CYBER FRI - Sept 11, 2026

Yasmine Johnston-Ison
This week's cyber reality for small and mid-size businesses:
- Microsoft's September Patch Tuesday set a record: 974 vulnerabilities patched, including two actively exploited zero-days. CVE-2026-81963 is an elevation of privilege flaw in the Windows Update Stack — attackers with a foothold can gain SYSTEM-level access. If your team or your MSP hasn't pushed this update, you're running exposed. (SecurityWeek, BleepingComputer, CrowdStrike)
- CISA added six new entries to the Known Exploited Vulnerabilities catalog this week — four on September 9 and two more on September 10. The additions include BerriAI LiteLLM (an AI model gateway), Check Point Security Gateway, and MikroTik RouterOS — all actively exploited. The LiteLLM addition is notable: AI infrastructure is now firmly in attackers' crosshairs. (CISA)
- A new exploit kit called "BlueMoon" is chaining Windows and Chrome zero-day flaws to deliver attacks in the wild. Attackers are combining browser + OS vulnerabilities — if either is unpatched, the attack works. (OpenText Cybersecurity)
- Chinese government-linked hackers stole at least $20 million in COVID-19 relief funds from the U.S. government, including Small Business Administration funds. The breach targeted relief programs that SMBs relied on during the pandemic — and the data exposure may still be unfolding. (CSIS, Sep 10)
The deal lens: When you buy a business, you inherit its patch status, its vendor stack, and its breach history. This week shows why: a record Patch Tuesday, six new CISA exploits, AI infrastructure under attack, and a new exploit kit chaining browser and OS flaws. A pristine P&L means nothing if the Windows Update Stack has a known-exploited vulnerability nobody patched.
What's one system in your target's tech stack that hasn't been patched this week?
#CyberSecurity #ThreatIntel #SMBAcquisition #DueDiligence #PatchTuesday
Need Structured Guidance for Your Acquisition?
Book a 45-minute strategy call with our team to discuss your search progress, deal thesis, or transition plans.
Book an Appointment45 minutes to confirm fit and define next steps.
Related Insights
CYBER FRI (Analyst Edition) — Sept 18, 2026
Cisco ISE zero-day, Acronis backup flaw & record ransomware: IOCs & technical breakdown
The Cyber Liabilities You Inherit on Closing Day
Unpatched firewalls, exploited Windows flaws, and open SaaS guest access do not appear in the P&L—but buyers inherit them at close.