Here are today’s top cybersecurity stories for Tuesday, September 8, 2026.
Microsoft Ships Record 974-CVE Patch Tuesday With Two Exploited Zero-Days
Microsoft released fixes for 974 vulnerabilities in its September 2026 Patch Tuesday, its largest release on record, spanning 723 flaws in Windows and 222 in Office. Two vulnerabilities saw active exploitation before the patch: CVE-2026-85880, a Windows ALPC elevation-of-privilege flaw, and CVE-2026-81963, a link-following defect in the Windows Update Stack, letting local attackers reach System privileges. Twenty of the newly fixed flaws are rated wormable, and CISA added both exploited CVEs to its Known Exploited Vulnerabilities catalog the same day. SecurityWeek
Adobe Rushes Emergency Fix for Magento Zero-Day Already Deploying Backdoors
Adobe issued an emergency hotfix for CVE-2026-75650, a maximum-severity zero-day dubbed StyleSmuggler affecting Adobe Commerce, Commerce B2B, and Magento Open Source. E-commerce security firm Sansec traced exploitation back to at least September 4, with one attacker planting a Rust-based Linux backdoor disguised as an NTP server and a second deploying a PHP web shell. Adobe added the flaw to CISA’s KEV catalog and directs administrators to apply the VULN-39341 hotfix and rotate all credentials afterward. BleepingComputer | The Hacker News
CISA Adds Four Flaws to KEV Catalog, Including Both Patch Tuesday Zero-Days
CISA added four vulnerabilities to its Known Exploited Vulnerabilities catalog: the Adobe Commerce/Magento StyleSmuggler flaw, the two actively exploited Windows Patch Tuesday zero-days, and the N-able N-central static code injection bug patched last week. Federal agencies face a standard remediation deadline under Binding Operational Directive 22-01. CISA
SAP Patches Maximum-Severity Flaw in Extended Passport Processing
SAP’s September 2026 Security Patch Day delivered 19 new notes and one update, led by CVE-2026-44756, a memory corruption bug in SAP Extended Passport Processing rated 10.0 on the CVSS scale, affecting kernel and Web Dispatcher versions across the 7.x and 9.x branches. Additional critical fixes address a missing authentication check in NetWeaver Message Server (CVE-2026-58240, CVSS 9.8) and a credential disclosure flaw in the Cloud Application Programming Model library (CVE-2026-76969, CVSS 9.4). SecurityWeek
Google: Attacker Built AI Multi-Agent Credential-Theft Operation in Under Six Hours
Google’s Threat Intelligence Group reported a financially motivated actor used an autonomous multi-agent AI framework to plan, build, and deploy a mass credential-harvesting campaign in less than six hours, with the agents managing vulnerability scanning, IP rotation, and traffic routing through compromised cloud environments with minimal human input. In a separate incident, researchers found an exposed command-and-control panel named “Recon” managing more than 23,800 harvested secrets in real time. Google says fully autonomous attack pipelines remain rare, though the shift from AI-assisted coding to multi-agent operations is accelerating. BleepingComputer | The Hacker News
Zero-Click “WeWorm” Flaw Lets a Single WeChat Call Hijack Accounts
Researchers disclosed a zero-click vulnerability in WeChat, nicknamed WeWorm, allowing an attacker to hijack an account and self-propagate through a single voice call without any interaction from the victim. The flaw underscores growing researcher attention on messaging platforms with hundreds of millions of daily active users outside North America. Help Net Security
Help-Desk Vishing Wave Drains Microsoft 365 Accounts Through Residential Proxies
Security researchers documented a wave of data theft and extortion attacks against Microsoft 365 and other SaaS accounts, driven by attackers impersonating IT help-desk staff over the phone to trick employees into handing over session tokens or approving fraudulent multi-factor prompts. Stolen sessions are routed through residential proxy networks to evade location-based anomaly detection before attackers exfiltrate mailbox and file data. Help Net Security
Settra Ransomware Group Claims Canadian Telecom Infrastructure Firm Teletek Structures
The Settra ransomware group listed Teletek Structures Inc., an Ontario-based telecommunications engineering firm designing and reinforcing cell tower infrastructure for carriers including Bell, Rogers, and Telus, on its extortion leak site. The group claims exfiltrated data from an intrusion estimated to have begun around mid-August, and Teletek has issued no public statement confirming the incident. DeXpose
Hackers Return $263 Million of Liquid Network Bitcoin Theft, $47 Million Still Missing
Attackers who stole nearly 4,000 bitcoin from the Bitcoin sidechain Liquid Network returned 3,400 bitcoin, worth roughly $263 million, within a day of the theft. Around 598.5 bitcoin, worth close to $47 million, remains unreturned as investigators work to trace the outstanding funds. SecurityWeek
Stay tuned for today’s in-depth analysis posts.






