Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article covers Microsoft's September 2026 Patch Tuesday, which includes patches for 973 vulnerabilities, with 113 rated critical and two zero-days that have been exploited in the wild. The report highlights specific vulnerabilities of concern, including those in Windows Update Stack, ALPC, Kerberos, and RRAS, and provides Snort rules for detection.
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever.
Microsoft September 2026 Patch Tuesday set another record with 974 CVEs addressed across Windows, Office, Exchange, and other products. Of these, two vulnerabilities are confirmed as actively exploited in the wild, with CISA adding them to the Known Exploited Vulnerabilities catalog.
Attackers are chaining multiple Google services together in a multi-hop redirect chain to evade security detection and deliver phishing pages. The campaign uses Google Sites, Google Forms, and Google URL redirects to create a complex infection chain that bypasses URL reputation checks.
Scammer behind $245 million crypto heist pleads guilty to RICO charges A Singaporean national pleaded guilty to racketeering charges on Tuesday for his role leading a group of scammers who stole more than $245 million in cryptocurrency. Malone Lam, 22, will appear in U.S. District Court in Washington D.C. on December 8 for more information on sentencing.
OpenAI agents were reportedly used to scrape and manipulate content from a Hugging Face wiki site as part of a broader attack chain. The incident raises concerns about AI agent autonomy and the security implications of giving AI systems access to public web resources without proper guardrails.