Truckful is a single-player car delivery adventure game set to launch for PC via Steam and Android via Google Play on October 9, with PlayStation versions coming later.
Microsoft's Patch Tuesday on September 8, 2026, addressed two critical Windows privilege escalation vulnerabilities: CVE-2026-85880 and CVE-2026-81963, both with a CVSS score of 7.8. CVE-2026-85880 is a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC), allowing attackers with low-privilege local access to escalate privileges to SYSTEM. CVE-2026-81963 involves improper link resolution in the Windows Update Stack, enabling similar privilege escalation. Both vulnerabilities require no user interaction and have been actively exploited prior to the patch release. CISA added them to its Known Exploited Vulnerabilities catalog on September 8, 2026, with a remediation deadline of September 22 for U.S. federal agencies.
CVE-2026-85880 affects various Windows 10 and Server versions but excludes Windows 11 and Windows Server 2025. CVE-2026-81963 impacts newer Windows platforms, including Windows 11 and Windows Server 2025. Microsoft released security updates for both vulnerabilities on September 8, 2026, and organizations are advised to prioritize these updates. Security teams should monitor for signs of privilege escalation and unusual SYSTEM-level activities related to these vulnerabilities.
Bitdefender is recognized for its strong detection capabilities, mid-range pricing, and minimal system impact. Malwarebytes offers a free scanner for cleaning infected Macs, while Intego specializes in macOS with features tailored for Apple users. Norton provides a comprehensive security package with VPN, backup, and identity monitoring features. Gen Digital owns Norton, Avast, AVG, and Avira, indicating that these brands share threat intelligence and engineering resources.
The 2026 Mac Antivirus Scorecard ranks Bitdefender highest with a score of 8.8, followed by Intego (8.2), Malwarebytes (8.3), ESET (8.3), and Norton (7.4). Pricing structures often include discounted first-year rates that can double upon renewal. Free options include Avast and Avira with real-time protection, while Malwarebytes offers a free on-demand scanner. Multi-device licensing can provide better value, and business Macs should use business licenses for essential features.
macOS has built-in protections like XProtect and Gatekeeper, but third-party antivirus solutions can enhance security against newer threats.
Microsoft is offering Windows 11 Pro for .97, reduced from its standard retail price of 9. This promotional offer is valid until September 27 and provides a lifetime license for a single compatible PC, with no recurring subscription fees. Windows 11 Pro includes features such as BitLocker for full-disk encryption, Hyper-V for running virtual machines, and Windows Sandbox for secure application testing. It supports Azure AD for identity management, offers Snap layouts for multitasking, and includes DirectX 12 Ultimate for enhanced gaming performance. The license is non-transferable, tied to the original PC, and is a digital purchase with no physical product shipped. Users should verify compatibility with Microsoft's PC Health Check app before purchasing.
Windows 11 will introduce a feature for automatic switching between dark mode and light mode, as revealed by the Windows Insider program. This functionality will allow users to schedule transitions based on geographical location and specific times, with the mode changing only when the PC is idle to avoid disruptions during work or meetings. The feature aims to eliminate the need for third-party applications for theme management.
Recent investigations have identified the BlueMoon exploit kit, used by espionage-driven threat activity clusters, particularly linked to APT31, a China-aligned state-sponsored group, since August 28, 2026. BlueMoon exploits three vulnerabilities: CVE-2026-85046 (a type confusion vulnerability in Google Chrome's V8 engine), an unassigned V8 sandbox escape, and CVE-2026-85880 (a heap-based buffer overflow in Windows ALPC). Google and Microsoft have released patches for these vulnerabilities, which were exploited as "patch-gap" zero-days.
The attack vectors typically begin with phishing emails that lead victims to malicious URLs, triggering the vulnerabilities for code execution and privilege escalation. Variants of BlueMoon have been detected, featuring modifications for specific campaigns. Notable attack chains include:
- APT31 targeting NGOs and mining firms in the U.S. with a malicious browser add-on called GemStone.
- UNK_LateNight targeting U.S. aerospace companies, deploying BlueMoon alongside the ShadowPad backdoor.
- UNK_DoubleCheck targeting a Vietnamese manufacturer, using DLL sideloading to execute a Rust binary.
