Security news

Latest security news

Tue, 8 Sept 2026

  1. September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)

    This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.

    SANS Internet Storm CenterMicrosoft, Windows
  2. Adobe security advisory (AV26-888) – Update 1

    Serial Number: AV26-888 Date: September 8, 2026 As of September 8, 2026, Adobe is affected by a vulnerability in the following products: Adobe Acrobat Multiple versions Adobe Animate 2023 Prior to or equal to 2023.0.16 Adobe Animate 2024 Prior to or equal to 0.14 Adobe Campaign Classic Prior to or equal to ACC v7: 7.4.4 build 9401 Adobe ColdFusion 2023 Prior to or equal to 2023.0.23 Adobe ColdFusion 2025 Prior to or equal to 0.12 Adobe Commerce All except Hotfix for CVE-2026-7565 Prior to or equal to 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug Adobe Commerce B2B All except Hotfix for CVE-2026-7565 Prior to or equal to 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug Adobe Experience Manager (AEM) Prior to or equal to AEM Cloud Service (CS) Release 2026.7.0 Prior to or equal to 5 LTS Service Pack 2 Prior to or equal to 5 Service Pack 24 and earlier Adobe Illustrator 2025 Prior to or equal to 8.10 Adobe Illustrator 2026 Prior to or equal to 7 Adobe Photoshop 2025 Prior to or equal to 11.6 Adobe Photoshop 2026 Prior to or equal to 6 Magento Open Source All except Hotfix for CVE-2026-7565 Prior to or equal

    Canadian Centre for Cyber SecurityAdobe
  3. ClickFix Campaigns Abuse Legitimate Services for Persistent Access

    Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.

    Dark Reading
  4. Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

    A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment

    The Hacker News
  5. Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

    Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI

    The Hacker NewsGoogle
  6. AI Coding Tools Now a Prime Target for Threat Actors, Google Warns

    Google warned that the rapid integration of AI-assisted coding tools has significantly expanded software supply chain risks

    Infosecurity MagazineGoogle
  7. ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2

    Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session.

    Cisco TalosGoogle, Cisco
  8. BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials

    CloudSEK has uncovered BigBear 2.0, a new phishing-as-a-service operation targeting Microsoft 365

    Infosecurity MagazineMicrosoft
  9. BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

    Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect

    The Hacker News
  10. ISC Stormcast For Tuesday, September 8th, 2026 https://isc.sans.edu/podcastdetail/10084, (Tue, Sep 8th)

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

    SANS Internet Storm Center

About this news

1,259
Stories
33
Added in the last 24 hours
17
Critical in the last 7 days
4
Reported by several outlets