ARCHIVED READING · PERMANENT RECORD
WEEK OF SEPTEMBER 14, 2026
72/ 100HIGH PRESSURE
Four exploited zero-days across Chrome and Windows, a shared espionage exploit kit, and firewall-management exploitation trigger the federal three-day patch clock.
↑ 3 POINTS SINCE LAST WEEK2026-W38ISSUED 2026-09-14 · 14:00 UTCMETHODOLOGY V1.0
SIGNALS
ACTIVE EXPLOITATION↑
RISING
Eleven current KEV additions including four exploited zero-days — two Chrome V8, two Windows — with a shared exploit kit in use by four espionage groups, and Cisco FMC exploited by ransomware and state actors alike.
RATIONALE & SOURCE TYPES
CISA added eleven current-year CVEs, among them two Chrome V8 zero-days and two Windows zero-days from a record 974-flaw Patch Tuesday — reporting ties the browser/OS pairs to a 'BlueMoon' exploit kit used by four espionage groups within one week. Cisco Secure FMC's authentication bypass is confirmed exploited by both a ransomware gang and state-sponsored actors; NetScaler and Fortinet joined it under a September 12 federal deadline — the first visible use of BOD 26-04's three-day tier. N-able shipped its fourth exploited-N-central hotfix in five weeks, an unpatched Magento zero-day backdoored online stores, and an AI-assisted campaign exploited PaperCut at 395 organizations. Confidence is high.
CISA KEVVENDOR ADVISORYINCIDENT REPORTING
IDENTITY & HUMAN ATTACK PRESSURE→
STEADY
Machine identity joins the target list: replayable AI-service tokens surface in infostealer logs, and autonomous agents demonstrate credential compromise at speed.
RATIONALE & SOURCE TYPES
Research shows infostealer logs now carry replayable AI-service tokens that bypass MFA, and autonomous agents compromising thousands of credentials in under six hours; a FreeIPA flaw chain lets anonymous clients mint reusable administrator credentials, and an invisible-Unicode phishing campaign runs at millions-of-emails scale. Substantial, but single-source-class this week — the two-source rule holds the signal steady. Confidence is medium.
INCIDENT REPORTING
INTRUSION / RANSOMWARE TEMPO→
STEADY
Boston Scientific files a material-incident 8-K and ransomware operators work newly exploited firewall flaws; tempo holds at the recent raised level.
RATIONALE & SOURCE TYPES
Boston Scientific filed an Item 1.05 material-incident 8-K; AdaptHealth confirmed 4.1 million people affected by its July intrusion (disclosure-lag evidence); CISA reports the WatchGuard RCE now exploited in ransomware attacks; and fake IT-support calls drive Microsoft 365 data-theft extortion against executives. One material filing versus last week's three — activity consistent with, not exceeding, the raised tempo of recent weeks. Confidence is medium: disclosure lag limits week-level precision.
PUBLIC DISCLOSUREINCIDENT REPORTING
THREE MOVES THIS WEEK
01Match the federal three-day clock: patch the Cisco FMC, NetScaler, and Fortinet KEV set before the weekend, and push Chrome and Windows updates everywhere.
02If you run N-able N-central, apply the fourth hotfix and operate compromise-assumed — four exploited flaws in five weeks has earned it.
03Treat AI-service tokens like passwords: hunt for them in infostealer exposure, shorten lifetimes, and device-bind them where supported.
WHY WE BELIEVED THIS
RECEIPT LOG · WEEK 3810 RECEIPTS
REVISION HISTORY
2026-09-14 · 14:00 UTCOriginal publication.
← FULL ARCHIVE