141Articles
8Categories
2026-09-09Date
🐛 COMMON VULNERABILITIES AND EXPOSURES 13[−]
9 Sep KEVCisco bundles fixes for multiple vulnerabilities, some critical, into one patchCisco is looking to get ahead of attackers with a new set of more than a half-dozen fixes, some of them critical, for its IOS XR Linux-based network operating system (OS). As part of its regular testing, Cisco’s software engineering team flagged “multiple internally-discovered vu…CSOONLINE.COM
9 Sep KEVSeptember 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in WindowsPossibly wormable bugs and two zero-day holes highlight the almost 1,000 fixes issued today by Microsoft in its September Patch Tuesday release . The 964 vulnerabilities, another record since Microsoft began using AI in the middle of the year to find holes, require customer actio…CSOONLINE.COM
9 Sep KEVN-able N-central Pre-Auth RCE Flaw Exploited in the WildThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by Se…THEHACKERNEWS.COM
9 Sep KEVGoogle fixes second actively exploited Chrome zero-day in under five daysGoogle has released Chrome 153 to the stable channel with fixes for 230 security vulnerabilities, including a V8 memory corruption flaw that Google says is already being exploited in attacks. The actively exploited vulnerability is tracked as CVE-2026-87491 and is described as an…CYBERINSIDER.COM
9 Sep KEVGoogle fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit. “Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the company said in a Tuesday security advisory. The fix has been shipped i…HELPNETSECURITY.COM
9 Sep KEVChrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside SandboxGoogle on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bu…THEHACKERNEWS.COM
9 SepResearcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be BypassedThe security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which th…THEHACKERNEWS.COM
9 SepSAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code ExecutionSAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as …THEHACKERNEWS.COM
9 SepSeptember 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successorSeptember 2026 Patch Tuesday is here, with Microsoft delivering another record-breaking number of patches, including those for two vulnerabilities that have been exploited as zero-days. Another “new normal” is the anonymous security researcher Nightmare Eclipse publis…HELPNETSECURITY.COM
9 Sep KEVGoogle fixes the seventh actively exploited Chrome zero-day of 2026Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page. Google released a Chrome update fixing 230 security vulnerabilities, including one already exploited in the wild tracked as CVE-2026-87…SECURITYAFFAIRS.COM
9 SepChromium: CVE-2026-85046 Type confusion in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Google is aware that an exploit for CVE-2026-85046 exists i…MSRC.MICROSOFT.COM
9 SepMikroTik patches flaws currently being exploited to take over routersNetworking gear manufacturer MikroTik has released patches for six vulnerabilities in its RouterOS firmware, two of which can be chained together to take over devices without authentication over SSH. The exploit chain, dubbed MikroTrick, is already being used by attackers in the …CSOONLINE.COM
9 Sep KEVCisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacksCisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...]BLEEPINGCOMPUTER.COM
⚠️ VULNERABILITY DISCLOSURE 47[−]
9 Sep KEVMicrosoft patches record 966 flaws, Cybercriminals return $265 million in BitcoinMicrosoft's Record 966-Fix Patch Tuesday, Liquid Network Bitcoin Returned (Mostly), and Five Eyes' Back-to-Basics Warning Cybersecurity Today host David Shipley reports Microsoft's largest Patch Tuesday ever with 966 vulnerability fixes (plus 204 earlier cloud-service fixes), inc…CYBERSECURITYTODAY.LIBSYN.COM
9 SepBleachBit 6.0.4 fixes secure wiping that skipped clusters on WindowsThe open source cleaner BleachBit reached version 6.0.4 this week, erasing caches, browser traces, and files on Windows, Linux, and now macOS. If you shredded a sensitive file on Windows with an earlier build, parts of it may still sit on the disk where the wipe missed. Fragmenta…HELPNETSECURITY.COM
