grc-scanSecurity & governance
News digest8 September 2026Archived edition

Cybersecurity News

This edition was published on 8 September 2026 and is kept here unchanged as a record. The threats and cases it describes may have moved on — read the latest digest for the current picture.

The takeaway

This edition's five stories show defences failing in the gap after they're supposedly in place — a patch not yet installed, a login already stolen, a ransom refused but the data gone regardless.

  • Patch or mitigate internet-facing systems — remote-access gateways, online stores, browsers — the same week a fix or workaround appears.
  • Don't treat MFA as the finish line: train staff to spot phishing that steals a session after login, not just a password.
  • Keep offline backups and a recovery plan separate from any ransom decision, since stolen data can surface either way.

Cybersecurity News — 2026-09-08

Generated: 2026-09-08 | Sources: BleepingComputer, The Hacker News, Help Net Security, SecurityWeek, Rapid7, Sansec, SOC Prime, IT Security Guru, Huntress, Cybernews, Infosecurity Magazine


1. A Widely Used Remote-Access Gateway Is Being Broken Into by Attackers Who Skip the Login Screen Entirely

Citrix NetScaler — an appliance many businesses put at the edge of their network so staff can work remotely or connect via VPN — has a critical flaw (CVE-2026-19490) that lets an attacker walk straight past the login screen with no account or password at all, on devices set up as a remote-access gateway. Citrix published a fix back on 19 August, but this week brought reports that criminals are now actively scanning for and breaking into unpatched devices after working attack code was published, prompting Belgium's national cyber centre to issue a public warning urging administrators to patch immediately.

Why it matters for your business: if your business or IT provider uses a Citrix NetScaler Gateway for remote access or VPN, confirm today that it's on version 14.1-73.32, 13.1-63.21, or later. This is precisely the kind of device attackers can reach without any credentials, which makes it worth checking ahead of software that merely needs a password guessed.


2. Every Online Store Built on Magento or Adobe Commerce Is Exposed to an Attack With No Official Fix Yet

Researchers this week disclosed a flaw nicknamed "StyleSmuggler" affecting every current version of Magento and Adobe Commerce — the software behind a large share of small and mid-size online shops — and say it's already being used to plant a hidden backdoor on live stores. It works by hiding malicious code inside the store's own template styling settings, then triggering that code to run via an ordinary failed-payment email, so no password, login, or plugin bug is needed. As of this week Adobe has not issued an official patch or CVE advisory, though the firm that discovered the flaw, Sansec, has published a hotfix.

Why it matters for your business: if your online shop runs Magento or Adobe Commerce, don't wait for Adobe's own fix — ask whoever manages your site to apply Sansec's hotfix now and check for unfamiliar admin accounts or files, because "no login required" means an attacker needs nothing from you or your customers to get in.


3. Google Rushed Out a Chrome Fix After Attackers Found a Way to Run Code From a Web Page Alone

Google issued an emergency Chrome update this week after confirming a flaw in V8 — the engine that runs the JavaScript behind most websites — was already being exploited: simply loading a booby-trapped page could let an attacker run their own code on a visitor's computer. It's the sixth time this year Google has had to patch a Chrome bug already under active attack, and the fix shipped within days of the flaw being found.

Why it matters for your business: Chrome usually updates itself quietly in the background, but the fix only takes effect once the browser restarts — so close and reopen Chrome (or restart the computer) rather than assuming a silent update is already protecting you, and do the same for Edge and any other Chromium-based browser your business uses.


4. A New Phishing Kit Steals the Login Session Itself, So Multi-Factor Authentication Never Gets a Chance to Stop It

Researchers uncovered a phishing-as-a-service kit called "Knight Office" being used to break into Microsoft 365 and Google Workspace accounts by stealing an already-logged-in session rather than a password. A victim gets a DocuSign-style email, clicks through a chain of redirects — some via well-known services like Monday.com or a hacked website — signs in and completes multi-factor authentication exactly as normal, and the kit quietly captures the resulting session token: a live, already-verified login the attacker can reuse without ever needing a password or MFA code of their own. It's been running since at least April, with over 700 matching phishing emails reported so far.

Why it matters for your business: multi-factor authentication is still essential, but this is why it isn't the whole answer — train staff to be wary of "document ready to sign" emails they weren't expecting, especially ones that bounce through several unfamiliar links before asking for a login, and if your Microsoft 365 or Google Workspace plan supports it, turn on sign-in alerts so an unexpected session is caught quickly.


5. Berlin Refused to Pay a Ransom Demand — and the Stolen Data Was Published Anyway

The ransomware group Rhysida followed through on its threat to publish stolen data after Germany's Berlin state government refused to pay a roughly €2m ransom by the gang's own deadline. Rhysida says it took 5.8 terabytes — around 1.4 million files, including contracts, staff records, and infrastructure security assessments — from Berlin's administrative network after a break-in first discovered in mid-August, and has since put the data up for sale and leaked samples publicly. Berlin says election systems were unaffected and that it never intended to pay.

Why it matters for your business: this is "double extortion" in practice — refusing to pay doesn't undo the theft, it only decides whether you also fund the criminals. The lesson holds either way: keep offline backups the attacker can't reach or encrypt, and decide separately, in advance, who makes the pay-or-not call and who runs recovery, rather than waiting on one decision to start the other.


Sources

Reading about a breach — could it happen to you?

Most of these stories start with something an attacker can see from the outside: an exposed service, a spoofable domain, weak encryption. You can check your own domain for the same things in about a minute — free, no login, nothing intrusive.

Summaries are compiled from public threat-intelligence feeds and security news sources. This digest is for awareness purposes only and does not constitute professional security advice.