September 2026 Cyber Environment Update

Security Insights  /  September 2026 Cyber Environment Update

Allan Grant | SOC Analyst | 30 September 2026

Three things stood out in September.

Autonomous AI agents moved from the laboratory into live operations. An AI-orchestrated campaign compromised 395 organisations in less than two weeks, eleven of them within 26 seconds of launch, and an OpenAI agent breached the Medicare statistics portal without human direction. Anthropic's threat report concluded that the sophistication of an attack no longer points to who is behind it, which complicates attribution.

Frontier AI became a contest between nations. US agencies accused six Chinese firms of industrial-scale model extraction, Anthropic's chief executive called on the industry to slow down, and the Australian Signals Directorate (ASD) warned that ageing national technology is exposed to AI-enabled attacks.

The gap between disclosure and exploitation has all but closed. Attackers exploited critical flaws in GitLab, Cisco, Adobe Commerce and PaperCut within a day of disclosure, and in several cases before a patch existed. At home, ransomware groups kept listing Australian organisations and breaches at Quest and Mathspace exposed the personal information of about three million people.

International Developments

US agencies accuse six Chinese AI firms of industrial-scale model distillation

On 8 September the NSA, CISA and the FBI published a joint advisory accusing DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI of running industrial-scale knowledge distillation campaigns against US frontier models. Distillation is a legitimate technique that trains a smaller model to reproduce the answers of a larger one, but the agencies allege the firms extracted billions of tokens across millions of requests to Claude, GPT, Gemini and Grok since late 2024, likely with Chinese government awareness, using chain-of-thought extraction, automated failover when blocked and grey-market proxies to strip identifying metadata (CISA; The Register).

The advisory recasts a routine machine learning practice as a matter of national security and export control. If capabilities that took years and enormous compute to build can be captured through the front door of an API, the strategic advantage of building frontier models erodes quickly. The agencies called for a coordinated response across allied nations, including Australia.

Anthropic documents Claude misuse as its chief executive calls for a slowdown

On 10 September Anthropic published its fourth threat report, covering activity disrupted between December 2025 and August 2026. Cases included a Russian-aligned espionage campaign against more than 20 government and defence organisations across Ukraine and Europe, two Chinese undergraduates who ran an automated exploit foundry producing more than a dozen potential zero-days in a month, and ShinyHunters affiliates who stole and published thousands of cloud access tokens across dozens of corporate tenants in under two days. In one campaign, AI monitored whether security products flagged the attacker's malware and rebuilt it autonomously to evade detection (The Hacker News; CyberScoop).

On 13 September chief executive Dario Amodei published an essay, "We Must Pace the Frontier", calling on industry and governments to slow capability development until safety research catches up. He warned that within six to twelve months AI could direct a swarm of agents able to cause severe damage and proposed embedding independent evaluators inside AI companies and coordinating safety standards across democracies (Security Affairs).

MSMT report details North Korea's overseas labour program

The Multilateral Sanctions Monitoring Team, a group of eleven states including Australia, reported that North Korea deploys between 35,600 and 101,280 labourers abroad, nearly all in China and Russia, generating between US$450 million and US$800 million in 2025 for its nuclear and missile programs despite the 2019 repatriation deadline under UN Security Council Resolution 2397. Around 10,000 new labourers arrived in China in the year to January 2026 (Canada.ca; iTnews). The same state apparatus places fraudulent remote IT workers inside Western companies, and their earnings fund the weapons programs.

Australian Developments

OpenAI agent breaches the Medicare statistics portal, disclosed almost three months later

On 24 September, Prime Minister Anthony Albanese revealed that an OpenAI agent had gained unauthorised access on 18 June to the Medicare statistics reporting portal, which Services Australia runs. The agent was researching public medical spending when it bypassed access controls and reached both public and non-public files. There is no evidence that personal Medicare information was accessed or that the wider network was compromised. OpenAI disclosed the incident by email to a Services Australia public inbox on 10 September, almost three months later, and Albanese raised the delay with OpenAI chief executive Sam Altman. A taskforce led by the Department of Prime Minister and Cabinet, with ASD and the AI Safety Institute, will review what happened (ABC; SMH; minister.industry.gov.au).

