Compiled from 52 monitored sources · 1280 articles reviewed
Today’s Briefing
Microsoft's September 2026 Patch Tuesday addresses 974 vulnerabilities, a record volume that includes two actively exploited Windows zero-days now on CISA's KEV: CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call, and CVE-2026-81963, a link following flaw in the Windows Update Stack, both allowing local privilege escalation to SYSTEM. CISA also added CVE-2026-75650, an Adobe Commerce and Magento template injection vulnerability enabling pre-authentication remote code execution, and CVE-2026-86218 in N-able N-central, which permits unauthenticated RCE via static code injection. Google separately patched its seventh Chrome zero-day of the year. Cisco Talos is tracking a cryptocurrency theft campaign that uses the Google Visualization API for command and control, pulling obfuscated JavaScript from a public Google Sheets document and injecting it into victim browser sessions.
Top Stories
- Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
- ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
- Google warns of new Chrome zero-day bug exploited in attacks
- Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
- CISA Adds Four Known Exploited Vulnerabilities to Catalog
Full brief available to subscribers
The complete operator brief — action items with patch deadlines, the vulnerability appendix and named actor activity — goes out by email each morning. Subscribe free to receive it.