2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 21:50 UTC
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 21:50 UTC
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 21:50 UTC
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 21:50 UTC
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 21:50 UTC
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-19820.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 21:30 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Linux Kernel. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8.
P10
2026-09-09 04:41 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 06:20 UTC
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.
P45
2026-09-09 04:27 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 04:40 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a
P70
2026-09-09 02:36 UTC
Other
JPCERT · indexed 2026-09-09 03:10 UTC
P0
2026-09-09 02:36 UTC
Other
JPCERT · indexed 2026-09-09 03:10 UTC
P5
2026-09-09 02:03 UTC
Other
Proofpoint Threat Insight · indexed 2026-09-09 09:10 UTC
P0
2026-09-09 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-09-09 02:10 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-09-09 01:16 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-09-09 01:25 UTC
Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. [...]
P0
2026-09-09 01:00 UTC
Security Journalism
Huntress · indexed 2026-09-08 13:30 UTC
Huntress is tracking a pattern across multiple customer environments where rogue ScreenConnect clients repeatedly spawn the Windows Script Host to execute a series of four VBScript files.
P0
2026-09-08 22:40 UTC
Security Journalism
The Record · indexed 2026-09-08 22:45 UTC
The new record total for Patch Tuesday is 973 vulnerabilities.
P0
2026-09-08 22:16 UTC
Vendor Research
Cisco Talos Intelligence Blog · Cisco Talos · indexed 2026-09-08 22:45 UTC
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
P5
2026-09-08 21:44 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-09-08 21:50 UTC
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
P0
2026-09-08 21:44 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-09-09 00:10 UTC
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday, including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will e…
P65
2026-09-08 21:26 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-09-08 21:45 UTC
Attackers are actively exploiting two of the vulnerabilities, and another 58 are more likely to be exploited, according to Microsoft.
P0
2026-09-08 21:23 UTC
Other
Proofpoint Threat Insight · indexed 2026-09-11 04:30 UTC
P0
2026-09-08 21:03 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-08 21:15 UTC
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.
P0
2026-09-08 20:52 UTC
Security Journalism
The Record · indexed 2026-09-08 21:00 UTC
Malone Lam was indicted on scamming charges in September 2024 after drawing law enforcement scrutiny for parlaying stolen crypto into lavish Hamptons vacations, cars and private jets.
P0
2026-09-08 20:36 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-09-08 21:00 UTC
Researchers and OpenAI disagree on whether an earlier incident involving DseWiki, which the company did not disclose, was a “hack."
P0
2026-09-08 20:35 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-08 21:10 UTC
Crypto exchange network Liquid Network lost $320 million overnight, then got most of it back after the hackers demanded a bug fix instead of a ransom Bitcoin’s Liquid Network, a sidechain built by Blockstream and used by dozens of exchanges to move funds faster and more privately than the main Bitcoin blockchain allows, got drained […]
P0
2026-09-08 20:35 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-08 20:40 UTC
A massive operation dubbed "DoppelCart" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details. [...]
P0
2026-09-08 20:24 UTC
Security Journalism
BleepingComputer · Sponsored by ActiveState · indexed 2026-09-08 20:25 UTC
The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements. [...]
P25
2026-09-08 20:08 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-08 20:10 UTC
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. [...]
P0
2026-09-08 19:46 UTC
Security Journalism
The Record · indexed 2026-09-08 20:00 UTC
A "flawless" performance by the CIA's Cyber Mission Center contributed to the capture of Venezuelan President Nicolás Maduro in January, agency Deputy Director Michael Ellis says.
P0
2026-09-08 19:37 UTC
Security Journalism
The Record · indexed 2026-09-08 19:45 UTC
A Russian web developer who played a role in a multimillion-dollar bank account takeover scheme has been extradited to the U.S. to face an indictment.
P0
2026-09-08 19:20 UTC
Community
SANS Internet Storm Center · indexed 2026-09-08 19:35 UTC
This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.
P30