Breaking News – Cyber Threats – 2026-09-08 08:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-08 08:00 PDT
- SAP warns of maximum severity 'OVERPASS' kernel vulnerability
BleepingComputer • 2026-09-08 07:55 • www.bleepingcomputer.com
SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. […]
https://www.bleepingcomputer.com/news/security/sap-warns-of-maximum-severity-overpass-kernel-vulnerability/ - OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor
BleepingComputer • 2026-09-08 07:40 • www.bleepingcomputer.com
OpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the “Critical level” for cybersecurity capabilities. […]
https://www.bleepingcomputer.com/news/artificial-intelligence/openai-says-gpt-6-astra-can-find-zero-days-but-is-also-harder-to-monitor/ - Adobe fixes critical Magento zero-day exploited to backdoor servers
BleepingComputer • 2026-09-08 06:34 • www.bleepingcomputer.com
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. […]
https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-magento-zero-day-exploited-to-backdoor-servers/ - Webinar: The forgotten Google Workspace access that can lead to a breach
BleepingComputer • 2026-09-08 05:40 • www.bleepingcomputer.com
Third-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches and which security controls can help fast-growing companies reduce their exposure. […]
https://www.bleepingcomputer.com/news/security/webinar-the-forgotten-google-workspace-access-that-can-lead-to-a-breach/ - Hackers build AI frameworks for widescale credential theft
BleepingComputer • 2026-09-08 05:03 • www.bleepingcomputer.com
Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. […]
https://www.bleepingcomputer.com/news/security/hackers-build-ai-frameworks-for-widescale-credential-theft/ - Microsoft: Windows Server 2025 changes causing app crashes
BleepingComputer • 2026-09-08 04:57 • www.bleepingcomputer.com
Microsoft warned customers last week that they may experience application crashes on some Windows Server 2025 due to recent memory management changes. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-server-2025-changes-may-cause-app-crashes/ - WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
The Hacker News • 2026-09-08 04:54 • thehackernews.com
Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones.The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since
https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html - What It Took to Reach 1 Billion Build Manifests
The Hacker News • 2026-09-08 04:49 • thehackernews.com
In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what’s actually behind them. The number itself is less interesting than the system that produced it, and why we had to fundamentally
https://thehackernews.com/2026/09/what-it-took-to-reach-1-billion-build.html - FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
The Hacker News • 2026-09-08 04:22 • thehackernews.com
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says.FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software.
The
https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html - Stealing AI Reasoning Traces
Schneier on Security • 2026-09-08 03:20 • www.schneier.comInteresting research: “Stealing Reasoning Traces from Proprietary LLM APIs“:
Abstract: Leading large language model providers now conceal their models’ step-by-step reasoning, or chain-of-thought, to protect intellectual property and limit information leakage. Rather than storing these traces server-side, providers return them to the client as blocks of encrypted text, which the client passes back with each subsequent request. Building on prior research, we identify an architectural vulnerability: …
https://www.schneier.com/blog/archives/2026/09/stealing-ai-reasoning-traces.html - Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
The Hacker News • 2026-09-08 02:13 • thehackernews.com
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild.The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026.
“This update resolves a critical
https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.