
14 September 2026 · 4 min read
Patch Tuesday just got heavier, and your browser is still a frontline risk
CISA added CVE-2026-85706 to the KEV catalogue. Microsoft's September 2026 Patch Tuesday is unusually large. Google is still patching exploited Chrome zero-days. This week: tighten patch discipline and browser hardening.
The Monday Morning Cyber Brief
Every Monday, Baltimore reviews the previous week's most significant cybersecurity events and translates them into plain English. No fear tactics. No jargon. Just what happened, why it matters to regulated businesses in the Channel Islands, and what questions you should be asking your team.
Previous Briefs
One more KEV entry, finance phishing still live in the islands, and edge devices remain the fastest way in
CVE-2026-85046 is confirmed exploited, QuickBooks phishing continues to target Channel Islands finance teams, and SonicWall SMA1000 zero-day reports put edge appliances back in the spotlight. This week: patch the KEV item, tighten payment controls, and check your remote access kit.
QuickBooks phishing is hitting the islands, and exploited vulnerabilities are still the fastest way in
Guernsey has flagged a QuickBooks themed phishing campaign, while CISA KEV additions and PaperCut exploitation show how fast attackers weaponise common systems. This week: stop payment fraud, close the obvious doors.
Want to discuss anything from this week's brief?
Join the conversation on LinkedIn