Microsoft's record September release fixed up to 997 CVEs, including two local escalations to SYSTEM that attackers used before the patch shipped. A 7.8 score understates the step that turns a phishing foothold into control of the machine, so both go ahead of the 9.8 remote flaws.
Reality
- Evidence48
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence42
Google's threat intelligence team ties three suspected Russian clusters to abuse of Google OAuth, app passwords and device linking. MFA completes normally, so consent telemetry is the control.
Reality
- Evidence62
- Adoption30
- Hype gap+15
- Incentives
- Insufficient
- Confidence58
Proofpoint says at least four China-linked espionage groups fired the same BlueMoon code at different victims during the four weeks a Chromium fix took to reach stable Chrome, and two more groups probably did too.
Perspective Coverage
9 publishers
- Builder
- Builder 31%
- Operator
- Operator 60%
- Investor
- Investor 9%
Reality
- Evidence80
- Adoption30
- Hype gap+10
- Incentives40
- Confidence76
Volexity attributes September 1 spear-phishing at multiple NGOs to the Chinese cluster UTA0560. The chain used two Chrome flaws and one in Windows ALPC, and a second China-nexus actor ran the same chain.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence62
Volexity dates UTA0565's exploitation to September 3 and 4, five to six days before it first reported the chain publicly, delivered from typosquats of China Digital Times and the Center for American Progress and ending in a new implant it calls CLEANGULP.
Reality
- Evidence72
- Adoption58
- Hype gap+8
- Incentives52
- Confidence64
The device code phishing cluster Microsoft disclosed in February 2025 is now assessed as an initial access arm of Midnight Blizzard. The sign-in flow the campaign abused works as designed, so the remedy is configuration.
Reality
- Evidence60
- Adoption55
- Hype gap−12
- Incentives72
- Confidence58
CVE-2026-85889 let an unauthorized attacker elevate privileges over the network in the platform enterprises use to run generative AI agents. Microsoft says the fix is already live and there is nothing for customers to install.
Reality
- Evidence58
- Adoption45
- Hype gap+18
- Incentives72
- Confidence55
Microsoft's September release addressed 972 CVEs, the largest count it has ever shipped. Within hours a researcher published a working proof-of-concept against CVE-2026-69414, the second fix for a Defender flaw first patched in July.
Reality
- Evidence48
- Adoption45
- Hype gap+22
- Incentives55
- Confidence52
Proofpoint says a shared toolkit called BlueMoon chained two V8 flaws that Chromium had fixed in public but Chrome had not yet shipped, plus a Windows kernel bug that elevates only on older builds.
Reality
- Evidence62
- Adoption58
- Hype gap+18
- Incentives66
- Confidence58
Proofpoint says two of the three bugs in the BlueMoon chain were fixed in public Chromium source before they reached stable Chrome. Defenders could close one link: an old Windows build.
Publishers:proofpoint.com
Reality
- Evidence62
- Adoption50
- Hype gap+12
- Incentives66
- Confidence58
Volexity says UTA0560 and JungleBamboo ran the same V8-to-kernel chain against separate targets on September 1, from separate infrastructure and with the same shellcode, while the V8 fix sat in Chromium source.
Publishers:volexity.com
Reality
- Evidence62
- Adoption58
- Hype gap+10
- Incentives60
- Confidence64
Google's threat intel group ties UNC6293, UNC7005 and UNC5976 to attacks on OAuth consent, app passwords, device codes and WhatsApp linking. The login succeeds; the token leaves anyway.
Reality
- Evidence64
- Adoption58
- Hype gap+14
- Incentives57
- Confidence55