Cybersecurity · Monday, 14 September 2026
Microsoft fixed a hole in its built-in antivirus on 3 September. A researcher published a way round the fix within a week.
A researcher who has fought Microsoft since April released ShieldCrash, attack code aimed at Windows Defender that gets round a fix Microsoft shipped on 3 September. Also: Wildberries sellers still owed about $240 million after an attack, a hidden bitcoin mine found in Mexico's mountains, two Singapore phone-shop workers arrested, and 5,400 small-business websites turned into traps.
3
attacks on Defender in a row, each one getting round the fix for the last
RoguePlanet in June, ShieldBreak in August, ShieldCrash in September
20 days
from Microsoft acknowledging ShieldBreak to shipping its fix
14 August to 3 September, and ShieldCrash followed within a week
974
security flaws Microsoft fixed in its September updates
its biggest month ever; July's record had been 570
The lead story — what happened
-
A researcher who calls themself Nightmare Eclipse has published ShieldCrash, attack code aimed at Microsoft Defender, the antivirus built into Windows.
[1] [2] -
It came out just after Microsoft's September updates, and it targets Windows computers that have all of those updates installed.
[1] -
ShieldCrash gets round Microsoft's fix for ShieldBreak, an earlier attack on Defender by the same researcher.
[1] [2] -
Microsoft acknowledged ShieldBreak on 14 August and shipped fixes for it on 3 September.
[1] -
ShieldBreak was itself a way round Microsoft's fix for RoguePlanet, an attack the researcher released in June.
[1] -
The code shows someone already on a computer reading files that only Windows itself is allowed to open.
[1] [2] -
The researcher says the flaw goes further and can hand over full control of the machine.
[1] [2] -
Ensar Seker of SOCRadar, a threat intelligence company, says the published code does not do that yet.
[2] -
Seker says files read this way can include passwords and other secrets, and can become one step in a larger attack.
[2] -
The fight began in April over a disagreement about bug reports, and Microsoft at one point appeared to threaten legal action.
[2] -
Since then the researcher has kept releasing new Windows attacks on Microsoft's monthly update days, before any fix exists.
[2] -
Microsoft did not answer questions about ShieldCrash from SecurityWeek or Dark Reading.
[1] [2]
Who is involved
-
Nightmare Eclipse
a security researcher, also known as Chaotic Eclipse; has released Windows attacks monthly since April and published ShieldCrash
-
Microsoft
makes Windows and its built-in Defender antivirus; fixed ShieldBreak on 3 September and has not commented on ShieldCrash
-
Ensar Seker
chief information security officer at SOCRadar, a threat intelligence company; examined the ShieldCrash code
How it unfolded
-
April the researcher's dispute with Microsoft begins with an attack called BlueHammer
[2] -
June RoguePlanet, an attack on Defender, is released
[1] -
19 July Microsoft fixes RoguePlanet
[1] -
August ShieldBreak gets round that fix; Microsoft acknowledges it on 14 August
[1] -
3 Sep Microsoft ships fixes for ShieldBreak
[1] -
September ShieldCrash gets round those fixes, just after Microsoft's September updates
[1]
Where this points
Watch whether Microsoft fixes ShieldCrash before its October update day, and whether it repairs the whole part of Defender these attacks keep reaching, which is what Seker says it should do.
What is pushing on the whole day
The bar and the word are our reading of how hard each one is pushing today. The arrow is where it is heading. The evidence is in the stories below.
Microsoft shipped fixes for 974 flaws in one month, and companies have to test them before installing.
Police in Puebla, Mexico, are checking whether a hidden bitcoin mine took its power from a dam.
Three online marketplaces account for most of the bosses' social security numbers that Rapid7, a security company, found exposed.
Sellers on Wildberries, a Russian online marketplace, are owed about $240 million after payments were delayed.
The rest of the day
19 more stories on this beat.
Each with its own sources. None of these is a link to the story above.
-
02
Wildberries sellers still waiting for their money
Wildberries, one of Russia's largest online marketplaces, says an attack that flooded its systems with traffic has delayed payments to some sellers.
