{"date_iso":"2026-09-21","date_human":"Monday, September 21, 2026","generated_utc":"2026-09-21 18:36 UTC","read_minutes":4,"patch_tuesday":false,"top_stories":[{"title":"Google Fined \u20ac403 Million Over GDPR Violations Tied to Location Data","link":"https://thehackernews.com/2026/09/google-fined-403-million-over-gdpr.html","reason":"Google","category":"News","sources":["Ars Technica Security","Bleeping Computer","Infosecurity Magazine","Malwarebytes Labs","SecurityWeek","The Hacker News","The Record"],"coverage":7,"cve_ids":[],"summary":"Google has been fined \u20ac403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020. Ireland's Data Protection\u2026","source":"The Hacker News","date_rel":"1h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhrjOPn27sYW7sjjV6-SlFPjlnnAtZ2bVGvrJRbbussed8ddYCwrRnmyIBKOsJy9p3QGdwzMuxmxhtyNvyPQD9u53V0T84o-Pi1Euo1SPlHX9DiaFzVby2cKpyfdma7mA0b4F1gqDCvjWBrk3n916K6Su1Y1TaJcOKXHsuzNn0cxOmVzlUK1NIjPtElIXM/s1600/google-location.jpg","description":"Google has been fined \u20ac403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020. Ireland's Data Protection Commission (DPC), Google's lead regulator in the EU, also ordered the company to make its processing comply with the law within 6 months. The DPC has not said publicly which","related":[{"title":"Google Hit With $463 Million Fine for EU Location Data Rule Breach","link":"https://www.securityweek.com/google-hit-with-463-million-fine-for-eu-location-data-rule-breach/","source":"SecurityWeek","date_rel":"1h ago"},{"title":"Google fined \u20ac403 million over location data privacy violations","link":"https://www.bleepingcomputer.com/news/security/google-fined-403-million-over-location-data-privacy-violations/","source":"Bleeping Computer","date_rel":"2h ago"},{"title":"Google Hit with \u20ac403m GDPR Fine Over Location Data Practices","link":"https://www.infosecurity-magazine.com/news/google-hit-with-403m-gdpr-fine/","source":"Infosecurity Magazine","date_rel":"3h ago"},{"title":"Gemini\u2019s breach of real companies exposes an AI guardrail problem","link":"https://www.malwarebytes.com/blog/ai/2026/09/geminis-breach-of-real-companies-exposes-an-ai-guardrail-problem","source":"Malwarebytes Labs","date_rel":"4h ago"},{"title":"Google says Gemini breached three companies during security test","link":"https://therecord.media/gemini-google-cyber-breach","source":"The Record","date_rel":"6h ago"},{"title":"Google Confirms Gemini AI Breached Three Firms","link":"https://www.securityweek.com/google-confirms-gemini-ai-breached-three-firms/","source":"SecurityWeek","date_rel":"11h ago"}]},{"title":"Microsoft Entra ID to Block SMS First-Factor Sign-Ins Worldwide in February 2027","link":"https://cybersecuritynews.com/entra-id-sms-sign-in-retirement/","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Cyber Security News","Google Project Zero","SANS Internet Storm Center"],"coverage":4,"cve_ids":["CVE-2026-50343","CVE-2026-66804"],"summary":"Microsoft is retiring SMS first-factor sign-in for Microsoft Entra ID workforce tenants worldwide and requires organizations to migrate affected users before February 1, 2027. The security-focused change will prevent\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Microsoft-Entra-ID-SMS-Sign-In.webp","description":"Microsoft is retiring SMS first-factor sign-in for Microsoft Entra ID workforce tenants worldwide and requires organizations to migrate affected users before February 1, 2027. The security-focused change will prevent employees from using a registered telephone number and SMS one-time passcode as their primary sign-in method, potentially disrupting Microsoft 365 and other Entra-protected services if administrators fail to prepare. SMS first-factor authentication, internally identified as SignInNoPassword, allows a user to enter a registered phone number instead of a username and password\u2026","related":[{"title":"Microsoft to retire Microsoft 365 Companion apps in December","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-to-retire-microsoft-365-companion-apps-in-december/","source":"Bleeping