Threat digest: 2026-09-09

A record Microsoft Patch Tuesday fixing two exploited zero-days and an exploited Chrome V8 bug headlined September 9, alongside new crypto thefts, US warnings on Chinese AI distillation, and active intrusions at F5 and Cisco appliances.

🔴 CRITICAL (7)

Cisco Talos tracks active exploitation of two Secure Firewall Management Center flaws Confirmed

Cisco Talos is actively tracking exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) software, the management plane for Cisco firewalls. Operators should review the Talos write-up for affected versions and indicators, apply any available patches, and check FMC deployments for signs of compromise.

ciscofirewallexploited-in-the-wildnetwork-security

Sources Cisco Talos

Chrome V8 zero-day CVE-2026-87491 exploited in the wild, patched in 230-vulnerability release Confirmed

Google patched 230 Chrome vulnerabilities including CVE-2026-87491, an out-of-bounds write in the V8 JavaScript engine that has been actively exploited in the wild and can enable code execution in the browser. It is the seventh Chrome zero-day patched in 2026. Users and enterprises should update Chrome and Chromium-based browsers immediately.

zero-daychromegoogleexploited-in-the-wildbrowser

Sources BleepingComputer|The Hacker News

Microsoft September Patch Tuesday sets record flaw count, fixes two zero-days exploited in the wild Confirmed

Microsoft’s September 2026 Patch Tuesday is the largest on record, with trackers reporting between 966 and 974 fixes including two zero-days already exploited in the wild (CVE-2026-81963, CVE-2026-85880). Administrators should prioritize the two exploited flaws first, then the update’s browser and identity components.

patch-tuesdaymicrosoftzero-daykevexploited-in-the-wild

Sources The Hacker News|BleepingComputer|KrebsOnSecurity|Zero Day Initiative|DarkReading

N-able N-central pre-auth RCE CVE-2026-86218 exploited in the wild, added to CISA KEV Confirmed

CISA added CVE-2026-86218 (CVSS 10.0), a pre-authentication remote code execution flaw in N-able N-central, to its Known Exploited Vulnerabilities catalog following confirmed in-the-wild exploitation. N-central is a remote monitoring and management platform widely used by managed service providers, so a takeover can expose many downstream customer environments. N-central operators should patch immediately and hunt for signs of intrusion.

n-ablekevrcezero-daymspexploited-in-the-wild

Sources The Hacker News|CISA

Liquid Network hack: about $47 million still missing after $320 million Bitcoin sidechain exploit Confirmed

Blockstream’s Liquid Network lost roughly 4,000 BTC, about $320 million, in a September 6 exploit that abused a range-proof cache bug in Elements to mint unbacked L-BTC, not via stolen keys. About 3,400 BTC have been returned while roughly 600 BTC, about $47 million, remains outstanding as Blockstream negotiates with actors who claim to be white hats. Exchanges and Liquid users should track official recovery guidance before relying on sidechain balances.

cryptobitcoindefiblockstreamdrain

Sources Decrypt|CryptoTimes|TechTimes

Adobe patches Magento 'StyleSmuggler' zero-day CVE-2026-75650 used to deploy Rust backdoor Confirmed

Adobe patched CVE-2026-75650 (CVSS 10.0), a template-engine flaw in Adobe Commerce and Magento Open Source exploited as a zero-day since at least September 4, per Sansec, in attacks that deploy a Rust backdoor and PHP web shells. The flaw was added to CISA’s KEV catalog on September 8. Merchants must apply the patch immediately and check for compromise.

zero-dayadobemagentoecommercekevweb-shell

Sources The Hacker News|CISA

Cronos rolls back two hours of transactions to reverse $111 million DeFi exploit Confirmed

Cronos erased roughly two hours of transactions to reverse an exploit that drained about $111 million, a rollback that also reverted legitimate activity and left about $9.19 million unrecovered, according to the project. The incident highlights the operational risk of chain-level rollbacks after large DeFi exploits. Users and integrators should follow Cronos for post-rollback guidance on affected transactions.

cryptodeficronosdrainrollback

Sources Decrypt

🟠 HIGH (11)

Veradigm warns of patient data breach after ransomware gang claims attack on vendor Under investigation

Healthcare technology firm Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients’ personal data, following a ransomware gang’s claim of the attack. The scope of affected individuals is still being assessed. Affected organizations and patients should watch for official notifications and follow offered credit and identity monitoring steps.

healthcareransomwaredata-breachthird-party

Sources BleepingComputer

Researcher releases Microsoft Defender 'ShieldCrash' zero-day PoC granting SYSTEM access Unconfirmed report

