2026-09-10 05:35 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-10 06:35 UTC
Four espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly two weeks of the first observed use. Google’s Threat Intelligence Group, Microsoft’s MSTIC, and Volexity all contributed to […]
P25
2026-09-09 21:35 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-09-09 21:30 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research and Lior Leizerovich · indexed 2026-09-09 22:40 UTC
Microsoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms. The post Threat matrix: Mapping threats across cloud web applications appeared first on Microsoft Security Blog.
P0
2026-09-09 21:19 UTC
Other
Proofpoint Threat Insight · indexed 2026-09-11 04:30 UTC
P0
2026-09-09 17:41 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research, Krithika Ramakrishnan, Bharat Vaghela, Vaibhav Deshmukh, Subhajit Ghosh, Anusha Chakraborty, Akash Chaudhuri, Victor Chingtham and Ivan Macalintal · indexed 2026-09-09 18:45 UTC
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mitigation guidance. The post Passkey-themed social engineering leads to identity and cloud compromise appeared first on Microsoft Security Blog.
P0
2026-09-09 16:34 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 19:50 UTC
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,
P0
2026-09-09 15:16 UTC
Vendor Research
Rapid7 · Conor McCormick · indexed 2026-09-09 16:10 UTC
If your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them.Every scan begins with the same question: which ports on this host are open? Everything after it, from identifying services to checking for vulnerabilities to evaluating policy, depends on the answer being right. The traditional answer comes from the outside: the scan engine sends traffic to a range of ports and infers each port's state from how the host responds. That…
P0
2026-09-09 13:00 UTC
Vendor Research
Tenable Blog · Mark Beblow · indexed 2026-09-09 13:10 UTC
Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new CyberAgents Exchange registry, Tenable paired its exposure management expertise with OpenAI GPT Cyber models to create the CyberAgents Exchange AI Inspector.Key takeawaysThe Exchange Inspector combines Tenable’s exposure detection with OpenAI’s GPT Cyber models and with human oversight to rigorously vet submissions made to th…
P0
2026-09-09 10:00 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-09 10:10 UTC
Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first on SecurityWeek.
P0
2026-09-09 07:53 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-09 08:30 UTC
The researcher Chaotic Eclipse released ShieldCrash, a PoC exploit for a Microsoft Defender Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit ShieldCrash, it triggers an arbitrary file read as SYSTEM. The researcher claims that Microsoft has not fully […]
P25
2026-09-09 07:30 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-09 07:50 UTC
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]
P30
2026-09-09 07:06 UTC
Other
Group-IB · indexed 2026-09-09 07:35 UTC
How the Gigabud Android banking trojan abuses Shelter, an open-source app cloner, and what that means for banks, users, and defenders.
P0
2026-09-09 07:03 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-09 07:10 UTC
September 2026 Patch Tuesday fixes a record 974 CVEs including 2 exploited zero-days, 20 wormable bugs, and a critical Exchange RCE via Visio email. Microsoft’s September 2026 Patch Tuesday set a new record. Depending on how researchers count external and Chromium bugs, Microsoft fixed between 966 and 997 CVEs in this update. The company also […]
P40
2026-09-09 06:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 09:30 UTC
The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic
P30
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:30 UTC
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Azure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.8.
P0
2026-09-09 04:41 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 06:20 UTC
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.
P45
2026-09-09 04:27 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 04:40 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a
P70
2026-09-09 02:36 UTC
Other
JPCERT · indexed 2026-09-09 03:10 UTC
P5
2026-09-09 01:16 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-09-09 01:25 UTC
Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. [...]
P0
2026-09-09 01:00 UTC
Security Journalism
Huntress · indexed 2026-09-08 13:30 UTC
Huntress is tracking a pattern across multiple customer environments where rogue ScreenConnect clients repeatedly spawn the Windows Script Host to execute a series of four VBScript files.
P0
2026-09-08 22:40 UTC
Security Journalism
The Record · indexed 2026-09-08 22:45 UTC
The new record total for Patch Tuesday is 973 vulnerabilities.
P0
2026-09-08 22:16 UTC
Vendor Research
Cisco Talos Intelligence Blog · Cisco Talos · indexed 2026-09-08 22:45 UTC
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
P5
2026-09-08 21:44 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-09-08 21:50 UTC
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
P0
2026-09-08 21:44 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-09-09 00:10 UTC
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday, including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will e…
P65
2026-09-08 21:26 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-09-08 21:45 UTC
Attackers are actively exploiting two of the vulnerabilities, and another 58 are more likely to be exploited, according to Microsoft.
P0
2026-09-08 20:35 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-08 21:10 UTC
Crypto exchange network Liquid Network lost $320 million overnight, then got most of it back after the hackers demanded a bug fix instead of a ransom Bitcoin’s Liquid Network, a sidechain built by Blockstream and used by dozens of exchanges to move funds faster and more privately than the main Bitcoin blockchain allows, got drained […]
P0
2026-09-08 19:20 UTC
Community
SANS Internet Storm Center · indexed 2026-09-08 19:35 UTC
This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.
P30
2026-09-08 19:20 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-08 19:30 UTC
The record-breaking September security update fixes two exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities. The post Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek.
P45
2026-09-08 18:49 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-08 19:00 UTC
Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes. [...]
P5
2026-09-08 18:18 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-08 18:20 UTC
Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. [...]
P30