Published: 09/10/26
Today’s pattern is shared kits and authentication that fails open: a Chrome exploit chain four espionage groups picked up in days, an orchestrator that trusted a suffix match, an AI gateway that swapped failed auth for an empty session object, and a Windows Update Stack zero-day that turns footholds into SYSTEM.
Lead Story
BlueMoon Turns Chromium’s Patch Gap Into a Shared Espionage Kit
Proofpoint’s BlueMoon kit chains CVE-2026-85046 (V8 type confusion), a V8 sandbox escape, and CVE-2026-85880 (Windows ALPC LPE). Both V8 issues were patch-gap zero-days—fixed upstream weeks before stable Chrome/Edge. Four clusters (TA412, UNK_LateNight, UNK_QuietRacket, UNK_DoubleCheck) adopted it from late August into early September. CISA has both CVEs in KEV.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
Why it matters: Force Chromium to current stable, apply September Windows updates for the ALPC bug, and hunt chrome → cmd → curl → msgbox.exe trees plus fake Gemini extensions.
Read more on CyberExperts: Read the analysis
Also Worth Your Attention
Kestra’s endsWith(“/configs”) Badge Skip
CVE-2026-49869 (CVSS 10.0) lets unauthenticated callers create and run workflows named configs, yielding root RCE in the worker via default script plugins. Fixed in 1.0.45 / 1.3.21. KEV since September 2.
Why it matters: Orchestration hosts hold credentials and cloud reach. Patch, hunt flows named configs, and treat exposed instances as incident-grade.
Read more on CyberExperts: Read more
LiteLLM’s Empty MCP Session Object
CVE-2026-59822 lets arbitrary Bearer tokens fall through to an empty UserAPIKeyAuth() on MCP Streamable HTTP routes before 1.84.0. KEV deadline September 16 for federal civilian agencies.
Why it matters: AI gateways broker model keys and tools. Upgrade, lock down /mcp, rotate reachable secrets.
Read more on CyberExperts: Read more
Windows Update Stack Link-Following Zero-Day
CVE-2026-81963 (CVSS 7.8) is an exploited Update Stack elevation of privilege to SYSTEM on Windows 11 and Server 2025. KEV September 8. Exploitation Detected outranks the base score for triage.
Why it matters: Stage-two for every foothold. Ship September cumulatives in parallel with domain-controller critical RCEs from the same Patch Tuesday.
Read more on CyberExperts: Read the analysis
Go Deeper
Editorial Promise
CyberExperts should help you turn headlines into decisions. The value is in pulling the operational facts forward before the day turns them into background noise.
Start your morning with the signal that matters.
Subscribe to the 5-Minute Cyber Brief
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
Free. Weekday mornings. Unsubscribe anytime.
Built from 100+ trusted cybersecurity sources.