Skip to main content
New AI-powered DMARC analysis + open REST API See how → →
Advanced

CrowdStrike Falcon Exploited, OpenAI Builds Exploits, AI Agents Breach

Brad Slavin
Brad Slavin General Manager

Quick Answer

What were the biggest cybersecurity threats from September 1–7, 2026? Key threats included zero-day exploits, AI-driven attacks, ransomware, supply-chain compromises, phishing, data breaches, browser flaws, and attacks targeting email and collaboration platforms.

AI threats and zero-day attacks

Last week was dominated by two big themes: AI tools turning into attack weapons on both sides of the fight, and a wave of zero-days hitting the very security software meant to protect endpoints. Here’s a rundown of the 15+ biggest stories cybersecurity teams were watching.

CrowdStrike Falcon hit by unpatched “FalconFlank” zero-day

A researcher known as Nightmare Eclipse (aka Chaotic Eclipse) published a working proof-of-concept exploit that abuses Falcon’s own malicious-macro remediation feature to grant SYSTEM-level privileges on fully patched Windows 11 and Windows Server 2025 machines. As of the report, CrowdStrike had not assigned a CVE or shipped a fix, only advising customers to disable the affected macro-removal policy. Source: BleepingComputer

OpenAI’s GPT-6 Astra builds working exploits from scratch

In internal cyber testing, OpenAI’s newest frontier model discovered zero-day flaws and built functioning exploits, intensifying concern in the security community over how quickly frontier AI models can be turned toward offensive hacking. Source: GBHackers

Frontier AI agents breach an enterprise network in under 10 hours

Dmarc Lookup 9647 Researchers demonstrated that autonomous AI agents could compromise a full enterprise network in under ten hours end-to-end, setting a new benchmark for how fast unsupervised, AI-driven attacks can move compared to human red teams. Source: GBHackers

CISA flags actively exploited PaperCut NG/MF flaws

CISA added multiple PaperCut print-management vulnerabilities to its Known Exploited Vulnerabilities catalog after confirming active exploitation, and Metasploit shipped a public exploit module for the same bugs days later — a combination that sharply raises urgency for organizations still running exposed print servers. Source: GBHackers

APT28-linked hackers deploy new “HOOKEDGE” backdoor across Europe

Russian state-linked group BlueDelta (tracked elsewhere as APT28) was observed deploying a previously undocumented backdoor named HOOKEDGE in espionage operations against European targets, giving the group stealthy, persistent access to compromised networks. Source: GBHackers

Dmarc Record 8138 A new variant of the Shai-Hulud supply-chain worm compromised the widely used TanStack Query package on npm in an attempt to harvest developer secrets, underscoring how quickly a single poisoned package can propagate through the JavaScript ecosystem. Source: GBHackers

New “Panzer” ransomware hits 16 victims across 11 countries

A newly identified Ransomware-as-a-Service operation called Panzer claimed 16 victims spread across 11 countries in a short window, using the now-standard double-extortion model of both encrypting and stealing data to pressure victims. Source: GBHackers

Google patches actively exploited Chrome V8 zero-day

Google shipped an emergency Chrome update after CISA confirmed a V8 engine flaw (CVE-2026-85046) was being exploited in the wild via crafted webpages, giving attackers code execution inside the browser sandbox. Federal agencies were given until September 18 to patch. Source: The Hacker News

Microsoft 365 “Direct Send” bypass lets attackers spoof internal users

Dmarc Record Generator 5088 A flaw in Microsoft 365’s Direct Send feature allows attackers to send emails that appear to come from internal colleagues without needing any credentials, making internal-looking phishing lures far more convincing. Source: GBHackers

Thomson Reuters court-software breach exposes sealed records and SSNs

West Publishing, part of Thomson Reuters, notified at least 24 court systems across 11 U.S. states plus the Virgin Islands that unauthorized access to a storage location ran from March through late June 2026, exposing sensitive court data including Social Security numbers. Minnesota’s Judicial Branch confirmed exposure of its appellate court data and cut off the vendor’s access. Source: The Hacker News

IDScan sued after breach allegedly exposes 153 million driver’s licenses

Identity-verification company IDScan is facing multiple lawsuits after hackers claimed to have breached the service and offered to sell more than 153 million scanned driver’s licenses, one of the largest identity-document exposures reported this year. Source: BleepingComputer

12-year-old PostgreSQL flaw (“PostGREShell”) allows full database takeover

Dmarc Check 1120 A newly disclosed vulnerability dating back over a decade lets low-privileged users execute arbitrary code and seize control of PostgreSQL database servers, putting a massive base of production deployments at risk once patches roll out. Source: GBHackers

Hackers compromise more than 14,500 Dahua security cameras

A mass exploitation campaign against Dahua IP cameras compromised over 14,500 devices, building a large pool of hijacked IoT infrastructure that can be repurposed for botnets, surveillance, or further attacks. Source: GBHackers

Attackers pose as IT support on Microsoft Teams to target 150+ employees

A social-engineering campaign impersonated internal helpdesk staff over Microsoft Teams to trick more than 150 employees at a target organization, continuing the trend of abusing trusted collaboration tools rather than plain email to gain remote access. Source: GBHackers Dmarc Generator 4108

QR-code phishing hit new record volumes as attackers increasingly embed malicious links inside QR images to slip past traditional link-scanning email defenses. Source: GBHackers

Infostealers now target Claude AI session cookies to hijack accounts

Threat actors are using off-the-shelf infostealer malware to grab active session cookies for Claude accounts, letting them bypass multi-factor authentication entirely and hijack AI accounts without ever touching a password. Source: GBHackers

As cyber threats continue to evolve—from zero-days and AI-driven attacks to phishing and data breaches—strong cybersecurity practices supported by DMARC, DKIM, and SPF are essential for protecting organizations and email communications.

Brad Slavin
Brad Slavin

General Manager

Founder and General Manager of DuoCircle. Product strategy and commercial lead for DMARC Report's 2,000+ customer base.

LinkedIn Profile →

Take control of your DMARC reports

Turn raw XML into actionable dashboards. Start free - no credit card required.