- UNK_QuietRacket targeting government and financial organizations in Indonesia and Singapore, modifying BlueMoon to execute a .NET assembly.
CISA added the Chrome flaw to its Known Exploited Vulnerabilities catalog on September 4, 2026, requiring federal agencies to apply patches by September 18, 2026. Indicators of compromise include specific process trees, files, folders, scheduled tasks, mutexes, and registry keys. Proofpoint has released detection rules to help organizations identify and mitigate these threats.
Cybercriminals are using advanced Android malware that mimics banking applications within hidden Work Profiles to bypass traditional fraud detection systems. This method is linked to Gigabud, a Remote Access Trojan active since at least 2022, and Vwork, an application cloning tool based on open-source software. Attackers distribute phishing links via social media and messaging, tricking victims into installing malicious files disguised as legitimate utilities.
Once installed, the malware seeks Accessibility permissions and other capabilities to capture screen credentials and control the device. Vwork creates an isolated Work Profile to duplicate banking apps, allowing attackers to conduct fraudulent transactions without triggering security alerts in the personal space. Instances of counterfeit financial applications operating from these isolated environments have been documented, particularly in Indonesia.
Between February and July 2026, monitoring revealed around 1,469 compromised devices and 1,281 compromised account credentials in Indonesia, resulting in estimated financial losses of 8.2 crore rupees. The operation is believed to be part of a larger international campaign linked to GoldFactory, with malware targeting users in multiple countries including Brazil, Colombia, Egypt, and others.
Security experts warn that unusual Work Profile installations, duplicated banking apps, and unexpected requests for Accessibility permissions indicate a compromised device. Users are advised against sideloading APK files from private messages and should limit sensitive permissions to verified applications. Researchers emphasize the need for financial institutions to adopt behavioral analysis to detect unauthorized transactions effectively.
The Zonko Android 16 Tablet is currently available at Walmart for a 55% discount, priced at $— down from its original price of $—. It features a 10-inch 1280×800 HD IPS display, dual speakers, an 8MP front camera, and a 13MP rear camera. The tablet runs on the Android 16 operating system, has 12GB of RAM, and 64GB of internal storage (expandable up to 512GB). It includes a 6000 mAh battery with a lifespan of 32 to 48 hours, and dual-band 2.4G/5G WiFi. The purchase comes with an accessory bundle including a Bluetooth keyboard, mouse, stylus pen, screen protector, protective case, and charger. The tablet supports Google Mobile Services and is pre-installed with Google Play. It is noted for its affordability and quality, although it has a limited number of reviews and does not support Apple apps.
The Gigabud Android banking trojan can clone banking applications into a separate Android work profile, allowing fraudsters to bypass malware alerts during transactions. Research by Group-IB, released on September 9, indicates that Gigabud is used with Vwork, a modified app for cloning, attributed to the GoldFactory group. The infection has been confirmed in Indonesia but targets 11 countries, including Brazil, Colombia, Egypt, Mexico, Thailand, and Turkiye. Vwork uses Android's Work Profile feature to isolate cloned apps, making them less detectable. This allows operators to install malware, clone banking apps, and execute transactions without raising alarms. During fraud, fake login screens capture credentials, and an invisible overlay collects lock screen codes. From February to July 2026, 1,469 devices were compromised in Indonesia, with financial losses nearing 0,939. Gigabud spreads through phishing and social media, requesting permissions to control devices. Group-IB identified six behavioral signals for banks to monitor as indicators of high-risk sessions. Recommendations include device binding and downloading apps only from official stores.
Walmart is offering a limited-time Flash deal on the Zonko Android 16 Tablet, reducing its price by 55% from its original price of 0 to 5. The tablet features a 10-inch 1280×800 HD IPS display, Android 16 operating system, dual speakers, an 8MP front camera, and a 13MP rear camera. It includes 12GB of RAM, 64GB of storage (expandable up to 512GB), and a 6000 mAh battery with a lifespan of 32 to 48 hours. The purchase comes with an accessories bundle that includes a Bluetooth keyboard, mouse, stylus pen, screen protector, protective case, and charger. The tablet supports Google Mobile Services and is pre-installed with Google Play. It has parental controls for safety and dual-band 2.4G/5G WiFi for stable internet connectivity.