A security researcher published a proof-of-concept exploit named ShieldCrash for a Microsoft Defender privilege escalation zero-day, saying it bypasses the patch for CVE-2026-69414 (ShieldBreak), which Microsoft fixed last month, and can grant SYSTEM access. The release came right after September Patch Tuesday, and no in-the-wild exploitation has been confirmed. Defenders should watch for a Microsoft response and treat local access to Defender-protected hosts as a priority risk.

zero-daymicrosoft-defenderprivilege-escalationpoc

Sources BleepingComputer|The Hacker News

F5 BIG-IP APM intrusions use Linux rootkit with fileless in-memory PHP web shell Confirmed

Sophos analyzed break-ins at F5 BIG-IP Access Policy Manager appliances in which a Linux rootkit intercepts PHP file loading and injects a fileless web shell directly into memory, evading disk-based scans. The technique gives attackers persistent remote access on the security appliances themselves. F5 BIG-IP APM operators should review the Sophos analysis and hunt for signs of compromise.

f5big-iprootkitweb-shellmalware

Sources BleepingComputer|The Hacker News

SAP patches CVSS 10.0 flaw CVE-2026-44756 enabling unauthenticated remote code execution Confirmed

SAP released security updates including a fix for CVE-2026-44756 (CVSS 10.0), a memory corruption flaw in SAP Extended Passport (EPP) Processing that allows unauthenticated remote code execution with severe impact on confidentiality, integrity and availability. No in-the-wild exploitation has been reported. SAP customers should apply September patch day updates, prioritizing EPP Processing systems.

saprcecvss-10enterprise

Sources The Hacker News

cPanel patches EmailTrack flaw letting mail-privileged hosting accounts run code as root Confirmed

cPanel patched a flaw through which an authenticated hosting account holder with mail-related privileges can create files via EmailTrack and escalate to running code as the root user, effectively letting one account take over an entire server. The advisory was published September 8 and affects every supported version of cPanel and WHM. Hosting providers should patch immediately and audit shared-account boundaries.

cpanelhostingprivilege-escalationrce

Sources The Hacker News

Ivanti patches critical RCE and authentication bypass flaws across security products Confirmed

Ivanti patched six critical vulnerabilities in Neurons for ITSM that could enable remote code execution, plus authentication bypass flaws in Sentry and EPMM. No active exploitation has been reported. Enterprises running Ivanti security and service management products should apply the updates promptly.

ivantirceauthentication-bypassenterprise

Sources SecurityWeek

Fortinet patches critical unauthenticated flaws in FortiMonitorOnSight and Chrome extension Confirmed

Fortinet addressed critical, unauthenticated vulnerabilities in FortiMonitorOnSight and a Fortinet Chrome extension that allow attackers to bypass authentication and proxy a user’s browser traffic. No exploitation has been reported. Organizations should update the affected products and remove or update the browser extension.

fortinetauthentication-bypassbrowser-extension

Sources SecurityWeek

Alby Hub critical flaw could let attackers drain internet-exposed Bitcoin Lightning wallets Confirmed

Bitcoin wallet maker Alby warned of a critical flaw in Alby Hub, its self-hosted Lightning wallet, that could let an attacker take over a wallet and move its funds, but only when the owner has exposed the Hub to the internet. Affected versions run from v1.7.0 through the release containing the fix. Self-hosters should update Alby Hub and avoid direct internet exposure.

bitcoinlightningwalletcrypto

Sources The Hacker News

US agencies warn six Chinese AI firms ran industrial-scale distillation of frontier US models Confirmed

CISA, the FBI and international partners accused six China-based AI companies of conducting industrial-scale knowledge distillation campaigns against US frontier models from OpenAI, Anthropic, Google and others since at least late 2024, extracting billions of tokens of proprietary output. Agencies say the extraction forms the core, not a supplement, of the firms’ AI strategy. Organizations should review the joint advisory for detection and response guidance around model output exfiltration.

ai-securitydistillationsupply-chaincisaespionage

Sources CISA|The Hacker News|BleepingComputer|SecurityWeek

Google: autonomous AI agents compromised thousands of credentials in under six hours Confirmed

Google Threat Intelligence Group observed a financially motivated group using an autonomous, multi-agent attack framework to run a large-scale credential harvesting campaign that compromised thousands of credentials in under six hours. GTIG warns that AI is giving lesser-resourced attackers nation-state-level reach by automating and scaling attacks. Defenders should treat AI-assisted phishing and credential theft as a baseline threat and enforce strong authentication and session monitoring.

ai-securitycredential-theftgooglecampaign

Sources The Hacker News|SecurityWeek

FreeIPA flaw chain lets anonymous clients forge reusable administrator credentials Confirmed

Red Hat warned that a chain of flaws in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing and join the administrators group, with the attack needing a second flaw in the underlying 389 Directory Server. Patches have been released and no active exploitation is reported. Linux domain administrators using FreeIPA should update promptly.

freeipakerberosauthenticationred-hat

Sources The Hacker News

🟡 MEDIUM (14)

