{"date_iso":"2026-09-07","date_human":"Monday, September 7, 2026","generated_utc":"2026-09-07 18:13 UTC","read_minutes":4,"patch_tuesday":false,"top_stories":[{"title":"Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks","link":"https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News","The Register Security"],"coverage":4,"cve_ids":[],"summary":"Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk\u2026","source":"The Hacker News","date_rel":"2h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjg-Zo4zgxCrVcz6-00WV2qAPHSD-av2Ed5hgRmR-2vUzkr9jVeph0NNb6gGsQfwSkFyuRfRcSsaISSpfysl_Xx5F48IM7HdBpO4F3CaVuLhk1v0a4vcH5xK_bxX6BxIjkfAjhDaNGcLG7_R9IcTjVGlFcW7y1ZV64imACHi9528LOjH1Flhk-cy9LFgrMv/s1600/phish-ms.jpg","description":"Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff","related":[{"title":"BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations","link":"https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/","source":"Bleeping Computer","date_rel":"2h ago"},{"title":"Switzerland Moves Away From Microsoft 365 to Open-Source Alternatives","link":"https://cybersecuritynews.com/switzerland-moves-away-from-microsoft-365/","source":"Cyber Security News","date_rel":"3h ago"},{"title":"Microsoft to Retire Manifest V2 Extensions and Switch to V3 for Improved Security and Performance","link":"https://cybersecuritynews.com/microsoft-to-retire-manifest-v2-extensions/","source":"Cyber Security News","date_rel":"3h ago"},{"title":"ASCII smuggling isn't just an AI security risk","link":"https://www.theregister.com/security/2026/09/04/ascii-smuggling-isnt-just-an-ai-security-risk/5294595","source":"The Register Security","date_rel":"4 Sep"}]},{"title":"Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores","link":"https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html","reason":"Adobe","category":"News","sources":["Bleeping Computer","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec\u2026","source":"The Hacker News","date_rel":"5 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjghsT_skiIfdOHK2B0WWDfWnSK0G5Ih7BqsX98tKrY4TH7I77oLEmnldtVHuUMEQaIiZZBSPJGI2t8Me7h9kDtE4YGZ9-5NypnAu2-yFFrXsWYkR6OJPlbqkZDEHBAXCmRjWm6Mk4h0Ni48JT0nrDWMYygztjoi4HuHPbe2y-2jreFVkzrxO8r4IhHIEU/s1600/adobe-exploit.jpg","description":"Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. \"Sansec is","related":[{"title":"Magento StyleSmuggler zero-day exploited to deploy Linux backdoor","link":"https://www.bleepingcomputer.com/news/security/magento-stylesmuggler-zero-day-exploited-to-deploy-linux-backdoor/","source":"Bleeping Computer","date_rel":"1h ago"},{"title":"Adobe Commerce Zero-Day Exploited to Backdoor Online Stores","link":"https://www.securityweek.com/adobe-commerce-zero-day-exploited-to-backdoor-online-stores/","source":"SecurityWeek","date_rel":"6h ago"}]},{"title":"OpenAI Agents Hacked Another Website","link":"https://www.wired.com/story/security-news-this-week-openai-agents-hacked-another-website/","reason":"Another Website Openai","category":"Media","sources":["SecurityWeek","Wired Security"],"coverage":2,"cve_ids":[],"summary":"Plus: Tens of millions of US and Canadian drivers\u2019 licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.","source":"Wired Security","date_rel":"5 Sep","thumbnail":"https://media.wired.com/photos/6a9b056f355eb442715c734d/master/pass/Security_OpenAIAgentsTriedtoHackAnotherWebsite_v1-ezgif.com-video-to-gif-converter.gif","description":"","related":[{"title":"OpenAI Agents Hijack Another Victim Website","link":"https://www.securityweek.com/openai-agents-hijack-another-victim-website/","source":"SecurityWeek","date_rel":"6h ago"}]},{"title":"Bimbo Bakeries USA Confirms Data Breach in Oracle EBS Zero-Day Attack","link":"https://cybersecuritynews.com/bimbo-oracle-ebs-data-breach/","reason":"Oracle","category":"News","sources":["Cyber Security News","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Bimbo Bakeries USA, the American arm of the world\u2019s largest baking company, has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle\u2019s E-Business Suite (EBS), joining a growing\u2026","source":"Cyber Security