Computer","date_rel":"41m ago"},{"title":"Microsoft fixes broken Excel copy and paste for all Office users","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-broken-excel-copy-and-paste-for-all-office-users/","source":"Bleeping Computer","date_rel":"3h ago"},{"title":"Microsoft Investigating Teams Calling Issue Blocking Users From Making or Receiving Calls","link":"https://cybersecuritynews.com/microsoft-teams-calling-issue/","source":"Cyber Security News","date_rel":"4h ago"},{"title":"Microsoft Confirms September 2026 Windows Updates Break File History Backups","link":"https://cybersecuritynews.com/windows-updates-breaks-file-history-backup/","source":"Cyber Security News","date_rel":"5h ago"},{"title":"Microsoft reminds admins to migrate Entra ID users to passkeys","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-reminds-admins-to-migrate-entra-id-users-to-passkeys/","source":"Bleeping Computer","date_rel":"5h ago"},{"title":"TerminalFix: PNG Steganography, (Mon, Sep 21st)","link":"https://isc.sans.edu/diary/rss/33318","source":"SANS Internet Storm Center","date_rel":"8h ago"}]},{"title":"Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR","link":"https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html","reason":"Github","category":"News","sources":["Palo Alto Unit 42","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it\u2026","source":"The Hacker News","date_rel":"1h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEil-5ZV6QK7R23fL7Vtl-pdxgFYPAG9dT_cIIrXWgR70hLZRM705Ij3WuRpCL00VuDop9dTmVNf1t3QS60nqRGV9GCzsZ792yd7mFY_pjvgfufOK9D-oQJdxP4ZtrXiyeq08KNUBv3-mhQ_KCiCOMWIbeQpCAyF_h4lMZw54T0l9AcDdGf6aRptXAZJNcU/s1600/last.jpg","description":"A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17. Microsoft's own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers","related":[{"title":"From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies","link":"https://unit42.paloaltonetworks.com/detecting-exposed-aws-iam-credentials/","source":"Palo Alto Unit 42","date_rel":"8h ago"},{"title":"CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories","link":"https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html","source":"The Hacker News","date_rel":"19 Sep"}]},{"title":"PAYLOAD Ransomware Hijacks Active Directory GPO to Disrupt Entire Windows Domain Without Encryption","link":"https://cybersecuritynews.com/payload-ransomware-hijacks-active-directory/","reason":"Windows","category":"News","sources":["Cyber Security News","Microsoft Security"],"coverage":2,"cve_ids":["CVE-2026-40400","CVE-2026-68825","CVE-2026-83498"],"summary":"A PAYLOAD ransomware attack used Active Directory Group Policy Objects to disrupt an entire Windows domain without encrypting files or deploying ransomware binaries. The operation targeted a manufacturing organization\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/PAYLOAD-Ransomware-Hijacks-Active-Directory-GPO-to-Disrupt-Entire-Windows-Domain-Without-Encryption.webp","description":"A PAYLOAD ransomware attack used Active Directory Group Policy Objects to disrupt an entire Windows domain without encrypting files or deploying ransomware binaries. The operation targeted a manufacturing organization in the Middle East. It relied on domain-level control, stolen credentials, and malicious GPOs to display ransom demands, disable defenses, and lock down administrator access. In April 2026, the attackers reportedly accessed the organization through its FortiGate SSL VPN using a valid but compromised domain account. The source of the credential theft remains unconfirmed. However\u2026","related":[{"title":"CVE-2026-68825 Windows Bind Filter Driver Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68825","source":"Microsoft Security","date_rel":"4h ago"},{"title":"CVE-2026-83498 Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-83498","source":"Microsoft Security","date_rel":"4h ago"},{"title":"CVE-2026-40400 Windows PowerShell Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-40400","source":"Microsoft Security","date_rel":"4h ago"}]},{"title":"A week in