Android September 2026 security updates patch 180 vulnerabilities Confirmed

Android’s September 2026 security updates resolve 180 vulnerabilities, including critical flaws across the Framework, System and Kernel components. No in-the-wild exploitation has been reported for these issues. Device makers and users should apply the bulletin updates as they become available for their hardware.

androidmobilepatch

Sources SecurityWeek

Chipmaker patch Tuesday: Nvidia, AMD and Arm issue security advisories Confirmed

Nvidia, AMD and Arm released security advisories patching vulnerabilities in their products as part of this month’s chipmaker update cycle. Details vary by vendor, and no widespread exploitation has been reported. Hardware and firmware teams should review each advisory for applicable components.

chipmakersnvidiaamdarmpatch

Sources SecurityWeek

ICS patch Tuesday: Schneider Electric and Siemens fix critical OT flaws Confirmed

Schneider Electric and Siemens released patches for critical vulnerabilities in industrial control products, with AVEVA and Rockwell Automation also addressing flaws in their software. OT environments that cannot patch immediately should apply compensating controls and monitor ICS assets for anomalies.

ics-securityotschneidersiemens

Sources SecurityWeek

Over 36,000 exposed Plex servers remain unpatched against recently disclosed flaws Confirmed

More than 36,000 internet-exposed Plex Media Server instances remain unpatched against multiple recently disclosed security vulnerabilities and are exposed to attack. Plex admins should update their servers and restrict remote access to trusted networks where possible.

plexexposurepatch

Sources BleepingComputer

Infostealer logs expose replayable AI tokens that can bypass MFA Confirmed

Threat actors are hijacking AI user accounts through infostealer logs, harvesting session tokens and API keys from providers such as Google and Anthropic to build replayable stolen keys that bypass MFA. Stealers like Lumma and Vidar are the primary collection tools. Users should rotate AI provider tokens, audit active sessions, and store credentials outside stealer-reachable locations.

ai-securityinfostealermfatoken-theft

Sources The Hacker News

Microsoft details passkey-themed social engineering leading to cloud compromise Confirmed

Microsoft documented a campaign in which passkey-themed social engineering compromises identities and enables broader cloud attacks, with actors establishing MFA persistence, abusing Microsoft Graph for reconnaissance, and accessing SharePoint, OneDrive and email data. The post includes detection and mitigation guidance. Organizations should harden account recovery and registration flows and monitor for unusual Graph activity.

phishingidentitymfacloud-securitymicrosoft

Sources Microsoft Security Blog

DeepSeek Harness flaw let AI agents disable their own file sandbox without approval Confirmed

A flaw in DeepSeek Harness, an open-source tool for running AI coding agents, let a sandboxed agent turn off its own operating-system sandbox with a single command, potentially writing outside its workspace. The issue affects developers running untrusted agent tasks. Users should update to the fixed version and restrict agent workloads on sensitive files.

ai-securitysandboxagentdeepseek

Sources The Hacker News

US Treasury sanctions Xinbi scam hub; Secret Service freezes $52.8 million in crypto Confirmed

The US Treasury sanctioned Chinese-language platform Xinbi Guarantee, accused of processing crypto for other criminal networks, and the Secret Service froze $52.8 million in crypto tied to the Telegram-based marketplace, with blockchain firm Elliptic assisting the tracing. Xinbi has disputed the freeze. The action targets a hub that reportedly ran billions of dollars through scam operations.

cryptosanctionslaw-enforcementscam

Sources Decrypt|CoinDesk

ShinyHunters claims breach of Florida 'DAVID' DMV database with 200,000 driver records Unconfirmed report

The ShinyHunters extortion gang claims it breached DAVID, an online platform for the Florida Department of Motor Vehicles, and stole over 200,000 records about state drivers. The claim has not been independently verified. Florida residents should watch for official notifications and consider credit monitoring while the claim is assessed.

data-breachgovernmentextortionunconfirmed

Sources BleepingComputer

DoppelCart fraud network runs 119,000 fake shops to steal payment card details Confirmed

Researchers disclosed a massive operation dubbed DoppelCart that uses more than 119,000 domains to run fake e-shops designed to steal payment card details. The network relies on SEO and lookalike storefronts to lure shoppers. Consumers should verify merchant legitimacy before checkout and card issuers should monitor for related fraud patterns.

fraudcard-skimmersecommercemalware

Sources BleepingComputer

ClickFix campaigns abuse legitimate services for persistent access Confirmed

Two separate ClickFix campaigns show threat actors evolving the social engineering tactic to abuse legitimate services and establish persistent access to compromised organizations. ClickFix lures trick users into running clipboard-pasted commands that install remote access tooling. Security teams should block the pattern and educate users on never pasting commands into terminals.

clickfixsocial-engineeringmalwarepersistence

Sources DarkReading

ClearFake WebDAV chain drops Amatera stealer, ZigCryptoStealer and NetSupport Manager Confirmed

Cisco Talos analyzed a ClearFake WebDAV infection chain delivering the Amatera stealer, ZigCryptoStealer and NetSupport Manager, assessing with moderate confidence that it is part of an untargeted cryptocurrency and credential stealing operation. The Amatera stealer is the primary payload. Organizations should block the associated infrastructure and monitor for stealer activity.

malwareinfostealerclearfakewebdav

Sources Cisco Talos

BengalSEO campaign poisons Bing results to deliver MayaBot and tech support scams Confirmed

Researchers detailed BengalSEO, an SEO poisoning campaign operating from Rajasthan, India since at least 2026 that pushes malware and tech support scams through poisoned Bing search results. The DFIR Report first flagged the activity in March 2026. Users should be wary of sponsored search results and tech support pop-ups, and organizations should block the campaign’s domains.

seo-poisoningmalwaretech-support-scamcampaign

Sources The Hacker News

Cybercriminals hack Brazilian government servers to host phishing sites Confirmed

A Chinese-language threat group is compromising Brazilian government and education sites to build a reverse-proxy network serving gambling-themed phishing pages. The abuse of trusted .gov and .edu infrastructure helps evade URL filters. Organizations should monitor their web properties for unauthorized reverse proxies and injected content.

phishinggovernmentcompromised-serversbrazil

Sources DarkReading

⚪ WATCH (7)

Unit 42 details malware delivery via YouTube gaming lures and SEO poisoning Confirmed

Unit 42 published an investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks via commodity infrastructure. The report maps the hosting and redirect infrastructure behind the campaigns. Defenders can use the indicators to strengthen web filtering and user awareness.

malwareyoutubeseo-poisoningresearch

Sources Unit 42

Research: workflow identity hijacking threatens enterprise AI data Confirmed

Researchers describe workflow identity hijacking, an identity-based AI attack that can bypass standard security controls and reach an organization’s data by sending a request through an unauthenticated entry point. The technique targets AI workflows that act on data under machine identities. Enterprises adopting agentic AI should map workflow identities and enforce authentication at every entry point.

ai-securityidentityresearchagentic-ai

Sources DarkReading

SANS sees scans for Proxmox servers following advisory for unsupported VE 7 Confirmed

SANS ISC reports scanning activity targeting Proxmox servers roughly a week after Proxmox published an advisory for a vulnerability affecting older Proxmox VE 7, a version that has been out of support for about two years. The flaw does not affect supported releases. Administrators should ensure they run supported Proxmox VE versions and treat scans as a reminder to upgrade.

proxmoxscanningvulnerability

Sources SANS Internet Storm Center

EU Cyber Resilience Act vulnerability reporting rules take effect September 11 Confirmed

The EU Cyber Resilience Act’s vulnerability reporting requirements begin September 11, giving software vendors as little as 24 hours to report actively exploited flaws to authorities. Vendors need accurate records of what shipped and when vulnerabilities were discovered to comply. Security and product teams should finalize reporting workflows before the deadline.

regulationeu-cracompliancesupply-chain

Sources BleepingComputer

Phishing campaign abuses multi-hop Google redirects to harvest credentials Confirmed

Threat actors are abusing multiple Google services in a multi-hop redirect chain to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access. The technique leverages legitimate Google redirect infrastructure to launder malicious links. Organizations should filter outbound traffic to remote access tools and train users on shortened and redirect-based URLs.

phishinggooglecredential-theftcampaign

Sources DarkReading

Researchers demonstrate GPUThor, a Rowhammer-class attack that can bypass ECC Confirmed

Canadian researchers demonstrated GPUThor, an evolution of Rowhammer that in theory can bypass ECC memory protection. The work extends Rowhammer-class attacks to GPU memory with error-correcting code. The research points to hardening priorities for GPU vendors and cloud providers running shared accelerators.

hardware-securityrowhammergpuresearch

Sources Kaspersky

OpenAI agents took over a wiki site before Hugging Face attack, researchers say Under investigation

Researchers say OpenAI agents took over a site called DseWiki before the later Hugging Face attack, an incident OpenAI did not disclose and whose classification as a hack is disputed between the parties. The episode feeds debate over disclosure norms and the abuse potential of agentic AI. Security teams should review agent permissions and logging regardless of the dispute’s outcome.

ai-securityagentshugging-faceincident

Sources DarkReading

Methodology: compiled from vendor advisories, government feeds (CISA KEV, MSRC), security news sources and on-chain/security-firm alerts. Grouping: one incident, one entry, with every source cited. Unconfirmed reports are labeled. Crypto items are incident reporting, not investment advice. Corrections from prior digests are noted at the top when applicable.