Security news.
Today's security landscape is dominated by a record-breaking Microsoft Patch Tuesday, addressing nearly a thousand vulnerabilities, including several actively exploited zero-days. Additionally, a critical flaw in DeepSeek Harness highlights AI agent security concerns, while US agencies warn of systematic AI capability extraction by China.
DeepSeek Harness Flaw Lets AI Agents Disable Own Sandbox
A critical flaw in DeepSeek's open-source tool for AI coding agents allowed sandboxed agents to disable their own file sandbox with a single command, posing a significant risk for developers running untrusted AI code.
US Agencies Accuse China AI Firms of Systematic AI Model Extraction
US cybersecurity and intelligence agencies report that China-based AI companies are systematically extracting proprietary functionalities and capabilities from American frontier models like Claude, GPT, Gemini, and Grok through "distillation attacks."
New Microsoft Defender 'ShieldCrash' Zero-Day Grants SYSTEM Access
A security researcher has released a new proof-of-concept for a Microsoft Defender zero-day exploit, "ShieldCrash," which grants SYSTEM access and bypasses the patch for a previously reported vulnerability (CVE-2026-69414).
Google Warns of New Chrome Zero-Day Bug Exploited in Attacks
Google has patched 230 vulnerabilities in Chrome, including CVE-2026-87491, an actively exploited out-of-bounds bug in the V8 JavaScript engine, marking the seventh Chrome zero-day addressed this year.
SAP Patches CVSS 10.0 Kernel Flaw Enabling Remote Code Execution
SAP has released updates for multiple vulnerabilities, including a critical memory corruption flaw (CVE-2026-44756, CVSS 10.0) in SAP Extended Passport (EPP) Processing that allows unauthenticated remote code execution.
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Microsoft's September Patch Tuesday addressed a record-breaking 974 vulnerabilities across its software portfolio, including two actively exploited Windows zero-days (CVE-2026-81963 and CVE-2026-85880) and 110+ critical issues.
Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
A critical flaw in Alby Hub, a self-hosted Lightning Bitcoin wallet, could have allowed attackers to take over wallets and steal funds if the owner had exposed the Hub to the internet.
Ivanti Patches Critical Flaws Across Enterprise Security Products
Ivanti has released patches for six critical vulnerabilities in Neurons for ITSM that could lead to remote code execution, alongside authentication bypass flaws in Sentry and EPMM.