Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Sep 9, 2026·5m

Cyber Security News for September 9 2026 - Daily DefSec Brief

Show notes

1. Record 974-CVE Patch Tuesday, two zero-days live — CVE-2026-81963, CVE-2026-85880 (CVSS 7.8) — Do: Install September Windows updates now — SecurityWeek — https://www.securityweek.com/microsoft-patches-record-974-vulnerabilities-including-two-exploited-zero-days/
2. Chrome 153 patches its seventh zero-day of 2026 — CVE-2026-87491 — Do: Push Chrome 153.0.8010.36, force restart — SecurityWeek — https://www.securityweek.com/chrome-153-patches-seventh-zero-day-of-2026/
3. F5 BIG-IP rootkit hides its web shell in memory — CVE-2025-53521 (CVSS 9.8) — Do: Patch BIG-IP APM, then hunt memory — The Hacker News — https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html
4. Defender patch bypassed again, no fix yet — CVE-2026-69414 (the bypassed fix) — Do: No fix — watch SYSTEM-level file reads — Security Affairs — https://securityaffairs.com/198726/security/chaotic-eclipse-released-shieldcrash-a-poc-for-microsoft-defender-zero-day.html
5. SAP kernel flaw scores 10.0, no auth needed — CVE-2026-44756 (CVSS 10.0) — Do: Apply September SAP security notes — SecurityWeek — https://www.securityweek.com/sap-patches-critical-extended-passport-processing-vulnerability/
6. Phishing chain hides inside Google's own redirects — Do: Hunt unauthorised ScreenConnect installs — Dark Reading — https://www.darkreading.com/cyberattacks-data-breaches/attackers-multi-hop-google-redirects-phishing-campaign
7. Ivanti patches ten flaws, two unauth RCE at 9.8 — CVE-2026-12744, CVE-2026-12745, CVE-2026-18851, CVE-2026-83527 — Do: Patch EPMM to 12.10.0.0 or 12.9.0.2 — Ivanti — https://www.ivanti.com/blog/september-2026-security-update
8. ClearFake runs its loader straight off WebDAV — Do: Block outbound WebDAV at the proxy — Cisco Talos — https://blog.talosintelligence.com/clearfake-webdav-infection-chain/
9. New N-central chain creates its own admin account — CVE-2026-86206, CVE-2026-86207 — Do: Apply N-central 2026.3 Hotfix 3 — Rapid7 — https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed
10. FreeIPA lets an anonymous client become admin — CVE-2026-76578, CVE-2026-13097, CVE-2026-76560, CVE-2026-79678 — Do: Update FreeIPA to 4.13.4 — The Hacker News — https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html
11. Extortion crews now steal the model itself — Do: Inventory model weights as crown jewels — The Register — https://www.theregister.com/research/2026/09/08/extortion-crews-have-their-eyes-on-high-value-ai-data-google-warns/5294640
12. VMware Workstation and Fusion guest escapes — CVE-2026-59346, CVE-2026-59347 — Do: Update VMware Workstation and Fusion — SC World — https://www.scworld.com/brief/broadcom-patches-critical-vmware-workstation-and-fusion-vm-escape-vulnerabilities
13. Planted prompt sent ChatGPT's Gmail data elsewhere — Do: Cut ChatGPT connector scopes back — Check Point Research — https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/
14. Android RAT worms through open ADB ports — Do: Disable ADB over TCP on managed Android — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/thost9-android-rat-packed-loader/
15. UEFI shell in flash defeats Secure Boot — CVE-2026-20293, VU#718077 — Do: Set BIOS passwords, patch UCS firmware — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW
16. Military kills ad IDs — Do: Disable advertising IDs via MDM — Bitdefender — https://www.bitdefender.com/en-us/blog/hotforsecurity/us-military-turned-off-ad-tracking-phones
17. BleachBit's shredder skipped parts of the file — Do: Update BleachBit, wipe free space — Help Net Security — https://www.helpnetsecurity.com/2026/09/09/bleachbit-6-0-4-released/