Security news
Latest security news
Thu, 10 Sept 2026
- Cybercriminals are building phishing pages that exist only inside victims’ browsers
A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside their own browser, according to researchers at Barracuda. “Instead of delivering a phishing page from a web server, the malicious content is assembled inside the victim’s browser using a blob URL — a temporary browser-generated URL that points to content stored locally in memory rather than on a website,” researchers explained. The attack … More →
Help Net SecurityMicrosoft, Barracuda
Wed, 9 Sept 2026
- Serial Microsoft 0-day hunter drops yet another Defender exploit
A bypass of a bypass of a bypass
The RegisterMicrosoft - Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,
The Hacker NewsGoogle, Microsoft, Windows - Microsoft fixes record 964 flaws, including 2 exploited zero-days
Microsoft’s September 2026 Patch Tuesday fixes a record 964 vulnerabilities, including two actively exploited zero-days.
Malwarebytes LabsMicrosoft - Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026
The update contained 119 critical flaws and two zero days, with security teams needing to prioritize updates
Infosecurity MagazineMicrosoft - New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates.
BleepingComputerMicrosoft - Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed
The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic
The Hacker NewsMicrosoft - Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.
The Hacker NewsMicrosoft, Windows - Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults
Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth.
BleepingComputerMicrosoft, Windows - Microsoft breaks Patch Tuesday record with 974-CVE deluge
Adobe also brought goodies to the patch party and they deserve immediate attention
The RegisterMicrosoft, Adobe
About this news
- 1,256
- Stories
- 40
- Added in the last 24 hours
- 19
- Critical in the last 7 days
- 4
- Reported by several outlets