All issues
Tech & Security Intelligence Issue 017 · 14 Sep 2026

The Weekly
Brief

Three New Zealand breaches in a fortnight, two of them through a supplier’s software. Microsoft’s biggest patch day ever. A print server taken over by a swarm of AI agents in seconds. And the text-message code your staff sign in with now has a retirement date.

Paul, Director of Node-Red
Curated by Paul
Editor · Node-Red

4 stories · 8 min read

In this issue

01 Data Breach

Three NZ breaches in a fortnight — and two came through somebody else’s software

On 11 September RNZ reported that security researchers were raising the alarm after three New Zealand organisations disclosed breaches in quick succession. The one closest to home for most businesses is Thankyou Payroll, a New Zealand payroll provider used by charities and small organisations. On 10 September it told customers that names, IRD numbers, email and physical addresses, bank account details and payment histories had been accessed. The detail that matters: none of Thankyou Payroll’s own systems were breached. The way in was Metabase, a third-party reporting tool it used, which had a critical flaw — CVE-2026-72898, an unauthenticated SQL injection in the password-reset endpoint, rated the maximum CVSS 10.0, confirmed by the vendor as actively exploited and on CISA’s Known Exploited Vulnerabilities list since 11 August. The company took the tool offline, forced password resets and notified the Privacy Commissioner.

The other two are different flavours of the same problem. Police are investigating a breach at health research company Zenith Technology (ZenTech), where a large number of clinical trial files may have been stolen — and as University of Auckland’s Dr Abhinav Chopra told RNZ, health data cannot be changed the way a password can, so a stolen clinical dataset stays valuable indefinitely. And Mathspace, an online maths platform used in schools on both sides of the Tasman, confirmed attackers downloaded names and email addresses of more than a million students, parents and teachers. Victoria University researcher Ben Van Der Weerd made the point about payroll firms specifically: they hold an unusual concentration of personally identifiable information, which is exactly what sells. Metabase, for what it is worth, has been hitting companies globally — Framework, Anaconda and n8n have all disclosed customer-data access through the same flaw.

02 Patch Now

Microsoft’s biggest patch day ever, and the two flaws already being used

Microsoft’s September update landed on Tuesday 8 September US time — Wednesday morning here — and by Tenable’s count it fixed 964 CVEs, 104 of them critical. That is comfortably the largest monthly release Microsoft has ever shipped; the previous record, set only in July, was under 600. Different trackers land on slightly different totals depending on how they count third-party components, but every one of them agrees on the two that matter: both are zero-days, meaning attackers were using them before the fix existed. CVE-2026-85880 is a heap buffer overflow in Windows Advanced Local Procedure Call (ALPC), the internal plumbing Windows processes use to talk to each other. CVE-2026-81963 is a link-following flaw in the Windows Update Stack — the first exploited zero-day in that component since 2022. Both are rated CVSS 7.8, both hand the attacker SYSTEM, the highest privilege on the machine, and both are on CISA’s exploited list with a 22 September deadline for US federal agencies.

Neither of these gets an attacker in the door on its own. They are elevation-of-privilege bugs: they need code already running on the PC as an ordinary user, and they turn that into total control. Which sounds reassuring until you remember what an ordinary-user foothold costs today — one clicked attachment, one ClickFix page from last week’s issue, one “install this to join the meeting”. The privilege-escalation bug is the step that turns a nuisance on one laptop into disabled security tools, dumped passwords and a path to every other machine on the network. It is also why these flaws get used quietly for months before anyone notices: nothing about the initial phish looks different. The volume is the other story. Nobody is going to read 964 advisories, and nobody should try. The only sensible response to a release this size is to install it as a unit, this week, and confirm it actually installed.

