10 Things You May Have Missed in September 2026

October 7, 2026

September was another busy month across Microsoft, cyber security and emerging technologies. From Microsoft's continued push towards passkeys and new Security Copilot capabilities to growing concerns around AI-powered attacks and active vulnerability exploitation, organisations faced no shortage of developments to keep track of.


Here's our roundup of ten stories that caught our attention during September and what they could mean for organisations.


1. Microsoft Continues the Move Towards Passkeys

Microsoft has confirmed that passkeys will become the default authentication experience, with Microsoft-provided SMS and voice authentication being retired in favour of phishing-resistant authentication methods. The move forms part of Microsoft's wider effort to strengthen identity security and reduce the risk of account compromise.


Traditional authentication methods remain a common target for phishing and social engineering attacks. As organisations continue strengthening identity security, now is a good time to review authentication policies and identify users who still rely on older authentication methods. At Indiko Data, this is already a key discussion we're having with organisations looking to improve security and prepare for future changes.


2. Windows 11 26H2 Draws Closer

Windows 11 26H2 is expected later this year and will use the same servicing branch as Windows 11 24H2 and 25H2. This should allow many organisations to deploy the update through a smaller enablement package rather than undertaking a major operating system migration.


Although the update is expected to have a lower deployment impact, organisations should continue reviewing compatibility, version support and rollout planning. With Windows 11 24H2 support ending in October 2026, endpoint readiness should already be on the agenda.


3. Microsoft Security Copilot Expands Investigation Capabilities

Microsoft announced new Security Copilot capabilities designed to help security teams investigate threats faster and manage increasingly complex environments. New features include AI-generated investigation summaries and additional tools to support threat prioritisation.


As cyber security teams continue dealing with growing volumes of alerts and incidents, AI-powered tools have the potential to improve visibility and productivity while supporting, rather than replacing, human expertise. Organisations evaluating Microsoft's security stack should consider where automation can add value within existing security processes.


4. Windows Updates Cause Desktop Loading Issues

Microsoft acknowledged reports that recent Windows updates caused desktop loading issues for some users. The issue was one of several update-related problems reported during the month.


While security updates remain essential, incidents like this highlight the balance organisations must strike between maintaining security and preserving operational stability. Effective testing procedures and rollback plans remain important components of any patch management strategy.


5. JADEPUFFER Shows How AI Could Be Used in Future Attacks

Researchers detailed JADEPUFFER, an agentic AI attack capable of autonomously targeting Azure cloud resources. The research demonstrates how AI technologies could increasingly be used to automate offensive security activities with limited human involvement.


As organisations adopt Microsoft Copilot and other AI technologies, security and governance should be part of the conversation from day one. At Indiko Data, we're increasingly helping organisations explore AI securely, ensuring appropriate governance, controls and data protection measures are in place.


6. UK Government Issues Frontier AI Update

The UK Government released an update on frontier AI following several high-profile incidents over the summer. The update highlighted how advanced AI systems are becoming capable of performing increasingly complex tasks with limited human oversight.


As adoption accelerates, businesses, regulators and policymakers are paying closer attention to governance, oversight and emerging risks. Organisations introducing AI technologies should ensure that governance frameworks evolve alongside adoption rather than after it.


7. NCSC Warns of Active Citrix NetScaler Exploitation

The National Cyber Security Centre (NCSC) issued guidance regarding the active exploitation of vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway products. Organisations using affected systems were urged to review guidance and take action where necessary.


Internet-facing infrastructure remains one of the most common attack vectors used by threat actors. Timely patching, vulnerability management and visibility across critical systems continue to be fundamental elements of a strong cyber security strategy.


8. Microsoft Disrupts AI-Powered Phishing Infrastructure

Microsoft announced the seizure of 50 websites linked to the EvilTokens phishing operation. Reports suggested the campaign compromised thousands of email accounts and used AI throughout the attack chain to support phishing and fraud activities.