9 SepAI-Infra-Guard: Open-source security scanner for AI systemsTencent’s Zhuque Lab built AI-Infra-Guard, an open-source security scanner for AI systems. It fingerprints running services such as Ollama, vLLM and ComfyUI and checks them against more than 1,600 known CVEs, inspects MCP servers and agent skills across 14 categories of ris…HELPNETSECURITY.COM
9 Sep KEVMicrosoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-DaysMicrosoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62…THEHACKERNEWS.COM
9 Sep KEVGoogle warns of new Chrome zero-day bug exploited in attacksGoogle has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...]BLEEPINGCOMPUTER.COM
9 SepNew Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM accessAn anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]BLEEPINGCOMPUTER.COM
9 SepMicrosoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable BugsSeptember 2026 Patch Tuesday fixes a record 974 CVEs including 2 exploited zero-days, 20 wormable bugs, and a critical Exchange RCE via Visio email. Microsoft’s September 2026 Patch Tuesday set a new record. Depending on how researchers count external and Chromium bugs, Microsoft…SECURITYAFFAIRS.COM
9 Sep50% of CISOs see Mythos as a sign to exit the professionCISOs already have it tough, but the straw that breaks the back of many IT security executives may be the rapidly advancing capabilities of frontier AI models, enterprise insistence on rapid and widespread AI experimentation, and the compounding risk responsibilities and personal…CSOONLINE.COM
9 SepSAP Patches Maximum Severity “Overpass” FlawOnapsis urges SAP customers to patch “Overpass” vulnerability, which has a CVSS score of 10.0INFOSECURITY-MAGAZINE.COM
9 SepChaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-DayThe researcher Chaotic Eclipse released ShieldCrash, a PoC exploit for a Microsoft Defender Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defend…SECURITYAFFAIRS.COM
9 SepWhen the prompt becomes the payload: A practical pen-testing guide for GenAI, LLM and RAG applicationsGenerative AI has moved well beyond the stand-alone chatbot. It now drafts code, searches internal knowledge, reviews contracts, opens support cases and, in some deployments, takes action through connected tools. That broader role changes the security question. A tester is no lon…CSOONLINE.COM
9 SepPost-quantum cryptography adoption and the national security implicationsQuantum computers have advanced significantly in capability and compute power in the last several years and are turning theoretical vulnerabilities in modern cryptography into real-world threats. The shift to post-quantum cryptography (PQC) needs to start now, but several challen…CSOONLINE.COM
9 SepMicrosoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026The update contained 119 critical flaws and two zero days, with security teams needing to prioritize updatesINFOSECURITY-MAGAZINE.COM
9 SepChrome 153 Patches Seventh Zero-Day of 2026The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible. The post Chrome 153 Patches Seventh Zero-Day of 2026 appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepPoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server MemoryPoisonedRefresh rootkit injects PHP web shells into F5 BIG-IP APM Apache memory, leaving no disk artifacts. SophosLabs published a detailed technical analysis on September 8, 2026, of a Linux implant, dubbed PoisonedRefresh by ESET, they found in compromised F5 BIG-IP Access Poli…SECURITYAFFAIRS.COM
9 Sep KEVMicrosoft fixes record 964 flaws, including 2 exploited zero-daysMicrosoft’s September 2026 Patch Tuesday fixes a record 964 vulnerabilities, including two actively exploited zero-days.MALWAREBYTES.COM
9 SepOver 36,000 exposed Plex servers vulnerable to recent flawsOver 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. [...]BLEEPINGCOMPUTER.COM
9 SepIvanti Patches Critical Flaws Across Enterprise Security ProductsSix critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws. The post Ivanti Patches Critical Flaws Across Enterprise Security Products appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepSecurin Platform helps security teams prove when attack paths are closedSecurin has announced the general availability of the Securin Platform, an AI-native Preemptive Exposure Management platform designed to answer three questions security teams struggle with every day: What can attackers actually exploit? What should we fix first? And did the fix a…HELPNETSECURITY.COM
