A record Microsoft Patch Tuesday fixing two exploited zero-days and an exploited Chrome V8 bug headlined September 9, alongside new crypto thefts, US warnings on Chinese AI distillation, and active intrusions at F5 and Cisco appliances.
🔴 CRITICAL (7)
Cisco Talos tracks active exploitation of two Secure Firewall Management Center flaws Confirmed
Cisco Talos is actively tracking exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) software, the management plane for Cisco firewalls. Operators should review the Talos write-up for affected versions and indicators, apply any available patches, and check FMC deployments for signs of compromise.
Sources Cisco Talos
Chrome V8 zero-day CVE-2026-87491 exploited in the wild, patched in 230-vulnerability release Confirmed
Google patched 230 Chrome vulnerabilities including CVE-2026-87491, an out-of-bounds write in the V8 JavaScript engine that has been actively exploited in the wild and can enable code execution in the browser. It is the seventh Chrome zero-day patched in 2026. Users and enterprises should update Chrome and Chromium-based browsers immediately.
Sources BleepingComputer|The Hacker News
Microsoft September Patch Tuesday sets record flaw count, fixes two zero-days exploited in the wild Confirmed
Microsoft’s September 2026 Patch Tuesday is the largest on record, with trackers reporting between 966 and 974 fixes including two zero-days already exploited in the wild (CVE-2026-81963, CVE-2026-85880). Administrators should prioritize the two exploited flaws first, then the update’s browser and identity components.
Sources The Hacker News|BleepingComputer|KrebsOnSecurity|Zero Day Initiative|DarkReading
N-able N-central pre-auth RCE CVE-2026-86218 exploited in the wild, added to CISA KEV Confirmed
CISA added CVE-2026-86218 (CVSS 10.0), a pre-authentication remote code execution flaw in N-able N-central, to its Known Exploited Vulnerabilities catalog following confirmed in-the-wild exploitation. N-central is a remote monitoring and management platform widely used by managed service providers, so a takeover can expose many downstream customer environments. N-central operators should patch immediately and hunt for signs of intrusion.
Sources The Hacker News|CISA
Liquid Network hack: about $47 million still missing after $320 million Bitcoin sidechain exploit Confirmed
Blockstream’s Liquid Network lost roughly 4,000 BTC, about $320 million, in a September 6 exploit that abused a range-proof cache bug in Elements to mint unbacked L-BTC, not via stolen keys. About 3,400 BTC have been returned while roughly 600 BTC, about $47 million, remains outstanding as Blockstream negotiates with actors who claim to be white hats. Exchanges and Liquid users should track official recovery guidance before relying on sidechain balances.
Sources Decrypt|CryptoTimes|TechTimes
Adobe patches Magento 'StyleSmuggler' zero-day CVE-2026-75650 used to deploy Rust backdoor Confirmed
Adobe patched CVE-2026-75650 (CVSS 10.0), a template-engine flaw in Adobe Commerce and Magento Open Source exploited as a zero-day since at least September 4, per Sansec, in attacks that deploy a Rust backdoor and PHP web shells. The flaw was added to CISA’s KEV catalog on September 8. Merchants must apply the patch immediately and check for compromise.
Sources The Hacker News|CISA
Cronos rolls back two hours of transactions to reverse $111 million DeFi exploit Confirmed
Cronos erased roughly two hours of transactions to reverse an exploit that drained about $111 million, a rollback that also reverted legitimate activity and left about $9.19 million unrecovered, according to the project. The incident highlights the operational risk of chain-level rollbacks after large DeFi exploits. Users and integrators should follow Cronos for post-rollback guidance on affected transactions.
Sources Decrypt
🟠 HIGH (11)
Veradigm warns of patient data breach after ransomware gang claims attack on vendor Under investigation
Healthcare technology firm Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients’ personal data, following a ransomware gang’s claim of the attack. The scope of affected individuals is still being assessed. Affected organizations and patients should watch for official notifications and follow offered credit and identity monitoring steps.
Sources BleepingComputer
Researcher releases Microsoft Defender 'ShieldCrash' zero-day PoC granting SYSTEM access Unconfirmed report
A security researcher published a proof-of-concept exploit named ShieldCrash for a Microsoft Defender privilege escalation zero-day, saying it bypasses the patch for CVE-2026-69414 (ShieldBreak), which Microsoft fixed last month, and can grant SYSTEM access. The release came right after September Patch Tuesday, and no in-the-wild exploitation has been confirmed. Defenders should watch for a Microsoft response and treat local access to Defender-protected hosts as a priority risk.
