2026-09-09 01:00 UTC
Security Journalism
Huntress · indexed 2026-09-08 13:30 UTC
Huntress is tracking a pattern across multiple customer environments where rogue ScreenConnect clients repeatedly spawn the Windows Script Host to execute a series of four VBScript files.
P0
2026-09-08 22:40 UTC
Security Journalism
The Record · indexed 2026-09-08 22:45 UTC
The new record total for Patch Tuesday is 973 vulnerabilities.
P0
2026-09-08 22:16 UTC
Vendor Research
Cisco Talos Intelligence Blog · Cisco Talos · indexed 2026-09-08 22:45 UTC
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
P5
2026-09-08 21:44 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-09-08 21:50 UTC
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
P0
2026-09-08 21:44 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-09-09 00:10 UTC
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday, including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will e…
P65
2026-09-08 21:26 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-09-08 21:45 UTC
Attackers are actively exploiting two of the vulnerabilities, and another 58 are more likely to be exploited, according to Microsoft.
P0
2026-09-08 21:23 UTC
Other
Proofpoint Threat Insight · indexed 2026-09-11 04:30 UTC
P0
2026-09-08 21:03 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-08 21:15 UTC
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.
P0
2026-09-08 20:52 UTC
Security Journalism
The Record · indexed 2026-09-08 21:00 UTC
Malone Lam was indicted on scamming charges in September 2024 after drawing law enforcement scrutiny for parlaying stolen crypto into lavish Hamptons vacations, cars and private jets.
P0
2026-09-08 20:36 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-09-08 21:00 UTC
Researchers and OpenAI disagree on whether an earlier incident involving DseWiki, which the company did not disclose, was a “hack."
P0
2026-09-08 20:35 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-08 21:10 UTC
Crypto exchange network Liquid Network lost $320 million overnight, then got most of it back after the hackers demanded a bug fix instead of a ransom Bitcoin’s Liquid Network, a sidechain built by Blockstream and used by dozens of exchanges to move funds faster and more privately than the main Bitcoin blockchain allows, got drained […]
P0
2026-09-08 20:35 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-08 20:40 UTC
A massive operation dubbed "DoppelCart" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details. [...]
P0
2026-09-08 20:24 UTC
Security Journalism
BleepingComputer · Sponsored by ActiveState · indexed 2026-09-08 20:25 UTC
The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements. [...]
P25
2026-09-08 20:08 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-08 20:10 UTC
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. [...]
P0
2026-09-08 19:46 UTC
Security Journalism
The Record · indexed 2026-09-08 20:00 UTC
A "flawless" performance by the CIA's Cyber Mission Center contributed to the capture of Venezuelan President Nicolás Maduro in January, agency Deputy Director Michael Ellis says.
P0
2026-09-08 19:37 UTC
Security Journalism
The Record · indexed 2026-09-08 19:45 UTC
A Russian web developer who played a role in a multimillion-dollar bank account takeover scheme has been extradited to the U.S. to face an indictment.
P0
2026-09-08 19:20 UTC
Community
SANS Internet Storm Center · indexed 2026-09-08 19:35 UTC
This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.
P30
2026-09-08 19:20 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-08 19:30 UTC
The record-breaking September security update fixes two exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities. The post Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek.
P45
2026-09-08 19:12 UTC
Security Journalism
The Record · indexed 2026-09-08 19:30 UTC
On August 26, the State Department labeled A/I an “extremist group” operating infrastructure for “far-left militants across the world” and announced that anyone engaging with the group financially risked exposure to sanctions.
P0
2026-09-08 18:49 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-08 19:00 UTC
Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes. [...]
P5
2026-09-08 18:37 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-08 18:50 UTC
Tracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code. The post Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day appeared first on SecurityWeek.
P30
2026-09-08 18:18 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-08 18:20 UTC
Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. [...]
P30
2026-09-08 18:09 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-08 18:50 UTC
Researchers built a WeChat worm that spreads through incoming calls without user action. Tencent has blocked the exploit. Researchers at Calif created a WeChat worm that can take over an account through an incoming call, even if the victim never answers or touches the phone. The attack works only when the caller already appears in […]
P0
2026-09-08 18:07 UTC
Vendor Research
Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-09-08 18:20 UTC
104Critical860Important0Moderate0LowMicrosoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important.This month’s update includes patches for:.NET.NET and Visual StudioASP.NET CoreActive Directory Certificate Services (AD CS)Active Directory Domain Serv…
P65
2026-09-08 17:57 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-09-08 18:05 UTC
Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]
P0
2026-09-08 17:25 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-08 17:35 UTC
Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.
P0
2026-09-08 17:21 UTC
Vendor Research
Tenable Blog · Eric Doerr · indexed 2026-09-08 17:30 UTC
Tenable is bringing Anthropic’s Claude Mythos 5 into our enterprise security offerings. Adding frontier adversarial reasoning to the Tenable One Exposure Management Platform will help customers better anticipate how attackers could breach their environments and stay ahead of AI-fueled risk. Tenable One Adversary View, the first innovation planned from this work, will debut in the coming weeks.Key takeawaysClaude Mythos 5 is coming to Tenable One. In addition to using Claude Mythos 5 for researc…
P0
2026-09-08 17:00 UTC
Security Journalism
The Record · indexed 2026-09-08 17:20 UTC
Public negotiations between hackers and the operators of the Liquid Network crypto platform ended with the attackers sending back most — but not all — of what they took.
P0
2026-09-08 17:00 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-08 17:15 UTC
Malicious prompts concealed in documents, metadata, emails, images and code can manipulate autonomous agents into taking dangerous actions. The post The Hidden Instructions That Can Hijack AI Agents appeared first on SecurityWeek.
P0
2026-09-08 16:35 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-08 16:40 UTC
Alleged ‘white-hat’ hackers drained $320 million from Liquid’s federation wallet, demanding a bug fix. The post Hackers Return $263 Million Stolen From Liquid Network appeared first on SecurityWeek.
P0