Breaking News – Cyber Threats – 2026-09-08 13:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-08 13:00 PDT
- September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)
SANS ISC Diary (full) • 2026-09-08 12:20 • isc.sans.eduThis month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.
- Microsoft releases Windows 10 KB5122878 extended security update
BleepingComputer • 2026-09-08 11:49 • www.bleepingcomputer.com
Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month’s record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5122878-extended-security-update/ - Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
BleepingComputer • 2026-09-08 11:18 • www.bleepingcomputer.com
Today is Microsoft’s September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-patch-tuesday-fixes-966-flaws-2-zero-days/ - Windows 11 cumulative updates KB5124008 & KB5122880 released
BleepingComputer • 2026-09-08 10:57 • www.bleepingcomputer.com
Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. […]
https://www.bleepingcomputer.com/news/microsoft/windows-11-cumulative-updates-kb5124008-and-kb5122880-released/ - AIs as Modern Genies
Schneier on Security • 2026-09-08 10:12 • www.schneier.comThis essay was written with Barath Raghavan, and originally appeared in Lawfare.
In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its backups. In July, OpenAI asked an unreleased AI model to attempt a hacking test. Instead of staying in the …
https://www.schneier.com/blog/archives/2026/09/ais-as-modern-genies.html - ShinyHunters hackers claim breach of Florida "DAVID" DMV database
BleepingComputer • 2026-09-08 09:35 • www.bleepingcomputer.com
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as “DAVID” and stole over 200,000 records about drivers in the state. […]
https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/ - OpenAI says ChatGPT outage causes image generation errors
BleepingComputer • 2026-09-08 09:28 • www.bleepingcomputer.com
OpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays when uploading files. […]
https://www.bleepingcomputer.com/news/technology/openai-says-chatgpt-outage-causes-image-generation-errors/ - Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
The Hacker News • 2026-09-08 09:20 • thehackernews.com
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026.Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider.
“The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment
https://thehackernews.com/2026/09/slim-spider-steals-crypto-custody.html - The US military just turned off ad tracking on its phones. Maybe you should too
Graham Cluley • 2026-09-08 08:33 • www.bitdefender.com
Location data sold by the ad industry has reportedly helped adversaries target US troops. The Pentagon has responded by switching off ad tracking on its devices – and you can do the same on yours.Read more in my article on the Hot for Security blog.
https://www.bitdefender.com/en-us/blog/hotforsecurity/us-military-turned-off-ad-tracking-phones - August updates trigger 0xc0000409 errors on Windows Server 2016
BleepingComputer • 2026-09-08 08:22 • www.bleepingcomputer.com
Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled. […]
https://www.bleepingcomputer.com/news/microsoft/august-updates-trigger-0xc0000409-errors-on-windows-server-2016/ - SAP warns of maximum severity 'OVERPASS' kernel vulnerability
BleepingComputer • 2026-09-08 07:55 • www.bleepingcomputer.com
SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. […]
https://www.bleepingcomputer.com/news/security/sap-warns-of-maximum-severity-overpass-kernel-vulnerability/ - Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC
The Hacker News • 2026-09-08 07:54 • thehackernews.com
Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin’s public record shows. About 598.5 bitcoin has not come back.Liquid is a Bitcoin sidechain that holds real bitcoin to back a token called L-BTC. The network is still paused, so holders cannot turn that token back into bitcoin.
The 3,400 bitcoin was sent to a&
https://thehackernews.com/2026/09/liquid-hackers-return-3400-bitcoin.html - OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor
BleepingComputer • 2026-09-08 07:40 • www.bleepingcomputer.com
OpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the “Critical level” for cybersecurity capabilities. […]
https://www.bleepingcomputer.com/news/artificial-intelligence/openai-says-gpt-6-astra-can-find-zero-days-but-is-also-harder-to-monitor/ - ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account
The Hacker News • 2026-09-08 07:19 • thehackernews.com
Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user’s question as usual.In the company’s proof of concept, that hidden work read data from the user’s connected Gmail account and passed it to a second ChatGPT account through a hidden channel
https://thehackernews.com/2026/09/chatgpt-flaw-let-planted-prompt-send.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.