Weekly Wire #9: The Patch Race Tightens
The week’s loudest number was Microsoft’s: 974 patches in a single batch, and the 2026 year-to-date total already more than doubles the entire output of the record year 2020, with three months still to go. The more telling number was smaller: four espionage groups, one shared exploit chain, and a window measured in days between upstream fixes and weaponized attacks. When the patches themselves start breaking Remote Desktop Services, the defender’s problem stops being finding the needle and starts being surviving the haystack.

In brief
- Microsoft’s September Patch Tuesday set a single-month record at 974 fixes, and the 2026 year-to-date total already more than doubles the entire 2020 output, with three months still to go.
- Four espionage groups used the same Chrome-to-Windows exploit chain, dubbed BlueMoon, within days of the fixes going public.
- GitLab’s max-severity path traversal was already drawing internet-wide probes a day after the advisory, and MikroTik routers are falling to the “MikroTrick” chain.
- The Pentagon turned off ad tracking on military devices after commercial location data was linked to the targeting of US forces.
- The FTC rescinded the policy that put health apps under breach notification rules, while the FBI published its first cyber strategy.
- A zero-click worm now hijacks WeChat accounts through a single incoming call, with no interaction from the victim.
Digital forensics & DFIR
- Knowledge Retention & Sharing in DF/IR — Harlan Carvey’s essay on how DFIR teams fail to move knowledge from individual to operationalized is the quiet piece that will age better than any CVE write-up this week. The exchange in the comments about the Marines’ “turnover folder” is worth the read alone: tool knowledge transfers, investigative reasoning does not.
- $10 trillion vs. $300 billion: why cybersecurity investment needs to shift toward recovery — A former FBI investigator making the case that recovery spending is a rounding error next to the size of the cybercrime economy. The vendor framing is predictable, but the underlying asymmetry is one every CISO should be forced to defend against, especially in a week where prevention clearly lost the race.
Threat intelligence & APT
- North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters — Sekoia and Kudelski splitting the Lazarus umbrella into six clusters (TEMP.Hermit, Citrine Sleet, CryptoCore, Jade Sleet, Moonstone Sleet, Famous Chollima) is attribution housekeeping that actually matters. It explains why one “group” seems to be everywhere at once, and the fake IT worker program doubling as an espionage access engine is the detail to keep in mind.
- MantaxOtax Android Malware Combines Ransomware With Spyware — Zimperium’s zLabs found an Android package that encrypts files, steals WhatsApp and Telegram content, and harasses the victim with text-to-speech and full-screen overlays every 600 milliseconds. The harassment features read like a revenge tool rather than a business model, and the C2 domain resolved from a GitHub repo is a neat trick for evading takedowns.
- Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused — Berlin refusing the €2m demand and getting 5.7 TB published, including CBRN emergency plans, is the ransomware calculus laid bare. State disaster plans in a leak outlive the news cycle, and the forensic analysis of who is in the dataset will take months.
Privacy & surveillance
- The US military just turned off ad tracking on its phones. Maybe you should too — When the Army, Air Force, Navy and Special Operations Command disable advertising IDs because commercial location data is being used to target troops, the “it’s just ads” argument dies in the field. If it is good enough for SOCOM, it is good enough for the rest of us.
- Grindr settles HIV status data-sharing lawsuit for $35 million — £26 million (about $35 million) to settle claims that HIV status and other intimate data were shared with advertisers is the price of the advertising-ID economy. The data was shared years ago, but the settlement is a reminder that the consent question never expires.
- Nudity scanning tech will leave us more exposed — The UK’s on-device nudity scanning proposal is the Online Safety Act’s logical endpoint: blocking software baked into the OS, with adults forced through unregulated age verification to opt out. The HMD Fuse child-safety phone being pulled after flaws exposed children’s live locations is the cautionary tale that writes itself.
Policy & legislation
- FTC rescinds policy statement requiring health apps to notify customers after a breach — The FTC voted to rescind the Biden-era policy that put health and fitness apps under breach notification rules, even if the underlying 2024 rule technically survives. The message to health app makers is clear enough: the enforcement winds have shifted, and deregulation is the stated agenda.
- FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors — The FBI’s first cyber strategy measures success in disrupted infrastructure and burned access rather than arrests, which is a realistic read of how international cybercrime enforcement actually works. The “best athlete” model and automated indicator sharing are the operational details worth watching.
- Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal — A DOT rule carving cyberattacks out of airline compensation obligations is a policy gift to the industry. Expect “cyberattack” to join “weather” as the excuse that requires no proof and no payout.
Tools & research
- BlueMoon exploit kit turns Chrome and Windows flaws into attacks — Proofpoint finding four espionage groups using the same Chrome-to-Windows exploit chain within days of the upstream fixes is the week’s defining detail. Attackers are effectively beta-testing the patches before most users install them, and the gap between “fixed upstream” and “everyone protected” is now the product being sold.
- GitLab urges users to patch max severity path traversal flaw — CVE-2026-85706 lets unauthenticated attackers read arbitrary files from self-managed GitLab servers, and watchTowr already saw internet-wide probes a day after the advisory. The hunt for HTTP POST requests to the commits API is the detection to add today, not next week.
- MikroTik router flaws allow takeover without a password — CERT Polska documenting the actively exploited “MikroTrick” chain, an SSH auth bypass plus a crafted-username privilege escalation, shows that a strong password is now optional. The detail that the patched packages let researchers reconstruct the flaws is a reminder that binary diffing keeps the exploit economy running.
- Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent — A national CERT calling exploitation “imminent” for two critical VPN flaws, including a heap overflow in the ASN.1 decoder, is as close to a formal warning as it gets. VPN gateways remain the gift that keeps giving, and the LivePatch coverage gaps mean some customers are already unprotected.
- Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls — A worm that takes over a WeChat account through an incoming VoIP call, with no interaction from the victim, is the mobile equivalent of the old network worms. The detail that the researchers’ own WeChat account was banned after reporting the flaw to Tencent is a disclosure-process story on its own.
Extra
- Getting a stranger’s phone kicked off the cellular network costs a few dollars — Michigan State researchers bricking phones and alarm panels by reporting IMEIs as lost, for $2.50 to $4 per device, shows how thin the identity checks in carrier systems really are. The attack on home security gateways through vulnerable IoT chipsets is the part that should worry anyone with a monitored alarm.
- GPUThor: an evolution of the Rowhammer idea — The University of Toronto variant on Nvidia GDDR6 memory is thousands of times more effective than earlier GPU attacks, even if arbitrary code execution remains unproven. Cloud GPU tenants hammering each other’s memory is a threat model that keeps getting more plausible.
The pick of the week is Malwarebytes’ write-up of the BlueMoon exploit kit, because it turns the week’s loudest number (974 patches) into a concrete operational problem: four groups, one shared chain, days of head start. Next week, watch whether the GitLab and MikroTik chains produce the first mass-exploitation events, and whether the IDScan saga keeps expanding beyond the class actions and the Florida DMV breach.
FAQ
Why did September 2026 set a record for Microsoft patches, and why does that not feel like good news?
Microsoft shipped 974 fixes in a single month, pushing the 2026 year-to-date total past 2,600, more than double the previous record year, with three months to go. Exploit kits like BlueMoon weaponized the same flaws within days, and the September Server updates broke Remote Desktop Services. Volume without prioritization is making the defender’s job harder, not easier.
What are the most important cybersecurity events of the week of September 6?
Microsoft’s record 974-CVE Patch Tuesday; the BlueMoon exploit kit used by four espionage groups; GitLab’s max-severity path traversal drawing internet-wide probes; the actively exploited MikroTik MikroTrick chain; the FTC rescinding health app breach notification guidance; and the Pentagon disabling ad tracking on military devices.
How are articles selected for the Weekly Wire?
Articles are curated from a fixed set of RSS feeds weighted by source reliability and relevance to DFIR, threat intelligence, privacy, policy, and security research. Vendor marketing and press releases are discarded.