoft disclosed two active campaigns abusing cloud infrastructure: one sent over a million CEO-impersonation financial fraud emails between August 3-5, 2026 via third-party email delivery services, and another uses passkey-themed social engineering lures to breach Microsoft cloud accounts and exfiltrate data.
Why it matters: Passkey-themed phishing targeting Microsoft cloud accounts is directly relevant to M365 GCC High tenants; review conditional access and passkey enrollment prompts for spoofing indicators and reinforce user awareness training.
NSA reorganizes into five mission centers including cyber and AI
The NSA is undergoing a major reorganization that will consolidate its operations into five new 'mission centers,' including dedicated centers for cyber and AI. The restructuring is described as large in scope and being implemented rapidly.
Federal agencies' 'digital front door' has shifted, most haven't noticed
FedScoop reports that as AI systems increasingly mediate how citizens and businesses find and interact with government information, federal agencies have not adapted their digital presence or authority management strategies to reflect this shift.
UK government begins phasing out passwords for 23 million users
The UK government has started rolling out passkey authentication to replace passwords for 23 million citizen accounts. The move is projected to save roughly £600 a day in SMS-based two-factor authentication costs.
China-aligned group exploits Tencent Sogou flaw to deploy GrayRabbit backdoor
A China-aligned espionage group is exploiting CVE-2026-51990, a critical vulnerability in Tencent's Sogou Input Method for Windows, to deploy the GrayRabbit backdoor malware.