Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
CrowdStrike's Patch Tuesday analysis for September 2026 reveals that Microsoft patched 972 CVEs, including two exploited zero-days and 113 critical vulnerabilities. The breakdown by exploitation technique shows 437 elevation of privilege patches (45%), 258 RCE patches (26%), and 171 information disclosure patches (18%).
A podcast episode from Malwarebytes examines the rise of loyalty points fraud, where cybercriminals target customer rewards programs to steal and resell points for profit. The episode details how fraudsters hack accounts, drain points, and cash them out through dark web marketplaces.
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences integrity values," SOCRadar said .
A zero-day vulnerability in Adobe Magento called StyleSmuggler is being actively exploited to deploy Linux backdoors on e-commerce servers. The vulnerability allows attackers to inject malicious code through CSS files and gain persistent access to affected Magento installations.
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff, is being tracked by Arctic Wolf under the moniker PREY-0058 , adding it shares significant tradecraft similarities with a data extortion group that Google-owned Mandiant calls UNC6671 .
A phishing-as-a-service platform called BigBear was used to bypass multifactor authentication at 258 organizations. The service impersonates Microsoft 365 login pages and uses real-time credential harvesting combined with session cookie theft to bypass MFA protections.