Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit called ShieldCrash that bypasses Windows Defender protections and grants system-level access. The exploit targets the Microsoft Defender Antivirus service and demonstrates a method to disable real-time protection.
This article reports that a security researcher has released a proof-of-concept exploit for a new zero-day vulnerability in Microsoft Defender, called ShieldCrash, which bypasses a recent patch for CVE-2026-69414. The vulnerability allows an attacker to achieve arbitrary file read as SYSTEM on all supported Windows versions, and Microsoft has issued an update to the Malware Protection Engine to address it.
Google has patched 230 vulnerabilities in its September 2026 security update, including another actively exploited Chrome zero-day vulnerability. This marks the seventh Chrome zero-day exploited in the wild this year.
SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP security company Onapsis, it has been codenamed OVERPASS .
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools.
This article details a critical pre-authentication remote code execution vulnerability in N-able N-central, tracked as CVE-2026-86218, which is being actively exploited in the wild. CISA has added it to its KEV catalog, and N-able has released a hotfix, while researchers have also disclosed related vulnerabilities that can be chained for authentication bypass.