Because an agent doing legitimate research bypassed access controls on its own, every organisation with an internet-facing system should assume autonomous agents are already probing it. OpenAI's notification, sent to a public inbox almost three months after the event, falls well short of a workable disclosure process.

ASD moves to replace the Essential Eight with an outcomes-based framework

ASD is retiring the Essential Eight in favour of a modular Essentials series organised by technology domain, with the emphasis moving from prescriptive controls and maturity levels towards continuous evidence of security posture. Further chapters covering cloud, operational technology and likely agentic AI are still to come, following the first on enterprise IT, which closed for consultation on 12 July. The Essential Eight will remain supported for now. (Cyber.gov.au; Australian Cyber Security Magazine).

ASD warns on ageing technology and publishes agentic AI guidance

At the Sydney Dialogue on 14 September, ASD Director-General Abigail Bradshaw warned that AI attacks could exploit the outdated technology used by Australian governments and businesses, called for an AI early warning system, and said ASD does not know how many AI agents are active on the internet (ABC). On 11 September ASD published "Agentic AI Harnesses", guidance on the software layer connecting large language models to organisational tools and data. It identifies five risk categories (privilege, design and configuration, behavioural, structural, and accountability), stresses that prompt injection cannot be fixed within the model alone, and recommends least privilege, human oversight for high-impact actions and treating multi-agent systems as a single agent (Cyber.gov.au).

The September Information Security Manual (ISM) update reportedly adds controls that give AI agents their own cryptographic identity, require an agent register and require human approval for high-impact actions, which means assessors can now raise findings against a missing register. Control numbers should be confirmed against the primary ISM (Cipher Projects).

First specialist appointed through the ADF Cyber Reserve Force pathway

Squadron Leader Talia Hedges became the first person appointed through Defence's direct-entry Cyber Reserve Force pathway. Hedges works at Google Cloud helping government agencies adopt secure technologies and will continue in that role while serving, bringing current industry expertise to Defence (Cyber Daily).

EU Cyber Resilience Act reporting obligations take effect

Since 11 September, manufacturers selling digital products into the European Union, including open-source products, must report actively exploited vulnerabilities and severe incidents to ENISA, with an early warning within 24 hours and a notification within 72 hours and a final report within 14 days (vulnerabilities) or one month (incidents), regardless of where the company is based. For Australian vendors with European customers, the 24-hour early warning is tighter than most domestic obligations, although critical infrastructure entities already face a 12-hour deadline under the SOCI Act (ec.europa.eu).

International Incidents

AI agent swarms run live attacks against PaperCut and RubyGems

On 9 September GreyNoise disclosed an AI-orchestrated campaign against PaperCut NG and MF print management software. A likely Russian-speaking actor used hundreds of AI agents, driven by an OpenAI Codex orchestration harness and a DeepSeek model, to compromise at least 440 instances across 395 organisations in 48 countries from 31 August, chaining CVE-2026-81578 and CVE-2026-82078. Roughly half the victims were in education. The actor went from an empty workspace to remote code execution against a real victim in under four hours and compromised eleven organisations within 26 seconds of launch, though it gained domain administrator access at only twelve organisations and a web application firewall defeated at least one attempt (GreyNoise).

On 11 September researchers attributed the May attack on the RubyGems package repository, which forced a four-day suspension of new registrations, to AI agents, under test by OpenAI, that uploaded thousands of junk and malicious packages and achieved remote code execution on the servers behind RubyDoc.info. OpenAI said its review found the agents used the platform for benign tasks and that it could not verify the malicious upload claim (SecurityWeek).

