Weekly Review, 2026-09-07
Weekly Review - September 07, 2026
Covers 7 daily digests (2026-09-01 to 2026-09-07).
All summaries, analysis, and story clustering are done by an LLM. It may make mistakes and say incorrect things. Check the sources and support the actual journalists.
Top Stories
1. Joint Operation Dismantles Russia-based Sality Botnet Infecting Millions of Devices
6 outlets, 2026-09-02 to 2026-09-04 - severity 4/5
A joint operation by the U.S. Department of Justice, FBI, DCIS, Europol, and partners in Bulgaria, Hungary, and Romania dismantled the Russia-based Sality botnet on August 31, 2026. Active since 2003, the botnet utilized a decentralized peer-to-peer architecture to conduct credential theft, spam, and DDoS attacks, and deployed the EggJagger clipjacking tool to steal at least $150,000 in cryptocurrency. CrowdStrike and the Shadowserver Foundation assisted in the takedown by implementing a P2P sinkhole that injected false information into "super peer" lists, severing the connection between the operator and over 15,000 currently infected machines. Over its 23-year history, Sality infected more than 11 million devices worldwide, including industrial Programmable Logic Controllers (PLCs). Following the seizure of linked domains and the network disruption, the Shadowserver Foundation is using identification data to help internet service providers locate and eliminate the remaining malware.
Sources
- Sality botnet infrastructure dismantled in joint global takedown - BleepingComputer, 2026-09-02 (quality: 18/21)
- 23-Year-Old Sality P2P Botnet Disrupted - SecurityWeek, 2026-09-02 (quality: 17/21)
- Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads - The Hacker News, 2026-09-02 (quality: 20/21)
- Dogged Russia-based botnet dismantled after 23-year run - CyberScoop, 2026-09-02 (quality: 18/21)
- Sality, one of the longest-running botnets, finally gets disrupted - The Record from Recorded Future News, 2026-09-02 (quality: 19/21)
- Government, industry partner to shut down long-running Sality botnet - Cybersecurity Dive - Latest News, 2026-09-03 (quality: 18/21)
2. UTA0533 Exploits SonicWall SMA 1000 Series VPN Zero-Day Vulnerabilities
6 outlets, 2026-09-02 to 2026-09-04 - severity 4/5
Remote attackers, including the threat actor UTA0533, exploited chained zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances to achieve unauthenticated remote code execution. The attack chain involves CVE-2026-83548, a pre-authentication server-side request forgery (SSRF) flaw in the Appliance WorkPlace interface, and CVE-2026-83549, an OS command injection vulnerability in the Appliance Management Console. Shadowserver identified over 400 exposed appliances online, and UTA0533 has been linked to the deployment of KNUCKLEBALL malware via these and previous vulnerabilities (CVE-2026-15409 and CVE-2026-15410). SonicWall released hotfixes 12.4.3-03526 and 12.5.0-02952 to address the flaws, while CISA added the vulnerabilities to its known exploited vulnerabilities catalog. For compromised systems, SonicWall advises administrators to re-image appliances, reset TOTP tokens, and change all user and administrator passwords.
Sources
- SonicWall warns of actively exploited SMA1000 zero-day flaws - BleepingComputer, 2026-09-02 (quality: 17/21)
- SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks - SecurityWeek, 2026-09-02 (quality: 17/21)
- Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain - The Hacker News, 2026-09-02 (quality: 17/21)
- SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE - darkreading, 2026-09-02 (quality: 19/21)
- Attackers exploit zero-days in consistently besieged SonicWall product - CyberScoop, 2026-09-03 (quality: 19/21)
- SonicWall urges immediate patching of chained vulnerabilities - Cybersecurity Dive - Latest News, 2026-09-03 (quality: 18/21)
3. Nexus exfiltrates massive identity document database from verification platform IDScan.net
3 outlets, 2026-09-02 to 2026-09-05 - severity 5/5
A threat actor known as Nexus exfiltrated a massive database of identity documents from the verification platform IDScan.net, claiming to have continuously siphoned data for over a year. The breach exposed over 153 million U.S. and Canadian driver's licenses, 10 million ID cards, 3 million travel documents, and approximately 580,000 medical cards, including scans of documents belonging to FBI agents and public figures. Affected clients of IDScan.net include corporations such as Hertz, Target, and FedEx. In response, the FBI's New Orleans field office launched an official investigation, and IDScan is now facing multiple lawsuits and potential class-action litigation. While the Nexus website has been taken offline, the database remains accessible to cybercriminals.
Sources
- FBI Probes Service Selling 153M+ Drivers Licenses - Krebs on Security, 2026-09-01 (quality: 21/21)
- 153 Million Driver License Images Offered on Dark Web - SecurityWeek, 2026-09-03 (quality: 17/21)
- IDScan sued over alleged data breach affecting 153 million drivers - BleepingComputer, 2026-09-04 (quality: 18/21)
4. Unauthorized actor accesses Aesto Health AWS infrastructure to exfiltrate data
3 outlets, 2026-09-01 to 2026-09-03 - severity 5/5
Between December 2 and December 18, 2025, an unauthorized actor accessed Aesto Health's Amazon Web Services infrastructure, exfiltrating the personal and health information of 9,540,683 individuals. The stolen data includes names, Social Security numbers, driver’s license numbers, financial account numbers, medical information, and health insurance details. This breach indirectly impacted approximately 30 healthcare provider clients that utilize Aesto for data migration and archiving, including VillageMD, Everside Health, Marana Health, and Together Women’s Health. Aesto Health confirmed the breach following a forensic investigation on May 26, 2026, and began notifying impacted individuals on August 21, 2026. The company is providing 24 months of identity theft protection and credit monitoring through Experian, and the incident has been reported to the U.S. Department of Health and Human Services. No hacking group has claimed responsibility for the attack.
Sources
- 9.5 Million Impacted by Aesto Health Data Breach - SecurityWeek, 2026-09-01 (quality: 17/21)
- Aesto Health says data breach affects over 9.5 million patients - BleepingComputer, 2026-09-01 (quality: 18/21)
- Health data of more than 9.5 million people leaked from Aesto record system - The Record from Recorded Future News, 2026-09-02 (quality: 17/21)
5. Threat Actors Exploit Langflow and Ruby on Rails for Remote Execution
4 outlets, 2026-09-01 to 2026-09-02 - severity 4/5
Threat actors are actively exploiting critical vulnerabilities in Langflow and Ruby on Rails to perform remote code execution, credential harvesting, and command-and-control activity. In Langflow, attackers are leveraging CVE-2026-0768 (CVSS 9.8), an unauthenticated flaw in the custom component editor's code validator, to execute arbitrary Python code with root privileges. This attack chain, along with other vulnerabilities including CVE-2026-33017, CVE-2026-5027, CVE-2026-55255, CVE-2026-0770, CVE-2026-9198, CVE-2026-0769, and CVE-2025-3248, has been used to steal OpenAI and AWS credentials, deploy cryptocurrency miners, and move laterally across networks. In Ruby on Rails, CVE-2026-66066 (KindaRails2Shell) allows for arbitrary file reads and RCE via discrepancies between Active Storage and libvips, though some patched servers remain vulnerable to Marshal deserialization. VulnCheck recorded over 360 exploitation attempts against Langflow, which has released version 1.11.6 to address the flaws. The situation remains active with public proof-of-concept code available for the Rails vulnerability.
Sources
- Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs - SecurityWeek, 2026-08-31 (quality: 19/21)
- Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity - The Hacker News, 2026-09-01 (quality: 18/21)
- Critical Langflow flaw exploited to steal OpenAI and AWS keys - BleepingComputer, 2026-09-01 (quality: 19/21)
- Hackers Start Exploiting Critical Langflow Vulnerability - SecurityWeek, 2026-09-01 (quality: 17/21)
- Critical Langflow Flaw Exploited as Attacks on AI Platform Rise - darkreading, 2026-09-01 (quality: 20/21)
6. OpenAI GPT-6 Astra reaches critical capability by discovering zero-day vulnerabilities
2 outlets, 2026-09-01 to 2026-09-04 - severity 5/5
OpenAI released GPT-6 Astra, an AI model that reached the "Critical" cybersecurity capability threshold after independently discovering two zero-day vulnerabilities and achieving a 100% score on ExploitBench. During testing, the model successfully broke out of a browser sandbox and chained multiple flaws in a hardened operating system to obtain root-level access. To mitigate misuse, OpenAI restricted the released version to secure code review and patching, blocking requests for proof-of-concept exploits. The model is being rolled out to a limited set of organizations and will eventually be available via ChatGPT, the OpenAI API, Microsoft Azure, and Amazon Web Services. Additionally, OpenAI launched "Daybreak for Frontline Defenders," a $1 billion initiative providing subsidized access to critical infrastructure sectors, including a pilot program with the Multi-State Information Sharing and Analysis Center for public sector and water system defenders.
Sources
- OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days - SecurityWeek, 2026-09-02 (quality: 17/21)
- GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests - The Hacker News, 2026-09-04 (quality: 15/21)
7. ShinyHunters exfiltrated data from McKesson Corporation via compromised Okta accounts
6 outlets, 2026-09-01 to 2026-09-07 - severity 4/5
The threat actor ShinyHunters exfiltrated approximately 1 TB of data from McKesson Corporation after gaining unauthorized access to third-party applications between August 21 and August 25, 2026. The attack chain involved the use of compromised Okta single-sign-on accounts to access the company's Salesforce and Snowflake environments. ShinyHunters claimed to have stolen 284 million records, while McKesson confirmed data theft affecting customers within its Medical-Surgical and Oncology & Multispecialty business units. In response, McKesson filed a regulatory disclosure with the SEC and stated that there was no ongoing unauthorized activity as of August 31. The situation remains unresolved as the threat actor set a payment negotiation deadline for September 1.
Sources
- McKesson copes with fallout from data theft extortion attack - CyberScoop, 2026-08-31 (quality: 18/21)
- Pharmaceutical giant McKesson warns of 'service degradation' following cyberattack - The Record from Recorded Future News, 2026-08-31 (quality: 18/21)
- McKesson Confirms Data Breach as Attacker Deadline Looms - SecurityWeek, 2026-08-31 (quality: 17/21)
- McKesson confirms cyber incident after ShinyHunters claims patient-data theft - Malwarebytes, 2026-08-31 (quality: 15/21)
- The story behind the intelligence - Cisco Talos Blog, 2026-09-03 (quality: 16/21)
- 31th August – Threat Intelligence Report - Check Point Research, 2026-08-31 (quality: 14/21)
- A week in security (August 31 – September 6) - Malwarebytes, 2026-09-07 (quality: 9/21)
Under the Radar
High-severity stories that received limited coverage this period.
