Security news
Latest security news
Wed, 9 Sept 2026
- Android’s September 2026 Updates Patch 180 Vulnerabilities
The security updates resolve critical flaws across Android’s Framework, System, and Kernel components.
SecurityWeekAndroid - Over 36,000 exposed Plex servers vulnerable to recent flaws
Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks.
BleepingComputer - Microsoft fixes record 964 flaws, including 2 exploited zero-days
Microsoft’s September 2026 Patch Tuesday fixes a record 964 vulnerabilities, including two actively exploited zero-days.
Malwarebytes LabsMicrosoft - Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026
The update contained 119 critical flaws and two zero days, with security teams needing to prioritize updates
Infosecurity MagazineMicrosoft - Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.
The Hacker NewsMicrosoft, Windows
Tue, 8 Sept 2026
- The EU CRA's Real Question: What Shipped, and When Did You Know?
The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements.
BleepingComputer - Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities.
BleepingComputerMicrosoft2 outlets - Grindr settles HIV status data-sharing lawsuit for $35 million
Grindr has settled a UK lawsuit alleging that it shared sensitive user data, including HIV status, with advertising companies.
Malwarebytes Labs - MikroTik router flaws allow takeover without a password
Attackers are exploiting critical RouterOS flaws to take control of routers with SSH exposed to the internet.
Malwarebytes Labs - Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with third-parties. Grindr, which is the largest LGBTQ+ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising.
The Hacker News
About this news
- 1,256
- Stories
- 35
- Added in the last 24 hours
- 18
- Critical in the last 7 days
- 4
- Reported by several outlets