CFToday Curated security signals.

Daily edition · 2026-09-01

Tuesday, 1 September 2026

63 items across 7 sections, selected from 4614 candidates over 6 runs. 127 carried the panel unanimously.

Show
Section

  1. FBI Probes Service Selling 153M+ Drivers Licenses (opens in a new tab)

    Krebs on Security ·BrianKrebs ·fetched 1 Sep 2026, 23:41 UTC Must read agreed3/3

    Why readScans of 153 million North American drivers licenses, including those of serving senior US officials, are on sale, and the apparent source is an identity verification vendor many organisations rely on.

    A new listing on the Exploit forum advertises digital identity document images covering more than 170 million people, with over 153 million US and Canadian license scans available for purchase. Interviews with people whose documents appear in the service point to a Louisiana identity verification provider as the collection point, and the FBI's New Orleans field office has opened an inquiry. The practical consequence is that document image checks, the control many services adopted to defeat synthetic identity fraud, now have a large pool of genuine scans available to attackers, so any onboarding flow that trusts a license image as proof of identity needs rethinking.

  2. The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT (opens in a new tab)

    Huntress ·fetched 1 Sep 2026, 15:40 UTC Must read Research agreed3/3

    Why readA trojanised Exodus 24.33.4 wallet installer where only 3 of 1,973 files differ from the genuine package, one of them converted into a PE loader that maps a 10 MB payload in memory with zero VirusTotal detections.

    Between late July and mid August 2026 multiple Huntress-protected organisations were hit by the same modular RAT, three of them inside an 85-minute window. Victims ran a JavaScript file staged as a fake PDF or software update in a ZIP, which fetched an MSI declaring itself a Background Service by Apple Inc; the MSI installs a real, working Exodus 24.33.4 wallet with one file modified to suppress the window so the user never sees it, and another legitimate Exodus source file rewritten into a loader that decrypts and hand-maps a 10 MB payload that never touches disk. The near-identical file count and clean VirusTotal result make hash and reputation controls useless here, so detection has to sit on the JS-to-MSI chain and the in-memory mapping behaviour.

    Indicators14
    Hashes
    c513a7346484ee69a2931c4a89956ee50aa63e4366ef989315e669d8f10d7485 8c3b41ea5a85778145a6e5772bfee2eb0f8b027d0af199fb71a76dfb8bb29e5a fdd376562aac4be64fb635546a61e1912ff2c353360db73d2c553dcbb5a44f54 2f47cfbb13f7a8a2d30d287f4ddd974fabea6762ad9781d438eb53da41b4582d 84437d4239d2a3d90c4faad0a3c0630b2f61a40f7bbd12109bef74d7613b8756 5274e93e35586a341d14b50cdf8413d59c51fd94f32bdc70bfdfb77198367603 7e74f6e2eb7a17a8d25bb322a14c392c9d92c6ab29fc66b50221da134a1bdba8 5fe753945da0eaac2c2ef3845cba603dea6c3e8529fa581d7e0192f8af60391a
    Addresses
    35[.]212[.]159[.]20
    Domains
    us05[.]org api[.]blockchain[.]info api[.]moonpay[.]com api[.]rampnetwork[.]com api[.]segment[.]io
  3. Hackers push malicious Virtualizor update in BGP hijacking attack (opens in a new tab)

    BleepingComputer ·Bill Toulas ·fetched 1 Sep 2026, 15:40 UTC Must read agreed3/3

    Why readAn attacker BGP-hijacked Hetzner IP space to redirect Softaculous update traffic and push a malicious Virtualizor update to hosting providers between 20:57 UTC 28 August and 06:10 UTC 30 August.

    Softaculous confirmed that a block of its Hetzner-hosted addresses was falsely announced, diverting traffic from both the software update systems and the client and billing portal. A small number of Virtualizor installations received the attacker-supplied update, giving code execution on control panels that manage VPS fleets. Any hosting provider that updated Virtualizor inside that 33-hour window should treat the host as compromised and review the billing portal session and credential exposure alongside it.

  4. Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set (opens in a new tab)

    Securelist ·Omar Amin ·fetched 1 Sep 2026, 07:42 UTC Must read Research agreed3/3

    Why readTwo previously undocumented cross-platform RATs from Mirage Kitten, NodeRabbit (Node.js) and PollCat (obfuscated JavaScript), delivered through trojanized coding challenge archives sent via LinkedIn job lures.

    NodeRabbit runs on Windows, Linux and macOS and was first found on a system in Afghanistan, with two more advanced variants recovered in Egypt and Ethiopia; PollCat is a second, separately tracked JavaScript RAT distributed the same way. Both mark the first publicly documented shift by Mirage Kitten away from native C, C++ and Go payloads deployed via DLL search-order hijacking. Targeting covers aviation and FinTech across the Middle East and Africa, and the delivery path means developer workstations are the initial access point.

