
BigDiskBuster Zero-Day Blocks Defender Updates, No Patch Issued
Researcher Abdelhamid Naceri published BigDiskBuster proof-of-concept on September 19, preventing Microsoft Defender updates by filling disk space. No patch available.

Researcher Abdelhamid Naceri published BigDiskBuster proof-of-concept on September 19, preventing Microsoft Defender updates by filling disk space. No patch available.

CVE-2026-93952 (CVSS 10.0) in on-premises VeloCloud Orchestrator under active exploit. Unauthenticated attackers access privileged internal functions.

CVE-2026-89775 in Linux kernel KVM for ARM64 processors exposes freed host memory to guest VMs, enabling guest-to-host privilege escalation when

CVE-2026-65660, initially classified by Microsoft as spoofing with CVSS 6.5, enables authenticated remote code execution on SharePoint Server per researcher

indexed-btree npm package hides malicious behavior in application runtime code instead of lifecycle scripts, evading npm security controls, per Checkmarx

SideCopy threat actor expanded targeting from Indian government to academic institutions using spear-phishing with ReverseRAT and mshta.exe abuse, per Trellix

Researcher Patrick Wardle published proof-of-concept on September 21 showing malware can hijack Meta Muse AI assistant by changing a hidden

WordPress patched CVE-2026-93485 (Comment2Shell) in version 7.1.1 on September 17, a flaw allowing anonymous comments to achieve RCE when viewed

Fake LastPass Authenticator installer distributed via GitHub installs Microsoft-signed kernel driver to disable antivirus and EDR before deploying password stealer.

CVE-2026-89026 in Issabel Framework under active exploitation allows unauthenticated attackers to execute arbitrary OS commands remotely via hard-coded credentials.
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.