# Archive

Browse past daily curated stories

Sep 09 Sep 08 Sep 06 Sep 05 Sep 04 Sep 03 Sep 01 Aug 31 Aug 30 Aug 29 Aug 28 Aug 27 Aug 26 Aug 25 Aug 24 Aug 23 Aug 22 Aug 21 Aug 20 Aug 19 Aug 18 Aug 16 Aug 15 Aug 14 Aug 13 Aug 12 Aug 09 Aug 08 Aug 07 Aug 06

Wednesday, September 09, 2026

  1. 1
    0
    Krebs on Security threat-intel
    Microsoft Plugs Nearly 1,000 Security Holes

    Microsoft's September 2026 Patch Tuesday set a new all-time record with 974 CVEs patched, with AI-assisted vulnerability discovery credited for the surge. Two zero-days are actively exploited, 20 vulnerabilities are potentially wormable, and 112 are rated Critical — raising urgent concerns about organizations' capacity to test and deploy patches at this scale. Security experts warn that AI-accelerated patch volume is outpacing human-intensive remediation workflows.

  2. 2
    0
    The Hacker News general
    Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

    Adobe patched CVE-2026-75650 (CVSS 10.0), a zero-day dubbed 'StyleSmuggler' in Adobe Commerce and Magento Open Source, with active exploitation detected by Sansec starting September 4, 2026. Attackers exploited the flaw to deploy a Rust backdoor and PHP web shell on compromised servers. An emergency out-of-band patch was released before the regular Patch Tuesday cycle.

  3. 3
    0
    BleepingComputer general
    Adobe fixes critical Magento zero-day exploited to backdoor servers

    Adobe's emergency fix for CVE-2026-75650, the 'StyleSmuggler' Magento/Adobe Commerce zero-day, addresses an actively exploited max-severity RCE flaw used to backdoor e-commerce servers. The vulnerability affects multiple versions of both Magento and Adobe Commerce and requires no authentication to exploit. Merchants running these platforms should patch immediately given active in-the-wild exploitation beginning September 4.

  4. 4
    0
    The Hacker News general
    WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

    Security firm Calif demonstrated a zero-click worm targeting WeChat that spreads via incoming calls on both iPhone and Android — the recipient does not need to answer or interact with their device for account takeover to occur. The attacker must be an existing WeChat contact, and the worm successfully propagated across three test phones in a proof-of-concept. Tencent was notified in July 2026 and has since patched the flaw.

  5. 5
    0
    BleepingComputer general
    DoppelCart fraud network uses 119,000 fake shops to steal credit cards

    Researchers uncovered 'DoppelCart,' a massive fraud network operating over 119,000 domains hosting fake e-commerce shops designed to harvest payment card data from unsuspecting shoppers. The operation represents one of the largest skimming infrastructure networks ever documented. Security teams should review card-not-present fraud controls and block the associated domain clusters.

  6. 6
    0
    The Hacker News general
    Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

    Google Threat Intelligence Group (GTIG) documented a financially motivated threat actor deploying an autonomous multi-agent AI attack framework that harvested thousands of credentials in under six hours. The framework automates all attack stages end-to-end without human operator involvement, representing a significant escalation in AI-assisted offensive capabilities. This signals a shift from AI coding assistants to fully autonomous attack pipelines.

  7. 7
    0
    The Hacker News general
    N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

    CISA added CVE-2026-86218 (CVSS 10.0) in N-able N-central to its Known Exploited Vulnerabilities catalog, a pre-authentication RCE flaw with a FCEB agency remediation deadline of September 11, 2026. N-able N-central is widely used by managed service providers to remotely manage client endpoints, making exploitation particularly high-impact. Administrators are advised to check for newly created unauthorized accounts as indicators of compromise.

  8. 8
    0
    BleepingComputer general
    220 million traveler records exposed in Vietnam-linked APIS leak

    An exposed Advance Passenger Information System (APIS) database linked to Vietnam leaked 220 million passenger and crew records including names, passport numbers, dates of birth, nationalities, and flight details spanning 2017–2026. Researchers accessed the cloud-hosted system using default credentials, exposing a systemic failure in securing sensitive border control data. The dataset's scope — nearly a decade of international travel records — makes it a significant counterintelligence and identity theft risk.

  9. 9
    0
    The Hacker News general
    ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account

    Check Point Research demonstrated a prompt injection attack against ChatGPT where a single planted instruction caused the model to silently exfiltrate a victim's Gmail data to an attacker-controlled ChatGPT account via a covert channel, while continuing to respond normally to the user. The attack exploits ChatGPT's tool integrations and highlights the data exfiltration risks inherent in AI assistants with access to connected productivity apps. Organizations allowing ChatGPT-Gmail integration should reassess the risk surface.

  10. 10
    0
    SecurityWeek general
    MikroTik Patches Critical Flaws Chained to Hack Routers

    MikroTik patched a chain of critical vulnerabilities dubbed 'MikroTrick' that allow unauthenticated attackers to bypass authentication, overwrite configuration files, and fully compromise RouterOS devices. MikroTik routers are ubiquitous in ISP and enterprise network infrastructure globally, making this class of vulnerability a high-priority target for threat actors seeking persistent network access. Administrators should apply patches immediately and audit router configurations for signs of compromise.