{"date_iso":"2026-09-14","date_human":"Monday, September 14, 2026","generated_utc":"2026-09-14 18:31 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Perfect-10 GitLab bug under attack days after patch lands","link":"https://www.theregister.com/security/2026/09/14/perfect-10-gitlab-bug-under-attack-days-after-patch-lands/5296176","reason":"Gitlab","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","CyberScoop","Infosecurity Magazine","Rapid7 Blog","The Register Security"],"coverage":6,"cve_ids":["CVE-2026-85706"],"summary":"CISA says attackers are exploiting a maximum-severity GitLab flaw that lets unauthenticated miscreants read arbitrary files from vulnerable servers after the code shack released fixes on September 10. The US\u2026","source":"The Register Security","date_rel":"4h ago","thumbnail":"https://image.theregister.com/?imageId=5279434&width=800","description":"CISA says attackers are exploiting a maximum-severity GitLab flaw that lets unauthenticated miscreants read arbitrary files from vulnerable servers after the code shack released fixes on September 10. The US Cybersecurity and Infrastructure Security Agency has added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog. The vulnerability is a path traversal bug in the repository commits API affecting GitLab Community Edition and Enterprise Edition. GitLab rates it a perfect 10.0, the maximum score on the CVSS v3.1 severity scale. Under certain conditions, an attacker doesn't need to\u2026","related":[{"title":"CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild","link":"https://www.rapid7.com/blog/post/etr-cve-2026-85706-critical-gitlab-path-traversal-exploited-in-the-wild","source":"Rapid7 Blog","date_rel":"8h ago"},{"title":"Hackers Exploit Maximum Severity Flaw in GitLab","link":"https://www.infosecurity-magazine.com/news/hackers-exploit-maximum-severity/","source":"Infosecurity Magazine","date_rel":"8h ago"},{"title":"CISA: Hackers now exploit max severity GitLab flaw in attacks","link":"https://www.bleepingcomputer.com/news/security/cisa-hackers-now-exploit-max-severity-gitlab-flaw-in-attacks/","source":"Bleeping Computer","date_rel":"11h ago"},{"title":"GitLab security advisory (AV26-917)","link":"https://cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-917","source":"CCCS Alerts & Advisories","date_rel":"11 Sep"},{"title":"GitLab\u2019s critical flaw is already drawing internet-wide probes","link":"https://cyberscoop.com/gitlab-critical-flaws-path-traversal-scans/","source":"CyberScoop","date_rel":"11 Sep"}]},{"title":"Microsoft Offers Up to $30,000 for Critical AI Flaws in Dynamics 365 and Power Platform","link":"https://cybersecuritynews.com/microsoft-ai-bug-bounty/","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Cyber Security News","Schneier on Security","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"Microsoft is offering security researchers up to $30,000 for finding critical AI vulnerabilities in Dynamics 365 and Power Platform, sharpening its focus on flaws that could manipulate AI inference or expose information\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Microsoft-AI-Bug-Bounty.webp","description":"Microsoft is offering security researchers up to $30,000 for finding critical AI vulnerabilities in Dynamics 365 and Power Platform, sharpening its focus on flaws that could manipulate AI inference or expose information through model behavior. The program covers qualifying bugs in Microsoft-hosted services and third-party or open-source components embedded in them, provided researchers demonstrate a security impact on an in-scope service. Under the bounty table, a high-quality report documenting critical \u201cInference Manipulation\u201d or \u201cInferential Information Disclosure\u201d can earn the maximum\u2026","related":[{"title":"Microsoft\u2019s Patching","link":"https://www.schneier.com/blog/archives/2026/09/microsofts-patching.html","source":"Schneier on Security","date_rel":"7h ago"},{"title":"Microsoft: September updates cause RDS failures on Windows Server","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-september-updates-cause-rds-failures-on-windows-server/","source":"Bleeping Computer","date_rel":"8h ago"},{"title":"Microsoft: September updates break audio on some Windows PCs","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-september-updates-break-audio-on-some-windows-pcs/","source":"Bleeping Computer","date_rel":"10h ago"},{"title":"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data","link":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html","source":"The Hacker News","date_rel":"13 Sep"}]},{"title":"A week in security (September 7 \u2013 September 13)","link":"https://www.malwarebytes.com/blog/news/2026/09/a-week-in-security-september-7-september-13","reason":"Android","category":"Threat Intel","sources":["Bleeping Computer","CCCS Alerts & Advisories","Malwarebytes Labs"],"coverage":3,"cve_ids":[],"summary":"Here\u2019s what we\u2019ve covered in the last seven days on Malwarebytes Labs: Crypto customers targeted by scammers after email marketing provider breach Android malware creates a hidden copy of your banking app BlueMoon\u2026","source":"Malwarebytes