[6] The Russian Union of Marketplace Sellers says about 20 billion rubles, around $240 million, is still unpaid for goods sold in the last week of July.[6] In its survey of nearly 2,000 sellers, 95.6% had not received money they expected.[6] In August, Ukraine's military intelligence said it had disrupted Wildberries' systems with a hacker group called Cyber Corps.[6] Why it matters — Wildberries has not said whether that operation and the payment delays are connected.
[6] The sellers' union doubts the company's explanation, says foreign sellers kept being paid on time, and has asked Russia's prime minister to step in.[6] -
03
A hidden bitcoin mine in Mexico's mountains
Police in Puebla state, Mexico, found a building near the village of Tlaola holding 300 computer graphics cards used to mine cryptocurrency, Reuters reported.
[7] Mining uses powerful computers to create new coins, and Reuters says electricity is the biggest expense in running a mine.[7] Authorities are investigating whether the mine was taking power from a nearby hydroelectric dam.[7] It is the fourth such farm found in the area since early last year.[7] Why it matters — A security analyst told Reuters that setting it up would have needed a well-funded group, such as one of Mexico's most powerful drug cartels.
[7] An expert on energy theft said that if the power was stolen, the mine's main running costs would be close to nothing.[7] -
04
Singapore phone-shop workers arrested
Singapore police arrested two Malaysian men, aged 25 and 47, who worked at a mobile phone shop.
[8] Police say they used their jobs to get into customers' accounts on Singpass, Singapore's national digital ID.[8] In one case, a customer buying a SIM card was offered help updating the phone number on their Singpass, and a LiquidPay payment account was opened without their knowledge.[8] Investigators linked more than 170 people's Singpass accounts to the scheme.[8] Why it matters — Those accounts were used to register more than 160 LiquidPay accounts.
[8] Police say the men used chances that came with their jobs at the shop, such as helping a customer at the counter.[8] -
05
5,400 small-business websites turned into traps
Netskope, a security company, counted more than 5,400 hacked websites being used in one attack campaign.
[8] It says the sites have little in common beyond being small businesses, such as clinics, plumbers and online shops.[8] Code added to each site shows visitors a fake prompt telling them to run a command on their own computer.[8] This kind of fake prompt is known as ClickFix.[8] Why it matters — Netskope found no shared industry, region or owner among the sites.
[8] The people shown the fake prompt are the clinics', plumbers' and shops' own visitors.[8] -
06
A fake DocuSign page built inside the browser
Barracuda, a security company, described phishing emails dressed up as DocuSign, a service people use to sign documents online.
[8] Victims are passed through real Microsoft services before they reach a fake sign-in page.[8] That page is built inside the victim's own browser for that session only.[8] So there is no fixed web address that security tools can look up and block in advance.[8] Why it matters — Barracuda says passing through trusted Microsoft services makes both people and automatic scanners less likely to spot the attack.
[8] -
07
Browser add-ons that took traders' logins
Socket, a security company, found four browser add-ons for Chrome and Firefox aimed at users of Axiom Trade and Padre, two cryptocurrency trading sites.
[8] They were published under the names J7Tracker, VREO and Orbit Tracker.[8] Socket says they collected logged-in user details, wallet data and access tokens, and sent them to servers the attackers control.[8] The same Chrome publisher was linked to two earlier add-ons that pretended to be another trading tool.[8] Why it matters — An add-on runs inside a browser the trader is already logged into, so it can collect details that the login has already unlocked.
[8] The earlier fakes show the same publisher returning under new names.[8] -
08
A fake Microsoft tool led to ransomware
The DFIR Report, which publishes investigations of real break-ins, described an attack that began with a fake installer posing as a Sysinternals tool, a set of free Windows utilities from Microsoft.
[8] It installed a remote-control program and a malware kit called TukTuk that the report says was made with AI.[8] The attacker used stolen service-account logins to spread GoTo Resolve, a real remote-management tool, across servers.[8] Data was copied to a cloud service and The Gentlemen ransomware was deployed.[8] Why it matters — The attack reached domain controllers, the servers that manage every login on a company network.
[8] The whole chain started from one fake installer for a real Microsoft tool.[8] -
09
Bosses' social security numbers exposed
Rapid7, a security company, says it found 476 cases of exposed US social security numbers, the ID numbers used for tax and credit, belonging to 395 company staff since early 2026.
[8] More than 73% belonged to top leaders: 44.6% were senior executives and 28.6% were company presidents.[8] Three online marketplaces, Xilo, Bankom and PeopleFinder, account for 81.5% of the leaks in its data.[8] Why it matters — Rapid7 says the exposures directly targeted leadership rather than falling at random.
[8] Finance companies made up over a quarter of the organisations affected, and industrial companies 17%.[8] -
10
LG denies its TVs map home networks
Gamers Nexus, a YouTube channel that tests computer hardware, says LG smart TVs gather extensive information about people and their homes, and that LG uses it for advertising.
[8] It says it saw a TV record IP addresses, location data, and the names and signal strength of nearby Wi-Fi networks.[8] It also says the TV listed devices on the home network it was never paired with, including phones, watches, thermostats and PCs.[8] LG told The Register the claims are not true.[8] Why it matters — LG says scanning for nearby devices is a standard smart TV feature.
[8] It says voice data is only sent when the remote's voice button is held or a wake word is heard.[8] -
11
Meta left AI abuse videos up after reports
Futurism, a US news site, found a large network of Facebook accounts posting AI-generated videos of violence against children, WIRED reported.
[9] It found most of the accounts by following Facebook's own recommendations from one account to the next.[9] Futurism reported eight accounts through Facebook's normal reporting tool.[9] Meta removed two, one of them only after first rejecting the report, and several decisions took more than a week.[9] Why it matters — Meta's written rules ban depictions of child abuse, real or synthetic, and do not say whether AI video falls under exceptions for art and games.
[9] Meta told the reporters that some of the flagged links did not break its rules.[9] -
12
Clearview tests a tool to map a person's contacts
Clearview AI, a face-recognition company that sells searches to police, is testing a prototype tool called InquiryIQ, WIRED reported.
[9] The tool would help police find a target's associates, social media accounts and other personal information.[9] The prototype had not been reported before.[9] Why it matters — The tool is built to look at the people around a target, not only the target.
[9] -
13
Windows will tell apps a user's age group
Microsoft is adding a feature to Windows 11 called the Windows Age API.
[8] It lets apps learn whether a user is a child, a teenager or an adult.[8] The app does not see the user's exact date of birth.[8] Microsoft says building this into Windows lets app makers add safety features from the start, instead of families setting protections one app at a time.[8] Why it matters — Microsoft says apps get only the age signal they need and not sensitive personal data such as a full date of birth.
[8] -
14
Teams will blur QR codes from outsiders
Microsoft says Teams, its workplace chat app, will blur images containing QR codes when they come from people outside a company.
[8] A QR code is the square barcode a phone camera opens as a web link.[8] A user will have to choose to reveal the image before viewing or scanning it.[8] Microsoft expects the change to start reaching users next month.[8] Why it matters — Microsoft says the point is to cut phishing and fraud by making people stop before they scan a code sent by a stranger.
[8] -
15
US cyber agency updates its insider guide
CISA, the US cyber-defence agency, has released an updated version of its Insider Threat Mitigation Guide.
[8] It deals with the harm people inside an organisation can do to critical infrastructure, such as power and water systems.[8] The new version adds material on hybrid and remote work, on AI used to manipulate and deceive, on who gets access, and on screening visitors.[8] Why it matters — The Singapore arrests the same week were this kind of case: police say shop staff used access their jobs gave them.
[8] -
16
Many AI assistant add-ons can take real actions
Island, a security company, examined 33,563 published MCP servers, which are add-ons that give AI assistants extra tools.
[8] It found that two in five include a tool that can reach sensitive data or take an action with real effects.[8] One in 13 contains a way to run code or commands.[8] Island says the text describing a tool can be read by the AI as an instruction.[8] Why it matters — Island says an attacker may not need malicious software at all, because a paragraph of plain language can be enough to steer the assistant.