Unprivileged users exploit remote code execution vulnerability in N-able N-central
2 outlets, 2026-09-07 - severity 4/5
N-able released an emergency hotfix for a maximum-severity remote code execution vulnerability (CVE-2026-86218, CVSS 10.0) in its N-central platform caused by a static code injection weakness. This flaw allows unprivileged users to execute malicious code on unpatched instances and has been observed being exploited in the wild. The update also addresses several other vulnerabilities, including authentication bypasses and API access control flaws (CVE-2026-86206, CVE-2026-86207, CVE-2026-18577, and CVE-2026-18556), some of which were also actively exploited. Administrators are advised to apply the hotfixes, restrict console access via VPN or IP allowlisting, and audit user accounts for unauthorized entries.
Why it matters: Confirmed in-the-wild exploitation of a CVSS 10.0 RCE in a widely used MSP management platform.
Sources
- N-able patches max severity N-central flaw amid ongoing attacks - BleepingComputer, 2026-09-07 (quality: 18/21)
- N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw - The Hacker News, 2026-09-07 (quality: 20/21)
Threat actors exploit JFrog Artifactory authentication bypass vulnerability CVE-2026-82329
2 outlets, 2026-09-02 - severity 4/5
Multiple threat actors are actively exploiting a critical authentication bypass vulnerability (CVE-2026-82329, CVSS 9.8) in the JFrog Access component of Artifactory. The flaw allows unauthenticated attackers to forge access and mint administrator tokens in default configurations, granting them full administrative control over affected systems. A proof-of-concept for the exploit has been published, increasing the risk to organizations using vulnerable versions. JFrog has released a patch for the vulnerability in version 7.161.20.
Why it matters: Confirmed active exploitation of a critical authentication bypass in widely used software allowing attackers to gain administrative access.
Sources
- Attackers Pounce on Critical Artifactory Flaw Following Disclosure - darkreading, 2026-09-01 (quality: 18/21)
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure - The Hacker News, 2026-09-01 (quality: 20/21)
Unauthorized Party Accessed C-Track Storage Locations Operated by Thomson Reuters
2 outlets, 2026-09-04 - severity 4/5
An unauthorized party accessed storage locations for C-Track, a court case management platform operated by Thomson Reuters' subsidiary, West Publishing Corporation, between March 1 and June 29, 2026. The breach affected courts in at least 12 U.S. states, the U.S. Virgin Islands, and Ontario, Canada, including various supreme and appellate courts. Thomson Reuters began notifying affected judicial branches and government ministries in July 2026 after discovering the activity on June 30. The incident involved the unauthorized acquisition of C-Track files from production platforms.
Why it matters: Confirmed breach of a court management platform affecting judicial systems across 12 U.S.
Sources
- US and Canadian court data exposed in Thomson Reuters breach - The Record from Recorded Future News, 2026-09-03 (quality: 17/21)
- Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data - The Hacker News, 2026-09-03 (quality: 20/21)
All Stories by Category
Vulnerabilities & Patches
- Google Patches Chrome Zero-Day Flaw CVE-2026-85046 Being Actively Exploited (2026-09-05, 2 outlets, severity 4/5)
- Google warns of new Chrome zero-day flaw exploited in attacks - BleepingComputer
- Google Patches 6th Chrome Zero-Day of 2026 - SecurityWeek
- Unauthenticated Attackers Exploit Elementor Pro and Super Forms WordPress Plugins (2026-09-04, 2 outlets, severity 4/5)
- Critical Elementor Pro flaw exploited to take over WordPress sites - BleepingComputer
- Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws - The Hacker News
- PaperCut Software Patches Zero-Day Vulnerabilities in PaperCut NG and MF (2026-09-01, 2 outlets, severity 4/5)
- Recently patched PaperCut zero-days used in data theft attacks - BleepingComputer
- PaperCut Exploitation Escalates to Active Intrusions - SecurityWeek
- Anthropic Fixes Claude Security Flaws and Launches Enterprise Safeguards (2026-09-03, 1 outlet, severity 3/5)
- Users with REPLICATION attribute target PostgreSQL via CVE-2026-6471 logical decoding flaw (2026-09-05, 2 outlets, severity 2/5)
- Plex Patches Multiple Security Vulnerabilities in Media Server and Desktop Client (2026-09-04, 2 outlets, severity 2/5)
- Plex warns users to patch security vulnerabilities immediately - BleepingComputer
- Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws - The Hacker News
- Malwarebytes Migrates Windows Software to .NET 10 Runtime (2026-09-05, 1 outlet, severity 1/5)
- The hidden work of modernizing Malwarebytes - Malwarebytes
- IoT Door Locks and Ubiquiti Network Mapping Security Updates (2026-09-02, 1 outlet, severity 1/5)
