Content
01. News Bites
-
Microsoft issues record-breaking Patch Tuesday update for 966 flaws
-
AdaptHealth cyberattack exposes data of 4.1 million people
-
Japan records highest-ever Ransomware levels in first half of 2026
-
Data Exposure surges across financial services devices
-
Ontario court records exposed in C-Track cyberattack
02. Conclusion
Microsoft issues record-breaking Patch Tuesday update for 966 flaws
Microsoft’s September 2026 Patch Tuesday has delivered the company’s largest security update on record, addressing 966 vulnerabilities, including 105 rated Critical and two actively exploited zero-days.
The release fixes 258 remote code execution flaws, 438 elevation of privilege vulnerabilities, 173 information disclosure issues, 56 denial-of-service vulnerabilities, 19 security feature bypasses and 16 spoofing flaws. It follows already substantial releases in July and August, which addressed 570 and 400 vulnerabilities respectively. The sharp increase comes as Microsoft expands its use of AI-powered systems to uncover weaknesses across its products.
The two exploited zero-days, CVE-2026-81963 and CVE-2026-85880, affect the Windows Update Stack and Windows Advanced Local Procedure Call respectively. Both allow an authorised local attacker to elevate privileges and gain SYSTEM-level access.
With attackers already exploiting these vulnerabilities, organisations should prioritise testing and deploying the September updates, beginning with internet-facing, business-critical and high-value Windows systems, as quickly as their change processes permit.
AdaptHealth cyberattack exposes data of 4.1 million people
US healthcare company AdaptHealth has confirmed that a cyberattack exposed the personal and health information of 4,115,802 people. The incident has reportedly been linked to the ShinyHunters extortion group.
Attackers gained access on 5 June 2026 after a social-engineering attack compromised the privileged account of a third-party contractor. They subsequently accessed cloud-based business applications, including patient management systems, document storage platforms and electronic health record portals. AdaptHealth received a ransom demand on 15 June and publicly disclosed the incident in July.
Exposed information may include names, contact and demographic details, health insurance information and health data. AdaptHealth says it has found no evidence that the stolen information has been used for identity theft, fraud or other malicious activity.
Affected individuals have been offered 12 months of complimentary credit monitoring and identity protection. The incident highlights the significant security risks created by third-party privileged access within healthcare environments and supply chains.
Japan records highest-ever Ransomware levels in first half of 2026
Japan recorded 123 ransomware attacks during the first half of 2026, the highest number reported for the period, according to the National Police Agency. Small and medium-sized businesses accounted for 79 incidents, while 31 affected large companies and 13 targeted other organisations.
Manufacturing was the most heavily affected sector, recording 37 attacks. VPN devices were the most common entry point, highlighting the danger posed by vulnerable or poorly secured remote-access infrastructure. Recovery frequently took more than a month and generated costs.
Police-monitored networks also received an average of 13,687 suspicious access attempts per IP address each day, more than 4,000 above the previous year. Separately, authorities recorded 127 business email compromise cases causing losses of ¥3.88 billion.
Overall, Japanese police handled 7,607 cybercrime cases, an annual increase of 982. The figures underline the need for stronger vulnerability management, access controls, network monitoring and incident response planning.
Data Exposure surges across financial services devices
Data exposure on financial services devices has risen to 40% over the past year, the steepest increase across any industry, according to a new report surveying 1,000 UK and US security leaders.
The research found that Windows 10 patching now lags by an average of 105 days, 74 days longer than the previous year. This leaves financial organisations exposed to known vulnerabilities as automated, machine-speed attacks become more common.
Although 79% of CISOs have a cyber resilience strategy and 96% believe they could recover from ransomware, only 41% can remotely restore devices following a fleet-wide attack. Average recovery costs have reached $2.41 million per incident.
Operational downtime remains the greatest impact of ransomware, followed by regulatory penalties. Despite scrutiny under DORA and SEC disclosure requirements, 58% of CISOs would consider paying a ransom. The findings highlight the need for automated patching, resilient endpoints and tested recovery capabilities.
Ontario court records exposed in C-Track cyberattack
Ontario’s chief justices have warned that personal information contained in court records may have been stolen in a cyberattack affecting Thomson Reuters’ C-Track case-management platform.
Thomson Reuters detected unauthorised activity within a cloud environment on 30 June 2026. Its investigation found that the breach began in March and allowed an unauthorised party to obtain records from Ontario’s Court of Appeal, Superior Court of Justice and Court of Justice. Potentially affected material includes names, personal data and confidential, redacted or sealed information, although the number and age of the exposed records remain unknown.
The company stressed that the incident did not originate from the courts’ networks. Security measures have since been introduced, while credit monitoring and a helpline are available for affected individuals.
C-Track court systems across 11 US states and the US Virgin Islands were also affected, with exposed data possibly including Social Security numbers, driving licence details and medical information.
If you are worried about any of the threats outlined in this bulletin or need help in determining what steps you should take to protect yourself from the most material threats facing your organisation, please contact your account manager, or alternatively Get in touch to find out how you can protect your organisation.
Disclaimer
The Threat Intel Roundup was prepared by Integrity360 summarising threat news as we observe it, current at the date of publishing. It should not be considered to be legal, consulting or any other professional advice. Any recommendations should be considered in the context of your own organisation. Integrity360 does not take any political stance in the information that we share. Moreover, the opinions expressed may not necessarily be the views of Integrity360.