left cover bg
circles

Security Daily.

Friday, September 11, 2026

Automatically Curated Security Digest

Collected

19 Articles

Across

2 Trusted Sources

Published

Last Updated 11:18 AM UTC

Coverage

BleepingComputer
CISA
Top Story

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISACritical

Why it matters

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

Read Original

19

Articles

2

Sources

3

CVEs

5

Alerts

0

Research

4m

Read Time

Feed Status

CISA6
NIST NVD
BleepingComputer15
PortSwigger Research

Automated Security Digest — This page is an automatically curated cybersecurity digest generated from publicly available security feeds. All articles remain the property of their respective publishers. Click any item to read the original article.

Last generated: Sep 11, 2026, 11:18 AM

Security Alerts

5

Critical alerts and advisories from official agencies.

CISASecurity AlertsCritical

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-67277 MikroTik RouterOS Missing Authentication for Critical Function Vulnerability CVE-2026-86060 MikroTik RouterOS Improper…

CVE-2026-67277CVE-2026-86060
Read Original
CISASecurity Alerts

Orthanc DICOM Server

View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a…

Read Original
CISASecurity AlertsCritical

AVEVA Pipeline Integrity Monitor

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session. The following versions of AVEVA Pipeline Integrity Monitor are affected: AVEVA Pipeline Integrity…

Read Original
CISASecurity Alerts

ST Engineering iDirect iQ-Series Terminals (Update A)

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST Engineering iDirect iQ-Series Terminals (Update A) are affected:…

Read Original
CISASecurity AlertsHigh

NextGen Healthcare Mirth Connect

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition. The following versions of NextGen Healthcare Mirth Connect are affected: Mirth Connect <=v4.7.1 (CVE-2026-82583, CVE-2026-78224,…

CVE-2026-82583CVE-2026-78224
Read Original

Cybersecurity News

14

Latest news from trusted cybersecurity publications.

BleepingComputerCybersecurity NewsHigh

GitLab urges users to patch max severity path traversal flaw

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2023-2825. [...]

CVE-2023-2825
Read Original
BleepingComputerCybersecurity News

Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs

Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. [...]

Read Original
BleepingComputerCybersecurity News

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. [...]

Read Original
BleepingComputerCybersecurity News

Conti ransomware gang member sentenced to 4 years in prison

A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]

Read Original
BleepingComputerCybersecurity News

New Android malware encrypts files, steals data, and harasses victims

A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. [...]

Read Original
BleepingComputerCybersecurity News

September Windows Server updates break Remote Desktop Services

Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality. [...]

Read Original
BleepingComputerCybersecurity News

Surfshark VPN says hackers breached internal testing, proxy servers

Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. [...]

Read Original
BleepingComputerCybersecurity News

Microsoft Excel KB5002914 update breaks copy and paste for some users

Microsoft Excel users report that this week's KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality. [...]

Read Original
BleepingComputerCybersecurity News

AI-powered attack exploited PaperCut flaws to hack 395 organizations

A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. [...]

Read Original
BleepingComputerCybersecurity News

Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [...]

Read Original
BleepingComputerCybersecurity News

IDScan confirms breach tied to 153 million stolen driver’s licenses

Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans. [...]

Read Original
BleepingComputerCybersecurity NewsCritical

New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. [...]

Read Original
BleepingComputerCybersecurity News

The Top 4 Threats We Found by Investigating Every Alert for a Quarter

Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked. [...]

Read Original
BleepingComputerCybersecurity News

Microsoft says September updates fix mouse settings reset issues

Microsoft has fixed a known issue that wiped mouse settings on some Windows 11 systems after installing the KB5120998 August 2026 preview update. [...]

Read Original

Share This Digest