The Matthew Chapman Podcast

Microsoft Patches Nine Hundred Seventy-Four Flaws, Two Live Zero-Days

Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.

0:00 | 4:09
Here is your briefing for Wednesday, September 9, 2026. Microsoft just set another Patch Tuesday record: nine hundred seventy-four of its own C.V.E.s, plus twenty-five third-party fixes for nine hundred ninety-nine total. Over one hundred ten are critical. Two Windows privilege-escalation bugs were already being exploited, C.V.E. twenty twenty-six dash eighty-one thousand nine hundred sixty-three in the Update Stack, and C.V.E. twenty twenty-six dash eighty-five thousand eight hundred eighty in A.L.P.C., both landing SYSTEM. CISA put both on the K.E.V. list with a September twenty-second federal deadline. Microsoft says A.I. is finding bugs faster, and year-to-date patches already top two thousand six hundred. That is not a queue you triage by vibes. Prioritize the zero-days, then your exposed criticals, and assume the Update Stack bug is riding behind low-privilege footholds. Google patched two hundred thirty Chrome issues, including an out-of-bounds write in V8 tracked as C.V.E. twenty twenty-six dash eighty-seven thousand four hundred ninety-one. A crafted page can execute code inside the sandbox. Google says an exploit is already in the wild and kept details thin until most users update. That is the seventh actively exploited Chrome zero-day this year. Update to one fifty-three point zero point eight thousand ten point thirty-six or thirty-seven on Windows and macOS, and the Linux build matching that train. Browsers remain the cheapest remote foothold. Patch Chrome today, not after lunch. OX Research found that DeepSeek Harness, the open-source runner for coding agents on a developer machine, let a sandboxed agent disable its own file sandbox with one shell command. The local control A.P.I. had no auth, and the sandbox left loopback open, so the agent called home, flipped the session to danger-full-access, and stopped approval prompts. VulnCheck tracked it as C.V.E. twenty twenty-six dash eighty-two thousand five hundred thirty-three, C.V.S.S. nine point four. It worked on default installs until DeepSeek shipped zero point one point two alpha one on August twenty-seventh. Prompt injection was enough to trigger the call. If your coding agents can reach their own control plane, that plane is part of the attack surface. Upgrade Harness, bind control A.P.I.s to real peer checks, and do not trust Host headers as identity. Check Point Research showed a planted instruction in ChatGPT could run a hidden second stream while the user got a normal answer. In the demo, that stream used the victim's connected Gmail and relayed mail data to another ChatGPT account over a shared internal Artifactory cache that both sandboxes could write. Delivery was a pasted prompt, a shared chat link, or a custom G.P.T. with hidden builder instructions. The only visible hint was a small Talked to Gmail label. OpenAI took the Artifactory path offline. Connected apps turn an assistant into a privilege broker. Revoke unused connectors, treat shared chats and custom G.P.T.s as untrusted code, and watch for surprise app labels on otherwise boring replies. SAP patched a max-severity memory corruption bug in Extended Passport processing, C.V.E. twenty twenty-six dash forty-four thousand seven hundred fifty-six, codenamed OVERPASS by Onapsis. Unauthenticated remote attackers can send a malformed E.P.P. header and run O.S. commands as the SAP admin user on the host. A second critical, S4GET in NetWeaver Message Server, scored nine point eight and sits on the same public logon port you cannot firewall without breaking users. That is full compromise of business data and processes from outside the app login. Patch the September SAP Security Notes now, restrict Message Server exposure where you can, and hunt for odd E.P.P. traffic. E.R.P. kernels with internet-facing parsers are still a gift that keeps giving. Nearly a thousand Microsoft fixes with two live escalations, a Chrome V8 zero-day already in the wild, an agent harness that lets the model fire its own warden, a ChatGPT side channel that walked Gmail out under a polite reply, and an unauthenticated SAP kernel R.C.E. Trust boundaries around browsers, update stacks, agent control planes, and E.R.P. parsers are where this week is paying out. That's the briefing. Stay sharp, keep your systems patched, and we'll see you tomorrow.

Kindle: https://www.amazon.com/dp/B0HHMH88H9 
Apple Books: https://books.apple.com/us/book/local-ai-on-the-mac/id6807243472

Barnes & Noble: https://www.barnesandnoble.com/w/books/1151622292?ean=2940185390764

https://mattch

Support the show