TL;DR
Microsoft patched a record 974 vulnerabilities in September Patch Tuesday, with two already exploited in the wild. Separately, credential-stealing AI agents compromised thousands of accounts in six hours, and F5 BIG-IP devices are being breached to deploy Linux rootkits. Immediate patching and credential rotation are critical.
Executive Summary
- Microsoft released its largest security patch batch ever—974 vulnerabilities—including two privilege-escalation zero-days already being exploited in the wild.
- Financially motivated threat actors deployed autonomous AI agents to harvest thousands of credentials within six hours, demonstrating rapid attack automation.
- F5 BIG-IP APM devices are being actively compromised to install Linux rootkits capable of fileless web shell injection.
- A previously undocumented threat actor, tracked as Slim Spider by CrowdStrike, has been targeting Brazilian financial institutions' crypto custody infrastructure since March 2026.
- DoppelCart fraud network operates over 119,000 fake e-commerce domains to harvest payment card data at scale.
Top Threats Today
1. Microsoft September Patch Tuesday: Record 974 Vulnerabilities, Two Zero-Days Under Active Exploit
Severity: HIGH Affected: Technology
Microsoft released updates addressing 974 security vulnerabilities across Windows and other software, marking the largest single patch batch in company history [1]. Two privilege-escalation zero-days are confirmed to be actively exploited in the wild [2][3]. Additionally, 58 vulnerabilities are flagged as more likely to be exploited . Microsoft attributes the increase partly to artificial intelligence aiding vulnerability ⚠ discovery, though security experts caution that accelerated patching also increases complexity for defenders [1].
Sources:[1] Krebs on Security[2] The Record[3] SecurityWeek
Recommended Action
- Prioritize deployment of patches for the two [exploitation unverified] CVEs (CVE-2026-81963 and CVE-2026-85880) to all Windows systems within 48 hours [11, 21].
- Review CVSS and exploitation likelihood for the 58 flagged vulnerabilities and create a staged rollout plan for high-risk infrastructure.
- Test patches in non-production environments before broad deployment to avoid regression.
2. Autonomous AI Agents Harvest Thousands of Credentials in Six-Hour Campaign
Severity: HIGH Affected: Technology
A financially motivated hacking group deployed an autonomous, multi-agent artificial intelligence attack framework to conduct large-scale credential harvesting, compromising thousands of credentials within six hours [1]. Google Threat Intelligence tracked the campaign, noting the streamlined use of AI to accelerate attack operations [1].
Sources:[1] The Hacker News
Recommended Action
- Implement multi-factor authentication (MFA) across all cloud and on-premises accounts to limit credential-only compromise impact.
- Monitor for unusual API access patterns and bulk credential usage via SIEM and identity platform logs.
- Force password reset for any accounts flagged in credential-stuffing or harvesting alerts within 24 hours.
3. F5 BIG-IP APM Devices Compromised; Linux Rootkit Deploys Fileless Web Shells
Severity: HIGH Affected: Technology
Attackers have breached F5 BIG-IP APM devices and deployed a Linux rootkit that intercepts PHP file loading to inject fileless web shells directly into memory, avoiding disk-based detection [1]. The in-memory injection technique allows persistent access without traditional malware signatures [1].
Sources:[1] BleepingComputer
Recommended Action
- Audit all F5 BIG-IP APM instances for unauthorized access logs and unexpected PHP execution patterns.
- Isolate affected devices and conduct forensic memory analysis to detect in-memory web shells before reconnecting to production.
- Apply the latest F5 security patches and restrict administrative access to F5 devices via network segmentation.
4. Slim Spider: Financially Motivated Threat Actor Targeting Brazilian Financial Institutions
Severity: HIGH Affected: Finance
CrowdStrike has identified a previously undocumented financially motivated threat actor operating under the name Slim Spider, targeting Brazilian financial institutions with focus on cryptocurrency custody infrastructure [1]. Activity has been ongoing since at least March 2026, indicating sustained operations [1].
Sources:[1] The Hacker News
Recommended Action
- Financial institutions with Brazilian operations should review access logs to crypto custody systems and wallets for signs of unauthorized activity.
- Implement enhanced monitoring for exfiltration of cryptographic keys or custody-related credentials.
- Coordinate with incident response teams to baseline network traffic from financial systems and detect anomalies indicative of Slim Spider TTPs.
5. DoppelCart Fraud Network: 119,000 Fake Shops Harvesting Payment Card Data
Severity: MEDIUM Affected: Retail
A fraud operation dubbed DoppelCart operates a network of more than 119,000 domains hosting fake e-commerce storefronts designed to harvest payment card details [1]. The scale and coordination indicate organized financial crime infrastructure [1].
Sources:[1] BleepingComputer
Recommended Action
- E-commerce organizations should audit domain registrations for lookalike domains and report phishing/fraud URLs to domain registrars and law enforcement.
- Implement email security controls to block redirects to known DoppelCart domains and educate customers on URL verification before checkout.
- Monitor payment processing logs for unusual card test patterns or declined transactions indicative of card harvesting.
Today’s Action Checklist
- ☐ URGENT: Prioritize patches for CVE-2026-81963 and CVE-2026-85880 ([exploitation unverified] Microsoft zero-days) across all Windows systems within 48 hours.
- ☐ URGENT: Enable or enforce multi-factor authentication on all user accounts to mitigate AI-driven credential harvesting attacks.
- ☐ HIGH: Audit F5 BIG-IP APM device access logs and memory for indicators of rootkit deployment; isolate and forensically analyze suspicious instances.
- ☐ HIGH: Monitor cryptocurrency custody systems and wallets for unauthorized access; rotate crypto-related credentials if Brazilian operations are in scope.
- ☐ MEDIUM: Notify e-commerce partners and payment processors of DoppelCart fake domain activity; implement URL filtering and customer education campaigns.