~/greenteam/nerd

Weekly review

Week of September 7-13, 2026

This week's digests were dominated by AI agents being weaponized by attackers (and abused by employees), a wave of actively exploited edge/perimeter appliance flaws, and passkey/MFA-themed identity attacks against Microsoft 365 — with CMMC and federal AI policy churning in parallel; search turned up a major Azure regional outage and a federal funding/info-sharing policy story that the curated feeds missed.

What you might have missed

Stories not surfaced in this week's daily digests.

infrastructure Meridian Micro

Azure East US Outage Takes Down ChatGPT, Claude, and Grok

A regional outage in Microsoft Azure's East US datacenter region caused cascading downtime for major third-party AI chatbot services including ChatGPT, Claude, and Grok, which rely on Azure-hosted infrastructure. Coverage of the incident framed it as a wake-up call for organizations overly dependent on a single cloud region or provider for AI-dependent workflows.

Why it matters: It highlights concentration risk in cloud infrastructure — a single regional outage can simultaneously disrupt multiple 'competing' AI vendors that all sit on the same underlying provider.

cmmc Defense One

Stopgap Funding Bill Temporarily Extends Key Cyber Information-Sharing Law

Congress's short-term continuing resolution to avoid a government shutdown before the election also included a temporary extension of the Cybersecurity Information Sharing Act of 2015, which had been set to lapse. The law provides liability protections that encourage private-sector companies to share threat intelligence with the federal government.

Why it matters: A lapse in these liability protections would chill private-sector threat-intel sharing with CISA at exactly the moment KEV additions and appliance exploitation are accelerating.

cybersec CISA

CISA Adds Four More Known Exploited Vulnerabilities to Catalog (Sept 9)

CISA published a KEV catalog update on September 9, 2026 adding four actively exploited vulnerabilities — a separate batch from the Cisco/Citrix/Fortinet additions covered in the September 10 digest story. Federal civilian agencies face their own remediation clock for whichever products are included in this batch.

Why it matters: IT admins tracking BOD 22-01 deadlines should check this advisory directly since it's distinct from the Cisco/Citrix/Fortinet KEV batch already summarized elsewhere this week.

Themes this week

Patterns observed across coverage.

AI agents as both attacker and attack surface

The week's coverage repeatedly showed autonomous AI agents driving offense (OpenAI agents behind the RubyGems RCE campaign, hundreds of agents automating PaperCut exploitation, Claude misused by Russian state actors and flagged in a fourth Anthropic incident) while also creating new SOC alert categories and exploitable surface area (ChatGPT prompt-injection data exfiltration, exposed LiteLLM admin keys, infostealers replaying AI session tokens).

Edge and remote-management appliance exploitation wave

A dense cluster of actively exploited flaws hit network and RMM/appliance products — Check Point VPN, Cisco FMC, Citrix, Fortinet, WatchGuard, MikroTik RouterOS, JFrog Artifactory, GitLab, F5 BIG-IP, ConnectWise ScreenConnect, and N-able N-central — several tied directly to ransomware deployment (Qilin) and backdoor installation.

Passkey and MFA-themed identity attacks on Microsoft 365

Multiple distinct campaigns (Microsoft's own passkey-phishing disclosures, ShinyHunters/Helix-linked lures, BigBear PhaaS, vishing against BYOD devices, and fake IT-helpdesk calls to executives) show attackers pivoting from malware toward identity-layer bypass of MFA and session-token theft to reach Microsoft 365 data.

Federal cyber policy racing to keep pace with AI adoption

CMMC Phase 2's suspension was formalized, DoD is pulling classified workloads off Anthropic, quantum-crypto deadlines were set, the EU's Cyber Resilience Act imposed a 24-hour disclosure clock, and a stopgap bill barely kept cyber information-sharing protections alive — all while a Pentagon commander warned decades of deferred network maintenance leave DoD exposed to AI-driven attacks.

Suggested new sources

Worth considering for your feed list. Review and add manually.

SecurityWeek

Broad enterprise cybersecurity news and vulnerability reporting

Provides fast, wire-style coverage of enterprise vulnerabilities and breaches that complements the more narrative-driven reporting already in the digest without much topical overlap.

RSS: https://www.securityweek.com/feed/

CyberScoop

Cybersecurity policy and threat intelligence at the industry-government intersection

Sister publication to FedScoop/DefenseScoop but focused specifically on cybersecurity rather than broader federal IT, filling the gap between pure threat-intel feeds and pure policy feeds already subscribed.

RSS: https://cyberscoop.com/feed/

SANS NewsBites

Curated, editorialized digest of the week's top security stories with expert commentary

Offers concise analyst commentary and cross-story synthesis (rather than raw article feeds), which is useful for spotting patterns like the ones surfaced in this review.