{"date_iso":"2026-09-10","date_human":"Thursday, September 10, 2026","generated_utc":"2026-09-10 16:59 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"Serial Microsoft 0-day hunter drops yet another Defender exploit","link":"https://www.theregister.com/security/2026/09/09/serial-microsoft-0-day-hunter-drops-yet-another-defender-exploit/5295335","reason":"Microsoft","category":"News","sources":["Ars Technica Security","Bleeping Computer","CCCS Alerts & Advisories","Cisco Talos","CyberScoop","Dark Reading","Huntress","Infosecurity Magazine","Krebs On Security","Malwarebytes Labs","Rapid7 Blog","SANS Internet Storm Center","SecurityWeek","Tenable Blog","The Hacker News","The Register Security"],"coverage":16,"cve_ids":["CVE-2026-81963","CVE-2026-85880"],"summary":"Zero-day researcher Nightmare Eclipse, aka MSNightmare, published yet another Microsoft Defender proof-of-concept exploit for a zero-day dubbed ShieldCrash, which they claim will allow attackers to bypass the earlier\u2026","source":"The Register Security","date_rel":"23h ago","thumbnail":"https://image.theregister.com/?imageId=4094178&width=800","description":"Zero-day researcher Nightmare Eclipse, aka MSNightmare, published yet another Microsoft Defender proof-of-concept exploit for a zero-day dubbed ShieldCrash, which they claim will allow attackers to bypass the earlier ShieldBreak patch and read files as SYSTEM. \u201cI might rework this later into a full SYSTEM PoC but for now I'm dropping this skeleton PoC because I'm feeling a bit lazy,\u201d the prolific Microsoft bug hunter and thorn in Redmond's side said in their latest zero-day exploit's README. As is usual with Nightmare\u2019s zero-day cadence, they published ShieldCrash shortly after Microsoft\u2026","related":[{"title":"Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit","link":"https://www.darkreading.com/vulnerabilities-threats/nightmare-eclipse-strikes-again-shieldcrash-windows-exploit","source":"Dark Reading","date_rel":"1h ago"},{"title":"Microsoft says September updates fix mouse settings reset issues","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-resolves-mouse-settings-reset-bug-windows-11-update/","source":"Bleeping Computer","date_rel":"5h ago"},{"title":"Microsoft fixes bug that wiped Windows desktop settings","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bug-that-wiped-windows-desktop-settings/","source":"Bleeping Computer","date_rel":"8h ago"},{"title":"New \u2018ShieldCrash\u2019 Zero-Day Exploit Targets Microsoft Defender","link":"https://www.securityweek.com/new-shieldcrash-zero-day-exploit-targets-microsoft-defender/","source":"SecurityWeek","date_rel":"9h ago"},{"title":"Microsoft fixes record 964 flaws, including 2 exploited zero-days","link":"https://www.malwarebytes.com/blog/news/2026/09/microsoft-fixes-record-964-flaws-including-2-exploited-zero-days","source":"Malwarebytes Labs","date_rel":"9 Sep"},{"title":"Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026","link":"https://www.infosecurity-magazine.com/news/microsoft-patch-tuesday-record/","source":"Infosecurity Magazine","date_rel":"9 Sep"}]},{"title":"Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits","link":"https://www.theregister.com/research/2026/09/09/novel-blue-moon-kit-targeting-chrome-and-windows-reflects-new-reality-of-ai-driven-exploits/5295399","reason":"Chrome","category":"News","sources":["Ars Technica Security","Bleeping Computer","Fortinet PSIRT","Malwarebytes Labs","The Hacker News","The Register Security","Volexity"],"coverage":7,"cve_ids":["CVE-2026-87491"],"summary":"At least four espionage groups, most with suspected links to China, are using a new exploit kit that chains two Chromium-based browser flaws and one Microsoft Windows bug to break into organizations' networks in the US\u2026","source":"The Register Security","date_rel":"18h ago","thumbnail":"https://image.theregister.com/?imageId=5295408&width=800","description":"At least four espionage groups, most with suspected links to China, are using a new exploit kit that chains two Chromium-based browser flaws and one Microsoft Windows bug to break into organizations' networks in the US and Southeast Asia. Mark Kelly, a threat researcher at email security shop Proofpoint, told The Register that the researchers don't know exactly who was targeted, nor how, and so far the damage appears limited. \u201cIn terms of organizations targeted, we saw fewer than 20 organizations globally targeted across the activity highlighted,\" he said. \"However, the true number is almost\u2026","related":[{"title":"BlueMoon exploit kit turns Chrome and Windows flaws into attacks","link":"https://www.malwarebytes.com/blog/bugs/2026/09/bluemoon-exploit-kit-turns-chrome-and-windows-flaws-into-attacks","source":"Malwarebytes Labs","date_rel":"1h ago"},{"title":"New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws","link":"https://www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/","source":"Bleeping Computer","date_rel":"2h ago"},{"title":"Update Chrome now to protect against an actively exploited vulnerability","link":"https://www.malwarebytes.com/blog/bugs/2026/09/update-chrome-now-to-protect-against-an-actively-exploited-vulnerability","source":"Malwarebytes Labs","date_rel":"6h ago"},{"title":"Four groups caught using the same Chrome and Windows exploit kit","link":"https://arstechnica.com/information-technology/2026/09/4-groups-caught-using-the-same-chrome-and-windows-exploit-kit/","source":"Ars Technica Security","date_rel":"20h ago"},{"title":"Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows","link":"https://www.volexity.com/blog/2026/09/09/mind-the-patch-gap-multiple-chinese-threat-actors-chain-0-day-exploits-in-chrome-windows/","source":"Volexity","date_rel":"23h ago"},{"title":"Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week","link":"https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html","source":"The Hacker News","date_rel":"9 Sep"}]},{"title":"US Government Accuses Chinese AI Firms of Distilling Frontier Models","link":"https://www.darkreading.com/application-security/us-government-chinese-ai-firms-distilling-frontier-models","reason":"Google","category":"News","sources":["CCCS Alerts & Advisories","Cisco Talos","Dark Reading","Infosecurity Magazine","The Hacker News","The Register Security"],"coverage":6,"cve_ids":[],"summary":"US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.","source":"Dark Reading","date_rel":"21h ago","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt33b13b556aa2e63e/6aa1a92888ea9adc3dabaf29/distillery-ArtistGNDphotography-GettyImages-2195175104.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Google security advisory (AV26-904)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-904","source":"CCCS Alerts & Advisories","date_rel":"21h ago"},{"title":"Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA","link":"https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html","source":"The Hacker News","date_rel":"9 Sep"},{"title":"ClickFix Moves into the Browser to Steal Cryptocurrency","link":"https://www.infosecurity-magazine.com/news/clickfix-browser-cryptocurrency/","source":"Infosecurity Magazine","date_rel":"9 Sep"},{"title":"Attackers Use Multi-Hop Google Redirects for Phishing Campaign","link":"https://www.darkreading.com/cyberattacks-data-breaches/attackers-multi-hop-google-redirects-phishing-campaign","source":"Dark Reading","date_rel":"8 Sep"},{"title":"AI Coding Tools Now a Prime Target for Threat Actors, Google Warns","link":"https://www.infosecurity-magazine.com/news/ai-coding-tools-threat-actors/","source":"Infosecurity Magazine","date_rel":"8 Sep"},{"title":"Extortion crews have their eyes on high-value AI data, Google warns","link":"https://www.theregister.com/research/2026/09/08/extortion-crews-have-their-eyes-on-high-value-ai-data-google-warns/5294640","source":"The Register Security","date_rel":"8 Sep"}]},{"title":"ZDI-26-645: Fortinet FortiSandbox write_remote_backup_to_crontab cronValue Command Injection Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-645/","reason":"Fortinet","category":"Research","sources":["CCCS Alerts & Advisories","SecurityWeek","Zero Day Initiative"],"coverage":3,"cve_ids":[],"summary":"This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiSandbox. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of\u2026","source":"Zero Day Initiative","date_rel":"9 Sep","thumbnail":"","description":"This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiSandbox. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-84387.","related":[{"title":"Cybersecurity M&A Roundup: 33 Deals Announced in August 2026","link":"https://www.securityweek.com/cybersecurity-ma-roundup-33-deals-announced-in-august-2026/","source":"SecurityWeek","date_rel":"43m ago"},{"title":"Fortinet security advisory (AV26-023) - Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-023","source":"CCCS Alerts & Advisories","date_rel":"21h ago"},{"title":"Fortinet security advisory (AV26-898)","link":"https://cyber.gc.ca/en/alerts-advisories/fortinet-security-advisory-av26-898","source":"CCCS Alerts & Advisories","date_rel":"9 Sep"}]},{"title":"Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell","link":"https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html","reason":"Adobe","category":"News","sources":["CCCS Alerts & Advisories","The Hacker News","Zero Day Initiative"],"coverage":3,"cve_ids":[],"summary":"Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as\u2026","source":"The Hacker News","date_rel":"8 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_xdakttovno7kFgFYIw5XGFGcSZibVvXYB64vih4iZpc4_WY_t7oe1X3igSPGXBa8UTkf4z4xn_GzZ_n7PmuFFvYC8Wsmb04PxYP5z-XHjZZFe_SASihwZNg1dxHXQzz8hBRo-6LhvQmwyo_MA9Kj6hrcci6ouvOX1D4f-0dNvs57M6WneQHC61yZkF_o/s1600/magento.jpg","description":"Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. \"This update resolves a critical","related":[{"title":"Adobe security advisory (AV26-808) \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-808","source":"CCCS Alerts & Advisories","date_rel":"54m ago"},{"title":"ZDI-26-679: Adobe Photoshop DCM JPEG Image Parsing Integer Overflow Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-679/","source":"Zero Day Initiative","date_rel":"11h ago"},{"title":"ZDI-26-678: Adobe Photoshop DCM File Parsing Integer Overflow Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-678/","source":"Zero Day Initiative","date_rel":"11h ago"},{"title":"ZDI-26-677: Adobe Photoshop DCM JPEG-LS Image Parsing Integer Overflow Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-677/","source":"Zero Day Initiative","date_rel":"11h ago"},{"title":"Adobe security advisory (AV26-888) \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/adobe-security-advisory-av26-888","source":"CCCS Alerts & Advisories","date_rel":"8 Sep"}]},{"title":"CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline","link":"https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html","reason":"Cisco","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal\u2026","source":"The Hacker News","date_rel":"6h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh7j6Sm8OqDeYzrbb5faLBuDOc0zIMlvfjiKbn1aCMpx_2iBl6gb3HhJhpbqU8SPajHUClJEXUwnFbY1DcubmzWeVaWCyGcHkw45rCYqU_4IFO_g4OwdyNrTFFK3l3YsXwfOWQj2QtW3UTeglKmyRJ4GvbVKMxLTByMgeZ7E0WWpxpi50qie2lx9DbCY9rr/s1600/cisa-list.jpg","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below - CVE-2026-20079 (CVSS score: 10.0) - An authentication","related":[{"title":"Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers","link":"https://www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/","source":"Bleeping Computer","date_rel":"1h ago"},{"title":"Cisco security advisory (AV26-197) \u2013 Update 3","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-197","source":"CCCS Alerts & Advisories","date_rel":"20h ago"}]},{"title":"Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks","link":"https://cybersecuritynews.com/check-point-vpn-vulnerabilities/","reason":"Check Point","category":"News","sources":["CCCS Alerts & Advisories","Cyber Security News","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-85102","CVE-2026-85103"],"summary":"Check Point Software has disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a maximum CVSS score of 9.8 and both capable of allowing unauthenticated remote\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Check-Point-VPN-Vulnerabilities.webp","description":"Check Point Software has disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a maximum CVSS score of 9.8 and both capable of allowing unauthenticated remote code execution under specific conditions. Check Point\u2019s own research team uncovered the flaws, and the company says it has found no evidence of active exploitation or public proof-of-concept code as of this writing. Check Point VPN Vulnerabilities CVE-2026-85102 is rooted in improper certificate trust validation during VPN negotiation, tracked under CWE-295. According to Check\u2026","related":[{"title":"Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE","link":"https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html","source":"The Hacker News","date_rel":"5h ago"},{"title":"Check Point security advisory (AV26-902)","link":"https://cyber.gc.ca/en/alerts-advisories/check-point-security-advisory-av26-902","source":"CCCS Alerts & Advisories","date_rel":"21h ago"},{"title":"ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account","link":"https://thehackernews.com/2026/09/chatgpt-flaw-let-planted-prompt-send.html","source":"The Hacker News","date_rel":"8 Sep"}]},{"title":"Active exploitation of Cisco Secure Firewall Management Center vulnerabilities","link":"https://blog.talosintelligence.com/fmc-ongoing-exploitation/","reason":"CVE-2026-20079","category":"Threat Intel","sources":["Bleeping Computer","Cisco Talos","SecurityWeek"],"coverage":3,"cve_ids":["CVE-2026-20079"],"summary":"Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco\u2019s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched\u2026","source":"Cisco Talos","date_rel":"9 Sep","thumbnail":"https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/09/threat_advisory.jpg","description":"Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco\u2019s Secure Firewall Management Center (FMC) Software. First, CVE-2026-20079 is an authentication bypass vulnerability in unpatched instances of Cisco\u2019s Secure FMC Software, which allows an unauthenticated, remote attacker to bypass authentications and execute scripts on impacted devices to obtain root access to the underlying operating system. Second, CVE-2026-20316 is a vulnerability that allows a remote attacker to log in using a low-privileged account. CVE-2026-20079 is a critical vulnerability with a CVSS\u2026","related":[{"title":"Organizations Warned of Cisco Secure FMC Exploitation","link":"https://www.securityweek.com/organizations-warned-of-cisco-secure-fmc-exploitation/","source":"SecurityWeek","date_rel":"6h ago"},{"title":"Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks","link":"https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/","source":"Bleeping Computer","date_rel":"19h ago"}]},{"title":"Top 10 Best Server Security Solutions in 2026","link":"https://cybersecuritynews.com/best-server-security-solutions/","reason":"Windows","category":"News","sources":["Cyber Security News","Fortinet PSIRT","Microsoft Security"],"coverage":3,"cve_ids":["CVE-2026-68877","CVE-2026-69508","CVE-2026-69777"],"summary":"Bottom line up front: servers are not big laptops. They run Linux as often as Windows, can\u2019t tolerate agent-induced latency, host the data ransomware actually wants, and increasingly live as VMs, containers, or cloud\u2026","source":"Cyber Security News","date_rel":"8h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Best-Server-Security-Solutions-.webp","description":"Bottom line up front: servers are not big laptops. They run Linux as often as Windows, can\u2019t tolerate agent-induced latency, host the data ransomware actually wants, and increasingly live as VMs, containers, or cloud instances. Deploying dedicated endpoint detection and response (EDR) on servers requires balancing performance overhead with deep telemetry. Trend Micro\u2019s server heritage still leads for hybrid estates, CrowdStrike and SentinelOne bring the strongest detection, Defender for Servers wins on Azure-centric economics and the quiet failure mode everywhere is the hypervisor nobody\u2019s\u2026","related":[{"title":"CVE-2026-69777 Windows DHCP Client Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69777","source":"Microsoft Security","date_rel":"9 Sep"},{"title":"CVE-2026-69508 Windows MIDI Service Module Elevation of Privileges Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69508","source":"Microsoft Security","date_rel":"9 Sep"},{"title":"CVE-2026-68877 Windows Storage Spaces Controller Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68877","source":"Microsoft Security","date_rel":"9 Sep"},{"title":"Arbitrary process termination from exposed minifilter communication port","link":"https://fortiguard.fortinet.com/psirt/FG-IR-26-165","source":"Fortinet PSIRT","date_rel":"8 Sep"}]},{"title":"Google Play Early Access Abused to Push Thousands of Deceptive Android Apps","link":"https://thehackernews.com/2026/09/google-play-early-access-abused-to-push.html","reason":"Android","category":"News","sources":["Infosecurity Magazine","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the\u2026","source":"The Hacker News","date_rel":"2h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh4vbRDTWaQnxiILexae9P_rAk0hzx-re0czK2tM_WNQcoVDPlKblD4M5qOy8FZ9hHJBDLGjHHAyYutmaiacI54o5q1SH5qSbsptviRF16T2r6i8Iywvzk4GJprCm60p12qrK7t3R8h_ZR7CUoG47YfdeOb0iKY0WRapDeObI8_poWklMtKXrmr421Scjzi/s1600/play.jpg","description":"Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their","related":[{"title":"Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews","link":"https://www.securityweek.com/deceptive-android-apps-exploit-google-play-early-access-to-evade-reviews/","source":"SecurityWeek","date_rel":"3h ago"},{"title":"MantaxOtax Android Malware Combines Ransomware With Spyware","link":"https://www.infosecurity-magazine.com/news/mantaxotax-android-malware/","source":"Infosecurity Magazine","date_rel":"3h ago"},{"title":"Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks","link":"https://thehackernews.com/2026/09/gigabud-creates-android-work-profiles.html","source":"The Hacker News","date_rel":"5h ago"},{"title":"Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls","link":"https://www.infosecurity-magazine.com/news/wechat-zeroclick-worm-hijack/","source":"Infosecurity Magazine","date_rel":"9 Sep"},{"title":"Gigabud Uses Android App Cloning to Evade Fraud Detection","link":"https://www.infosecurity-magazine.com/news/gigabud-android-app-cloning-fraud/","source":"Infosecurity Magazine","date_rel":"9 Sep"},{"title":"WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls","link":"https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html","source":"The Hacker News","date_rel":"8 Sep"}]}],"worth_reading":[{"title":"Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AI","link":"https://www.tenable.com/blog/ai-agent-security-openai-tenable-cyberagents-exchange-inspector","reason":"Exchange","category":"Research","sources":["Microsoft Security","Tenable Blog"],"coverage":2,"cve_ids":["CVE-2026-55007"],"summary":"Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That\u2019s why for its new CyberAgents Exchange registry, Tenable paired\u2026","source":"Tenable Blog","date_rel":"9 Sep","thumbnail":"","description":"Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That\u2019s why for its new CyberAgents Exchange registry, Tenable paired its exposure management expertise with OpenAI GPT Cyber models to create the CyberAgents Exchange AI Inspector. Key takeaways The Exchange Inspector combines Tenable\u2019s exposure detection with OpenAI\u2019s GPT Cyber models and with human oversight to rigorously vet submissions made to the CyberAgents Exchange. Securing AI agents requires analyzing a broad attack surface that includes\u2026","related":[{"title":"CVE-2026-55007 Microsoft Exchange Server Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-55007","source":"Microsoft Security","date_rel":"8 Sep"}]},{"title":"StyleSmuggler (CVE-2026-75650): Frequently asked questions about Adobe Commerce and Magento zero-day","link":"https://www.tenable.com/blog/stylesmuggler-cve-2026-75650-frequently-asked-questions-about-adobe-commerce-and-magento-zero","reason":"CVE-2026-75650","category":"Research","sources":["CISA Alerts & Advisories","Tenable Blog"],"coverage":2,"cve_ids":["CVE-2026-75650"],"summary":"A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a\u2026","source":"Tenable Blog","date_rel":"8 Sep","thumbnail":"","description":"A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available. Key takeaways CVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication. Active exploitation of CVE-2026-75650 began on September 4, 2026, three days before Adobe released a hotfix, with multiple victim stores confirmed across