03 AI & Threats

A swarm of AI agents broke into eleven organisations in 26 seconds

Two weeks ago, in Issue 015, we covered PaperCut’s emergency patches for two flaws in its NG and MF print-management servers — CVE-2026-81578, an authentication bypass, and CVE-2026-82078, remote code execution — disclosed as zero-days on 27 August and patched the next day. On 10 September researchers at GreyNoise and Blackpoint Cyber published what happened to the servers that were not patched in time. A suspected Russian-speaking actor compromised more than 440 PaperCut instances at 395 organisations across 48 countries, with the education sector hit hardest in the US, UK, France, Spain, Canada, Belgium, Portugal, Australia, Germany and Switzerland. What is new is how. The attacker ran hundreds of AI agents — built on OpenAI Codex and a DeepSeek model, wired up to ordinary offensive tools like Mimikatz, SharpHound, Certipy, Rubeus and Impacket — and let them scan, exploit and move through victims’ networks largely on their own.

The timings are the part to sit with. The agents went from an empty workspace to a working exploit in under four hours, having built and attacked their own lab copy of PaperCut and Active Directory to test it. Once the campaign started, eleven organisations were compromised in 26 seconds. At one US high school the run from first access to domain administrator took seven minutes. Arctic Wolf saw the follow-on activity you would expect from a human crew — registry hive collection, Metasploit payloads, commands enumerating hosts, users, processes and configuration files — except the crew was not human and did not need to sleep. Blackpoint’s own conclusion was measured: the AI did not invent a clever new technique. It simply removed most of the manual effort from every stage, which meant one operator could do to 395 organisations what used to take a team and a month.

04 Microsoft 365

The text-message login code has a date on it now: 1 February 2027

Microsoft has started the clock on the six-digit text-message code. From 1 September 2026, passkeys are the default sign-in experience in Microsoft Entra ID — the identity system under every Microsoft 365 account. Any user currently enabled for SMS or voice-call verification has been automatically enabled for passkeys as well, and the next time they complete MFA they will be nudged to register one. The nudge can be snoozed, for now, as many times as the user likes. The hard date is 1 February 2027: on that day Microsoft stops sending SMS and voice codes itself, and any user whose only registered method is SMS or voice will hit a blocking prompt — register a passkey, or you do not get in. Microsoft’s wording is unusually blunt: there is no opt-out from the February behaviour; it will be enforced for all tenants.

A passkey, in plain terms, is a login tied to a device you already unlock — your phone’s face or fingerprint, Windows Hello on the laptop, a small hardware key on the keyring. There is no code to read out, so there is nothing for a scam caller to ask for and nothing for a fake login page to capture; that is the entire reason Microsoft is doing this, and it is a genuine improvement over a text message that can be phished or SIM-swapped. For the minority who really need a phone code — a regulated process, a site with no smartphones — Microsoft will let you bring your own telecom provider through its Security Store: details from 18 September, configurable from 30 October, at your cost. Admins who need breathing room can apply a temporary opt-out from the automatic passkey enablement, but it expires on the same 1 February date, so it buys time, not an exemption.

Tip of the week

Write down who holds your data, and who patches it — one page, this week

Every story in this issue comes back to the same blind spot: software you depend on that you do not run. Thankyou Payroll’s customers found out on Wednesday that a reporting tool they had never heard of held their staff’s bank details. So make the list. Open a blank document and write down every system that holds information about your customers, your staff or your money — including the ones that belong to somebody else: the payroll bureau, the accounting platform, the booking or point-of-sale system, the CRM, the recruitment site, the shared drive, the website host, the school app, the print server. For each one, four columns: what data is in it, who owns the relationship on your side, who patches it (you, us, the vendor, or “don’t know”), and whether they would tell you if it was breached. “Don’t know” is an acceptable first answer; it is also the finding. Then send the three suppliers holding the most sensitive data a one-line email: “What third-party tools have access to our data, and what is your process for notifying us if one of them is compromised?” You are not auditing them. You are finding out whether they have ever been asked, and a vendor who cannot answer in a paragraph is telling you something. Keep the page somewhere two people can find it, because the day you need it is the day the email from a supplier arrives, and under the Privacy Act a breach likely to cause serious harm has to be reported to the Privacy Commissioner and to the people affected — by you, not by the vendor — and the first question you will be asked is “what did they have?” Managed clients: we can fill in the systems we manage for you; send us the rest and we will fold them into one page.

Node-Red

Want all of this handled for you?

We keep an eye on the threats, the updates and the fine print so you don't have to. Book a free, no-obligation IT checkup.

Book your free IT checkup