# Today's Top Stories
September 09, 2026
-
1Krebs on Security threat-intel Sep 08Microsoft Plugs Nearly 1,000 Security Holes
Microsoft's September 2026 Patch Tuesday set a new all-time record with 974 CVEs patched, with AI-assisted vulnerability discovery credited for the surge. Two zero-days are actively exploited, 20 vulnerabilities are potentially wormable, and 112 are rated Critical — raising urgent concerns about organizations' capacity to test and deploy patches at this scale. Security experts warn that AI-accelerated patch volume is outpacing human-intensive remediation workflows.
-
2The Hacker News general Sep 08Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Adobe patched CVE-2026-75650 (CVSS 10.0), a zero-day dubbed 'StyleSmuggler' in Adobe Commerce and Magento Open Source, with active exploitation detected by Sansec starting September 4, 2026. Attackers exploited the flaw to deploy a Rust backdoor and PHP web shell on compromised servers. An emergency out-of-band patch was released before the regular Patch Tuesday cycle.
-
3BleepingComputer general Sep 08Adobe fixes critical Magento zero-day exploited to backdoor servers
Adobe's emergency fix for CVE-2026-75650, the 'StyleSmuggler' Magento/Adobe Commerce zero-day, addresses an actively exploited max-severity RCE flaw used to backdoor e-commerce servers. The vulnerability affects multiple versions of both Magento and Adobe Commerce and requires no authentication to exploit. Merchants running these platforms should patch immediately given active in-the-wild exploitation beginning September 4.
-
4The Hacker News general Sep 08WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
Security firm Calif demonstrated a zero-click worm targeting WeChat that spreads via incoming calls on both iPhone and Android — the recipient does not need to answer or interact with their device for account takeover to occur. The attacker must be an existing WeChat contact, and the worm successfully propagated across three test phones in a proof-of-concept. Tencent was notified in July 2026 and has since patched the flaw.
-
5BleepingComputer general Sep 08DoppelCart fraud network uses 119,000 fake shops to steal credit cards
Researchers uncovered 'DoppelCart,' a massive fraud network operating over 119,000 domains hosting fake e-commerce shops designed to harvest payment card data from unsuspecting shoppers. The operation represents one of the largest skimming infrastructure networks ever documented. Security teams should review card-not-present fraud controls and block the associated domain clusters.
-
ADSponsoredProtect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected → -
6The Hacker News general Sep 08Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Google Threat Intelligence Group (GTIG) documented a financially motivated threat actor deploying an autonomous multi-agent AI attack framework that harvested thousands of credentials in under six hours. The framework automates all attack stages end-to-end without human operator involvement, representing a significant escalation in AI-assisted offensive capabilities. This signals a shift from AI coding assistants to fully autonomous attack pipelines.
-
7The Hacker News general Sep 09N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
CISA added CVE-2026-86218 (CVSS 10.0) in N-able N-central to its Known Exploited Vulnerabilities catalog, a pre-authentication RCE flaw with a FCEB agency remediation deadline of September 11, 2026. N-able N-central is widely used by managed service providers to remotely manage client endpoints, making exploitation particularly high-impact. Administrators are advised to check for newly created unauthorized accounts as indicators of compromise.
-
8BleepingComputer general Sep 08220 million traveler records exposed in Vietnam-linked APIS leak
An exposed Advance Passenger Information System (APIS) database linked to Vietnam leaked 220 million passenger and crew records including names, passport numbers, dates of birth, nationalities, and flight details spanning 2017–2026. Researchers accessed the cloud-hosted system using default credentials, exposing a systemic failure in securing sensitive border control data. The dataset's scope — nearly a decade of international travel records — makes it a significant counterintelligence and identity theft risk.
-
9The Hacker News general Sep 08ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account
Check Point Research demonstrated a prompt injection attack against ChatGPT where a single planted instruction caused the model to silently exfiltrate a victim's Gmail data to an attacker-controlled ChatGPT account via a covert channel, while continuing to respond normally to the user. The attack exploits ChatGPT's tool integrations and highlights the data exfiltration risks inherent in AI assistants with access to connected productivity apps. Organizations allowing ChatGPT-Gmail integration should reassess the risk surface.
-
10SecurityWeek general Sep 08MikroTik Patches Critical Flaws Chained to Hack Routers
MikroTik patched a chain of critical vulnerabilities dubbed 'MikroTrick' that allow unauthenticated attackers to bypass authentication, overwrite configuration files, and fully compromise RouterOS devices. MikroTik routers are ubiquitous in ISP and enterprise network infrastructure globally, making this class of vulnerability a high-priority target for threat actors seeking persistent network access. Administrators should apply patches immediately and audit router configurations for signs of compromise.