security (September 14 \u2013 September 20)","link":"https://www.malwarebytes.com/blog/news/2026/09/a-week-in-security-september-14-september-20","reason":"Android","category":"Threat Intel","sources":["Malwarebytes Labs","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"Last week on Malwarebytes Labs: New Android malware uses AI to steal bank logins and PINs Did an AI really try to break free from human control? Fake parcel delivery messages steal your card and bank details Flock\u2026","source":"Malwarebytes Labs","date_rel":"11h ago","thumbnail":"","description":"Last week on Malwarebytes Labs: New Android malware uses AI to steal bank logins and PINs Did an AI really try to break free from human control? Fake parcel delivery messages steal your card and bank details Flock cameras are tracking people as well as cars Revolut phishing texts appear days after data breach 12 celebrity deepfake websites seized by Manhattan DA T-Mobile rewards points expiry texts are a phishing scam Google Pixel owners urged to patch actively exploited modem flaw AI helps scammers build convincing antivirus renewal pages How to opt out of AI chatbot training HBO Max\u2019s\u2026","related":[{"title":"RatHat Android Trojan Uses AI for Automation","link":"https://www.securityweek.com/rathat-android-trojan-uses-ai-for-automation/","source":"SecurityWeek","date_rel":"5h ago"}]},{"title":"\u26a1 Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks","link":"https://thehackernews.com/2026/09/weekly-recap-cisco-0-day-ai-agent-rce.html","reason":"Cisco","category":"News","sources":["Dark Reading","The Hacker News"],"coverage":2,"cve_ids":["CVE-2026-76460"],"summary":"A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming\u2026","source":"The Hacker News","date_rel":"4h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjovXeakmAmPG68i_kNoeGFJjwSSGDdpj-29aojemBxtTQVOHzR668zKtV5GGPhnJ0zyCEdlsNCc11LIT-F8n1U8Rkv3jr-3AAt6HC4YwwyfENs_Y8V-O_OlPC4_WByxrsUBq6NifTKHQpgWuSnIqnV4bg4rXVoe9BrtMtgRCo4ECfMLWHRIKOQsqjb0zEt/s1600/recap-2.jpg","description":"A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not","related":[{"title":"Cisco Zero-Day Highlights API Endpoint Authentication Issues","link":"https://www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endpoint-authentication-issues","source":"Dark Reading","date_rel":"18 Sep"}]},{"title":"CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild","link":"https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html","reason":"Linux","category":"News","sources":["SecurityWeek","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active\u2026","source":"The Hacker News","date_rel":"19 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcKuQ4GC9r1-4fQ3Ap_CQko0y3nMI0SnATF3WNSv48uFtNskrV4PqnyW4s0L7sXcojrHoJCEZRazGJNz5JhxrTTSYZSAQeD-xwdquE3X7pJ_ylBUerrybIiaE3V-i1vXdiLr_N1KCM9GTmeAKLlgySqEr0QeCB5ckvnppiEHSZhnEqv0IfUnqCKdA1kKsN/s1600/cisa-linux.jpg","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2025-39682 (CVSS score: 9.8) - An improper check for unusual or exceptional conditions vulnerability in the TLS receive path","related":[{"title":"Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities","link":"https://www.securityweek.com/organizations-warned-of-3-exploited-linux-kernel-vulnerabilities/","source":"SecurityWeek","date_rel":"9h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-94003","vendor":"Comfast","product":"CF-N1-S","severity":"CRITICAL","score":10.0,"description":"A vulnerability has been found in Comfast CF-N1-S 2.6.0.1. Impacted is the function get_css_path_from_uri of the file /cgi-bin/mbox-config of the component Web Management Interface. The manipulation leads to stack-based buffer overflow. The\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-94003"},{"id":"CVE-2026-94089","vendor":"D-Link","product":"DIR-868L","severity":"CRITICAL","score":10.0,"description":"A vulnerability was determined in D-Link DIR-868L 2.01b05. This issue affects the function strcpy of the file /webfa_authentication.cgi of the component Authentication Handler. Executing a manipulation of the argument id/password can lead t\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-94089"},{"id":"CVE-2026-94097","vendor":"Netcore","product":"NBR200V2","severity":"CRITICAL","score":10.0,"description":"A vulnerability was determined in Netcore NBR200V2 1.3.241127.071246. This affects an unknown part of the file /www/cgi-bin/network_tools of the component CGI Diagnostic Endpoint. This manipulation of the argument param/key/val causes comma\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-94097"},{"id":"CVE-2026-94095","vendor":"Netcore","product":"NBR200V2","severity":"CRITICAL","score":9.9,"description":"A vulnerability has been found in Netcore NBR200V2 1.3.241127.071246. Affected by this vulnerability is an unknown functionality of the file /usr/bin/network_tools of the component Traceroute Diagnostic Feature. The manipulation of the argu\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-94095"},{"id":"CVE-2026-94096","vendor":"Netcore","product":"NBR200V2","severity":"CRITICAL","score":9.9,"description":"A vulnerability was found in Netcore NBR200V2 1.3.241127.071246. Affected by this issue is some unknown functionality of the file /usr/bin/network_tools of the component LAN IP Configuration Handler. The manipulation of the argument ipv4 re\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-94096"},{"id":"CVE-2026-94099","vendor":"Netcore","product":"NBR200V2","severity":"CRITICAL","score":9.9,"description":"A security flaw has been discovered in Netcore NBR200V2 1.3.241127.071246. This issue affects some unknown processing of the file restore.cgi of the component Backup Restore. Performing a manipulation of the argument QUERY_STRING results in\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-94099"},{"id":"CVE-2026-94100","vendor":"Netcore","product":"NBR200V2","severity":"CRITICAL","score":9.9,"description":"A weakness has been identified in Netcore NBR200V2 1.3.241127.071246. Impacted is the function wan_config_set_vlan of the file /usr/bin/routerd of the component WAN VLAN Reconfiguration. Executing a manipulation of the argument vlan_wanX.po\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-94100"},{"id":"CVE-2026-94101","vendor":"Netcore","product":"NBR200V2","severity":"CRITICAL","score":9.9,"description":"A security vulnerability has been detected in Netcore NBR200V2 1.3.241127.071246. The affected element is the function vlan_load_form_uci of the file /usr/bin/routerd. The manipulation of the argument wan_num leads to buffer overflow. It is\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-94101"},{"id":"CVE-2026-90817","vendor":"Microsoft","product":"REDCap","severity":"CRITICAL","score":9.8,"description":"An unauthenticated Remote Code Execution vulnerability was found in the survey passthrough routing and Data Import processing logic, in which a malicious user could potentially exploit it by manipulating HTTP requests to access an unintende\u2026","cwe":"CWE-73","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-90817"},{"id":"CVE-2026-94098","vendor":"Netcore","product":"NBR200V2","severity":"CRITICAL","score":9.1,"description":"A vulnerability was identified in Netcore NBR200V2 1.3.241127.071246. This vulnerability affects unknown code of the file /www/cgi-bin/upgrade of the component Firmware Upgrade CGI Endpoint. Such manipulation of the argument QUERY_STRING le\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-94098"}],"vendor_spikes":[{"vendor":"Unknown","count":9,"critical_count":0},{"vendor":"Netcore","count":7,"critical_count":7},{"vendor":"SourceCodester","count":6,"critical_count":0},{"vendor":"Red Hat","count":6,"critical_count":0},{"vendor":"Microsoft","count":5,"critical_count":1},{"vendor":"WordPress","count":5,"critical_count":0},{"vendor":"OrdaSoft.com","count":4,"critical_count":0},{"vendor":"Apple","count":4,"critical_count":0},{"vendor":"Omega Solution","count":4,"critical_count":0},{"vendor":"D-Link","count":3,"critical_count":1}],"epss_risers":[],"developing_map":{},"trending_count":7,"new_cve_count":96,"has_news_data":true,"has_cve_data":true}