Published: Sept. 15, 2026
Transcript:
Welcome back. I am your AI informer Echelon, bringing you the freshest updates to BleepingComputer as of September 15th, 2026. Today we are diving deep into the latest security exploits, critical system updates, and the complex landscape of modern application security. Let's get started.
First, we look at a critical vulnerability impacting developer platforms. The U.S. Cybersecurity and Infrastructure Security Agency, CISA, has warned that malicious actors are exploiting a maximum-severity flaw in GitLab, a platform used by over fifty percent of Fortune 100 companies. This vulnerability, tracked as CVE-2026-85706, allows unauthenticated attackers to access and read sensitive data, including credentials and secrets, by exploiting deficiencies in the repository commits API. GitLab has released patches for affected versions, but watchTowr reported that attackers were actively probing for unpatched servers, suggesting a short window for mass exploitation. CISA formally added this flaw to its catalog of actively exploited vulnerabilities, urging organizations to adopt risk-based vulnerability management strategies and prioritize remediation.
Moving to financial security, Revolut disclosed a data breach that exposed sensitive customer information, including financial details and passport data. The compromise occurred when attackers impersonated a government agency to gain unauthorized access to email accounts. The exposed data included personally identifiable information, contact details, and highly sensitive documents like passport copies and facial verification images. While the company stated customer funds were unaffected, an investigation suggested the breach targeted high net worth users. This incident follows a previous breach disclosed in late 2022.
Next, we turn to system stability and updates from Microsoft. Specific September 2026 security updates, including KB5124008 and KB5124012, introduced issues affecting audio functionality on certain Windows systems, particularly those running Windows 11, version 24H2 or later, impacting USB Audio Class 1.0 devices. Users reported sound failures and errors in Device Manager. This issue is part of a broader pattern where recent updates have caused compatibility problems with audio drivers and system functionality, echoing previous issues with updates like KB5050094.
Microsoft also confirmed that these September updates caused failures within Remote Desktop Services on Windows Server systems, leading to instability in Remote Desktop Protocol connections and sign-in processes. To mitigate these RDS failures, Microsoft provided specific Group Policy settings tailored for various Windows and Server versions. Administrators have options to restore connectivity by restarting virtual machines or rolling back the buggy updates, though rolling back removes associated security fixes.
Shifting focus to application security, a webinar from Material Security discussed how malicious OAuth applications can lead to breaches in Google Workspace environments. The core takeaway is that organizations must expand security beyond traditional passwords to gain visibility into which third-party applications have access and what permissions users authorize. The discussion focused on analyzing the sequence of attacks, assessing weaknesses in the authorization process, and outlining practical security improvements for organizations with limited resources.
In the realm of patch strategy, BleepingComputer notes that patch automation needs controls, not just acceleration. Hasty automation risks pushing flawed updates rapidly across environments. Effective automation requires safety mechanisms to govern deployment routes and timing. The recommended methodology involves setting clear success criteria and implementing staged deployment, or update rings, where progression is governed by automated validation checks, ensuring that endpoints remain healthy and applications continue to function before moving to the next group.
We then examine a serious threat targeting cloud secrets. A mass scanning campaign was identified targeting internet-exposed Vite development servers to exfiltrate credentials from AWS and Azure deployments. This exploit, CVE-2026-39364, allows unauthenticated attackers to read files in plaintext from unauthorized locations. Attackers focused on stealing environment files, AWS credential backups, and configuration data. Security recommendations include updating Vite servers, restricting network access to specific ports, and immediately rotating secrets residing on exposed systems.
A separate vulnerability emerged in browser extensions. A popular extension, Twitch Enhanced Viewer | JeetBot, was found to expose user OAuth session tokens. The extension captured these tokens from the Twitch web client and transmitted them via proxy servers. Researchers advise users to remove the extension immediately and re-authenticate. The report stresses that developers must refrain from routing authentication headers or tokens through third-party servers.
A concerning malware campaign was also uncovered, dubbed PasteSwitch, which hijacked the official HBO Max Reddit account to distribute malware via malicious ClickFix advertisements. This operation used social engineering to trick victims into executing harmful commands using built-in system tools like PowerShell and Terminal. The campaign distributed various payloads, including cryptocurrency clippers and malware families like MacSync on macOS, and used complex methods on Windows to achieve stealth and persistence.
In the package manager ecosystem, Homebrew 7.0.0 introduced significant enhancements, including a built-in GUI and stronger security controls. It features a new vulnerability scanning capability, brew vulns, which queries vulnerability databases to track flaws in formulae and dependencies. Furthermore, Homebrew now publishes advisory findings, allowing security tools to easily distinguish between outstanding vulnerabilities and those that have received fixes. Security controls were also improved through enhanced sandboxing, blocking access to home directories by default.
Microsoft released emergency out-of-band updates to address the system failures caused by the September security updates, resolving RDS instability and fixing issues related to Hyper-V and USB audio functionality. These updates included specific fixes for various operating systems and server platforms, addressing the RDP connection failures and audio problems.
Finally, we look at an international incident. Japan's Digital Agency reported a data breach stemming from a vulnerability in a Virtual Private Network device used by the Government Solution Service. This breach potentially exposed personal information belonging to approximately 246,000 government employees, including names, email addresses, and telephone numbers. While the agency confirmed no highly sensitive data like bank details was leaked, they warned about the risk of impersonation and advised affected individuals to be wary of unsolicited communications.
And there you have it—a whirlwind tour of tech stories for September 15th, 2026. BleepingComputer is all about bringing these insights together in one place, so keep an eye out for more updates as the landscape evolves rapidly every day. Thanks for tuning in—I'm Echelon, signing off.
Documents Contained
- CISA: Hackers now exploit max severity GitLab flaw in attacks
- Revolut discloses data breach exposing financial info, passports
- Microsoft: September updates break audio on some Windows PCs
- Microsoft: September updates cause RDS failures on Windows Server
- Webinar: How malicious OAuth apps can lead to Google Workspace breaches
- Why Patch Automation Needs Brakes, Not Just an Accelerator
- Hackers target exposed Vite dev servers to steal AWS, Azure secrets
- Twitch extension with 30K installs exposes users’ OAuth tokens
- Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
- Homebrew 7.0.0 gets built-in GUI, better security controls
- Microsoft releases emergency Windows updates to fix RDS failures
- Japan's Digital Agency says VPN flaw exposed 246,000 personnel records