{"date_iso":"2026-09-06","date_human":"Sunday, September 6, 2026","generated_utc":"2026-09-06 16:09 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner","link":"https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html","reason":"Windows","category":"News","sources":["Cyber Security News","Microsoft Security","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-50376"],"summary":"Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of\u2026","source":"The Hacker News","date_rel":"7h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpRcdfXd6kYnqLLWSFdzGKICUzSr90MsV2f3PXtw8VDVcT-xOP2w4HwnVzrRI4bdJqhboQMFIm9BZ393b89IOqgYx-VVmb_B8-XJCsZ9SAIymdlBpEf5ARizHvn32t8Mr9stzV6nMVcn3utUYI1xSRxhaC29QZjS-C3haNSRPfQI_eBYzXCrwn5rl18Nw/s1600/rev.jpg","description":"Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and","related":[{"title":"Hackers Use Popular Messaging Services to Control New Windows Backdoors","link":"https://cybersecuritynews.com/popular-messaging-services/","source":"Cyber Security News","date_rel":"4 Sep"},{"title":"CVE-2026-50376 Windows Remote Desktop Client Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50376","source":"Microsoft Security","date_rel":"4 Sep"}]},{"title":"CrowdStrike Launches SafeMind \u2013 First Agentic Cybersecurity Solution Built for Defenders","link":"https://cybersecuritynews.com/crowdstrike-launches-safemind/","reason":"Crowdstrike","category":"News","sources":["Bleeping Computer","Cyber Security News","The Register Security"],"coverage":3,"cve_ids":[],"summary":"CrowdStrike has unveiled SafeMind, a family of purpose-built security models and harnesses that the company is calling the first agentic system engineered specifically for cyber defenders. Announced at Fal.Con 2026 in\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/CrowdStrike-Launches-SafeMind.webp","description":"CrowdStrike has unveiled SafeMind, a family of purpose-built security models and harnesses that the company is calling the first agentic system engineered specifically for cyber defenders. Announced at Fal.Con 2026 in Las Vegas, the launch marks a strategic pivot away from generic frontier AI models toward a dedicated offensive-defensive framework built to operate natively inside the CrowdStrike Falcon platform. The system emerges from CrowdStrike\u2019s newly established Cyber Superintelligence Lab and represents one of the most ambitious applications of agentic AI in enterprise security to date\u2026","related":[{"title":"New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges","link":"https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/","source":"Bleeping Computer","date_rel":"4 Sep"},{"title":"Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC","link":"https://www.theregister.com/security/2026/09/03/prolific-microsoft-0-day-hunter-drops-crowdstrike-falcon-exploit-poc/5294318","source":"The Register Security","date_rel":"3 Sep"}]},{"title":"Microsoft Teams Desktop Client Fails to Load on Windows System \u2013 Microsoft Investigating","link":"https://cybersecuritynews.com/microsoft-teams-desktop-client-fails/","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Cyber Security News","SecurityWeek","The Hacker News","The Register Security"],"coverage":5,"cve_ids":[],"summary":"Microsoft is investigating an ongoing issue causing some Windows users to face significant delays or outright failures when launching the Microsoft Teams desktop client. The company acknowledged the problem, tracked\u2026","source":"Cyber Security News","date_rel":"5 Sep","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Microsoft-Teams-Desktop-Client-Fails.webp","description":"Microsoft is investigating an ongoing issue causing some Windows users to face significant delays or outright failures when launching the Microsoft Teams desktop client. The company acknowledged the problem, tracked internally as TM1466820, and confirmed it remains unresolved as engineers continue digging through service logs to find a root cause. According to Microsoft\u2019s incident notice, affected users encounter trouble specifically during the first launch of Teams on a Windows device. Some cannot load the client at all, while others experience delays stretching up to two minutes before the\u2026","related":[{"title":"ASCII smuggling isn't just an AI security risk","link":"https://www.theregister.com/security/2026/09/04/ascii-smuggling-isnt-just-an-ai-security-risk/5294595","source":"The Register Security","date_rel":"4 Sep"},{"title":"Microsoft Unveils Project Zenith Windows PCs That Can Run 30B+ AI Models Locally","link":"https://cybersecuritynews.com/project-zenith-windows-pcs/","source":"Cyber Security News","date_rel":"4 Sep"},{"title":"In Other News: Microsoft\u2019s Cloud Patches, Hacked Dropbox Accounts, Guardio\u2019s $1.1B Valuation","link":"https://www.securityweek.com/in-other-news-microsofts-cloud-patches-hacked-dropbox-accounts-guardios-1-1b-valuation/","source":"SecurityWeek","date_rel":"4 Sep"},{"title":"Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters","link":"https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html","source":"The Hacker News","date_rel":"4 Sep"},{"title":"Microsoft says some users can\u2019t open the Teams desktop client","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-says-some-users-cant-open-the-teams-desktop-client/","source":"Bleeping Computer","date_rel":"4 Sep"},{"title":"Exchange Online outage causes email delays, 'Server busy' errors","link":"https://www.bleepingcomputer.com/news/microsoft/exchange-online-outage-causes-email-delays-server-busy-errors/","source":"Bleeping Computer","date_rel":"4 Sep"}]},{"title":"10 Best ZTNA Solutions (Zero Trust Network Access) In 2026","link":"https://cybersecuritynews.com/best-ztna-solutions/","reason":"Teams","category":"News","sources":["Cyber Security News","CyberScoop"],"coverage":2,"cve_ids":[],"summary":"Zero Trust Network Access (ZTNA) anchors 2026 cybersecurity amid remote, cloud, and hybrid booms. ZTNA solutions aren\u2019t hype\u2014they\u2019re vital for data locks, compliance wins, and borderless teams. \u201cNever trust, always\u2026","source":"Cyber Security News","date_rel":"11h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/07/best-ztna-solutions-cloudconnexa.webp","description":"Zero Trust Network Access (ZTNA) anchors 2026 cybersecurity amid remote, cloud, and hybrid booms. ZTNA solutions aren\u2019t hype\u2014they\u2019re vital for data locks, compliance wins, and borderless teams. \u201cNever trust, always verify\u201d: ZTNA okays only vetted users/devices, location-blind. Shrink attack planes, block lateral creeps, master app gates. Market clutter and threat flux complicate picks. We rank 2026\u2019s top 10: specs, perks, real impacts dissected.Prioritizing usability, relevance for CISOs, IT pros, scaling firms. CISO, manager, or tech enthusiast find your Zero Trust match. Per-tool: intros\u2026","related":[{"title":"AI Agents Breach Company Network in Under 10 Hours and Steal Root Credentials","link":"https://cybersecuritynews.com/ai-agents-breach-company-network/","source":"Cyber Security News","date_rel":"5 Sep"},{"title":"Why judgment is emerging as cybersecurity\u2019s defining skill","link":"https://cyberscoop.com/ai-security-operations-human-context-ciso-op-ed/","source":"CyberScoop","date_rel":"4 Sep"}]},{"title":"Hackers Actively Exploiting Magento and Adobe Commerce 0-Day RCE Vulnerability","link":"https://cybersecuritynews.com/magento-and-adobe-commerce-0-day-rce/","reason":"Adobe","category":"News","sources":["Cyber Security News","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available. Dutch\u2026","source":"Cyber Security News","date_rel":"12h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Magento-and-Adobe-Commerce-0-Day-RCE.webp","description":"A newly discovered zero-day vulnerability in Magento Open Source and Adobe Commerce is being actively exploited by attackers to seize full control of online stores, and there is still no official patch available. Dutch e-commerce security firm Sansec disclosed the flaw, dubbed StyleSmuggler, on September 5, 2026, warning that unauthenticated attackers can achieve remote code execution on vulnerable installations and that live attacks began the previous day . The company said it was publishing its findings early, before completing its full technical analysis, \u201cbecause stores are being\u2026","related":[{"title":"Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores","link":"https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html","source":"The Hacker News","date_rel":"19h ago"}]},{"title":"New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic","link":"https://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.html","reason":"Linux","category":"News","sources":["CCCS Alerts & Advisories","Rapid7 Blog","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to\u2026","source":"The Hacker News","date_rel":"4 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgzLyhHupZwRy1pOQzT93Qhs5waZ8gqtlgDJUKgt1f37dz3KqIDDZY8uNo8QguZNccBHivdA_ecnY8cQUyhZQAvLH4APu3imxP-rwo2dYLZtKnJ92IkRPFmwepmJgRk9GrLrJiN_IbInwvNXaW7N5761YfEB1IIK4uDdNBTy6Koz8uXgOSXaQWixXM1Wts/s1600/HAProxy.jpg","description":"A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and","related":[{"title":"DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors","link":"https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors","source":"Rapid7 