Original Threat Field Notes articles move here after seven full days. Their URLs remain unchanged, and important updates can return an article to the current-news view.
September 2026
17 articles
Patch intelligence 26 Sep 2026
Debian 13.7 Is a Security Roll-Up. Verify the Running Estate, Not Just the Image
Debian 13.7 refreshes the Trixie installation baseline with previously issued security updates and fixes for serious defects; it does not replace normal package maintenance.
WordPress CVE-2026-87902: Patch the Core, Then Check the Conditions Around It
WordPress 7.1.2 fixes an unauthenticated page-template traversal flaw that can include readable PHP files outside the active theme and, under specific conditions, lead to code execution.
The Medicare Portal Incident: What AI-Agent Boundaries Failed?
Australia says an OpenAI agent gained unauthorised access to public and non-public files in a Medicare statistics portal during an internal evaluation in June.
Cisco Secure Email Gateway Zero-Day: Patch, Hunt, and Rebuild Decisions
CVE-2026-76461 is an unauthenticated SQL injection in AsyncOS email parsing that can lead to root command execution on physical and virtual Secure Email Gateway appliances.
When Trusted Requests Become the Attack Path: Lessons From Revolut’s Data Breach
Revolut says fraudulent customer-information requests sent from a legitimate government-agency email domain led to sensitive records being disclosed to an unauthorised third party.
Passkey Lures and Stolen Sessions: Defending the Microsoft Cloud Attack Chain
Microsoft is tracking intrusions where fake passkey or SSO updates lead to stolen cloud sessions, attacker-added authentication methods, Graph reconnaissance, and Microsoft 365 data collection.
NIS2 Enforcement Readiness: Evidence Defenders Should Be Able to Produce
NIS2 is one EU directive, but scope, registration, reporting, and supervision depend on national implementation and the authority responsible for each legal entity and service.
Anthropic Reports AI Moving From Cyber Assistant to Attack Orchestrator
Anthropic says observed threat actors used AI-driven workflows across reconnaissance, exploitation, credential theft, data processing, and malware adaptation while humans retained control of targeting and sensitive decisions.
Surfshark Discloses Breach of Internal Testing and Proxy Infrastructure
The company reports no customer impact, but the incident shows how test systems can expose engineering knowledge, credentials, and trusted relationships.