SecBriefs
SECBRIEFS TREND RADAR

What the cyber world is sharing. Without confusing noise for fact.

A compact daily signal layer built from public engagement, major incident coverage and direct-source checks. Social momentum helps rank the stories; SecBriefs confidence labels show what is confirmed, developing or still unverified.

REPORT DATE2026-09-09
WINDOWLast 24 hours, maximum approximately 36 hours for still-trending stories

Trend Score v1. 10 ranked feed candidates reviewed; 9 qualified; 1 stale item excluded; 0 incident merges; 0 selected-link validation failures. Raw engagement was unavailable in the feed, so engagement contribution is 0 for all items. Engagement figures are snapshot values from the incoming Trend Radar feed and may change after capture.

ARCHIVE

Trend Radar calendar

Days with published Trend Radar data are selectable.

September 2026
MONTUEWEDTHUFRISATSUN123456789101112131415161718192021222324252627282930
1
VulnerabilityVERIFIEDTREND 63 · EMERGING

Microsoft September 2026 Patch Tuesday fixes a record number of vulnerabilities, including two exploited zero-days

Microsoft released its September security updates with a record patch volume and two Windows privilege-escalation flaws confirmed exploited in the wild. Major security coverage counts 974 CVEs, while some outlets count flaws differently; the core confirmed signal is the record release and two exploited zero-days.

Why trending: Record patch volume plus confirmed exploitation makes this the day’s broadest enterprise patching signal.

Microsoft advisories, CISA KEV and multiple major security publications circulating
Open details
VulnerabilityVERIFIEDTREND 63 · EMERGING
TREND RADAR #1 · 2026-09-08

Microsoft September 2026 Patch Tuesday fixes a record number of vulnerabilities, including two exploited zero-days

Microsoft released its September security updates with a record patch volume and two Windows privilege-escalation flaws confirmed exploited in the wild. Major security coverage counts 974 CVEs, while some outlets count flaws differently; the core confirmed signal is the record release and two exploited zero-days.

WHY TRENDING

Record patch volume plus confirmed exploitation makes this the day’s broadest enterprise patching signal.

Microsoft advisories, CISA KEV and multiple major security publicationsCIRCULATING

Source: SecurityWeek

2
CryptocurrencyVERIFIEDTREND 60 · EMERGING

Liquid Network exploit drains about $320M in Bitcoin; most funds later returned

About 4,000 BTC were withdrawn from the Liquid Network federation wallet after a software flaw. Subsequent reporting and blockchain analysis documented the return of roughly 3,400 BTC, with the network still paused and a material shortfall remaining.

Why trending: The enormous financial impact plus the unusual partial return of funds kept the incident highly relevant through the reporting window.

Liquid/Blockstream statements, Reuters, TRM Labs and multiple crypto/security outlets circulating
Open details
CryptocurrencyVERIFIEDTREND 60 · EMERGING
TREND RADAR #2 · 2026-09-06

Liquid Network exploit drains about $320M in Bitcoin; most funds later returned

About 4,000 BTC were withdrawn from the Liquid Network federation wallet after a software flaw. Subsequent reporting and blockchain analysis documented the return of roughly 3,400 BTC, with the network still paused and a material shortfall remaining.

WHY TRENDING

The enormous financial impact plus the unusual partial return of funds kept the incident highly relevant through the reporting window.

Liquid/Blockstream statements, Reuters, TRM Labs and multiple crypto/security outletsCIRCULATING

Source: Reuters

3
Zero-DayVERIFIEDTREND 58 · EMERGING

Adobe patches actively exploited Magento/Commerce zero-day CVE-2026-75650

Adobe released an emergency fix for CVE-2026-75650, a CVSS 10.0 unauthenticated arbitrary-code-execution flaw in Adobe Commerce and Magento Open Source, and confirmed exploitation in the wild.

Why trending: A maximum-severity unauthenticated RCE under active exploitation creates immediate risk for widely deployed e-commerce systems.

