This cybersecurity brief for September 8, 2026, covers a surge in actively exploited zero-day vulnerabilities affecting critical enterprise software. Adobe Commerce, N-able N-central, and MikroTik RouterOS are all under attack from unauthenticated remote code execution flaws, prompting emergency patches. Additionally, a new local privilege escalation zero-day in CrowdStrike's Falcon Sensor has been publicly disclosed. Threat actors continue to evolve, with a North Korean group backdooring HAProxy source code and sophisticated phishing campaigns using vishing and adversary-in-the-middle techniques to bypass MFA and steal Microsoft 365 session tokens. A new report also highlights how fragmented federal incident reporting rules are hampering response efforts in the U.S.
Help others stay informed about cybersecurity threats
Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.
Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.
Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.