Skip to content

Sam's News โ€” security โ€” 2026-09-14

Security

8.5 Microsoft September patch breaks record with 972 vulnerabilities, 112 critical

Microsoft's September security patch sets a new record by addressing approximately 972 vulnerabilities, including 112 rated as critical severity.

Sources: Schneier on Security RSS

8 DDRop attack compromises Intel TDX and AMD SEV-SNP confidential computing

Researchers from KU Leuven, ETH Zurich, Durham University, and Google disclosed DDRop, a hardware attack that breaks Intel TDX, Intel Scalable SGX, and AMD SEV-SNP confidential computing by silently dropping memory writes. An attacker needs server software control and brief physical access to insert a sub-$200 interposer board; on Intel TDX the attack achieves full protected VM control, marking the first active interposer attack on DDR5 and the first to break TDX integrity rather than just read data.

  • DDRop breaks Intel TDX, Intel Scalable SGX, AMD SEV-SNP confidential computing
  • Interposer board costs under $200 to build
  • First active interposer attack on DDR5 memory in current cloud servers
  • Enables full control of protected VMs via encrypted page table manipulation
  • Research presenting at ACM CCS 2026 in November with open-source code

Sources: The Hacker News AI Web Searched

7.5 Three JFrog Artifactory vulnerabilities actively exploited for backdoor deployment

Security researchers identified three JFrog Artifactory flaws being exploited in the wild to bypass authentication and gain administrator privileges.

  • CVE-2026-42018 and CVE-2026-42016 chained to escalate anonymous token to administrator privileges in under five minutes
  • Attacks appeared in logs as 'token:anonymous' rather than named accounts
  • JFrog released CVE-2026-42018 fix August 12; attacks began August 15 (three days later)
  • Separate critical flaw CVE-2026-82329 (CVSS 9.8) exploited September 1โ€“8; affects versions up to 7.161; CISA added to known exploited catalog September 2 with September 5 federal deadline

Sources: SecurityWeek RSS Update to: Attackers chain JFrog Artifactory flaws to gain admin control and plant backdoors

7.5 ConnectWise patches critical ScreenConnect vulnerability exploited in attacks

ConnectWise has released a patch for a critical ScreenConnect flaw allowing unauthorized file execution and transfer in active remote sessions.

Sources: SecurityWeek RSS

7.5 Malicious Twitch browser extension leaks OAuth tokens from 31,000 users

The Twitch Enhanced Viewer | JeetBot extension, installed by 30,000 users and available in Chrome and Firefox, leaked users' Twitch OAuth session tokens to a commercial service.

Sources: The Hacker News RSS, BleepingComputer RSS

7.5 CISA warns of active GitLab maximum-severity vulnerability exploitation

The U.S. Cybersecurity and Infrastructure Security Agency reports that hackers are exploiting a maximum-severity GitLab vulnerability in live attacks.

Sources: BleepingComputer RSS

7.5 Chinese threat actor Red Heron exploits Gitea RCE vulnerability across six countries

Red Heron, a suspected Chinese threat actor, exploited CVE-2026-60004, a critical Gitea RCE vulnerability, to compromise 13 organizations across Canada, Argentina, Taiwan, U.S., Qatar, and Sri Lanka. The group weaponized public exploit code into an automated framework within days of the July 2026 disclosure, progressing from source-code theft to persistent root-level access, deploying a C++ Linux implant and an LD_PRELOAD rootkit across defense, election, energy, aerospace, and government sectors.

  • CVE-2026-60004 Gitea RCE exploited by Red Heron
  • 13 organizations compromised across 6 countries (Taiwan 4, U.S. 4, Canada 2, others 3)
  • 1,386 Gitea instances scanned; 477 Taiwan-based systems tracked
  • Automated Python exploit framework deployed by July 29, 2026
  • JITTERLY C++ implant and SIXZUT LD_PRELOAD rootkit deployed
  • Victims in defense, election, energy, aerospace, telecommunications, government sectors

Sources: The Hacker News AI Web Searched

7 Microsoft releases emergency Windows updates for RDS failures

Microsoft issued out-of-band security updates to fix Remote Desktop Services failures, Hyper-V, and USB audio issues.

Sources: BleepingComputer RSS

7 Hackers hijack HBO Max Reddit account to distribute ClickFix malware

Attackers compromised HBO Max's official Reddit account and used it to push malicious advertisements that deployed ClickFix malware to Windows and macOS systems.

Sources: BleepingComputer RSS

6.5 CISOs grapple with securing AI agents

Security leaders face challenges modernizing cyber hygiene while preventing over-privileged AI agents from causing unintended harm.

Sources: SecurityWeek RSS