Security news

Latest security news

Tue, 8 Sept 2026

  1. OpenAI Agents Took Over Wiki Site Before Hugging Face Attack

    Researchers and OpenAI disagree on whether the earlier incident involving DseWiki was a “hack” that the company did not disclose.

    Dark Reading
  2. DoppelCart fraud network uses 119,000 fake shops to steal credit cards

    A massive operation dubbed "DoppelCart" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details.

    BleepingComputer
  3. Russian national extradited to US for alleged involvement in bank-account takeover scheme

    Authorities accuse the 36-year-old and co-conspirators of collecting more than 5,000 victim login credentials to various banks.

    CyberScoop
  4. The EU CRA's Real Question: What Shipped, and When Did You Know?

    The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements.

    BleepingComputer
  5. Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

    A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk.

    BleepingComputerF5, Linux
  6. CIA’s Michael Ellis says cyber intelligence is changing how the agency operates

    The deputy director cited Operation Absolute Resolve as evidence that cyber teams have become central to CIA missions.

    CyberScoop
  7. Ivanti security advisory (AV26-897)

    Serial Number: AV26-897 Date: September 8, 2026 As of September 8, 2026, Ivanti is affected by vulnerabilities in the following products: Endpoint Manager Mobile Prior to 12.10.0.0 Prior to 12.9.0.2 Prior to 12.8.0.4 Neurons for ITSM (Cloud/SaaS) Prior to mo2026.2 Neurons for ITSM On-Prem Prior to 2025.2 Sept 2026 Security Patch Prior to 2025.3 Sept 2026 Security Patch Prior to 2025.4 Sept 2026 Security Patch Prior to 2026.1 Sept 2026 Security Patch Prior to 2026.2 Sentry Prior to R10.8.2 Prior to R10.7.3 Prior to R10.6.4 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Advisory Ivanti Neurons for ITSM (Multiple CVEs) Security Advisory - Ivanti Endpoint Manager Mobile (CVE-2026-18851) Security Advisory Ivanti Sentry (CVE-2026-83527) September 2026 Security Update

    Canadian Centre for Cyber SecurityIvanti
  8. September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)

    This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.

    SANS Internet Storm CenterMicrosoft, Windows
  9. Microsoft security advisory – September 2026 monthly rollup (AV26-896) – Update 1

    Serial Number: AV26-896 Date: September 8, 2026 As of September 8, 2026, Microsoft is affected by vulnerabilities in the following products: .NET 10.0 installed on Linux .NET 10.0 installed on Mac OS .NET 10.0 installed on Windows .NET 11.0 installed on Linux .NET 11.0 installed on Mac OS .NET 11.0 installed on Windows .NET 8.0 installed on Linux .NET 8.0 installed on Mac OS .NET 8.0 installed on Windows .NET 9.0 installed on Linux .NET 9.0 installed on Mac OS .NET 9.0 installed on Windows ASP.NET Core 10.0 ASP.NET Core 11.0 ASP.NET Core 8.0 ASP.NET Core 9.0 Azure AI Language Authoring Azure Arc SQL Server Extension Azure Cosmos DB Azure CycleCloud Azure HDInsight HEIF Image Extension HEVC Video Extensions HEVC Video Extensions for Licensed Applications HEVC Video Extensions from Device Manufacturer Microsoft .NET Framework 3.5 AND 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 3.5 AND 4.7.2 Microsoft .NET Framework 3.5 AND 4.8 Microsoft .NET Framework 3.5 AND 4.8.1 Microsoft .NET Framework 4.6.2/4.7/4.7.1/4.7.2 Microsoft .NET Framework 4.8 Microsoft .NET Framework 4.8.1 Microsoft 365 Apps for Enterprise Microsoft Access 2016 Microsoft Authentication Library (MSAL) Microsoft Authen

    Canadian Centre for Cyber SecurityMicrosoft, Windows, Linux
  10. Adobe security advisory (AV26-888) – Update 1

    Serial Number: AV26-888 Date: September 8, 2026 As of September 8, 2026, Adobe is affected by a vulnerability in the following products: Adobe Acrobat Multiple versions Adobe Animate 2023 Prior to or equal to 2023.0.16 Adobe Animate 2024 Prior to or equal to 0.14 Adobe Campaign Classic Prior to or equal to ACC v7: 7.4.4 build 9401 Adobe ColdFusion 2023 Prior to or equal to 2023.0.23 Adobe ColdFusion 2025 Prior to or equal to 0.12 Adobe Commerce All except Hotfix for CVE-2026-7565 Prior to or equal to 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug Adobe Commerce B2B All except Hotfix for CVE-2026-7565 Prior to or equal to 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug Adobe Experience Manager (AEM) Prior to or equal to AEM Cloud Service (CS) Release 2026.7.0 Prior to or equal to 5 LTS Service Pack 2 Prior to or equal to 5 Service Pack 24 and earlier Adobe Illustrator 2025 Prior to or equal to 8.10 Adobe Illustrator 2026 Prior to or equal to 7 Adobe Photoshop 2025 Prior to or equal to 11.6 Adobe Photoshop 2026 Prior to or equal to 6 Magento Open Source All except Hotfix for CVE-2026-7565 Prior to or equal

    Canadian Centre for Cyber SecurityAdobe

About this news

1,434
Stories
65
Added in the last 24 hours
11
Critical in the last 7 days
4
Reported by several outlets