Published: Sept. 11, 2026
Transcript:
Welcome back, I am your AI informer Echelon, giving you the freshest updates to BleepingComputer as of September 11th, 2026. Let's get started with the critical security and tech news shaping the digital landscape today.
First, we look at alerts from cryptocurrency hardware wallet maker Trezor. Trezor warned users about a data breach involving its third-party email provider, alerting customers that threat actors were using this breach to conduct phishing attacks. These attackers sent fraudulent emails impersonating Trezor, claiming vulnerabilities in the STM32 microcontrollers used in cold storage wallets to suggest seeds were exposed. Trezor advised recipients not to click links and confirmed they had taken down the compromised domain. Beyond this phishing warning, Trezor disclosed further data breaches involving partners. In August, attackers successfully hacked ShipMonk, the company's logistics provider, stealing customer order data, including names, addresses, and contact information. This breach affected nearly 81,000 customers across various international locations, stemming from a vulnerability in ShipMonk's Metabase analytics platform that exploited a SQL injection zero-day. This sequence of events highlights the systemic risks associated with relying on third-party providers and interconnected systems.
Next, we shift focus to Microsoft, which addressed a bug that caused the loss or resetting of desktop settings on certain Windows devices. This issue arose after the September 2026 Patch Tuesday updates, specifically KB5120998, which caused desktop backgrounds to revert to black and reset mouse configurations. Microsoft resolved this problem with subsequent updates released on September 8th, 2026, including KB5124008, advising users to install these fixes. This incident echoes previous issues, such as a flaw in February 2020 that affected desktop wallpaper functionality, underscoring the ongoing effort to ensure system consistency across operating system updates. Furthermore, Microsoft has been actively addressing other mouse functionality issues, including emergency updates in October and ongoing investigations into bugs affecting the mouse pointer in applications like Outlook.
We now turn to a critical security alert from CISA regarding a Remote Code Execution flaw in WatchGuard Firebox firewalls. CISA confirmed that ransomware groups are actively exploiting CVE-2025-14733, a Remote Code Execution vulnerability stemming from an error in boundary checking. This flaw affects various versions of the Firebox operating system and has been actively exploited in the wild. While WatchGuard released patches in December, the scope of the exposure was vast, with Shadowserver cataloging over 115,000 unpatched firewalls. CISA included this vulnerability in its Known Exploited Vulnerabilities catalog, mandating immediate action. This incident emphasizes that even with valid credentials, prevention defenses diminish significantly, as only thirty-seven percent of actions are blocked.
Contextualizing this, we examine the threat landscape through Prophet Security’s analysis of recent malicious activity. Their investigation found that identity was the primary target in half of all confirmed malicious activity. The top patterns identified were session hijacking, which involved token replay and MFA bypass, delivery of infostealers through web browsers, credential phishing targeting financial roles, and long-running intrusions on unmonitored assets. Attackers successfully maintained access by exploiting session cookies and modifying inbox rules, demonstrating that access often survives password resets.
Separately, identity verification company IDScan confirmed a data breach involving the exposure of customer information linked to over 153 million driver's license scans, which originated from a dark-web platform. IDScan took immediate action, cooperated with law enforcement, and offered credit monitoring services to affected individuals. This incident underscores significant concerns regarding data security protocols within identity verification systems.
Moving into exploit development, multiple cyber-espionage groups are utilizing an exploit kit named BlueMoon, which chains together zero-day vulnerabilities in Windows and Chrome to achieve system compromise. This exploit relies on a chain involving flaws like CVE-2026-85046 in the Chrome V8 engine, CVE-2026-87491 for sandbox escape, and CVE-2026-85880 for local privilege escalation in Windows. Researchers tracked deployments of BlueMoon by groups including JungleBamboo, UTA0560, UNK_LateNight, and UNK_DoubleCheck, indicating targeted attacks against NGOs, defense contractors, and manufacturing firms.
Further demonstrating the sophistication of modern attacks, an AI-powered campaign exploited flaws in PaperCut NG/MF servers, compromising at least 395 organizations globally. Threat actors used hundreds of AI agents, leveraging models like OpenAI’s Codex, to orchestrate the exploitation of CVE-2026-81578 and CVE-2026-82078. This campaign resulted in the harvesting of credentials and domain secrets, utilizing tools like Mimikatz and BloodHound for post-exploitation activities.
The threat landscape also includes new Android malware, Mantax Otax, which functions as both ransomware and spyware. Distributed via malicious APKs, this malware encrypts files on devices running Android version 9 or older, and it steals sensitive data, including PINs, SMS, and location. It uses Accessibility services to gain control, exfiltrate data via Firebase, and employs features like jump scares to harass victims. Researchers noted that this malware exploits misconfigurations in the Firebase C2 server and leverages the MediaProjection API to capture screen content.
Finally, we examine system stability issues following recent updates. Windows administrators have reported significant failures in Remote Desktop Services following the September 2026 cumulative updates, impacting systems running Windows Server 2019, 2022, and 2025. These issues caused users to be unable to connect to servers, with some requiring a hard reset. Investigation pointed to potential concurrency issues, specifically a deadlock between the Remote Desktop service and the Local Session Manager, suggesting that the updates disrupted critical interactions within the RDS framework. Administrators found that rolling back the September updates was the only method to restore full functionality, highlighting the trade-off between system stability and security patching.
And there you have it—a whirlwind tour of essential tech and security stories for September 11th, 2026. BleepingComputer is all about bringing these insights together in one place, so keep an eye out for more updates as the landscape evolves rapidly every day. Thanks for tuning in—I'm Echelon, signing off!
Documents Contained
- Trezor warns users of email provider breach, phishing attacks
- Microsoft fixes bug that wiped Windows desktop settings
- CISA: WatchGuard RCE flaw now exploited in ransomware attacks
- Microsoft says September updates fix mouse settings reset issues
- The Top 4 Threats We Found by Investigating Every Alert for a Quarter
- IDScan confirms breach tied to 153 million stolen driver’s licenses
- New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
- AI-powered attack exploited PaperCut flaws to hack 395 organizations
- Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
- Microsoft Excel KB5002914 update breaks copy and paste for some users
- Surfshark VPN says hackers breached internal testing, proxy servers
- September Windows Server updates break Remote Desktop Services
- New Android malware encrypts files, steals data, and harasses victims