The 5-Minute Cyber Brief: September 10, 2026

By George Bailey   Published: 09/09/26   Updated: 09/10/26   2 min read

Published: 09/10/26

Today’s pattern is shared kits and authentication that fails open: a Chrome exploit chain four espionage groups picked up in days, an orchestrator that trusted a suffix match, an AI gateway that swapped failed auth for an empty session object, and a Windows Update Stack zero-day that turns footholds into SYSTEM.

Lead Story

BlueMoon Turns Chromium’s Patch Gap Into a Shared Espionage Kit

Proofpoint’s BlueMoon kit chains CVE-2026-85046 (V8 type confusion), a V8 sandbox escape, and CVE-2026-85880 (Windows ALPC LPE). Both V8 issues were patch-gap zero-days—fixed upstream weeks before stable Chrome/Edge. Four clusters (TA412, UNK_LateNight, UNK_QuietRacket, UNK_DoubleCheck) adopted it from late August into early September. CISA has both CVEs in KEV.

Why it matters: Force Chromium to current stable, apply September Windows updates for the ALPC bug, and hunt chrome → cmd → curl → msgbox.exe trees plus fake Gemini extensions.

Read more on CyberExperts: Read the analysis

Also Worth Your Attention

Kestra’s endsWith(“/configs”) Badge Skip

CVE-2026-49869 (CVSS 10.0) lets unauthenticated callers create and run workflows named configs, yielding root RCE in the worker via default script plugins. Fixed in 1.0.45 / 1.3.21. KEV since September 2.

Why it matters: Orchestration hosts hold credentials and cloud reach. Patch, hunt flows named configs, and treat exposed instances as incident-grade.

Read more on CyberExperts: Read more

LiteLLM’s Empty MCP Session Object

CVE-2026-59822 lets arbitrary Bearer tokens fall through to an empty UserAPIKeyAuth() on MCP Streamable HTTP routes before 1.84.0. KEV deadline September 16 for federal civilian agencies.

Why it matters: AI gateways broker model keys and tools. Upgrade, lock down /mcp, rotate reachable secrets.

Read more on CyberExperts: Read more

Windows Update Stack Link-Following Zero-Day

CVE-2026-81963 (CVSS 7.8) is an exploited Update Stack elevation of privilege to SYSTEM on Windows 11 and Server 2025. KEV September 8. Exploitation Detected outranks the base score for triage.

Why it matters: Stage-two for every foothold. Ship September cumulatives in parallel with domain-controller critical RCEs from the same Patch Tuesday.

Read more on CyberExperts: Read the analysis

Go Deeper

Editorial Promise

CyberExperts should help you turn headlines into decisions. The value is in pulling the operational facts forward before the day turns them into background noise.

Start your morning with the signal that matters.

Subscribe to the 5-Minute Cyber Brief

George Bailey

George Bailey is a cybersecurity researcher and writer at CyberExperts, covering cyber threats, AI, cloud security, vulnerabilities, and defensive strategies. His goal is to help security professionals quickly understand what matters most and how it impacts their organizations.