[8] -
17
Thirteen poisoned wallet code packages
Thirteen booby-trapped packages were found on npm, the public library where programmers download ready-made JavaScript code, according to InstallSafe.
[8] Their names mention wallets, signing, analytics, Solana, Base or mobile parts, so they sound like ordinary cryptocurrency building blocks.[8] GitHub, which runs npm, warned that any computer that installed one should be treated as fully taken over.[8] Why it matters — GitHub says removing the package does not guarantee removing everything it installed.
[8] Every secret and key on an affected computer has to be replaced from a different computer.[8] -
18
Fewer Plex servers left open
Plex, which people use to stream their own films and music from a home server, released security updates for several flaws.
[11] It urged customers to install them as soon as possible, without giving details.[11] The Shadowserver Foundation, which scans the internet for exposed systems, counted over 33,800 Plex servers still open to the recently disclosed flaws.[8] That is down from 37,467 on 5 September.[8] Why it matters — That is about 3,600 fewer exposed servers, and nearly 20,000 of those still exposed are in North America.
[8] -
19
Visa pays $2.4 billion for a fraud-detection firm
SecurityWeek counted 33 deals to buy or merge security companies announced in August.
[10] Visa agreed to buy BioCatch, which spots fraud from how people use their devices, for $2.4 billion in cash.[10] Munich Re, a German reinsurance giant, agreed to buy the cyber-insurance company At-Bay for $575 million.[10] Fortinet and Palo Alto Networks, two big security companies, each bought a firm working on AI agents.[10] Why it matters — BioCatch will join Visa's existing fraud and risk products.
[10] At-Bay will join Munich Re's HSB unit, combining its security services with insurance cover.[10] -
20
Fifteen years for harassment with AI images
James Strahler II, 37, of Columbus, Ohio, was sentenced in the US to 15 years in prison.
[8] The US Justice Department says that from December 2024 to June 2025 he sent at least six women harassing messages.[8] The messages included nude images of them, both real and made with AI.[8] He also posted AI-generated obscene images of children online.[8] He was arrested in June 2025.[8] Why it matters — The Justice Department says he had installed more than 24 AI apps and used more than 100 AI models on the web from his phone.
[8]
A crime is cheap to run when someone else pays the bills
When the power, the website or the ID login belongs to someone else, a criminal pays almost nothing to run the scheme.
The twist
A crime can earn very little and still be worth running, because somebody else is paying for the power, the websites and the accounts it runs on.
How it works
- Running a crime costs money: electricity, websites, bank accounts
- The criminal takes those things from people who do not notice
- The owner keeps paying for them as normal
- So the crime can earn little and still make a profit
- It lasts until the owner, or the police, notice something odd
The same force, elsewhere today
Where this chain is also running, in today's other stories.
-
The hidden bitcoin mine in Puebla
Electricity is the biggest cost of mining, and authorities are checking whether this mine took it from a nearby dam instead of paying for it.
-
5,400 small-business websites turned into traps
Clinics, plumbers and online shops keep paying for their websites while the attacker uses those sites to reach visitors.
-
The Singapore phone-shop arrests
The payment accounts were opened on the Singpass logins of more than 170 real people, so the scheme ran on identities that belonged to other people.
Where you've seen this
Cuckoos
the bird lays its egg in another bird's nest, and the other bird spends its food raising the chick
Fly-tipping
rubbish dumped on someone else's land saves the dumper the tip fee, and the landowner pays to clear it
Pollution downstream
a factory that lets waste flow into a river saves on treatment, and the towns downstream pay to clean the water
The catch
It only works while the owner does not notice: the Puebla mine's noise could be heard a kilometre away, and a hacked website gets cleaned once its owner sees it.
And the whole of it
A plumber in one country and a village beside a dam in another can both be paying part of a criminal's running costs without knowing it. Each of them sees only their own bill, and nobody sees all the bills together.
What is really going on
A researcher showed that Microsoft's 3 September fix for Defender, the antivirus built into Windows, can still be got round, and Microsoft did not answer two security news sites that asked about it.
