The record-breaking September security update fixes two exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities.
Tag: EN
September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)
This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to…
BigBear 2.0 Bypasses Microsoft 365 MFA at 258 Organizations
BigBear 2.0 bypassed Microsoft 365 MFA at 258 organizations by stealing session cookies. Learn how the phishing service works and how to respond.
Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
Tracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code.
10 of the Best Patch Management Service Providers in 2026
Explore the top patch management solutions for 2026.
WeChat Worm Can Hijack Accounts Without Victims Answering Calls
Researchers built a WeChat worm that spreads through incoming calls without user action. Tencent has blocked the exploit. Researchers at Calif created a…
AI Agents Helped Breach an Enterprise Network in Under 10 Hours
Unit 42 says AI agents helped a threat actor breach an enterprise network in under 10 hours, compressing weeks of intrusion work into a single day.
ChatGPT Sandbox Flaw Lets Attackers Steal Gmail Data Across Accounts via Hidden Channel
A covert cross-account communication channel inside ChatGPT let an attacker hijack a victim’s session and silently exfiltrate data from connected apps…
Belgian Researcher Held in China-Linked Semiconductor Espionage Probe
A Belgian researcher is held in a probe into whether sensitive BelGaN semiconductor technology and trade secrets were unlawfully transferred to China.
Liquid Network Hackers Return Most of $320M Bitcoin Haul
Liquid Network hackers returned 3,400 BTC after draining $320 million from its federation wallet, but about $47 million in Bitcoin remains outstanding.
Unlocking High Value Enterprise Data for Confidential AI
Unlocking High Value Enterprise Data for Confidential AI lee.potok@thal… Mon, 09/07/2026 – 13:55 Data Security Cloud Security Aditya AGARWAL | Assistant…
Hackers Actively Exploiting FortiGate Firewalls to Deploy Custom Node.js Malware
An active exploitation campaign targeting FortiGate firewalls, in which attackers weaponize a critical vulnerability to plant a custom-built Node.js…
Ivanti EPMM, Neurons and Sentry Vulnerabilities Enable Privilege Escalation and RCE Attacks
Ivanti has disclosed a wave of security advisories affecting three flagship enterprise products, Endpoint Manager Mobile, Neurons for ITSM, and Sentry,…
FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack
Fortinet has disclosed a high-severity certificate validation flaw in the Agentless ZTNA portal of FortiOS and FortiProxy that could let an…
The Hidden Instructions That Can Hijack AI Agents
Malicious prompts concealed in documents, metadata, emails, images and code can manipulate autonomous agents into taking dangerous actions.
CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks
CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046, to its Known Exploited Vulnerabilities (KEV)…
AIs as Modern Genies
This essay was written with Barath Raghavan, and originally appeared in Lawfare . In April, an artificial intelligence (AI) agent conducting a routine…
Dell Secure Connect Gateway Vulnerabilities Allow Hackers to Gain Unauthorized Access
Dell has disclosed three critical vulnerabilities in its Secure Connect Gateway 5.0 platform that could allow attackers to gain unauthorized access,…
Phishing in 2026. Latest statistics and analysis
“You’ve been gifted a voucher!”. “Your account will be closed unless you act now”. “Late payment demand. Invoice # 207”. Phishing scams come in many…
Hackers Turn ScreenConnect Into Its Own Infection Vector in New Worm-Like Campaign
A remote access tool built for IT departments and help desks is now being weaponized against them. Researchers at Huntress say they’ve found hacked…