Security news
Latest security news
Thu, 10 Sept 2026
- September Windows Server updates break Remote Desktop Services
Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality.
BleepingComputerWindows - Conti ransomware crew member sentenced to four years in prison
Oleksii Lytvynenko joined the notorious group in 2021 and was directly involved in attacks on at least 12 companies.
CyberScoop - Mandiant Founder Kevin Mandia Joins Amazon Board
Mandiant founder and cybersecurity veteran brings more than 30 years of public and private sector experience to Amazon’s board.
SecurityWeekAmazon - Hawley probes OpenAI over Hugging Face breach
The Republican lawmaker called OpenAI’s leadership decisions “reckless,” and used recent warnings about the existential risk of AI to bolster his inquiry.
CyberScoop - AL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060
Number: AL26-020 Date: September 10, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Cyber Centre is aware of vulnerabilities impacting MikroTik RouterOS devices, especially if the SSH service is exposed to the Internet Footnote 1 . In response to the vendor advisory released on September 3, 2026, the Cyber Centre released AV26-887 on September 8, 2026 Footnote 2 . Tracked as CVE-2026-67277 Footnote 3 , this vulnerability is a Missing Authentication for Critical Function vulnerability (CWE-306) Footnote 4 that may allow a remote attacker to obtain potentially sensitive information. Tracked as CVE-2026-86060 Footnote 5 , this vulnerability is an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability (CWE-88) Footnote 6 that may allow a remote at
CriticalUsed in attacksCanadian Centre for Cyber SecurityMikroTik - Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent
War is peace. Freedom is slavery. Privacy is surveillance
The RegisterApple - AI lets small actors run state-level hacking campaigns, Anthropic report finds
The report details a Russian-aligned espionage campaign against more than 20 organizations, an exploit foundry run by Chinese undergraduates and ShinyHunters-affiliated breaches, among other disrupted operations.
CyberScoop - Surfshark VPN says hackers breached internal testing, proxy servers
Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet.
BleepingComputer - Microsoft Excel KB5002914 update breaks copy and paste for some users
Microsoft Excel users report that this week's KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality.
BleepingComputerMicrosoft
About this news
- 1,354
- Stories
- 66
- Added in the last 24 hours
- 10
- Critical in the last 7 days
- 4
- Reported by several outlets