CISA and five international cybersecurity agencies published technical guidance documenting 17 techniques hackers use to compromise Microsoft Active Directory environments, exploiting identity configurations, legacy protocols, and certificate services to escalate privileges and establish persistence in enterprise networks.
Google confirmed that a limited number of Pixel phones were exploited through CVE-2026-58704, a modem vulnerability allowing remote privilege escalation without user interaction. The flaw was patched in Google's September 2026 security update, which addressed over 200 vulnerabilities total.
Google patched a high-severity privilege escalation flaw (CVE-2026-58704) in its Pixel Cellular Modem that shows signs of limited targeted exploitation. The vulnerability allows remote privilege escalation without user interaction and can be exploited in zero-click attacks. Google also released patches for 109 other security flaws in September 2026, with CISA adding the modem flaw to its Known Exploited Vulnerabilities catalog.
Google confirmed that a limited number of Pixel phones were exploited through CVE-2026-58704, a modem vulnerability allowing remote privilege escalation without user interaction. The flaw was patched in September 2026 security update and CISA designated it a known exploited vulnerability used in targeted attacks.
CISA warned that hackers are actively exploiting a maximum-severity GitLab vulnerability (CVE-2026-85706) that allows unauthenticated attackers to read credentials and sensitive data. GitLab released patches on Thursday, and CISA added the flaw to its catalog of exploited vulnerabilities, requiring federal agencies to patch within three days.
U.S. intelligence agencies reported Tuesday that top Chinese AI companies have systematically copied advanced American AI models like Claude, ChatGPT, Gemini, and Grok since 2024 through a practice called distillation. The FBI, NSA, and CISA identified six Chinese developers—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—as conducting large-scale distillation campaigns likely with Chinese government awareness. China's Foreign Ministry rejected the accusations, stating its AI development reflects technological self-reliance and called for cooperation rather than confrontation.
Windows administrators are experiencing widespread Remote Desktop Services freezes following Microsoft's September 2026 Patch Tuesday updates for Server 2019, 2022, and 2025. The bug, triggered by session disconnects, causes RDP connections to hang and prevents new logins, with kernel-level analysis pointing to a deadlock in RDPSERVERBASE!WDLIB_Close. Organizations face a dilemma: rolling back restores stability but removes critical security patches including fixes for actively exploited zero-days.
GitLab urged users to immediately patch a maximum-severity path traversal vulnerability (CVE-2026-85706) in its repository commits API that allows unauthenticated attackers to read arbitrary data from vulnerable servers. Cybersecurity firm watchTowr reported that attackers are already probing for unpatched GitLab instances. The company also patched a second critical deserialization vulnerability (CVE-2026-87719) affecting GitLab Enterprise Edition.