
Cyber Security News for September 10 2026 - Daily DefSec Brief
Show notes
1. Cisco firewall manager exploited to root — CVE-2026-20079 (CVSS 10.0), CVE-2026-20316 — Do: Apply the Cisco Secure FMC hotfixes now — Cisco Talos — https://blog.talosintelligence.com/fmc-ongoing-exploitation/
2. NetScaler auth bypass now actively exploited — CVE-2026-19490 (CVSS 9.3, NVD v4.0) — Do: Upgrade NetScaler to 14.1-73.32 or 13.1-63.21 — Rapid7 — https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway/
3. Four spy crews, one shared exploit kit — CVE-2026-85046, CVE-2026-85880 — Do: Confirm Chrome 153 and September Windows landed — The Record — https://therecord.media/china-hackers-chrome-browser-zero-day-multiple-groups
4. FortiOS packet flaw added to CISA KEV — CVE-2025-25249 (CVSS 8.1) — Do: Upgrade FortiOS off the affected branches — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
5. Passkey social engineering ends in cloud takeover — Do: Alert on new auth methods added to accounts — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/
6. Shai-Hulud back past npm's scan — feishu-docx-mcp, bmc-i18n-extract-cli, blueai-cli, bmc-translate-utils — Do: Rotate npm tokens, install with --ignore-scripts — Aikido Security — https://www.aikido.dev/blog/shai-hulud-npm-resurfaces
7. Phishing page assembled inside the browser — Do: Alert on OAuth redirects leaving Microsoft — Help Net Security — https://www.helpnetsecurity.com/2026/09/10/browser-based-phishing-blob-urls-microsoft-oauth/
8. Stealer logs yield replayable AI tokens — Do: Rotate AI provider keys after any stealer hit — https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html
9. Fortinet portal leaks a token-forging secret — CVE-2026-84390 (CVSS 9.6), CVE-2026-84388 (CVSS 9.1) — Do: Patch FortiPAM and the browser extension together — SecurityWeek — https://www.securityweek.com/fortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extension/
10. Android patches 180 flaws in one month — Do: Push the September Android patch level — https://www.securityweek.com/androids-september-2026-updates-patch-180-vulnerabilities/
11. AI workflows run on the wrong identity — Do: Run AI workflows as the requester — https://www.darkreading.com/threat-intelligence/identity-based-ai-attack-security-enterprise-data
12. Agent could turn off its own sandbox — CVE-2026-82533 (CVSS 9.6) — Do: Update DeepSeek Harness to 0.1.2-alpha.1 — https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html
13. Scanning and brute force on Proxmox — Do: Take Proxmox port 8006 off the internet —https://isc.sans.edu/diary/rss/33324
14. Vendor credentials opened an EHR API — Do: List vendors holding API credentials to you — The Record — https://therecord.media/electronic-health-record-company-says-customer-data-stolen-in-breach
15. Machine identities overtake phishing — Do: Inventory and expire non-human identities — https://www.infosecurity-magazine.com/news/nhis-number-one-corporate-entry/
16. Contractor's admin account outlived him — Do: Match every admin account to a current person — The Register — https://www.theregister.com/security/2026/09/10/dental-contractor-set-up-secret-account-with-access-to-4000-patient-records-then-left-the-company/5295361
17. EU gives you 24 hours to report from Friday — Do: Name who files your EU 24-hour report — Dark Reading — https://www.darkreading.com/cybersecurity-operations/eu-cyber-resilience-act-reporting-requirements
18. Phishing from the vendor's own address — Do: List who can send mail as your domain — BleepingComputer — https://www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/← Previous
Cyber Security News for September 9 2026 - Daily DefSec Brief
Next →
Cyber Security News for September 11 2026 - Daily DefSec Brief