Threat Brief — 2026-09-03 — KEV Surge, Qilin Escalates, Inbox Traps
Executive summary
CISA has added seven actively exploited vulnerabilities to its KEV catalog, with attackers already deploying reverse shells and crypto miners — a broad expansion beyond the individual CVEs tracked earlier this week. The Qilin ransomware group now claims to have exfiltrated investigative materials from the breached US federal agency, including smartphone data and IP addresses, escalating an incident first confirmed late last month. A fresh phishing report highlights how routine accounting invoices are being used to place computers under covert criminal control. Separately, Microsoft Teams and New Outlook are failing to launch on ARM-based Windows PCs following August 2026 Patch Tuesday updates.
Top items
- CISA adds seven exploited flaws to KEV catalog. CISA added seven vulnerabilities to its Known Exploited Vulnerabilities catalog on Wednesday, with attackers observed deploying reverse shells and cryptocurrency miners. CVE-2026-83548KEV is among those listed. This expands the KEV additions tracked since mid-August, when the Philippines nuclear agency breach via unpatched ownCloud flaws was first reported on 2026-08-17 by CISA. (src: The Hacker News)
- Qilin claims exfiltration of federal investigative materials. The Qilin ransomware group asserts it obtained investigative materials from the breached US federal agency, including data from smartphones and IP addresses. This marks an escalation in the ATF incident, which was first reported on 2026-08-27 by BleepingComputer when the agency confirmed a major breach. The claims, if accurate, suggest sensitive law-enforcement data may be exposed. (src: SecurityLab)
- Accounting-invoice phishing delivers covert remote access. A new report details a phishing campaign where a routine accounting invoice is used to place victim computers under covert criminal control. The attack succeeded because the victim followed what appeared to be a standard business procedure, and antivirus did not flag the activity. This underscores the continued effectiveness of socially engineered document lures against accounting and finance workflows. (src: SecurityLab)
- Microsoft Teams and New Outlook crash on ARM Windows after August Patch Tuesday. Microsoft has confirmed a known issue causing crashes and launch failures for Microsoft Teams and New Outlook on ARM-based Windows PCs after installing updates released since August 2026 Patch Tuesday. Microsoft is working on a fix. This is an operational reliability issue rather than a security vulnerability, but it affects productivity tools on ARM deployments. (src: BleepingComputer)
- Geomagnetic storm caused GPS errors exceeding 10 meters across the US. A powerful geomagnetic storm disrupted GPS accuracy across nearly the entire United States, with positioning errors surpassing 10 meters. While not a cyberattack, this highlights the fragility of GPS-dependent systems to natural infrastructure disruption and is relevant for any organisation relying on precise location or timing data. (src: SecurityLab)
Themes
Exploitation velocity continues to outpace patching. The CISA KEV additions this week — spanning ownCloud, JFrog Artifactory, SonicWall SMA1000, Switchvox, LiteLLM, Starlette, Kestra, and now seven more — illustrate a consistent pattern: attackers are weaponising disclosed vulnerabilities faster than organisations can remediate them. The presence of reverse shells and crypto miners in active exploitation suggests both intrusion and monetisation are happening quickly after KEV listing.
Social engineering remains the highest-yield initial-access vector. The accounting-invoice phishing report, the Google/NFL-player scam, and the fake software installer campaign reported earlier this week all demonstrate that carefully crafted lures continue to bypass both technical controls and human suspicion.
