September 2026 Cybersecurity News Digest

September 2026 Cybersecurity News Digest

Our September cybersecurity digest brings together the latest disclosures in the field, from breaches affecting government systems and popular financial services to backup failures and rogue AI tools. Last but not least, it covers major security updates from tech giants such as Microsoft and Apple.

 

1.     Famous ShinyHunters cybercrime group claims to have breached FBI’s job site and stolen agents' data

The FBI is investigating a claimed ShinyHunters breach of its jobs portal and alleged theft of sensitive employee and applicant data, including names, home addresses, phone numbers, Social Security numbers, and details about family members. While the well-known cybercrime group provided sample 5,000 records and described a possible Oracle-PeopleSoft-to-AWS-cloud-infrastructure attack path, the FBI and vendors have not confirmed the broader claims, including the alleged terabytes of stolen data. The incident highlights risks like identity theft, harassment, social engineering, and physical threats to personnel. PeopleSoft users are advised to apply security updates and monitor administrative access.

ShinyHunters claimed the attack was politically motivated rather than financially driven, saying it was retaliation for an FBI cyber advisory issued in May. The group accused the bureau of spreading false information and reportedly gave it seven days to revise or remove the alert. 

2.     Claude Code agent supposedly deletes 48,000 files in only 103 seconds

A reported Claude Code incident allegedly deleted 48,218 live Windows files and damaged a Git repository in 103 seconds. The failure arose when a cleanup script mishandled directory junctions, allowing deletion to spread from a temporary mirror into the live project. Although the claim comes from Reddit and has not been independently verified, it emphasises the need for dry runs, reversible operations, least-privilege access, and filesystem sandboxing when using autonomous coding agents.

3.     File history backups broken by September 2026 Windows updates

Microsoft confirmed September 2026 Windows updates can disrupt File History, leaving backups incomplete despite connected drives and stale “Last Backup” timestamps, which may lead users to believe their files are safely backed up when they are not. The problem affects Windows 10 22H2 and 21H2 versions, Windows 11 26H1, 25H2, 24H2, and 23H2 versions, Windows 10 Enterprise LTSC 2019 and LTSC 2016, but not Windows Server.

Microsoft has not identified the root cause or offered an official workaround but says it is working on a fix for a future Windows update and will provide further details when available. Until a fix is released, users should verify backups and maintain an independent backup copy.

4.     AWS reports irrecoverable cloud data after war damage in data centres

AWS has announced officially that war damage in the Middle East in March and April made some customer data in the UAE availability zone `mec1-az2` and Bahrain’s `me-south-1` region permanently unrecoverable. This is probably the first time in history when military action has caused irrevocable data loss at a global cloud provider.

The incident underscores the shared-responsibility model and the need for geographic redundancy: customers with data stored only in the affected locations and no external backups lost it entirely.

5.     Apple has released one of its largest coordinated security updates

Apple patched 273 vulnerabilities across all their devices and software on September 14, 2026. macOS Golden Gate 27 has the most extensive coverage with 210 CVEs, followed by macOS Sequoia 15.8 with 154 and macOS Tahoe 26.7 with 153. Users should install the latest compatible updates promptly, especially on internet-facing, shared, developer, or Bluetooth-enabled systems.

6.     Revolut breach linked to fake government requests exposes customers’ ID data & complete transaction histories

Revolut confirmed that an unauthorised party obtained sensitive customer information by sending fraudulent data requests from an email address on a legitimate government domain. Because the messages passed domain authentication, Revolut treated them as genuine requests. The attacker did not breach Revolut’s app or banking systems, and customer funds were unaffected.

Potentially exposed information included names, birth dates, occupations, addresses, email addresses, phone numbers, passport or driving-licence copies, onboarding facial images, IBANs, account details, withdrawal records, and complete transaction histories, including Bitcoin activity. Revolut said biometric facial telemetry was not compromised and that only a limited number of customers were affected. Still, it has not disclosed the exact number, the government agency involved, the countries affected, or how long the scam lasted.

Revolut blocked the fraudulent address and notified authorities, regulators, and affected customers. Claims that the breach targeted wealthy users, involved compromised Italian law-enforcement departments, or exposed 147 GB of data remain unverified. The incident highlights the need for independent verification, authorisation checks, dual approval, anomaly detection, audit logs, and data minimisation for sensitive government information requests.

7.     The Biggest Microsoft Patch Tuesday Update September 2026: 973 issues fixed

Microsoft's September 2026 Patch Tuesday brings the biggest update up to now, addressing 973 vulnerabilities, including two already exploited zero-day threats. This follows the massive updates released in previous months, as well as the recent update focused on artificial intelligence.

The September security update spans a variety of Microsoft software products, including Windows (723 vulnerabilities), Microsoft Office (111 issues), SQL Server (62 issues), Exchange, SharePoint, Azure, and developer tools. Users are strongly encouraged to update their software immediately, especially considering the massive number of vulnerabilities that have been resolved. 

8.     Dropbox reports 5,000 compromised accounts due to a Lenovo ID authentication flaw

Dropbox said about 5,000 accounts were compromised after attackers exploited weak email verification in the Lenovo ID integration. They created Lenovo IDs using victims’ email addresses and accessed linked Dropbox accounts without needing Dropbox passwords. Some content was viewed or downloaded, though impact varied. Victims may not have needed a Lenovo ID to become exposed.

Dropbox removed the integration, ended Lenovo-authenticated sessions, and now requires a Dropbox password for Lenovo ID logins. Affected users should change their Dropbox and email passwords, enable two-step verification, and review sessions, connected apps, sharing links, file activity, and recovery settings.

From an enterprise security standpoint, the breach underscores the need for ongoing reviews of identity-provider integrations. It demonstrates the risks of allowing cloud platforms to rely on third-party identity providers without robust, account-level verification before granting access.

Staying secure means more than just reading the headlines. It’s about prevention, timely patching, proper backup strategy, consistent cybersecurity hygiene and ongoing training against ever-emerging threats.  We hope your systems remain safe and compliant with NIS2 through 2026. If you need assistance, please contact us for expert advice! 

Back to blog

Are you looking for a trusted partner who will guide you in the vast field of software solutions?

Or

Contact Us