Cybersecurity News: September 2026 | Kocho
Skip to content
Funnel overlay image

Cybersecurity Roundup September 2026

arrow icon arrow icon

From Kocho’s Security Operations Centre (SOC)

Published: 09 September 2026

Unseen exposure, phishing-resistant identity and the infrastructure attackers reach first

The NCSC has warned of increased targeting of operational technology and internet-exposed systems, including activity affecting UK organisations.

In this edition, our SOC team focus on what the warning reveals about the gap between the systems organisations document and the infrastructure attackers can actually reach.

Also: Microsoft Entra makes passkeys the default authentication method, thousands of Exchange servers remain unpatched, Google fixes an exploited Chrome zero-day, the Manchester Airport data breach and follow-on phishing risks, attackers test a critical Citrix NetScaler flaw, and an Artifactory vulnerability puts software supply chains at risk.

What the NCSC warning tells us about unseen exposure

The NCSC has warned of increased targeting of operational technology, internet-exposed systems and edge devices across multiple sectors, including in the UK. Although aimed at operational technology, the warning has wider relevance because organisations often know what they deliberately publish online, but not everything attackers can reach.

That might include a remote-access appliance installed for a project, an unowned supplier connection or a management interface left behind after a migration.

The NCSC advises organisations to maintain a definitive view of assets, communications pathways and external connections, alongside stronger controls for internet-facing infrastructure. Without that visibility, security teams cannot patch, monitor or retire exposed systems.

Organisations should compare their asset inventory with what is actually reachable from the internet. Any difference between the two may reveal unmanaged or forgotten exposure.

Entra passkeys become the default

From 1 September 2026, Microsoft began making passkeys the default authentication experience in Entra ID. Users enabled for SMS or voice authentication will be prompted to register a passkey during multifactor authentication.

Microsoft-provided SMS and voice authentication will end on 1 February 2027. Organisations that still require either method will need to use a supported provider through the Microsoft Security Store.

Passkeys resist phishing by replacing passwords and interceptable one-time codes with public-key cryptography. Organisations now need to identify users who depend on weaker methods, resolve device, recovery and exception requirements, and prepare the service desk and users for the change.

If saved passwords can be stolen, valid access becomes real risk
tag icon

Further reading

Why valid credentials are the fastest route past your defences

Kocho Security Operations Technical Lead Adam Febery explains why credential theft is only the start of an identity breach, and why attackers who gain valid access can move through an environment looking exactly like a legitimate user.

He sets out the identity controls that limit lateral movement, shorten dwell time, and turn valid-looking activity into an early warning rather than a missed signal.

Also in the news

Thousands of Exchange servers remain exposed after a fix was released

Nearly 22,000 internet-exposed Exchange servers remained unpatched for CVE-2026-62911 at the beginning of September, despite a fix released in August and reports of working exploit code.

Confirm the versions in use, apply available updates and remove unnecessary internet exposure. Unsupported Exchange deployments need a defined replacement plan because a released patch only reduces risk when systems can receive it.

Chrome’s latest zero-day makes browser coverage the priority

Google has patched CVE-2026-85046, a high-severity vulnerability in Chrome’s V8 engine that was exploited in the wild.

Verify that the update reached every device, including unmanaged browsers and endpoints that rarely connect or no longer report into endpoint management. Coverage matters more than successful deployment across known assets.

Manchester Airports breach increases follow-on phishing risk

Manchester Airports Group has confirmed that customer contact and vehicle data was accessed, although payment details, airport operations and passenger safety were unaffected.

The data could still support convincing phishing and impersonation attempts. Affected customers should treat unexpected airport or travel-related requests for payments, banking details or credentials with caution.

Attackers are testing Citrix NetScaler authentication defences

Requests matching public proof-of-concept code have been observed for CVE-2026-19490, a critical authentication bypass affecting some Citrix NetScaler Gateway and AAA configurations. The activity shows exploitation attempts, but not confirmed compromise.

Identify exposed NetScaler systems, verify affected configurations, apply Citrix’s recommended builds and review earlier activity. Public exploit code shortens the time available to respond.

Artifactory’s privileged position makes this more than a server flaw

CVE-2026-82329 is a critical authentication weakness that can give an unauthenticated attacker administrative access to self-hosted JFrog Artifactory under its default configuration. Attackers have reportedly used it to create administrator tokens.

Patch self-hosted deployments and review privileged tokens, credentials and federation relationships. Because Artifactory feeds trusted build and delivery processes, investigate connected development systems rather than treating it as an isolated server.

This month’s priority actions

Ebony and green pie chart clipboard icon on transparent background

Compare your asset inventory with the systems and services that are genuinely accessible from the internet. Give every exposed asset a named owner and a clear reason for still being exposed.

Ebony and green magnifying glass tick icon on transparent background

Identify Entra users who still rely on SMS or voice authentication and begin a controlled move to passkeys before Microsoft ends native provision of those methods in February 2027.

Ebony and green tickets on transparent background

Patch Exchange Server and Google Chrome, then identify systems and endpoints that sit outside normal update coverage.

Update self-hosted JFrog Artifactory and review administrator tokens, credentials, federation relationships and connected development systems.

tag icon

Get cyber confident

Real partnership. Microsoft expertise. Complete transparency.

Request a call back today.

  • AI-powered rapid protection, from day one
  • Dedicated Microsoft experts, by your side
  • Powerful, intuitive reporting tools
  • Collaboration and transparency as standard

Butterfly overlay image

Got a question? Need more information?

Our expert team is here to help.