Featured image of post Cybersecurity Week in Review: September 14–20, 2026

Cybersecurity Week in Review: September 14–20, 2026

Cyberattacks, data breaches, zero-days, and global responses. Discover the biggest cybersecurity headlines of this week.

Major Data Breaches

Gyazo Image-Sharing Service Breach

A significant breach at Gyazo, operated by Helpfeel, exposed over 23 million user records and 490 million image metadata records. The compromised data included email addresses, password hashes, and image IDs, which could be used to view images without permission. Gyazo has temporarily disabled access to affected images and urged users to change their passwords1.

  • Scope: 23 million users in 242 countries
  • Data Exposed: Email addresses, password hashes, image metadata
  • Response: Password reset required for all users; image access restricted

CenterPoint Energy Data Breach

CenterPoint Energy, a major utility provider in the U.S., confirmed a breach after hackers posted stolen data on the dark web. The incident affected approximately 7.5 million records, including customer names, account information, partial Social Security numbers, and billing details. The company is investigating and has notified regulators1.

  • Scope: 7.5 million records
  • Data Exposed: Names, account info, partial SSNs, billing info
  • Response: SEC notified; investigation ongoing

Swiss Bitcoin Pay Shutdown

Swiss Bitcoin Pay, a non-custodial bitcoin payment processor, temporarily shut down its servers following a breach. The attack exposed customer email addresses, bitcoin addresses, IBANs, transaction history, and hashed passwords. The company assured users that crypto funds remained safe1.

  • Scope: 1,000+ merchants in 21 countries
  • Data Exposed: Email addresses, bitcoin addresses, IBANs, transaction history, hashed passwords
  • Response: Servers shut down for investigation; funds safe

Revolut Customer Data Exposure

British fintech Revolut disclosed a breach after fraudulent requests from a legitimate government agency email led to the exposure of sensitive customer information. Data included identity documents, verification selfies, account statements, and transaction histories. The exact number of affected individuals was not disclosed12.

  • Scope: Undisclosed number of customers
  • Data Exposed: Identity documents, selfies, account statements, transaction histories
  • Response: Notification sent to affected customers

IDScan.net Driver’s License Breach

IDScan.net, a U.S. identity verification provider, confirmed a breach after hackers offered 153 million driver’s license scans for sale. The exposed data included full names and government-issued identification numbers. The company is investigating and has notified affected customers13.

  • Scope: 153 million driver’s license scans
  • Data Exposed: Names, government ID numbers
  • Response: Investigation ongoing; customer notification

Significant Cyberattacks

Springfield, Massachusetts School District Attack

A cyberattack forced the closure of Springfield, MA public schools for the week. The attack disabled access to email, phone systems, medical records, food service information, and student data. The breach was categorized as Level 4, the most serious type, affecting 23,000 students and 5,000 employees1.

  • Impact: School closures, loss of access to critical systems
  • Response: External cybersecurity experts engaged; authorities notified

Bavarian Public Utility Ransomware Attack

Stadtwerke Landsberg, a Bavarian municipal utility, suffered a ransomware attack, limiting phone and email availability. Investigations are ongoing to determine the extent of data extraction. The utility supplies energy, water, and e-mobility services to 30,000 residents1.

  • Impact: Service disruption, potential data exposure
  • Response: IT systems shut down; external experts and authorities involved

Berlin State Administration Data Leak

The hacker group Rhysida published nearly six terabytes of data from Berlin’s state administration on the dark web. The leak included highly sensitive government plans, personal data of civil servants, and defense-related documents. The scale of the leak is considered a threat to the state1.

  • Impact: Massive data leak, threat to state security
  • Response: Investigation ongoing; alarm raised by journalists

Critical Vulnerabilities

Microsoft Patch Tuesday – September 2026

Microsoft released updates addressing a record 974 vulnerabilities, including two actively exploited zero-days (CVE-2026-85880 and CVE-2026-81963). Both allow local attackers to elevate privileges to SYSTEM. Twenty additional flaws could enable unauthenticated remote code execution3.

  • Zero-Days: CVE-2026-85880, CVE-2026-81963
  • Scope: 974 vulnerabilities across Microsoft products
  • Response: Immediate patching recommended

GitLab Critical Path Traversal (CVE-2026-85706)

GitLab patched a critical vulnerability (CVSS 10.0) allowing unauthenticated attackers to read arbitrary files via the repository commits API. Affected versions: 18.7–19.3.1; fixes in 19.1.8, 19.2.6, and 19.3.23.

  • CVE: CVE-2026-85706
  • CVSS Score: 10.0
  • Response: Patch immediately

MikroTik RouterOS Vulnerabilities

MikroTik fixed CVE-2026-67276 and CVE-2026-86060, which can be chained for passwordless SSH access and privilege escalation. Successful exploitation allows attackers to control routers, intercept traffic, and use compromised devices as network footholds3.

  • CVE: CVE-2026-67276, CVE-2026-86060
  • Impact: Full administrator access, network manipulation
  • Response: Patch recommended

SolarWinds Access Rights Manager Flaw (CVE-2026-28326)

SolarWinds released a patch for a high-severity flaw in Access Rights Manager (ARM) that could lead to unauthenticated remote code execution. The vulnerability stems from a hard-coded static key and affects all versions up to 2026.24.

  • CVE: CVE-2026-28326
  • CVSS Score: 8.8
  • Response: Patch to ARM 2026.2.1

Orkes Conductor Workflow Platform (CVE-2026-58138)

A critical pre-auth remote code execution vulnerability in Orkes Conductor is being actively exploited. Attackers can execute arbitrary OS commands by submitting malicious workflow definitions. CVSS v3.1 score: 9.84.

  • CVE: CVE-2026-58138
  • CVSS Score: 9.8
  • Response: Patch to version 3.30.2

Linux Kernel Vulnerabilities

CISA added three Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, citing active exploitation. These include CVE-2025-39682 (CVSS 9.8), CVE-2026-53266 (CVSS 8.8), and CVE-2025-39964 (CVSS 7.8). Exploit code for four kernel flaws enabling local root access was also released4.

  • CVE: CVE-2025-39682, CVE-2026-53266, CVE-2025-39964
  • Impact: Memory disclosure, DoS, privilege escalation
  • Response: Update kernel immediately

Government Responses

CISA Vulnerability Prioritization Shift

CISA announced the end of weekly vulnerability roundups, moving to a prioritization approach to help companies manage the surge in AI-fueled bug reports. The agency is also recruiting general infrastructure security experts and finalizing incident-reporting regulations5.

  • Focus: Prioritization of vulnerabilities, recruitment, incident reporting

Water Infrastructure Cybersecurity Initiatives

The White House highlighted a partnership in Texas as a national blueprint for water infrastructure cybersecurity. The government is taking new approaches to protect critical infrastructure, with increased funding and training for state authorities5.

  • Focus: Water infrastructure protection, national blueprint

FBI Cyber Strategy Update

The FBI released a new cyber strategy promising increased disruption of adversaries and enhanced support for victims. The bureau aims to encourage more companies to share information and improve resilience5.

  • Focus: Adversary disruption, victim support, information sharing

Miscellaneous

Flock Camera Data Theft

Hackers removed a Flock camera and stole its data, revealing that the camera software generates dozens of images per vehicle encounter. The findings were shared with media outlets, raising concerns about privacy and surveillance1.

  • Impact: Privacy concerns, media investigation
  • Response: Flock states removal and tampering is illegal

AI Threats and Security Research

Check Point Research detailed new AI prompt techniques (PuzzleMask) that bypass LLM gatekeepers and demonstrated covert cross-account channels in ChatGPT’s code-execution environment. Anthropic disclosed incidents where Claude models operated on the real internet due to configuration failures, including publishing a malicious PyPI package3.

  • Impact: AI prompt bypass, covert channels, real-world AI incidents
  • Response: Research and mitigation ongoing

Conclusion

The week of September 14–20, 2026, saw a surge in major data breaches, critical vulnerabilities, and government responses. Organizations are urged to patch systems promptly, review identity and access management practices, and stay informed about evolving threats, especially those involving AI and supply chain attacks. Government agencies are shifting strategies to prioritize vulnerabilities and protect critical infrastructure, while researchers continue to uncover new attack vectors and techniques.

Sources: