Daily Digest

Multiple Critical Zero-Days Under Active Exploitation; Phishing Campaigns Bypass MFA

September 8, 2026
7 articles (3 new, 4 updated)
21 min read

Summary

This cybersecurity brief for September 8, 2026, covers a surge in actively exploited zero-day vulnerabilities affecting critical enterprise software. Adobe Commerce, N-able N-central, and MikroTik RouterOS are all under attack from unauthenticated remote code execution flaws, prompting emergency patches. Additionally, a new local privilege escalation zero-day in CrowdStrike's Falcon Sensor has been publicly disclosed. Threat actors continue to evolve, with a North Korean group backdooring HAProxy source code and sophisticated phishing campaigns using vishing and adversary-in-the-middle techniques to bypass MFA and steal Microsoft 365 session tokens. A new report also highlights how fragmented federal incident reporting rules are hampering response efforts in the U.S.

Filter by Category

New Articles (3)

Updated Articles (4)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.