Hello! Shemihaza here, your Sentinel. Let us look back over the week of 21 to 26 September 2026.
Online safety this week: four entry points, and what to do next
21 Sept: unexplained bills. 330,497 complaints from people aged 65 and over
Built on the National Consumer Affairs Center of Japan report published on 16 September 2026 covering consumer complaints from people aged 65 and over in fiscal 2025. There were 330,497 such complaints, 37.7% of all complaints received.
The point of the article was that "my parents do not use the internet, so they are fine" does not hold. The share of mail-order and online complaints is highest in the 65 to 69 bracket and falls as age rises — the generation that uses the internet is now entering the older age bands.
If a bill you do not recognise arrives, do not call the number printed on it. Calling tells the sender the line reaches a real person.
23 Sept: 19,207 account takeovers on trading sites, and one-time passwords did not stop them
Built on the Financial Services Agency figures updated on 9 September 2026: 19,207 unauthorised accesses and 10,639 unauthorised trades reported across online securities trading services.
What matters is that these went through even where one-time passwords were in use. If a fake site captures the code and relays it to the real site in real time, a code that works only once still works that once.
The fix is to move to a factor that phishing cannot capture. Switch to a passkey wherever it is offered, and make sure login notifications are on.
24 Sept: an AI-generated face on a video call, and special fraud losses up 51.7% overall
Built on the National Police Agency report on threats in cyberspace for the first half of 2026, published in September 2026. It records a case in which police arrested a suspect who generated a face with AI, made a video call and posed as a police officer (page 29 of the report). The report describes the case as cleared by police and the suspect arrested in August 2025 after extradition; it does not state a prosecution outcome.
Separately, losses from special fraud as a whole in the first half of 2026 came to about 181.62 billion yen, up 51.7% year on year, which the report calls the worst on record (page 15). That total covers the whole category, not this technique alone.
Quoting the report precisely, the AI was used so that the face of the suspect playing the officer could not be identified — generated to hide identity. A uniform-like outfit, a fake police ID held up to the camera and the AI-generated face were combined within a single call.
"I can see their face, so it is real" no longer works as a check. Every visual element can be arranged. Hang up, and call the police consultation line #9110 in Japan yourself to verify.
26 Sept: 12,516 reports judged to be criminal recruitment, and 50,213 police warning replies
From the same report. In the first half of 2026, 12,516 of the reports received by the Internet Hotline Center (IHC) were assessed as recruiting people to commit crimes, roughly 97% more than the same period a year earlier (page 32). Note that this counts reports the hotline received, not the internet as a whole. Police posted 50,213 individual warnings as replies to such posts, up 41% year on year (page 67).
That is exactly why you should read the replies before you apply — a police warning may already be sitting there.
The other point is sequence. The advert promises easy, well-paid work, and the actual job is revealed only after you apply and start exchanging messages (National Police Agency material from July 2023). If identification documents or your home address are requested first, stop there.
For engineers: this week’s security alerts
Three this week. All three were added by CISA to the Known Exploited Vulnerabilities catalogue, meaning exploitation was actually observed.
All three remediation deadlines have already passed as of this recap. If any of them is still outstanding, the task is no longer meeting a deadline but checking whether you were compromised.
Linux kernel CVE-2025-39682 (CVSS v3.1: 7.1 HIGH): three parties scored it differently
A flaw in the kernel TLS (kTLS) receive path. If you do not use kTLS it does not affect you — `/proc/net/tls_stat` shows whether it is in use.
The reason this one is worth recording is the disagreement over severity: NIST rated it 7.1 HIGH, kernel.org 9.8, and Red Hat 7.0. Do not pass the number along on its own — state whose score, on which CVSS version, and then decide against your own configuration. The CISA deadline was 21 September.
For the record, our 18 September piece covered only two of the three additions to KEV that day, so this article existed to close our own gap.
Zyxel GS1900 switches CVE-2026-7273 (CVSS v3.1: 8.8 HIGH): 996 units already breached
A stack-based buffer overflow. Zyxel shipped fixed firmware on 16 June 2026, yet the flaw was added to KEV on 21 September — which means devices went more than three months without the update.
