Security news
Latest security news
Wed, 9 Sept 2026
- Check Point security advisory (AV26-902)
Serial Number: AV26-902 Date: September 9, 2026 As of September 9, 2026, Check Point is affected by vulnerabilities in the following products: Security Gateway Multiple versions Check Point Spark Firewall using Site to Site VPN or Remote Access VPN Multiple versions Security Management Server Multiple versions Check Point Spark Firewall Multiple versions The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. CVE-2026-85102 - Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN CVE-2026-85103 - ASN.1 decoding heap overflow leading to a remote code execution Check Point Security
Canadian Centre for Cyber Security - N-able security advisory (AV26-885) – Update 2
Serial Number: AV26-885 Date: September 8, 2026 Updated: September 9, 2026 As of September 6, 2026, N-able is affected by vulnerabilities in the following product: N-central Prior to 2026.3.1.14 N-able indicates that CVE-2026-86218 is being exploited in the wild. Update 1 On September 8, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-86218 to their Known Exploited Vulnerabilities (KEV) Database. Update 2 Open-source reporting indicates that CVE-2026-86207 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. N-central 2026.3 Hotfix 4 – CVE-2026-86218 2026.3 HF4 Release Notes Release Notes | N-able Status | N-able Status Page CISA KEV: CVE-2026-86218
CriticalUsed in attacksCanadian Centre for Cyber SecurityN-able - FTC rescinds policy requiring health apps to notify customers after a breach
The policy, passed under the Biden administration, forced health apps to disclose when users’ personal health records were exposed in a breach or shared without authorization.
CyberScoop - Lawmakers call on Treasury to sanction hackers-for-hire
The groups have allegedly targeted American citizens and companies, including the wife of GOP Senate candidate Mike Rogers, a former representative running in a Michigan swing race.
CyberScoop - U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime
The Hacker News - Grindr settles privacy lawsuit tied to disclosure of users’ HIV statuses for $35 million
The settlement concludes a legal fight that dates to April 2024, when UK users sued for the alleged violations of their country’s privacy laws.
The Record - Scans for Proxmox Servers, (Wed, Sep 9th)
About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment product. The vulnerability only affects version 7, which has not been supported for a couple of years now.
SANS Internet Storm Center - HelmGuard Raises $7.3 Million for Agentic GRC and Security
The company will increase its US market presence and will expand its engineering and go-to-market teams.
SecurityWeek - Serial Microsoft 0-day hunter drops yet another Defender exploit
A bypass of a bypass of a bypass
The RegisterMicrosoft
About this news
- 1,393
- Stories
- 56
- Added in the last 24 hours
- 10
- Critical in the last 7 days
- 4
- Reported by several outlets