View all sources for this day →

The Signal

This edition prioritizes events with demonstrated paths to account control, elevated access, or targeted compromise, while retaining fraud as a separate victim-facing risk. The remaining items provide operational context on patching, AI-model extraction, and agent authorization without implying a shared mechanism. [1][2][3][4][5][6][7]

Must Know

Exploitation · Theregister Security

Exploitation · Vulnerability

What happened

Tencent patched a zero-click WeChat VoIP memory-corruption vulnerability that researchers used to demonstrate a worm spreading through calls on iOS and Android. [1]

In the demonstration, the exploit took control of a victim’s WeChat account within seconds without the recipient answering; the compromised account then called another contact and repeated the process without user interaction. [1]

Why it matters

The researchers said exploitation required the attacker to be on the victim’s friends list and provided full control of the WeChat account, including reading and sending messages and making calls. [1]

Identity · Cyberscoop

Exploitation · Identity

What happened

Proofpoint researchers reported that at least four state-aligned threat groups chained three zero-day vulnerabilities against targets of interest to China’s government since late August. [2]

The BlueMoon exploit chain targets Chrome, Chromium-based browsers and Microsoft Windows; it can run code in the browser sandbox, escape it and gain system privileges. [2]

Why it matters

Proofpoint directly observed fewer than 20 organizations targeted globally, while its researcher assessed that the true number of impacted organizations was likely higher. [2]

Exploitation · Securityaffairs

Exploitation · Vulnerability

What happened

Researcher Chaotic Eclipse released ShieldCrash, a proof-of-concept exploit targeting a Microsoft Defender zero-day vulnerability, CVE-2026-69414, referred to as ShieldBreak. [3]

The published PoC demonstrates arbitrary file reading with SYSTEM privileges; the researcher describes it as a basic version and says it currently publishes only enough code to show the patch does not completely block the issue. [3]

Why it matters

The researcher claims Microsoft closed several exploitation paths but missed a specific condition that still permits the same attack, and says all supported Windows versions remain affected after the September 2026 updates. [3]

Identity · Malwarebytes Labs

Identity · Research

What happened

Nebty identified DoppelCart, a cluster of 118,787 .shop domains linked by shared website and infrastructure characteristics; the researchers described it as the largest publicly documented fake-shop network by associated domain count. [4]

The operation copies legitimate retailers’ catalogs, descriptions, branding, and images, and the fake shops mimic more than 44,000 brands; 96% of confirmed shops reportedly shared identical build files and used 27 ecommerce backends. [4]

Why it matters

Fraudulent checkout pages collect card numbers, expiry dates, CVVs, billing information, and potentially bank-issued one-time confirmation codes, transmitting the data to attacker-controlled servers over WebSockets in real time. [4]

Also Worth Knowing

Exploitation · The Hacker News

Vulnerability · Exploitation

What happened

Microsoft addressed 974 vulnerabilities across its software portfolio in the referenced Patch Tuesday release, including two flaws it said were actively exploited in the wild. [5]

AI & Agents · Securityaffairs

AI & Agents · Policy

What happened

NSA, CISA, and the FBI jointly published an advisory accusing six Chinese AI companies of industrial-scale extraction campaigns against U.S. frontier models since at least late 2024. [6]

AI & Agents · Helpnetsecurity

AI & Agents · Identity

What happened

Akeyless announced general availability of Akeyless Agentic Runtime Authority, described as a real-time identity control layer for AI-agent actions. [7]

Sources (7)
  1. [1] WeChat worm could pwn a friend before they even answered the call

    theregister security · September 9, 2026

  2. [2] Chinese espionage groups swarm to exploit triple-link chain of zero-days

    cyberscoop · September 9, 2026

  3. [3] Chaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-Day

    securityaffairs · September 9, 2026

  4. [4] More than 100,000 fake stores are out to steal your card details

    malwarebytes labs · September 9, 2026

  5. [5] Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

    the hacker news · September 9, 2026

  6. [6] US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models

    securityaffairs · September 9, 2026

  7. [7] Akeyless adds real-time enforcement for AI agents in production

    helpnetsecurity · September 9, 2026