10 Things You May Have Missed in September 2026
September was another busy month across Microsoft, cyber security and emerging technologies. From Microsoft's continued push towards passkeys and new Security Copilot capabilities to growing concerns around AI-powered attacks and active vulnerability exploitation, organisations faced no shortage of developments to keep track of.
Here's our roundup of ten stories that caught our attention during September and what they could mean for organisations.
1. Microsoft Continues the Move Towards Passkeys
Microsoft has confirmed that passkeys will become the default authentication experience, with Microsoft-provided SMS and voice authentication being retired in favour of phishing-resistant authentication methods. The move forms part of Microsoft's wider effort to strengthen identity security and reduce the risk of account compromise.
Traditional authentication methods remain a common target for phishing and social engineering attacks. As organisations continue strengthening identity security, now is a good time to review authentication policies and identify users who still rely on older authentication methods. At Indiko Data, this is already a key discussion we're having with organisations looking to improve security and prepare for future changes.
2. Windows 11 26H2 Draws Closer
Windows 11 26H2 is expected later this year and will use the same servicing branch as Windows 11 24H2 and 25H2. This should allow many organisations to deploy the update through a smaller enablement package rather than undertaking a major operating system migration.
Although the update is expected to have a lower deployment impact, organisations should continue reviewing compatibility, version support and rollout planning. With Windows 11 24H2 support ending in October 2026, endpoint readiness should already be on the agenda.
3. Microsoft Security Copilot Expands Investigation Capabilities
Microsoft announced new Security Copilot capabilities designed to help security teams investigate threats faster and manage increasingly complex environments. New features include AI-generated investigation summaries and additional tools to support threat prioritisation.
As cyber security teams continue dealing with growing volumes of alerts and incidents, AI-powered tools have the potential to improve visibility and productivity while supporting, rather than replacing, human expertise. Organisations evaluating Microsoft's security stack should consider where automation can add value within existing security processes.
4. Windows Updates Cause Desktop Loading Issues
Microsoft acknowledged reports that recent Windows updates caused desktop loading issues for some users. The issue was one of several update-related problems reported during the month.
While security updates remain essential, incidents like this highlight the balance organisations must strike between maintaining security and preserving operational stability. Effective testing procedures and rollback plans remain important components of any patch management strategy.
5. JADEPUFFER Shows How AI Could Be Used in Future Attacks
Researchers detailed JADEPUFFER, an agentic AI attack capable of autonomously targeting Azure cloud resources. The research demonstrates how AI technologies could increasingly be used to automate offensive security activities with limited human involvement.
As organisations adopt Microsoft Copilot and other AI technologies, security and governance should be part of the conversation from day one. At Indiko Data, we're increasingly helping organisations explore AI securely, ensuring appropriate governance, controls and data protection measures are in place.
6. UK Government Issues Frontier AI Update
The UK Government released an update on frontier AI following several high-profile incidents over the summer. The update highlighted how advanced AI systems are becoming capable of performing increasingly complex tasks with limited human oversight.
As adoption accelerates, businesses, regulators and policymakers are paying closer attention to governance, oversight and emerging risks. Organisations introducing AI technologies should ensure that governance frameworks evolve alongside adoption rather than after it.
7. NCSC Warns of Active Citrix NetScaler Exploitation
The National Cyber Security Centre (NCSC) issued guidance regarding the active exploitation of vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway products. Organisations using affected systems were urged to review guidance and take action where necessary.
Internet-facing infrastructure remains one of the most common attack vectors used by threat actors. Timely patching, vulnerability management and visibility across critical systems continue to be fundamental elements of a strong cyber security strategy.
8. Microsoft Disrupts AI-Powered Phishing Infrastructure
Microsoft announced the seizure of 50 websites linked to the EvilTokens phishing operation. Reports suggested the campaign compromised thousands of email accounts and used AI throughout the attack chain to support phishing and fraud activities.
The incident demonstrates how cybercriminals are increasingly incorporating AI into existing attack methods to improve automation and scale. Strong authentication, cyber awareness training and layered security controls remain critical defences against phishing threats. This is why identity security and security awareness continue to be key areas of focus for many organisations working with Indiko Data.
9. ShinyHunters Claims FBI-Related Breach
The ShinyHunters threat group claimed to have breached systems connected to the FBI through a reported Oracle PeopleSoft zero-day vulnerability. While the claims generated significant attention across the cyber security industry, the story also reinforced a familiar lesson around vulnerability management.
Organisations should ensure visibility extends beyond core infrastructure and includes business-critical applications, third-party systems and internet-facing services. Unpatched vulnerabilities remain one of the most common pathways into corporate environments.
10. Apple Fixes Zero-Day Vulnerability
Apple released fixes for a zero-day vulnerability affecting CoreGraphics which had reportedly been exploited in targeted attacks. The vulnerability serves as a reminder that attackers do not focus solely on Windows environments.
Many organisations now operate mixed-device environments that include Windows, macOS and mobile devices. Security and update policies should cover every endpoint to minimise exposure to emerging threats and vulnerabilities.
Final Thoughts
If one theme stood out throughout September, it was the growing intersection between AI and cyber security. Organisations are seeing the benefits of AI-powered tools such as Microsoft Security Copilot while also facing the reality that threat actors are beginning to use similar technologies to scale attacks and improve efficiency.
Alongside ongoing developments in identity security, vulnerability management and endpoint protection, the message remains clear: security, governance and resilience need to remain at the heart of every technology decision.
At Indiko Data, we help organisations strengthen cyber security, modernise IT operations and adopt technologies such as Microsoft 365, Azure and AI solutions securely and effectively.









