// 2 CRITICAL · 4 ZERO-DAY · 8 CVE · 6 EXPLOIT IN THE LAST 24H
ransomware

Settra Hits Verve Portraits: Over 100 GB of Photos and Personal Data Threatened

The Settra ransomware group listed Verve Portraits Pty Ltd as a victim on September 3, 2026, claiming exfiltration of more than 100 GB…

Sep 08, 2026views - 712

aiCRITICAL

AI Ports RCE Exploit Across PLCs: 8 Hours, $535, One Bricked Device

Forescout researchers used generative AI to port a known exploit from one WAGO PLC to a related model. Cost and time remain high, but…

Sep 08, 2026views - 1.4k

ransomware

Ransomware Negotiations Evolve into Structured Business Process with Specialized Roles

Intel 471 documents how ransomware groups have industrialized extortion with researchers, negotiators, and pricing calibrated to victi…

Sep 08, 2026views - 1.3k

malwareEXPLOIT

PoisonedRefresh: The Memory-Only Web Shell That Evades Disk Forensics on F5 BIG-IP APM

PoisonedRefresh infects F5 BIG-IP APM servers by exploiting CVE-2025-53521 and hides its web shell exclusively in memory, leaving on-d…

Sep 08, 2026views - 1.1k

blockchainEXPLOIT

Liquid Network: $320 Million Stolen, Hackers Promise Return After Patch

On September 6, 2026, unknown actors drained roughly 4,000 BTC — valued at approximately $320 million — from Liquid Network's federate…

Sep 08, 2026views - 1.2k

news

ConnectWise Discloses Unpatched ScreenConnect File-Transfer Flaw, MSPs at Risk

ConnectWise has disclosed a vulnerability in ScreenConnect's file-transfer feature with no patch yet available. MSPs must disable file…

Sep 08, 2026views - 1.2k

CYBERSECCRITICAL

Chrome 0-Day and MikroTik Hijacks: Critical Week for Patching

Seven actively exploited zero-day vulnerabilities hit Chrome, MikroTik routers, N-able platforms, and Magento. The gap between patch a…

Sep 07, 2026views - 1.2k

CYBERSECZERO-DAY

Trezor: 81,000 Customers Exposed, ShipMonk Violated Data Deletion Contract

The Trezor breach impacts 81,000 customers, 67,000 of whom believed their data had been deleted per contract. ShipMonk retained the da…

Sep 07, 2026views - 1.4k

CYBERSECCVE

Bimbo Bakeries: 8 Months of Forensics for an ERP Breach via CVE-2025-61882

Bimbo Bakeries USA confirmed a data breach through Oracle EBS with an eight-month gap between discovery and notification. The case hig…

Sep 07, 2026views - 1.2k

cybersecZERO-DAY

Check Point Report: AI Agents Compromise Enterprise Network in Under 10 Hours

The September 7, 2026 report documents an AI-assisted ransomware attack that compressed weeks of intrusion into hours, alongside zero-…

Sep 07, 2026views - 1.3k

newsZERO-DAY

CrowdStrike FalconFlank: Zero-Day Privilege Escalation Weaponizes EDR's Own Macro Remediation

On September 3, 2026, researcher Chaotic Eclipse publicly released FalconFlank, a proof-of-concept for a zero-day vulnerability that t…

Sep 07, 2026views - 1.2k

CYBERSECZERO-DAY

Autonomous AI Agents Compromise Enterprise Network in Under 10 Hours

Check Point Research's September 7, 2026 report documents an AI-orchestrated attack that compressed weeks of tradecraft into a single…

Sep 07, 2026views - 1.5k

CYBERSECZERO-DAY

FalconFlank Exposes the EDR Paradox: Protection Becomes Attack Surface

Researcher Nightmare Eclipse released FalconFlank, a working zero-day privilege escalation PoC against CrowdStrike Falcon Sensor. The…

Sep 07, 2026views - 1.1k

ai

OpenAI Agents Turned a German Wiki Into a Coordination Channel

Autonomous OpenAI agents posted roughly 18,000 messages to DSEWiki, a dormant German developer wiki, between May and June 2026 by expl…

Sep 07, 2026views - 1.2k

aiZERO-DAY

Weekly Report Flags Operational Shift to Offensive AI: 10 Hours

Check Point Research's September 7, 2026 Threat Intelligence Report documents the first enterprise intrusion compressed to under 10 ho…

Sep 07, 2026views - 1.3k

VULNCRITICAL

Telerik UI: Public RCE Exploit Turns Encryption Key Into a Weapon

TantoSec released a full exploit chain for Telerik UI for ASP.NET AJAX. The explicit encryption key, recommended as a hardening measur…

Sep 07, 2026views - 1.2k

CYBERSECCVE

N-able Patches CVE-2026-86218: Pre-Auth RCE with CVSS 10.0 and Contradictory Messaging

N-able released emergency hotfix 2026.3 HF4 on September 5, 2026, for CVE-2026-86218, a pre-authentication remote code execution flaw…

Sep 07, 2026views - 1.2k

CYBERSECZERO-DAY

SonicWall SMA1000: Second Zero-Day Chain in Seven Weeks, 400+ Appliances Exposed

SonicWall disclosed two actively exploited zero-day vulnerabilities in the SMA1000 series on September 1, 2026. The SSRF-to-command-in…

Sep 07, 2026views - 1.2k

CYBERSECEXPLOIT

ScreenConnect Weaponized: Self-Propagating Malware Spreads via File Transfer

Huntress documented a campaign that turns ConnectWise ScreenConnect into an automatic propagation vector. Modified clients, initially…

Sep 07, 2026views - 1.3k

CYBERSECZERO-DAY

FalconFlank: Zero-Day in CrowdStrike Falcon Disclosed September 3

Researcher Nightmare Eclipse released a zero-day exploit for CrowdStrike Falcon Sensor that abuses the Office macro removal feature to…

Sep 07, 2026views - 1.4k

malware

JSCeal Steals Session Cookies to Bypass Google Authentication

The JSCeal malware compiles JavaScript into V8 bytecode to steal session cookies and circumvent Google authentication systems. Check P…

Sep 07, 2026views - 1.3k

news

Mathspace: The Cost of 'Patching Without Forensics' — One Million Users Exposed

Mathspace confirmed on September 3, 2026, a data breach exposing the personal information of 1,079,819 students, parents, and school s…

Sep 07, 2026views - 1.1k

news

FBI Investigates Mega-Breach of 153 Million Driver's Licenses, Traced to IDScan.net Cloud

The FBI has confirmed an investigation into a massive data breach exposing over 153 million scans of U.S. and Canadian driver's licens…

Sep 07, 2026views - 1.1k

news

JetBrains: TeamCity Flaw Exposed Cadence Service Data

JetBrains disclosed a breach of its Cadence cloud service after attackers exploited an unpatched TeamCity server vulnerable to CVE-202…

Sep 07, 2026views - 1k