Labs","date_rel":"11h ago","thumbnail":"","description":"Here\u2019s what we\u2019ve covered in the last seven days on Malwarebytes Labs: Crypto customers targeted by scammers after email marketing provider breach Android malware creates a hidden copy of your banking app BlueMoon exploit kit turns Chrome and Windows flaws into attacks Will AI kill us all within the next decade? Update Chrome now to protect against an actively exploited vulnerability Copyright scammers get Instagram accounts suspended and demand payment More than 100,000 fake stores are out to steal your card details Microsoft fixes record 964 flaws, including 2 exploited zero-days The push\u2026","related":[{"title":"Android security advisory \u2013 September 2026 monthly rollup (AV26-920)","link":"https://cyber.gc.ca/en/alerts-advisories/android-security-advisory-september-2026-monthly-rollup-av26-920","source":"CCCS Alerts & Advisories","date_rel":"1h ago"},{"title":"Hackers abused Claude to extract secrets from 1.8M Android apps","link":"https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/","source":"Bleeping Computer","date_rel":"11 Sep"}]},{"title":"Cyclops Blink Evolves Into x86-64 Linux Implant With Packet Sniffing and Internal Network Scanning","link":"https://cybersecuritynews.com/cyclops-blink-evolves/","reason":"Linux","category":"News","sources":["Cyber Security News","Microsoft Security","Zero Day Initiative"],"coverage":3,"cve_ids":["CVE-2026-43502","CVE-2026-76023"],"summary":"Cyclops Blink has returned in a form that gives attackers a deeper view inside corporate networks. The malware was found on compromised Cisco Firewall Management Center devices, where it can maintain remote access\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Cyclops-Blink-Evolves-Into-x86-64-Linux-Implant-With-Packet-Sniffing-and-Internal-Network-Scanning.webp","description":"Cyclops Blink has returned in a form that gives attackers a deeper view inside corporate networks. The malware was found on compromised Cisco Firewall Management Center devices, where it can maintain remote access, inspect traffic, and map systems behind the network edge. The activity is concerning because management appliances occupy trusted positions. Recent reporting that covered attackers gaining root access shows how a breach at this layer can expose configurations, credentials, and paths to systems that are otherwise difficult to reach. Analysts at Sophos identified the new implant in\u2026","related":[{"title":"New ZcopyReaper Linux Kernel Vulnerability Enables Privilege Escalation Attacks","link":"https://cybersecuritynews.com/zcopyreaper-linux-kernel-vulnerability/","source":"Cyber Security News","date_rel":"5h ago"},{"title":"ZDI-26-702: Linux Kernel usbnet Driver Race Condition Privilege Escalation Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-702/","source":"Zero Day Initiative","date_rel":"13h ago"},{"title":"ZDI-26-701: Linux Kernel TLS Protocol Out-Of-Bounds Read Information Disclosure Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-701/","source":"Zero Day Initiative","date_rel":"13h ago"},{"title":"ZDI-26-700: Linux Kernel QFQ Plus Scheduler Use-After-Free Local Privilege Escalation Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-700/","source":"Zero Day Initiative","date_rel":"13h ago"},{"title":"Chromium CVE-2026-76023: Improper resource control in Linux Toolkit Theming","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-76023","source":"Microsoft Security","date_rel":"12 Sep"}]},{"title":"Hackers exploit Tencent app flaw to deploy GrayRabbit malware","link":"https://www.bleepingcomputer.com/news/security/hackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware/","reason":"Windows","category":"News","sources":["Bleeping Computer","Microsoft Security","SecurityWeek"],"coverage":3,"cve_ids":["CVE-2026-51990","CVE-2026-62721","CVE-2026-85921"],"summary":"Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor.","source":"Bleeping Computer","date_rel":"13 Sep","thumbnail":"","description":"","related":[{"title":"CVE-2026-85921 Windows Secure Kernel Mode Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921","source":"Microsoft Security","date_rel":"4h ago"},{"title":"CVE-2026-62721 Windows User-Mode Power Service (UMPS) Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62721","source":"Microsoft Security","date_rel":"4h ago"},{"title":"Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution","link":"https://www.securityweek.com/chinese-hackers-exploit-critical-tencent-software-flaw-for-one-click-code-execution/","source":"SecurityWeek","date_rel":"6h ago"}]},{"title":"Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware","link":"https://www.huntress.com/blog/google-doc-sidebar-malware-mac-windows","reason":"Google","category":"Threat Intel","sources":["Huntress","Malwarebytes Labs"],"coverage":2,"cve_ids":[],"summary":"A single X DM split into two malware chains: AMOS stealer on Mac, NetSupport Manager on Windows, see the Huntress SOC analyst breakdown.","source":"Huntress","date_rel":"just now","thumbnail":"https://cdn.builder.io/api/v1/image/assets%2F3eb6f92aedf74f109c7b4b0897ec39a8%2Fdca76d702afd4b8fb78824a5b8651986","description":"","related":[{"title":"Google\u2019s new search redirects make links harder to check before you click","link":"https://www.malwarebytes.com/blog/news/2026/09/googles-new-search-redirects-make-links-harder-to-check-before-you-click","source":"Malwarebytes Labs","date_rel":"4h ago"}]},{"title":"Malicious Twitch Extension Exposes OAuth Tokens of 30,000 Chrome and Firefox Users","link":"https://cybersecuritynews.com/malicious-twitch-extension/","reason":"Extension Malicious Exposes","category":"News","sources":["Cyber Security News","Infosecurity Magazine","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A browser extension promoted as a Twitch viewing helper has been found sending live account tokens through servers controlled by its operator. The add-on, called \u201cTwitch Enhanced Viewer | JeetBot,\u201d was available to\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Malicious-Twitch-Extension-Exposes-OAuth-Tokens-of-30000-Chrome-and-Firefox-Users.webp","description":"A browser extension promoted as a Twitch viewing helper has been found sending live account tokens through servers controlled by its operator. The add-on, called \u201cTwitch Enhanced Viewer | JeetBot,\u201d was available to Chrome and Firefox users and advertised conveniences such as ad blocking, higher-quality playback, region-unlocked streams, and automatic channel-point collection. The risk sits behind those seemingly useful features. To alter video delivery, the extension reroutes Twitch playlist requests through third-party proxies. During that process, it captures the logged-in user\u2019s OAuth\u2026","related":[{"title":"Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens","link":"https://www.infosecurity-magazine.com/news/malicious-twitch-extension-oauth/","source":"Infosecurity Magazine","date_rel":"3h ago"},{"title":"Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users","link":"https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html","source":"The Hacker News","date_rel":"11h ago"}]},{"title":"New York Seizes 12 Celebrity Deepfake Websites","link":"https://www.404media.co/new-york-district-attorney-seizes-12-celebrity-deepfake-websites/","reason":"Celebrity Deepfake Websites","category":"News","sources":["404 Media","Wired Security"],"coverage":2,"cve_ids":[],"summary":"The New York District Attorney announced on Monday that it has seized 12 websites hosting AI-generated non-consensual intimate imagery, primarily of celebrities and public figures. The DA\u2019s office said it believes that\u2026","source":"404 Media","date_rel":"1h ago","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/09/20260914_130929-1.jpg","description":"The New York District Attorney announced on Monday that it has seized 12 websites hosting AI-generated non-consensual intimate imagery, primarily of celebrities and public figures. The DA\u2019s office said it believes that this marks the largest seizure of such sites in history. The people using and running these sites who are now under investigation used AI tools to turn approximately 1,200 people\u2019s photos into \u201chyper-realistic\u201d images and videos of them engaged in sexual conduct, according to the DA\u2019s office. The images allegedly depicted \u201cpoliticians, first ladies of multiple countries\u2026","related":[{"title":"New York Seizes a Dozen Celebrity Deepfake Websites","link":"https://www.wired.com/story/new-york-seizes-a-dozen-celebrity-deepfake-websites/","source":"Wired Security","date_rel":"1h ago"}]},{"title":"Hackers Mass-Scan Exposed Vite Servers to Steal AWS and Azure Cloud Credentials","link":"https://cybersecuritynews.com/vite-servers-under-attack/","reason":"Aws","category":"News","sources":["Bleeping Computer","Cyber Security News"],"coverage":2,"cve_ids":[],"summary":"Hackers are conducting a large-scale automated scanning campaign against internet-exposed Vite development servers, attempting to steal AWS credentials , Azure access tokens, environment variables, and\u2026","source":"Cyber Security News","date_rel":"1h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Vite-Server-Cloud-Credentials.webp","description":"Hackers are conducting a large-scale automated scanning campaign against internet-exposed Vite development servers, attempting to steal AWS credentials , Azure access tokens, environment variables, and Infrastructure-as-Code secrets. F5 honeypot sensors recorded 807 session-grouped attacks and about 32,000 raw events in August 2026, a sharp increase from only 1,732 Vite-related file-read events observed over the previous three months. The operation primarily exploited CVE-2026-39364, a high-severity Vite file-disclosure vulnerability published in April 2026. Attackers also tested older Vite\u2026","related":[{"title":"Hackers target exposed Vite dev servers to steal AWS, Azure secrets","link":"https://www.bleepingcomputer.com/news/security/hackers-target-exposed-vite-dev-servers-to-steal-aws-azure-secrets/","source":"Bleeping Computer","date_rel":"2h ago"},{"title":"AWS Systems Manager Agent Vulnerability Allows Attackers to Bypass Port-Forwarding Restrictions","link":"https://cybersecuritynews.com/aws-systems-manager-agent-vulnerability/","source":"Cyber