← Back to Blog
Security News
Security News — 17 September 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 11 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 17 September 2026 · 27 items.
Government & Critical Vulnerability Advisories
CVEDatabase - Critical CVEs17 Sep
CVSS 9.6 CRITICAL · Vendor: Microsoft Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.
Read at source →
CVEDatabase - Critical CVEs17 Sep
CVSS 10.0 CRITICAL · Vendor: Microsoft Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network.
Read at source →
CVEDatabase - Critical CVEs17 Sep
CVSS 9.9 CRITICAL · Vendor: Microsoft Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.
Read at source →
CVEDatabase - Critical CVEs17 Sep
CVSS 10.0 CRITICAL · Vendor: Microsoft Improper access control in Azure Logic Apps allows an unauthorized attacker to elevate privileges over a network.
Read at source →
CISA Cybersecurity Advisories17 Sep
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific t…
Read at source →
CISA Cybersecurity Advisories17 Sep
View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in mem…
Read at source →
CISA Cybersecurity Advisories17 Sep
View CSAF Summary Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and…
Read at source →
CISA Cybersecurity Advisories17 Sep
View CSAF Summary Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware. The following versions of Bransys ELD are affected: Android <11.00.00 (CVE-2026-86520, CVE-2026-86689, CVE-2…
Read at source →
Primary Threat Research & Vendor Intelligence
Palo Alto Unit 4217 Sep
Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths. The post Inside the Modern SOC: Defending the Cross-Environment Pivot appeared first…
Read at source →
Cisco Talos17 Sep
In this week's Threat Source, David talks about why focusing on your security basics is still your best bet, even in a world with rapid AI advancements.
Read at source →
Microsoft Security Blog17 Sep
AI has made fundamental changes to the operating environment for cybersecurity. Explore exposure management guidance on recommended controls and take action and stay ahead of cyberthreats. The post From guidance to action: Security fundame…
Read at source →
Microsoft Security Blog17 Sep
The latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where threats and defenses continue to evolve. The post Improving email security outcomes…
Read at source →
Cisco Talos17 Sep
Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY…
Read at source →
Independent Investigative Journalism & Breaking News
BleepingComputer17 Sep
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. [...]
Read at source →
Dark Reading17 Sep
The move is consistent with the agency's advice on the need for organizations to prioritize the vulnerabilities that actually matter.
Read at source →
Dark Reading17 Sep
Amid the US and China's fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight.
Read at source →
BleepingComputer17 Sep
OpenAI has presented new examples of what they call "AI model misalignment" from the past six months, including unauthorized file uploads, following self-generated instructions, hiding mistakes, and leveraging exposed API keys. [...]
Read at source →
BleepingComputer17 Sep
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...]
Read at source →
BleepingComputer17 Sep
AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that both the user and th…
Read at source →
The Hacker News17 Sep
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolv…
Read at source →
The Hacker News17 Sep
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure a…
Read at source →
The Hacker News17 Sep
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that ga…
Read at source →
The Hacker News17 Sep
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. "Spa…
Read at source →
Blue Team, Incident Response & Detection Engineering
SANS Internet Storm Center (Handler Diary)17 Sep
At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a…
Read at source →
TrustedSec Blog17 Sep
<p>Six stages. Multiple encryption layers. One static analysis. In this blog, we unpack a multi-stage malware loader combining Python obfuscation, Donut shellcode, and laZzzy PE encryption, without executing the payload.</p>
Read at source →
SANS Internet Storm Center (Handler Diary)17 Sep
Read at source →
Security Executive, Architecture & Policy
Schneier on Security17 Sep
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian . There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI’s impacts on the co…
Read at source →