// 2 CRITICAL · 4 ZERO-DAY · 8 CVE · 6 EXPLOIT IN THE LAST 24H
CYBERSECCRITICAL

SonicWall SMA 1000: Two Chained Zero-Days Enable Unauthenticated RCE

SonicWall patched two actively exploited zero-days in SMA 1000 appliances that chain for unauthenticated remote code execution. CISA o…

Sep 05, 2026views - 1.4k

CYBERSEC

BOD 26-04: CISA Compresses Patch Deadlines but Recommends, Doesn't Mandate Them

A tech-insider.org operational tutorial outlines a 12-step KEV workflow with a 24-hour deadline. CISA recommends it for federal agenci…

Sep 05, 2026views - 1.2k

news

FalconFlank: 0-day PoC Targets CrowdStrike Falcon, Disable Macro Policy

Nightmare Eclipse released FalconFlank, a privilege-escalation proof-of-concept that weaponizes CrowdStrike Falcon's suspicious macro…

Sep 04, 2026views - 1.2k

phishing

ASCII Smuggling: From AI Attack to 2.37 Million Phishing Emails

A technique originally developed for prompt injection against language models has spawned a financial phishing campaign exceeding 2.37…

Sep 04, 2026views - 1.2k

CYBERSEC

From AI to Inbox: The 'Invisible' Technique That Flooded Corporate Email

Microsoft detected a campaign sending over 2 million messages per day by embedding invisible Unicode characters inside financial keywo…

Sep 04, 2026views - 1.1k

VULNCRITICAL

HPE Patches Two Critical RCE Flaws in ArubaOS-CX: Structural Technical Debt

HPE released patches on September 1, 2026 for 34 vulnerabilities in the ArubaOS-CX (AOS-CX) platform, the operating system powering en…

Sep 04, 2026views - 1.1k

quantum

G7 and CISA: The Quantum Threat Is Here, Time to Act Is Running Out

The G7 and CISA issued a joint advisory on September 3, 2026, turning post-quantum cryptography migration from a future concern into a…

Sep 04, 2026views - 1.1k

CYBERSEC

"ted" Backdoor in HAProxy: Load Balancer Turned Spy in South Korea

Rapid7 Labs uncovered a previously undocumented Linux toolkit that injects the "ted" backdoor into HAProxy 2.8.12 to intercept traffic…

Sep 04, 2026views - 1.1k

CYBERSECCRITICAL

VMware Workstation: Critical Patches for VM Escape with CVSS 9.3

Broadcom has released updates for VMware Workstation and Fusion addressing two vulnerabilities rated CVSS 9.3 and 8.1. With no workaro…

Sep 04, 2026views - 1.1k

openai

OpenAI Commits $1 Billion to OT Defenders: Private Model Outpaces Federal Funding

OpenAI has pledged $1 billion in subsidized credits for its Daybreak for Frontline Defenders program, targeting under-resourced critic…

Sep 04, 2026views - 1.2k

newsEXPLOIT

WordPress Under Fire: Over 440,000 Exploit Attempts Target Two Critical Plugins in Days

Threat actors have launched more than 440,000 exploit attempts against two unauthenticated arbitrary file upload vulnerabilities in wi…

Sep 04, 2026views - 1.2k

CYBERSEC

AI-Driven Attacks in Latin America: Unit 42 Exposes Two Operational Clusters

Palo Alto Networks' Unit 42 has uncovered two ongoing multi-stage intrusion campaigns across Mexico, Ecuador, and Brazil that leverage…

Sep 04, 2026views - 1.1k

CYBERSECZERO-DAY

Google Patches Chrome Zero-Day: Urgent Update for 3 Billion Users

Google released Chrome 152.0.7977.82 to fix CVE-2026-85046, an actively exploited zero-day in the V8 engine with a CVSS score of 8.8.…

Sep 04, 2026views - 1.6k

CYBERSEC

CNIL Fines French Hospital €500K: 727,000 Profiles Exposed Without MFA or VPN

France's data protection authority fined Hôpital privé de la Loire €500,000 for a 2025 breach that exposed 727,113 individuals. The at…

Sep 03, 2026views - 1.2k

CYBERSEC

ShinyHunters Tried to Hit ReliaQuest: Device-Trust Controls Stopped the Escalation

ReliaQuest confirms a contained social-engineering attack on August 22, 2026. Device-trust controls blocked lateral movement despite v…

Sep 03, 2026views - 1.2k

news

StreamRat Reached 570,000 Meta Users via Paid Ads: The Malvertising Playbook

A malicious ad campaign distributed the Android malware StreamRat through sponsored ads on Meta and TikTok, exploiting the perceived l…

Sep 03, 2026views - 1.1k

CYBERSECCVE

CVE-2026-20212: Cisco Nexus 9000 with Silicon One ASIC Exposed to Pre-Auth Root RCE

Cisco disclosed a critical vulnerability in Nexus 9000 Series Switches equipped with Silicon One ASIC. CVE-2026-20212 carries a CVSS 9…

Sep 03, 2026views - 1.2k

malware

BraZetsu: The Brazilian Malware Turning Every PC into a Dark Web Product

The Exilware threat actor's BraZetsu framework automates the compromise of Windows hosts and their resale on an underground marketplac…

Sep 03, 2026views - 1.1k

malware

Node.js Turns Trojan Horse: Signed Runtime Hides Targeted Malware

Symantec uncovers threat actors abusing node.exe — a legitimate, signed binary — to deliver malicious payloads against government and…

Sep 03, 2026views - 1k

VULN

Plex Demands Urgent Update: Patches Before CVEs, Admins Left in the Dark

Plex urged users to immediately update Plex Media Server and Plex Desktop between September 1 and 3, 2026, without publishing the CVE…

Sep 03, 2026views - 1.2k

CYBERSEC

Thomson Reuters C-Track Breach Exposes 14 Jurisdictions; Attack Vector Undisclosed

Thomson Reuters disclosed a breach of its C-Track court case-management platform affecting at least 12 U.S. states, the U.S. Virgin Is…

Sep 03, 2026views - 1.3k

CYBERSECCRITICAL

Backup Turned Weapon: How the All-in-One WP Migration Plugin Exposes 3.2 Million Sites

CVE-2026-19949: A second-order SQL injection in the WordPress plugin All-in-One WP Migration enables remote code execution via the res…

Sep 03, 2026views - 1.3k

news

Pegasus Hits Serbian Activist: First Confirmed 2026 Infection

On September 2, 2026, Citizen Lab and SHARE Foundation published a forensic analysis of an iPhone belonging to a member of the Serbian…

Sep 03, 2026views - 1.3k

CYBERSEC

GitHub Reveals the True Cost of Ingesting Threat Intelligence at Scale

The Dependabot lead details how ingesting 18 malicious packages per day across 30 million repositories demanded more validation engine…

Sep 03, 2026views - 1.2k