Cybersecurity · Wednesday, 9 September 2026
Microsoft fixed 974 security holes in one day. Two of them were already being used.
The biggest batch of software repairs ever shipped, because machines now hunt for flaws faster than people did. The hunting got faster; the fixing did not.
974
security flaws Microsoft repaired in a single day, its largest batch ever
the previous record, 570, was set by Microsoft two months earlier
2 of 974
are known to be under attack right now
the US cyber-defence agency gave federal offices until 22 September to fix those two
20
of the flaws spread from machine to machine on their own
Dustin Childs of the Zero Day Initiative said he stopped counting at twenty
22,000+
company email servers still open to attack code that is already public
counted by Nick Carroll of the security firm Nightwing
The lead story — what happened
-
Microsoft published fixes for at least 974 security flaws on Tuesday, by far the biggest single batch of repairs it has ever shipped.
[1] -
The old record was 570 flaws, set by Microsoft in July. Its running total for 2026 has now passed 2,600, more than double its worst previous year.
[1] -
Two of the flaws were already being used to attack people. Both let someone who has got into a Windows machine take full control of it.
[2] -
CISA, the US cyber-defence agency, confirmed those two are under attack and gave US federal agencies until 22 September to install them. It set no deadline for the other 972.
[4] -
One of the two sits inside the Windows update system itself. An attacker who owns the update system owns the tool you would use to throw them out, an Automox engineer said.
[4] -
About 113 of the flaws are rated critical, meaning an attacker could seize a machine with little or no help from the person using it.
[1] -
Dustin Childs of the Zero Day Initiative counted 20 flaws that can spread from machine to machine with nobody clicking anything, then stopped counting.
[5] -
Microsoft says software that hunts for flaws is now finding them faster. Adobe, Cisco, Google, Mozilla and Oracle have all said the same, and Google said on Tuesday it will ship Chrome security fixes every two weeks.
[1] -
Satnam Narang of the security firm Tenable said the hunting is building bigger haystacks without finding more needles: the number of flaws that reach most organisations has not gone up.
[3] -
Finding got faster and fixing did not. Every update has to be tested against a company's own software first, and more than 22,000 company email servers are still unpatched against attack code that is already public.
[1] [4] -
Windows accounted for 723 of the flaws, Office for 222, SQL for 62, SharePoint for 16 and Azure for 12.
[3] -
Ordinary Windows users do not have to test anything. They do have to open Windows Update, and the advice from Krebs on Security is not to let the months pile up.
[1]
Who is involved
-
Microsoft
makes Windows and Office; it published the fixes and says software is now finding flaws faster than people used to
[1] -
CISA
the US cyber-defence agency; it confirmed two flaws are being used in attacks and set a 22 September deadline for federal offices
[4] -
Dustin Childs
head of threat awareness at the Zero Day Initiative, a bug-hunting team at the security company Trend Micro; he counted the self-spreading flaws and calls batches this size the new normal
[2] [5] -
Satnam Narang
a senior research engineer at the security company Tenable; he argues the hunt is finding far more flaws without finding more that matter
[3] -
Tyler Reguly
an associate director of security research at the security firm Fortra; he says each update must be tested against a company's own software before it can go on, and told bosses to feed the teams doing it at weekends
[1]
How it unfolded
-
July Microsoft sets a record with 570 fixes in one month
[1] -
Tuesday it publishes at least 974, and says two are already being used in attacks
[1] [2] -
Also Tuesday CISA confirms the two and orders US federal offices to fix them
[4] -
22 September the deadline for those offices to have both installed
[4] -
So far in 2026 Microsoft has fixed more than 2,600 flaws, with three months of the year left
[1]
Where this points
Watch whether the count of flaws actually being attacked rises alongside the count being found. The Zero Day Initiative says it has not yet.
What is pushing on the whole day
The bar and the word are our reading of how hard each one is pushing today. The arrow is where it is heading. The evidence is in the stories below.
Microsoft published at least 974 in a day
Extortion crews took a healthcare firm's drug research and its own AI model
Researchers found 474 Microsoft 365 sessions captured whole, past the second check
Boston Scientific says August's attack will make it miss its targets for the year
British peers pushed to make bosses personally liable under a new cyber law
The rest of the day
23 more stories on this beat.
Each with its own sources. None of these is a link to the story above.
-
02
Adobe fixes the shop flaw at last
Adobe published an emergency fix on Monday for a flaw in Magento and Adobe Commerce, the software behind a large share of the world's online shops.
