# Archive

Browse past daily curated stories

Sep 10 Sep 09 Sep 08 Sep 06 Sep 05 Sep 04 Sep 03 Sep 01 Aug 31 Aug 30 Aug 29 Aug 28 Aug 27 Aug 26 Aug 25 Aug 24 Aug 23 Aug 22 Aug 21 Aug 20 Aug 19 Aug 18 Aug 16 Aug 15 Aug 14 Aug 13 Aug 12 Aug 09 Aug 08 Aug 07

Thursday, September 10, 2026

  1. 1
    0
    The Hacker News general
    Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

    Microsoft's September 2026 Patch Tuesday set an all-time record with 974 CVEs addressed, including 723 Windows flaws, 111 Office vulnerabilities, and over 110 critical-severity issues. Two zero-days are confirmed actively exploited in the wild, and 20 vulnerabilities are flagged as potentially wormable. Security teams should immediately prioritize the two exploited zero-days and review exposure across Windows, Office, and SQL Server components.

  2. 2
    0
    CyberScoop general
    Chinese espionage groups swarm to exploit triple-link chain of zero-days

    Multiple China-aligned APT groups rapidly exploited a triple-link zero-day chain targeting various organizations, with Proofpoint confirming the activity is ongoing and expected to expand in scope. The chained exploit approach suggests coordinated intelligence-sharing or exploit kit distribution among Chinese state-sponsored actors. Defenders should monitor for indicators across all three vulnerability components and treat any related detections as high-priority incidents.

  3. 3
    0
    The Hacker News general
    Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

    Four separate espionage-motivated threat groups, including China-aligned APT31 (aka Bronze Vinewood/JungleBamboo), deployed an undocumented exploit kit called BlueMoon that chains multiple Chrome and Windows vulnerabilities — all within a single week. The rapid adoption across multiple actors suggests either shared tooling infrastructure or a commercially distributed exploit package. Security teams running unpatched Chrome and Windows environments should treat this as critical given the confirmed in-the-wild exploitation by state-level actors.

  4. 4
    0
    BleepingComputer general
    Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

    Cisco confirmed active exploitation of CVE-2026-20079, a maximum-severity authentication bypass vulnerability in its Secure Firewall Management Center (FMC) software. The flaw allows unauthenticated attackers to bypass access controls, making it a critical priority for any organization using Cisco FMC in their network security infrastructure. Administrators should apply available patches immediately and review FMC access logs for signs of unauthorized activity.

  5. 5
    0
    The Hacker News general
    Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

    Google's Chrome 153 release patches CVE-2026-87491, an out-of-bounds write vulnerability in the V8 JavaScript and WebAssembly engine that has been confirmed exploited in the wild — marking the seventh Chrome zero-day of 2026. The update bundles 230 total security fixes, and the V8 flaw enables code execution inside the browser sandbox. Users and enterprise administrators should prioritize updating Chrome immediately given the active exploitation.

  6. 6
    0
    SecurityWeek general
    Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

    Adobe's September 2026 Patch Tuesday addressed over 170 vulnerabilities, including CVE-2026-75650, a zero-day in Adobe Commerce that allows unauthenticated remote code execution and is already being exploited in the wild. E-commerce operators running Adobe Commerce should treat this as an emergency patch given that no authentication is required to exploit the flaw. The breadth of 170+ fixes across Adobe products also warrants a thorough review of the full advisory.

  7. 7
    0
    BleepingComputer general
    AdaptHealth confirms 4.1 million people exposed in July cyberattack

    Healthcare company AdaptHealth confirmed that 4.1 million individuals had personal data exposed in a cyberattack discovered in July 2026, with attribution pointing to the ShinyHunters threat group. ShinyHunters has a well-documented history of large-scale data theft targeting healthcare and consumer platforms. Affected individuals face elevated risks of identity fraud and health data misuse, and the breach may trigger HIPAA breach notification obligations.

  8. 8
    0
    The Hacker News general
    F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

    Sophos published a September 7 analysis detailing malware targeting F5 BIG-IP Access Policy Manager (APM) appliances that injects a PHP web shell directly into Apache's in-memory process, bypassing disk-based detection entirely. The malware hooks into three specific BIG-IP PHP scripts, meaning file integrity checks return clean results while the web shell remains active in memory. Organizations running F5 BIG-IP APM should implement memory-based detection and review Sophos's indicators of compromise immediately.

  9. 9
    0
    The Hacker News general
    SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

    SAP patched CVE-2026-44756, a CVSS 10.0 memory corruption vulnerability in SAP Extended Passport (EPP) Processing that enables unauthenticated remote code execution with severe impact on confidentiality, integrity, and availability. A maximum CVSS score combined with no authentication requirement makes this an immediate patching priority for any organization running SAP EPP. SAP customers should apply September 2026 Security Patch Day updates without delay.

  10. 10
    0
    The Hacker News general
    U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

    U.S. cybersecurity and intelligence agencies accused six China-based AI companies of conducting industrial-scale distillation attacks against American frontier AI models including Claude, GPT, Google Gemini, and SpaceX's Grok, extracting billions of tokens since at least late 2024. The agencies describe distillation — systematically querying models to train competing systems — as the 'core' of these firms' AI development strategy, achieved by routing requests across multiple accounts and platforms to evade detection. AI providers should review API usage patterns for signs of systematic extraction and consider rate-limiting or behavioral anomaly detection for high-volume querying.