SECURITY Affairs published its 594th weekly newsletter on 13 September 2026, presenting a selection of the site’s recent cybersecurity reporting alongside links to international coverage. The main selection spans artificial intelligence security, ransomware, vulnerability exploitation, malware, data breaches and cybercrime.
Featured reports include attacks involving a critical Cisco Secure Firewall Management Center flaw and a SonicWall vulnerability, additions to the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalogue, an actively exploited Chrome zero-day, and Microsoft’s September 2026 update covering 974 CVEs, two zero-days and 20 wormable bugs.
The newsletter also highlights reports about a fileless Linux rootkit targeting F5 BIG-IP APM Server memory, a WeChat account-hijacking worm, exposed passport and flight data in a Vietnam-linked API database, a North Korea-linked backdoor hidden in HAProxy, and an alleged breach involving 32.8 million Condé Nast user records.
Its international press section links to external reporting on Berlin’s response to published stolen data, IT help-desk vishing and residential-proxy abuse, active exploitation of MikroTik RouterOS and Artifactory vulnerabilities including CVE-2026-42016, CVE-2026-42018 and CVE-2026-82329, as well as state-linked activity involving Chrome and Windows zero-days.
The newsletter is a roundup rather than a single incident report, and the supplied article does not provide additional technical detail or response guidance for the individual stories.