9 SepDeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without ApprovalA flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on u…THEHACKERNEWS.COM
9 SepSpyCloud 2026 Identity Threat Report Finds Non-Human Identities Are Now the Leading Path into the EnterpriseNinety-five percent of organizations believe they have visibility into their AI and machine identity exposures, yet only 36% are actually monitoring them. SpyCloud , the leader in identity threat protection, today released its annual SpyCloud Identity Threat Report , a survey-bas…CSOONLINE.COM
9 SepChatGPT flaw lets attackers pull Gmail data across accounts via a hidden channelA flaw in OpenAI’s ChatGPT allowed attackers to extract data from a victim’s connected Gmail account by passing hidden instructions between separate user sessions, according to research from Check Point. In a proof-of-concept, Check Point demonstrated that a victim’s ChatGPT sess…CSOONLINE.COM
9 SepShinyHunters claims Florida DMV breach, puts data on the clockShinyHunters is claiming to have broken into a Florida government database containing sensitive information on the state’s drivers. The notorious extortion group said it has breached the Florida Department of Highway Safety and Motor Vehicles’ Driver and Vehicle Information Datab…CSOONLINE.COM
9 SepA “proof” of Fermat’s Last Theorem that fits the marginFermat famously claimed to have a “truly marvelous proof” of his Last Theorem , but he never wrote it down, insisting the margin of his page was too narrow to contain it. A few centuries later, Anthropic announced a complete formalization of Fermat’s Last Theorem using 13 m…TRAILOFBITS.COM
9 SepHackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memoryA rootkit found on hacked F5 BIG-IP APM devices skips the usual step of writing a web shell to disk, hiding it in memory instead, according to Sophos. F5 BIG-IP APM provides access policy enforcement to secure access to apps, APIs, and data. It’s primarily used by enterprises, fi…HELPNETSECURITY.COM
9 SepWebinar: Learn How to Answer “Are We Exposed?” Faster After a New CVEA major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application …THEHACKERNEWS.COM
9 SepIntroducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AIOpen-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new CyberAgents Exchange registry, Tenable paired its exposure management expertise with OpenAI GPT Cyber models…TENABLE.COM
9 SepUkraine prosecutor general steps down amid scam call center bribery probeUkraine’s prosecutor general, Ruslan Kravchenko, resigned this week over allegations that officials in his office took bribes to shield scam call centers from law enforcement.THERECORD.MEDIA
9 SepSkullcandy earbuds flaw lets nearby attackers access the microphoneSkullcandy Dime 3 wireless earbuds have a Bluetooth vulnerability that lets a nearby attacker pair with the device without putting it into pairing mode or getting the owner’s approval. Successful exploitation can let an attacker disrupt audio playback and potentially captur…CYBERINSIDER.COM
9 Sep“Network outage” disrupts Westfield Public Schools in New Jersey as ransomware group posts samplesJoseph Topping reports: Westfield Public Schools in New Jersey kept classrooms open during a districtwide network outage that disrupted communications and digital instruction throughout the first week of school. The district initially attributed the outage to equipment failure. “…DATABREACHES.NET
9 SepRussian suspect in bank account takeovers is extradited to USJoe Warminsky reports: A Russian web developer who played a role in a multimillion-dollar bank account takeover scheme has been extradited to the U.S. to face an indictment in the case, federal authorities said Tuesday. Sergei Anatolyevich Filimonov, 36, appeared in an Atlanta fe…DATABREACHES.NET
9 SepAkeyless adds real-time enforcement for AI agents in productionAkeyless has announced the general availability of Akeyless Agentic Runtime Authority, the real-time identity control layer for AI agent actions. It works on top of Akeyless SecretlessAI, a credential protection layer that keeps credentials out of AI agents and brokers access to …HELPNETSECURITY.COM
9 SepPassing the bucks $$$: Passback attacks explainedTL;DR Introduction Default printer configurations are common to find in internal infrastructure engagements. These configurations are usually insecure, exposing outdated protocols like SNMPv1 and web interfaces without requiring authentication. For an unauthenticated, internal at…PENTESTPARTNERS.COM
9 SepVeradigm warns of patient data breach after ransomware gang claims attackHealthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. [...]BLEEPINGCOMPUTER.COM
9 SepCredentialed Pre-Port Discovery: Don't Probe the Host, Ask itIf your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them. Every scan begins with the same question: which ports on this host are open? Everything after it, from identifying services to checking for vulnerabili…RAPID7.COM
9 SepMultiple Chinese hacking groups seen using identical Chrome zero-day exploitA Google Chrome bug identified in August was exploited by at least four China-linked cyber-espionage groups, according to researchers.THERECORD.MEDIA
9 SepAI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google WarnsCriminal and state-sponsored adversaries are increasingly using AI to automate and scale their attacks, according to GTIG. The post AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepOff Guard: Breaking LiteLLM from authentication bypass to cloud compromiseHow default keys, unauthenticated MCP sessions, and custom code guardrails expose cloud AI infrastructure to root-level remote code execution and IAM theft.WIZ.IO
9 SepScans for Proxmox Servers, (Wed, Sep 9th)About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment product. The vulnerability only affects version 7, which has not been supported for a couple of years now. ISC.SANS.EDU
9 SepMind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & WindowsOn September 1, 2026, Volexity’s Network Security Monitoring (NSM) service detected a spear-phishing campaign from a Chinese threat actor it tracks as UTA0560 targeting customers at multiple non-governmental organizations (NGOs). […] The post Mind the (Patch) Gap: Multiple …VOLEXITY.COM
9 SepU.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in CryptoThe U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and depl…THEHACKERNEWS.COM
9 SepFour Spy Groups Used the Same Chrome and Windows Exploit Kit Within a WeekMultiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to…THEHACKERNEWS.COM
9 SepThe state of AI for security: Measuring what matters most for building trustSecurity teams are starting to actively use AI for security work, including vulnerability triage, penetration testing, threat modeling, incident response, and code review. The promise is speed, but a security tool that moves fast and raises too many false alarms doesn’t save time…AWS.AMAZON.COM
9 SepFTC rescinds policy requiring health apps to notify customers after a breachThe policy, passed under the Biden administration, forced health apps to disclose when users’ personal health records were exposed in a breach or shared without authorization. The post FTC rescinds policy requiring health apps to notify customers after a breach appeared first on …CYBERSCOOP.COM
9 SepChinese espionage groups swarm to exploit triple-link chain of zero-daysMultiple China-aligned threat groups exploited the defects quickly to target various organizations. Proofpoint said the activity is ongoing and expects it to widen. The post Chinese espionage groups swarm to exploit triple-link chain of zero-days appeared first on CyberScoop .CYBERSCOOP.COM
9 SepMythos Vulnerability Firehose Hits a Human BottleneckAn analysis of Project Glasswing findings shows only a fraction have reached disclosure, and an even smaller number have been fixed.DARKREADING.COM
9 SepCO: Cyberattack damages files at Salida School District in ColoradoDysruptionHub reports: A cyberattack forced Salida School District in Colorado to shut down its network June 29, damaging locally stored files and disrupting administrative operations, the district said. The attack began about 6:30 a.m. and was detected two hours later, according…DATABREACHES.NET
📋 SECURITY BULLETINS 5[−]
9 SepICS Patch Tuesday: Schneider Electric, Siemens Fix Critical FlawsAVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products. The post ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepPatch Tuesday notes: Microsoft sets another record.New ClickFix technique targets browsers. Business news: NetSPI and Synack to merge.THECYBERWIRE.COM
