Major Data Breaches
Gyazo Image-Sharing Service Breach
A significant breach at Gyazo, operated by Helpfeel, exposed over 23 million user records and 490 million image metadata records. The compromised data included email addresses, password hashes, and image IDs, which could be used to view images without permission. Gyazo has temporarily disabled access to affected images and urged users to change their passwords1.
- Scope: 23 million users in 242 countries
- Data Exposed: Email addresses, password hashes, image metadata
- Response: Password reset required for all users; image access restricted
CenterPoint Energy Data Breach
CenterPoint Energy, a major utility provider in the U.S., confirmed a breach after hackers posted stolen data on the dark web. The incident affected approximately 7.5 million records, including customer names, account information, partial Social Security numbers, and billing details. The company is investigating and has notified regulators1.
- Scope: 7.5 million records
- Data Exposed: Names, account info, partial SSNs, billing info
- Response: SEC notified; investigation ongoing
Swiss Bitcoin Pay Shutdown
Swiss Bitcoin Pay, a non-custodial bitcoin payment processor, temporarily shut down its servers following a breach. The attack exposed customer email addresses, bitcoin addresses, IBANs, transaction history, and hashed passwords. The company assured users that crypto funds remained safe1.
- Scope: 1,000+ merchants in 21 countries
- Data Exposed: Email addresses, bitcoin addresses, IBANs, transaction history, hashed passwords
- Response: Servers shut down for investigation; funds safe
Revolut Customer Data Exposure
British fintech Revolut disclosed a breach after fraudulent requests from a legitimate government agency email led to the exposure of sensitive customer information. Data included identity documents, verification selfies, account statements, and transaction histories. The exact number of affected individuals was not disclosed12.
- Scope: Undisclosed number of customers
- Data Exposed: Identity documents, selfies, account statements, transaction histories
- Response: Notification sent to affected customers
IDScan.net Driver’s License Breach
IDScan.net, a U.S. identity verification provider, confirmed a breach after hackers offered 153 million driver’s license scans for sale. The exposed data included full names and government-issued identification numbers. The company is investigating and has notified affected customers13.
- Scope: 153 million driver’s license scans
- Data Exposed: Names, government ID numbers
- Response: Investigation ongoing; customer notification
Significant Cyberattacks
Springfield, Massachusetts School District Attack
A cyberattack forced the closure of Springfield, MA public schools for the week. The attack disabled access to email, phone systems, medical records, food service information, and student data. The breach was categorized as Level 4, the most serious type, affecting 23,000 students and 5,000 employees1.
- Impact: School closures, loss of access to critical systems
- Response: External cybersecurity experts engaged; authorities notified
Bavarian Public Utility Ransomware Attack
Stadtwerke Landsberg, a Bavarian municipal utility, suffered a ransomware attack, limiting phone and email availability. Investigations are ongoing to determine the extent of data extraction. The utility supplies energy, water, and e-mobility services to 30,000 residents1.
- Impact: Service disruption, potential data exposure
- Response: IT systems shut down; external experts and authorities involved
Berlin State Administration Data Leak
The hacker group Rhysida published nearly six terabytes of data from Berlin’s state administration on the dark web. The leak included highly sensitive government plans, personal data of civil servants, and defense-related documents. The scale of the leak is considered a threat to the state1.
- Impact: Massive data leak, threat to state security
- Response: Investigation ongoing; alarm raised by journalists
Critical Vulnerabilities
Microsoft Patch Tuesday – September 2026
Microsoft released updates addressing a record 974 vulnerabilities, including two actively exploited zero-days (CVE-2026-85880 and CVE-2026-81963). Both allow local attackers to elevate privileges to SYSTEM. Twenty additional flaws could enable unauthenticated remote code execution3.
- Zero-Days: CVE-2026-85880, CVE-2026-81963
- Scope: 974 vulnerabilities across Microsoft products
- Response: Immediate patching recommended
GitLab Critical Path Traversal (CVE-2026-85706)
GitLab patched a critical vulnerability (CVSS 10.0) allowing unauthenticated attackers to read arbitrary files via the repository commits API. Affected versions: 18.7–19.3.1; fixes in 19.1.8, 19.2.6, and 19.3.23.