[8] Attackers had been using it since late August to install a small hidden program written in Rust that waits for orders from an outside server.[7] The program disguises that server as an ordinary internet clock.[9] A second, unrelated group used the same hole to plant a 485-byte page that runs whatever commands it is sent.[8] Adobe gave the update its highest priority rating.[8] Why it matters — The clean-up is longer than the patch. Adobe tells shop owners to change database passwords, payment keys, administrator logins, SSH keys and integration tokens afterwards, because the attackers may already hold all of them.
[8] -
03
A top-severity flaw in big-company software
SAP, the German firm whose business software runs 99 of the world's 100 largest companies, fixed 20 flaws on Tuesday.
[10] One of them was named OVERPASS by the researchers at Onapsis who found it.[10] It sits in the part of SAP that faces the internet, and lets an attacker with no special privileges run commands on an SAP machine with administrator rights.[10] Onapsis counted more than 10,000 SAP systems reachable from the open internet and called that figure conservative.[10] Why it matters — Since November 2021 the US cyber-defence agency has added 14 SAP flaws to its list of ones being actively used, three of them by ransomware gangs.
[10] -
04
Google patches a Chrome flaw already in use
Google shipped a Chrome update after saying it knows an attack already exists in the wild for one of the flaws it fixes.
[11] That flaw, CVE-2026-85046, is in V8, the part of the browser that runs the code on web pages, and it makes Chrome mistake one kind of data for another so a booby-trapped page can corrupt its memory.[11] Google is holding back the technical details to give everyone time to update, and the same release repairs nine other serious holes.[11] Why it matters — Edge, Brave, Opera and Vivaldi are built on the same engine and get the fix a few days later, so a browser that looks unrelated inherits the same hole.
[11] -
05
Three US agencies accuse six Chinese AI firms
The US cyber-defence agency CISA, the National Security Agency and the FBI published a joint advisory on Tuesday accusing six China-based companies of copying American AI models at industrial scale.
[12] They name DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI.[12] Since late 2024 the six pulled billions of words out of Claude, GPT, Gemini and Grok across millions of requests, the agencies say.[12] The method is knowledge distillation: train a small model on a big model's answers.[12] It is an ordinary technique, and using it this way breaks the American firms' terms of service.[12] Why it matters — The advisory calls this the core of China's AI development strategy and says it was likely done with the Chinese government's awareness. One of its three recommendations is that American firms quietly give worse answers to accounts they suspect.
[12] -
06
The CIA says it now spies on Chinese companies
Michael Ellis, deputy director of the CIA, the United States' foreign intelligence service, told a cybersecurity conference in Washington on Tuesday that American agencies now target Chinese firms as well as the Chinese state.
[13] China poses a different kind of threat because the competition is economic, he said, and the intelligence worth having about artificial intelligence, chips and biotechnology sits inside companies rather than ministries.[13] Earlier US administrations drew a line between spying for national defence and spying for commercial advantage.[13] Why it matters — The New York Times calls it a subtle departure from that precedent. It was said in public at a conference rather than found in a leak, which makes it policy rather than an accusation.
[13] -
07
Criminals move from customer lists to AI models
Google published its latest AI Threat Tracker on Tuesday.
[14] Its incident responders at Mandiant describe a break-in at a healthcare company where attackers took corporate files, drug research and the firm's own AI model, then threatened to publish all of it unless they were paid.[14] At an AI media company, attackers took source code, prompts, model scripts and secrets and made the same threat.[14] In a separate case, attackers broke into a company's cloud systems and harvested thousands of other people's credentials using a set of automated agents in under six hours.[15] Why it matters — John Hultquist, Google's chief analyst, says companies are spending heavily on AI and do not want the results in the open, which is exactly what makes a threat to publish work.
[14] A group tracked as UNC6780 has been poisoning open-source package registries to steal the keys to AI tools and selling them on.[16] -
08
A Brazilian bank's cloud keys copied
CrowdStrike named a new criminal group, Slim Spider, that has been attacking Brazilian financial firms since at least March.
[17] In one break-in the group used small scripts to ask the bank's own cloud service for temporary access keys.[17] It then listed every secret held in the bank's key store and copied the ones tied to digital assets and to Pix, Brazil's instant payment system.[17] CrowdStrike says the group shows detailed knowledge of Brazilian banking systems and is after money rather than information.[17] Why it matters — Nothing was broken and nothing went missing: the keys stayed where they were and copies of them left. There is no missing object for the bank to notice.