Adobe advisory, Sansec, CISA and major security publications circulating
Open details
Zero-DayVERIFIEDTREND 58 · EMERGING
TREND RADAR #3 · 2026-09-07

Adobe patches actively exploited Magento/Commerce zero-day CVE-2026-75650

Adobe released an emergency fix for CVE-2026-75650, a CVSS 10.0 unauthenticated arbitrary-code-execution flaw in Adobe Commerce and Magento Open Source, and confirmed exploitation in the wild.

WHY TRENDING

A maximum-severity unauthenticated RCE under active exploitation creates immediate risk for widely deployed e-commerce systems.

Adobe advisory, Sansec, CISA and major security publicationsCIRCULATING

Source: Adobe

4
VulnerabilityVERIFIEDTREND 58 · EMERGING

SAP patches maximum-severity OVERPASS kernel vulnerability

SAP’s September Patch Day fixed CVE-2026-44756, a CVSS 10.0 memory-corruption vulnerability in Extended Passport processing that can enable unauthenticated remote command execution and compromise sensitive SAP data.

Why trending: The flaw affects core enterprise SAP infrastructure and carries maximum severity with remote unauthenticated impact.

SAP advisory, Onapsis research and major security publications circulating
Open details
VulnerabilityVERIFIEDTREND 58 · EMERGING
TREND RADAR #4 · 2026-09-08

SAP patches maximum-severity OVERPASS kernel vulnerability

SAP’s September Patch Day fixed CVE-2026-44756, a CVSS 10.0 memory-corruption vulnerability in Extended Passport processing that can enable unauthenticated remote command execution and compromise sensitive SAP data.

WHY TRENDING

The flaw affects core enterprise SAP infrastructure and carries maximum severity with remote unauthenticated impact.

SAP advisory, Onapsis research and major security publicationsCIRCULATING

Source: SAP

5
FraudVERIFIEDTREND 57 · EMERGING

DoppelCart network uses about 119,000 fake shops to steal payment-card data

Nebty documented a cluster of roughly 119,000 fake-shop domains that impersonate legitimate brands and collect payment-card and customer data during checkout. More than 105,000 shops were reported active in recent scans.

Why trending: The exceptional scale makes DoppelCart a major payment-fraud and brand-abuse signal.

Nebty investigation and BleepingComputer coverage circulating
Open details
FraudVERIFIEDTREND 57 · EMERGING
TREND RADAR #5 · 2026-09-08

DoppelCart network uses about 119,000 fake shops to steal payment-card data

Nebty documented a cluster of roughly 119,000 fake-shop domains that impersonate legitimate brands and collect payment-card and customer data during checkout. More than 105,000 shops were reported active in recent scans.

WHY TRENDING

The exceptional scale makes DoppelCart a major payment-fraud and brand-abuse signal.

Nebty investigation and BleepingComputer coverageCIRCULATING

Source: Nebty

6
CyberattackVERIFIEDTREND 53 · EMERGING

Active FortiGate exploitation delivers custom PivotC2 Node.js RAT

SOCRadar reported high-confidence active exploitation of CVE-2025-25249 against FortiGate devices, delivering a purpose-built Node.js RAT called PivotC2. The research identified more than 30,000 targeted IPs and 178 confirmed infected devices.

Why trending: Ongoing exploitation of widely deployed perimeter devices with a specialized post-exploitation tool is highly relevant to enterprise defenders.

SOCRadar research and independent cybersecurity coverage circulating
Open details
CyberattackVERIFIEDTREND 53 · EMERGING
TREND RADAR #6 · 2026-09-08

Active FortiGate exploitation delivers custom PivotC2 Node.js RAT

SOCRadar reported high-confidence active exploitation of CVE-2025-25249 against FortiGate devices, delivering a purpose-built Node.js RAT called PivotC2. The research identified more than 30,000 targeted IPs and 178 confirmed infected devices.

WHY TRENDING

Ongoing exploitation of widely deployed perimeter devices with a specialized post-exploitation tool is highly relevant to enterprise defenders.

SOCRadar research and independent cybersecurity coverageCIRCULATING

Source: SOCRadar

7
Data BreachUNVERIFIEDTREND 50 · EMERGING

ShinyHunters claims breach of Florida DAVID DMV database affecting 200,000+ records

ShinyHunters claims it accessed Florida’s DAVID driver database and stole more than 200,000 records, publishing a sample record as purported proof. BleepingComputer reported the claim, but no agency confirmation was available at publication time.

Why trending: The claim concerns sensitive government identity data and has substantial media attention, but remains explicitly unconfirmed.

Threat-actor claim plus multiple independent news reports; no official confirmation circulating
Open details
Data BreachUNVERIFIEDTREND 50 · EMERGING
TREND RADAR #7 · 2026-09-07

ShinyHunters claims breach of Florida DAVID DMV database affecting 200,000+ records

ShinyHunters claims it accessed Florida’s DAVID driver database and stole more than 200,000 records, publishing a sample record as purported proof. BleepingComputer reported the claim, but no agency confirmation was available at publication time.

WHY TRENDING

The claim concerns sensitive government identity data and has substantial media attention, but remains explicitly unconfirmed.

Threat-actor claim plus multiple independent news reports; no official confirmationCIRCULATING

Source: BleepingComputer

8
PhishingVERIFIEDTREND 49 · WATCH

BigBear 2.0 phishing service bypasses Microsoft 365 MFA at hundreds of organizations

CloudSEK’s investigation of the BigBear 2.0 Evilginx2-based phishing service found 5,137 credential records, 4,148 session cookies and 1,032 plaintext passwords. BleepingComputer reported that 258 organizations had at least one completed MFA-bypass compromise.

Why trending: The campaign provides unusually detailed evidence of real-world adversary-in-the-middle phishing and Microsoft 365 session hijacking.

CloudSEK research plus several independent security publications circulating
Open details
PhishingVERIFIEDTREND 49 · WATCH
TREND RADAR #8 · 2026-09-07

BigBear 2.0 phishing service bypasses Microsoft 365 MFA at hundreds of organizations

CloudSEK’s investigation of the BigBear 2.0 Evilginx2-based phishing service found 5,137 credential records, 4,148 session cookies and 1,032 plaintext passwords. BleepingComputer reported that 258 organizations had at least one completed MFA-bypass compromise.

WHY TRENDING

The campaign provides unusually detailed evidence of real-world adversary-in-the-middle phishing and Microsoft 365 session hijacking.

CloudSEK research plus several independent security publicationsCIRCULATING

Source: CloudSEK

9
VulnerabilityNOT A CYBER INCIDENTTREND 42 · WATCH

Researchers demonstrate zero-click WeChat worm spreading through incoming calls

Calif demonstrated WeWorm, a zero-click proof of concept that can take over a WeChat account through an incoming call and spread to contacts on iOS and Android. The flaw was reported to Tencent and the exploit path has been blocked; no attacks using the technique were reported.

Why trending: The research is technically significant because of WeChat’s scale, but it is a demonstration rather than a confirmed in-the-wild cyber incident.

Calif research demonstration and The Hacker News coverage circulating
Open details
VulnerabilityNOT A CYBER INCIDENTTREND 42 · WATCH
TREND RADAR #9 · 2026-09-08

Researchers demonstrate zero-click WeChat worm spreading through incoming calls

Calif demonstrated WeWorm, a zero-click proof of concept that can take over a WeChat account through an incoming call and spread to contacts on iOS and Android. The flaw was reported to Tencent and the exploit path has been blocked; no attacks using the technique were reported.

WHY TRENDING

The research is technically significant because of WeChat’s scale, but it is a demonstration rather than a confirmed in-the-wild cyber incident.

Calif research demonstration and The Hacker News coverageCIRCULATING

Source: Calif

SECBRIEFS MEMBERSHIP

Get the signal, not the noise.

Join the free SecBriefs briefing for concise cybersecurity intelligence, Trend Radar signals and practical context.