Oracle September 2026 Update Fixes 673 Security Vulnerabilities
Oracle’s September 2026 security update fixes 673 vulnerabilities across its products. Of these, 104 are rated critical, 503 important, and 59 medium severity. Oracle E-Business Suite received the most fixes, with 159 vulnerabilities addressed, followed by Fusion Middleware with 153 and Hyperion with 102.
A key concern is that many of these vulnerabilities could potentially be exploited remotely without requiring a username or password. For example, 78 Fusion Middleware vulnerabilities and 50 Hyperion vulnerabilities have this exposure. Oracle E-Business Suite also includes three critical vulnerabilities with a CVSS score of 9.8, indicating a particularly serious level of risk.
The update also fixes 41 vulnerabilities in third-party or open-source components used within Oracle products. Oracle Database received 13 updates in total, including 11 for Database Server and two for Autonomous Health Framework. Qualys has already released detection IDs (QIDs) for several affected Oracle products, including E-Business Suite, WebLogic Server, PeopleSoft, VirtualBox, and JDeveloper, with additional coverage expected.
Researchers State Browser Extensions Could Hijack AI Assistants
Researchers at Forever Security found that a malicious browser extension could hijack AI assistants in five Chromium-based products: Google Chrome’s Gemini Live, Perplexity Comet, Microsoft Edge, Opera Neon, and Anthropic’s Claude in Chrome. The extension could make these AI tools perform actions for an attacker, and in some cases read local files, take screenshots, or access the camera and microphone.
The researchers said the attacks worked by exploiting the way browser-based AI assistants communicate with trusted websites. With just two common browser permissions, an extension could insert its own code into a trusted page and send commands to the AI as if they came from the browser vendor. These were demonstrations rather than attacks observed in the wild, and the attacker would first need the victim to install the malicious extension.
Google and Microsoft have fixed the vulnerabilities reported for Chrome and Edge, which have assigned CVE numbers. The researchers also reported similar issues in Comet, Opera Neon, and Claude in Chrome, although those findings do not currently have CVE numbers. Users should keep their browsers and AI tools updated and remove browser extensions they do not recognize or need, since installing a malicious extension is the starting point for these attacks.
Parallels Desktop Flaw Could Give Attackers Root Access on Mac
Parallels Desktop for Mac has a security flaw that could allow a regular local user to gain full administrator-level control of the Mac. The issue, called ParaShells and tracked as CVE-2026-90894, does not allow remote attacks by itself; an attacker would first need to get code running on the Mac under a normal user account.
The vulnerability affects the Mac itself, not the Windows or Linux virtual machines running through Parallels. Researchers found that a background Parallels service running with the highest privileges could be manipulated by a normal user, potentially allowing the attacker to run their own programs as the system administrator. Parallels Desktop 27 reportedly fixes the problem, but Intel-based Macs cannot upgrade to version 27 and remain on the 26.x release line, for which researchers say this particular fix is not currently available.
Organizations using Parallels should identify Macs running affected versions and upgrade to Parallels Desktop 27.0.1 or later where possible. Intel Mac users should monitor Parallels for a security fix for version 26 and restrict unnecessary local accounts in the meantime. Administrators should also remember that simply installing an update may not remove an attacker who has already gained administrator access.
Defensible Strategies
Learn from those who have been attacked
Spain Reports AI Agent Used in Alleged Cyberattack
Spain’s data protection agency, the AEPD, was notified of a reported cyberattack involving an AI agent. According to the organization that reported it, the AI independently searched for weaknesses, gained access to systems, investigated applications for additional flaws, changed personal information, and accessed financial documents. However, the AEPD has not yet investigated or verified the incident, so these details remain unconfirmed.
The agency says the case highlights how AI could make cyberattacks faster, larger, and more adaptable, leaving organizations less time to respond. It recommends stronger protection of accounts, passwords, API keys, and other digital credentials, along with faster automated detection and response. The AEPD also stresses that an AI being used in an attack would not necessarily mean the underlying AI model or its provider was compromised or intentionally designed for malicious use.
Dark-Web Service Exposes 153 Million Driver’s Licenses
A new dark-web service called Nexus is reportedly selling access to more than 153 million U.S. and Canadian driver’s license records, along with other identification documents. The database appears to be growing, with hundreds of thousands of new records reportedly added within a day. Researchers found their own licenses and those of friends and family, suggesting the information may have been collected during activities such as car rentals, travel, or other identity checks.
Investigators traced many of the records to IDScan.net, a company that provides identity-verification technology to businesses including rental-car companies, retailers, hotels, and other organizations. The stolen records can include detailed images of both sides of a license, including specialized scans using infrared and ultraviolet light. IDScan.net says it is investigating the matter, but has not publicly confirmed that its systems were breached.
The FBI’s New Orleans field office has opened an investigation into the suspected breach. The incident highlights the risks of handing sensitive identification documents to third-party verification services: once collected, copies of licenses can become valuable targets for criminals and may be difficult for individuals to control or recover if stolen.
N0va Phishing Campaign Targets Corporate Accounts
N0va is a phishing campaign targeting organizations in North America and Europe, particularly sectors such as government, healthcare, technology, and consulting. It impersonates familiar services like Microsoft Teams, SharePoint, OneDrive, DocuSign, Google Drive, and Zoom to trick employees into completing seemingly legitimate sign-in processes.
Rather than simply stealing passwords, N0va can capture digital authentication credentials that allow attackers to access accounts and cloud services as if they were legitimate users. A compromised account could provide access to emails, files, business applications, and other corporate resources, potentially leading to financial fraud, sensitive-data theft, operational disruption, and regulatory consequences.
The article recommends that security teams look beyond individual phishing alerts and investigate the wider campaign and its behavior. Organizations should use threat intelligence, monitor authentication activity, and feed newly identified threats into existing security tools so they can detect and contain compromised accounts more quickly.