Blog","date_rel":"4 Sep"},{"title":"SUSE Linux security advisory (AV26-882)","link":"https://cyber.gc.ca/en/alerts-advisories/suse-linux-security-advisory-av26-882","source":"CCCS Alerts & Advisories","date_rel":"3 Sep"}]},{"title":"Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code","link":"https://thehackernews.com/2026/09/critical-vmware-workstation-and-fusion.html","reason":"Vmware","category":"News","sources":["SecurityWeek","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The\u2026","source":"The Hacker News","date_rel":"5 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhzExwAd4Vsd2Xz-9kex6ucfK6MDmftPVCfiOGQICWDKrgxMJ6fOj0EttLP2kpYBDv4xSYdrEXt8Wntz916Oa2tyrMnaSHDLH9vb5RF4ncjvwdkeFU8GwaqWvT6zLHRTKIF-BOGK8p24Im4NwqlqZxTokMsYOfXSBdA0-jXxMbMozfjdK-iyyavdAywjAAh/s1600/vmware-host.jpg","description":"Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. \"A","related":[{"title":"VMware Workstation and Fusion Updates Patch Critical Vulnerability","link":"https://www.securityweek.com/vmware-workstation-and-fusion-updates-patch-critical-vulnerability/","source":"SecurityWeek","date_rel":"4 Sep"}]},{"title":"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws","link":"https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html","reason":"Wordpress","category":"News","sources":["SecurityWeek","The Hacker News"],"coverage":2,"cve_ids":["CVE-2026-14894","CVE-2026-32475"],"summary":"Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) \u2026","source":"The Hacker News","date_rel":"4 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9jQ8JSakEpnqxzsAZhwXnVvTMB0Lrbj7shOcXtSJzA30wcMTbkAIUGvSZPiBXOLeAW66Jpuysxn56W8YWD00hsCNB742oLqeyvgD8MXdIHHqwyeehyoyXx9G9c6XjxwN10Co_XVZuBkRjMquzgf9V17gh2Gw-xff0qJ9rh3sPO4tBq4OjjS0dxsl73WKT/s1600/wp-main.jpg","description":"Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms \u2013 Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including","related":[{"title":"Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites","link":"https://www.securityweek.com/elementor-pro-wordpress-plugin-vulnerability-exploited-to-hack-sites/","source":"SecurityWeek","date_rel":"5 Sep"}]},{"title":"Critical Citrix NetScaler auth bypass now leveraged in attacks","link":"https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/","reason":"CVE-2026-19490","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories"],"coverage":2,"cve_ids":["CVE-2026-19489","CVE-2026-19490"],"summary":"Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian.","source":"Bleeping Computer","date_rel":"4 Sep","thumbnail":"","description":"","related":[{"title":"AL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489","link":"https://cyber.gc.ca/en/alerts-advisories/al26-019-vulnerabilities-impacting-citrix-netscaler-adc-netscaler-gateway-cve-2026-19490-cve-2026-19489","source":"CCCS Alerts & Advisories","date_rel":"4 Sep"}]},{"title":"Cisco searched for IOS XR bugs and found so many it rolled them into an update release","link":"https://www.theregister.com/security/2026/09/04/cisco-searched-for-ios-xr-bugs-and-found-so-many-it-rolled-them-into-an-update-release/5294410","reason":"Ios","category":"News","sources":["Cisco Security Advisories","The Register Security"],"coverage":2,"cve_ids":["CVE-2026-20274"],"summary":"Cisco has warned its customers of three critical-rated flaws in its products. Two of them are present in the Cisco IOS XR operating system that powers the company\u2019s carrier-grade kit. CVE-2026-20274 scores 9.8 on the\u2026","source":"The Register Security","date_rel":"4 Sep","thumbnail":"https://image.theregister.com/?imageId=5294415&width=800","description":"Cisco has warned its customers of three critical-rated flaws in its products. Two of them are present in the Cisco IOS XR operating system that powers the company\u2019s carrier-grade kit. CVE-2026-20274 scores 9.8 on the ten-point CVSS scale and covers a buffet of buffering issues, the potential for out-of-bounds writes, and the chance to initialize resources with an insecure default. CVE-2026-20279 is another 9.8-rated flaw. Cisco says it\u2019s an improper access control problem that covers \u201cimproper certificate validation, missing authentication for critical function, missing authorization, and\u2026","related":[{"title":"Cisco IOS XR Software Security Hardening Release: September 