ISC Stormcast For Monday, September 14th, 2026 https://isc.sans.edu/podcastdetail/10092, (Mon, Sep 14th)

2026-09-14T07:23:40Z•f15e65f6649b228eae3ba0b83250270288ac5b362570035902cf982b7c8b156a
AI agentLLM API abuseMicrosoft Patch TuesdayMikroTikProxmox VERedtail malwareSSH authentication bypassaccount creationactive exploitationcredential and account farmingcritical vulnerabilitiesinference supply chainpersistencevulnerability scanningzero-day exploitation

What happened

SANS Internet Storm Center entries report active exploitation and scanning of vulnerable infrastructure, including an exploited MikroTik SSH authentication bypass with attackers creating persistent accounts, scanning for outdated Proxmox VE 7 servers, and a major September 2026 Microsoft Patch Tuesday covering 973 vulnerabilities, including 113 critical and two exploited in the wild. Additional reporting describes Redtail malware analysis and an AI-assisted operation aggregating stolen or fraudulently obtained LLM inference access through a self-operated gateway.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sans_isc_diary
Record identifier
f15e65f6649b228eae3ba0b83250270288ac5b362570035902cf982b7c8b156a
Enrichment time
2026-09-14T07:23:40Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ISC Stormcast For Monday, September 14th, 2026 https://isc.sans.edu/podcastdetail/10092, (Mon, Sep 14th) · Baitaphish