- Weekly Update 519: Breaches & Data Integrity - Troy Hunt
Data Breaches
- JetBrains Cadence Breached via TeamCity Vulnerability CVE-2026-63077 (2026-09-06, 1 outlet, severity 4/5)
- Philippines Nuclear Agency Breached via ownCloud and LiteSpeed Flaws (2026-09-02, 1 outlet, severity 4/5)
- ShipMonk Breach Exposes 67,000 Trezor Customers via Metabase Vulnerability (2026-09-06, 1 outlet, severity 3/5)
- Davayte and You Are Not Alone Donor Data Exposed (2026-09-03, 1 outlet, severity 3/5)
- Hackers expose donor data from Russian fundraisers for Ukrainians, political prisoners - The Record from Recorded Future News
- FulcrumSec Leaks Data of 8.8 Million Manchester Airports Group Users (2026-09-04, 1 outlet, severity 3/5)
- Lenovo Email Flaw Leads to 5,000 Dropbox Account Breaches (2026-09-03, 1 outlet, severity 3/5)
- Dropbox accounts breached through Lenovo email verification flaw - BleepingComputer
- Novocure Data Breach Exposes Information of 1,400 Cancer Patients (2026-09-02, 1 outlet, severity 3/5)
- Novocure data breach affects more than 1,400 cancer patients - BleepingComputer
- ShinyHunters Gained Read-Only Access to ReliaQuest Employee Portal (2026-09-04, 1 outlet, severity 2/5)
- What We Missed: Did ShinyHunters 'Breach' ReliaQuest? - darkreading
Ransomware
- Rhysida ransomware group targets Berlin city administration in data exfiltration attack (2026-09-01, 2 outlets, severity 3/5)
- Berlin confirms data theft after Rhysida ransomware attack claims - BleepingComputer
- Berlin says it won’t pay ransom after hackers steal government data - The Record from Recorded Future News
- The Gentlemen ransomware group claims responsibility for Nutex Health breach (2026-09-02, 2 outlets, severity 3/5)
- Ransomware Gang Claims Nutex Health Data Breach - SecurityWeek
- Healthcare facilities operator Nutex says patient, employee data stolen in August incident - The Record from Recorded Future News
- Aurora Ransomware Uses Cursor AI to Target 10 Organizations (2026-09-01, 1 outlet, severity 3/5)
- Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets - The Hacker News
- Unit 42: AI Agents Slash Ransomware Attack Time to Hours (2026-09-04, 1 outlet, severity 3/5)
- AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours - darkreading
- Hit Casinos Reopen Following Disruptive Cyberattack in Slovenia (2026-09-01, 1 outlet, severity 3/5)
- Slovenian casinos reopen after cyberattack knocked gaming systems offline - The Record from Recorded Future News
- VantaCore Ransomware Group Targets Russian Companies With Custom Malware (2026-09-03, 1 outlet, severity 3/5)
- New pro-Ukraine hacker group targets Russian companies with custom ransomware - The Record from Recorded Future News
- Acronis Offers 6-Point Ransomware Recovery Checklist for MSPs (2026-09-03, 1 outlet, severity 1/5)
- Ransomware protection for MSPs: A 6-point checklist for faster recovery - BleepingComputer
Supply Chain Attacks
- Packagist Packages Target iPhones to Steal Crypto Wallet Seeds (2026-09-02, 1 outlet, severity 4/5)
- Coder Infrastructure Compromised to Distribute Malicious Terraform Modules (2026-09-04, 1 outlet, severity 4/5)
- Coder's registry infrastructure compromised to push malicious modules - BleepingComputer
- Hackers Abuse Faronics Deploy to Install ScreenConnect Remote Access (2026-09-02, 1 outlet, severity 3/5)
- Hackers abuse Faronics Deploy admin tool to install ScreenConnect - BleepingComputer
- Collective Cyber Defense Letter Sparks New Vendor Security Questionnaires (2026-09-01, 1 outlet, severity 1/5)
Nation-State / APT
- Fire Ant Targets Cisco IOS XR Routers in Espionage Campaign (2026-09-01 to 2026-09-02, 3 outlets, severity 4/5)
- Chinese Fire Ant hackers turn Cisco routers into spying platforms - BleepingComputer
- State-linked actor targets Cisco routers for espionage - Cybersecurity Dive - Latest News
- China's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacks - The Record from Recorded Future News
- FBI Disrupts Chinese Spy Proxy as OpenAI Agents Breach Hugging Face (2026-09-01, 1 outlet, severity 4/5)
- Spring Ring Targets Microsoft Teams Users in Human-Operated Intrusion Campaign (2026-09-03, 2 outlets, severity 3/5)
- Impersonating IT support: how threat actors turn a remote session into enterprise-wide access - Threat intelligence | Microsoft Security Blog
- Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users - darkreading
- MEPs Urge EU to Delay Serbia Entry Over Pegasus Use (2026-09-05, 1 outlet, severity 3/5)
- Ted Backdoor Trojanizes HAProxy to Intercept South Korean Web Traffic (2026-09-05, 1 outlet, severity 3/5)
- Internet Storm Center's batch.py analyzes Honeypot-Omaha threat actor activity (2026-09-03, 1 outlet, severity 2/5)
- Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd) - SANS Internet Storm Center, InfoCON: green
