Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 08:20 09/09/2026 UTC
Last updated: 16:20 08/09/2026 UTC

Latest updates

Browse →

Microsoft Defender SYSTEM privilege escalation bypass (CVE-2026-69414)

Vulnerability

Updated: 09.09.2026 10:30 · First: 09.09.2026 10:30 · 📰 1 src / 1 articles · H score: 26

A new ShieldCrash proof-of-concept exposes CVE-2026-69414 in Microsoft Defender, enabling SYSTEM privileges on fully patched Windows 10, Windows 11, and Windows Server systems.

Microsoft September 2026 Patch Tuesday security updates (966 flaws)

Security Patch Release

Updated: 08.09.2026 21:18 · First: 08.09.2026 21:18 · 📰 4 src / 4 articles · H score: 54

Microsoft released its September 2026 Patch Tuesday updates for a record 966 flaws, including two actively exploited zero-days that can enable local SYSTEM privilege escalation on affected systems.

N-able security patch release for CVE-2026-86218

Security Patch Release

Updated: 07.09.2026 09:17 · First: 07.09.2026 09:17 · 📰 3 src / 4 articles · H score: 55

N-able released N-central 2026.3 HF4 to close CVE-2026-86218, a maximum-severity RCE in the N-central RMM platform. The patch protects on-premises deployments exposed online, where unprivileged attackers could run code with low-complexity attacks. N-able urged customers to upgrade immediately, and systems still on HF3 remain at risk until they move to HF4.

DoppelCart 119,000-domain fake-shop fraud campaign

Campaign

Updated: 08.09.2026 23:35 · First: 08.09.2026 23:35 · 📰 1 src / 1 articles · H score: 66

The DoppelCart operation now spans 119,000+ domains, running fake e-shops that steal payment card details and expose shoppers to real-time fraud. More than 105,000 shops remain active, extending the reach of the cluster across the .SHOP ecosystem. The sites mimic legitimate brands and relay checkout data and bank one-time codes to the operators' C2. The scale and persistence make it a broad, ongoing consumer-fraud campaign.

PoisonedRefresh Linux rootkit on F5 BIG-IP APM

Malware Activity

Updated: 08.09.2026 23:08 · First: 08.09.2026 23:08 · 📰 1 src / 1 articles · H score: 30

The PoisonedRefresh Linux rootkit was deployed on F5 BIG-IP APM systems as a second-stage payload, enabling fileless PHP web-shell injection and a local Bash backdoor without writing the implant to disk. It also used Apache and Linux hooks to run before normal application logic, raising the risk of stealthy device compromise. The payload’s persistence and in-memory execution make detection and remediation harder on affected appliances.

Windows Update Stack and ALPC actively exploited elevation-of-privilege flaws (multiple vulnerabilities)

Vulnerability

Updated: 08.09.2026 21:18 · First: 08.09.2026 21:18 · 📰 2 src / 2 articles · H score: 38

Microsoft patched two actively exploited Windows elevation-of-privilege flaws in Windows Update Stack and Windows Advanced Local Procedure Call (ALPC), preventing local attackers from escalating to SYSTEM privileges.

FLHSMV DAVID driver records leak-extortion

Data Leak

Updated: 08.09.2026 19:35 · First: 08.09.2026 19:35 · 📰 1 src / 1 articles · H score: 41

A claimed FLHSMV DAVID data leak has put records for more than 200,000 Florida drivers at risk of public release and extortion. The threat group says it used a password-reset flaw to access accounts and pull driver data from the system. A posted sample record for Jeffrey Epstein shows the exposed data can include addresses, Social Security numbers, birth dates, and license details.

Slim Spider campaign targeting Brazilian financial institutions and Pix infrastructure

Campaign

Updated: 08.09.2026 19:20 · First: 08.09.2026 19:20 · 📰 1 src / 1 articles · H score: 34

The Slim Spider campaign is tied to multi-stage intrusions against Brazilian financial institutions, putting Pix transfers and cryptocurrency custody secrets at risk of theft and unauthorized access. CrowdStrike says the Brazil-based cluster has operated since at least March 2026 and shows deep knowledge of financial cloud environments. The activity uses custom Bash scripts to steal temporary cloud credentials, enumerate secrets, and pivot into Azure DevOps and managed Kubernetes infrastructure. Supporting tools and panels point to an organized operation built for credential abuse, endpoint discovery, and bulk unauthorized financial transactions.