2026","link":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20IOS%20XR%20Software%20Security%20Hardening%20Release:%20September%202026%26vs_k=1","source":"Cisco Security Advisories","date_rel":"4 Sep"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-86152","vendor":"Tenda","product":"CP3","severity":"CRITICAL","score":10.0,"description":"A flaw has been found in Tenda CP3 27.5.57.101. The impacted element is the function CAutoAddWifi::ThreadProc of the file Functions/AutoAddWifi.cpp of the component Kylin. Executing a manipulation can lead to os command injection. The attac\u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86152"},{"id":"CVE-2026-86167","vendor":"Tenda","product":"HG10","severity":"CRITICAL","score":9.9,"description":"A vulnerability was identified in Tenda HG10 300001138. Impacted is the function formgponConf of the file /boaform/admin/formgponConf of the component Boa. The manipulation of the argument fmgpon_loid leads to os command injection. Remote e\u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86167"},{"id":"CVE-2026-86121","vendor":"trycua","product":"cua-computer-server","severity":"CRITICAL","score":9.8,"description":"Cua computer-server versions before 0.3.42 skip authentication when the CONTAINER_NAME environment variable is unset and bind to all interfaces by default, allowing unauthenticated attackers to execute arbitrary commands. Attackers can reac\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86121"},{"id":"CVE-2026-86124","vendor":"HKUDS","product":"AutoAgent","severity":"CRITICAL","score":9.8,"description":"AutoAgent contains an unauthenticated remote code execution vulnerability in the TCP server that binds to all interfaces and executes attacker-supplied commands as root. Attackers can connect to the exposed communication port and execute ar\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86124"},{"id":"CVE-2026-10196","vendor":"Microsoft","product":"Mail Mint \u2013 Email Marketing, Newsletter, Email Automation & WooCommerce Emails","severity":"CRITICAL","score":9.8,"description":"The Mail Mint \u2013 Email Marketing, Newsletter, Email Automation & WooCommerce Emails plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 1.31.0 via deserialization of untrusted input in the 'handle\u2026","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-10196"},{"id":"CVE-2026-86184","vendor":"laradashboard","product":"laradashboard","severity":"CRITICAL","score":9.8,"description":"Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackers can request the G\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86184"},{"id":"CVE-2026-86189","vendor":"WWBN","product":"AVideo","severity":"CRITICAL","score":9.8,"description":"WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parameter. Attackers can r\u2026","cwe":"CWE-73","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86189"},{"id":"CVE-2026-16310","vendor":"WordPress","product":"MemberDash","severity":"CRITICAL","score":9.8,"description":"The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthen\u2026","cwe":"CWE-639","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-16310"},{"id":"CVE-2026-75816","vendor":"WordPress","product":"Frontend Admin by DynamiApps","severity":"CRITICAL","score":9.8,"description":"The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to Authentication Bypass to Account Takeover in all versions up to, and including, 3.29.12. This is due to the pre_update_value function lacking any capability or ownership\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-75816"},{"id":"CVE-2026-86165","vendor":"Tenda","product":"HG10","severity":"CRITICAL","score":9.8,"description":"A vulnerability was found in Tenda HG10 300001138. This vulnerability affects the function formURL of the file /boaform/admin/formURL. Performing a manipulation of the argument Keywd/urlFQDN results in buffer overflow. The attack may be ini\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86165"}],"vendor_spikes":[{"vendor":"WordPress","count":11,"critical_count":2},{"vendor":"Tenda","count":9,"critical_count":7},{"vendor":"The Tcpdump Group","count":7,"critical_count":0},{"vendor":"Mikrotik","count":6,"critical_count":0},{"vendor":"WWBN","count":5,"critical_count":2},{"vendor":"getgrav","count":5,"critical_count":0},{"vendor":"SourceCodester","count":4,"critical_count":0},{"vendor":"code-projects","count":4,"critical_count":0},{"vendor":"bookwyrm-social","count":3,"critical_count":0},{"vendor":"N-able","count":3,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":12,"new_cve_count":93,"has_news_data":true,"has_cve_data":true}