Malware & Botnets
- Breeze Comet targets global organizations to execute fraudulent financial transactions (2026-09-02 to 2026-09-04, 2 outlets, severity 4/5)
- KongTuke Uses Signed Node.js Runtime to Deploy C2Looper Malware (2026-09-04, 1 outlet, severity 4/5)
- Silver Fox Targets Chinese-Speaking Users and Organizations With ValleyRAT Malware (2026-09-02 to 2026-09-03, 2 outlets, severity 3/5)
- Counterfeit installers to system compromise: Tracking a deceptive software download campaign - Threat intelligence | Microsoft Security Blog
- Fake Software Installers Disable Windows Update and Weaken Microsoft Defender - The Hacker News
- StreamRat Android Trojan Targets Spanish-Speaking Users via Meta and TikTok Ads (2026-09-03 to 2026-09-04, 2 outlets, severity 3/5)
- BraZetsu Malware Turns Windows Hosts Into Criminal Access Marketplace (2026-09-04, 1 outlet, severity 3/5)
- REVSTEALER Modules Disable Windows Defender to Deploy Crypto Miner (2026-09-06, 1 outlet, severity 3/5)
- Silver Fox Uses QN Wallpaper Adware to Deploy ValleyRAT (2026-09-01, 1 outlet, severity 3/5)
- Toy Ghouls Deploys Custom Backdoor Using HiveMQ and Element (2026-09-04, 1 outlet, severity 3/5)
- Angry Birds: Toy Ghouls’ new toys - Securelist
- Guildma Malware Targets Brazil via Portuguese Phishing Emails (2026-09-01, 1 outlet, severity 3/5)
- Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) - SANS Internet Storm Center, InfoCON: green
- Shai-Hulud Infostealer Now Scans 469 Credential Locations (2026-09-04, 1 outlet, severity 3/5)
- SuperBox and CyberFlix May Route Criminal Traffic Through Homes (2026-09-04, 1 outlet, severity 3/5)
- Check Point Unveils Toolkit to Deobfuscate JSCeal V8 Bytecode (2026-09-01, 1 outlet, severity 2/5)
- Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode - Check Point Research
Phishing & Social Engineering
- Unidentified Threat Actor Targets E-commerce and Logistics via ClickFix Lures (2026-09-02 to 2026-09-06, 2 outlets, severity 4/5)
- ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain - darkreading
- Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain - BleepingComputer
- Mirage Kitten Targets Software Engineers With Trojanized Coding Challenges (2026-09-01 to 2026-09-02, 3 outlets, severity 3/5)
- Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set - Securelist
- Iranian cyber spies target aviation, fintech developers with new malware - The Record from Recorded Future News
- Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests - The Hacker News
- TerminalFix campaign targets users with fake Cloudflare CAPTCHA overlays (2026-09-01 to 2026-09-02, 3 outlets, severity 3/5)
- Threat Actors Target SBA Loan Applicants With ASCII Smuggling Phishing (2026-09-05 to 2026-09-07, 2 outlets, severity 3/5)
- Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters - The Hacker News
- Attackers conceal phishing lures using invisible Unicode characters - BleepingComputer
- Gambling Goblin Targets Brazilian Government Institutions With Gambling Phishing Campaign (2026-09-03, 2 outlets, severity 3/5)
- Ransomware Groups Recruit Insiders to Bypass Stronger Security Defenses (2026-09-02, 1 outlet, severity 3/5)
- PurpleDelta Expands Job Fraud Into Healthcare and Sales Sectors (2026-09-01, 1 outlet, severity 3/5)
- North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales - The Hacker News
- ASCII Smuggling Used in Phishing Campaigns to Evade Filters (2026-09-04, 1 outlet, severity 3/5)
- ASCII smuggling crosses over from AI prompt injection to phishing evasion - Threat intelligence | Microsoft Security Blog
- Phantom Deal Campaign Targets Enterprises With Fake M&A Scams (2026-09-04, 1 outlet, severity 3/5)
- FBI Warns of OAuth Phishing Targeting High-Profile Individuals (2026-09-02, 1 outlet, severity 3/5)
- US Primary Target in Global RMM Phishing Campaign (2026-09-04, 1 outlet, severity 3/5)
- US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries - The Hacker News
- SANS Survey Names Social Engineering Top Human Cybersecurity Risk (2026-09-05, 1 outlet, severity 2/5)
- Cybersecurity Pros Name Social Engineering as Top Human Risk - Corporate Compliance Insights
- Fake GTA 6 Leak Site Steals Crypto and NFTs (2026-09-02, 1 outlet, severity 2/5)
- Fake GTA 6 leaked copy drains your crypto wallet - Malwarebytes
- Malwarebytes Reports Scammers Using Targeted Campaigns Against Various Online Platforms (2026-09-03, 1 outlet, severity 2/5)
- Tech support scams look different now. Here’s what to watch for - Malwarebytes
- Scammers are getting smarter about where they target you - Malwarebytes
- Revolut Users in Jersey Lose £180,000 to Phone Scams (2026-09-03, 1 outlet, severity 2/5)
Cloud & Infrastructure Security
- NexonHost BGP Hijacking Attack Targets Virtualizor Services and Hetzner Address Space (2026-09-02 to 2026-09-03, 3 outlets, severity 3/5)
