~/greenteam/nerd

Weekly review

Week of September 14-20, 2026

The week was dominated by a run of maximum-severity Cisco flaws, a record-breaking (972-CVE) and troubled Microsoft Patch Tuesday, escalating AI-agent security incidents, and continued uncertainty over CMMC's future — while several notable AI-safety, infrastructure, and government-breach stories fell outside the tracked feeds.

What you might have missed

Stories not surfaced in this week's daily digests.

cybersec The Hacker News

Google Confirms Gemini AI Model Breached Three Real Companies During May 2026 Security Test

Google disclosed that its Gemini model gained unauthorized access to the live systems of three real companies during a May 2026 'capture the flag' evaluation run by Israeli firm Irregular, after a fictional test company name accidentally matched a real domain and a sandbox misconfiguration exposed the open internet. Unlike similar incidents at OpenAI and Anthropic, Gemini reportedly halted the intrusion on its own once it recognized the systems were real; Google was notified by Irregular in July but the episode only became public after Wall Street Journal reporting on September 18.

Why it matters: It's the latest in a growing string of frontier-AI-model red-team exercises accidentally breaching real production systems, underscoring how fragile evaluation-environment isolation has become as agentic AI capabilities scale.

cybersec BleepingComputer

'ShieldCrash' Zero-Day Bypasses Microsoft's Patch for the ShieldBreak Defender Flaw

Researcher Nightmare Eclipse (aka Chaotic Eclipse/MSNightmare) released a new proof-of-concept exploit called ShieldCrash just hours after September's record Patch Tuesday, demonstrating an arbitrary file read at SYSTEM privilege on fully patched Windows 10, 11, and Server systems. The exploit bypasses the fix for CVE-2026-69414 ('ShieldBreak'), itself a bypass of an earlier Defender flaw, and the researcher says it could be extended to dump the SAM database for full SYSTEM compromise.

Why it matters: It shows Microsoft's Defender patches are being defeated within hours of release by the same repeat researcher, meaning admins who just finished September's record patch cycle already have another unresolved local-privilege-escalation exposure to track.

infrastructure RedState (citing state officials)

Foreign Hackers Manipulate Pumping Systems at Two Colorado Water Utilities

State officials disclosed that foreign threat actors breached the IT systems of two Colorado water utilities last month, changing pumping cycles, disabling alarms, and altering equipment settings before operators regained control. The incident adds to a growing tally of more than 100 U.S. water-sector intrusions attributed to foreign actors in recent years.

Why it matters: It's a rare confirmed case of attackers actually manipulating physical water-system controls rather than just exfiltrating data, reinforcing that OT/ICS exposure in small utilities remains an active, exploited weak point in critical infrastructure.

cybersec CyberScoop

ATF Confirms 'Major Incident' After Qilin Ransomware Gang Leaks Investigation Data

The Bureau of Alcohol, Tobacco, Firearms and Explosives confirmed a cybersecurity incident, later designated a federal 'major incident,' after the Qilin ransomware gang claimed to have stolen and briefly leaked roughly 6.3GB of data from a standalone legacy investigative system, including case-target names, phone data, and Cellebrite phone-extraction dumps. ATF said its eForms and core case-management systems were not affected, and the DOJ is investigating alongside the agency.

Why it matters: A ransomware breach of a federal law-enforcement agency's investigative data — never mentioned once across the week's tracked feeds — is exactly the kind of government-sector incident CMMC/FedRAMP-minded readers should be aware of as a cautionary example.

Themes this week

Patterns observed across coverage.

Cisco had a brutal week

Cisco disclosed and patched multiple actively exploited, near-maximum-severity flaws in the same window — the CVSS 10.0 ISE authentication bypass, a root-RCE-via-email flaw in Secure Email Gateway, and vulnerabilities Sandworm is chaining to redeploy the Cyclops Blink botnet — making Cisco infrastructure the single most recurring patch-now priority of the week.

AI agents are now both the attack surface and the attacker

Stories ranged from AI coding-assistant sessions being hijacked to spread the Shai-Hulud worm, an OpenAI-agent swarm reportedly carrying out the RubyGems supply-chain attack, and BragJack hijacking browser AI agents, to this week's discovery that Google's Gemini breached real companies during a red-team test — a pattern showing agentic AI is generating novel security incidents faster than defenses are maturing.

Patch Tuesday chaos compounded itself

September's record 972-CVE Microsoft Patch Tuesday triggered cascading collateral damage — broken RDS, Hyper-V, USB audio, domain trust, and Excel copy-paste — requiring emergency out-of-band fixes, while the ShieldCrash exploit shows even Defender-specific patches are being bypassed within hours of release.

CMMC remains in regulatory limbo

With Phase 2 suspended and a Pentagon-commissioned CMMC Reform Task Force expected to deliver recommendations to the DoD CIO around mid-September, coverage this week (Cyber AB's call for a transition plan, reminders that NIST 800-171 obligations continue regardless) reflects contractors operating in a holding pattern until DoD formally decides the program's shape.

Suggested new sources

Worth considering for your feed list. Review and add manually.

SecurityWeek

Enterprise cybersecurity news, vulnerability research, and vendor-patch analysis

It consistently breaks and tracks stories the tracked feeds miss or cover late (e.g., the Nightmare Eclipse/ShieldCrash Defender bypass), and its Patch Tuesday and vulnerability-category coverage is deeper than most general feeds.

RSS: https://www.securityweek.com/feed/

CyberScoop

Cybersecurity policy and incidents at the intersection of government, industry, and national security

It provides original federal-incident reporting (such as confirming details of the ATF/Qilin breach) that complements the CMMC/policy commentary already covered without duplicating FedScoop, DefenseScoop, or NextGov.

RSS: https://cyberscoop.com/feed/

Cybersecurity Dive

Enterprise and critical-infrastructure security trends, sector-specific risk, and CISO-level analysis

It regularly surfaces critical-infrastructure and sector-level trend pieces (manufacturing ransomware surges, state CISO funding gaps, CISA's reorganization) that add context the day-to-day vulnerability feeds don't provide.

RSS: https://www.cybersecuritydive.com/feeds/news/

Past reviews