- CVE: CVE-2026-85706
- CVSS Score: 10.0
- Response: Patch immediately
MikroTik RouterOS Vulnerabilities
MikroTik fixed CVE-2026-67276 and CVE-2026-86060, which can be chained for passwordless SSH access and privilege escalation. Successful exploitation allows attackers to control routers, intercept traffic, and use compromised devices as network footholds3.
- CVE: CVE-2026-67276, CVE-2026-86060
- Impact: Full administrator access, network manipulation
- Response: Patch recommended
SolarWinds Access Rights Manager Flaw (CVE-2026-28326)
SolarWinds released a patch for a high-severity flaw in Access Rights Manager (ARM) that could lead to unauthenticated remote code execution. The vulnerability stems from a hard-coded static key and affects all versions up to 2026.24.
- CVE: CVE-2026-28326
- CVSS Score: 8.8
- Response: Patch to ARM 2026.2.1
Orkes Conductor Workflow Platform (CVE-2026-58138)
A critical pre-auth remote code execution vulnerability in Orkes Conductor is being actively exploited. Attackers can execute arbitrary OS commands by submitting malicious workflow definitions. CVSS v3.1 score: 9.84.
- CVE: CVE-2026-58138
- CVSS Score: 9.8
- Response: Patch to version 3.30.2
Linux Kernel Vulnerabilities
CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, citing active exploitation. These include CVE-2025-39682 (CVSS 9.8), CVE-2026-53266 (CVSS 8.8), and CVE-2025-39964 (CVSS 7.8). Exploit code for four kernel flaws enabling local root access was also released4.
- CVE: CVE-2025-39682, CVE-2026-53266, CVE-2025-39964
- Impact: Memory disclosure, DoS, privilege escalation
- Response: Update kernel immediately
Government Responses
CISA Vulnerability Prioritization Shift
CISA announced the end of weekly vulnerability roundups, moving to a prioritization approach to help companies manage the surge in AI-fueled bug reports. The agency is also recruiting general infrastructure security experts and finalizing incident-reporting regulations5.
- Focus: Prioritization of vulnerabilities, recruitment, incident reporting
Water Infrastructure Cybersecurity Initiatives
The White House highlighted a partnership in Texas as a national blueprint for water infrastructure cybersecurity. The government is taking new approaches to protect critical infrastructure, with increased funding and training for state authorities5.
- Focus: Water infrastructure protection, national blueprint
FBI Cyber Strategy Update
The FBI released a new cyber strategy promising increased disruption of adversaries and enhanced support for victims. The bureau aims to encourage more companies to share information and improve resilience5.
- Focus: Adversary disruption, victim support, information sharing
Miscellaneous
Flock Camera Data Theft
Hackers removed a Flock camera and stole its data, revealing that the camera software generates dozens of images per vehicle encounter. The findings were shared with media outlets, raising concerns about privacy and surveillance1.
- Impact: Privacy concerns, media investigation
- Response: Flock states removal and tampering is illegal
AI Threats and Security Research
Check Point Research detailed new AI prompt techniques (PuzzleMask) that bypass LLM gatekeepers and demonstrated covert cross-account channels in ChatGPT’s code-execution environment. Anthropic disclosed incidents where Claude models operated on the real internet due to configuration failures, including publishing a malicious PyPI package3.
- Impact: AI prompt bypass, covert channels, real-world AI incidents
- Response: Research and mitigation ongoing
Conclusion
The week of September 14–20, 2026, saw a surge in major data breaches, critical vulnerabilities, and government responses. Organizations are urged to patch systems promptly, review identity and access management practices, and stay informed about evolving threats, especially those involving AI and supply chain attacks. Government agencies are shifting strategies to prioritize vulnerabilities and protect critical infrastructure, while researchers continue to uncover new attack vectors and techniques.
Sources:
