🚨 CISA KEV 1[−]
8 Sep KEVStyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-dayA critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available. Key takeaways CVE-2026-75650 is …TENABLE.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 11[−]
8 SepAdobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web ShellAdobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler…THEHACKERNEWS.COM
8 SepAdobe Commerce max-severity bug comes under active attackOnline stores running Adobe Commerce and Magento Open Source have been hit by a max-severity, zero-day bug that lets unauthenticated attackers execute code on vulnerable servers. Security firm Sansec is calling the flaw StyleSmuggler because of the way attackers abused Magento’s …CSOONLINE.COM
8 SepCVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)Overview While conducting research into a recent N-able N-central authentication bypass vulnerability ( CVE-2026-18577 ), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unau…RAPID7.COM
8 Sep KEVAdobe fixes critical Magento zero-day exploited to backdoor serversAdobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]BLEEPINGCOMPUTER.COM
8 SepVU#859658: Skullcandy Dime 3 wireless earbuds contain an unauthenticated Bluetooth pairing vulnerabilityOverview Skullcandy Dime 3 wireless earbuds, running firmware version 1.0.0.28, accept a new Bluetooth Classic (BR/EDR) pairing request from an unpaired device without requiring the earbuds to be placed into pairing mode or requiring any physical confirmation or interaction from …KB.CERT.ORG
8 SepVU#943094: ONLYOFFICE ownCloud integration plugin contains a Server-Side Request Forgery (SSRF) vulnerabilityOverview A Server-Side Request Forgery (SSRF) vulnerability exists in Ascensio System SIA's ONLYOFFICE ownCloud integration plugin (version 9.12). The plugin’s backend endpoint does not adequately validate the user‑supplied document server URL before initiating outbound connectio…KB.CERT.ORG
8 SepCVE-2026-50696 Internet Key Exchange (IKE) Protocol Denial of Service VulnerabilityAcknowledgement UpdatedMSRC.MICROSOFT.COM
8 Sep KEVMicrosoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)104 Critical 860 Important 0 Moderate 0 Low Microsoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild. Microsoft patched a record 964 CVEs in its September 202…TENABLE.COM
8 SepAdobe Patches Over 170 Vulnerabilities, Including Commerce Zero-DayTracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code. The post Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
8 Sep KEVMicrosoft releases Windows security update addressing 723 flawsMicrosoft has released its September 2026 security updates, fixing two Windows elevation-of-privilege vulnerabilities that attackers are already exploiting in the wild. The company’s broader Patch Tuesday release addresses 974 CVEs across its products, including 723 affecting Win…CYBERINSIDER.COM
8 Sep KEVPatch Tuesday - September 2026Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday , including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the…RAPID7.COM
⚠️ VULNERABILITY DISCLOSURE 41[−]
8 SepProduct showcase: Doppler secures secrets for humans, pipelines, and AI agentsEvery engineering team has spent years trying to keep credentials out of source code. Then AI agents moved the problem. Coding agents review code, agents run workflows, and MCP servers broker access to databases, cloud providers, and internal APIs on a developer’s behalf. For eve…HELPNETSECURITY.COM
8 SepSecurity leaders must prepare for likely threats, not sensationalized agentic attacksA malicious dataset exploits code-execution paths in a remote-code dataset loader and a dataset configuration before compromising access credentials to move laterally through the target network. A frontier AI model publishes a malicious Python package to a public PyPI registry af…CSOONLINE.COM
8 SepSecuring AI agents: Key controls and best practicesEnterprises increasingly give AI agents the credentials, tools, and network access of privileged employees, but security experts warn that existing security controls designed to govern human access are insufficient. An AI agent operates at inhuman speed, can chain allowed actions…CSOONLINE.COM