-
09
British account-hack losses rise 929%
The City of London Police, the force behind Britain's national fraud reporting service, published its first annual assessment on Friday.
[18] Reported losses from account hacking rose from 1.2 million pounds to 6.3 million in the year to 31 March, and the number of people reporting a loss went from 226 to 2,325.[18] The force says 92% of those reports arrived in the six months after Report Fraud, a new national reporting website, replaced the widely criticised Action Fraud service in January.[18] It warns that comparing the two years directly is not straightforward.[18] Why it matters — Part of the rise is people finally reporting what was already happening. The same assessment counted 64,608 reports of hacking and malware, of which 44,355 were account takeovers, and 3.2 billion pounds of reported losses across all fraud categories.
[18] -
10
Most UK staff use AI their employer never approved
Britain's National Cyber Security Centre, which advises British government and business on cyber defence, warned about what it calls shadow AI: tools staff bring in themselves.
[19] It cited Microsoft research finding that 71% of UK employees had used AI tools their employer had not approved.[19] Anything typed into a consumer AI service may be stored, kept or used to improve it, which the agency says raises the risk of a breach.[19] It also warned that a flaw in an AI agent hands an attacker everything that agent is allowed to touch.[19] Why it matters — The agency's advice is to reduce shadow AI rather than try to block it, because blocking every AI tool will not work. David Chismon, its architecture chief, said security teams should not assume they are seeing the full picture.
[19] -
11
An August attack reaches the annual accounts
Boston Scientific, one of the world's largest medical device makers, told the US securities regulator on Tuesday that last month's cyberattack will have a material effect on its results.
[20] It now expects to miss both the sales growth and the earnings guidance it issued in July, for the third quarter and for the full year.[20] The company found unauthorised activity on its network on 25 August and took systems offline, which stopped it processing and shipping customer orders worldwide.[20] It is still clearing the backlog.[20] Why it matters — Two weeks on, the cost stops being an IT problem and becomes a number shareholders read. Boston Scientific says it still does not know the full figure.
[20] -
12
A Bavarian town's utility encrypted
Stadtwerke Landsberg, the town-owned utility in Landsberg, Bavaria, said on Monday that attackers encrypted its central computer network overnight on 1 September.
[21] Electricity, water and the other essential services kept running; the office systems did not, and staff are reachable only patchily by phone and email.[21] The utility says it cannot rule out that customers' names, addresses, phone numbers, email addresses and bank details were taken.[21] It has named no ransomware group and has not said whether it received a demand.[21] Why it matters — Germany's federal cyber agency, the BSI, has repeatedly called ransomware one of the country's most serious threats. A utility serving three towns in North Rhine-Westphalia was hit the same way in late June and had systems down for weeks.
[21] -
13
220 million travel records left open
Researchers at Kinryu Labs found an unprotected database holding 220,783,700 records on air passengers and crew, covering flights to, from and through Vietnam between January 2017 and April 2026.
[22] The records come from an Advance Passenger Information System, the kind airlines must file before a flight arrives so a country knows who is on board.[22] Each entry holds a name, date of birth, sex, nationality and passport number, plus the flight, the seat and the baggage reference.[22] The server sat in Hanoi, in address space belonging to the telecoms company Viettel.[22] Why it matters — None of the people in the file chose the system: their airline filed the data because a government required it. BleepingComputer says it could not confirm which organisation ran the server.
[22] -
14
Researchers read a phishing crew's own records
Researchers at CloudSEK got administrator access to the control panel of BigBear 2.0, a phishing service rented out to criminals for attacking Microsoft 365 accounts.
[23] Inside they found 5,137 stolen records from 461 organisations, including 1,032 passwords in plain text and 4,148 session cookies.[23] Of those, 474 were complete captured sessions: the attacker held the logged-in state of the account and never needed the second check that multi-factor authentication adds.[23] The operation was still running while they watched.[23] Why it matters — The service sits between the victim and the real Microsoft login page and passes everything through, so the login works and nothing looks wrong. A captured session opens email, calendars, Teams conversations and files in SharePoint and OneDrive.
[23] [24] -
15
Phone calls from a fake IT desk
Arctic Wolf described a group it tracks as PREY-0058 that telephones directors and vice presidents pretending to be their own company's IT help desk.
