ISC Stormcast For Monday, September 14th, 2026 https://isc.sans.edu/podcastdetail/10092, (Mon, Sep 14th)

2026-09-14T13:23:41Z•eae2cfb50fb4589b8e9d1c3c5380d9aa93b5d25c1ca7bb6c657d4e6d2746f610
AI agentsLLM API abuseMicrosoft Patch TuesdayMikroTikProxmox VERedtail malwareSANS ISCSSH authentication bypassactive exploitationcredential theftcritical vulnerabilitiespersistencevulnerability scanning

What happened

SANS Internet Storm Center RSS entries for September 2026 covering active exploitation and vulnerability activity, including a critical MikroTik SSH authentication bypass with attackers adding persistence accounts, scanning for vulnerable Proxmox VE 7 servers, a large Microsoft Patch Tuesday with 973 fixes and two exploited vulnerabilities, Redtail payload analysis, and an AI-assisted operation harvesting and aggregating stolen LLM inference access.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
eae2cfb50fb4589b8e9d1c3c5380d9aa93b5d25c1ca7bb6c657d4e6d2746f610
Enrichment time
2026-09-14T13:23:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Monday, September 14th, 2026 https://isc.sans.edu/podcastdetail/10092, (Mon, Sep 14th) · Baitaphish