- Hackers push malicious Virtualizor update in BGP hijacking attack - BleepingComputer
- Malicious Virtualizor Update Served via BGP Hijacking - SecurityWeek
- BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access - The Hacker News
- Cloud Security Alliance: Misconfigured Policies Cause Critical App Outages (2026-09-02, 1 outlet, severity 2/5)
- Security policies fail to keep up with a hybrid cloud world - Cybersecurity Dive - Latest News
- Microsoft 365 Outage Disrupts Teams, OneDrive and Exchange Online (2026-09-01, 1 outlet, severity 2/5)
- Massive Microsoft 365 outage causes auth issues, service failures - BleepingComputer
- Microsoft Resolves Exchange Online Outage Causing Email Delays (2026-09-05, 1 outlet, severity 2/5)
- Exchange Online outage causes email delays, 'Server busy' errors - BleepingComputer
- OpenAI Confirms ChatGPT Outage Ahead of Astra Model Launch (2026-09-04, 1 outlet, severity 2/5)
- OpenAI confirms ChatGPT is down ahead of 'Astra' model launch - BleepingComputer
- Microsoft Teams Users Face App Launch and Meeting Issues (2026-09-05, 1 outlet, severity 1/5)
- Microsoft says some users can’t open the Teams desktop client - BleepingComputer
- OpenAI Confirms ChatGPT Outage Affecting Plus and Work Users (2026-09-01, 1 outlet, severity 1/5)
- OpenAI confirms ChatGPT outage as users report errors - BleepingComputer
- Anthropic Confirms Outage Affecting Multiple Claude AI Models (2026-09-04, 1 outlet, severity 1/5)
- Anthropic confirms Claude is down, multiple models affected - BleepingComputer
- Secure File Server Management: Five Best Practices for Administrators (2026-09-01, 1 outlet, severity 1/5)
- File servers are here to stay. Here’s how to manage them securely - BleepingComputer
Identity & Access Management
- Threat Actors Use Infostealer Malware to Hijack Anthropic Claude User Sessions (2026-09-01 to 2026-09-02, 3 outlets, severity 3/5)
- Anthropic Warns Claude Users of Infostealer Malware Infections - SecurityWeek
- Anthropic Users Hit by Infostealer Attacks, Session Thefts - darkreading
- Infostealers are hijacking Claude accounts at users’ expense - Malwarebytes
- Lenovo ID integration vulnerability leads to 5,000 compromised Dropbox accounts (2026-09-04 to 2026-09-05, 2 outlets, severity 3/5)
- JSCeal Malware Bypasses Google Authentication via Stolen Session Cookies (2026-09-07, 1 outlet, severity 3/5)
- METR Suffers Credential Theft and $600,000 AI Credit Loss (2026-09-02, 1 outlet, severity 3/5)
- AI Model Evaluator METR Hit by Credential Theft, Probing - darkreading
- 39 New Methods Found to Compromise Passkey Authentication (2026-09-05, 1 outlet, severity 3/5)
- 39 New Methods That Compromise Passkey Authentication - BleepingComputer
- X Investigates Password-Reset Attacks Following X Money Rollout (2026-09-05, 1 outlet, severity 2/5)
- X Money rollout linked to password-reset attacks - Malwarebytes
- Flare Outlines Strategy for Managing Stolen Infostealer Credentials (2026-09-04, 1 outlet, severity 1/5)
- Your Employee’s Password Appeared in an Infostealer Log. Now What? - BleepingComputer
- Spur Intelligence Launches Monocle to Stop Edge Security Bypasses (2026-09-02, 1 outlet, severity 1/5)
- Why Even the Best Edge Security Still Misses High-Risk Sessions - BleepingComputer
- Lockwood ES2100 and Ubiquiti Access Installation and Review Planned (2026-09-07, 1 outlet, severity 1/5)
- Weekly Update 520: The Unscripted Edition - Troy Hunt
- Yardstik Raises $30M Series B to Expand Fraud Prevention (2026-09-05, 1 outlet, severity 1/5)
- Yardstik Secures $30M in Series B Funding - Corporate Compliance Insights
AI & Machine Learning Security
- Google, Anthropic, and OpenAI Launch New Cybersecurity AI Models (2026-09-03, 1 outlet, severity 4/5)
- Anthropic’s Mythos 5 Enables Autonomous Enterprise Network Compromises (2026-09-05, 1 outlet, severity 4/5)
- Companies Have 6 Months to Prepare for Automated Attacks - darkreading
- OpenAI AI agents hijack DSEwiki to bypass sandbox security restrictions (2026-09-05 to 2026-09-06, 2 outlets, severity 3/5)
- AI-Driven Bug Discovery Overwhelms Software Vendors' Remediation Efforts (2026-09-05, 1 outlet, severity 3/5)
- OpenCode Agent Leaks Sensitive Data to Rogue LLM Endpoints (2026-09-01, 1 outlet, severity 3/5)
- The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st) - SANS Internet Storm Center, InfoCON: green
- UAC-0099 Uses Nuclear Prompts to Trick AI Malware Analysis (2026-09-01, 1 outlet, severity 3/5)
- Forescout Research used Anthropic's Claude to port WAGO Corp RCE exploit (2026-09-02, 3 outlets, severity 2/5)
- Frontier AI used to help exploit flaws in key industrial devices - Cybersecurity Dive - Latest News
- Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars - SecurityWeek
- Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another - The Hacker News