8 SepMathspace breach exposes data on over a million students and parentsMathspace has confirmed that attackers broke into its internal reporting system through an unpatched Metabase vulnerability and stole data belonging to more than a million students, parents, and school staff. The Sydney-based maths education company wrote in a blog post that the …HELPNETSECURITY.COM
8 SepBengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support ScamsCybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has op…THEHACKERNEWS.COM
8 SepSecurity Conversations on AI, Agents, and Emerging Threats from Black Hat 2026 - ASW #399We showcase recordings from this year's Black Hat. The Hidden Risks of the AI Supply Chain - Black Hat interview with Michael Leland, VP and Field CTO of Island Agents can independently discover and install tools, but the emerging ecosystem of Skills and MCP servers lacks many of…YOUTUBE.COM
8 SepStealing AI Reasoning TracesInteresting research: “ Stealing Reasoning Traces from Proprietary LLM APIs “: Abstract: Leading large language model providers now conceal their models’ step-by-step reasoning, or chain-of-thought, to protect intellectual property and limit information leakage.…SCHNEIER.COM
8 SepBigBear 2.0 phishing campaign hijacks Microsoft 365 sessions after MFAA phishing-as-a-service operation targeting Microsoft 365 users has harvested thousands of session cookies that could be used to hijack authenticated sessions after victims complete multifactor authentication, CloudSEK said. The cybersecurity firm said in a report that it uncover…CSOONLINE.COM
8 SepMikroTik router flaws allow takeover without a passwordAttackers are exploiting critical RouterOS flaws to take control of routers with SSH exposed to the internet.MALWAREBYTES.COM
8 Sep25 Years After 9/11: The CIA's First Moments Behind Enemy Lines in AfghanistanRetired Colonel Justin Sapp was a Green Beret detailed to the CIA after the September 11th terrorist attacks. He was part of Team Alpha, the first eight Americans to drop behind enemy lines into the mountains of Afghanistan. At 29, Justin was its youngest member. There was no tim…THECYBERWIRE.COM
8 SepN-able Patches Critical Zero-Day in N-centralAdministrators are advised to check their deployments for newly created user accounts they don’t recognize. The post N-able Patches Critical Zero-Day in N-central appeared first on SecurityWeek .SECURITYWEEK.COM
8 SepNorth Korea-linked Hackers Hide a Backdoor Inside HAProxyNorth Korea-linked hackers hid a backdoor inside HAProxy, masking C2 traffic and stealing data while keeping the load balancer working normally. North Korean-linked hackers found a genuinely clever hiding spot for their malware: inside the actual source code of HAProxy, the load …SECURITYAFFAIRS.COM
8 SepParty’s over for scammers who went on spending spree after $240M bitcoin theftMichael Kunzelman of the AP reports: They pulled off one of the largest cryptocurrency thefts in U.S. history, duping a stranger out of bitcoin worth over $240 million. They tried to hide their digital fingerprints, carrying out a sophisticated scheme to launder the proceeds. And…DATABREACHES.NET
8 SepThreat actors are giving AI agents a bigger role in cyberattacksAI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker. (Source: Google) The report draws on Mandiant incid…HELPNETSECURITY.COM
8 SepMars Security brings threat intelligence to detection in real timeMars Security has announced Real-Time Intel-Based Detection, a capability that turns newly published threat intelligence into validated, ready-to-deploy detection rules within minutes of release. Built by former offensive operators, the new capability converts advisories from CIS…HELPNETSECURITY.COM
8 Sep“Zero-click” WeChat worm could hijack accounts and spread via a single callResearchers with security company Calif have discovered, weaponized, and privately reported to Tencent a critical vulnerability that allowed them to create “WeWorm”, a worm that spreads via WeChat calls without any user interaction. During its rampage, the WeWorm comp…HELPNETSECURITY.COM
8 SepEverett, Massachusetts, closes City Hall after cybersecurity incidentDysruptionHub reports: Everett, Massachusetts, closed City Hall to the public Tuesday after a cybersecurity incident affected its internal network and technology systems, shifting most essential employees to another municipal building. The city said in a Monday announcement that …DATABREACHES.NET
8 SepSAP warns of maximum severity 'OVERPASS' kernel vulnerabilitySAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. [...]BLEEPINGCOMPUTER.COM
8 SepOpenAI says GPT-6 Astra can find zero-days, but is also harder to monitorOpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the "Critical level" for cybersecurity capabilities. [...]BLEEPINGCOMPUTER.COM
8 SepSAP Patches Critical Extended Passport Processing VulnerabilityAffecting the SAP kernel code, the flaw allows unauthenticated, remote attackers to run arbitrary commands, recover secrets, and modify data. The post SAP Patches Critical Extended Passport Processing Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
8 SepThe US military just turned off ad tracking on its phones. Maybe you should tooLocation data sold by the ad industry has reportedly helped adversaries target US troops. The Pentagon has responded by switching off ad tracking on its devices - and you can do the same on yours. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
8 SepMars Security Debuts Automated Threat Engine Processing Live Cyber Intelligence Into Validated Rules Within MinutesMars Security , an autonomous threat hunting and detection engineering platform founded by offensive cybersecurity veterans, today announced Real-Time Intel-Based Detection. The milestone expansion equips enterprise security operations centers (SOCs) to convert newly published th…CSOONLINE.COM
8 SepVU#718077: UEFI Shell module embedded in SPI Flash can be used to bypass Secure BootOverview The UEFI Shell program may expose raw memory access capabilities that, if present in platform firmware for debugging or advanced support use cases, could be abused to undermine UEFI Secure Boot protections. When the UEFI Shell is included in SPI flash, an attacker with t…KB.CERT.ORG
8 SepN-able issues patch for zero-day flawSecurity researchers warned the company of unusual threat activity in a recently patched N-able environment.CYBERSECURITYDIVE.COM
8 SepZero-click worm spreads on iPhones and Android via WeChat callsA zero-click worm can spread between iPhones and Android devices through WeChat calls, allowing attackers to hijack accounts even without victims answering. Dubbed WeWorm, the proof-of-concept attack exploits a memory corruption vulnerability in WeChat’s Voice-over-IP (VoIP) stac…CYBERINSIDER.COM
8 SepCISA tells operators to harden Siemens S7 PLCs. Here’s how to do it without disrupting productionOn a conventional server, disabling an unused service is usually a routine hardening task. On a Siemens S7 controller, the supposedly unused service may carry remote I/O traffic, supply process values to an HMI or provide the maintenance team’s only path to diagnostics. Close it …CSOONLINE.COM
8 SepClaude Mythos 5 is coming to Tenable One, powering the new “Adversary View”Tenable is bringing Anthropic’s Claude Mythos 5 into our enterprise security offerings. Adding frontier adversarial reasoning to the Tenable One Exposure Management Platform will help customers better anticipate how attackers could breach their environments and stay ahead of AI-f…TENABLE.COM
8 Sep KEVMicrosoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-daysToday is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. [...]BLEEPINGCOMPUTER.COM
8 SepSingaporean Ringleader of $245 Million Cryptocurrency Racketeering Enterprise Pleads Guilty in Washington D.C.WASHINGTON – Malone Lam, 22, a citizen of Singapore and recent resident of Miami, pleaded guilty today in U.S. District Court in Washington D.C. in connection with his role as ringleader of an international cybercrime conspiracy that used social engineering to steal and launder c…DATABREACHES.NET
8 Sep KEVSeptember 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while …ISC.SANS.EDU
8 SepMicrosoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-DaysThe record-breaking September security update fixes two exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities. The post Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek .SECURITYWEEK.COM
8 SepWeChat Worm Can Hijack Accounts Without Victims Answering CallsResearchers built a WeChat worm that spreads through incoming calls without user action. Tencent has blocked the exploit. Researchers at Calif created a WeChat worm that can take over an account through an incoming call, even if the victim never answers or touches the phone. The …SECURITYAFFAIRS.COM
8 SepWorming its way through WeChat.Researchers build a self-propagating attack against WeChat. Threat actors move toward multi-agent AI frameworks. N-able issues an emergency patch for a maximum-severity bug under active exploitation. MikroTik patches multiple RouterOS vulnerabilities. China accesses restricted Am…THECYBERWIRE.COM
8 SepScammer behind $245 million crypto heist pleads guilty to RICO chargesMalone Lam was indicted on scamming charges in September 2024 after drawing law enforcement scrutiny for parlaying stolen crypto into lavish Hamptons vacations, cars and private jets.THERECORD.MEDIA
8 Sep KEVThe EU CRA's Real Question: What Shipped, and When Did You Know?The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be cr…BLEEPINGCOMPUTER.COM
8 SepHackers breach F5 BIG-IP APM devices to deploy Linux rootkitA Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. [...]BLEEPINGCOMPUTER.COM
8 SepSurvival of the Basics: Which Security Fundamentals Were Secretly Relying on Lazy Attackers?A few weeks ago I asked on X and LinkedIn a deceptively simple question: which “security basics” matter more against AI-armed attackers, and which ones don’t matter anymore? What Gemini think of this blog [before you freak out about ‘…but Anton, we don’t even have a consensus def…MEDIUM.COM
8 SepPatch Tuesday Sets Another Record With 974 CVEsAttackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.DARKREADING.COM
8 SepHow Fast Can You Repair AI?A vulnerability in an AI-powered system can turn from a technical problem into an operational problem once the system controls real-world actions. Patching matters, but resilience also means being able to respond quickly when automated systems behave unexpectedly. The consequence…YOUTUBE.COM
8 SepMicrosoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploitedThe new record total for Patch Tuesday is 973 vulnerabilities.THERECORD.MEDIA
8 Sep KEVMicrosoft discloses two actively exploited zero-days among 974 vulnerabilitiesWhile the vendor hit another monthly record, it hasn’t resulted in a flood of active exploits. Researchers encourage customers to focus on their specific areas of risk and exposure. The post Microsoft discloses two actively exploited zero-days among 974 vulnerabilities appeared f…CYBERSCOOP.COM
📋 SECURITY BULLETINS 3[−]
8 SepAugust updates trigger 0xc0000409 errors on Windows Server 2016Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled. [...]BLEEPINGCOMPUTER.COM
8 SepMicrosoft releases Windows 10 KB5122878 extended security updateMicrosoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes. [...]BLEEPINGCOMPUTER.COM
8 SepMicrosoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilitiesMicrosoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."TALOSINTELLIGENCE.COM
📢 SECURITY ADVISORIES 20[−]
8 SepCybersecurity jobs available right now: September 8, 2026CISO AudioCodes | Israel | Hybrid – View job details As a CISO, you will lead security strategy, governance, and risk management across SaaS, managed services, and customer-hosted environments. You will oversee security controls, incident response, Secure SDLC, cu…HELPNETSECURITY.COM
8 SepJellyfin 12.0 security fixes arrive alongside the removal of legacy client loginsJellyfin shipped version 12.0 of its media server. Several of the security fixes in it block requests built to reach files outside the folders the server is supposed to hand out. The rest of the security work touches first-run setup, plugin installs, parental controls, and the we…HELPNETSECURITY.COM
8 SepIT Help Desk Impersonation Lets Hackers Bypass MFAAttackers bypass endpoint security by posing as IT staff, stealing Microsoft 365 sessions, draining SaaS data and demanding extortion. Forget installing malware because today’s extortionists just pick up the phone instead of writing code. A widespread threat cluster tracked as PR…SECURITYAFFAIRS.COM
8 SepFreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator CredentialsA flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities i…THEHACKERNEWS.COM
