Cybersecurity news & advisories
Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults
Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth.
Microsoft breaks Patch Tuesday record with 974-CVE deluge
The vulnpocalypse is upon us, dear reader. Microsoft delivered a record number of patches to address 974 CVEs in its own products this month, including two bugs that Redmond says are already under exploitation…
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Microsoft addressed 974 defects across its product suite, including two actively exploited zero-day vulnerabilities, in its monthly Patch Tuesday security program . The massive batch of patches, Microsoft’s largest…
Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited
The new record total for Patch Tuesday is 973 vulnerabilities.
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical." Microsoft notes that 2 of the…
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping…
Patch Tuesday - September 2026
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday , including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of…
Patch Tuesday Sets Another Record With 974 CVEs
Attackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.
OpenAI's Artifactory opened covert data-stealing channel alongside Hugging Face attack
A secret channel running through ChatGPT's internal JFrog Artifactory instance allowed one account to send hidden tasks - such as retrieving email data from a connected Gmail account - to a ChatGPT session under another…
Why this month's Microsoft patch release is a doozy
Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold. It was only two months ago that Microsoft patched a…
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.
Scammer behind $245 million crypto heist pleads guilty to RICO charges
Malone Lam was indicted on scamming charges in September 2024 after drawing law enforcement scrutiny for parlaying stolen crypto into lavish Hamptons vacations, cars and private jets.
Feds accuse China of ‘systematic’ distillation of U.S. AI models
The U.S. government is accusing Chinese AI companies of engaging in a deliberate and “systematic” effort to illegally distill U.S. frontier AI models and their capabilities. According to a joint cybersecurity advisory…
OpenAI Agents Took Over Wiki Site Before Hugging Face Attack
Researchers and OpenAI disagree on whether the earlier incident involving DseWiki was a “hack” that the company did not disclose.
DoppelCart fraud network uses 119,000 fake shops to steal credit cards
A massive operation dubbed "DoppelCart" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details.
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Authorities extradited a 36-year-old Russian national from the Republic of Georgia under accusations of widespread bank-account takeover attacks , including a scheme to defraud two banks of more than $6.3 million, the…
The EU CRA's Real Question: What Shipped, and When Did You Know?
The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly…
Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk.
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
CIA Deputy Director Michael Ellis said Tuesday that the agency’s role in Operation Absolute Resolve is an example of how it has moved to put cyber operations at the center of intelligence collection and field missions…
CIA official touts agency’s Cyber Mission Center in capture of Venezuela’s Maduro
A "flawless" performance by the CIA's Cyber Mission Center contributed to the capture of Venezuelan President Nicolás Maduro in January, agency Deputy Director Michael Ellis says.
Russian suspect in bank account takeovers is extradited to US
A Russian web developer who played a role in a multimillion-dollar bank account takeover scheme has been extradited to the U.S. to face an indictment.
September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)
This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026…
Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
The record-breaking September security update fixes two exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities.
Cisco IOS XR Software Security Hardening Release: September 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software…
Italian tech collective Autistici/Inventati shuts down after US terrorist designation
On August 26, the State Department labeled A/I an “extremist group” operating infrastructure for “far-left militants across the world” and announced that anyone engaging with the group financially risked exposure to…
Microsoft releases Windows 10 KB5122878 extended security update
Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes.
Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
Tracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code.
Why federal cyber defense demands an offense-driven mindset
Federal agencies are drowning in cybersecurity data. Every day, security operations centers absorb millions of logs, scanner alerts and inventory feeds. But raw, static data isn’t actionable intelligence. Ask a room of…
Channel 5 Gave Hunter Biden a List of Its Subscribers’ Emails for Some Reason
Channel 5, the YouTube channel hosted by Andrew Callaghan, said it gave a list of its email subscribers to Hunter Biden, the former president’s son, who went on to promote his new memecoin, a move that a data privacy…
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities.
Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880)
104 Critical 860 Important 0 Moderate 0 Low Microsoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the…
Windows 11 cumulative updates KB5124008 & KB5122880 released
Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features.
Phishing Powers 80% of Attacks on US Companies: How SOCs Can Detect It Early
Phishing remains one of the most effective ways for attackers to gain access to corporate environments. From 2013-2023, the FBI recorded 158,436 US victims of Business Email Compromise (BEC), with over $20 billion in…
Massive Microsoft Patch Tuesday September 2026 – 973 Vulnerabilities Fixed, Including 2 Zero-Days
Microsoft released its September 2026 Patch Tuesday security updates on September 8, addressing 973 vulnerabilities, including two zero-days already exploited in attacks. This massive patch follows the recent Microsoft…
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.
Claude Mythos 5 is coming to Tenable One, powering the new “Adversary View”
Tenable is bringing Anthropic’s Claude Mythos 5 into our enterprise security offerings. Adding frontier adversarial reasoning to the Tenable One Exposure Management Platform will help customers better anticipate how…
FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack
Fortinet has disclosed a high-severity certificate validation flaw in the Agentless ZTNA portal of FortiOS and FortiProxy that could let an unauthenticated remote attacker intercept traffic flowing between the ZTNA…
The Hidden Instructions That Can Hijack AI Agents
Malicious prompts concealed in documents, metadata, emails, images and code can manipulate autonomous agents into taking dangerous actions.
Hackers Actively Exploiting FortiGate Firewalls to Deploy Custom Node.js Malware
An active exploitation campaign targeting FortiGate firewalls, in which attackers weaponize a critical vulnerability to plant a custom-built Node.js remote access trojan (RAT) that turns compromised perimeter devices…
Hackers Return $263 Million Stolen From Liquid Network
Alleged ‘white-hat’ hackers drained $320 million from Liquid’s federation wallet, demanding a bug fix.
ShinyHunters hackers claim breach of Florida "DAVID" DMV database
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state.
OpenAI says ChatGPT outage causes image generation errors
OpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays when uploading files.
CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks
CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046 , to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploited in attacks…
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the…
Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability
A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with…
Boston Scientific left nursing its bottom line after cyberattack
Boston Scientific says that last month's cyberattack caused enough disruption that it is unlikely to meet its sales growth and adjusted earnings guidance for either the third quarter or the full year. The medical device…
Ivanti EPMM, Neurons and Sentry Vulnerabilities Enable Privilege Escalation and RCE Attacks
Ivanti has disclosed a wave of security advisories affecting three flagship enterprise products, Endpoint Manager Mobile , Neurons for ITSM, and Sentry, exposing organizations to risks ranging from privilege escalation…
The US military just turned off ad tracking on its phones. Maybe you should too
Location data sold by the ad industry has reportedly helped adversaries target US troops. The Pentagon has responded by switching off ad tracking on its devices - and you can do the same on yours.
Dell Secure Connect Gateway Vulnerabilities Allow Hackers to Gain Unauthorized Access
Dell has disclosed three critical vulnerabilities in its Secure Connect Gateway 5.0 platform that could allow attackers to gain unauthorized access , execute commands remotely, and obtain root-level control of affected…
August updates trigger 0xc0000409 errors on Windows Server 2016
Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled.
Cylake Raises $245 Million Ahead of Cybersecurity Platform Beta
The startup founded by Palo Alto Networks’ Nir Zuk has raised $290 million to build an AI-native security platform for highly regulated organizations that cannot rely on the public cloud.
ChatGPT Sandbox Flaw Lets Attackers Steal Gmail Data Across Accounts via Hidden Channel
A covert cross-account communication channel inside ChatGPT let an attacker hijack a victim’s session and silently exfiltrate data from connected apps like Gmail, all while the victim saw nothing unusual in their…