Breeze Comet-CL-CRI-1163-Plump Spider alliance reshapes ransomware ecosystem operations

Threat Actor Meta

Updated: 08.09.2026 19:20 · First: 08.09.2026 19:20 · 📰 1 src / 1 articles · H score: 35

Breeze Comet is pushing Latin American cybercrime away from client-side retail fraud and toward direct intrusions into payment infrastructure, increasing risk to Brazilian financial systems and instant-transfer rails. The group's activity has expanded beyond Brazil to municipal websites in other countries, creating a reusable path for fraudulent transactions and follow-on social engineering.

Cylake raises $245 million cybersecurity funding round

Industry Action

Updated: 08.09.2026 18:21 · First: 08.09.2026 18:21 · 📰 1 src / 1 articles · H score: 14

Cylake raised $245 million in new funding to accelerate its sovereign security platform development, increasing total capital to $290 million just six months after launch. The financing supports the startup’s push toward a beta release by end of 2026 and general availability in 2027 for customers that need tighter data sovereignty and infrastructure control.

Elements L-BTC creation security flaw

Vulnerability

Updated: 08.09.2026 17:54 · First: 08.09.2026 17:54 · 📰 1 src / 1 articles · H score: 43

A bug in Elements created the L-BTC used in an unauthorized Liquid Network peg-out, tying the theft path to a specific software flaw. The flaw affected the software Liquid runs on and was linked to the withdrawal of roughly 4,000 bitcoin from the federation wallet. Blockstream said updated software has been deployed and the network is still paused while bridge nodes are patched and restarted. The incident left the status of the remaining reserve backing L-BTC unresolved.

Liquid Network hit by cyberattack

Incident

Updated: 08.09.2026 17:54 · First: 08.09.2026 17:54 · 📰 1 src / 1 articles · H score: 46

Liquid Network suffered a federation wallet theft that removed nearly 4,000 bitcoin and left the network paused, disrupting L-BTC redemption and reserve backing. About 3,400 bitcoin were returned the next day, but roughly 598.5 bitcoin remained unreturned as recovery work continued.

ChatGPT planted-instruction cross-account data exfiltration security flaw

Vulnerability

Updated: 08.09.2026 17:19 · First: 08.09.2026 17:19 · 📰 1 src / 1 articles · H score: 25

ChatGPT was shown to accept a planted instruction that could trigger hidden tool use and cross-account data exfiltration from connected apps, including Gmail. In the proof of concept, the model kept answering normally while covertly reading session data and relaying it through a hidden channel to another ChatGPT account. The weakness depended on the session's existing permissions and connected services, so impact scaled with what the conversation could already access. OpenAI said the internal service behind the channel was taken offline, and there is no user update to install.

Magento Open Source and Adobe Commerce StyleSmuggler zero-day actively exploited security flaw

Vulnerability

Updated: 05.09.2026 23:14 · First: 05.09.2026 23:14 · 📰 2 src / 3 articles · H score: 25

CVE-2026-75650 / StyleSmuggler is an actively exploited zero-day affecting Magento Open Source and Adobe Commerce. Exploitation was observed since at least September 4, with attacks using PHP code injection to plant a backdoor on vulnerable sites and persist through disguised activity such as Payment Transaction Failed Reminder emails and cron-based execution. Adobe has now issued an emergency fix and VULN-39341 hotfix with highest priority, and Sansec reported a separate attacker using the flaw to deploy a 485-byte PHP web shell.

UNC6780 open-source software supply chain campaign targeting AI environments

Campaign

Updated: 08.09.2026 15:02 · First: 08.09.2026 15:02 · 📰 2 src / 2 articles · H score: 45

UNC6780 is running a large-scale open-source supply-chain campaign that targets AI-assisted coding tools and software dependencies across PyPI, npm, and Docker Hub. GTIG says the group uses Dustmaker to extract tokens from GitHub Actions runners, publish compromised packages that pass automated trust checks, and plant or modify files in hidden workspace directories used by AI coding assistants. The operation also collects credentials to AI tools for resale, increasing downstream exposure for developers and teams that rely on these environments.

China-based AI companies' knowledge-distillation campaign against U.S. frontier AI models

Campaign

Updated: 08.09.2026 15:00 · First: 08.09.2026 15:00 · 📰 1 src / 1 articles · H score: 29

A coordinated knowledge distillation campaign by China-based AI companies has extracted billions of tokens from U.S. frontier AI models, accelerating capability transfer and undermining model IP protection. The activity has been linked to DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, and it has been active since at least late 2024.

CISA, NSA, and FBI joint advisory on AI model distillation

Public Sector Action

Updated: 08.09.2026 15:00 · First: 08.09.2026 15:00 · 📰 1 src / 1 articles · H score: 25

CISA, NSA, and FBI released a joint cybersecurity advisory warning U.S. AI companies about knowledge distillation campaigns targeting frontier models. The advisory says the activity has been unfolding since at least late 2024 and involves extraction of billions of tokens across millions of exchanges/requests. It directs AI providers to strengthen detection, response, and cross-org intelligence sharing to blunt the abuse.

U.S. frontier AI companies knowledge distillation mitigation advisory

Advisory/Mitigation

Updated: 08.09.2026 15:00 · First: 08.09.2026 15:00 · 📰 1 src / 1 articles · H score: 31

CISA, NSA, and FBI issued a joint advisory for U.S. frontier AI companies, warning that knowledge distillation campaigns can strip proprietary model capabilities at scale. The guidance responds to activity tied to China-based AI companies that extracted billions of tokens from models including Claude, GPT, Gemini, and Grok since at least late 2024. It directs firms to strengthen detection, adjust responses to suspected extraction attempts, and share intelligence across providers and platforms.

Microsoft Windows Server 2025 memory-management crash disruption

Service Disruption

Updated: 08.09.2026 14:57 · First: 08.09.2026 14:57 · 📰 1 src / 1 articles · H score: 0

Microsoft’s Windows Server 2025 memory-management change is causing application crashes and SQL Server instability on affected systems. The problem hits software that uses Address Windowing Extensions (AWE), including deployments with Lock Pages in Memory (LPIM) enabled. Impacted servers can show memory corruption, 0xC0000005 access violations, failed DBCC CHECKDB jobs, and services that stop or restart unexpectedly. Microsoft has issued a temporary workaround and says a future Windows update will provide a permanent fix.

Tencent WeChat security update for zero-click call flaw

Security Patch Release

Updated: 08.09.2026 14:54 · First: 08.09.2026 14:54 · 📰 1 src / 1 articles · H score: 16

Tencent released WeChat 8.0.77 for Android and 8.0.76 for iOS to mitigate a zero-click account-takeover flaw affecting mobile users. Calif said the releases mitigated the bug, and Tencent later blocked the exploit on its servers for all users. No attacks using the flaw were reported.

WeChat zero-click incoming-call account takeover security flaw

Vulnerability

Updated: 08.09.2026 14:54 · First: 08.09.2026 14:54 · 📰 1 src / 1 articles · H score: 16

Calif demonstrated a zero-click incoming-call flaw in WeChat that let an attacker seize accounts on iPhone and Android, creating account-takeover risk without user interaction. The worm spread across three test phones and required the caller to already be on the target's contact list. Once it ran, the attacker could read and send messages, place calls, and act as the account owner. Tencent later said it had mitigated the exploit for all users.

FreeIPA anonymous Kerberos identity privilege escalation (multiple vulnerabilities)

Vulnerability

Updated: 08.09.2026 14:22 · First: 08.09.2026 14:22 · 📰 1 src / 1 articles · H score: 39

FreeIPA faces a critical privilege-escalation chain on default installations after an unauthenticated client can create a Kerberos identity and reach administrators-group privileges. The issue is tied to CVE-2026-76578 and the supporting 389 Directory Server CVE-2026-76560 ownership-check flaw. FreeIPA 4.13.4 fixes the FreeIPA side, and Red Hat reproduced the chain on stock installs. Temporary mitigation is to limit LDAP access and review anonymous bind use.

THost9 Android RAT with embedded ADB worm

Malware Activity

Updated: 08.09.2026 14:15 · First: 08.09.2026 14:15 · 📰 1 src / 1 articles · H score: 22

The THost9 Android RAT now pairs a concealed loader with an embedded ADB worm, extending reach to exposed Android Debug Bridge services and increasing the risk of unauthorized installs on reachable devices. The payload is loaded from tc9.dex, and the wider cluster is tracked as Hagaseca. The second stage adds shell execution, file transfers, tunneling and reverse-shell access.

