← Back to Blog

Security News — 17 September 2026

A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 11 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 17 September 2026 · 27 items.

Government & Critical Vulnerability Advisories

CVEDatabase - Critical CVEs17 Sep

CVE-2026-87701 — CRITICAL (CVSS 9.6)

CVSS 9.6 CRITICAL · Vendor: Microsoft Improper neutralization of special elements in output used by a downstream component ('injection') in Azure Cosmos DB allows an authorized attacker to elevate privileges over a network.

Read at source →
CVEDatabase - Critical CVEs17 Sep

CVE-2026-85885 — CRITICAL (CVSS 9.9)

CVSS 9.9 CRITICAL · Vendor: Microsoft Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an authorized attacker to elevate privileges over a network.

Read at source →
CISA Cybersecurity Advisories17 Sep

Hitachi Energy FACTS Control Platform (FCP)

View CSAF Summary Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and…

Read at source →
CISA Cybersecurity Advisories17 Sep

Bransys ELD

View CSAF Summary Successful exploitation of these vulnerabilities could allow unauthorized access to telemetry data and firmware. The following versions of Bransys ELD are affected: Android <11.00.00 (CVE-2026-86520, CVE-2026-86689, CVE-2…

Read at source →

Primary Threat Research & Vendor Intelligence

Independent Investigative Journalism & Breaking News

Blue Team, Incident Response & Detection Engineering

TrustedSec Blog17 Sep

Unpacking a laZzzy Donut

<p>Six stages. Multiple encryption layers. One static analysis. In this blog, we unpack a multi-stage malware loader combining Python obfuscation, Donut shellcode, and laZzzy PE encryption, without executing the payload.</p>

Read at source →

Security Executive, Architecture & Policy

Schneier on Security17 Sep

How Candidates Could Use AI for Good

This essay was written with Nathan E. Sanders, and originally appeared in The Guardian . There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI’s impacts on the co…

Read at source →
← All blog posts