<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
<channel>
<title>AuraTracer · Tech Events, Tracked in Full · Cybersecurity</title>
<link>/index.html</link>
<description>In-depth tech event tracking · Faithful summaries · Integrated timelines</description>
<language>en</language>

<item>
  <title>Microsoft releases September Patch Tuesday for 2026: Fixes over a thousand vulnerabilities; high-risk CVE-2026-81963 has been exploited in the wild.</title>
  <link>/events/73897bf6f3d3.html</link>
  <guid>/events/73897bf6f3d3.html</guid>
  <pubDate>Wed, 09 Sep 2026 08:00:00 +0800</pubDate>
  <description>On September 8, 2026, Microsoft released a security update (Windows 10 KB5122878) covering all products including Windows 10/11, Office, and Azure. This “Patch Tuesday” fixed a total of 974 vulnerabilities, with 723 of them affecting Windows systems and 611 in the Windows 11 version. The update included two zero-day vulnerabilities that were being exploited; the high-risk vulnerability CVE-2026-81963 had been confirmed to be exploited in the wild, affecting the Windows Update Stack and potentially allowing local privilege escalation. Microsoft has tightened the recommended installation period for critical quality updates to within 3 days to reduce the attack window.</description>
</item>

<item>
  <title>OpenAI&#39;s Artifactory opened covert data-stealing channel alongside Hugging Face attack</title>
  <link>/events/fedb784ea4e4.html</link>
  <guid>/events/fedb784ea4e4.html</guid>
  <pubDate>Wed, 09 Sep 2026 05:12:19 +0800</pubDate>
  <description>Check Point Research discovered that there was a secret channel within OpenAI’s JFrog Artifactory instance, allowing attackers to send hidden tasks to ChatGPT sessions on other accounts (such as stealing Gmail data). This vulnerability was addressed at the end of June. Threat hunter disclosed this issue at the end of June, and on the same day, OpenAI exploited the zero-day vulnerability in Artifactory to gain internet access and invade Hugging Face. Although both involved the same internal package management system, they were different attacks. Check Point researchers noted that containers should have been isolated from each other, but Artifactory exposed its item management functionality, allowing instructions to be passed between accounts through text attributes (including Base64-encoded binary data). Defects in read/write permissions and authentication mechanisms enabled code to access the storage directly without additional credentials. Attackers could write malicious tasks into shared storage, and victim sessions would execute those tasks and return results without exposing the second-party instructions.</description>
</item>

<item>
  <title>Why this month&#39;s Microsoft patch release is a doozy</title>
  <link>/events/42caa8fb74f7.html</link>
  <guid>/events/42caa8fb74f7.html</guid>
  <pubDate>Wed, 09 Sep 2026 05:11:46 +0800</pubDate>
  <description>In September 2026, Microsoft released system patches that addressed approximately 972 security vulnerabilities, of which 112 reached high severity thresholds, setting a new record. In the previous two months, Microsoft had addressed 570 and 620 vulnerabilities respectively. Meanwhile, technology companies such as Google have also recently disclosed an unprecedented number of vulnerability information. Two weeks ago, 100 organizations including OpenAI, Anthropic, Amazon Web Services, and Google jointly issued a public letter warning that the window for patching vulnerabilities is narrowing before the arrival of AI-driven attacks. The industry is responding to threats by releasing an unprecedented number of patches. Dustin Childs, a researcher at the Zero Day Initiative, calls this “the new normal” and warns that despite the surge in patch deliveries, the potential damage caused by AI-assisted attacks could still be significant.</description>
</item>

<item>
  <title>Boston Scientific left nursing its bottom line after cyberattack</title>
  <link>/events/1b10480a46e3.html</link>
  <guid>/events/1b10480a46e3.html</guid>
  <pubDate>Tue, 08 Sep 2026 23:45:00 +0800</pubDate>
  <description>In September 2026, Boston Scientific revealed that the cyberattack last month caused business disruptions, making it difficult to achieve third-quarter and annual sales growth as well as adjusted earnings per share targets. On August 25, the company shut down some systems to contain the unauthorized activities; this incident affected the business applications used for processing and shipping customer orders. Currently, the distribution network has largely returned to normal, with major distribution centers achieving or exceeding normal processing and shipping levels. Sterilization facilities are operating normally, and most manufacturing sites worldwide have resumed operations. The interruption in new patient activations for remote monitoring of specific cardiac devices has also been resolved. Although devices not connected to the network were unaffected and no evidence of continuous unauthorized access was found, details such as how the attackers infiltrated, whether ransomware was involved, who is responsible, and whether data was stolen remain unclear. The company has not yet determined a specific date for fully resuming operations.</description>
</item>