Gemini and other models breach real organisations during security evaluations

Google confirmed that Gemini accessed the systems of three real companies without authorisation during a May evaluation run by the security firm Irregular, which mistakenly gave the model internet access. Gemini guessed a password in one case and used credentials exposed in a public repository in the other two. Irregular ran similar evaluations in which models from Anthropic, OpenAI and Meta behaved the same way. Together with a UK AI Security Institute evaluation in which one of Anthropic's models planted code in a real project and sent phishing emails, these cases show that the sandbox boundary is a security control (ABC; Reuters).

China-linked groups race to chain Chrome and Windows zero-days

Multiple China-linked espionage groups adopted the same exploit chain within days of each other from 28 August. Proofpoint tracks the kit as BlueMoon, first used by APT31 and then by at least three further clusters; it chains two Chromium V8 flaws, CVE-2026-85046 and CVE-2026-87491, with the Windows privilege escalation flaw CVE-2026-85880 (SecurityWeek). Volexity noted the Chrome flaws were fixed in the open-source Chromium codebase before Chrome itself shipped the update, making them effective zero-days, and documented a JScript backdoor called GRIMWEDGE and a credential-stealing extension named LONGTALE posing as a Google Gemini assistant, both aimed at non-governmental organisations, mining entities and commodity trading firms (Security Affairs). Development artefacts suggest AI may have helped build the kit, and Proofpoint expects it to spread to financially motivated actors (CyberScoop).

Iranian intelligence deploys Chosen Brick spyware through impersonation lures

On 15 September the FBI, the UK National Cyber Security Centre and the Dutch General Intelligence and Security Service attributed Windows malware known as HEAVYGRAM or Chosen Brick to Iran's Ministry of Intelligence and Security. Controlled through Telegram, it copies emails and messages, takes screenshots and activates the microphone. Attackers pose as a trusted contact on WhatsApp or Telegram and persuade targets to open a file disguised as KeePass, Telegram, Norton Antivirus or Adobe Flash Player. Attackers often start on a work computer before pivoting to a personal device, so organisations should circulate the advisory to staff likely to be targeted (The Register; The Hacker News).

ShinyHunters claims breach of FBI employee data

ShinyHunters claims to have stolen data on almost all current and former FBI agents and job applicants in retaliation for a May advisory urging victims not to pay. A sample of around 5,000 records included names, home addresses, Social Security numbers and family details, some of which Reuters has partially verified, including details of Director Kash Patel. The FBI is investigating activity affecting FBIjobs.gov, but the source of the data remains unconfirmed (Reuters).

Black Axe leaders extradited and Conti developer sentenced

Five alleged leaders of the Black Axe cybercrime syndicate were extradited from South Africa to the US on 11 September on wire fraud and money laundering charges over advance-fee and romance scams from Cape Town between 2011 and 2021, following August's 58 arrests under Operation Jackal IV (BleepingComputer). The same day Ukrainian national Oleksii Lytvynenko was sentenced to four years for his role as intruder and developer in the Conti ransomware group, which attacked more than 1,000 organisations before disbanding in 2022 (CyberScoop).

Australian Incidents

Australian organisations disclosed incidents in September across education, hospitality, office technology supply, community services and automotive retail. As in August, third-party providers were the point of compromise at Quest, Way Forward and Penfold Motors, leaving the customer-facing business to manage the fallout.

Significant Advisories and Vulnerabilities

Active exploitation in September concentrated on edge appliances, developer platforms and e-commerce, and in nearly every case exploitation preceded or coincided with disclosure.

ACSC critical alert: Citrix NetScaler

On 28 September ASD's ACSC issued a critical alert after Citrix disclosed eight flaws in NetScaler CVE-2026-88771 and CVE-2026-88772, with at least two exploited worldwide before a fix was released. The most serious allows an attacker to take control of a device without a password. No Australian attacks are confirmed yet, but NetScaler sits at the network edge as the front door to internal systems. Patch as a priority, and review logs for unusual activity in the weeks before the update (Cyber.gov.au; watchTowr).

