1. A maximum-severity Magento zero-day was exploited for three days before Adobe shipped a fix — CVE-2026-75650 — Do: Apply the APSB26-146 composer patch, then hunt — Adobe — https://helpx.adobe.com/security/products/magento/apsb26-146.html
2. MikroTik routers taken over through an SSH key check that ignores half the key — CVE-2026-67276, CVE-2026-67277 — Do: Update RouterOS, then audit SSH users and keys — CERT Polska — https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/
3. N-able's fourth N-central hotfix in five weeks, and its own notices disagree on exploitation — CVE-2026-86218 — Do: Install N-central Hotfix 4, build 2026.3.1.14 — N-able — https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/
4. A phishing service beat MFA at 258 organisations and took 5,000 Microsoft 365 logins — Do: Move admins to phishing-resistant sign-in — BleepingComputer — https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/
5. ConnectWise has no patch for a ScreenConnect file-transfer flaw, and rogue clients are spreading malware — Do: Deselect TransferFiles on every ScreenConnect role — ConnectWise — https://www.connectwise.com/company/trust/advisories
6. Attackers are phoning executives, posing as the help desk, and walking off with the session — Do: Give the help desk a caller-verification step — The Hacker News — https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html
7. One researcher dropped zero-days for Avast, CrowdStrike and Nvidia inside a week — Do: Disable Falcon's Office macro removal for now — SecurityWeek — https://www.securityweek.com/nightmare-eclipse-drops-crowdstrike-nvidia-avast-zero-day-exploits/
8. A working exploit chain for Telerik is now public, two months after the patch — CVE-2019-18935, CVE-2026-13181 — Do: Upgrade Telerik UI to 2026.2.708 or later — The Hacker News — https://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html
9. A fake bookmarks extension turns Chrome and Edge into a command channel — Do: Hunt for extensions loaded outside the Web Store — The Hacker News — https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html
10. Nine years of passenger records sat in an Elasticsearch cluster anyone could reach — Do: Find search clusters answering from the internet — BleepingComputer — https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/
11. Berlin refused a €2m ransom and Rhysida published nearly six terabytes — Do: Write down who refuses a ransom — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/rhysida-berlin-data-extortion/
12. An unpatched Metabase handed over a million students' details — Do: Patch and gate your self-hosted BI tools — Help Net Security — https://www.helpnetsecurity.com/2026/09/08/mathspace-data-breach-metabase-vulnerability/
13. The NCSC says most staff are already using AI you have not approved — Do: Publish an approved AI tool people will use — NCSC — https://www.ncsc.gov.uk/blog-post/shadow-ai
14. Ransomware negotiation has turned into a business process with its own staff — Do: Work out your own ransom number first — Help Net Security — https://www.helpnetsecurity.com/2026/09/08/ransomware-negotiation-tactics-video/
15. A North Korean backdoor is compiled into the victim's own load balancer — Do: Verify HAProxy and daemons against their packages — Security Affairs — https://securityaffairs.com/198656/apt/north-korea-linked-hackers-hide-a-backdoor-inside-haproxy.html
16. The SEO agency poisoning your search results has been at it since 2015 — — The Hacker News — https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html