{
  "type": "bundle",
  "id": "bundle--4aa5f8a2-ecb0-47d5-8b28-6c8a6a16014a",
  "objects": [
    {
      "type": "report",
      "spec_version": "2.1",
      "id": "report--fd204b0f-fc39-4216-bf7f-988abedb0305",
      "created": "2026-09-24T12:22:07.000Z",
      "modified": "2026-09-24T12:22:07.000Z",
      "name": "September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs",
      "description": "For the latest discoveries in cyber research for the week of 21st Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Japan\u2019s Digital Agency, which operates the Government Solution Service used by multiple ministries, has confirmed a data breach after attackers exploited a vulnerability in a VPN appliance. Approximately 246,000 records were exposed, [\u2026] The post 21st September \u2013 Threat Intelligence Report appeared first on Check Point Research .",
      "published": "2026-09-24T12:21:50.000Z",
      "report_types": [
        "threat-report"
      ],
      "object_refs": [
        "attack-pattern--02cd3f7a-2ab7-4028-ab78-b73d79a44e69"
      ],
      "external_references": [
        {
          "source_name": "CrowdStrike Blog",
          "url": "https://www.crowdstrike.com/en-us/blog/patch-tuesday-analysis-september-2026",
          "description": "September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs"
        }
      ],
      "labels": []
    },
    {
      "type": "attack-pattern",
      "spec_version": "2.1",
      "id": "attack-pattern--02cd3f7a-2ab7-4028-ab78-b73d79a44e69",
      "created": "2026-09-24T12:22:07.000Z",
      "modified": "2026-09-24T12:22:07.000Z",
      "name": "Exploit Public-Facing Application",
      "external_references": [
        {
          "source_name": "mitre-attack",
          "external_id": "T1190",
          "url": "https://attack.mitre.org/techniques/T1190/"
        }
      ],
      "kill_chain_phases": [
        {
          "kill_chain_name": "mitre-attack",
          "phase_name": "initial-access"
        }
      ]
    }
  ]
}