News","date_rel":"1h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Bimbo-Oracle-EBS-Data-Breach.webp","description":"Bimbo Bakeries USA, the American arm of the world\u2019s largest baking company, has confirmed that hackers stole employee data by exploiting a zero-day vulnerability in Oracle\u2019s E-Business Suite (EBS), joining a growing list of organizations swept up in the Clop ransomware gang\u2019s global extortion campaign against Oracle customers. In a notification letter dated August 31, 2026, and filed with the California Attorney General\u2019s office on September 4, as detailed in the official filing published by the California Attorney General\u2019s Office , the bakery giant said the incident traced back to a\u2026","related":[{"title":"Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE \u2014 Public Exploit Released","link":"https://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html","source":"The Hacker News","date_rel":"6h ago"}]},{"title":"Linux Rootkit Injects Fileless PHP Web Shells Into Compromised F5 BIG-IP Servers","link":"https://cybersecuritynews.com/linux-rootkit/","reason":"Linux","category":"News","sources":["Cyber Security News","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"A stealthy Linux rootkit is giving attackers a new way to keep control of compromised F5 BIG-IP Access Policy Manager servers. Instead of leaving an obvious malicious PHP file behind, it places a web shell only in the\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Linux-Rootkit-Injects-Fileless-PHP-Web-Shells-Into-Compromised-F5-BIG-IP-Servers.webp","description":"A stealthy Linux rootkit is giving attackers a new way to keep control of compromised F5 BIG-IP Access Policy Manager servers. Instead of leaving an obvious malicious PHP file behind, it places a web shell only in the memory used by the running server process. The activity is linked to BIG-IP APM webtop environments running Apache and PHP. F5 has associated related activity with CVE-2025-53521, an exploited, unauthenticated remote-code-execution flaw, a risk already highlighted in coverage of exposed BIG-IP APM devices . Sophos analysts identified the implant while examining compromised\u2026","related":[{"title":"New Linux Bot Hides as Kernel Process and Launches DDoS Attacks","link":"https://cybersecuritynews.com/new-linux-bot/","source":"Cyber Security News","date_rel":"4h ago"},{"title":"North Korean Hackers Deploy New Linux Espionage Toolkit","link":"https://www.securityweek.com/north-korean-hackers-deploy-new-linux-espionage-toolkit/","source":"SecurityWeek","date_rel":"6h ago"}]},{"title":"Hackers Abuse Trusted Google Services to Hide Credential-Stealing Phishing Attacks","link":"https://cybersecuritynews.com/trusted-google-services/","reason":"Google","category":"News","sources":["Cyber Security News","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Criminals are using trusted Google services as cover for a wide phishing campaign that steals corporate credentials and, in some cases, installs remote-access software. The malicious path runs through Google-owned\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Hackers-Abuse-Trusted-Google-Services-to-Hide-Credential-Stealing-Phishing-Attacks.webp","description":"Criminals are using trusted Google services as cover for a wide phishing campaign that steals corporate credentials and, in some cases, installs remote-access software. The malicious path runs through Google-owned domains before reaching attacker-controlled pages for users and filters. The emails use familiar workplace themes, including document reviews, expiring mailboxes, package deliveries, payment notices, voicemail alerts and government benefits. The lures target staff across manufacturing, government, finance and non-profit organizations. KnowBe4 Threat Lab analysts identified the\u2026","related":[{"title":"JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies","link":"https://thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html","source":"The Hacker News","date_rel":"10h ago"}]},{"title":"Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits","link":"https://www.securityweek.com/nightmare-eclipse-drops-crowdstrike-nvidia-avast-zero-day-exploits/","reason":"Crowdstrike","category":"News","sources":["Infosecurity