Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

2026-09-14T01:24:02Z•100b5104b9311f08849cc5082d19917f453fd636c340ce56ba5d379452d877e9
CVE-2026-20079CVE-2026-42016CVE-2026-85706AI-assisted attacksCISA KEVCheck PointChina-linked threat actorsเป็น?,Cisco Secure FMCConnectWise ScreenConnectGitLabJFrog ArtifactoryMikroTik RouterOSPaperCutRubyGemsactively exploited vulnerabilitiesarbitrary file readauthentication bypassbackdoorcloud account hijackingcredential theftgenerative AIpasskey phishingpath traversalphishingransomwareremote code executionsoftware supply chainstate-sponsored espionage

What happened

The document aggregates September 2026 cybersecurity reporting, including actively exploited vulnerabilities, ransomware and backdoor campaigns, phishing and account hijacking, AI-assisted attacks, software supply-chain compromise, mobile malware, exposed AI infrastructure, and state-sponsored espionage. Several entries describe critical or actively exploited flaws affecting GitLab, Cisco Secure FMC, JFrog Artifactory, PaperCut, Check Point, and other products.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
100b5104b9311f08849cc5082d19917f453fd636c340ce56ba5d379452d877e9
Enrichment time
2026-09-14T01:24:02Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.