DEFENDERS CLOCK
THE PUBLIC OPERATING SIGNAL FOR DEFENDERS
ISSUED 2026-09-14 · 14:00 UTC
ARCHIVED READING · PERMANENT RECORD

WEEK OF SEPTEMBER 14, 2026

72/ 100HIGH PRESSURE

Four exploited zero-days across Chrome and Windows, a shared espionage exploit kit, and firewall-management exploitation trigger the federal three-day patch clock.

↑ 3 POINTS SINCE LAST WEEK2026-W38ISSUED 2026-09-14 · 14:00 UTCMETHODOLOGY V1.0

SIGNALS

ACTIVE EXPLOITATION
RISING

Eleven current KEV additions including four exploited zero-days — two Chrome V8, two Windows — with a shared exploit kit in use by four espionage groups, and Cisco FMC exploited by ransomware and state actors alike.

CONFIDENCE · HIGH
IDENTITY & HUMAN ATTACK PRESSURE
STEADY

Machine identity joins the target list: replayable AI-service tokens surface in infostealer logs, and autonomous agents demonstrate credential compromise at speed.

CONFIDENCE · MEDIUM
INTRUSION / RANSOMWARE TEMPO
STEADY

Boston Scientific files a material-incident 8-K and ransomware operators work newly exploited firewall flaws; tempo holds at the recent raised level.

CONFIDENCE · MEDIUM

THREE MOVES THIS WEEK
01Match the federal three-day clock: patch the Cisco FMC, NetScaler, and Fortinet KEV set before the weekend, and push Chrome and Windows updates everywhere.
02If you run N-able N-central, apply the fourth hotfix and operate compromise-assumed — four exploited flaws in five weeks has earned it.
03Treat AI-service tokens like passwords: hunt for them in infostealer exposure, shorten lifetimes, and device-bind them where supported.

WHY WE BELIEVED THIS

RECEIPT LOG · WEEK 3810 RECEIPTS
CISA KEV · ANCHORCISA adds NetScaler, Fortinet, Chrome V8, and Cisco FMC CVEs to the KEV catalogSept 12 federal patch deadline — first visible use of BOD 26-04's three-day tier EXPLOITATION · 2026-09-09
CISA KEV · ANCHORCISA adds Adobe Commerce, two Windows zero-days, and N-able N-central CVEs to the KEV catalogThe Windows pair came out of a record 974-flaw Patch Tuesday; eleven KEV additions in the window overall EXPLOITATION · 2026-09-08
VENDOR ADVISORY · CORROB.Cisco advisory: Secure FMC authentication bypass (CVE-2026-20079, exploited) EXPLOITATION · 2026-09-09
INCIDENT REPORTING · CORROB.The Hacker News: four spy groups used the same Chrome and Windows exploit kit within a weekThe 'BlueMoon' kit pairing the Chrome V8 and Windows zero-days EXPLOITATION · 2026-09-09
PUBLIC DISCLOSURE · ANCHORBoston Scientific SEC 8-K (Item 1.05): material cybersecurity incident INTRUSION · 2026-09-08
INCIDENT REPORTING · CORROB.BleepingComputer: AdaptHealth confirms 4.1 million people exposed in July cyberattackDisclosure-lag evidence: July intrusion, scale confirmed this week INTRUSION · 2026-09-09
INCIDENT REPORTING · ANCHORThe Hacker News: infostealer logs expose replayable AI tokens that can bypass MFA IDENTITY · 2026-09-09
REVISION HISTORY
2026-09-14 · 14:00 UTCOriginal publication.
READINGS ARE IMMUTABLE ONCE PUBLISHED · CORRECTIONS APPEND TO THE REVISION HISTORY ABOVE · RUBRIC AT /METHODOLOGY
← FULL ARCHIVE