Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
Bitdefender found abuse of Google Play's review-free Early Access program to push thousands of deceptive casino and reward apps promoted with AI deepfake ads.
Bitdefender reports threat actors are abusing Google Play's Early Access program, which blocks public reviews and ratings, to distribute thousands of deceptive casino, reward, and utility apps. A GTA imitator, 'Vice Streets: Open World,' surpassed 1 million downloads before disappearing, with apps promoted via AI celebrity deepfake ads on TikTok and Facebook and monetized through endless ad serving and payouts that never arrive. The report coincides with disclosures on Android malware families Hagaseca, Mantax Otax, StreamRat, and GoldFactory's Gigabud banking trojan with its Vwork companion app used for cloned-app financial fraud.
September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor
Microsoft's September 2026 Patch Tuesday delivers a record patch count, fixing two exploited zero-days and a wormable DNS flaw dubbed a SigRed successor.
Microsoft's September 2026 Patch Tuesday sets another record patch count, fixing two vulnerabilities exploited as zero-days: CVE-2026-81963, a Windows Update Stack low-privilege-to-SYSTEM escalation reported by MSTIC, and CVE-2026-85880, a Windows Advanced Local Procedure Call escalation reported by Proofpoint. Zero Day Initiative's Dustin Childs urges priority on a cluster of 20 potentially wormable bugs including DNS RCE CVE-2026-69730, described as a spiritual successor to SigRed, plus Kerberos authentication bypass CVE-2026-69676 that could give any authenticated domain user RCE on domain controllers, and Exchange RCE CVE-2026-55007 via a malicious Visio attachment. All Windows fixes are bundled in cumulative updates, and experts stress prioritizing exploitable, reachable flaws over raw patch counts.
September 2026 Patch Tuesday roundup: Plugs for two zero day holes among almost 1,000 fixes in Windows
Microsoft's September 2026 Patch Tuesday ships 964 fixes including two exploited Windows zero-days (CVE-2026-85880, CVE-2026-81963) and a wormable DNS RCE.
Microsoft's September 2026 Patch Tuesday includes 964 Microsoft vulnerabilities requiring customer action, a record attributed to AI-assisted bug discovery, plus 174 third-party/open-source and 23 Chromium/Edge CVEs. Two zero-days are exploited in the wild: CVE-2026-85880, a Windows ALPC heap overflow enabling AppContainer sandbox escape and privilege escalation, and CVE-2026-81963, a Windows Update Stack escalation to SYSTEM. CVE-2026-69730, an unauthenticated Windows DNS RCE, is not yet exploited but Microsoft expects exploitation, and roughly 20 bugs could be wormable. Separately, SAP issued a critical CVSS 10.0 fix for the EPP component used in S/4HANA and NetWeaver.
Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
Microsoft's September 2026 Patch Tuesday fixes a record 974 CVEs, including two Windows zero-days exploited in the wild for privilege escalation.
Microsoft patched 974 vulnerabilities, its largest Patch Tuesday ever, including CVE-2026-85880, a heap buffer overflow in Windows ALPC allowing AppContainer sandbox escape to System, and CVE-2026-81963, a link-following flaw in the Windows Update Stack enabling local privilege escalation. Both were exploited as zero-days before the patch. ZDI's Dustin Childs says 20 of the fixed flaws are wormable, enabling unauthenticated remote code execution. The release also covers 723 Windows flaws and 222 Office bugs, plus fixes in Exchange, SharePoint, SQL Server, Azure and Exchange Server RCE (CVE-2026-55007).
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
DFIR Report exposes BengalSEO, an India-based SEO-poisoning operation running since 2015, delivering MayaBot malware and tech support scams via Bing results.
The DFIR Report details BengalSEO, a financially motivated cluster operating from Rajasthan, India, since at least 2015, run through two IT service providers: WeConnect Solutions LLC and Garage2Global. The group uses black-hat SEO techniques—backlinks, DOM injection, DOM shuffling, keyword stuffing—to push lure pages to the top of Microsoft Bing results, routing victims through a traffic distribution system to either the custom MayaBot malware (which delivers an XMRig cryptominer and enables C2) or tech support scam call centers. A Vizio decoy page had 2,000 backlinks from 167 unique external domains, and Matomo analytics is used for victim fingerprinting, with the tracking domain appearing in 1,112 urlscan.io results.
Indian man who fled US arrested on charges he helped scammers siphon $7.5 million from the elderly
US prosecutors charged Indian national Jay Goswami as a money mule who collected $7.5 million from nine elderly scam victims, now facing extradition from Canada.
US prosecutors charged 21-year-old Indian national Jay Sunilbharthi Goswami with wire fraud and money laundering for working as a money mule for India-based scammers. The scammers posed as law enforcement or government officials by phone and email, convincing at least nine elderly victims in New York and New Jersey to hand over $7,559,185 in cash, gold bars, and gift cards. Goswami collected the money and shipped it to India, allegedly earning about $90,000 while on a student visa at Fairleigh Dickinson University. After fleeing to Canada across the Peace Bridge, he was arrested at Toronto's airport and is awaiting extradition to the US.
Cyberattack on logistics giant Ceva hits retailers and Steam customers across Europe
Cyberattack on Ceva Logistics disrupted eight European warehouses, delaying shipments for Bol, De Bijenkorf, Ajax and exposing Steam hardware buyers' data.
A cyberattack on Ceva Logistics disrupted operations at eight European warehouses, delaying shipments for Bol, De Bijenkorf, Ace & Tate, Ajax and Steam hardware customers. Attackers accessed two Ceva systems processing Bol orders, potentially exposing names, addresses, phone numbers, email addresses and order details. Valve began notifying European Steam customers whose hardware shipping data may have been compromised and is contacting data protection authorities. Ceva, with about 110,000 employees and over 1,700 facilities, has not disclosed the attackers or whether ransomware was involved.
Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak
A 32.8 million-record Conde Nast user database is offered for $15,000 on a Russian cybercrime forum, extending December's WIRED leak with millions of unseen records.
A database of 32,815,767 Conde Nast user records went on sale on 7 September 2026 for $15,000 on a Russian-language forum, containing names, addresses, birth dates and phone numbers but no passwords or payment data. Ransomnews verified a 5,000-record sample as genuine account data collected between September and late October 2025, with roughly 30.5 million non-WIRED records never previously published. The listing matches the December 2025 WIRED leak of 2,366,576 records, claimed by an actor called 'Lovely' who said 40+ million records were stolen via IDOR and broken access controls. Conde Nast has not confirmed the breach; exposed data enables credible targeted phishing and fraud.