Independent cybersecurity news and intelligence
HomeSourcesRSS
Cybersecurity News. Source-grounded Intelligence.
Back to newsroom
AI SecurityCyberDeltaForce Newsroom

The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords

The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords. Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880).

Qualys Threat Research UnitSep 9, 2026, 3:00 PM UTC3 min readCVE-2026-81963
IN 30 SECONDS

Understand the story quickly

What happenedSource reporting

The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords.

Who or what is affectedSource reporting

Attackers are already using this issue in real-world attacks, so exposed systems may need both remediation and investigation for earlier compromise.

Why it mattersSource reporting

The question of whether a Frontier AI model could find vulnerabilities that no human researcher had found was settled in April.

Defender next stepCDF guidance

Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.

THE NEWS

The full story

Source-grounded reporting, presented as a continuous narrative.

The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords. Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880). A security weakness in Windows is being tracked as CVE-2026-81963.

This month’s updates include patches for two zero-days that were exploited in the wild. Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days.

The question of whether a Frontier AI model could find vulnerabilities that no human researcher had found was settled in April. 104 Critical 860 Important 0 Moderate 0 Low Microsoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. Attackers are already using this issue in real-world attacks, so exposed systems may need both remediation and investigation for earlier compromise.

SOURCE EVIDENCE

What the reporting is based on

Qualys Threat Research Unit

The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords

The question of whether a Frontier AI model could find vulnerabilities that no human researcher had found was settled in April.

Open source
Tenable Research

Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)

104 Critical 860 Important 0 Moderate 0 Low Microsoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.

Open source
The Hacker News

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools.

Open source
CYBERDELTAFORCE INTELLIGENCE

Reporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.

CDF ANALYSIS

What this means

Risk depends on whether the affected technology and the affected component are deployed and reachable, because the reported flaw can lead to privilege escalation. Exposure, privilege, business criticality and compensating controls should determine remediation priority.

DEFENDER ACTIONS

What security teams should check now

  • Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.
  • Apply the vendor patch or mitigation for CVE-2026-81963 and validate the affected path after remediation.
OPEN QUESTIONS

What is not yet confirmed

  • Who was responsible has not yet been confirmed publicly.
Continue the story

Related Cybersecurity Coverage

More cybersecurity news
CyberDeltaForce publication standards