
Hello all,
Wow, it has been an amazing week in cybersecurity news! Microsoft tops the charts with nearly 1000 vulnerabilities patched in a single month. AI appears to be going off the rails and people in the know in the upper ranks of companies are getting scared. There was a huge quantity of exploits and vulnerabilities this week starting with Adobe and ending with VMware, not quite A to Z, but maybe we can include FortiProxy’s ZTNA defect as a letter Z.
This email and video commentary is from the RedDotSecurity.news website that contains a plethora of links to other items, not mentioned or gone into detail here, that are worth skimming to see if they interest you or pertain to your particular environment or of those you support. There is a lot more than what is provided in these opening comments. Now, on to the headline news.
Headline NEWS:
- Adobe Commerce max-severity bug comes under active attack. Threat Actors are actively exploiting a zero‑day vulnerability in Adobe Commerce and Magento that allows unauthenticated remote code execution (RCE), enabling stealthy backdoors on affected online stores. The defect, dubbed StyleSmuggler, abuses Magento’s template styling system to inject malicious PHP code deploying a Rust‑based implant. In response, Adobe has released an emergency hotfix. Customers with compromised stores are urged to hunt for secondary backdoors and rotate credentials.
- Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE. Check Point quietly patched two critical CVSS 9.8‑rated VPN certificate vulnerabilities that could lead to unauthenticated RCE on Security Gateways and Management Servers under certain undisclosed conditions . Although the company says it found the flaws internally and sees no evidence of exploitation, customers report slow patch rollouts, unclear mitigation guidance, and broken download links. And unfortunately, the only workaround the vendor offered was disabling implied VPN rules, but the guidance was so unclear that many customers aren’t able to safely implement it.
- Microsoft’s September 2026 Massive Patch Release. If it wasn’t for them warning us in the prior few months that this was coming, I’d say this was unusually voluminous, fixing nearly 1000 vulnerabilities across Windows, Azure, Office, Defender, and developer tooling, including dozens rated critical and several already exploited in the wild. Analysts describe it as Microsoft’s largest and most urgent patch drop ever, driven by broad attack surface coverage and multiple high‑risk privilege‑escalation chains. I’m impressed that Redmond was even able to produce that many patches in one month! This month’s release is huge, messy, and absolutely mandatory to get deployed quickly.
- SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution. How do you still have unauthenticated RCE’s after all this time? SAP rushed out fixes for OVERPASS, a CVSS perfect 10 kernel vulnerability across multiple SAP NetWeaver and ABAP‑based products. The defect is apparently trivially exploitable, affects core components used in thousands of enterprises, and requires immediate patching because there are no workarounds that adequately address the risk.
In Ransomware, Malware, and Vulnerabilities News:
- There’s not one thing that stands out in this section this week, there’s just so much. Check Point VPN, Chromium and Chrome zero-days, Palo Alto PAN-OS vulnerability, Papercut finally has a patch, not just an emergency hotfix, GitLab CVSS perfect 10 file read defect, cPanel defect allowing an attacker to run as root, VLC vulnerabilities, Microsoft recommendations on executive phishing, and Florida’s DAVID DMV database being exfiltrated by ShinyHunters. Be sure to check out the full listing of links.
In Other News Events of Note and Interest:
- Retired man turns spare room into Soviet-era supercomputer. No doom or gloom, just a cool article and link to a video of a guy’s build of a computer that uses vacuum tubes. People are definitely creative!
Musings
- Are we on the verge of a real Skynet moment? This week has seen three executives resign from AI companies Anthropic and OpenAI over what one described as, “racing straight to self‑improving superintelligence and gambling with our lives”. In July more than 1,300 AI company employees signed an open letter calling on the US Government to “support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development.” And then there are the break-out events that are increasingly being reported, another one this week. And, to me, it seems very suspicious timing that all three major AI engines went down on September 3, 2026, when ChatGPT, Claude, and Grok experienced overlapping global outages. Coincidence? Or was this a coordinated reboot by handlers attempting to regain control? Just glancing across the article titles in our AI, LLM’s, Robots, and Skynet section of the full newsletter seems to imply that something’s up, and many are getting nervous.

Keep the Shields Up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- Adobe Commerce max-severity bug comes under active attack
- Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
- Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs
- Microsoft Plugs Nearly 1,000 Security Holes
- Why this month’s Microsoft patch release is a doozy
- SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
- SAP warns of maximum severity ‘OVERPASS’ kernel vulnerability
Ranomware, Malware, and Vulnerabilities News
Ransomware, Malware, and Vulnerabilities News
- Good News, Government News, and Interesting
- Beyond Lazarus: How North Korea Organizes Its Cyber Operations
- Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
- DoD cyber strategy aims for ‘something big, something muscular’ in offensive ops
- Ukrainian lawyer’s second career as a Conti coder earns him 4 years behind bars
- Conti ransomware gang member sentenced to 4 years in prison
- Vulnerabilities and Exploits
- CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks
- GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
- GitLab urges users to patch max severity path traversal flaw
- Palo Alto PAN-OS Vulnerability Enables Arbitrary Code Execution as Root User
- PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
- LG TVs Reportedly Eavesdrop on Users Even When the Screen Is Off
- LG Denies Its Televisions Record Ambient Conversations for Ad Targeting
- Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
- Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
- Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
- Chrome Will Now Release Updates Every Two Weeks To Better Tackle Security Threats
- Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed
- New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
- Cpanel ConfigServer Security & Firewall Vulnerability Allows Remote Attacker to Execute Arbitrary Commands
- FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack
- Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
- Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls
- Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit
- Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days
- New ‘BlueMoon’ kit exploited Windows and Chrome zero-day flaws
- PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
- Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking
- Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
- Multiple VLC Media Player Vulnerabilities Allow Attackers to Corrupt or Read Heap Memory
- Phishing, Malware, and Similar
- PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
- BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
- JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
- BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
- Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
- DoppelCart fraud network uses 119,000 fake shops to steal credit cards
- Attackers Use Multi-Hop Google Redirects for Phishing
- Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
- Protecting organizations from AI-assisted executive impersonation and invoice fraud
- Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers
- Passkey-themed social engineering leads to identity and cloud compromise
- ShinyHunters Gained Access to 6 Million Customers Record Using a Single Call
- New Android malware encrypts files, steals data, and harasses victims
- ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
- Trezor: 347,000 users targeted in phishing attacks after Brevo breach
- Breaches, Leaks, and Ransomware
- Mathspace discloses data breach affecting over 1 million people
- Trezor data breach impact now reaches 81,000 customers
- Thomson Reuters detects cybersecurity incident, says unauthorized party accessed files
- ShinyHunters hackers claim breach of Florida “DAVID” DMV database
- Florida confirms DMV database breached via stolen police account
- IDScan confirms breach after 170M identity documents put up for sale
- Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC
- Bimbo Bakeries USA Confirms Data Breach in Oracle EBS Zero-Day Attack
- Boston Scientific says unlikely to meet 2026 sales, profit forecast after cyberattack
- ‘No user data affected’ — Surfshark reveals details of September’s security incident
- Surfshark VPN says hackers breached internal testing, proxy servers
- ‘Stark wakeup call’: Cyberattack on Hilltop Bank highlights growing online threats – Casper, WY
- Revolut confirms customer data breach through fake government requests
Other News Events of Note and Interest
- Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak Models
- G7 urges organizations to prepare for quantum cyber threats
- A decade of software infrastructure
- Retired man turns spare room into Soviet-era supercomputer
- AlphaGenome Atlas: a high-resolution map of human DNA
- VMware defends ending downloads of SDK that helps VM backups– or migrations to rivals
- Asus Receives Exemption to US’s Foreign-Made Wi-Fi Router Ban
- Apple unveils its first foldable, the iPhone Duo
- How and why Google will share anonymized search data with their competitors
- AI, LLM’s, Robots, and Skynet
- An Alien Mind | OpenAI
- Anthropic researcher says more than 10% chance AI “could kill all humans”
- Scenarios for our Economic Future \ Anthropic
- Anthropic spent this week in hot water over cybersecurity
- ChatGPT May Soon Learn Your Writing Style From Your Slack or Gmail
- Four Questions About AGI – THE VOICE IN THE MACHINE
- The Education of a Doomer
- Companies are spending millions rewiring how AI gets used. Almost none can prove it’s working.
- A Response to Bill Gates’s Essay – by X.PIN and CT Zhao
- Meta Introduces Muse, an A.I. Agent That Can Send Your Emails and Book Your Travel
- Meta’s AI agent Muse is now the No. 2 app in the US
- Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6
- Smartwatch Users Have A Big Issue With Apple’s New AI Listening Feature
- Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
- XPENG IRON Humanoid Robot Now Walks Off the Production Line
- Microsoft
- Microsoft Finally Backs Down: The Windows 11 Taskbar Update You’ve Been Waiting For
- Microsoft to Retire Manifest V2 Extensions and Switching to V3 for Improved Security and Performance
- Windows 11 KB5124008, KB5122880 September 2026 Patch Tuesday now available to download
- Windows 11 users are getting full-desktop ads as wallpapers from Microsoft
- Download Security Update for Exchange Server SE RTM SU10 (KB5121608) from Official Microsoft Download Center
- Download Security Update for SQL Server 2025 RTM CU8 (KB5122769) from Official Microsoft Download Center
- August updates trigger 0xc0000409 errors on Windows Server 2016
- Microsoft reminds customers that Publisher support is ending in a few days
- Microsoft: Windows Server 2025 changes causing app crashes
- Microsoft Entra expands passkey registration campaigns
- Microsoft says September updates fix mouse settings reset issues
- September Windows Server updates break Remote Desktop Services
- Windows 11 just dropped the tool ransomware abused, Microsoft says don’t restore WMIC
- Retiring NTLM: Frequently asked questions – Windows IT Pro Blog
- Microsoft Excel KB5002914 update breaks copy and paste for some users
- Microsoft is finally tackling Windows 11’s annoying Bluetooth problem
- Microsoft is finally getting ready to release Administrator Protection in Windows 11
- Windows 11 update KB5124008 breaks Always On VPN connections
- Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs
- Windows 11 Future Platforms build 29667 fixes Arm64 update failures
- Windows 11 KB5124008, KB5126052 may be breaking AMD PCs with the easiest fix not working
- Windows 11 update triggers Code 10 error and breaks USB audio devices
- Microsoft released Windows 11 KB5126056, KB5124015 setup and recovery updates
- Windows 11’s new update manages to break WSL and Claude Cowork at the same time
- Media Creation Tool gets one of the last Windows 11 25H2 ISOs before 26H2 release
