← Back to Blog
Security News
Security News — 8 September 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 12 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 8 September 2026 · 32 items.
Government & Critical Vulnerability Advisories
CVEDatabase - Critical CVEs08 Sep
CVSS 9.9 CRITICAL · Vendor: Adobe ColdFusion is affected by an Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability that could result in arbitrary code execution in the context of the current…
Read at source →
CVEDatabase - Critical CVEs08 Sep
CVSS 9.9 CRITICAL · Vendor: Adobe Adobe Experience Manager is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user, potentially gaining elevated access or con…
Read at source →
CVEDatabase - Critical CVEs08 Sep
CVSS 10.0 CRITICAL · Vendor: Adobe Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the…
Read at source →
CVEDatabase - Critical CVEs08 Sep
CVSS 9.8 CRITICAL · Vendor: Microsoft Use after free in Windows Failover Cluster allows an unauthorized attacker to execute code over a network.
Read at source →
CISA Current Activity08 Sep
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Templa…
Read at source →
CISA Cybersecurity Advisories08 Sep
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take full control of the device. The following versions of CareCam Pro IP Cameras are affected: ANJIA AJL33PC0801 Firmware linux_linux_202008261138_…
Read at source →
CISA Cybersecurity Advisories08 Sep
Executive summary China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaign…
Read at source →
Primary Threat Research & Vendor Intelligence
Cisco Talos08 Sep
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
Read at source →
Cisco Talos08 Sep
We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.
Read at source →
Cisco Talos08 Sep
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the v…
Read at source →
Google Project Zero08 Sep
Many security bugs are race conditions, where multi-threaded execution has to occur with the right interleaving for a negative effect to appear. This creates challenges for several use cases: Confirming bug candidates that have been discov…
Read at source →
Independent Investigative Journalism & Breaking News
Krebs on Security08 Sep
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discov…
Read at source →
Dark Reading08 Sep
Attackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.
Read at source →
Dark Reading08 Sep
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.
Read at source →
Dark Reading08 Sep
Researchers and OpenAI disagree on whether the earlier incident involving DseWiki was a “hack” that the company did not disclose.
Read at source →
BleepingComputer08 Sep
A massive operation dubbed "DoppelCart" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details. [...]
Read at source →
BleepingComputer08 Sep
The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when v…
Read at source →
BleepingComputer08 Sep
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. [...]
Read at source →
BleepingComputer08 Sep
Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes. [...]
Read at source →
Dark Reading08 Sep
Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.
Read at source →
The Hacker News08 Sep
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster u…
Read at source →
The Hacker News08 Sep
Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds real bitcoi…
Read at source →
The Hacker News08 Sep
Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of c…
Read at source →
The Hacker News08 Sep
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential…
Read at source →
Blue Team, Incident Response & Detection Engineering
SANS Internet Storm Center (Handler Diary)08 Sep
This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities ar…
Read at source →
SANS Internet Storm Center (Handler Diary)08 Sep
Read at source →
Security Executive, Architecture & Policy
Daniel Miessler08 Sep
A charcoal sketch of four slumped people being fed sheets of paper by a tall purple machine, while across the room one person writes at a wooden desk and a small purple Socrates leans in with open, empty hands/images/the-socrates-agent.web…
Read at source →
Schneier on Security08 Sep
This essay was written with Barath Raghavan, and originally appeared in Lawfare . In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’…
Read at source →
Schneier on Security08 Sep
Interesting research: “ Stealing Reasoning Traces from Proprietary LLM APIs “: Abstract: Leading large language model providers now conceal their models’ step-by-step reasoning, or chain-of-thought, to protect intellectual property and lim…
Read at source →
Daniel Miessler08 Sep
Charcoal cutaway of a three-story building: a small purple glass lab on top where researchers admire a humanoid robot, and two much larger sienna floors below crowded with a family at a kitchen table, an old man in a sickbed, a child readi…
Read at source →
Daniel Miessler08 Sep
A charcoal sketch of a man whose head is an open purple ledger with a rubber stamp on it, dropping coins into a donation box held by a smiling person on his left while his other arm shoves a startled waiter away on his right/images/the-goo…
Read at source →
Daniel Miessler08 Sep
Charcoal sketch of a man in a long coat holding a carpenter's level against an upright purple machine, while behind him a toppled column smokes and small figures huddle in the rubble/images/humans-arent-aligned-either-header.webp/images/hu…
Read at source →