9 SepAndroid’s September 2026 Updates Patch 180 VulnerabilitiesThe security updates resolve critical flaws across Android’s Framework, System, and Kernel components. The post Android’s September 2026 Updates Patch 180 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepChipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security AdvisoriesMajor chipmakers announced patches for vulnerabilities recently discovered in their products. The post Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepClear your calendar, it’s Patch Tuesday.Patch Tuesday is a doozy. The Feds warn China-based AI companies are distilling U.S. AI models. A new ClickFix campaign goes straight for the browser. Smart TVs get nosy. Hackers gift themselves a $47 million bug bounty. An Ohio man gets 15 years in federal prison for cyberstalki…THECYBERWIRE.COM
📢 SECURITY ADVISORIES 14[−]
9 SepChinese AI firms use industrial-scale distillation to copy US modelsCISA, the NSA, and the FBI warn that several China-based artificial intelligence companies have run industrial-scale campaigns to extract proprietary capabilities from leading US AI models. The agencies say the activity, underway since at least late 2024, involved billions of tok…CYBERINSIDER.COM
9 SepNew cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as RootcPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPan…THEHACKERNEWS.COM
9 SepChinese AI firms are siphoning capabilities from American models, CISA warnsChina-based AI companies are using large-scale knowledge distillation campaigns to copy capabilities from leading U.S. AI models, according to a joint cybersecurity advisory from the CISA, NSA, and FBI. Knowledge distillation is a standard AI training technique that uses outputs …HELPNETSECURITY.COM
9 SepUS Agencies Warn Chinese AI Firms Are Extracting Advanced AI ModelsUS agencies accuse six Chinese AI firms of extracting billions of tokens from US AI models to accelerate development and copy advanced capabilities. NSA, CISA, and the FBI jointly published an advisory accusing six Chinese AI companies, DeepSeek, Moonshot AI, Alibaba, MiniMax, St…SECURITYAFFAIRS.COM
9 SepSkullcandy Dime 3 earbuds expose users to Bluetooth hijackingThe Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. [...]BLEEPINGCOMPUTER.COM
9 SepCISA head says agency must change quickly to prevent the 'worst that could happen'CISA's cybersecurity, infrastructure security and emergency communications divisions are among the priorities as the agency fills vacancies created at the beginning of the Trump administration, acting director Nick Andersen says.THERECORD.MEDIA
🔥 INCIDENT REPORTING 11[−]
9 SepThe Other Side of the PR Pitch with Pulitzer Prize Winner Yael GrauerYael Grauer won a Pulitzer and got laid off in the same year. She is a freelance investigative reporter covering cybersecurity, privacy, and surveillance. She sat down with Gianna to talk about what companies get wrong when journalists come knocking, why lying in that moment make…THECYBERWIRE.COM
9 SepWhat breach and attack simulation needs to become in the AI eraBreach and attack simulation (BAS) has always had a supply chain. Somebody has to read the threat report, pull out the techniques, and turn them into something that will actually run against your controls. That somebody has always been a human red team. Up until a few months ago,…HELPNETSECURITY.COM
9 SepRisky Business #852 -- Cyber Command wants to buy shellsOn this week’s show Patrick Gray and James Wilson are joined by guest co-host Robby Winchester from SpecterOps to talk through the week’s news, including: ID verification company IDScan was breached and 153m driver licenses wound up for sale online. Cue the barrage of lawsuits Th…RISKY.BIZ
9 SepRisky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandalUkraine’s top prosecutor resigns amid a scam call center scandal, the US accuses Chinese AI companies of industrial-scale distillation, a cyberattack hits medical practices in Luxembourg, and the Liquid Network attacker returns some stolen Bitcoin, but keeps a $50 million bounty.RISKY.BIZ
9 SepWhy Threat Actors Love Your RMMIn this episode of the Microsoft Threat Intelligence Podcast, recorded live at Black Hat, Microsoft Threat Intelligence Director Elliot Volkman is joined by Andrew “Spike” Grant, Principal Threat Intelligence Incident Commander at Huntress. They explore how cybercriminals are inc…THECYBERWIRE.COM
9 SepCRPx0 ransomware: what you need to knowCRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Read more in my article on the Fortra blog.FORTRA.COM
