
SANS Stormcast September 2026: Cybersecurity Threats and Updates
The September 2nd, 2026 SANS Internet Storm Center Stormcast covers multiple cybersecurity threats. Guild/Asteroth malware targets Brazilian users via Portuguese-language emails and a website restricting access to Brazilian IPs, browsers with Brazilian Portuguese settings, and local configurations, delivering a DLL via a ZIP archive and alternate data streams. Proxmox warns of an ongoing authentication bypass campaign exploiting an unpatched vulnerability in Proxmox 7 (end-of-life since 2024), affecting systems with libPVE access control versions below 8.0.4, though multi-factor authentication mitigates the risk. Microsoft’s Patch Tuesday for September 2026 includes an unscheduled server reboot, deviating from the quarterly baseline release cycle. Virtualizer suffered a sophisticated BGP hijack and TLS certificate impersonation attack, distributing malicious updates via a valid Let’s Encrypt certificate, with few customers impacted.