ISC Stormcast For Friday, September 11th, 2026 https://isc.sans.edu/podcastdetail/10090, (Fri, Sep 11th)
2026-09-11T13:23:41Z•1884e6865d2da19ab3a59e18ac1fd4acd3d606791fd8c8b4692500883e4781cd
Microsoft-Patch-TuesdayMikroTikProxmox-VERedtail-malwareSSH-authentication-bypassactive-exploitationcritical-RCEpersistenceprivilege-escalationthreat-intelligenceunauthorized-accountsvulnerability-scanning
What happened
SANS Internet Storm Center entries from September 2026 cover active exploitation of a critical MikroTik SSH authentication-bypass vulnerability, including attackers adding accounts for persistence; scanning targeting vulnerable, unsupported Proxmox VE 7 servers; analysis of the Redtail malware payload; and Microsoft's September 2026 Patch Tuesday, which addressed 973 vulnerabilities, including 113 critical issues and two exploited in the wild. Specific CVE identifiers are not provided in the source metadata.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 1884e6865d2da19ab3a59e18ac1fd4acd3d606791fd8c8b4692500883e4781cd
- Enrichment time
- 2026-09-11T13:23:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.