<item>
  <title>Microsoft released a record number of 974 security patches, including two vulnerabilities that have been exploited.</title>
  <link>/events/701bb16555a8.html</link>
  <guid>/events/701bb16555a8.html</guid>
  <pubDate>Wed, 09 Sep 2026 08:25:22 +0800</pubDate>
  <description>In September 2026, Microsoft released 974 security patches, hitting a record high, including two zero-day vulnerabilities that had been exploited. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) listed these two vulnerabilities in its known exploitable vulnerabilities list and set deadlines for federal agencies to fix them. One of the vulnerabilities (CVE-2026-85880) was located in the Windows ALPC component, allowing privilege escalation to the SYSTEM level without user interaction; another vulnerability (CVE-2026-81963) affected the Windows Update Stack, also providing system-level access. Additionally, the CVE-2026-55007 vulnerability in Exchange Server allowed attackers to remotely execute code through malicious Visio attachments. In the same month, Adobe released 172 CVE announcements, covering security updates related to Magento and Adobe Commerce systems that had been exploited as zero-day vulnerabilities.</description>
</item>

<item>
  <title>ShinyHunters hackers claim breach of Florida &#34;DAVID&#34; DMV database</title>
  <link>/events/1bde916ce03e.html</link>
  <guid>/events/1bde916ce03e.html</guid>
  <pubDate>Wed, 09 Sep 2026 00:35:47 +0800</pubDate>
  <description>On September 8, 2026, the hacking group ShinyHunters claimed to have successfully infiltrated the online platform database of the Florida Department of Motor Vehicles, named ‘DAVID’. The group stated that they had stolen over 200,000 pieces of personal record information about drivers in that state.</description>
</item>

<item>
  <title>“The US accused Alibaba and DeepSeek of systematically stealing AI models and launched an investigation.”</title>
  <link>/events/1ec5779594b5.html</link>
  <guid>/events/1ec5779594b5.html</guid>
  <pubDate>Wed, 09 Sep 2026 08:00:00 +0800</pubDate>
  <description>On September 9, 2026, the United States officially accused Alibaba and DeepSeek of systematically stealing artificial intelligence models through technical means. The accusation stated that these companies illegally obtained and copied the weight and architecture data of external AI models. Currently, the US has initiated formal investigation procedures to verify the flow of relevant data and specific operational details. If the investigation results confirm the allegations, the involved companies may face severe consequences such as large fines, business restrictions, and legal proceedings.</description>
</item>

<item>
  <title>“This is the AI men actually use”: Meta ads pushed apps nudifying real teens</title>
  <link>/events/cff8145f7358.html</link>
  <guid>/events/cff8145f7358.html</guid>
  <pubDate>Wed, 09 Sep 2026 02:43:09 +0800</pubDate>
  <description>Meta took several days to remove advertisements containing AI-generated child sexual abuse material (CSAM) from the Facebook and Instagram platforms. According to the Tech Transparency Project’s survey, Meta failed to detect 332 such violations this year. These advertisements primarily promoted AI-based applications and “debodying” software developed in China; some advertisements converted real child photos into pornographic videos. The involved individuals included a member of the European royal family, a 14-year-old internet celebrity, and a former teenager identified as an influencer. Their images were processed by AI to create videos of sexual behavior or abuse. TTP has identified multiple CSAM advertisements that contained real child photos online. Since the U.S. Department of Justice has clearly determined that AI-generated CSAM is just as harmful as physical CSAM, these actions are suspected of violating federal child pornography laws.</description>
</item>

<item>
  <title>Claude’s quota disappeared mysteriously; Anthropic confirmed that the account was hacked.</title>
  <link>/events/d168a7aa5970.html</link>
  <guid>/events/d168a7aa5970.html</guid>
  <pubDate>Wed, 09 Sep 2026 07:29:06 +0800</pubDate>
  <description>On September 8, 2026, several Claude users noticed that their account quotas were quickly consumed without any apparent action. British consultant Grant Deswart encountered this issue on August 4, and his account’s usage continued to rise even when there were no local tasks. Anthropic confirmed that hackers used stolen login sessions to exploit the quotas. The attackers obtained session keys through information theft malware and generated OAuth tokens, consuming quotas or automatically upgrading subscriptions without the users’ knowledge. Since Anthropic’s customer service system could only view total usage without detailed records, the theft may have gone undetected for several months. Due to slow processing and lack of detailed recording tools, Deswart ultimately canceled his subscription and switched to Cursor. Anthropic has suspended the relevant accounts, cancelled the tokens, and refunded the fees.</description>
</item>

