Breaking News – Cyber Threats – 2026-09-08 17:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-08 17:00 PDT
- Microsoft Plugs Nearly 1,000 Security Holes
KrebsOnSecurity • 2026-09-08 14:44 • krebsonsecurity.com
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/ - DoppelCart fraud network uses 119,000 fake shops to steal credit cards
BleepingComputer • 2026-09-08 13:35 • www.bleepingcomputer.com
A massive operation dubbed “DoppelCart” uses more than 119,000 domains to run a network of fake e-shops that steal payment card details. […]
https://www.bleepingcomputer.com/news/security/doppelcart-fraud-network-uses-119-000-fake-shops-to-steal-credit-cards/ - The EU CRA's Real Question: What Shipped, and When Did You Know?
BleepingComputer • 2026-09-08 13:24 • www.bleepingcomputer.com
The EU Cyber Resilience Act’s vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements. […]
https://www.bleepingcomputer.com/news/security/the-eu-cras-real-question-what-shipped-and-when-did-you-know/ - Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
BleepingComputer • 2026-09-08 13:08 • www.bleepingcomputer.com
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. […]
https://www.bleepingcomputer.com/news/security/hackers-breach-f5-big-ip-apm-devices-to-deploy-linux-rootkit/ - September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)
SANS ISC Diary (full) • 2026-09-08 12:20 • isc.sans.eduThis month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.
- Microsoft releases Windows 10 KB5122878 extended security update
BleepingComputer • 2026-09-08 11:49 • www.bleepingcomputer.com
Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month’s record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5122878-extended-security-update/ - Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
BleepingComputer • 2026-09-08 11:18 • www.bleepingcomputer.com
Today is Microsoft’s September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-patch-tuesday-fixes-966-flaws-2-zero-days/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.