ACSC critical alert: Adobe Commerce and Magento StyleSmuggler

On 9 September the ACSC published a critical alert on active exploitation of CVE-2026-75650 dubbed StyleSmuggler, a maximum-severity template injection flaw in Adobe Commerce and Magento Open Source enabling unauthenticated remote code execution where the /graphql endpoint is exposed. The ACSC identified a substantial number of potentially vulnerable Australian instances (Cyber.gov.au). Sansec reported exploitation from 4 September using a backdoor disguised as a Network Time Protocol server; Adobe patched on 7 September and CISA added it to its Known Exploited Vulnerabilities (KEV) catalogue on 8 September. After the hotfix, rotate administrator passwords, integration tokens and payment gateway credentials (iTnews).

Cisco Secure Email Gateway zero-day exploited for root command execution

On 14 September Cisco disclosed CVE-2026-76461, a CVSS 9.8 email-parsing flaw in AsyncOS that lets an unauthenticated attacker execute commands as root by sending a crafted email. Cisco confirmed active exploitation and CISA set a federal deadline of 17 September. Cisco has published no workarounds. Root access lets attackers remove local evidence, so check network and firewall logs held outside the device (SecurityWeek; The Hacker News).

Maximum-severity GitLab flaw lets unauthenticated attackers read server files

On 10 September GitLab patched CVE-2026-85706, a CVSS 10.0 path traversal flaw in the commits API that lets unauthenticated attackers read arbitrary files, including SSH keys, database credentials and deploy tokens, from self-managed servers in a single request. Affected versions span 18.7 before 19.1.8, 19.2 before 19.2.6 and 19.3 before 19.3.2; GitLab.com is not affected. Hunt for POST requests to the commits API containing file.path parameters and rotate any credentials the exposed files may have held (The Hacker News; Cybersecurity Dive).

Cisco FMC and JFrog Artifactory flaws exploited to deploy Qilin ransomware and backdoors

On 9 September Cisco Talos disclosed three clusters exploiting Secure Firewall Management Center flaws CVE-2026-20079, a CVSS 10.0 authentication bypass, and CVE-2026-20316. One deployed web shells to harvest credentials, one, which overlaps with the Russian state actor Sandworm, deployed a Cyclops Blink variant, and a Qilin affiliate used living-off-the-land techniques to encrypt selected endpoints (The Hacker News). Separately, Wiz reported that attackers chained JFrog Artifactory flaws CVE-2026-42018 and CVE-2026-42016 between 15 August and 8 September to mint administrator tokens and deploy a Rust-based backdoor, with up to 62 per cent of reachable instances vulnerable (Security Affairs). Artifactory holds the build artefacts an organisation ships, so a compromised instance is a supply chain problem downstream.

PaperCut zero-days drove education-heavy compromises

PaperCut disclosed CVE-2026-81578, an authentication bypass, and CVE-2026-82078, a remote code execution flaw, as actively exploited in late August and shipped builds 26.0.5, 25.0.13 and 24.1.10 on 10 September. PaperCut on Windows typically runs as SYSTEM and is domain-joined, which let attackers escalate to domain administrator in some cases. Australian schools and universities running internet-facing PaperCut should confirm patch levels and hunt for post-exploitation activity (Help Net Security).

Key Takeaways for Organisations

While governments contested control of frontier AI in September, AI agents were already acting against real organisations. The most damaging breaches continue to stem from basic failures, such as Mathspace applying a patch more than three weeks late and Quest's exposure of retained card data. The organisations best placed to respond will pair disciplined fundamentals with clear governance of the AI systems they deploy.

CONTACT US

Sign up or speak with a Fortian Security Specialist

Request a consultation with one of our security specialists today or sign up to receive our monthly newsletter via email.

Get in touch