September 12, 2026

Header image for the Red Dot Weekly Cyber Security News https://reddotsecurity.news

Hello all,

Wow, it has been an amazing week in cybersecurity news! Microsoft tops the charts with nearly 1000 vulnerabilities patched in a single month. AI appears to be going off the rails and people in the know in the upper ranks of companies are getting scared. There was a huge quantity of exploits and vulnerabilities this week starting with Adobe and ending with VMware, not quite A to Z, but maybe we can include FortiProxy’s ZTNA defect as a letter Z.

This email and video commentary is from the RedDotSecurity.news website that contains a plethora of links to other items, not mentioned or gone into detail here, that are worth skimming to see if they interest you or pertain to your particular environment or of those you support. There is a lot more than what is provided in these opening comments. Now, on to the headline news.

Headline NEWS:

  • Adobe Commerce max-severity bug comes under active attack. Threat Actors are actively exploiting a zero‑day vulnerability in Adobe Commerce and Magento that allows unauthenticated remote code execution (RCE), enabling stealthy backdoors on affected online stores. The defect, dubbed StyleSmuggler, abuses Magento’s template styling system to inject malicious PHP code deploying a Rust‑based implant. In response, Adobe has released an emergency hotfix. Customers with compromised stores are urged to hunt for secondary backdoors and rotate credentials.
  • Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE. Check Point quietly patched two critical CVSS 9.8‑rated VPN certificate vulnerabilities that could lead to unauthenticated RCE on Security Gateways and Management Servers under certain undisclosed conditions . Although the company says it found the flaws internally and sees no evidence of exploitation, customers report slow patch rollouts, unclear mitigation guidance, and broken download links. And unfortunately, the only workaround the vendor offered was disabling implied VPN rules, but the guidance was so unclear that many customers aren’t able to safely implement it.
  • Microsoft’s September 2026 Massive Patch Release. If it wasn’t for them warning us in the prior few months that this was coming, I’d say this was unusually voluminous, fixing nearly 1000 vulnerabilities across Windows, Azure, Office, Defender, and developer tooling, including dozens rated critical and several already exploited in the wild. Analysts describe it as Microsoft’s largest and most urgent patch drop ever, driven by broad attack surface coverage and multiple high‑risk privilege‑escalation chains. I’m impressed that Redmond was even able to produce that many patches in one month! This month’s release is huge, messy, and absolutely mandatory to get deployed quickly.
  • SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution. How do you still have unauthenticated RCE’s after all this time? SAP rushed out fixes for OVERPASS, a CVSS perfect 10 kernel vulnerability across multiple SAP NetWeaver and ABAP‑based products. The defect is apparently trivially exploitable, affects core components used in thousands of enterprises, and requires immediate patching because there are no workarounds that adequately address the risk.

In Ransomware, Malware, and Vulnerabilities News:

  • There’s not one thing that stands out in this section this week, there’s just so much. Check Point VPN, Chromium and Chrome zero-days, Palo Alto PAN-OS vulnerability, Papercut finally has a patch, not just an emergency hotfix, GitLab CVSS perfect 10 file read defect, cPanel defect allowing an attacker to run as root, VLC vulnerabilities, Microsoft recommendations on executive phishing, and Florida’s DAVID DMV database being exfiltrated by ShinyHunters. Be sure to check out the full listing of links.

In Other News Events of Note and Interest:

Musings

  • Are we on the verge of a real Skynet moment? This week has seen three executives resign from AI companies Anthropic and OpenAI over what one described as, “racing straight to self‑improving superintelligence and gambling with our lives”. In July more than 1,300 AI company employees signed an open letter calling on the US Government to “support an international effort to develop the technical and governance tools needed to deliberately pace the frontier of automated AI development.” And then there are the break-out events that are increasingly being reported, another one this week. And, to me, it seems very suspicious timing that all three major AI engines went down on September 3, 2026, when ChatGPT, Claude, and Grok experienced overlapping global outages. Coincidence? Or was this a coordinated reboot by handlers attempting to regain control? Just glancing across the article titles in our AI, LLM’s, Robots, and Skynet section of the full newsletter seems to imply that something’s up, and many are getting nervous.
Visc. Jan Broucinek

Keep the Shields Up!

Viscount Jan Broucinek
Red Dot Security News

Headline NEWS

Ranomware, Malware, and Vulnerabilities News

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest

 

Share this with:

Leave a Reply

Your email address will not be published. Required fields are marked *