9 SepInfostealer Logs Expose Replayable AI Tokens That Can Bypass MFACybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others.  Information stealers like Lumma Stealer or Vidar are equi…THEHACKERNEWS.COM
9 SepFBI cyber chief worries private sector not sharing enough cyber threat informationBrett Leatherman said that industry has the wrong idea about what the FBI does with the data it collects during incidents, which is used to help victims and investigations alike. The post FBI cyber chief worries private sector not sharing enough cyber threat information appeared …CYBERSCOOP.COM
9 SepElectronic health record company says customer data stolen in breachVeradigm said access was limited to a specific interface, and did not impact the company’s broader environment such as its networks, servers or databases. The incident did not result in operational disruptions, the company added.THERECORD.MEDIA
9 SepAdaptHealth confirms 4.1 million people exposed in July cyberattackHealthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. [...]BLEEPINGCOMPUTER.COM
9 SepSmashing Security podcast #484: How websites are tracking you with silenceWhen a chap called Matt noticed his Bluetooth headphones wouldn't switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fi…GRAHAMCLULEY.COM
🕵️ THREAT INTELLIGENCE 26[−]
9 SepISC Stormcast For Wednesday, September 9th, 2026 https://isc.sans.edu/podcastdetail/10086, (Wed, Sep 9th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
9 SepAWS spent years rebuilding its routing control plane without taking the network downEvery AWS API call, CloudFront video stream, and Route 53 lookup crosses the same infrastructure, which AWS calls its border network. It now runs on a routing system rebuilt from scratch over several years. The system that tells traffic where to go The scale AWS reports, current …HELPNETSECURITY.COM
9 SepGartner: 70% of SOCs will pilot AI agents. Only 15% will see resultsIn the Gartner report Validate the Promises of AI SOC Agents With These Key Questions, analysts Craig Lawson and Andrew Davies posit that “By 2028, 70% of large SOCs will pilot AI agents to augment Tier 1 and Tier 2 operations, but only 15% will achieve measurable improvements wi…HELPNETSECURITY.COM
9 SepSecurity Money: The Index Explodes, as the History of AI Teaches Us About Investments - BSW #464AI is all the hype, but we're currently stuck at the bottom of the 'J' curve. Wild enthusiasm has given way to the reality of costs, benefits, and risks. What's next for AI and companies looking to capitalize on the AI trends? John Willis, author, researcher, and technology indus…YOUTUBE.COM
9 SepThis Key Will Self-Destruct: An Open Standard for Revocable API KeysEvery leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. The post This Key Will Self-Destruct: An Open Standard for Revocable API Keys appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepNew Phishing Attack Creates Malicious Pages Inside the Victim’s BrowserAttackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepUntracked Nightmares: The Threats Hiding Behind Commodity InfrastructureAn investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
9 SepZscaler Agentic SOC combines AI agents with zero trust telemetryZscaler has announced Zscaler Agentic SOC, a new approach to security operations built to proactively reduce exposures, scale human expertise and stop AI-driven attacks at machine speed. Simply layering in AI capabilities onto the existing security stack will not provide the prot…HELPNETSECURITY.COM
9 SepClaude Fable Solves a Historical CipherClaude Fable 5.1 solved a 370-year-old cipher in forty-four minutes. This tracks with what I wrote about AIs doing mathematics: It’s good at things that involve lots of searching and testing.SCHNEIER.COM
9 SepUS Agencies Warn China Is Systematically Extracting Frontier AI CapabilitiesDistillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model. The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek .SECURITYWEEK.COM
9 Sep$245 million in stolen crypto funded racketeering crew’s lavish lifestyleA 22-year-old man built his fortune by breaking into strangers’ digital wallets, then spent it on nightclub tabs, private jets, and a fleet of cars worth millions. Malone Lam, a Singapore citizen, pleaded guilty this week in a Washington D.C. federal court to running a rack…HELPNETSECURITY.COM