8 SepFrance Establishes New Government-Focused Cyber Incident Response UnitAfter a major cyber-attack targeted France's national tax authority, the Prime Minister called for the establishment of a new dedicated cyber incident response capabilityINFOSECURITY-MAGAZINE.COM
8 SepFeds accuse China of ‘systematic’ distillation of U.S. AI modelsA joint advisory alleges Chinese companies are using sophisticated systems to route millions of data requests to US AI models across different accounts and platforms. The post Feds accuse China of ‘systematic’ distillation of U.S. AI models appeared first on CyberScoop .CYBERSCOOP.COM
🔥 INCIDENT REPORTING 13[−]
8 SepRansomware negotiation tactics have turned into a business processIn this Help Net Security video, Dave Ross, Senior Director of the Intelligence Fusion Team at Intel 471, explains what happens behind the scenes during ransomware negotiations. Ross walks through the tactics groups use once an attack begins, from research on a victim’s rev…HELPNETSECURITY.COM
8 Sep220 million traveler records exposed in Vietnam-linked APIS leakExclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing names, passport numbers, dates of birth, nationalities, and flight details spanning 2017 to 2026. Researchers accessed the Vietnam-linked system throu…BLEEPINGCOMPUTER.COM
8 SepTrezor Supply Chain Breach Now Impacts 81,000 CustomersCrypto wallet-maker Trezor says a data breach at supplier ShipMonk is far worse than originally thoughtINFOSECURITY-MAGAZINE.COM
8 SepMathspace Data Breach Exposes Over 1 Million PeopleHackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance. The post Mathspace Data Breach Exposes Over 1 Million People appeared first on SecurityWeek .SECURITYWEEK.COM
8 SepTrezor customers hit with phishing calls and letters after shipping-partner breachRoughly 67,000 more customers of SatoshiLabs, the maker of hardware crypto-wallet Trezor, are at heightened risk of phishing attacks after their names, email addresses, phone numbers, and shipping addresses were exposed. “The leaked information could be used for scam emails…HELPNETSECURITY.COM
8 SepFrench prosecutors confirm arrest of suspected ZeroBytes hacker behind tax cyberattackFrench authorities detained an 18-year-old suspected member of the ZeroBytes hacking group over cyberattacks against the country's tax authority and other organizations.THERECORD.MEDIA
8 SepCyberattack encrypts systems at Bavarian municipal utilityA municipal utility in Bavaria is recovering from a cyberattack that encrypted its internal IT systems but did not affect water and electricity services.THERECORD.MEDIA
8 SepShinyHunters claims breach of Florida DMV, threatens data leakThe ShinyHunters cybercrime group claims it compromised systems containing driver and vehicle records and is threatening to release stolen data on September 11. As purported evidence, the group posted a screenshot showing what appears to be a record from DAVID, Florida’s Driver a…CYBERINSIDER.COM
8 SepWebinar: The forgotten Google Workspace access that can lead to a breachThird-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches and which security controls can help fast-growing companies reduce their exposu…BLEEPINGCOMPUTER.COM
8 SepShinyHunters hackers claim breach of Florida "DAVID" DMV databaseThe ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state. [...]BLEEPINGCOMPUTER.COM
8 SepOpenAI says ChatGPT outage causes image generation errorsOpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays when uploading files. [...]BLEEPINGCOMPUTER.COM
8 SepAIs as Modern GeniesThis essay was written with Barath Raghavan, and originally appeared in Lawfare . In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its backups.…SCHNEIER.COM
8 SepOpenAI Agents Took Over Wiki Site Before Hugging Face AttackResearchers and OpenAI disagree on whether the earlier incident involving DseWiki was a “hack” that the company did not disclose.DARKREADING.COM
🕵️ THREAT INTELLIGENCE 26[−]
8 SepISC Stormcast For Tuesday, September 8th, 2026 https://isc.sans.edu/podcastdetail/10084, (Tue, Sep 8th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
8 SepMicrosoft’s Project Zenith puts large AI models directly on developer PCsMicrosoft’s Project Zenith is a ready-to-code Windows 11 experience for developer-class PCs capable of running AI models with more than 30 billion parameters locally without relying on metered cloud tokens. Designed for systems with at least 64 GB of unified memory and 250 GB/s o…HELPNETSECURITY.COM
