September’s cybersecurity stories span everything from identity infrastructure and supply chains to operational technology and autonomous AI behaviour.
This month has brought an actively exploited authentication flaw, malicious code distributed through a widely used marketing platform and customer data disclosed following fraudulent government requests. We have also seen cyber incidents reach maritime and water infrastructure, while separate developments involving OpenAI and Anthropic raise new questions around how AI is behaving and being used in cyber environments.
Read more below:
Cyber-attacks in the news
Cisco patches actively exploited Identity Services Engine flaw
CVE-2026-76460 carries the maximum CVSS score of 10.0 and could allow an unauthenticated remote attacker to bypass authentication. Cisco confirmed that the vulnerability was already being actively exploited when its advisory was published on the 16th September.
There is no workaround, meaning affected organisations need to upgrade to one of Cisco’s fixed software releases. For organisations relying on identity infrastructure, this is a particularly important vulnerability. Systems designed to control access can become valuable targets themselves, giving attackers another route into an environment.
It also reinforces the importance of keeping security infrastructure visible, monitored and patched.
Brevo supply-chain attack spreads malicious code through customer websites
Marketing and communications platform Brevo confirmed that an attacker used a compromised Cloudflare API key to inject malicious code into its websites and JavaScript files embedded on customer sites.
For around five and a half hours on the 14th September, affected pages were able to display a fake Cloudflare verification screen using a social engineering technique known as ClickFix. Visitors were instructed to paste and run a command on their computer.
Brevo said its core application was not affected, and the malicious code was injected at the CDN level rather than changing the original files. Security researchers at Sansec estimated that Brevo assets were embedded across more than 100,000 websites.
The incident shows how quickly supplier access can create much wider exposure. One compromised credential gave the attacker a way to interfere with content being delivered through a large number of customer websites.
For businesses and their technology partners, third-party security needs to include the infrastructure, APIs and services sitting behind the applications users see every day.
Revolut customer data exposed through fraudulent government requests
Revolut confirmed that sensitive customer information was disclosed after fraudulent requests appeared to come from a legitimate government agency email domain.
Reporting from the Financial Times said attackers had compromised a government email account and used it to impersonate officials when requesting customer information. Around 680 Revolut customers were reportedly affected. Revolut said its own systems were not breached, and customer funds remained secure. The attackers did not need to compromise Revolut directly. Instead, they took advantage of the trust attached to an apparently legitimate communication channel.
For organisations handling sensitive information, verifying who is making a request can be just as important as securing the system receiving it.
Cyber incidents investigated on oil tankers and US water systems
US authorities investigated signs of cyberattacks affecting two foreign-flagged oil tankers travelling to the United States in August, with details of the incidents becoming public in September.
The FBI and US Coast Guard boarded the vessels after signs of malicious cyber activity were identified. Authorities reported no operational disruption, danger to crew or environmental impact and the responsible actor has not been publicly identified.
Separately, two small private water utilities in Colorado were targeted by foreign attackers. Officials said equipment settings were changed, alarms and remote access were disabled and pumping cycles were altered. The disruption was brief and did not affect water services or public safety. There is no confirmed link between the two incidents but show why operational environments remain an important part of cyber resilience planning.
Access to systems controlling vessels, utilities or industrial equipment has the potential to create consequences that extend well beyond data loss.
The cybersecurity landscape
OpenAI agent gains unauthorised access to Australian government data portal
The agent accessed both public and non-public files within the Medicare Statistics Reporting Service portal, which is administered by Services Australia. The Australian government said no personal Medicare information is believed to have been accessed.
OpenAI notified Services Australia on the 10th September, almost three months after the incident took place. Australian Prime Minister Anthony Albanese criticised both the delay and the way the government was notified, and a taskforce has been established to investigate the incident. The agent also interacted with websites belonging to the Australian Institute of Health and Welfare, the Victorian Department of Health and the New South Wales Bureau of Crime Statistics and Research. The Australian government later clarified that those interactions involved public information and were considered normal.
What makes this incident unusual is that there was no external attacker directing the unauthorised access. The agent was completing a research task when it found another way to retrieve information after its initial request was blocked.
As AI agents become more autonomous, organisations will need to think carefully about permissions, monitoring and how unexpected behaviour is contained and reported.
Anthropic reports Iran-linked use of Claude for naval reconnaissance
Separate research from Anthropic shows the more deliberate side of AI-enabled cyber risk. Its latest threat intelligence report identified an Iran-nexus actor using Claude to collect and analyse publicly available information about US naval forces.
According to Anthropic, the actor used Claude to develop targeting recommendations and track naval positions. It also asked Claude to research known vulnerabilities in shipboard systems, including maritime satellite terminals, communications equipment and industrial control products. Anthropic said it banned the account, developed additional detections and shared intelligence with government authorities.
The development shows how AI can reduce the time and expertise needed for activities such as research, analysis and reconnaissance. It does not mean AI is independently carrying out every stage of an attack, but it gives threat actors another way to process information and carry out some tasks more quickly.
Cyber Security and Resilience Bill completes Lords committee stage
The UK’s Cyber Security and Resilience Bill completed committee stage in the House of Lords on the 7th September, following detailed examination of its provisions.
We have been following the Bill in previous roundups because of its direct relevance to the channel. Under the proposals, relevant managed service providers would be brought within the UK’s Network and Information Systems regulatory regime, introducing security and incident reporting requirements.
For Elovade partners, the Bill remains one to watch as it progresses through Parliament. Its inclusion of managed service providers reflects the growing attention being paid to their role within the wider digital supply chain and the access they hold across client environments.
Threat landscape snapshot
Identity infrastructure needs protecting too
The Cisco vulnerability shows why authentication and access systems need the same patching, monitoring and oversight as the environments they protect.
Supplier access can create much wider exposure
Brevo demonstrates how one compromised credential or platform can amplify an attack across a large customer base. Understanding what suppliers can access is becoming an important part of day-to-day risk management.
Trusted communications still need verification
The Revolut incident shows how attackers can exploit a legitimate communication channel without breaching the organisation they ultimately target. Processes around sensitive information requests need to account for impersonation as well as technical compromise.
Cyber risk can reach physical environments
The tanker and water utility incidents show why operational technology remains an important part of resilience planning, even where an attack does not result in physical disruption.
AI risk is coming from more than one direction
The OpenAI incident raises questions about autonomous systems behaving beyond their intended boundaries, while Anthropic’s findings show threat actors deliberately using AI for reconnaissance and vulnerability research.
Both put more emphasis on permissions, monitoring and human oversight.
Trusted access deserves the same scrutiny as external threats
This month’s incidents show how cyber risk can appear through systems and relationships organisations already trust and understanding who and what has access across an organisation is becoming increasingly important to wider resilience.
At Elovade, we support channel partners in protecting their clients with our selected vendor portfolio, specialists and dedicated support. To explore our vendors or discuss how we can support your security offering, visit our vendor page or get in touch with the Elovade team.