9 SepFBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patchingThe remarks, to both CyberScoop and at the Billington CyberSecurity Summit, dovetail with the release of a new bureau cyber strategy. The post FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching appeared first on CyberScoop .CYBERSCOOP.COM
9 SepMeta Launches Personal AI Agent, Muse, Emphasizes Safety and PrivacyMuse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data. The post Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepOrchid Security targets AI agent risk with drift detection and kill switchesOrchid Security has announced identity drift detection and application-level kill switches for AI agents. They can complete authorized objectives beyond their initial privilege level within seconds. AI agents do not need to “break” security controls or workflow guardrails. AI age…HELPNETSECURITY.COM
9 SepAI Is Reshaping Tech AcquisitionsThe technology market is seeing significant acquisition activity and consolidation. One hypothesis is that AI is disrupting traditional fundraising, making it harder for some companies to secure new capital. Companies that cannot raise money may increasingly have to consider acqu…YOUTUBE.COM
9 SepFortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome ExtensionThe critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic. The post Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepNew FBI cyber strategy promises increase in adversary disruptionsThe document also focuses on helping victims, reflecting the bureau’s attempt to encourage more companies to share information with it.CYBERSECURITYDIVE.COM
9 SepDriver’s License Data for SaleA database of 153 million drivers licenses is for sale on the dark web. Brian Krebs has more detail .SCHNEIER.COM
9 SepCISOs are feeling the security burden of accelerated AI useA report shows CISOs face increased pressures related to cyber resilience and business continuity.CYBERSECURITYDIVE.COM
9 SepYour TV Still Watches HDMIAutomatic Content Recognition, or ACR, is designed to identify content displayed on smart TVs. Research published at the 2024 ACM Internet Measurement Conference found ACR activity on LG and Samsung TVs even when they were being used as external HDMI displays. That means the trac…YOUTUBE.COM
9 SepHelmGuard Raises $7.3 Million for Agentic GRC and SecurityThe company will increase its US market presence and will expand its engineering and go-to-market teams. The post HelmGuard Raises $7.3 Million for Agentic GRC and Security appeared first on SecurityWeek .SECURITYWEEK.COM
9 SepLawmakers call on Treasury to sanction hackers-for-hireThe groups have allegedly targeted American citizens and companies, including the wife of GOP Senate candidate Mike Rogers, a former representative running in a Michigan swing race. The post Lawmakers call on Treasury to sanction hackers-for-hire appeared first on CyberScoop .CYBERSCOOP.COM
9 SepPasskey-themed social engineering leads to identity and cloud compromisePasskey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mi…MICROSOFT.COM
9 SepAgentic AI SOCs Face ConsolidationThe agentic AI SOC market is attracting significant attention, but the discussion points to an increasingly crowded field. Salem Cyber has reportedly submitted paperwork to shut down operations. The panel argues that simply labeling a product “agentic AI SOC” will not be enough. …YOUTUBE.COM
9 SepThreat Matrix: Mapping threats across cloud web applicationsMicrosoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms. The post Threat Matrix: Mapping threats across cloud web appli…MICROSOFT.COM
9 SepOpenSSL’s new alpha build speeds up post-quantum cryptoThe OpenSSL project released the first alpha of OpenSSL 4.1.0, giving developers an early look at a version built for encrypted communication over unreliable connections and faster post-quantum cryptography. This marks the opening test build for a version still months from genera…HELPNETSECURITY.COM
🌐 CYBER THREAT LANDSCAPE 2[−]
9 SepF5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk ScansMalware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the w…THEHACKERNEWS.COM
9 SepGigabud Uses Android App Cloning to Evade Fraud DetectionGigabud clones banking apps into a work profile to break the link between malware alerts and fraudINFOSECURITY-MAGAZINE.COM
📡 INFOSEC NEWS 23[−]
9 SepWeekly Threat Bulletin – September 9th, 2026These are the top threats you should know about this week.F5.COM
9 SepThe push to stop algorithms controlling social media feeds has begunAustralia is proposing a law that gives people a choice over what fills their feeds. It may not be long before other countries demand the same.MALWAREBYTES.COM
9 SepMan gets 15 years for extorting women with AI-generated porn videosAn Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content. [...]BLEEPINGCOMPUTER.COM
9 SepAlby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin WalletsBitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the ow…THEHACKERNEWS.COM
9 SepU.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and GrokU.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been descr…THEHACKERNEWS.COM
9 SepGroup of bipartisan lawmakers ask US government to ban several hack-for-hire firmsThe three Indian companies are accused of using hackers to steal information used to sway litigation.TECHCRUNCH.COM
9 SepSequoia doubles down on Cymphony as AI agents create new enterprise security risksCymphony was valued at more than $100 million in a $25 million Series A co-led by Sequoia and SMBC Fin Atlas Beyond Fund.TECHCRUNCH.COM
9 SepNHIs Now the Number One Corporate Entry Point for HackersSpyCloud claims non-human identities are the most likely route into the enterpriseINFOSECURITY-MAGAZINE.COM
9 SepClickFix Moves into the Browser to Steal CryptocurrencyClickFix campaign uses browser-injected JavaScript and Google Sheets to steal cryptocurrencyINFOSECURITY-MAGAZINE.COM
9 SepMFA's Weakest Link: Account Recovery Is the New Attack PathMFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from…BLEEPINGCOMPUTER.COM
9 Sep‘Gambling with our lives’: Anthropic researcher quits, warns against self-improving AIAnthropic researcher Jacob Coxon resigned over AI extinction fears, calling for pacing agreements between labs.TECHCRUNCH.COM
9 SepResearchers Build WeChat Zero-Click Worm Hijacking Phones via CallsThe hacking tool, built using a combination of AI models, is effective against Android and iOS devicesINFOSECURITY-MAGAZINE.COM
9 SepMore than 100,000 fake stores are out to steal your card detailsDoppelCart’s fake stores copy real retailers and steal shoppers’ card details and one-time bank confirmation codes.MALWAREBYTES.COM
9 SepFBI puts its cyber strategy on paperThe first public cybersecurity strategy issued by the FBI "directs our teams, our field offices, our global presence" to align their efforts on countering malicious hackers and cybercrime groups, senior official Brett Leatherman says.THERECORD.MEDIA
9 SepIdentity-Based AI Attack Threatens Security of Enterprise Data"Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.DARKREADING.COM
9 SepYou Can Now Destroy Flock Cameras for Cash in GTA VA new GTA mod lets you smash and shoot Flock’s automatic license plate readers around the fictional Los Santos.WIRED.COM
9 SepUS says Chinese firms extracted billions of tokens from frontier AI modelsU.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. [...]BLEEPINGCOMPUTER.COM
9 SepGrindr settles privacy lawsuit tied to disclosure of users’ HIV statuses for $35 millionThe settlement concludes a legal fight that dates to April 2024, when UK users sued for the alleged violations of their country’s privacy laws.THERECORD.MEDIA
9 SepNVIDIA to acquire Hugging Face for $12.9 billion.Upwind has raised $300 million in Series C funding led by Bessemer Venture Partners and TCV.THECYBERWIRE.COM
9 SepUS disrupts Xinbi Guarantee marketplace fueling the cyber scam economyThe U.S. government also carried out a seizure of $52.8 million from 52 wallets connected to the platform.THERECORD.MEDIA
9 SepApple Doesn’t Want You to Worry About the New Apple Watch’s Listening FeaturesThe new Apple Watch includes several “intelligent” listening features that have privacy and security baked in. But the protections can’t change the facts of what the tools do.WIRED.COM
9 SepUS Government Accuses Chinese AI Firms of Distilling Frontier ModelsUS agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.DARKREADING.COM
9 SepSan Francisco Orders Meta to Stop ‘Allowing’ AI Child Abuse AdsThe City Attorney’s Office has asked Meta to explain how the harmful ads repeatedly ran on Facebook and Instagram. The company claims the ads are not under the city’s jurisdiction.WIRED.COM