ISC Stormcast For Monday, September 14th, 2026 https://isc.sans.edu/podcastdetail/10092, (Mon, Sep 14th)
2026-09-14T13:23:41Z•eae2cfb50fb4589b8e9d1c3c5380d9aa93b5d25c1ca7bb6c657d4e6d2746f610
AI agentsLLM API abuseMicrosoft Patch TuesdayMikroTikProxmox VERedtail malwareSANS ISCSSH authentication bypassactive exploitationcredential theftcritical vulnerabilitiespersistencevulnerability scanning
What happened
SANS Internet Storm Center RSS entries for September 2026 covering active exploitation and vulnerability activity, including a critical MikroTik SSH authentication bypass with attackers adding persistence accounts, scanning for vulnerable Proxmox VE 7 servers, a large Microsoft Patch Tuesday with 973 fixes and two exploited vulnerabilities, Redtail payload analysis, and an AI-assisted operation harvesting and aggregating stolen LLM inference access.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sans_isc_diary
- Record identifier
- eae2cfb50fb4589b8e9d1c3c5380d9aa93b5d25c1ca7bb6c657d4e6d2746f610
- Enrichment time
- 2026-09-14T13:23:41Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.