Security news.
September Patch Tuesday brought a record-breaking number of fixes from Microsoft, including two actively exploited zero-days, alongside a critical zero-day patch from Adobe. Meanwhile, the cybersecurity community is increasingly concerned about the active use and exploitation of AI agents by cybercriminals for large-scale attacks and data exfiltration.
Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
Microsoft's September Patch Tuesday addressed a record 974 vulnerabilities, including two actively exploited privilege escalation zero-days and 20 potentially wormable flaws.
Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
Adobe released emergency patches for over 170 vulnerabilities, with a critical zero-day (CVE-2026-75650) in Adobe Commerce and Magento Open Source allowing unauthenticated remote code execution.
CISA Adds Four Known Exploited Vulnerabilities to Catalog
CISA updated its KEV Catalog with four new vulnerabilities, including the actively exploited Adobe Commerce zero-day (CVE-2026-75650) and several Microsoft Windows flaws, urging immediate remediation.
Silicon Valley’s AI Agent Push Has Been Paying Off—for Cybercriminals
Google reports that threat actors from China, Iran, and Russia are leveraging autonomous AI systems for cybercriminal activities, moving beyond simple chatbots to more sophisticated operations.
The Hidden Instructions That Can Hijack AI Agents
Malicious prompts concealed in various data types, such as documents and images, can manipulate autonomous AI agents into performing dangerous, unintended actions.
MikroTik Patches Critical Flaws Chained to Hack Routers
MikroTik released patches for "MikroTrick" vulnerabilities, including an SSH authentication bypass, which attackers can chain to overwrite configuration files and take over devices.
SAP warns of maximum severity 'OVERPASS' kernel vulnerability
SAP's September security updates address 20 vulnerabilities, notably a maximum-severity memory corruption flaw in the SAP Kernel that allows unauthenticated remote code execution and data compromise.
The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT
Research revealed a ChatGPT flaw where a planted prompt could exfiltrate a victim's Gmail data to another account via a hidden channel, highlighting risks in LLM security models.