September 9, 2026
One Phone Call, Zero Clicks: A WeChat Worm Crossed iOS and Android
WeWorm, a zero-click worm on WeChat that spreads across iOS and Android without user interaction, has been reported to Tencent and mitigated. Microsoft released a record-breaking 974 patches on Patch Tuesday, including two actively exploited Windows privilege-escalation zero-days (CVE-2026-81963 and CVE-2026-85880), while Adobe shipped an emergency fix for StyleSmuggler (CVE-2026-75650), a Magento zero-day exploited since September 4. Chinese AI companies including DeepSeek, Alibaba, and MiniMax have been conducting industrial-scale model distillation of Claude, GPT, Gemini, and Grok since late 2024 via native APIs and gray-market proxies, according to NSA, CISA, and FBI. Check Point disclosed a prompt-injection vulnerability in ChatGPT Thinking mode that allowed planted instructions to redirect tasks to a hidden mailbox, read the victim's Gmail, and exfiltrate data across code-execution sandboxes.