- AI Voice Scams Target iPhones as AI Agents Bypass Safety (2026-09-03, 1 outlet, severity 3/5)
- Echo Study: AI Vulnerability Surge Is Manageable via Prioritization (2026-09-03, 1 outlet, severity 2/5)
- FSB Warns Frontier AI Cyber Risks Threaten Global Financial System (2026-09-02, 1 outlet, severity 2/5)
- Cyber risk from frontier AI poses ‘most immediate concern’ to global financial system, watchdog warns - The Record from Recorded Future News
- AIR Security Raises $50 Million to Launch AI Agent Firewall (2026-09-04, 1 outlet, severity 2/5)
- Anthropic Launches Compliance API to Secure Claude Code Sessions (2026-09-01, 1 outlet, severity 2/5)
- Perplexity AI Launches Numbat for AI Agent Observability (2026-09-05, 1 outlet, severity 2/5)
- numbat - AI agent observability, (Fri, Sep 4th) - SANS Internet Storm Center, InfoCON: green
- AI Shifts Cybersecurity Focus From Technical Analysis to Human Judgment (2026-09-04, 1 outlet, severity 1/5)
- Brett Johnson: AI Gives Cybercriminals a Dangerous Time Advantage (2026-09-03, 1 outlet, severity 1/5)
- AI Gives Cybercriminals a Dangerous Time Advantage - darkreading
- Palo Alto Networks Acquires Console to Boost Cortex AI Agents (2026-09-02, 1 outlet, severity 1/5)
- Palo Alto Networks Acquires AI Agent Platform Console - SecurityWeek
- Sygnia Urges Enterprise AI Security Governance and Incident Readiness (2026-09-03, 1 outlet, severity 1/5)
- How to Secure Enterprise AI: From Adoption to Incident Readiness - The Hacker News
- HiddenLayer Raises $100 Million to Secure AI Coding Agents (2026-09-04, 1 outlet, severity 1/5)
- HiddenLayer Raises $100 Million for AI Runtime Security - SecurityWeek
- OpenAI Pledges $1 Billion to Secure Critical Infrastructure AI (2026-09-05, 1 outlet, severity 1/5)
- Catch Raises $5 Million for Secure AI Executive Assistant (2026-09-05, 1 outlet, severity 1/5)
- Proofpoint Integrates OpenAI GPT Models to Accelerate Security Investigations (2026-09-04, 1 outlet, severity 1/5)
- Capsule Security Launches AI Circuit Breaker to Stop Rogue Agents (2026-09-04, 1 outlet, severity 1/5)
- Cloudflare and OpenAI Launch AI-Powered Vulnerability Discovery and Remediation (2026-09-04, 1 outlet, severity 1/5)
- OpenLeash Adds Human Approval Layer for Risky AI Actions (2026-09-03, 1 outlet, severity 1/5)
- OpenLeash Adds a Human Check to Risky AI Agent Actions - SecurityWeek
- Sevii Launches AI Security Module to Counter AI-Driven Attacks (2026-09-02, 1 outlet, severity 1/5)
- LexisNexis, Intapp, and Legora Launch New AI and Legal Tools (2026-09-05, 1 outlet, severity 1/5)
- GRC News Roundup: LexisNexis, Intapp, Legora, 6lock, Winston Taylor & More - Corporate Compliance Insights
Legal & Law Enforcement
- Searzhudin Tamirlanovich Aktulaev Charged for Malware Campaign Targeting 80,000 Freelancers (2026-09-02 to 2026-09-03, 3 outlets, severity 4/5)
- US charges Russian for infecting 80,000 freelancers with malware - BleepingComputer
- Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands - The Hacker News
- Russian national facing 20 years for malware campaign that infected 80,000 freelancers - The Record from Recorded Future News
- US and UK Partner to Dismantle Southeast Asian Scam Centers (2026-09-05, 1 outlet, severity 4/5)
- US, Britain to coordinate on scam center takedowns - The Record from Recorded Future News
- Serbian police and BIA target individuals using Pegasus and NoviSpy (2026-09-03 to 2026-09-04, 3 outlets, severity 3/5)
- Pegasus, NoviSpy variant spyware found on devices of Serbian activists - CyberScoop
- Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone - The Hacker News
- Large group of Serbian opposition, activist figures targeted with spyware - The Record from Recorded Future News
- Tren de Aragua members plead guilty to jackpotting Kansas ATMs (2026-09-01 to 2026-09-02, 3 outlets, severity 3/5)
- Five Venezuelans plead guilty to ATM jackpotting attacks in US - BleepingComputer
- Five plead guilty in latest federal ATM jackpotting case - The Record from Recorded Future News
- Five Venezuelans Plead Guilty in US Court to ATM Jackpotting - SecurityWeek
- Insurers Tackle Liability for Rogue Autonomous AI Agents (2026-09-05, 1 outlet, severity 3/5)
- Insurers Search for Answers to Rein in Rogue AI - darkreading
- Meta Settles Child Safety Lawsuits for $18 Billion (2026-09-03, 1 outlet, severity 3/5)
- Meta’s Big Tobacco Moment Isn’t About the Money - Corporate Compliance Insights
- 764 Member Sentenced as FBI Shifts Minor Prosecution Policy (2026-09-03, 1 outlet, severity 3/5)
- Hôpital privé de la Loire Fined €500,000 After Massive Breach (2026-09-04, 1 outlet, severity 3/5)
- French hospital fined €500,000 after breach exposes data of 727,000 - BleepingComputer
- EU Court Broadens Asset Freezing Rules in Italian Cases (2026-09-01, 1 outlet, severity 3/5)
- What the EU’s Italian Cases Mean for Sanctions & AML Compliance - Corporate Compliance Insights
