
SEPT
15
The FBI published its first-ever comprehensive cyber strategy in September 2026, focusing on disrupting threat actors rather than just defending networks. The strategy outlines four pillars: disrupt, pursue, protect, and prepare. CISA and NSA contributed to the strategy.

SEPT
15
ScreenConnect CVE-2026-84869 is a 9.9 CVSS critical guest-to-host file execution flaw patched in ScreenConnect 26.6.5 on September 8, 2026. ConnectWise issued priority 1 high severity advisory. Servers not affected. Update immediately or strip TransferFiles permission.

SEPT
15
Switzerland's federal government announced in September 2026 it will move away from Microsoft 365 to open-source alternatives citing data sovereignty, cost, and vendor lock-in concerns. The transition will roll out over 3-5 years across federal agencies.

SEPT
15
Tesla CEO Elon Musk confirmed the company repelled a 'serious' ransomware attack in early September 2026, attributing the success to the company's internal security team. Bank Info Security reports the incident. Tesla did not pay any ransom.

SEPT
15
Active exploitation wave hits Palo Alto Networks PAN-OS and Fortinet FortiGate enterprise edge devices in September 2026. Critical PAN-OS root-level RCE and FortiGate vulnerabilities under active attack by APT and ransomware groups. Patch immediately.

SEPT
15
A new phishing-as-a-service platform named BigBear bypassed Microsoft 365 multi-factor authentication at 258 organizations in early September 2026. BleepingComputer reports the platform uses adversary-in-the-middle techniques to steal session tokens.

SEPT
15
Plesk disclosed CVE-2026-68488, a symlink race condition in the Backup Manager's subscription-content restore function that allows low-privileged users to escalate to root on Linux servers. Patched in Plesk Obsidian 18.0.62. Update immediately.

SEPT
15
The Liquid Network, a Bitcoin sidechain operated by Blockstream, lost approximately $320 million in Bitcoin to attackers in September 2026. The attackers claim they are 'the good guys' returning the funds. DataBreaches.net reports the incident.

SEPT
15
Both Quinn Emanuel Urquhart & Sullivan and McDermott Will & Emery disclosed data breaches on September 14, 2026, exposing sensitive client data. The Economic Times reports the incidents may or may not be related. Affected clients should monitor for phishing and verify any data requests.

SEPT
15
Revolut disclosed a data breach September 13-14, 2026 exposing KYC data on thousands of customers via a fraudulent request appearing from a legitimate government agency. BleepingComputer and cybersecuritynews.com reported the incident. Affected customers should reset passwords and enable 2FA.

SEPT
15
High-yield savings accounts pass through Fed rate hikes within 30-60 days. Online banks lead with 4.00-4.50% APY; brick-and-mortar banks average 0.42% APY. Best HYSAs in 2026: UFB Direct 4.51%, Marcus 4.40%, Bask Bank 4.40%, Ally 4.35%.

SEPT
15
Goldman Sachs raised its September 2026 Fed hike call to 100% after the August CPI hot core print. GS now sees 2 cuts in 2027 in September and December, terminal rate at 3.25-3.50%. Credit Agricole leans hold with hawkish tone. Reuters poll says hold; Kalshi market prices ~52% hike.
Get career tips in your inbox
One email a week — new articles, guides and course updates. No spam.