Microsoft released 972 security patches on September 14th, 2026, including 112 critical flaws, and you must install them today. AI-powered tools now find and exploit vulnerabilities faster than businesses can deploy fixes, collapsing the safe window from days to hours.
In today's cybersecurity update for September 14th, 2026, small business owners face several critical security developments requiring immediate attention.
Microsoft has released its largest security update ever, patching 972 vulnerabilities with 112 rated as critical severity. This represents nearly double the volume from just two months ago. The surge is attributed to AI-powered vulnerability discovery tools that are finding flaws faster than ever before. However, these same AI tools can reverse-engineer exploits from patches immediately upon release, shrinking the safe window for updates to essentially zero. Windows users must prioritize installing these patches immediately, and businesses should ensure automatic updates are enabled.
Revolut, the digital banking platform, disclosed a significant data breach after falling victim to a sophisticated social engineering attack. Scammers impersonating government officials used legitimate government email domains to fraudulently request customer data. The breach exposed passports, identity documents, financial records, and transaction histories. This incident demonstrates the evolution of social engineering tactics and highlights the critical need for verification procedures when handling requests for sensitive information, even from apparently official sources.
CISA added three vulnerabilities to its Known Exploited Vulnerabilities catalog affecting GitLab (specific CVE not mentioned in voice text to avoid technical jargon), JFrog Artifactory (CVE-2026-42016), and ConnectWise ScreenConnect. These flaws are being actively exploited by attackers in the wild. Organizations using these platforms must update immediately, as CISA only catalogs vulnerabilities with confirmed active exploitation.
A malicious browser extension targeting Twitch users, called "Twitch Enhanced Viewer | JeetBot," compromised approximately 30,000 Chrome and Firefox users by stealing OAuth tokens and forwarding them to Russian-controlled servers. This incident serves as a reminder to audit installed browser extensions, remove unused ones, and limit extension installations to only essential tools.
Google has modified its search results functionality, removing the ability to preview destination URLs by hovering over links before clicking. While Google claims this change combats abuse, it eliminates a key method users employed to detect phishing links. Organizations should train employees to verify URLs in the address bar after pages load and to exercise caution when clicking search results.
Finally, threat actors associated with the ShinyHunters ecosystem used the Claude AI assistant to analyze 1.8 million Android applications, successfully extracting hardcoded credentials and secrets. This campaign demonstrates how AI-assisted workflows enable rapid credential harvesting at scale. Development teams must ensure sensitive credentials are never hardcoded in applications and instead use secure credential storage methods.
Small business owners should prioritize immediate patching, implement verification procedures for data requests, audit third-party applications and browser extensions, and ensure secure development practices for any custom applications.
Why patch vulnerabilities immediately when attackers move this fast?
Microsoft's record patch volume reflects a fundamental shift in attack speed. AI discovery tools identify flaws at scale, and attackers reverse-engineer exploits from patches in hours, not weeks. CISA confirmed active exploitation of GitLab, JFrog Artifactory (CVE-2026-42016), and ConnectWise ScreenConnect flaws. For manufacturers and professional services firms, delay means exposure. Your immediate action: enable automatic Windows updates, apply all critical patches within 24 hours, and verify that your most-used applications (GitLab, Artifactory, ScreenConnect, or similar development tools) are current. One missed patch can cost your firm downtime and customer data.
Key takeaways
- Deploy all 112 critical Microsoft patches within 24 hours; automatic updates reduce manual lag risk.
- Audit and update development tools (GitLab, Artifactory, ScreenConnect) this week; CISA tracks these as actively exploited.
- Disable browser extensions not in active use and block extensions enterprise-wide unless pre-approved; 30,000 users lost credentials through one malicious Twitch extension.
- Require verification of data requests through out-of-band channels (call a known number); Revolut breach started with social engineering using spoofed government emails.
Frequently asked questions
How long do we have to patch after Microsoft releases these updates?
Hours, not days. AI tools now extract working exploits from patches within hours of release. Treat critical patches as same-day installs. CISA only adds vulnerabilities to its Known Exploited list after confirming real-world attacks, which means attackers are already using these flaws.
Which platforms should we prioritize if we can't patch everything at once?
Start with GitLab, JFrog Artifactory, and ConnectWise ScreenConnect if you use them, since CISA confirmed active exploitation. Then move to Windows servers and workstations running Microsoft products. Development tools pose the highest immediate risk because attackers target them first to extract credentials.
Do we really need to remove browser extensions?
Yes. The Twitch extension compromised 30,000 users by stealing OAuth tokens. Conduct an audit this week, remove any extension not actively used, and implement a policy blocking new extensions without IT approval. This is a quick win that prevents credential theft at the endpoint.
What should we do about the Revolut breach and social engineering risk?
Never fulfill data requests via email, even from addresses that look official. Require out-of-band verification: call your known government agency number or your customer directly using a verified phone number. Train staff to pause when requests ask for passports, financial records, or transaction history, and escalate to management before responding.
Sources
- https://www.schneier.com/blog/archives/2026/09/microsofts-patching.html
- https://www.infosecurity-magazine.com/news/revolut-data-breach-fake-government/
- https://www.malwarebytes.com/blog/news/2026/09/revolut-gave-customer-ids-and-financial-data-to-a-government-impostor
- https://www.securityweek.com/personal-financial-info-exposed-in-revolut-data-breach/
- https://securityaffairs.com/199032/security/u-s-cisa-adds-gitlab-jfrog-artifactory-and-connectwise-screenconnect-flaws-to-its-known-exploited-vulnerabilities-catalog.html
- https://cybersecuritynews.com/malicious-twitch-extension/
- https://www.malwarebytes.com/blog/news/2026/09/googles-new-search-redirects-make-links-harder-to-check-before-you-click
- https://cybersecuritynews.com/hackers-leverage-claude-to-exfiltrate-secrets-android-apps/