Security news
Latest security news
Thu, 10 Sept 2026
- New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome.
BleepingComputerGoogle, Microsoft, Windows - 2026-004: Critical Vulnerability in SharePoint Exploited
On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA's Known Exploited Vulnerabilities (KEV) catalogue on 18 March 2026. Additionally, three further RCE flaws affecting Microsoft SharePoint were addressed in the March 2026 release. CERT-EU strongly recommends updating SharePoint servers as soon as possible, prioritising internet-facing assets. CERT-EU also encourages IT administrators to take necessary remediation actions.
CERT-EUMicrosoft, SharePoint - 2026-008: Critical vulnerabilities in Ivanti Sentry
On 9 June 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their Sentry products[1]. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device.
CERT-EUIvanti - 2026-009: Critical Vulnerabilities in Microsoft SharePoint
[UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, CVE-2026-45659, CVE-2026-56164, and CVE-2026-58644. CERT-EU strongly recommends updating affected servers immediately, rotating credentials for any assets that may have been exposed to the internet, and conducting a compromise assessment.
CriticalUsed in attacksCERT-EUMicrosoft, SharePoint - Palo Alto Networks security advisory (AV26-905)
Serial number: AV26-905 Date: September 10, 2026 As of September 10, 2026, Palo Alto Networks is affected by vulnerabilities in the following products: Cloud NGFW All on AWS*, All on Azure* PAN-OS Multiple versions Prisma Access Multiple versions Prisma Browser Prior to 151.26.5.170 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CVE-2026-0310 PAN-OS: Buffer Overflow Vulnerability via XML Processing PAN-SA-2026-0012 Chromium: Monthly Vulnerability Update (September 2026) Palo Alto Networks Security Advisories
Canadian Centre for Cyber SecurityAWS, Palo Alto - Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security
The Hacker News - PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to
The Hacker NewsPaperCut - Update Chrome now to protect against an actively exploited vulnerability
Chrome issues another monster update, fixing an actively exploited V8 vulnerability and 229 other flaws.
Malwarebytes LabsChrome - CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below - CVE-2026-20079 (CVSS score: 10.0) - An authentication
CriticalThe Hacker NewsCitrix, Cisco, Fortinet
Wed, 9 Sept 2026
- Grindr settles privacy lawsuit tied to disclosure of users’ HIV statuses for $35 million
The settlement concludes a legal fight that dates to April 2024, when UK users sued for the alleged violations of their country’s privacy laws.
The Record
About this news
- 1,256
- Stories
- 35
- Added in the last 24 hours
- 18
- Critical in the last 7 days
- 4
- Reported by several outlets