Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Friday, September 11, 2026

Here are today’s top cybersecurity stories for Friday, September 11, 2026.

September Patch Tuesday Updates Break Remote Desktop Services on Windows Server
Windows administrators report Microsoft’s September 2026 cumulative updates — KB5122876, KB5122882, and KB5122871 for Windows Server 2019, 2022, and 2025 — cause Remote Desktop Services connections to fail hours after installation, sometimes requiring a hard reset to restore service. Rolling back the update restores Remote Desktop functionality but removes this month’s security fixes. Microsoft confirmed it is investigating and will publish guidance. BleepingComputer

Trezor: Marketing-Platform Breach Exposes 347,000 Users to Phishing
An attacker breached Brevo, a third-party email marketing platform Trezor uses for newsletters, by exploiting its SAML single sign-on process to reach 138 customer accounts. The attacker sent phishing emails from Trezor’s account to roughly 347,000 addresses, and 2,500 recipients clicked the malicious link before Trezor took the phishing domain down within 20 minutes. SecurityWeek

New Android Malware Mantax Otax Combines Ransomware With Spyware
Zimperium researchers identified Mantax Otax, an Android malware strain distributed through malicious APKs outside Google Play and targeting users in Indonesia. The malware steals SMS messages, one-time passwords, photos, and account credentials, encrypts files on older Android versions, and pushes victims into an on-device extortion chat. BleepingComputer

Unsecured Veeam Database Exposes an Estimated 445 Million Records
Independent researcher Bob Diachenko found a Veeam marketing database hosted on Amazon Web Services left open without authentication since at least September 5, exposing customer names, emails, and countries dating back to 2013 through 2017. Veeam locked down the server September 9, days after Diachenko’s outreach went unanswered. Dark Reading

Gigabud Banking Trojan Clones Apps Into Hidden Android Work Profiles
Group-IB researchers documented the GoldFactory-linked Gigabud trojan pairing with Vwork, a modified version of an open-source Android cloning tool, to copy banking apps into a sandboxed work profile invisible to fraud-detection scans. Group-IB tracked Vwork-compatible Gigabud samples across eleven countries, with roughly 1,469 compromised devices and an estimated $960,000 in losses in Indonesia between February and July 2026. The Hacker News

Researchers Demonstrate InjectEave Electromagnetic Side-Channel Attack
A research team detailed InjectEave, a new class of electromagnetic side-channel attacks in which an external radio-frequency signal induces hardware nonlinearities, leaking analog information from a device. Tests across eleven commercial devices recovered private audio and appliance states without physical access or hardware modification. SecurityWeek

Review Finds Anthropic’s AI Bug-Hunting Program Fixed Few Reported Flaws
VulnCheck’s review of Anthropic’s Project Glasswing found maintainers fixed only 202 of 26,153 claimed vulnerabilities after nearly five months, while withdrawing 245 more. Claude rated 91.5 percent of findings with available severity scores as high or critical, compared with 51.3 percent from human maintainers. SecurityWeek

SANS ISC: AI Coding Agent Harvests and Resells Stolen LLM Access
The SANS Internet Storm Center described a semi-autonomous coding agent scanning for poorly secured LLM resale gateways, then harvesting and reselling stolen inference access without direct human operation at each step. The captured operation loaded roughly 379 upstream endpoints and consolidated working access behind a single attacker-controlled gateway. SANS Internet Storm Center

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.