Security News","date_rel":"3h ago"}]},{"title":"Revolut discloses data breach exposing financial info, passports","link":"https://www.bleepingcomputer.com/news/security/revolut-discloses-data-breach-exposing-financial-info-passports/","reason":"Financial Revolut Breach","category":"News","sources":["Bleeping Computer","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency.","source":"Bleeping Computer","date_rel":"9h ago","thumbnail":"","description":"","related":[{"title":"Personal, Financial Info Exposed in Revolut Data Breach","link":"https://www.securityweek.com/personal-financial-info-exposed-in-revolut-data-breach/","source":"SecurityWeek","date_rel":"5h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-81648","vendor":"WordPress","product":"CryptoPayment Gateway","severity":"CRITICAL","score":10.0,"description":"The CryptoPayment Gateway WordPress plugin from 1.2.1 to 1.2.2 does not apply an authorization check on one of its AJAX endpoints, allowing unauthenticated users to invoke administrative operations, including deleting arbitrary files on the\u2026","cwe":"","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-81648"},{"id":"CVE-2026-90605","vendor":"Totolink","product":"A3002MU","severity":"CRITICAL","score":9.9,"description":"A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6addr can lead to buffe\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90605"},{"id":"CVE-2026-90606","vendor":"Totolink","product":"A3002MU","severity":"CRITICAL","score":9.9,"description":"A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument static_ipv6 leads to bu\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90606"},{"id":"CVE-2026-90607","vendor":"Totolink","product":"A3002MU","severity":"CRITICAL","score":9.9,"description":"A vulnerability was detected in Totolink A3002MU Hh-B20211125.1046. Impacted is the function formNewSchedule of the file /boafrm/formNewSchedule of the component boa. The manipulation of the argument submit-url results in buffer overflow. T\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90607"},{"id":"CVE-2026-90608","vendor":"Totolink","product":"A3002MU","severity":"CRITICAL","score":9.9,"description":"A flaw has been found in Totolink A3002MU Hh-B20211125.1046. The affected element is the function formPortFw of the file /boafrm/formPortFw of the component boa. This manipulation of the argument service_type causes buffer overflow. It is p\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90608"},{"id":"CVE-2026-90680","vendor":"D-Link","product":"DIR-823G","severity":"CRITICAL","score":9.9,"description":"A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_20181207. The impacted element is the function strcpy of the file /HNAP1/SetStaticRouteSettings of the component HNAP1. The manipulation of the argument PAddress/SubnetMask/Gat\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90680"},{"id":"CVE-2026-90692","vendor":"D-Link","product":"DIR-878","severity":"CRITICAL","score":9.9,"description":"A vulnerability was detected in D-Link DIR-878 120B05. This affects the function SetDynamicDNSIPv6Settings of the component Dynamic DNS IPv6 Settings. The manipulation of the argument IPv6Address/Hostname results in stack-based buffer overf\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90692"},{"id":"CVE-2026-90693","vendor":"D-Link","product":"DIR-878","severity":"CRITICAL","score":9.9,"description":"A flaw has been found in D-Link DIR-878 120B05. This impacts the function SetWan3Settings of the component WAN Settings. This manipulation of the argument Primary/Secondary causes stack-based buffer overflow. Remote exploitation of the atta\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90693"},{"id":"CVE-2026-90699","vendor":"D-Link","product":"DWR-M920","severity":"CRITICAL","score":9.9,"description":"A weakness has been identified in D-Link DWR-M920 1.1.7. This issue affects the function sub_41E60C of the file /boafrm/formPinManageSetup. This manipulation of the argument newPin causes os command injection. The attack can be initiated re\u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90699"},{"id":"CVE-2026-82787","vendor":"Contec Co., Ltd.","product":"CPSL-08P1EN","severity":"CRITICAL","score":9.8,"description":"Missing authentication for critical function vulnerability exists in CPSL-08P1EN. If this vulnerability is exploited, an affected product may be operated by a remote attacker without authentication.","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82787"}],"vendor_spikes":[{"vendor":"Contec Co., Ltd.","count":32,"critical_count":1},{"vendor":"Samsung","count":20,"critical_count":0},{"vendor":"Unknown","count":19,"critical_count":0},{"vendor":"Mattermost","count":10,"critical_count":0},{"vendor":"D-Link","count":9,"critical_count":6},{"vendor":"regularlabs.com","count":9,"critical_count":0},{"vendor":"SourceCodester","count":8,"critical_count":0},{"vendor":"Simon Tatham","count":7,"critical_count":0},{"vendor":"Apache","count":7,"critical_count":0},{"vendor":"WordPress","count":6,"critical_count":1}],"epss_risers":[],"developing_map":{},"trending_count":10,"new_cve_count":268,"has_news_data":true,"has_cve_data":true}