Threat Brief — 2026-09-08 — EU CRA deadline looms, ClickFix evolves
Executive summary
The EU Cyber Resilience Act's vulnerability-reporting obligations take effect September 11, giving software vendors as little as 24 hours to disclose actively exploited flaws and placing immediate pressure on supply-chain visibility. ClickFix social-engineering campaigns are expanding beyond blockchain-hosted payloads into abuse of legitimate services for persistent access, marking a tangible evolution of the tactic. The remainder of today's feed is dominated by minor informational updates to Microsoft's September Patch Tuesday advisories—table corrections for DHCP/DNS server CVEs and acknowledgement updates—with no new exploitability details.
Top items
- EU CRA vulnerability-reporting requirements effective September 11. The Cyber Resilience Act mandates that software vendors report actively exploited vulnerabilities within as little as 24 hours. The core compliance challenge is provenance: organisations must know exactly which components shipped, in which versions, and when. Vendors and downstream integrators without precise software-bill-of-materials visibility face regulatory exposure. (src: BleepingComputer)
- ClickFix campaigns evolve to abuse legitimate services for persistent access. Two separate attacks now demonstrate ClickFix operators moving beyond blockchain-hosted payload delivery (first reported 2026-09-05 by BleepingComputer) toward co-opting legitimate infrastructure to maintain footholds after initial compromise. This broadens the campaign's persistence surface and complicates detection based on infrastructure reputation alone. (src: DarkReading)
Minor updates
- Microsoft issued informational corrections to multiple September Patch Tuesday advisories—removing client versions from the affected-products tables for roughly 20 Windows DHCP Server and DNS Server CVEs (elevation of privilege, information disclosure, and RCE classes) because those flaws only impact Windows Server. Acknowledgement fields were also updated for CVE-2026-54990 (Remote Desktop Client RCE) and CVE-2026-50696 (IKE Protocol DoS). None of these changes alter exploitability ratings or add new vulnerability details. (src: MSRC)
Themes
Regulatory pressure converges with patch cadence. The EU CRA's 24-hour reporting window lands in the same week as Microsoft's record-breaking 966-flaw Patch Tuesday, underscoring that vulnerability disclosure obligations now operate on a faster clock than many organisations' internal triage cycles.
===
