Hackers Favor US Eastern Business Hours in M365 Phishing Campaign
2026-09-11T14:52:08Z•9092479f35d7a7e27372749899c2fdb60e0b822e0a8c5afb351568b5ea7bb7e4
CVE-2026-86218AI agentsAI securityAndroid malwareDirect SendLazarusMicrosoft 365actively exploited vulnerabilitiesbotnetcredential theftcryptocurrency theftcybercrimedata breachdata extortiongovernment cybersecurityinsider threatnon-human identitiesphishingphishing-as-a-serviceprivacyprivilege escalationransomwareremote code executionshadow AIsupply-chain securityzero-day
What happened
Infosecurity Magazine feed covering September 2026 security news, including Microsoft 365 phishing and credential theft, Android malware, ransomware and data extortion, actively exploited zero-days, supply-chain breaches, AI-agent and shadow-AI risks, cybercrime disruption, and government cybersecurity policy. Notable vulnerabilities include CVE-2026-86218, a critical N-able remote-code-execution flaw; Microsoft’s September update reportedly addressed 974 CVEs including critical issues and zero-days. Several reports describe exploitation in the wild, but most entries are news summaries without
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- infosecurity_magazine
- Record identifier
- 9092479f35d7a7e27372749899c2fdb60e0b822e0a8c5afb351568b5ea7bb7e4
- Enrichment time
- 2026-09-11T14:52:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.