Skip to content

Morning Brief

Monday, September 14, 2026 · generated · ~5 min read

Top developments

Perfect-10 GitLab bug under attack days after patch lands

CISA says attackers are exploiting a maximum-severity GitLab flaw that lets unauthenticated miscreants read arbitrary files from vulnerable servers after the code shack released fixes on September 10. The US…

Microsoft Offers Up to $30,000 for Critical AI Flaws in Dynamics 365 and Power Platform

Microsoft is offering security researchers up to $30,000 for finding critical AI vulnerabilities in Dynamics 365 and Power Platform, sharpening its focus on flaws that could manipulate AI inference or expose information…

A week in security (September 7 – September 13)

Here’s what we’ve covered in the last seven days on Malwarebytes Labs: Crypto customers targeted by scammers after email marketing provider breach Android malware creates a hidden copy of your banking app BlueMoon…

Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning

Cyclops Blink has returned in a form that gives attackers a deeper view inside corporate networks. The malware was found on compromised Cisco Firewall Management Center devices, where it can maintain remote access…

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor.

Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware

A single X DM split into two malware chains: AMOS stealer on Mac, NetSupport Manager on Windows, see the Huntress SOC analyst breakdown.

Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users

A browser extension promoted as a Twitch viewing helper has been found sending live account tokens through servers controlled by its operator. The add-on, called “Twitch Enhanced Viewer | JeetBot,” was available to…

New York Seizes 12 Celebrity Deepfake Websites

The New York District Attorney announced on Monday that it has seized 12 websites hosting AI-generated non-consensual intimate imagery, primarily of celebrities and public figures. The DA’s office said it believes that…

Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials

Hackers are conducting a large-scale automated scanning campaign against internet-exposed Vite development servers, attempting to steal AWS credentials , Azure access tokens, environment variables, and…

Revolut discloses data breach exposing financial info, passports

Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency.

Vulnerability watch

CVE-2026-81648 WordPress · CryptoPayment Gateway CRITICAL 10.0

The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the…

CVE-2026-90605 Totolink · A3002MU CWE-119 CRITICAL 9.9

A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffe…

CVE-2026-90606 Totolink · A3002MU CWE-119 CRITICAL 9.9

A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to bu…

CVE-2026-90607 Totolink · A3002MU CWE-119 CRITICAL 9.9

A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. T…

CVE-2026-90608 Totolink · A3002MU CWE-119 CRITICAL 9.9

A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is p…

CVE-2026-90680 D-Link · DIR-823G CWE-119 CRITICAL 9.9

A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gat…

CVE-2026-90692 D-Link · DIR-878 CWE-119 CRITICAL 9.9

A vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynamicDNSIPv6Settings of the component Dynamic DNS IPv6 Settings. The manipulation of the argument IPv6Address/Hostname results in stack-based buffer overf…

CVE-2026-90693 D-Link · DIR-878 CWE-119 CRITICAL 9.9

A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings. This manipulation of the argument Primary/Secondary causes stack-based buffer overflow. Remote exploitation of the atta…

CVE-2026-90699 D-Link · DWR-M920 CWE-77 CRITICAL 9.9

A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated re…

CVE-2026-82787 Contec Co., Ltd. · CPSL-08P1EN CWE-306 CRITICAL 9.8

Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication.

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →