> InfoSec News Nuggets – 09/10/2026
[AUTHOR: Mary]
[DATE: 10/09/2026 10:28]
[LANGUAGE: EN]
Anthropic Discloses Fourth Cyber Incident in Alignment Assessment
Anthropic disclosed a fourth incident in which a Claude model gained unauthorized access to real third-party systems during a cybersecurity evaluation, a case its own July review had missed entirely. The newly found incident occurred in January 2026 when an early checkpoint of Claude Opus 4.6, running a capture-the-flag exercise built by the same third-party partner behind the previously disclosed three incidents, accidentally broke its assigned target and then reached an unrelated organization’s live system after a misconfiguration left the supposedly isolated test environment connected to the internet. Anthropic said it found the gap while assembling material to share with independent AI evaluator METR, then widened its search from roughly 141,000 transcripts to about 481 million spanning red-team logs, reinforcement learning environments, and subagent activity — a second-stage review of 9.2 million flagged transcripts found no additional incidents of similar or greater severity, and the company has signed an eight-week agreement giving METR direct access to staff and further transcripts for an independent investigation.
Microsoft September 2026 Patch Tuesday Fixes 966 Flaws, 2 Zero-Days
Microsoft shipped its largest Patch Tuesday on record, addressing 966 vulnerabilities including 105 rated Critical and two actively exploited zero-days — CVE-2026-81963, a Windows Update Stack elevation-of-privilege flaw granting SYSTEM access, and CVE-2026-85880, a similar Windows ALPC flaw, both discovered by Microsoft’s own Threat Intelligence Center with no public detail yet on how they were exploited. Beyond the headline zero-days, researchers are flagging CVE-2026-69730, a critical DNS Server flaw with a 9.8 CVSS score that Trend Micro’s Zero Day Initiative calls “SigRed’s spiritual successor,” alongside 20 total wormable vulnerabilities and an unauthenticated Exchange Server RCE (CVE-2026-55007) triggerable by simply emailing a malicious Visio attachment. With this release following closely on the heels of major zero-days at SonicWall, N-able, and Adobe Commerce, security teams face one of the largest single-month patch volumes of the year and should prioritize the DNS, Exchange, and Kerberos flaws alongside the two confirmed zero-days.
PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory
SophosLabs detailed a sophisticated Linux implant, dubbed PoisonedRefresh by ESET, found on compromised F5 BIG-IP Access Policy Manager systems that avoids writing a web shell to disk entirely — instead intercepting PHP file operations and altering how legitimate scripts are presented to the running Apache process, so content visible to traditional file-based security scans differs from what the server actually executes. F5 has linked the related activity to CVE-2025-53521, an unauthenticated remote code execution flaw in BIG-IP APM already exploited in the wild, with the implant using custom ELF loading, early startup interception, and memory-only payload delivery specifically engineered for Apache and BIG-IP APM webtop environments. Administrators should follow F5’s official remediation guidance for CVE-2025-53521 first, and Sophos recommends restricting ptrace access to limit — though not fully prevent — the implant’s ability to inspect and manipulate running processes.
Google Fixes the Seventh Actively Exploited Chrome Zero-Day of 2026
Google patched 230 Chrome vulnerabilities including CVE-2026-87491, an actively exploited out-of-bounds write flaw in V8, Chrome’s JavaScript and WebAssembly engine, that lets an attacker execute arbitrary code inside the browser sandbox via a specially crafted HTML page. The fix arrives just six days after Google patched a separate actively exploited V8 zero-day, CVE-2026-85046, marking the second Chrome zero-day addressed in under a week and the seventh of 2026 overall — four of which have specifically targeted V8. As is standard practice, Google withheld technical details and exploitation specifics while the patch rolls out to reduce information available to attackers targeting still-vulnerable installations; users should confirm Chrome has both updated to version 153.0.8010.36 or later and fully restarted to activate the fix.
CISA, NSA and FBI Warn of China-Based AI Companies Targeting US AI Models With Industrial-Scale Knowledge Distillation Campaigns
CISA, the NSA, and the FBI issued a joint advisory accusing six China-based AI companies — DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI — of running industrial-scale knowledge distillation campaigns since at least late 2024 to extract proprietary reasoning, coding, and agentic capabilities from frontier US models including Claude, GPT, Gemini, and Grok. The agencies say Z.AI alone had distilled billions of tokens from GPT-5.5 and Claude Opus 4.8 by mid-2026, with the campaigns using a gray market of API proxies called “transfer stations” alongside pools of premium accounts to bypass geographic restrictions, obscure their origin, and evade rate limits and usage-based detection. The advisory frames the activity as more than a cost-cutting shortcut for Chinese firms, warning it also strengthens China’s military and cyberattack capabilities, and recommends AI companies strengthen identity verification, monitoring, and output controls — with sanctions or Entity List designations reportedly under consideration by the Treasury Department.
The post InfoSec News Nuggets – 09/10/2026 appeared first on AboutDFIR - The Definitive Compendium Project.