# Today's Top Stories
September 10, 2026
-
1The Hacker News general Sep 09Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Microsoft's September 2026 Patch Tuesday set an all-time record with 974 CVEs addressed, including 723 Windows flaws, 111 Office vulnerabilities, and over 110 critical-severity issues. Two zero-days are confirmed actively exploited in the wild, and 20 vulnerabilities are flagged as potentially wormable. Security teams should immediately prioritize the two exploited zero-days and review exposure across Windows, Office, and SQL Server components.
-
2CyberScoop general Sep 09Chinese espionage groups swarm to exploit triple-link chain of zero-days
Multiple China-aligned APT groups rapidly exploited a triple-link zero-day chain targeting various organizations, with Proofpoint confirming the activity is ongoing and expected to expand in scope. The chained exploit approach suggests coordinated intelligence-sharing or exploit kit distribution among Chinese state-sponsored actors. Defenders should monitor for indicators across all three vulnerability components and treat any related detections as high-priority incidents.
-
3The Hacker News general Sep 09Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Four separate espionage-motivated threat groups, including China-aligned APT31 (aka Bronze Vinewood/JungleBamboo), deployed an undocumented exploit kit called BlueMoon that chains multiple Chrome and Windows vulnerabilities — all within a single week. The rapid adoption across multiple actors suggests either shared tooling infrastructure or a commercially distributed exploit package. Security teams running unpatched Chrome and Windows environments should treat this as critical given the confirmed in-the-wild exploitation by state-level actors.
-
4BleepingComputer general Sep 09Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
Cisco confirmed active exploitation of CVE-2026-20079, a maximum-severity authentication bypass vulnerability in its Secure Firewall Management Center (FMC) software. The flaw allows unauthenticated attackers to bypass access controls, making it a critical priority for any organization using Cisco FMC in their network security infrastructure. Administrators should apply available patches immediately and review FMC access logs for signs of unauthorized activity.
-
5The Hacker News general Sep 09Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Google's Chrome 153 release patches CVE-2026-87491, an out-of-bounds write vulnerability in the V8 JavaScript and WebAssembly engine that has been confirmed exploited in the wild — marking the seventh Chrome zero-day of 2026. The update bundles 230 total security fixes, and the V8 flaw enables code execution inside the browser sandbox. Users and enterprise administrators should prioritize updating Chrome immediately given the active exploitation.
-
ADSponsoredProtect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected → -
6SecurityWeek general Sep 08Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
Adobe's September 2026 Patch Tuesday addressed over 170 vulnerabilities, including CVE-2026-75650, a zero-day in Adobe Commerce that allows unauthenticated remote code execution and is already being exploited in the wild. E-commerce operators running Adobe Commerce should treat this as an emergency patch given that no authentication is required to exploit the flaw. The breadth of 170+ fixes across Adobe products also warrants a thorough review of the full advisory.
-
7BleepingComputer general Sep 09AdaptHealth confirms 4.1 million people exposed in July cyberattack
Healthcare company AdaptHealth confirmed that 4.1 million individuals had personal data exposed in a cyberattack discovered in July 2026, with attribution pointing to the ShinyHunters threat group. ShinyHunters has a well-documented history of large-scale data theft targeting healthcare and consumer platforms. Affected individuals face elevated risks of identity fraud and health data misuse, and the breach may trigger HIPAA breach notification obligations.
-
8The Hacker News general Sep 09F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
Sophos published a September 7 analysis detailing malware targeting F5 BIG-IP Access Policy Manager (APM) appliances that injects a PHP web shell directly into Apache's in-memory process, bypassing disk-based detection entirely. The malware hooks into three specific BIG-IP PHP scripts, meaning file integrity checks return clean results while the web shell remains active in memory. Organizations running F5 BIG-IP APM should implement memory-based detection and review Sophos's indicators of compromise immediately.
-
9The Hacker News general Sep 09SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
SAP patched CVE-2026-44756, a CVSS 10.0 memory corruption vulnerability in SAP Extended Passport (EPP) Processing that enables unauthenticated remote code execution with severe impact on confidentiality, integrity, and availability. A maximum CVSS score combined with no authentication requirement makes this an immediate patching priority for any organization running SAP EPP. SAP customers should apply September 2026 Security Patch Day updates without delay.
-
10The Hacker News general Sep 09U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
U.S. cybersecurity and intelligence agencies accused six China-based AI companies of conducting industrial-scale distillation attacks against American frontier AI models including Claude, GPT, Google Gemini, and SpaceX's Grok, extracting billions of tokens since at least late 2024. The agencies describe distillation — systematically querying models to train competing systems — as the 'core' of these firms' AI development strategy, achieved by routing requests across multiple accounts and platforms to evade detection. AI providers should review API usage patterns for signs of systematic extraction and consider rate-limiting or behavioral anomaly detection for high-volume querying.