Attackers have deployed a Linux rootkit on F5 BIG-IP APM devices, utilizing a method that hides a web shell in memory rather than writing it to disk. This technique makes detection more challenging for traditional security tools. F5 BIG-IP APM is a system designed for enforcing access policies.
In a separate development, state-sponsored and financially motivated threat actors are actively exploiting two critical vulnerabilities in Cisco Secure Firewall Management Center (FMC). These include CVE-2026-20079, an authentication bypass flaw, and CVE-2026-20316. Cisco FMC is used for centralized management of multiple Cisco Secure Firewall devices across a network.
Additionally, N-able has released an emergency hotfix for CVE-2026-86218, a critical remote code execution (RCE) vulnerability affecting its N-central remote monitoring and management (RMM) solution. This flaw, which has a critical CVSS rating, could allow pre-authenticated remote code execution on the N-central server and has been exploited in the wild. N-central is widely used by managed service providers (MSPs).
ConnectWise has confirmed a file transfer flaw in ScreenConnect Remote Access Support and Access sessions, impacting both Cloud and On-Premise deployments. The company recommends that partners disable file transfers for technicians until a fix is available.
CERT Polska has identified and coordinated the disclosure of six vulnerabilities in MikroTik's RouterOS. Among these, two combined flaws, dubbed "MikroTrick," allow an attacker to gain full control of a device without authentication, provided that SSH is accessible from the internet. Attackers are currently exploiting this chain of vulnerabilities to hijack MikroTik devices.
Google has addressed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, which has been actively exploited. The fix has been released in Chrome versions 153.0.8010.36 and .37 for Windows and macOS, and 153.0.8010.36 for Linux.
SatoshiLabs, the manufacturer of Trezor hardware crypto-wallets, has confirmed that approximately 67,000 of its customers are at increased risk of phishing attacks following a breach at a shipping partner. The exposed data includes names, email addresses, phone numbers, and shipping addresses.
Mathspace, a Sydney-based maths education company, has confirmed a breach of its internal reporting system. Attackers exploited an unpatched Metabase vulnerability in the company's self-hosted installation, gaining administrator access without legitimate login credentials. This breach resulted in the theft of data belonging to over a million students, parents, and school staff.
Researchers have discovered a critical vulnerability in WeChat that allowed them to create a "zero-click" worm, named "WeWorm." This worm could spread via WeChat calls without any user interaction, enabling account hijacking. The vulnerability has been privately reported to Tencent.
Microsoft's September 2026 Patch Tuesday included a record number of patches, addressing two vulnerabilities that have been exploited as zero-days.
Threat actors are increasingly incorporating AI agents into cyberattacks, automating processes such as vulnerability scanning, credential harvesting, and troubleshooting, thereby reducing the need for human involvement. This trend was highlighted in Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker.
IT help-desk vishing calls, stolen session tokens, and sign-ins routed through residential proxies are being used in a wave of data theft and extortion targeting Microsoft 365 and other SaaS accounts.
Amazon has elected Kevin Mandia to its Board of Directors on September 8. Mandia founded Mandiant and served as its CEO before its acquisition by Google in September 2022, bringing over 30 years of experience in cybersecurity to the role.






