ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

Today’s signal The Hacker News recently reported ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories. Published context: September 10, 2026. A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic probl ...

September 13, 2026 · 3 min · David Gomez

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Today’s signal The Hacker News recently reported Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data. Published context: September 13, 2026. Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masq ...

September 13, 2026 · 3 min · David Gomez

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

Today’s signal The Hacker News recently reported GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure. Published context: September 11, 2026. GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary ...

September 12, 2026 · 3 min · David Gomez

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

Today’s signal The Hacker News recently reported OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers. Published context: September 12, 2026. The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that ta ...

September 12, 2026 · 3 min · David Gomez

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Today’s signal The Hacker News recently reported Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware. Published context: September 11, 2026. Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unaut ...

September 11, 2026 · 3 min · David Gomez

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

Today’s signal The Hacker News recently reported Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed. Published context: September 9, 2026. The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. “Microsoft has failed to properly patch Shield ...

September 10, 2026 · 3 min · David Gomez

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

Today’s signal The Hacker News recently reported Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days. Published context: September 9, 2026. Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been as ...

September 10, 2026 · 3 min · David Gomez

Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

Today’s signal The Hacker News recently reported Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE. Published context: September 9, 2026. A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act. As AI accelerates vulnerability discovery a ...

September 9, 2026 · 3 min · David Gomez

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

Today’s signal The Hacker News recently reported Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell. Published context: September 8, 2026. Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. " ...

September 8, 2026 · 3 min · David Gomez

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

Today’s signal The Hacker News recently reported Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts. Published context: September 7, 2026. Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-de ...

September 7, 2026 · 3 min · David Gomez

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

Today’s signal The Hacker News recently reported Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials. Published context: September 5, 2026. JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. “Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their ...

September 6, 2026 · 3 min · David Gomez

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Today’s signal The Hacker News recently reported Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root. Published context: September 3, 2026. Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as ...

September 5, 2026 · 3 min · David Gomez