Skip to content

Morning Brief

Tuesday, September 8, 2026 · generated 2026-09-08 17:13 UTC · ~5 min read

Top developments

BigBear phishing crew nets thousands of Microsoft 365 credentials

A Microsoft 365 phishing operation targeting hundreds of organizations captured thousands of passwords and session cookies, including hundreds of authenticated sessions that could be hijacked to bypass MFA, according to…

Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain

A new intrusion campaign shows how quickly a Windows domain can be turned into a launchpad for deeper compromise. The operators used a Sliver command-and-control beacon, account creation, credential theft and remote…

WeWorm – First 0-Click Worm Spreading Through WeChat Calls Across iOS and Android

A proof-of-concept zero-click worm dubbed “WeWorm” that it says can spread through WeChat voice calls on both iOS and Android, compromising a target’s WeChat account in seconds without the victim answering the call…

Extortion crews have their eyes on high-value AI data, Google warns

Data theft and extortion crews are stealing companies’ proprietary AI data and threatening to leak it if the victim organizations don’t pay a ransom, according to Google’s threat hunters. In one case that Google’s…

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as…

Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the…

SAP Security Updates September 2026 – Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport

SAP has released its September 2026 Security Patch Day updates , delivering 19 new security notes and one update to a previously issued note. The patches address vulnerabilities across SAP NetWeaver, SAP Extended…

StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day

A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a…

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code…

Mathspace discloses data breach affecting over 1 million people

Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system.

Vulnerability watch

CVE-2026-86296 D-Link · DIR-822A CWE-119 CRITICAL 10.0

A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possibl…

CVE-2026-75650 Adobe · Adobe Commerce CWE-1336 CRITICAL 10.0

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerabil…

CVE-2026-44756 SAP · SAP Extended Passport (EPP) Processing CWE-120 CRITICAL 10.0

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially r…

CVE-2026-86299 Linksys · RE7000 CWE-77 CRITICAL 9.9

A vulnerability was detected in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pingTestIp/pingTestPktSize/p…

CVE-2026-86510 D-Link · DIR-822A CWE-119 CRITICAL 9.9

A vulnerability has been found in D-Link DIR-822A A_101. Affected is the function tunnel_set_params of the component L2TP Control Message Parser. Such manipulation leads to out-of-bounds write. The attack can be launched remotely. The explo…

CVE-2026-76578 Red Hat · Red Hat Enterprise Linux 10 CWE-306 CRITICAL 9.8

A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry. An unauthenticated LDAP client can exploit this, combined with a rela…

CVE-2026-18922 Red Hat · Red Hat Directory Server 11.7 E4S for RHEL 8 CWE-287 CRITICAL 9.8

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, a stale identity carried in a Cyrus SASL auxiliary property from a prior failed bind attempt can be installed on a connection following a subsequent, unrelated succ…

CVE-2026-7861 Next4Biz Information Technologies Inc. · CSM (Customer Service Management) CWE-502 CRITICAL 9.8

Deserialization of untrusted data vulnerability in Next4Biz Information Technologies Inc. CSM (Customer Service Management) allows Code Injection. This issue affects CSM (Customer Service Management): through 07092026. NOTE: The vendor was…

CVE-2026-86478 JetBrains · YouTrack CWE-290 CRITICAL 9.8

In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improper authentication in YouTrack Helpdesk allowed unauthenticated account takeover via a self-asserted email address

CVE-2026-86480 JetBrains · Hub CWE-306 CRITICAL 9.8

In JetBrains Hub before 2026.2.52442 an unauthenticated attacker could register a trusted service and gain superuser privileges

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →