{
  "schema_version": 2,
  "issue_date": "2026-09-09",
  "generated_at": "2026-09-09T23:05:39.322Z",
  "insight_context": {
    "schema_version": 2,
    "mode": "current",
    "checked_at": "2026-09-09T23:05:37.629Z",
    "report_date": "2026-09-09",
    "manifest_generated_at": "2026-09-09T20:48:22Z",
    "report_url": "https://ricomanifesto.github.io/SentryInsight/"
  },
  "articles": [
    {
      "id": "reporting-8e055682245b",
      "title": "Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks",
      "link": "https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/",
      "date": "2026-09-09T21:40:44.000Z",
      "source": "Bleeping Computer",
      "summary": "Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks…",
      "firstSeen": "2026-09-09T23:05:38.037Z"
    },
    {
      "id": "reporting-1e9110d4393f",
      "title": "AdaptHealth confirms 4.1 million people exposed in July cyberattack",
      "link": "https://www.bleepingcomputer.com/news/security/adapthealth-confirms-41-million-people-exposed-in-july-cyberattack/",
      "date": "2026-09-09T21:30:36.000Z",
      "source": "Bleeping Computer",
      "summary": "Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group…",
      "firstSeen": "2026-09-09T23:05:38.037Z"
    },
    {
      "id": "reporting-323b6c23b480",
      "title": "Mythos Vulnerability Firehose Hits a Human Bottleneck",
      "link": "https://www.darkreading.com/application-security/mythos-vulnerability-firehose-hits-human-bottleneck",
      "date": "2026-09-09T21:19:55.000Z",
      "source": "Dark Reading",
      "summary": "An analysis of Project Glasswing findings shows only a fraction have reached disclosure, and an even smaller number have been fixed.",
      "firstSeen": "2026-09-09T23:05:38.037Z"
    },
    {
      "id": "reporting-39904fbf6822",
      "title": "Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking",
      "link": "https://www.bleepingcomputer.com/news/security/skullcandy-dime-3-earbuds-expose-users-to-bluetooth-hijacking/",
      "date": "2026-09-09T21:02:14.000Z",
      "source": "Bleeping Computer",
      "summary": "The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction…",
      "firstSeen": "2026-09-09T23:05:38.037Z"
    },
    {
      "id": "reporting-9c92e5a0f52d",
      "title": "US Government Accuses Chinese AI Firms of Distilling Frontier Models",
      "link": "https://www.darkreading.com/application-security/us-government-chinese-ai-firms-distilling-frontier-models",
      "date": "2026-09-09T19:47:50.000Z",
      "source": "Dark Reading",
      "summary": "US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.",
      "firstSeen": "2026-09-09T20:45:06.462Z"
    },
    {
      "id": "reporting-8df866a72a61",
      "title": "U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto",
      "link": "https://thehackernews.com/2026/09/us-disrupts-xinbi-guarantee-scam.html",
      "date": "2026-09-09T18:26:05.000Z",
      "source": "The Hacker News",
      "summary": "The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime…",
      "firstSeen": "2026-09-09T20:45:06.462Z"
    },
    {
      "id": "reporting-c6ee9d174c9f",
      "title": "US says Chinese firms extracted billions of tokens from frontier AI models",
      "link": "https://www.bleepingcomputer.com/news/security/us-says-chinese-firms-extracted-billions-of-tokens-from-frontier-ai-models/",
      "date": "2026-09-09T16:48:33.000Z",
      "source": "Bleeping Computer",
      "summary": "U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024…",
      "firstSeen": "2026-09-09T20:45:06.462Z"
    },
    {
      "id": "reporting-9927501cbbee",
      "title": "Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week",
      "link": "https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html",
      "date": "2026-09-09T16:34:05.000Z",
      "source": "The Hacker News",
      "summary": "Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo…",
      "firstSeen": "2026-09-09T20:45:06.462Z"
    },
    {
      "id": "reporting-1f143425b810",
      "title": "Veradigm warns of patient data breach after ransomware gang claims attack",
      "link": "https://www.bleepingcomputer.com/news/security/veradigm-discloses-patient-data-breach-after-gentlemen-gang-claims-attack/",
      "date": "2026-09-09T15:31:23.000Z",
      "source": "Bleeping Computer",
      "summary": "Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data…",
      "firstSeen": "2026-09-09T16:17:44.063Z"
    },
    {
      "id": "reporting-22db05aa27de",
      "title": "Identity-Based AI Attack Threatens Security of Enterprise Data",
      "link": "https://www.darkreading.com/threat-intelligence/identity-based-ai-attack-security-enterprise-data",
      "date": "2026-09-09T14:39:44.000Z",
      "source": "Dark Reading",
      "summary": "\"Workflow identity hijacking\" can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.",
      "firstSeen": "2026-09-09T16:17:44.063Z"
    },
    {
      "id": "reporting-a7397cc291ce",
      "title": "Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA",
      "link": "https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html",
      "date": "2026-09-09T14:23:55.000Z",
      "source": "The Hacker News",
      "summary": "Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create \"stolen keys\" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API…",
      "firstSeen": "2026-09-09T16:17:44.063Z"
    },
    {
      "id": "reporting-7b70efb6ff4b",
      "title": "MFA's Weakest Link: Account Recovery Is the New Attack Path",
      "link": "https://www.bleepingcomputer.com/news/security/mfas-weakest-link-account-recovery-is-the-new-attack-path/",
      "date": "2026-09-09T14:01:11.000Z",
      "source": "Bleeping Computer",
      "summary": "MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover…",
      "firstSeen": "2026-09-09T16:17:44.063Z"
    },
    {
      "id": "reporting-8abca2d5974c",
      "title": "Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE",
      "link": "https://thehackernews.com/2026/09/webinar-learn-how-to-answer-are-we.html",
      "date": "2026-09-09T11:57:36.000Z",
      "source": "The Hacker News",
      "summary": "A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act. As AI accelerates vulnerability discovery and research, that delay matters more…",
      "firstSeen": "2026-09-09T16:17:44.063Z"
    },
    {
      "id": "reporting-c33829733f1a",
      "title": "DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval",
      "link": "https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html",
      "date": "2026-09-09T11:17:07.000Z",
      "source": "The Hacker News",
      "summary": "A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web…",
      "firstSeen": "2026-09-09T16:17:44.063Z"
    },
    {
      "id": "reporting-6724d5b1aa87",
      "title": "Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets",
      "link": "https://thehackernews.com/2026/09/alby-hub-critical-flaw-could-let.html",
      "date": "2026-09-09T10:43:04.000Z",
      "source": "The Hacker News",
      "summary": "Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through…",
      "firstSeen": "2026-09-09T16:17:44.063Z"
    },
    {
      "id": "reporting-4d22feb60955",
      "title": "Over 36,000 exposed Plex servers vulnerable to recent flaws",
      "link": "https://www.bleepingcomputer.com/news/security/over-36-000-plex-servers-unpatched-against-recently-disclosed-flaws/",
      "date": "2026-09-09T10:11:29.000Z",
      "source": "Bleeping Computer",
      "summary": "Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks…",
      "firstSeen": "2026-09-09T11:01:56.877Z"
    },
    {
      "id": "reporting-898e89677a09",
      "title": "U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok",
      "link": "https://thehackernews.com/2026/09/us-agencies-accuse-china-ai-firms-of.html",
      "date": "2026-09-09T09:32:26.000Z",
      "source": "The Hacker News",
      "summary": "U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting \"systematic extraction\" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrial-scale and one that forms the \"core\" of their AI development strategy, according to…",
      "firstSeen": "2026-09-09T16:17:44.063Z"
    },
    {
      "id": "reporting-375dd8a3b2ed",
      "title": "Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox",
      "link": "https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html",
      "date": "2026-09-09T09:11:03.000Z",
      "source": "The Hacker News",
      "summary": "Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. \"Out-of-bounds write in V8 in Google Chrome prior to…",
      "firstSeen": "2026-09-09T11:01:56.877Z"
    },
    {
      "id": "reporting-75062f3bb4ff",
      "title": "Man gets 15 years for extorting women with AI-generated porn videos",
      "link": "https://www.bleepingcomputer.com/news/security/man-gets-15-years-in-prison-for-cyberstalking-and-sextortion/",
      "date": "2026-09-09T08:44:22.000Z",
      "source": "Bleeping Computer",
      "summary": "An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content…",
      "firstSeen": "2026-09-09T11:01:56.877Z"
    },
    {
      "id": "reporting-369f97b0285e",
      "title": "New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root",
      "link": "https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account.html",
      "date": "2026-09-09T08:19:32.000Z",
      "source": "The Hacker News",
      "summary": "cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.",
      "firstSeen": "2026-09-09T11:01:56.877Z"
    },
    {
      "id": "reporting-88a0315141ea",
      "title": "F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans",
      "link": "https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html",
      "date": "2026-09-09T07:36:49.000Z",
      "source": "The Hacker News",
      "summary": "Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are…",
      "firstSeen": "2026-09-09T11:01:56.877Z"
    },
    {
      "id": "reporting-aa6e936777c6",
      "title": "New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access",
      "link": "https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldcrash-zero-day-grants-system-access/",
      "date": "2026-09-09T07:30:15.000Z",
      "source": "Bleeping Computer",
      "summary": "An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named \"ShieldCrash\" right after Microsoft rolled out its September 2026 Patch Tuesday security updates…",
      "firstSeen": "2026-09-09T11:01:56.877Z"
    },
    {
      "id": "reporting-b163f3fc8d81",
      "title": "Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed",
      "link": "https://thehackernews.com/2026/09/researcher-drops-new-microsoft-defender.html",
      "date": "2026-09-09T06:47:27.000Z",
      "source": "The Hacker News",
      "summary": "The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. \"Microsoft has failed to properly patch ShieldBreak CVE-2026-69414,\" Chaotic…",
      "firstSeen": "2026-09-09T11:01:56.877Z"
    },
    {
      "id": "reporting-7c0412571004",
      "title": "Google warns of new Chrome zero-day bug exploited in attacks",
      "link": "https://www.bleepingcomputer.com/news/security/google-patches-seventh-chrome-zero-day-exploited-in-attacks-this-year/",
      "date": "2026-09-09T06:25:48.000Z",
      "source": "Bleeping Computer",
      "summary": "Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year…",
      "firstSeen": "2026-09-09T11:01:56.877Z"
    },
    {
      "id": "reporting-419df1f3701a",
      "title": "SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution",
      "link": "https://thehackernews.com/2026/09/sap-patches-cvss-100-kernel-flaw.html",
      "date": "2026-09-09T06:25:45.000Z",
      "source": "The Hacker News",
      "summary": "SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP…",
      "firstSeen": "2026-09-09T11:01:56.877Z"
    },
    {
      "id": "reporting-07d47a2f7f2e",
      "title": "Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days",
      "link": "https://thehackernews.com/2026/09/microsoft-patches-record-974-flaws.html",
      "date": "2026-09-09T04:41:29.000Z",
      "source": "The Hacker News",
      "summary": "Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.",
      "firstSeen": "2026-09-09T11:01:56.877Z"
    },
    {
      "id": "reporting-4b40f1884595",
      "title": "N-able N-central Pre-Auth RCE Flaw Exploited in the Wild",
      "link": "https://thehackernews.com/2026/09/n-able-n-central-pre-auth-rce-flaw.html",
      "date": "2026-09-09T04:27:51.000Z",
      "source": "The Hacker News",
      "summary": "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a…",
      "firstSeen": "2026-09-09T11:01:56.877Z"
    },
    {
      "id": "reporting-d9942c7c320c",
      "title": "Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-adds-age-awareness-apis-that-can-tell-if-users-are-children-teens-or-adults/",
      "date": "2026-09-09T01:16:27.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth…",
      "firstSeen": "2026-09-09T04:01:24.063Z"
    },
    {
      "id": "reporting-6e80b0fb56bf",
      "title": "Microsoft Plugs Nearly 1,000 Security Holes",
      "link": "https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/",
      "date": "2026-09-08T21:44:22.000Z",
      "source": "Krebs on Security",
      "summary": "Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.",
      "firstSeen": "2026-09-08T23:18:07.859Z"
    },
    {
      "id": "reporting-12654741403d",
      "title": "Patch Tuesday Sets Another Record With 974 CVEs",
      "link": "https://www.darkreading.com/vulnerabilities-threats/patch-tuesday-another-record-974-cves",
      "date": "2026-09-08T21:26:02.000Z",
      "source": "Dark Reading",
      "summary": "Attackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.",
      "firstSeen": "2026-09-08T23:18:07.859Z"
    },
    {
      "id": "reporting-dacffe4f40c9",
      "title": "Attackers Use Multi-Hop Google Redirects for Phishing Campaign",
      "link": "https://www.darkreading.com/cyberattacks-data-breaches/attackers-multi-hop-google-redirects-phishing-campaign",
      "date": "2026-09-08T21:03:46.000Z",
      "source": "Dark Reading",
      "summary": "Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.",
      "firstSeen": "2026-09-08T23:18:07.859Z"
    },
    {
      "id": "reporting-e1327ff1da81",
      "title": "OpenAI Agents Took Over Wiki Site Before Hugging Face Attack",
      "link": "https://www.darkreading.com/cyberattacks-data-breaches/openai-agents-wiki-site-hugging-face-attack",
      "date": "2026-09-08T20:36:15.000Z",
      "source": "Dark Reading",
      "summary": "Researchers and OpenAI disagree on whether the earlier incident involving DseWiki, which the company did not disclose, was a “hack.\"",
      "firstSeen": "2026-09-08T23:18:07.859Z"
    },
    {
      "id": "reporting-44a5bf98b92e",
      "title": "DoppelCart fraud network uses 119,000 fake shops to steal credit cards",
      "link": "https://www.bleepingcomputer.com/news/security/doppelcart-fraud-network-uses-119-000-fake-shops-to-steal-credit-cards/",
      "date": "2026-09-08T20:35:14.000Z",
      "source": "Bleeping Computer",
      "summary": "A massive operation dubbed \"DoppelCart\" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details…",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-c5c4aee36770",
      "title": "The EU CRA's Real Question: What Shipped, and When Did You Know?",
      "link": "https://www.bleepingcomputer.com/news/security/the-eu-cras-real-question-what-shipped-and-when-did-you-know/",
      "date": "2026-09-08T20:24:16.000Z",
      "source": "Bleeping Computer",
      "summary": "The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements…",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-11f562db786d",
      "title": "Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit",
      "link": "https://www.bleepingcomputer.com/news/security/hackers-breach-f5-big-ip-apm-devices-to-deploy-linux-rootkit/",
      "date": "2026-09-08T20:08:55.000Z",
      "source": "Bleeping Computer",
      "summary": "A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk…",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-a9d06ef94cc0",
      "title": "Microsoft releases Windows 10 KB5122878 extended security update",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5122878-extended-security-update/",
      "date": "2026-09-08T18:49:19.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes…",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-983d80461afe",
      "title": "Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-patch-tuesday-fixes-966-flaws-2-zero-days/",
      "date": "2026-09-08T18:18:05.000Z",
      "source": "Bleeping Computer",
      "summary": "Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities…",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-ba85b5be00d0",
      "title": "Windows 11 cumulative updates KB5124008 & KB5122880 released",
      "link": "https://www.bleepingcomputer.com/news/microsoft/windows-11-cumulative-updates-kb5124008-and-kb5122880-released/",
      "date": "2026-09-08T17:57:03.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features…",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-c529667c7a8f",
      "title": "ClickFix Campaigns Abuse Legitimate Services for Persistent Access",
      "link": "https://www.darkreading.com/endpoint-security/clickfix-campaigns-legitimate-services-persistent-access",
      "date": "2026-09-08T17:25:37.000Z",
      "source": "Dark Reading",
      "summary": "Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-3e128c49a676",
      "title": "ShinyHunters hackers claim breach of Florida \"DAVID\" DMV database",
      "link": "https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/",
      "date": "2026-09-08T16:35:47.000Z",
      "source": "Bleeping Computer",
      "summary": "The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as \"DAVID\" and stole over 200,000 records about drivers in the state…",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-6f67d45fa1d4",
      "title": "OpenAI says ChatGPT outage causes image generation errors",
      "link": "https://www.bleepingcomputer.com/news/technology/openai-says-chatgpt-outage-causes-image-generation-errors/",
      "date": "2026-09-08T16:28:42.000Z",
      "source": "Bleeping Computer",
      "summary": "OpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays when uploading files…",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-08a6dd084273",
      "title": "Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution",
      "link": "https://thehackernews.com/2026/09/slim-spider-steals-crypto-custody.html",
      "date": "2026-09-08T16:20:23.000Z",
      "source": "The Hacker News",
      "summary": "A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. \"The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment…",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-ee826c08186e",
      "title": "August updates trigger 0xc0000409 errors on Windows Server 2016",
      "link": "https://www.bleepingcomputer.com/news/microsoft/august-updates-trigger-0xc0000409-errors-on-windows-server-2016/",
      "date": "2026-09-08T15:22:33.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-4e7dbf133d9c",
      "title": "SAP warns of maximum severity 'OVERPASS' kernel vulnerability",
