ISC Stormcast For Friday, September 11th, 2026 https://isc.sans.edu/podcastdetail/10090, (Fri, Sep 11th)
2026-09-11T07:23:40Z•519fd0cd906f0589befe8fe7464875343d01681801aab5974a7e2544b5c473d8
Microsoft-Patch-TuesdayMikroTikProxmox-VERedtail-malwareSSH-authentication-bypassactive-exploitationcritical-RCEpersistenceprivilege-escalationthreat-intelligencevulnerability-scanning
What happened
SANS Internet Storm Center entries for September 2026 highlight active exploitation of a critical MikroTik SSH authentication-bypass vulnerability, including attackers creating persistent accounts; scanning targeting vulnerable, unsupported Proxmox VE 7 systems; a record Microsoft Patch Tuesday with 973 fixes, including 113 critical vulnerabilities and two exploited in the wild; and analysis of a Redtail malware payload.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- 519fd0cd906f0589befe8fe7464875343d01681801aab5974a7e2544b5c473d8
- Enrichment time
- 2026-09-11T07:23:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.