[25] The caller sends the target to a web address built to look like their employer's login page.[25] That page passes the password and the second check straight through to Microsoft and keeps the resulting session token, which the attackers replay from home internet connections so the sign-in looks ordinary.[25] What they take is then used for extortion.[25] Why it matters — Executives are chosen because their accounts reach more of the company. The tradecraft overlaps with groups Google's Mandiant tracks separately, which suggests several crews renting the same infrastructure.
[25] -
16
Phishing links routed through Google
KnowBe4 published research on 4 September on a phishing campaign that hides where its links go behind a chain of redirects across several Google services.
[26] A security tool inspecting the link sees one Google address after another and lets it through.[26] The victim arrives at a page that either takes their password or installs ScreenConnect, a legitimate remote-control tool the attacker then uses.[26] Attackers have hidden behind single redirects for years; stringing several Google services together is what is new.[26] Why it matters — A filter that trusts a domain rather than a destination can be walked past by anyone who can get a link onto that domain.
[26] -
17
Florida bans plate readers from its highways
Florida's Department of Transportation has banned local police from putting number-plate-reading cameras on state highways and will revoke the permits already issued.
[27] Its memo cites the sharp rise in deployments, reports of misuse and privacy concerns.[27] It followed the state's Republican governor, Ron DeSantis, saying the cameras had got out of control, and Texas governor Greg Abbott ordering state agencies to pause funding for cameras made by Flock Safety.[27] Flock has about 120,000 cameras across 49 US states.[27] Why it matters — A Reuters/Ipsos poll that closed on Monday found 47% of Americans oppose the cameras in their area and 38% support them, with Republicans the most in favour. Both governors moved against them anyway.
[27] -
18
Peers ask why bosses face no penalty
Members of Britain's House of Lords questioned why the Cyber Security and Resilience Bill, now close to becoming law, does not let regulators penalise senior executives personally when a company's failure involves their consent or careless neglect.
[28] Baronesses Kidron and Ludford backed amendments adding personal civil liability and making cybersecurity a board responsibility.[28] Ministers say company fines of up to 17 million pounds and governance rules still to come are enough.[28] Why it matters — The argument is about where a penalty has to land before behaviour changes. Baroness Kidron said culture change starts at the top.
[28] -
19
A Russian developer in an Atlanta court
Sergei Anatolyevich Filimonov, a 36-year-old Russian web developer, was extradited from the Republic of Georgia and pleaded not guilty in a federal court in Atlanta on 4 September to fraud and identity theft charges.
[29] Prosecutors say that from November 2023 to October 2025 he and others bought sponsored search results that sent people looking for their bank to a fake login page.[29] When the FBI seized the domain behind it in December 2025, it held credentials for thousands of victims; investigators identified 19 with confirmed losses of about $14.6 million.[29] Why it matters — The scheme worked by buying the top of a search results page, a slot sold to whoever pays and not checked for being the real bank.
[29] -
20
A second extradition, nine years on
Searzhudin Tamirlanovich Aktulaev, 40, was extradited from Cyprus on 28 August and appeared in a San Francisco federal court on 31 August.
[30] The US Justice Department says he helped distribute malware to about 80,000 users of a freelance employment platform in 2016 and 2017.[30] He was arrested in Cyprus in May 2025, and a federal grand jury has indicted him on conspiracy, computer damage, unauthorised access and aggravated identity theft charges.[30] Why it matters — The offences are nine years old and the arrest itself took another fifteen months to turn into a court appearance.
[30] -
21
A subpoena for everyone who bought a beanie
Homeland Security Investigations is the investigative arm of the US immigration enforcement agency. Court filings say it subpoenaed the outdoor retailer REI in March.
[31] It asked for the transaction records of every person in the Minneapolis and St Paul area who had bought one particular dark green beanie since 2024.[31] The request is part of a federal lawsuit against 39 people who attended a protest at a church in March.[31] REI did not answer Wired's questions about whether it complied.[31] Why it matters — The request turns a shop's sales records into a way of converting a piece of clothing seen at a protest into a list of names.
[31] -
22
OpenAI puts $1bn behind small defenders
OpenAI has committed $1 billion in credits for its own services, plus training and support, to security teams that cannot afford them.
