
Vital Cyber Issues N Stuff
Weekly Report - 2026-09-14
Weekly Report Period: Week 38, 2026 (2026-09-07 — 2026-09-14) Summary Week 38 combined domestic regulatory and civil-defense preparation with a heavy international vulnerability disclosure cycle. Internationally, stolen credentials from the August Rhysida ransomware attack on two Berlin ministries surfaced online on 2026-09-08, compounding the original compromise [8], while GitLab, SAP, Check Point, Ivanti, and Microsoft all disclosed critical vulnerabilities within days of each other, including one ( CVE-2026-85706 ) already confirmed under active exploitation via CISA's KEV catalog [11][7][6][9][15]. A separate CERT Polska disclosure of six "MikroTrick" RouterOS flaws highlighted continued exposure of internet-facing network devices [12]. Patterns and Trends Compared to prior weeks, domestic reporting shifted further from incident response toward structural preparedness — regulatory implementation (CRA), civil-defense testing (SE-Alert), and military/civil-duty planning — with no confirmed cyberattack against a named Swedish victim this period. Internationally, the week's defining pattern was volume and severity: multiple vendors (GitLab, SAP, Check Point, Ivanti, Microsoft) released critical (CVSS 9.8-10.0) patches nearly simultaneously, alongside Microsoft's record 964-CVE Patch Tuesday, suggesting patching capacity is being outpaced by disclosure volume. The Berlin Rhysida case illustrates a recurring two-phase pattern where initial ransomware compromise is followed by secondary credential-exposure incidents once stolen data is published. Social-engineering tradecraft also evolved, with attackers now abusing passkey enrollment flows to hijack Microsoft 365 accounts, indicating adversaries are adapting phishing techniques to newer authentication mechanisms. Domestic (K1) The week's domestic reporting centered on regulatory implementation, civil-defense capability building, and one nationwide alert-system test, rather than on confirmed cyber incidents against named Swedish victims. CERT-SE's weekly bulletin for week 37 reports that the first requirements under the EU's Cyber Resilience Act entered into force during the week, and notes that NCSC will host the "Svensk cyber 2026" conference in November under the theme "capability to act in a changing time" (A2 — Usually reliable, Confirmed) [1]. On 2026-09-07, MSB (Myndigheten för civilt försvar) and Post- och telestyrelsen conducted a test of the SE-Alert warning system in Stockholm and Gotland counties; the test identified deviations that are now being analyzed by responsible authorities, with no further detail on the nature of the deviations (A2 — Usually reliable, Confirmed) [2]. On the capability side, the government on 2026-09-07 decided to procure Himars rocket artillery, with ammunition to be manufactured domestically at Swedish factories with a range of 500 km; Defence Minister Pål Jonson stated this complicates an attack against Sweden and its allies (A2 — Usually reliable, Confirmed) [4]. On the threat-landscape side, a Fortinet-cited survey reported that 86% of surveyed organizations experienced at least one data breach in the past year, with 56% of those citing a shortage of cybersecurity skills as a contributing factor, and costs exceeding one million dollars for a majority of affected organizations; Fortinet frames workforce shortages as a security issue rather than purely an HR/IT matter. This is general industry survey data without named Swedish victims or a specific incident (C2 — Fairly reliable, Probably true) [3]. Assessment No specific cyberattack against a named Swedish organization was reported this period; the domestic picture is instead one of regulatory and capability preparation. International (K2/K3) The week's international picture was dominated by a wave of critical vulnerability disclosures across enterprise infrastructure software combined with continued fallout from an August ransomware attack on German government networks. On 2026-09-08, stolen credentials and other sensitive data from the August Rhysida ransomware attack against two Berlin ministries appeared online, marking what sources describe as a "second phase of risk" in which exposed credentials compound the original compromise (C2 — Fairly reliable, Probably true) [8]. The report notes this coincides with a broader wave of actively exploited vulnerabilities affecting the same government network environment [8]. On the vulnerability front, GitLab published fixes on 2026-09-11 for multiple flaws in its Community and Enterprise Editions, including two critical issues ( CVE-2026-85706 , CVE-2026-87719 ); CVE-2026-85706 has already been