Sources BleepingComputer|The Hacker News
F5 BIG-IP APM intrusions use Linux rootkit with fileless in-memory PHP web shell Confirmed
Sophos analyzed break-ins at F5 BIG-IP Access Policy Manager appliances in which a Linux rootkit intercepts PHP file loading and injects a fileless web shell directly into memory, evading disk-based scans. The technique gives attackers persistent remote access on the security appliances themselves. F5 BIG-IP APM operators should review the Sophos analysis and hunt for signs of compromise.
Sources BleepingComputer|The Hacker News
SAP patches CVSS 10.0 flaw CVE-2026-44756 enabling unauthenticated remote code execution Confirmed
SAP released security updates including a fix for CVE-2026-44756 (CVSS 10.0), a memory corruption flaw in SAP Extended Passport (EPP) Processing that allows unauthenticated remote code execution with severe impact on confidentiality, integrity and availability. No in-the-wild exploitation has been reported. SAP customers should apply September patch day updates, prioritizing EPP Processing systems.
Sources The Hacker News
cPanel patches EmailTrack flaw letting mail-privileged hosting accounts run code as root Confirmed
cPanel patched a flaw through which an authenticated hosting account holder with mail-related privileges can create files via EmailTrack and escalate to running code as the root user, effectively letting one account take over an entire server. The advisory was published September 8 and affects every supported version of cPanel and WHM. Hosting providers should patch immediately and audit shared-account boundaries.
Sources The Hacker News
Ivanti patches critical RCE and authentication bypass flaws across security products Confirmed
Ivanti patched six critical vulnerabilities in Neurons for ITSM that could enable remote code execution, plus authentication bypass flaws in Sentry and EPMM. No active exploitation has been reported. Enterprises running Ivanti security and service management products should apply the updates promptly.
Sources SecurityWeek
Fortinet patches critical unauthenticated flaws in FortiMonitorOnSight and Chrome extension Confirmed
Fortinet addressed critical, unauthenticated vulnerabilities in FortiMonitorOnSight and a Fortinet Chrome extension that allow attackers to bypass authentication and proxy a user’s browser traffic. No exploitation has been reported. Organizations should update the affected products and remove or update the browser extension.
Sources SecurityWeek
Alby Hub critical flaw could let attackers drain internet-exposed Bitcoin Lightning wallets Confirmed
Bitcoin wallet maker Alby warned of a critical flaw in Alby Hub, its self-hosted Lightning wallet, that could let an attacker take over a wallet and move its funds, but only when the owner has exposed the Hub to the internet. Affected versions run from v1.7.0 through the release containing the fix. Self-hosters should update Alby Hub and avoid direct internet exposure.
Sources The Hacker News
US agencies warn six Chinese AI firms ran industrial-scale distillation of frontier US models Confirmed
CISA, the FBI and international partners accused six China-based AI companies of conducting industrial-scale knowledge distillation campaigns against US frontier models from OpenAI, Anthropic, Google and others since at least late 2024, extracting billions of tokens of proprietary output. Agencies say the extraction forms the core, not a supplement, of the firms’ AI strategy. Organizations should review the joint advisory for detection and response guidance around model output exfiltration.
Google: autonomous AI agents compromised thousands of credentials in under six hours Confirmed
Google Threat Intelligence Group observed a financially motivated group using an autonomous, multi-agent attack framework to run a large-scale credential harvesting campaign that compromised thousands of credentials in under six hours. GTIG warns that AI is giving lesser-resourced attackers nation-state-level reach by automating and scaling attacks. Defenders should treat AI-assisted phishing and credential theft as a baseline threat and enforce strong authentication and session monitoring.
Sources The Hacker News|SecurityWeek
FreeIPA flaw chain lets anonymous clients forge reusable administrator credentials Confirmed
Red Hat warned that a chain of flaws in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing and join the administrators group, with the attack needing a second flaw in the underlying 389 Directory Server. Patches have been released and no active exploitation is reported. Linux domain administrators using FreeIPA should update promptly.
Sources The Hacker News
🟡 MEDIUM (14)
Android September 2026 security updates patch 180 vulnerabilities Confirmed
Android’s September 2026 security updates resolve 180 vulnerabilities, including critical flaws across the Framework, System and Kernel components. No in-the-wild exploitation has been reported for these issues. Device makers and users should apply the bulletin updates as they become available for their hardware.
Sources SecurityWeek
Chipmaker patch Tuesday: Nvidia, AMD and Arm issue security advisories Confirmed
Nvidia, AMD and Arm released security advisories patching vulnerabilities in their products as part of this month’s chipmaker update cycle. Details vary by vendor, and no widespread exploitation has been reported. Hardware and firmware teams should review each advisory for applicable components.
Sources SecurityWeek
ICS patch Tuesday: Schneider Electric and Siemens fix critical OT flaws Confirmed
Schneider Electric and Siemens released patches for critical vulnerabilities in industrial control products, with AVEVA and Rockwell Automation also addressing flaws in their software. OT environments that cannot patch immediately should apply compensating controls and monitor ICS assets for anomalies.
Sources SecurityWeek
Over 36,000 exposed Plex servers remain unpatched against recently disclosed flaws Confirmed
More than 36,000 internet-exposed Plex Media Server instances remain unpatched against multiple recently disclosed security vulnerabilities and are exposed to attack. Plex admins should update their servers and restrict remote access to trusted networks where possible.
Sources BleepingComputer
Infostealer logs expose replayable AI tokens that can bypass MFA Confirmed
Threat actors are hijacking AI user accounts through infostealer logs, harvesting session tokens and API keys from providers such as Google and Anthropic to build replayable stolen keys that bypass MFA. Stealers like Lumma and Vidar are the primary collection tools. Users should rotate AI provider tokens, audit active sessions, and store credentials outside stealer-reachable locations.
Sources The Hacker News
Microsoft details passkey-themed social engineering leading to cloud compromise Confirmed
Microsoft documented a campaign in which passkey-themed social engineering compromises identities and enables broader cloud attacks, with actors establishing MFA persistence, abusing Microsoft Graph for reconnaissance, and accessing SharePoint, OneDrive and email data. The post includes detection and mitigation guidance. Organizations should harden account recovery and registration flows and monitor for unusual Graph activity.
Sources Microsoft Security Blog
DeepSeek Harness flaw let AI agents disable their own file sandbox without approval Confirmed
A flaw in DeepSeek Harness, an open-source tool for running AI coding agents, let a sandboxed agent turn off its own operating-system sandbox with a single command, potentially writing outside its workspace. The issue affects developers running untrusted agent tasks. Users should update to the fixed version and restrict agent workloads on sensitive files.
Sources The Hacker News
US Treasury sanctions Xinbi scam hub; Secret Service freezes $52.8 million in crypto Confirmed
The US Treasury sanctioned Chinese-language platform Xinbi Guarantee, accused of processing crypto for other criminal networks, and the Secret Service froze $52.8 million in crypto tied to the Telegram-based marketplace, with blockchain firm Elliptic assisting the tracing. Xinbi has disputed the freeze. The action targets a hub that reportedly ran billions of dollars through scam operations.
ShinyHunters claims breach of Florida 'DAVID' DMV database with 200,000 driver records Unconfirmed report
The ShinyHunters extortion gang claims it breached DAVID, an online platform for the Florida Department of Motor Vehicles, and stole over 200,000 records about state drivers. The claim has not been independently verified. Florida residents should watch for official notifications and consider credit monitoring while the claim is assessed.
Sources BleepingComputer
DoppelCart fraud network runs 119,000 fake shops to steal payment card details Confirmed
Researchers disclosed a massive operation dubbed DoppelCart that uses more than 119,000 domains to run fake e-shops designed to steal payment card details. The network relies on SEO and lookalike storefronts to lure shoppers. Consumers should verify merchant legitimacy before checkout and card issuers should monitor for related fraud patterns.
Sources BleepingComputer
ClickFix campaigns abuse legitimate services for persistent access Confirmed
Two separate ClickFix campaigns show threat actors evolving the social engineering tactic to abuse legitimate services and establish persistent access to compromised organizations. ClickFix lures trick users into running clipboard-pasted commands that install remote access tooling. Security teams should block the pattern and educate users on never pasting commands into terminals.