[32] Critical infrastructure operators, community banks, nonprofits and open-source maintainers can apply online, and the company expects the credits to be spent over six months.[32] The programme is called Daybreak for Frontline Defenders.[32] Water systems, electricity utilities and hospitals are attractive targets precisely because an outage forces a fast decision about paying a ransom.[32] Why it matters — The recipients become users of OpenAI's models for as long as the credits last, which is both the point of the gift and its return.
[32] -
23
Most of $320m in Bitcoin came back
People who drained about 4,000 Bitcoin, worth roughly $320 million, from the Liquid Network over the weekend returned 3,400 of it, worth about $263 million.
[33] Liquid is a sidechain of Bitcoin built by the company Blockstream; it disclosed the theft on Sunday, switched off its nodes and stopped all transactions.[33] The money left through something called the SideSwap peg-out authorisation key, but Liquid says that key was not compromised and it still does not know how the funds moved.[33] The people involved describe themselves as white-hat hackers demanding a bug fix.[33] Why it matters — About $57 million has not come back and Liquid has not explained the hole. Exchanges paused deposits and withdrawals of Liquid Bitcoin while it works.
[33] -
24
Ring turns on encryption by default
Ring, the Amazon-owned doorbell and camera company, is rolling out a new default encryption system this month called Throw Away the Key.
[34] It keeps a copy of each video's decryption key for 24 hours so the company's cloud features still work, then destroys it.[34] Ring says it delivers a person-detected alert in about three seconds; asked why it holds the key for a whole day, the company said that is standard for its current cloud processing.[34] Once the system is on for a device it cannot be switched off.[34] Why it matters — The design rests entirely on trusting Amazon to destroy those keys and keep no copies. Owners can choose full end-to-end encryption instead, but then lose the cloud features most of them bought the camera for.
[34]
When the valuable thing is a file, taking it does not look like theft
A copy leaves the original in place, so a company can lose years of work and still have everything it had yesterday.
The twist
A stolen file leaves no gap behind it, so the first sign that anything happened is usually a ransom demand or a competitor's product.
How it works
- A company's most valuable thing used to be a factory or a machine
- Now it is often a file: a model, a set of prompts, a body of research
- A file can be copied without being taken away
- So the owner may never notice, and may not be able to prove it happened
- And one copy sells three ways: as a ransom, as a rival's shortcut, as a government's intelligence
The same force, elsewhere today
Where this chain is also running, in today's other stories.
-
The US accusation against six Chinese AI firms
the same step: the copying is done by asking questions and keeping the answers, so the American models carried on working and there was no break-in to find
-
Google's report on crews stealing AI models
the attackers had to threaten to publish the healthcare firm's drug research, because taking a copy of it had cost that firm nothing yet
-
The CIA saying it now spies on Chinese companies
the target is the same file, so an intelligence agency and an extortion gang are after the same thing for different buyers
-
Slim Spider inside a Brazilian bank
the group listed every secret in the bank's cloud key store and copied the ones tied to money, and the key store went on working exactly as before
Where you've seen this
Factory processes
an engineer who leaves carries the method out in their head, and the factory keeps running
Film and music piracy
the studio still has the film, so the loss has to be argued rather than shown
Unpublished research
a rival lab that sees your results early saves the years it would have taken to get them
A small firm's customer list
the list is still in the drawer, and the first sign is a competitor ringing your customers
The catch
A copy is not always as good as the original. A model trained on another model's answers inherits that model's mistakes and cannot get ahead of it.
And the whole of it
Almost everyone now keeps something valuable as a file, the reader included: photographs, messages, a record of where you have been. Whether a copy of it has already been made is not something you can check from where you sit, and the people who could check are the ones holding it.
What is really going on
Microsoft published fixes for at least 974 flaws on Tuesday, and the US cyber-defence agency told federal offices to install two of them by 22 September. Those two are the ones somebody has been seen using; the other 972 are a sorting job that lands on every company running Windows.
Why it works on us — One big number is easier to report than a list of which flaws matter, so 974 travelled further this week than the two flaw numbers that people are actually being attacked with.
Who gains
-
The security firms quoted in every patch story
— Fortra, Tenable, Cohesity, Action1 and Automox all supplied comment on a day whose headline number is itself an argument for buying help with patching.
[1] [2] [4] -
The six Chinese AI companies named in the US advisory
— If the accusation holds, distillation gave them the results of other firms' training runs for the price of asking the questions.
[12] -
The CIA
— Calling Chinese firms a legitimate target in artificial intelligence, chips and biotechnology widens what the agency may collect, and Michael Ellis said so at a conference rather than being caught at it.
