CrowdStrike Falcon Exploited, OpenAI Builds Exploits, AI Agents Breach
Quick Answer
What were the biggest cybersecurity threats from September 1–7, 2026? Key threats included zero-day exploits, AI-driven attacks, ransomware, supply-chain compromises, phishing, data breaches, browser flaws, and attacks targeting email and collaboration platforms.
Last week was dominated by two big themes: AI tools turning into attack weapons on both sides of the fight, and a wave of zero-days hitting the very security software meant to protect endpoints. Here’s a rundown of the 15+ biggest stories cybersecurity teams were watching.
CrowdStrike Falcon hit by unpatched “FalconFlank” zero-day
A researcher known as Nightmare Eclipse (aka Chaotic Eclipse) published a working proof-of-concept exploit that abuses Falcon’s own malicious-macro remediation feature to grant SYSTEM-level privileges on fully patched Windows 11 and Windows Server 2025 machines. As of the report, CrowdStrike had not assigned a CVE or shipped a fix, only advising customers to disable the affected macro-removal policy. Source: BleepingComputer
OpenAI’s GPT-6 Astra builds working exploits from scratch
In internal cyber testing, OpenAI’s newest frontier model discovered zero-day flaws and built functioning exploits, intensifying concern in the security community over how quickly frontier AI models can be turned toward offensive hacking. Source: GBHackers
Frontier AI agents breach an enterprise network in under 10 hours
Researchers demonstrated that autonomous AI agents could compromise a full enterprise network in under ten hours end-to-end, setting a new benchmark for how fast unsupervised, AI-driven attacks can move compared to human red teams. Source: GBHackers
CISA flags actively exploited PaperCut NG/MF flaws
CISA added multiple PaperCut print-management vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation, and Metasploit shipped a public exploit module for the same bugs days later — a combination that sharply raises urgency for organizations still running exposed print servers. Source: GBHackers
APT28-linked hackers deploy new “HOOKEDGE” backdoor across Europe
Russian state-linked group BlueDelta (tracked elsewhere as APT28) was observed deploying a previously undocumented backdoor named HOOKEDGE in espionage operations against European targets, giving the group stealthy, persistent access to compromised networks. Source: GBHackers
Shai-Hulud “Trinitite” worm infects popular npm package
A new variant of the Shai-Hulud supply-chain worm compromised the widely used TanStack Query package on npm in an attempt to harvest developer secrets, underscoring how quickly a single poisoned package can propagate through the JavaScript ecosystem. Source: GBHackers
New “Panzer” ransomware hits 16 victims across 11 countries
A newly identified Ransomware-as-a-Service operation called Panzer claimed 16 victims spread across 11 countries in a short window, using the now-standard double-extortion model of both encrypting and stealing data to pressure victims. Source: GBHackers
Google patches actively exploited Chrome V8 zero-day
Google shipped an emergency Chrome update after CISA confirmed a V8 engine flaw (CVE-2026-85046) was being exploited in the wild via crafted webpages, giving attackers code execution inside the browser sandbox. Federal agencies were given until September 18 to patch. Source: The Hacker News
Microsoft 365 “Direct Send” bypass lets attackers spoof internal users
A flaw in Microsoft 365’s Direct Send feature allows attackers to send emails that appear to come from internal colleagues without needing any credentials, making internal-looking phishing lures far more convincing. Source: GBHackers
Thomson Reuters court-software breach exposes sealed records and SSNs
West Publishing, part of Thomson Reuters, notified at least 24 court systems across 11 U.S. states plus the Virgin Islands that unauthorized access to a storage location ran from March through late June 2026, exposing sensitive court data including Social Security numbers. Minnesota’s Judicial Branch confirmed exposure of its appellate court data and cut off the vendor’s access. Source: The Hacker News
IDScan sued after breach allegedly exposes 153 million driver’s licenses
Identity-verification company IDScan is facing multiple lawsuits after hackers claimed to have breached the service and offered to sell more than 153 million scanned driver’s licenses, one of the largest identity-document exposures reported this year. Source: BleepingComputer
12-year-old PostgreSQL flaw (“PostGREShell”) allows full database takeover
A newly disclosed vulnerability dating back over a decade lets low-privileged users execute arbitrary code and seize control of PostgreSQL database servers, putting a massive base of production deployments at risk once patches roll out. Source: GBHackers
Hackers compromise more than 14,500 Dahua security cameras
A mass exploitation campaign against Dahua IP cameras compromised over 14,500 devices, building a large pool of hijacked IoT infrastructure that can be repurposed for botnets, surveillance, or further attacks. Source: GBHackers
Attackers pose as IT support on Microsoft Teams to target 150+ employees
A social-engineering campaign impersonated internal helpdesk staff over Microsoft Teams to trick more than 150 employees at a target organization, continuing the trend of abusing trusted collaboration tools rather than plain email to gain remote access. Source: GBHackers

Record-breaking “quishing” wave hides malicious links inside QR codes
QR-code phishing hit new record volumes as attackers increasingly embed malicious links inside QR images to slip past traditional link-scanning email defenses. Source: GBHackers
Infostealers now target Claude AI session cookies to hijack accounts
Threat actors are using off-the-shelf infostealer malware to grab active session cookies for Claude accounts, letting them bypass multi-factor authentication entirely and hijack AI accounts without ever touching a password. Source: GBHackers
As cyber threats continue to evolve—from zero-days and AI-driven attacks to phishing and data breaches—strong cybersecurity practices supported by DMARC, DKIM, and SPF are essential for protecting organizations and email communications.
General Manager
Founder and General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.
LinkedIn Profile →Take control of your DMARC reports
Turn raw XML into actionable dashboards. Start free - no credit card required.