Why it works on us — The ShieldCrash story is told as a feud between one angry researcher and Microsoft, which makes a gap on fully updated Windows computers read like a quarrel between two parties.
Who gains
-
Anyone who wants to misuse ShieldCrash
— The code is public on GitHub, and Seker says attackers can be expected to use it to steal passwords or take more control.
[2] -
The group behind the Puebla mine
— An energy-theft expert told Reuters that with stolen power the mine's main costs would be close to nothing.
[7] -
Visa
— Buying BioCatch for $2.4 billion adds its tools for spotting fraud from how people use their devices to Visa's own fraud products.
[10] -
Munich Re
— Buying At-Bay for $575 million puts a cyber-insurance company and its security services inside Munich Re's HSB unit.
[10] -
Wildberries, if its sellers' union is right
— Blaming an outside attack gives the company a reason for late payments that is not its own doing, and the union calls that very convenient.
[6]
Who pays
-
Sellers on Wildberries
— About 20 billion rubles, around $240 million, for goods sold in late July is still unpaid, and 95.6% of sellers surveyed were missing money.
[6] -
IT staff who install Windows updates
— A record 974 fixes in one month have to be tested before they go out, and Fortra's Tyler Reguly talks of teams working Saturdays to install them.
[4] -
Small businesses whose websites were hacked
— Clinics, plumbers and online shops among 5,400 sites are now showing their own visitors a fake prompt.
[8] -
More than 170 people in Singapore
— Their Singpass logins were linked to a scheme that registered more than 160 LiquidPay accounts.
[8] -
Executives whose social security numbers are exposed
— Rapid7 found 476 exposures belonging to 395 staff, and 44.6% of the people affected were senior executives.
[8]
What nobody knows yet
Open questions from across today’s stories — ours included.
-
01
Whether ShieldCrash can take full control of a computer, or only read protected files.
The researcher says it is a full takeover. Ensar Seker of SOCRadar, who examined the code, says it does not yet do that. Microsoft has not said.
[1] [2] -
02
When, or whether, Microsoft will fix ShieldCrash.
Microsoft did not respond to SecurityWeek or Dark Reading, and two earlier fixes in the same part of Defender were got round within weeks.
[1] [2] -
03
How many flaws Microsoft actually fixed in September.
SecurityWeek, Krebs on Security and The Hacker News say 974, the Zero Day Initiative counts 972, BleepingComputer 966 and Tenable 964. Each counts different things, and The Hacker News reaches 999 with fixes for other companies' code.
[3] [4] [5] [11] [12] -
04
What Microsoft's July record really was.
Krebs on Security and BleepingComputer say 570 flaws, Tenable says 569 and The Hacker News says 663.
[4] [11] [12] -
05
Whether the attack on Wildberries is really why sellers have not been paid.
Wildberries blames an attack that flooded its systems. The sellers' union calls that convenient and says foreign sellers were paid on time.
[6] -
06
Whether Ukraine's military intelligence operation is connected to the Wildberries payment delays.
Ukraine's military intelligence claimed an operation against Wildberries in August, and Wildberries has neither confirmed it nor linked it to the delays.
[6] -
07
Who ran the Puebla bitcoin mine, and whether it stole power from the dam.
Mexico's federal attorney's office declined to comment, citing an active investigation. A link to a cartel is an analyst's view, not a finding.
[7] -
08
What LG smart TVs actually collect.
Gamers Nexus says it watched the TVs record Wi-Fi networks and devices on the home network. LG says the claims are not true.
[8] -
09
How many Singapore residents lost money through the LiquidPay accounts.
The police statement quoted gives the number of accounts linked, over 170 Singpass and over 160 LiquidPay, and no figure for money taken.
[8]
Singapore police arrested two phone-shop workers accused of using customers' Singpass logins to open more than 160 payment accounts in other people's names.
Also true today
- The number of Plex home media servers open to recently disclosed flaws fell from 37,467 on 5 September to just over 33,800.
- Police in Puebla, Mexico, found a hidden bitcoin mine in the mountains, led there by its noise and the huge amount of electricity it used.
More from Cybersecurity
Across the beats