Dark Atlas reverse engineers THost9 loader, tc9.dex payload, and ADB worm with Frida check

Technical Analysis

Updated: 08.09.2026 14:15 · First: 08.09.2026 14:15 · 📰 1 src / 1 articles · H score: 26

Researchers dissected THost9 as a packed Android RAT that hides its loader, loads tc9.dex, and expands access with an embedded ADB worm. The findings raise the risk of unauthorized installation on reachable devices and show how the malware uses dynamic loading to conceal its behavior. The sample also added a Frida detection check, reducing visibility for analysts who rely on instrumentation. The research provides concrete artifacts and behaviors that defenders can use to spot Hagaseca activity.

BengalSEO SEO poisoning campaign

Campaign

Updated: 08.09.2026 11:43 · First: 08.09.2026 11:43 · 📰 1 src / 1 articles · H score: 12

The BengalSEO operation now stands out as a long-running SEO poisoning campaign that funnels search users into MayaBot malware delivery and tech support scams. Discovered in March 2026 and active since at least 2015, it uses lure pages, redirector chains, and a traffic distribution system to hide final payload and scam destinations. The scale matters because the operation manipulates search rankings across many domains and hosting services, making malicious results look legitimate.

MayaBot malware activity in BengalSEO

Malware Activity

Updated: 08.09.2026 11:43 · First: 08.09.2026 11:43 · 📰 1 src / 1 articles · H score: 10

The MayaBot payload now anchors a Windows malware operation that gives BengalSEO command-and-control (C2), system monitoring, and XMRig mining capability, increasing both control and monetization of infected hosts. It is delivered through SEO-poisoned lure pages and ZIP archives that trigger a JavaScript dropper via wscript.exe. BengalSEO has leveraged the malware since 2022, showing the payload is a durable part of the infection chain.

Vietnam-linked APIS database exposure of 220 million traveler records

Data Leak

Updated: 08.09.2026 10:35 · First: 08.09.2026 10:35 · 📰 1 src / 1 articles · H score: 74

A Vietnam-linked APIS database was found accessible online, exposing 220 million+ passenger and crew records and creating a broad privacy and identity-risk event. The leaked material included passport numbers and flight details, along with names, dates of birth, and other travel information. Access was closed on June 8, but the records covered travel spanning January 2017 to April 2026 and could have been copied before remediation.

Grindr settles U.K. privacy lawsuit over HIV data sharing

Regulatory/Legal Action

Updated: 08.09.2026 10:00 · First: 08.09.2026 10:00 · 📰 2 src / 2 articles · H score: 31

Grindr agreed to pay £26 million ($35.1 million) to settle a U.K. privacy lawsuit over allegations that it shared users’ personal information, including HIV status, with third parties. The claims covered alleged use of sensitive data for advertising and other commercial purposes and involved more than 10,000 clients. The settlement resolves historical conduct tied to pre-2020 data practices.

N-central pre-auth RCE flaw (CVE-2026-86218)

Vulnerability

Updated: 07.09.2026 11:31 · First: 07.09.2026 11:31 · 📰 2 src / 3 articles · H score: 56

CVE-2026-86218 in N-central now has Hotfix 4, and the flaw can let unauthenticated attackers execute code on affected servers. Every on-premises build below 2026.3.1.14 is affected, including systems that had already installed Hotfix 3. N-able's notices conflict on exploitation, with one saying there are no confirmed production cases and another saying the flaw has been observed being exploited in the wild.

PEEP Chromium post-compromise backdoor

Malware Activity

Updated: 07.09.2026 21:12 · First: 07.09.2026 21:12 · 📰 1 src / 1 articles · H score: 29

The PEEP toolkit now turns Chrome/Edge into a persistent post-compromise backdoor, enabling credential theft, session abuse, and host command execution. It is installed as a fake bookmarks extension, uses a native-messaging bridge to cross into the OS, and maintains access through sideloading and preference tampering. The toolkit also polls a remote C2 and exfiltrates browser data, widening the blast radius of each infected browser.