Breaking News – Cyber Threats – 2026-09-14 17:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-14 17:00 PDT
- Microsoft releases emergency Windows updates to fix RDS failures
BleepingComputer • 2026-09-14 13:52 • www.bleepingcomputer.com
Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month’s security updates, along with Hyper-V and USB audio problems on some Windows versions. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-emergency-windows-updates-to-fix-rds-failures/ - Japan's Digital Agency says VPN flaw exposed 246,000 personnel records
BleepingComputer • 2026-09-14 13:36 • www.bleepingcomputer.com
Japan’s Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. […]
https://www.bleepingcomputer.com/news/security/japans-digital-agency-says-vpn-flaw-exposed-246-000-personnel-records/ - Homebrew 7.0.0 gets built-in GUI, better security controls
BleepingComputer • 2026-09-14 12:51 • www.bleepingcomputer.com
Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface. […]
https://www.bleepingcomputer.com/news/security/homebrew-700-gets-built-in-gui-better-security-controls/ - Twitch extension with 30K installs exposes users’ OAuth tokens
BleepingComputer • 2026-09-14 12:03 • www.bleepingcomputer.com
A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users’ Twitch OAuth session tokens to a commercial bot service. […]
https://www.bleepingcomputer.com/news/security/twitch-extension-with-30k-installs-exposes-users-oauth-tokens/ - Upcoming Speaking Engagements
Schneier on Security • 2026-09-14 12:02 • www.schneier.comThis is a current list of where and when I am scheduled to speak:
- I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026 at 5 PM ET.
- I’m speaking at CanSecWest 2026 in Vancouver, Canada. The conference runs September 30–October 1, 2026; the time of my talk is TBD.
- I’m giving a talk on “Free Speech and the Pr…
https://www.schneier.com/blog/archives/2026/09/upcoming-speaking-engagements-60.html - Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
BleepingComputer • 2026-09-14 11:34 • www.bleepingcomputer.com
Hackers compromised HBO Max’s official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. […]
https://www.bleepingcomputer.com/news/security/hackers-hijack-hbo-max-reddit-account-to-push-malware-in-clickfix-ads/ - Apple Updates Everything, (Mon, Sep 14th)
SANS ISC Diary (full) • 2026-09-14 11:33 • isc.sans.eduToday, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different vulnerabilities. This is the most vulnerabilities Apple has ever patched, but the increase is not as significant as other vendors' “post-AI” patch releases.
- New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
The Hacker News • 2026-09-14 11:02 • thehackernews.com
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server’s memory, so the processor keeps reading old encrypted data as if it were current.The attack requires an attacker who already controls the server’s software and can briefly access the machine to insert a small circuit
https://thehackernews.com/2026/09/new-ddrop-attack-breaks-intel-tdx-and.html - 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
The Hacker News • 2026-09-14 11:01 • thehackernews.com
An attacker was operating inside the network of 3BB, one of Thailand’s largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said.The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker’s own tools and a list of
https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.