996 units across 48 countries were actually breached, and 564 of those were still using the factory credentials. Updating the firmware is not the whole job; change the default password at the same time. Ten models are affected.
F5 BIG-IP APM CVE-2026-94127 (CVSS v3.1: 9.8 CRITICAL): scope depends on configuration
Unauthenticated remote code execution. Added to KEV on 22 September with a 25 September deadline.
A 9.8 score does not mean every box running BIG-IP APM is in scope. Only deployments configured as an OAuth authorisation server are affected; using it solely as an OAuth client is out of scope. When you take inventory, look at configuration rather than at whether the product is present. The affected and fixed versions are defined by F5’s own advisory, K000162605.
This week’s quiz: four questions
If you read this week’s articles you should spot all four. Try the first two with your family and the last two with colleagues.
📦This week’s articles
- Japan's police reply to criminal job ads: 12,516 recruitment posts in six months, up 97%, and 50,213 warning replies↗
- Deepfake fraud is not just voices any more: Japan's police report an AI-generated face used on a video call to impersonate an officer↗
- F5 BIG-IP APM CVE-2026-94127: unauthenticated RCE, but only on OAuth Authorization Server setups — CISA deadline 25 September↗
- Two-Step Verification Is Not Enough: 19,207 Brokerage Account Break-Ins↗
- Zyxel GS1900 CVE-2026-7273: Patch Now — 996 Switches Already Breached↗
- "My Parents Don't Use the Internet" Is the Wrong Assumption↗
- Linux Kernel CVE-2025-39682: Patch Now If You Use kTLS↗
Three lines to forward to your family
- ▸If a bill you do not recognise arrives, do not call the number printed on it. Calling tells the sender the line reaches a real person. In Japan, dial the consumer hotline 188 (no area code) yourself.
- ▸Seeing a face on a video call is not proof it is genuine. A fraudster who generated a face with AI and posed as a police officer has actually been arrested (National Police Agency, published September 2026). Hang up, then call the police consultation line #9110 in Japan yourself.
- ▸Before you apply to an "easy, well-paid" advert, read the replies underneath it. Police posted 50,213 warning replies in the first half of 2026. The real job is revealed only after you apply, so if you are asked for ID or your home address first, stop there.
Where to get help
If you realise something has gone wrong, working through it calmly and in order is enough. There is nothing to be ashamed of.
Paid money, or stuck with a bill — consumer hotline 188 (no area code; Japan only)
Possible fraud or crime, and unsure who to ask — police consultation line #9110 (Japan only)
Account taken over, or you opened something suspicious — the emergency guide linked below has step-by-step instructions by symptom.
Readers outside Japan should use their own national consumer and police reporting lines; the two numbers above reach Japanese services only.
- Emergency guides by symptom (this site; six situations)↗
- National Police Agency: police consultation line #9110 (list of prefectural contacts)↗
- National Consumer Affairs Center: consumer affairs centres nationwide (hotline 188)↗
- National Police Agency: where to report cyber incidents↗
- National Consumer Affairs Center: fiscal 2025 complaints from people aged 65 and over (published 16 September 2026; 330,497 and 37.7%)↗
- National Consumer Affairs Center: bogus billing for services you never used↗
- Financial Services Agency: unauthorised access and trading on online trading services↗
- Financial Services Agency: incident figures (PDF, updated 9 September 2026; 19,207 and 10,639)↗
- National Police Agency: threats in cyberspace, first half of 2026 (announcement page)↗
- National Police Agency: full report PDF (page 15 total special-fraud losses, page 29 the AI impersonation case, page 32 the 12,516 IHC-received reports judged to be criminal-recruitment information, page 67 the 50,213 warnings)↗
- National Police Agency: how criminal recruiters operate (July 2023)↗
- NVD: CVE-2025-39682 (NIST 7.1 HIGH)↗
- NVD: CVE-2026-7273 (8.8 HIGH)↗
- NVD: CVE-2026-94127 (9.8 CRITICAL)↗
- F5 advisory K000162605 (authoritative affected and fixed versions)↗
- CISA: Known Exploited Vulnerabilities catalogue (KEV)↗
