Daily cybersecurity briefing

Top 10 Cybersecurity Stories for September 9, 2026

Google shipped fixes for an actively exploited V8 out-of-bounds write (CVE-2026-87491) enabling sandboxed code execution via crafted HTML, and Microsoft's September cumulative update closes two confirmed zero-days—CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC—both granting SYSTEM to low-privilege authenticated users. SAP's newly patched CVSS 10.0 kernel flaw (CVE-2026-44756) permits unauthenticated remote code execution with administrative privileges across web, GUI, and RFC layers, and Onapsis warns that no network control or authorization boundary stops it because the vulnerable deserialization runs before any authentication step.

Compiled by the Slugnet Editorial System. Published Sep 9, 2026, 7:28 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    The Hacker News

    Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

    What happened

    Google released Chrome updates to patch CVE-2026-87491, an out-of-bounds write in the V8 engine that allows remote attackers to execute arbitrary code inside the browser sandbox via a crafted HTML page. The company confirmed the vulnerability is under active exploitation in the wild, though it has not disclosed details regarding the specific attack methods or the actors responsible. Users should update to Chrome version 153.0.8010.36 or later to mitigate the risk.

    Why it ranks #1

    Google confirmed that CVE-2026-87491, an out-of-bounds write in the V8 engine, is under active exploitation in the wild to execute arbitrary code inside the browser sandbox via a crafted HTML page, prompting the release of Chrome version 153.0.8010.36 as the mitigation.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    What to do

    Update Chrome to 153.0.8010.36/.37 on Windows and macOS, or 153.0.8010.36 on Linux, for optimal protection.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    Help Net Security

    September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor

    What happened

    Microsoft released a record number of patches in its September 2026 update, addressing two actively exploited zero-day vulnerabilities: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in the Windows Advanced Local Procedure Call. CVE-2026-81963 allows low-privilege authenticated attackers to escalate to SYSTEM privileges on Windows 11 and Server 2025, while CVE-2026-85880 is a privilege escalation to SYSTEM bug affecting Windows 10 and older server versions.

    Why it ranks #2

    Microsoft released a record number of patches in its September 2026 update, addressing two actively exploited zero-day vulnerabilities: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in the Windows Advanced Local Procedure Call.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    product
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    BleepingComputer

    Microsoft releases Windows 10 KB5122878 extended security update

    What happened

    The source text does not mention the EU Cyber Resilience Act, its vulnerability reporting requirements, or a September 11 effective date, so the claim that it mandates 24-hour reporting of actively exploited flaws is unsupported. The source text does not mention any deadline, vendor record-keeping requirements, or specific dates for vulnerability discovery.

    Why it ranks #3

    Microsoft released KB5122878 to address security vulnerabilities in Windows 10, providing a standard monthly update for system hardening without indicating active exploitation or immediate critical risk.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    BleepingComputer

    The EU CRA's Real Question: What Shipped, and When Did You Know?

    What happened

    The EU Cyber Resilience Act’s vulnerability reporting requirements take effect on September 11, mandating that software vendors report actively exploited flaws within 24 hours. ActiveState explains that knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the EU Cyber Resilience Act's requirement to report actively exploited flaws within 24 hours.

    Why it ranks #4

    The EU Cyber Resilience Act’s vulnerability reporting requirements take effect on September 11, mandating that software vendors report actively exploited flaws within 24 hours.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    low
    Urgency
    monitor
    Confidence
    medium
    Scope
    enterprise
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    The Hacker News

    F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

    What happened

    Sophos identified malware on F5 BIG-IP APM appliances that injects a PHP web shell directly into memory, allowing it to evade traditional disk-based file integrity checks. The intrusion leverages CVE-2025-53521, a remote code execution flaw in the APM component that F5 reclassified in March 2026 after confirming active exploitation.

    Why it ranks #5

    Sophos identified malware on F5 BIG-IP APM appliances that injects a PHP web shell directly into memory to evade disk-based file integrity checks, leveraging CVE-2025-53521, a remote code execution flaw that F5 reclassified in March 2026 after confirming active exploitation.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    Help Net Security

    What breach and attack simulation needs to become in the AI era

    What happened

    Picus released its 2026 Blue Report, which aggregated 338 million attack simulations to show that average prevention effectiveness dropped to 69% while alert scores remained flat at 14%. The data indicates that 49% of detection failures stem from performance issues and 41% from silent log collection gaps, leaving roughly a third of attacks unblocked. The report argues that traditional, schedule-driven breach and attack simulation cannot keep pace with AI-accelerated threats, necessitating a shift to signal-driven, agentic validation loops.

    Why it ranks #6

    Picus released its 2026 Blue Report, which aggregated 338 million attack simulations to show that average prevention effectiveness dropped to 69% while alert scores remained flat at 14%.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    The Hacker News

    SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

    What happened

    SAP released security updates to address CVE-2026-44756, a CVSS 10.0 memory corruption flaw in the SAP kernel's Extended Passport processing that allows unauthenticated remote code execution. The vulnerability, codenamed OVERPASS by Onapsis, enables attackers to execute arbitrary operating system commands with administrative privileges by sending crafted network requests containing malformed EPP headers.

    Why it ranks #7

    SAP released security updates to address CVE-2026-44756, a CVSS 10.0 memory corruption flaw in the SAP kernel's Extended Passport processing that allows unauthenticated remote code execution.

    Who should care

    Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    critical
    Urgency
    near-term
    Confidence
    high
    Scope
    product
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    The Hacker News

    New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

    What happened

    cPanel released a patch for CVE-2026-67401, an SQL injection vulnerability in EmailTrack that allows an authenticated user with mail privileges to create files and execute code as root. The advisory, published on September 8, affects all supported versions of cPanel and WHM, with no public evidence of active exploitation or a CVSS score assigned at the time of reporting.

    Why it ranks #8

    cPanel released a patch for CVE-2026-67401, an SQL injection vulnerability in EmailTrack that allows an authenticated user with mail privileges to create files and execute code as root.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    The Hacker News

    Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

    What happened

    Security researcher Chaotic Eclipse released a proof-of-concept for ShieldCrash, a patch bypass for the recently fixed Microsoft Defender vulnerability CVE-2026-69414. The exploit allows an attacker to perform arbitrary file reads with SYSTEM privileges on all supported Windows versions. Microsoft addressed the flaw in Malware Protection Engine version 1.1.26080.3, which deploys automatically to keep the engine current.

    Why it ranks #9

    Security researcher Chaotic Eclipse released a proof-of-concept for ShieldCrash, a patch bypass for the recently fixed Microsoft Defender vulnerability CVE-2026-69414, which allows an attacker to perform arbitrary file reads with SYSTEM privileges on all supported Windows versions.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    product
    Status
    proof of concept
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    Help Net Security

    AI-Infra-Guard: Open-source security scanner for AI systems

    What happened

    Tencent’s Zhuque Lab released AI-Infra-Guard, an open-source scanner that fingerprints AI services like Ollama and vLLM to check them against over 1,600 known CVEs. The tool also inspects MCP servers and agent skills for risks, including indirect prompt injection, though the repository warns it lacks built-in authentication and should not be exposed to the internet.

    Why it ranks #10

    Tencent’s Zhuque Lab released AI-Infra-Guard, an open-source scanner that fingerprints AI services like Ollama and vLLM to check them against over 1,600 known CVEs.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    low
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email