Magazine","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges.","source":"SecurityWeek","date_rel":"5h ago","thumbnail":"","description":"","related":[{"title":"Researcher Publishes CrowdStrike Privilege Escalation Zero Day","link":"https://www.infosecurity-magazine.com/news/crowdstrike-privilege-escalation/","source":"Infosecurity Magazine","date_rel":"9h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-86296","vendor":"D-Link","product":"DIR-822A","severity":"CRITICAL","score":10.0,"description":"A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possibl\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86296"},{"id":"CVE-2026-79697","vendor":"Advantech","product":"WISE-6610-NB","severity":"CRITICAL","score":9.9,"description":"A vulnerability was determined in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-79697"},{"id":"CVE-2026-79698","vendor":"Advantech","product":"WISE-6610-NB","severity":"CRITICAL","score":9.9,"description":"A vulnerability was identified in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-6610P-DEA, WISE-6610P-DNA and WISE-6\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-79698"},{"id":"CVE-2026-19633","vendor":"DALIBO","product":"PostgreSQL Anonymizer","severity":"HIGH","score":8.8,"description":"PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects are evaluated in the \u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19633"},{"id":"CVE-2026-20501","vendor":"MediaTek, Inc.","product":"MediaTek chipset","severity":"HIGH","score":8.4,"description":"In vdec, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS\u2026","cwe":"CWE-122","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20501"},{"id":"CVE-2026-20502","vendor":"MediaTek, Inc.","product":"MediaTek chipset","severity":"HIGH","score":8.4,"description":"In vdec, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS\u2026","cwe":"CWE-122","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-20502"},{"id":"CVE-2026-86295","vendor":"D-Link","product":"DIR-895L","severity":"HIGH","score":8.3,"description":"A vulnerability was found in D-Link DIR-895L A1_102b07. This affects the function sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. The manipulation of the argument Hostname results in command injection. The attack can be\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86295"},{"id":"CVE-2026-86242","vendor":"maximhq","product":"Bifrost","severity":"HIGH","score":8.1,"description":"Bifrost HTTP transport before 2.0.0 accepts an enabled custom plugin whose path is an HTTP URL through unauthenticated POST /api/plugins when management authentication is disabled (the default, governance.auth_config.is_enabled=false). The \u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86242"},{"id":"CVE-2026-86297","vendor":"D-Link","product":"DIR-605","severity":"HIGH","score":8.1,"description":"A vulnerability was identified in D-Link DIR-605 B1v202WWB03. This issue affects the function tunnel_set_params of the file progs.gpl/pppd.alpha/l2tp/tunnel.c of the component L2TP Control Message Parser. Such manipulation of the argument p\u2026","cwe":"CWE-189","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86297"},{"id":"CVE-2026-86313","vendor":"Samsung Opensource","product":"Walrus","severity":"HIGH","score":7.8,"description":"Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers.\n\nThis issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.","cwe":"CWE-787","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-86313"}],"vendor_spikes":[{"vendor":"MediaTek, Inc.","count":18,"critical_count":0},{"vendor":"itsourcecode","count":12,"critical_count":0},{"vendor":"SourceCodester","count":12,"critical_count":0},{"vendor":"Microsoft","count":10,"critical_count":0},{"vendor":"Unknown","count":9,"critical_count":0},{"vendor":"Oracle","count":7,"critical_count":0},{"vendor":"curl","count":7,"critical_count":0},{"vendor":"pmmp","count":5,"critical_count":0},{"vendor":"h3js","count":5,"critical_count":0},{"vendor":"MISP","count":4,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":7,"new_cve_count":149,"has_news_data":true,"has_cve_data":true}