different\u2026","related":[{"title":"CISA Adds Four Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/08/cisa-adds-four-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"8 Sep"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-67401","vendor":"WebPros","product":"cPanel","severity":"CRITICAL","score":9.9,"description":"A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi in EmailTrack component","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-67401"},{"id":"CVE-2026-19583","vendor":"Rapid7","product":"Velociraptor","severity":"CRITICAL","score":9.9,"description":"Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission to schedule. However\u2026","cwe":"CWE-732","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19583"},{"id":"CVE-2026-85978","vendor":"Perforce","product":"Akana","severity":"CRITICAL","score":9.8,"description":"An unauthenticated remote code execution vulnerability exists in the Policy Manager console of\u00a0Akana\u00a0API Platform. A path normalization discrepancy between the authentication filter and the servlet dispatcher allows a crafted request to byp\u2026","cwe":"CWE-41","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-85978"},{"id":"CVE-2026-80172","vendor":"Dell","product":"Secure Connect Gateway","severity":"CRITICAL","score":9.8,"description":"Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00, contains an Insufficient Verification of Data Authenticity vulnerability. An unauthenticated attacker with remote access could ex\u2026","cwe":"CWE-345","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-80172"},{"id":"CVE-2026-85102","vendor":"Check Point","product":"Quantum Security Gateway","severity":"CRITICAL","score":9.8,"description":"Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.","cwe":"CWE-295","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-85102"},{"id":"CVE-2026-85103","vendor":"Check Point","product":"Quantum Security Gateway","severity":"CRITICAL","score":9.8,"description":"A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.","cwe":"CWE-122","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-85103"},{"id":"CVE-2026-87929","vendor":"MaxSite","product":"MaxSite CMS","severity":"CRITICAL","score":9.8,"description":"MaxSite CMS through 109.6 ships with a hardcoded session encryption key in application/config/config.php that is never changed during installation, allowing unauthenticated attackers to forge administrator session cookies. Attackers can min\u2026","cwe":"CWE-321","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-87929"},{"id":"CVE-2026-18351","vendor":"WordPress","product":"Drag and Drop File Upload for Elementor Forms","severity":"CRITICAL","score":9.8,"description":"The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficient file type validati\u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18351"},{"id":"CVE-2026-7188","vendor":"Armiya Information Technologies Ltd. Co.","product":"Access Control System","severity":"CRITICAL","score":9.8,"description":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows SQL Injection.\n\nThis issue affects Access Control System: before Ver\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-7188"},{"id":"CVE-2026-88278","vendor":"GeoVision Inc.","product":"GV-LPCLPC2011/2211","severity":"CRITICAL","score":9.8,"description":"GeoVision GV-LPC2211 V1.13 fails to enforce WS-Security UsernameToken freshness or nonce reuse protection, allowing a captured PasswordDigest token to be replayed for subsequent ONVIF operations.","cwe":"CWE-294","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-88278"}],"vendor_spikes":[{"vendor":"Dell","count":59,"critical_count":1},{"vendor":"Unknown","count":35,"critical_count":0},{"vendor":"grokability","count":32,"critical_count":0},{"vendor":"WordPress","count":24,"critical_count":1},{"vendor":"GeoVision Inc.","count":22,"critical_count":2},{"vendor":"Apache","count":20,"critical_count":0},{"vendor":"pmmp","count":18,"critical_count":0},{"vendor":"open-webui","count":13,"critical_count":0},{"vendor":"Microsoft","count":12,"critical_count":1},{"vendor":"Red Hat","count":12,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":19,"new_cve_count":366,"has_news_data":true,"has_cve_data":true}