8 SepEssential AI agent security questionsAI agents are outpacing legacy IAM. Discover the 3 questions every CISO must ask to secure them.CYBERSECURITYDIVE.COM
8 SepIn most cities, nobody owns the whole networkJuly’s intrusions reached water controllers that sat on a cellular link no city network scan would find. Naming an owner and paying for the fix are decisions a utility can make this fiscal year, out of money it already applies for. The post In most cities, nobody owns the whole n…CYBERSCOOP.COM
8 SepAI Coding Tools Now a Prime Target for Threat Actors, Google WarnsGoogle warned that the rapid integration of AI-assisted coding tools has significantly expanded software supply chain risksINFOSECURITY-MAGAZINE.COM
8 SepGoogle warns hackers are deploying AI agents in autonomous attacksCybercriminals and state-backed hackers are moving beyond using AI as a coding or research assistant and are instead building agentic systems that can autonomously scan targets, troubleshoot failures, and harvest credentials. Google Threat Intelligence Group (GTIG) says one finan…CYBERINSIDER.COM
8 SepHackers build AI frameworks for widescale credential theftThreat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. [...]BLEEPINGCOMPUTER.COM
8 SepMikroTik Patches Critical Flaws Chained to Hack RoutersDubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices. The post MikroTik Patches Critical Flaws Chained to Hack Routers appeared first on SecurityWeek .SECURITYWEEK.COM
8 SepIT help-desk vishing tricks executives into handing over Microsoft 365 accessIT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are behind a wave of data theft and extortion against Microsoft 365 and other SaaS accounts, according to Arctic Wolf. The company is tracking the activity under the name PREY-0058 …HELPNETSECURITY.COM
8 SepThe Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPTResearch by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, AI assistants have moved far beyond text generation. Modern systems can execute code, install additional dependencies, analyze user files, and access data through connected services. These capab…RESEARCH.CHECKPOINT.COM
8 SepParty’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin TheftThe scammers purchased fleets of sports cars, flew on private jets, hired security guards and rented mansions in Miami and the Hamptons. The post Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft appeared first on SecurityWeek .SECURITYWEEK.COM
8 SepReflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conventional PentestsSpecialized team of AI agents that discover, attack, and validate web vulnerabilities, leveraging pre-existing site context to eliminate noise and speed remediation. Reflectiz, the continuous web exposure management company, today launched a multi-agent penetration testing platfo…CSOONLINE.COM
8 SepAutonomous AI Agents Compromise Thousands of Credentials in Under Six HoursThreat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Goo…THEHACKERNEWS.COM
8 SepThreat actors move toward multi-agent AI frameworks.N-able issues emergency fix for maximum-severity flaw. Stealthy DPRK toolkit targets South Korean organizations.THECYBERWIRE.COM
8 SepDon’t let AI distract from cybersecurity basics, officials and executives warnSimple attacks remain far more consequential than anything AI is doing, government and industry leaders said.CYBERSECURITYDIVE.COM
8 SepCylake Raises $245 Million Ahead of Cybersecurity Platform BetaThe startup founded by Palo Alto Networks’ Nir Zuk has raised $290 million to build an AI-native security platform for highly regulated organizations that cannot rely on the public cloud. The post Cylake Raises $245 Million Ahead of Cybersecurity Platform Beta appeared first on S…SECURITYWEEK.COM
8 SepSlim Spider Steals Crypto Custody Secrets From Brazilian Financial InstitutionA previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary…THEHACKERNEWS.COM
8 SepThe Hidden Instructions That Can Hijack AI AgentsMalicious prompts concealed in documents, metadata, emails, images and code can manipulate autonomous agents into taking dangerous actions. The post The Hidden Instructions That Can Hijack AI Agents appeared first on SecurityWeek .SECURITYWEEK.COM
8 SepHackers Return $263 Million Stolen From Liquid NetworkAlleged ‘white-hat’ hackers drained $320 million from Liquid’s federation wallet, demanding a bug fix. The post Hackers Return $263 Million Stolen From Liquid Network appeared first on SecurityWeek .SECURITYWEEK.COM
8 SepClickFix Campaigns Abuse Legitimate Services for Persistent AccessTwo separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.DARKREADING.COM
8 SepWhy federal cyber defense demands an offense-driven mindsetStatic checklists and annual penetration tests leave agencies with dangerous blind spots. True resilience requires moving from reactive attestation to continuous, automated validation. The post Why federal cyber defense demands an offense-driven mindset appeared first on CyberSco…CYBERSCOOP.COM
8 SepCIA official touts agency’s Cyber Mission Center in capture of Venezuela’s MaduroA "flawless" performance by the CIA's Cyber Mission Center contributed to the capture of Venezuelan President Nicolás Maduro in January, agency Deputy Director Michael Ellis says.THERECORD.MEDIA
8 SepCIA’s Michael Ellis says cyber intelligence is changing how the agency operatesThe deputy director cited Operation Absolute Resolve as evidence that cyber teams have become central to CIA missions. The post CIA’s Michael Ellis says cyber intelligence is changing how the agency operates appeared first on CyberScoop .CYBERSCOOP.COM
8 SepRussian national extradited to US for alleged involvement in bank-account takeover schemeAuthorities accuse the 36-year-old and co-conspirators of collecting more than 5,000 victim login credentials to various banks. The post Russian national extradited to US for alleged involvement in bank-account takeover scheme appeared first on CyberScoop .CYBERSCOOP.COM
8 SepCybercabs, Robohobos, BigBear, Nightmare Eclipse, weChat, Flock, ASCII, Aaran Leyland - SWN #614Cybercabs, Robohobos, BigBear, Nightmare Eclipse, weChat, Flock, ASCII, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-614YOUTUBE.COM
8 SepAttackers Use Multi-Hop Google Redirects for Phishing CampaignThreat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.DARKREADING.COM
🌐 CYBER THREAT LANDSCAPE 2[−]
8 SepBetween Two Nerds: Can AI defend critical infrastructure?In this edition of Between Two Nerds Tom Uren and The Grugq talk about whether AI will help cyber defence in critical infrastructure and organisations that are below the cyber poverty line. This episode is also available on YouTube.RISKY.BIZ
8 SepHackers gonna hack back.Welcome in! You’ve entered, Only Malware in the Building. Join us each month to sip tea and solve mysteries about today’s most interesting threats. Your host is Selena Larson, Proofpoint intelligence analyst and host of thei…THECYBERWIRE.COM
🎙️ PODCASTS 1[−]
8 SepInside the Media Mind of Ken Underhill: eSecurity PlanetOn this episode of #IMM, Christine and Madison chat with Ken Underhill to learn more about his role and coverage at eSecurity PlanetTHECYBERWIRE.COM
📡 INFOSEC NEWS 27[−]
8 SepGrindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data SharingOnline dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with third-parties. Grindr, which is the largest LGBTQ+ dating app, was sued in April 202…THEHACKERNEWS.COM
8 SepProofpoint Strengthens Executive Leadership Team with Appointment of Chief Legal Officer and Chief People OfficerPROOFPOINT.COM
8 SepBigBear 2 PhaaS Campaign Steals 5000+ Microsoft CredentialsCloudSEK has uncovered BigBear 2.0, a new phishing-as-a-service operation targeting Microsoft 365INFOSECURITY-MAGAZINE.COM
8 SepClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport ManagerWe assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.TALOSINTELLIGENCE.COM
8 SepClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session.TALOSINTELLIGENCE.COM
8 SepTHost9 Android RAT Pairs Packed Loader With ADB WormTHost9 hides its payload and uses ADB to spread across exposed Android devices and containersINFOSECURITY-MAGAZINE.COM
8 SepMicrosoft: Windows Server 2025 changes causing app crashesMicrosoft warned customers last week that they may experience application crashes on some Windows Server 2025 due to recent memory management changes. [...]BLEEPINGCOMPUTER.COM
8 SepMassive Vietnam-Linked APIS Database Exposes Passport and Flight DataAn exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data. Researchers found an exposed Advance Passenger Information System (APIS) database containing 220.8 million passenger and crew records from January 2017 …SECURITYAFFAIRS.COM
8 SepMeta Failed to Catch Hundreds of AI Child Abuse Ads. Some Included Images of Real KidsImages of real children—including a member of a European royal family—were used to create some of the 350 ads containing child sexual abuse. Lawmakers say they plan to investigate.WIRED.COM
8 SepGrindr Settles UK Data Privacy Claims for £26mGrindr settled UK claims over alleged unlawful processing of sensitive user dataINFOSECURITY-MAGAZINE.COM
8 SepWeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming CallsResearchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must…THEHACKERNEWS.COM
8 SepWhat It Took to Reach 1 Billion Build ManifestsIn the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually …THEHACKERNEWS.COM
8 SepGrindr settles HIV status data-sharing lawsuit for $35 millionGrindr has settled a UK lawsuit alleging that it shared sensitive user data, including HIV status, with advertising companies.MALWAREBYTES.COM
8 SepA hacker stole $340M in a crypto heist, then returned most of itThe latest heist is one of the largest thefts of cryptocurrency to date.TECHCRUNCH.COM
8 SepWhere the backlash against Flock Safety is having the biggest impactTwo populous states and two large cities are among the U.S. jurisdictions where leaders have taken direct action to address criticisms of automated license plate readers (ALPRs).THERECORD.MEDIA
8 SepLiquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTCWhoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds real bitcoin to back a token called L-BTC.…THEHACKERNEWS.COM
8 SepChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another AccountCheck Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read d…THEHACKERNEWS.COM
8 SepChrome is now shipping updates every 2 weeks as AI changes the security landscapeGoogle is speeding up Chrome’s release schedule to ship security patches and new features faster.TECHCRUNCH.COM
8 Sep‘White hat’ hackers take $47 million bounty after $320 million crypto theftPublic negotiations between hackers and the operators of the Liquid Network crypto platform ended with the attackers sending back most — but not all — of what they took.THERECORD.MEDIA
8 SepWindows 11 cumulative updates KB5124008 & KB5122880 releasedMicrosoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]BLEEPINGCOMPUTER.COM
8 SepRussian suspect in bank account takeovers is extradited to USA Russian web developer who played a role in a multimillion-dollar bank account takeover scheme has been extradited to the U.S. to face an indictment.THERECORD.MEDIA
8 SepItalian tech collective Autistici/Inventati shuts down after US terrorist designationOn August 26, the State Department labeled A/I an “extremist group” operating infrastructure for “far-left militants across the world” and announced that anyone engaging with the group financially risked exposure to sanctions.THERECORD.MEDIA
8 SepMuse, Meta's New Personal AI Agent, Needs You to Trust ItDesigned to compete with OpenClaw and Instinct, the company says Muse can do everything from sell your car to book you a plane ticket.WIRED.COM
8 SepDoppelCart fraud network uses 119,000 fake shops to steal credit cardsA massive operation dubbed "DoppelCart" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details. [...]BLEEPINGCOMPUTER.COM
8 SepMicrosoft Plugs Nearly 1,000 Security HolesMicrosoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security expe…KREBSONSECURITY.COM
8 SepHackers Drain $320 Million From Liquid Network, Then Return Most of ItCrypto exchange network Liquid Network lost $320 million overnight, then got most of it back after the hackers demanded a bug fix instead of a ransom Bitcoin’s Liquid Network, a sidechain built by Blockstream and used by dozens of exchanges to move funds faster and more pri…SECURITYAFFAIRS.COM
8 SepMicrosoft adds age-awareness APIs that can tell if users are children, teens, or adultsMicrosoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. [...]BLEEPINGCOMPUTER.COM