added to CISA's Known Exploited Vulnerabilities catalog, confirming active exploitation (A2 — Usually reliable, Confirmed) [11]. Separately, CERT Polska disclosed on 2026-09-07 a chain of six RouterOS vulnerabilities, dubbed "MikroTrick," that allow attackers to take full unauthenticated control of MikroTik devices exposing SSH to the internet, with coordinated disclosure to MikroTik (C2 — Fairly reliable, Probably true) [12]. SAP released its September Security Patch Day on 2026-09-08 addressing two critical vulnerabilities: CVE-2026-44756 ("OVERPASS," CVSS 10.0), a memory corruption flaw in SAP Extended Passport processing discovered by Onapsis Research Labs, and CVE-2026-58240 ("S4GET," CVSS 9.8), a missing authentication check (A2 — Usually reliable, Confirmed) [7]. Check Point disclosed two critical VPN vulnerabilities, CVE-2026-85102 and CVE-2026-8510 (CVSS 9.8), enabling potential unauthenticated remote code execution, though the vendor states these were found internally with no evidence of active exploitation (A2 — Usually reliable, Confirmed) [6]. Ivanti also patched a high-severity privilege-escalation flaw, CVE-2026-18851 , in Endpoint Manager Mobile, with no known exploitation reported at disclosure (A2 — Usually reliable, Confirmed) [9]. Microsoft's September 2026 Patch Tuesday, released 2026-09-08, addressed a record 964 CVEs — 104 critical — including two zero-days exploited in the wild (B2 — Usually reliable, Probably true) [15]. In parallel, Microsoft Security Research reported tracking an active cloud-intrusion campaign since May 2026 in which attackers impersonate IT helpdesk staff, direct employees to "enroll a passkey," and route them through adversary-in-the-middle phishing pages or device-code authentication flows to hijack Microsoft 365 accounts (C2 — Fairly reliable, Probably true) [14]. Assessment Given that CVE-2026-85706 is already listed in CISA's KEV catalog and MikroTrick targets internet-facing SSH without authentication, it is likely (60-90%) that opportunistic exploitation of both flaws will expand to additional unpatched organizations before patching reaches saturation, based on the confirmed active-exploitation status and the internet-facing nature of affected systems [11][12]. The Berlin case illustrates a probable pattern in which initial ransomware compromise is followed by secondary credential-abuse incidents once stolen data is published; if this sequence recurs elsewhere, similar two-phase disclosures are possible (20-60%) among other Rhysida victims in the near term [8]. The volume of critical CVSS 9.8-10.0 disclosures in SAP, Check Point, and Ivanti products within a single week, combined with Microsoft's record 964-CVE patch cycle, indicates that the exploitable attack surface for enterprise perimeter and identity infrastructure has grown faster than patching capacity, making it likely (60-90%) that unpatched instances of at least one of these flaws will be exploited within the coming months [7][6][9][15]. Follow-up Items CVE-2026-85706 (GitLab, CVSS critical) — confirmed in CISA's Known Exploited Vulnerabilities catalog as of 2026-09-11; organizations running affected Community/Enterprise Editions should verify patch status [11]. CVE-2026-44756 "OVERPASS" (SAP, CVSS 10.0) — patched 2026-09-08 via SAP's September Security Patch Day; discovered by Onapsis Research Labs, affects SAP Extended Passport processing [7]. MikroTrick RouterOS vulnerability chain — disclosed 2026-09-07 by CERT Polska, coordinated with MikroTik; affects devices exposing SSH to the internet, patch/mitigation timeline not specified [12]. Note: Claims flagged for review: 17. See "To verify" below. Automatically removed (low confidence): 6. Generated 2026-09-14 04:59 UTC from 15 priority articles (10 cited). [1] cert.se — https://www.cert.se/2026/09/cert-se-veckobrev-v37.html [2] msb.se — https://www.mcf.se/sv/aktuellt/nyheter/2026/september/test-av-se-alert-genomfort/ [3] aktuellsakerhet.se — https://www.aktuellsakerhet.se/fortinet-kompetensbrist-bidrar-till-dataintrang/ [4] svt.se — https://www.svt.se/nyheter/inrikes/sverige-koper-himars-ammunition-ska-tillverkas-i-svenska-fabriker [6] ncsc.fi — https://community.checkpoint.com/t5/General-Topics/Action-Required-Critical-Security-Advisory-VPN-Vulnerabilities/td-p/281995 [7] cert.europa.eu — https://cert.europa.eu/publications/security-advisories/2026-011/ [8] undercodenews.com — https://undercodenews.com/berlins-government-network-faces-a-new-data-leak-as-rhysida-fallout-collides-with-a-wave-of-actively-exploited-vulnerabilities-video/ [9] ncsc.fi — https://hub.ivanti.com/s/article/Security-Advisory---Ivanti- [... Report truncated. View full report at link above.]