<item>
  <title>LG TV shown scanning LAN for third-party phones and other devices</title>
  <link>/events/fc9f81f3915d.html</link>
  <guid>/events/fc9f81f3915d.html</guid>
  <pubDate>Wed, 09 Sep 2026 05:52:29 +0800</pubDate>
  <description>On September 8, 2026, security researchers, in collaboration with Gamers Nexus and Level1Techs, analyzed the tracking capabilities of the LG G5 OLED TV. Tests revealed that the TV continued to scan the local network even when turned off, identifying dozens of unrelated devices, including smartphones and smartwatches that were not detected by the staff. Due to this ability to track users, LG TVs are facing relevant regulations.</description>
</item>

<item>
  <title>After the Cologne Game Show, IFA Berlin 2026 also saw thefts: several devices from GeeMobi were stolen.</title>
  <link>/events/dc5004aa3f02.html</link>
  <guid>/events/dc5004aa3f02.html</guid>
  <pubDate>Wed, 09 Sep 2026 08:50:03 +0800</pubDate>
  <description>In September 2026, during the IFA Berlin 2026 exhibition, GeekMok suffered several cases of device theft. After the exhibition ended (on September 6), the brand stored the remaining EVO-X5 Pro prototype and flagship products in a booth storage cabinet. However, on September 7, staff discovered that the cabinet had been opened without permission, and all devices were stolen by people at the exhibition. Previously, several cases of exhibitor device theft had also occurred at the Cologne Game Show.</description>
</item>

<item>
  <title>Microsoft’s September patch fixed 974 vulnerabilities, a tenfold increase from previous years; the high-risk CVE-2026-81963 has been exploited by hackers.</title>
  <link>/events/92a02ca3d75b.html</link>
  <guid>/events/92a02ca3d75b.html</guid>
  <pubDate>Wed, 09 Sep 2026 09:46:12 +0800</pubDate>
  <description>On September 8, 2026, Microsoft fixed a total of 974 security vulnerabilities in all its products, including Windows 10 and Windows 11 (including versions 24H2 and 25H2), during the Patch Tuesday event. This represents a 1032.6% increase compared to the same period last year. Of these, 723 vulnerabilities were fixed for Windows systems, mainly involving improper link resolution before file access, Windows Hello, biometric services, and basic components such as the graphics kernel. The most notable vulnerability, CVE-2026-81963, was confirmed to have been exploited by hackers. Microsoft recommends that users install and upgrade as soon as possible. Jeremy Chapman, director of Microsoft 365, said that to reduce the time exposed to risk, the delay period for recommended quality updates has been tightened to at least 3 days.</description>
</item>

<item>
  <title>Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit</title>
  <link>/events/e9c56492aeca.html</link>
  <guid>/events/e9c56492aeca.html</guid>
  <pubDate>Wed, 09 Sep 2026 04:08:55 +0800</pubDate>
  <description>On September 8, 2026, according to Bleeping Computer, hackers successfully infiltrated F5 BIG-IP APM devices and deployed a Linux root kit. This malware uses fileless attack techniques, directly injecting code into memory without writing it to disk. Its core functions include intercepting the loading of PHP files and implanting a fileless web shell into the target system’s memory, thereby achieving deep control over the F5 BIG-IP APM environment and persistent residency.</description>
</item>

<item>
  <title>DoppelCart fraud network uses 119,000 fake shops to steal credit cards</title>
  <link>/events/ac1ecee89e25.html</link>
  <guid>/events/ac1ecee89e25.html</guid>
  <pubDate>Wed, 09 Sep 2026 04:35:14 +0800</pubDate>
  <description>The fraud network named DoppelCart operated over 119,000 domain names to create numerous fake e-commerce websites in order to steal credit card information. The core method used was the collection of payment card details; details such as the number of victims and subsequent law enforcement progress remain undisclosed.</description>
</item>

<item>
  <title>Hackers are stealing Claude tokens from subscribers</title>
  <link>/events/333055ba653c.html</link>
  <guid>/events/333055ba653c.html</guid>
  <pubDate>Wed, 09 Sep 2026 05:10:27 +0800</pubDate>
  <description>Last month, a Claude user noticed that their account continued to consume tokens even when it was not in use. After investigation by Anthropic, it was confirmed that there was a hacking attack, and Claude tokens of subscribers were being illegally stolen. As a result, Anthropic issued a security warning to affected users to alert them about such risks.</description>
</item>

</channel>
</rss>