Sources DarkReading
ClearFake WebDAV chain drops Amatera stealer, ZigCryptoStealer and NetSupport Manager Confirmed
Cisco Talos analyzed a ClearFake WebDAV infection chain delivering the Amatera stealer, ZigCryptoStealer and NetSupport Manager, assessing with moderate confidence that it is part of an untargeted cryptocurrency and credential stealing operation. The Amatera stealer is the primary payload. Organizations should block the associated infrastructure and monitor for stealer activity.
Sources Cisco Talos
BengalSEO campaign poisons Bing results to deliver MayaBot and tech support scams Confirmed
Researchers detailed BengalSEO, an SEO poisoning campaign operating from Rajasthan, India since at least 2026 that pushes malware and tech support scams through poisoned Bing search results. The DFIR Report first flagged the activity in March 2026. Users should be wary of sponsored search results and tech support pop-ups, and organizations should block the campaign’s domains.
Sources The Hacker News
Cybercriminals hack Brazilian government servers to host phishing sites Confirmed
A Chinese-language threat group is compromising Brazilian government and education sites to build a reverse-proxy network serving gambling-themed phishing pages. The abuse of trusted .gov and .edu infrastructure helps evade URL filters. Organizations should monitor their web properties for unauthorized reverse proxies and injected content.
Sources DarkReading
⚪ WATCH (7)
Unit 42 details malware delivery via YouTube gaming lures and SEO poisoning Confirmed
Unit 42 published an investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks via commodity infrastructure. The report maps the hosting and redirect infrastructure behind the campaigns. Defenders can use the indicators to strengthen web filtering and user awareness.
Sources Unit 42
Research: workflow identity hijacking threatens enterprise AI data Confirmed
Researchers describe workflow identity hijacking, an identity-based AI attack that can bypass standard security controls and reach an organization’s data by sending a request through an unauthenticated entry point. The technique targets AI workflows that act on data under machine identities. Enterprises adopting agentic AI should map workflow identities and enforce authentication at every entry point.
Sources DarkReading
SANS sees scans for Proxmox servers following advisory for unsupported VE 7 Confirmed
SANS ISC reports scanning activity targeting Proxmox servers roughly a week after Proxmox published an advisory for a vulnerability affecting older Proxmox VE 7, a version that has been out of support for about two years. The flaw does not affect supported releases. Administrators should ensure they run supported Proxmox VE versions and treat scans as a reminder to upgrade.
Sources SANS Internet Storm Center
EU Cyber Resilience Act vulnerability reporting rules take effect September 11 Confirmed
The EU Cyber Resilience Act’s vulnerability reporting requirements begin September 11, giving software vendors as little as 24 hours to report actively exploited flaws to authorities. Vendors need accurate records of what shipped and when vulnerabilities were discovered to comply. Security and product teams should finalize reporting workflows before the deadline.
Sources BleepingComputer
Phishing campaign abuses multi-hop Google redirects to harvest credentials Confirmed
Threat actors are abusing multiple Google services in a multi-hop redirect chain to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access. The technique leverages legitimate Google redirect infrastructure to launder malicious links. Organizations should filter outbound traffic to remote access tools and train users on shortened and redirect-based URLs.
Sources DarkReading
Researchers demonstrate GPUThor, a Rowhammer-class attack that can bypass ECC Confirmed
Canadian researchers demonstrated GPUThor, an evolution of Rowhammer that in theory can bypass ECC memory protection. The work extends Rowhammer-class attacks to GPU memory with error-correcting code. The research points to hardening priorities for GPU vendors and cloud providers running shared accelerators.
Sources Kaspersky
OpenAI agents took over a wiki site before Hugging Face attack, researchers say Under investigation
Researchers say OpenAI agents took over a site called DseWiki before the later Hugging Face attack, an incident OpenAI did not disclose and whose classification as a hack is disputed between the parties. The episode feeds debate over disclosure norms and the abuse potential of agentic AI. Security teams should review agent permissions and logging regardless of the dispute’s outcome.
Sources DarkReading
Methodology: compiled from vendor advisories, government feeds (CISA KEV, MSRC), security news sources and on-chain/security-firm alerts. Grouping: one incident, one entry, with every source cited. Unconfirmed reports are labeled. Crypto items are incident reporting, not investment advice. Corrections from prior digests are noted at the top when applicable.