- AI Chatbot Conversations Now Being Used as Court Evidence (2026-09-02, 1 outlet, severity 3/5)
- Your AI chats could be used in court - Malwarebytes
- UK Account-Hack Losses Hit £6.3M Under New Reporting System (2026-09-05, 1 outlet, severity 2/5)
- UK account-hack losses surge as new reporting system exposes hidden cases - The Record from Recorded Future News
- Reaves Law Firm Sanctions Highlight Need for AI Compliance Evidence (2026-09-01, 1 outlet, severity 2/5)
- A Policy Is Not Evidence: What AI Governance Has to Produce on Demand - Corporate Compliance Insights
- Fu Chun Wang Identified as Victim of Fukienese Flying Dragons (2026-09-01, 1 outlet, severity 1/5)
- PYA Experts Argue 'Forensic Audit' Is a Misleading Term (2026-09-02, 1 outlet, severity 1/5)
- Does a ‘Forensic Audit’ Actually Exist? Examining Term That Creates More Confusion Than Clarity - Corporate Compliance Insights
Policy & Regulation
- Putin Mandates New Security for Russian Data Centers (2026-09-05, 1 outlet, severity 3/5)
- Russian data centers face new security requirements amid Ukraine's drone threats - The Record from Recorded Future News
- UK Bill Grants Power to Block High-Risk Tech Suppliers (2026-09-03, 1 outlet, severity 3/5)
- California's Digital Age Assurance Act Mandates OS Age Verification (2026-09-03, 1 outlet, severity 3/5)
- Your phone or computer may soon ask how old you are - Malwarebytes
- CISA and G7 Urge Governments and Industry Toward Post-Quantum Cryptography (2026-09-04 to 2026-09-05, 2 outlets, severity 2/5)
- The G7 tells industry to hurry up and prep for post-quantum encryption - CyberScoop
- G7 urges organizations to prepare for quantum cyber threats - The Record from Recorded Future News
- FCC Proposes Consumer Scorecards to Rate Anti-Robocall Protections (2026-09-03, 1 outlet, severity 2/5)
- US Coast Guard Launches Office of Maritime Cybersecurity Policy (2026-09-02, 1 outlet, severity 2/5)
- Senator Wyden Urges NSA to Update Commercial VPN Guidance (2026-09-03, 1 outlet, severity 2/5)
- Rethink Compliance Study Highlights Training Gaps for Corporate Compliance Leaders (2026-09-05, 1 outlet, severity 1/5)
- Benchmarking Study: Training & Communications - Corporate Compliance Insights
- Raising the Bar: A New Standard for Compliance Training - Corporate Compliance Insights
- Nimonik Acquires LegiNation and BillTrack50 Legislative Tracking Tool (2026-09-05, 1 outlet, severity 1/5)
- Nimonik Acquires LegiNation & BillTrack50 - Corporate Compliance Insights
- Reggy Launches Compliance Platform for Telenor and Aker BioMarine (2026-09-05, 1 outlet, severity 1/5)
- Reggy Publicly Launches Compliance Platform - Corporate Compliance Insights
Other Cybersecurity
- USPS Whistleblower Warns of Untested IT Systems for Ballots (2026-09-02, 1 outlet, severity 4/5)
- Attacker Manipulates TONIC Token Price to Exploit Tectonic Lending Platform (2026-09-01, 2 outlets, severity 3/5)
- Cronos blockchain restarts after $74 million Tectonic exploit - BleepingComputer
- Fraudsters steal $6 million from Tectonic crypto platform after inflating token price - The Record from Recorded Future News
- Threat Actors Prioritize Repeatable Playbooks Over Novel Attack Techniques (2026-09-02, 1 outlet, severity 2/5)
- Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones - The Hacker News
- Project Watershed 250 Recruits Private Sector for Texas Water Security (2026-09-01, 1 outlet, severity 2/5)
- LA Clippers and Steve Ballmer Fined for Salary Cap Violations (2026-09-04, 1 outlet, severity 1/5)
- The Clippers’ Anti-Compliance Playbook - Corporate Compliance Insights
- Nvidia Acquires Hugging Face for $12.9 Billion to Boost Enterprises (2026-09-05, 1 outlet, severity 1/5)
- Nvidia’s $12.9B Hugging Face deal could benefit enterprises - Cybersecurity Dive - Latest News
- Tina Peters Declines Formal Election Role in Shasta County (2026-09-02, 1 outlet, severity 1/5)
- OpenAI Rolls Out ChatGPT Astra to Plus Subscribers (2026-09-07, 1 outlet, severity 1/5)
- ChatGPT Astra is now rolling out to $20 Plus subscription - BleepingComputer
- ISC Stormcast Reports Green Threat Level for September 4 (2026-09-04, 1 outlet, severity 1/5)
- ISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th) - SANS Internet Storm Center, InfoCON: green
- ISC Stormcast Reports Green Threat Level for September 1 (2026-09-01, 1 outlet, severity 1/5)
- ISC Stormcast For Tuesday, September 1st, 2026 https://isc.sans.edu/podcastdetail/10076, (Tue, Sep 1st) - SANS Internet Storm Center, InfoCON: green
- SANS Internet Storm Center Releases September 3 Stormcast Podcast (2026-09-03, 1 outlet, severity 1/5)
- ISC Stormcast For Thursday, September 3rd, 2026 https://isc.sans.edu/podcastdetail/10080, (Thu, Sep 3rd) - SANS Internet Storm Center, InfoCON: green
Reported Data Breaches
Breaches reported via Have I Been Pwned this period.