      "link": "https://www.bleepingcomputer.com/news/security/sap-warns-of-maximum-severity-overpass-kernel-vulnerability/",
      "date": "2026-09-08T14:55:20.000Z",
      "source": "Bleeping Computer",
      "summary": "SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-a714f833a627",
      "title": "Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC",
      "link": "https://thehackernews.com/2026/09/liquid-hackers-return-3400-bitcoin.html",
      "date": "2026-09-08T14:54:30.000Z",
      "source": "The Hacker News",
      "summary": "Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds real bitcoin to back a token called L-BTC. The network is still paused, so holders cannot turn that token back into bitcoin. The 3,400 bitcoin was sent to a&…",
      "firstSeen": "2026-09-09T11:22:04.142Z"
    },
    {
      "id": "reporting-a96d08506a53",
      "title": "OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor",
      "link": "https://www.bleepingcomputer.com/news/artificial-intelligence/openai-says-gpt-6-astra-can-find-zero-days-but-is-also-harder-to-monitor/",
      "date": "2026-09-08T14:40:32.000Z",
      "source": "Bleeping Computer",
      "summary": "OpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the \"Critical level\" for cybersecurity capabilities…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-7233e2d9b1b1",
      "title": "ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account",
      "link": "https://thehackernews.com/2026/09/chatgpt-flaw-let-planted-prompt-send.html",
      "date": "2026-09-08T14:19:17.000Z",
      "source": "The Hacker News",
      "summary": "Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel…",
      "firstSeen": "2026-09-09T11:22:04.142Z"
    },
    {
      "id": "reporting-c096727d1fae",
      "title": "Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours",
      "link": "https://thehackernews.com/2026/09/autonomous-ai-agents-compromise.html",
      "date": "2026-09-08T13:48:16.000Z",
      "source": "The Hacker News",
      "summary": "Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-7cfb420aff10",
      "title": "Adobe fixes critical Magento zero-day exploited to backdoor servers",
      "link": "https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-magento-zero-day-exploited-to-backdoor-servers/",
      "date": "2026-09-08T13:34:47.000Z",
      "source": "Bleeping Computer",
      "summary": "Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-4dfc5b9bb611",
      "title": "Webinar: The forgotten Google Workspace access that can lead to a breach",
      "link": "https://www.bleepingcomputer.com/news/security/webinar-the-forgotten-google-workspace-access-that-can-lead-to-a-breach/",
      "date": "2026-09-08T12:40:48.000Z",
      "source": "Bleeping Computer",
      "summary": "Third-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches and which security controls can help fast-growing companies reduce their exposure…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-6c7e13172b77",
      "title": "Hackers build AI frameworks for widescale credential theft",
      "link": "https://www.bleepingcomputer.com/news/security/hackers-build-ai-frameworks-for-widescale-credential-theft/",
      "date": "2026-09-08T12:03:03.000Z",
      "source": "Bleeping Computer",
      "summary": "Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-9d6faaed701d",
      "title": "WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls",
      "link": "https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html",
      "date": "2026-09-08T11:54:29.000Z",
      "source": "The Hacker News",
      "summary": "Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-9f18a97b3fdc",
      "title": "What It Took to Reach 1 Billion Build Manifests",
      "link": "https://thehackernews.com/2026/09/what-it-took-to-reach-1-billion-build.html",
      "date": "2026-09-08T11:49:02.000Z",
      "source": "The Hacker News",
      "summary": "In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually behind them. The number itself is less interesting than the system that produced it, and why we had to fundamentally…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-9af5dfe944e1",
      "title": "FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials",
      "link": "https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html",
      "date": "2026-09-08T11:22:07.000Z",
      "source": "The Hacker News",
      "summary": "A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-2fdb7e232890",
      "title": "Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell",
      "link": "https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html",
      "date": "2026-09-08T09:13:47.000Z",
      "source": "The Hacker News",
      "summary": "Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. \"This update resolves a critical…",
      "firstSeen": "2026-09-08T10:57:29.390Z"
    }
  ]
}