[13] -
Extortion crews
— A stolen AI model is worth more than a stolen customer list, because the company will pay to keep it off the open web rather than just notify people.
[14] -
OpenAI
— Its $1bn of credits go to water systems, hospitals, community banks and open-source maintainers, all of whom become users of its models for as long as the credits last.
[32] -
Nick Carroll of Nightwing
— His figure of 22,000 unpatched email servers is the number every outlet used this week, and it came from a company that sells the work of fixing them.
[4]
Who pays
-
The people who install Windows updates for a living
— All 974 have to be tested against a company's own software before they go on, and Fortra's public advice to bosses was to buy dinner for the teams doing it at weekends.
[1] -
Customers of Stadtwerke Landsberg
— The Bavarian utility says it cannot rule out that their names, addresses, phone numbers and bank details were taken.
[21] -
About 220 million air passengers and crew
— Their names, dates of birth, nationalities and passport numbers sat in an open database covering flights to, from and through Vietnam from 2017 to 2026.
[22] -
Hospitals waiting on Boston Scientific orders
— The company is still clearing a backlog two weeks after the attack that stopped it processing and shipping orders worldwide.
[20] -
Anyone in Minneapolis who bought a dark green beanie
— US immigration investigators asked REI for the transaction records of every such buyer since 2024, as part of a search for people at one protest.
[31] -
The 461 organisations in the BigBear panel
— 1,032 of their passwords were sitting there in plain text, and researchers counted 474 cases where an attacker held a fully logged-in Microsoft 365 account.
[23]
What nobody knows yet
Open questions from across today’s stories — ours included.
-
01
How many flaws Microsoft actually fixed on Tuesday.
The counts published on the day range from 966 to 997. BleepingComputer says 966, The Record 973, Dark Reading and SecurityWeek 974, and the Zero Day Initiative 972 new flaws or 997 counting browser fixes carried into Edge. The gap is about what each one counts.
[6] [4] [2] [5] -
02
Who is using the two Windows flaws, and against whom.
Microsoft and CISA both say the two are being exploited. Neither has published who is doing it or how widely.
[4] [5] -
03
What Microsoft's total for 2026 really is.
Krebs on Security and Tenable put it above 2,600. The Zero Day Initiative's count is 2,760. Nobody has reconciled the two in public.
[1] [5] -
04
Whether any of the six Chinese companies named by the US agencies accepts the accusation.
The joint advisory names DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI and says the copying was likely done with the Chinese government's awareness. No response from any of them appears in the announcement.
[12] -
05
Who runs the Vietnamese passenger database that was left open.
Kinryu Labs found the server in Hanoi, in address space belonging to the telecoms company Viettel. BleepingComputer says it could not confirm which organisation operated it.
[22] -
06
How much money Boston Scientific will lose to the August attack.
The company has told the US securities regulator the effect is material and that it will miss its guidance, but says it does not yet know the full figure.
[20] -
07
How the money left the Liquid Network, and whether the rest comes back.
About 3,400 of 4,000 Bitcoin were returned. Liquid says the key used to move the funds was not compromised and that it does not yet know how the withdrawal happened.
[33] -
08
How much of Britain's 929% rise in reported account-hack losses is new crime.
The City of London Police say 92% of the reports involving a loss arrived in the six months after a new reporting website opened, and warn that comparing the two years directly is not straightforward.
[18] -
09
Whether REI handed over its customer records.
Wired says Homeland Security Investigations subpoenaed the retailer in March for everyone in the Minneapolis area who bought one green beanie since 2024. REI did not answer questions about whether it complied.
[31]
People who drained about 4,000 Bitcoin from the Liquid Network over the weekend gave 3,400 of it back, worth roughly $263 million.
Also true today
- Sergei Filimonov was flown from the Republic of Georgia to a federal court in Atlanta and appeared there on 4 September, over a scheme that bought search results to steal bank logins. Searzhudin Aktulaev was extradited from Cyprus on 28 August over malware sent to about 80,000 users of a freelancing site in 2016 and 2017.
- Adobe published a fix on Monday for the Magento flaw that attackers had been using since late August to plant hidden programs on online shops.
- OpenAI has put $1 billion of credits behind water systems, electricity utilities, hospitals, community banks, nonprofits and open-source maintainers, who can apply for them online.
More from Cybersecurity
Across the beats