The incident demonstrates how cybercriminals are increasingly incorporating AI into existing attack methods to improve automation and scale. Strong authentication, cyber awareness training and layered security controls remain critical defences against phishing threats. This is why identity security and security awareness continue to be key areas of focus for many organisations working with Indiko Data.


9. ShinyHunters Claims FBI-Related Breach

The ShinyHunters threat group claimed to have breached systems connected to the FBI through a reported Oracle PeopleSoft zero-day vulnerability. While the claims generated significant attention across the cyber security industry, the story also reinforced a familiar lesson around vulnerability management.


Organisations should ensure visibility extends beyond core infrastructure and includes business-critical applications, third-party systems and internet-facing services. Unpatched vulnerabilities remain one of the most common pathways into corporate environments.


10. Apple Fixes Zero-Day Vulnerability

Apple released fixes for a zero-day vulnerability affecting CoreGraphics which had reportedly been exploited in targeted attacks. The vulnerability serves as a reminder that attackers do not focus solely on Windows environments.


Many organisations now operate mixed-device environments that include Windows, macOS and mobile devices. Security and update policies should cover every endpoint to minimise exposure to emerging threats and vulnerabilities.


Final Thoughts

If one theme stood out throughout September, it was the growing intersection between AI and cyber security. Organisations are seeing the benefits of AI-powered tools such as Microsoft Security Copilot while also facing the reality that threat actors are beginning to use similar technologies to scale attacks and improve efficiency.


Alongside ongoing developments in identity security, vulnerability management and endpoint protection, the message remains clear: security, governance and resilience need to remain at the heart of every technology decision.


At Indiko Data, we help organisations strengthen cyber security, modernise IT operations and adopt technologies such as Microsoft 365, Azure and AI solutions securely and effectively.


Abstract purple-to-cyan diagonal gradient background with a soft glow
October 7, 2026
Discover 10 important Microsoft, Acronis and cyber security updates from August 2026, including passkeys, AI security, Azure threats and more.
Team meeting in a bright office, with four people gathered around laptops and charts.
September 15, 2026
Wondering what an Acronis Cyber Protection Trial involves? Discover how Indiko Data delivers a fully managed, no-obligation trial with backup, security and support.
Futuristic green HUD on a computer monitor in a dark room, with a desk and electronics in the foreground
August 26, 2026
43% of UK businesses reported a cyber incident. Discover how Indiko Data's Acronis Bundle combines backup, security and monitoring to improve protection.
People working at desks in a modern glass-walled office with city views
August 21, 2026
Think Microsoft 365 automatically protects all your data? Discover why backup still matters and how Indiko Data's Acronis Bundle helps keep your business protected.
Modern glass-walled conference room with white table, black chairs, and city view
August 12, 2026
Discover what Microsoft Copilot Cowork means for your organisation and how Indiko Data helps businesses adopt AI securely, responsibly, and effectively.
Empty office conference room with glass doors and chairs around a wooden table
July 8, 2026
Think you need to upgrade to Microsoft 365 Enterprise? Discover how Indiko Data helps SMBs explore smarter, cost-effective licensing options.
Person working at a desk with dual monitors in a dimly lit room, lit by blue screen glow.
July 2, 2026
Discover the hidden security stack inside Microsoft 365 Business Premium and how Indiko Data helps SMBs maximise protection without adding more tools.
Glass-fronted office building with crisscross steel beams and people visible on multiple floors
June 18, 2026
Many SMBs are overpaying for tools already included in Microsoft Business Premium. Discover how Indiko Data helps you get full value from your setup.
Empty modern office with desks, chairs, laptops, papers, and sunlight from a large window.
June 18, 2026
Discover 5 common misconceptions about Microsoft Defender and how Indiko Data helps SMBs unlock its full potential for modern, connected security.
Hands typing on a laptop at a wooden desk with a coffee mug and notebook nearby.
June 9, 2026
Modern risk extends beyond endpoints. See how Microsoft Defender and Indiko Data provide visibility across SaaS, shadow IT, and AI usage.