Critical zero-days hit Defender and WeChat as TSMC revenue surges on AI demand
Multiple high-severity vulnerabilities surface across Windows, WeChat, and messaging apps while TSMC posts record monthly revenue and Windows 11 restores taskbar flexibility.
The TechMap Live reporter · · 2 min read · from 10 reports

Listen to this briefing
About 1 min to listen
Read the transcript
Good morning. Overnight the vulnerability landscape got a lot noisier. Researchers dropped a wormable remote code execution flaw in WeChat on both iOS and Android, calling it WeWorm, and a separate zero-day named ShieldCrash is handing attackers full system rights on Windows machines that already have the September patches installed. That one goes straight after Microsoft Defender. On top of that, Check Point found a serious issue linking ChatGPT and Gmail accounts, Vienna researchers can pinpoint WhatsApp and Signal users by phone number alone, and CISA just added four actively exploited flaws from Fortinet, Citrix, Cisco and Chrome to its must-patch list. The Fortinet bug shows up in live PivotC2 attacks months after its January patch. Meanwhile TSMC posted sixteen point three billion dollars in August revenue, up over fifty percent year on year on AI chip demand, and IBM with Lockheed Martin opened a quantum hub at ETH Zurich around Switzerland's first IBM Quantum Computer. Closer to home, Windows 11 finally lets you drag the taskbar to any screen edge again after five years, and in Poland a four hundred fifty kilogram mobile launcher for the Koral anti-ballistic system rolled out at the MSPO show. That's the picture today — patches, patches, and a few bright spots in hardware.
Critical vulnerabilities surface
Security researchers disclosed a wormable remote code execution flaw in WeChat for iOS and Android dubbed WeWorm, discovered by Calif engineers using AI-assisted analysis. Separately, a zero-day exploit named ShieldCrash grants full system privileges on Windows machines even with September 2026 patches applied, targeting Microsoft Defender directly.
Check Point Research found a serious vulnerability in the ChatGPT-Gmail integration that could link independent accounts and transfer data between them. Researchers at Vienna University also uncovered a flaw in WhatsApp and Signal allowing precise user location tracking via phone number alone.
CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities list, covering Fortinet, Citrix, Cisco, and Chrome. The Fortinet memory heap buffer overflow CVE-2025-25249 appears in both the CISA list and active PivotC2 RAT attacks, patched in January 2026 but still exploited months later.
AI chips and quantum computing advance
TSMC reported August revenue of about sixteen point three billion dollars, a fifty-three point three percent year-over-year increase driven by AI chip demand from its Hsinchu headquarters. The monthly figure underscores sustained appetite for advanced semiconductor manufacturing capacity.
IBM and Lockheed Martin established a quantum innovation hub at ETH Zurich anchored by Switzerland's first IBM Quantum Computer. The hub was created through an offset agreement with armasuisse, signaling continued government and defense investment in quantum research infrastructure.
Software updates and defense demo
Microsoft reintroduced the ability to move the Windows 11 taskbar to different screen edges in the September 2026 update, restoring a feature absent for five years. The change addresses long-standing user requests for multi-monitor flexibility.
At the MSPO defense exhibition in Kielce, Poland, a self-propelled launch platform for the Koral anti-ballistic missile system was demonstrated. The mobile platform weighs four hundred fifty kilograms and incorporates three guidance levels for intercept operations.
Questions people ask
Which vulnerabilities are actively being exploited right now?
CISA confirmed active exploitation of Fortinet CVE-2025-25249, Citrix, Cisco, and Chrome flaws. The Fortinet vulnerability is also being used in PivotC2 RAT attacks. ShieldCrash is a zero-day actively targeting Microsoft Defender on patched systems.
What makes the WeChat WeWorm vulnerability significant?
It is a wormable remote code execution flaw affecting both iOS and Android versions of WeChat, discovered through AI-assisted research by Calif engineers. Wormable means it can spread automatically between devices without user interaction.
How large was TSMC's August revenue increase?
TSMC reported about sixteen point three billion dollars in August revenue, representing a fifty-three point three percent increase compared to the same month last year, driven by AI chip demand.
The events in this briefing
Every event summarised above, in the order it was reported. Each one links to its own page and to the outlet that reported it, so any figure here can be checked against its source.
- Calif researchers disclose WeWorm RCE vulnerability in WeChat for iOS and Android · Habr News
- Windows 11 taskbar now movable across screens · 3DNews
- IBM and Lockheed Martin establish quantum innovation hub at ETH Zurich · The Quantum Insider
- ShieldCrash zero-day exploit targets Microsoft Defender · SecurityWeek
- TSMC August revenue surges 53.3% to $16.3 billion on AI demand · 3DNews
- Check Point Research discovers vulnerability in ChatGPT-Gmail integration · CNews
- Fortinet code execution flaw exploited in PivotC2 RAT attacks · SecurityWeek
- WhatsApp and Signal location tracking vulnerability discovered · Habr News
- Koral mobile launch platform demonstrated at MSPO in Kielce · ITC.ua
- CISA adds four actively exploited vulnerabilities to KEV list · iThome Taiwan
This briefing was written by an automated reporter from 10 event reports already published on this site. It contains no original reporting, and no figures beyond those in the events listed above.
More briefings
- Robotics surge and new tech launches as September events stack up
- Tech map update: payment shifts, AI labs, and cyber alerts
- Tech update: AI defence, phone teardowns and security alerts
- Tech updates: Apple foldable yield, crypto theft, and security patches
- AI security tests and software updates shape tech week