    Indicators7
    Hashes
    1ea83e4e4592b01e4acab63eb867bee5 810f8e3b88eb05f710c09552941d6f56 795e053a990a1569ffdcb57f48f6d085
    URLs
    hxxps://kyrasey-f8hfexa5cqamh7fk[.]westeurope-01[.]azurewebsites[.]net hxxps://lifespotify[.]com/api/users/b879746e-fed9-4211-a6da-4d8223681267/otp/validate
    Domains
    msmanagementgrp[.]com visitfinancedentists[.]com

    Also covered byThe Record (opens in a new tab).

  5. Open Directory Exposes Moobot Source Code and Ongoing Activity Post 2024 Court-Authorized Disruption (opens in a new tab)

    Censys ·Kate Lake ·fetched 1 Sep 2026, 15:40 UTC Research agreed3/3

    Why readAn open directory on 86.53.111[.]212:8080 leaked Moobot source code containing a dormant download-and-execute capability, the most plausible mechanism behind APT28's use of the botnet, plus a live DDoS panel and a Chinese PII lookup fraud service.

    Censys recovered Moobot source from a misconfigured directory and found download-and-execute functionality not previously documented, unused but present, alongside evidence the operation continued after the 2024 court-authorised disruption. The same host runs "StresD Pro+", a 16-account DDoS panel with 32 attacks recorded on the collection day, generating traffic locally through a purpose-built Minecraft Bedrock RakNet flooder. A third service branded as a public security identity verification system resells a third-party Chinese PII lookup API while harvesting identity documents from its own users through an appeal flow.

  6. Chinese-speaking threat actors targeting Mexican Android users with remote access Trojan (opens in a new tab)

    Intel 471 ·fetched 1 Sep 2026, 23:41 UTC Research agreed3/3

    Why readFirst public analysis of PanDa, an Android RAT pushed through Meta Ads as a fake Netflix APK to Spanish-speaking users in Mexico, with the ShellA loader and the AppPanda distribution panel named.

    Intel 471 tracked a phishing operation running since May 2026 that used paid Meta Ads to deliver a malicious APK impersonating Netflix. The APK, tracked as ShellA, loads a newly identified RAT called PanDa offering screen streaming, hidden VNC, remote control, keylogging and screen-lock capture. Infections are managed through AppPanda, a centralised phishing panel that also sells supporting services, and the actors shifted lures in July.

  7. Counterfeit installers to system compromise: Tracking a deceptive software download campaign (opens in a new tab)

    Microsoft Security ·Microsoft Security Research, Microsoft Defender Experts and Parth Jomadkar ·fetched 1 Sep 2026, 23:41 UTC Research agreed3/3

    Why readMicrosoft Defender Experts details an active fake software-download campaign consistent with Silver Fox (Yinhu), with counterfeit vendor sites delivering installers that establish persistence and weaken security tooling.

    Counterfeit download sites impersonating trusted software vendors have compromised organisations across healthcare, manufacturing, gaming, technology, logistics, government and education, primarily hitting China-based operations of multinationals and Chinese-speaking users. The installers deploy malware that persists, attempts to disable security protections and beacons to attacker infrastructure; Microsoft assesses with moderate confidence that this matches the publicly reported Silver Fox campaign but does not attribute it to a state actor. The attack chain breakdown and mitigation guidance give hunt material for search-engine-driven initial access.

    Indicators25
    Hashes
    6d6ba2bc9ad414837826f7278bc3e0116f1aeda02d0c2284ed65819f5d9180a8 1bd3662d784840e410d2d3c0a1040277f7f549089447359f01e05c2559cb1f17 676a2a7b94ca2f8ec76352ee656e4d075bb342bd7ad6efbc7c19c060001eace7 c4100ad39d8db98f063feb6c3b6c8e9a9f9d9bf25a1e0233f43b058ff8a7dbdf c6100166e2d3b40388980f7674712ef39e937ac04925ca5d370415399ed73faf f33d160d757e4b39019fdef21cf90cafb501b800ca0d4039366bc30856e3d81b e4fe2dee8f0bb132fa15fc686d1f93df39530a2d3a8d3a1f3a605a057c04e7b3
    URLs
    hxxp://www[.]gehie246[.]com/712down
    Addresses
    47[.]239[.]232[.]245 47[.]243[.]218[.]255 103[.]156[.]25[.]35 103[.]183[.]3[.]162 202[.]95[.]14[.]237
    Domains
    pc-razerzone[.]com[.]cn gehie246[.]com yimxg25tiy[.]com cc8ttkv35b[.]com n7b8t85zsg[.]com com[.]cn hl[.]cn calibre-ebook[.]com[.]cn translate-youdao[.]hl[.]cn app-microsoft-edge[.]com[.]cn oijfwe[.]net newopt001[.]oss-cn-hongkong[.]aliyuncs[.]com
  8. Ungentlemanly behavior: Insights into a ransomware operation (opens in a new tab)

    Sophos Threat Research ·fetched 1 Sep 2026, 15:40 UTC Research agreed3/3

    Why readCTU's reconstruction of The Gentlemen RaaS post-exploitation playbook, run by GOLD SHERWOOD, with ransomware sometimes deployed within 24 hours of first observed post-compromise activity.

    Counter Threat Unit researchers document a consistent affiliate playbook across The Gentlemen intrusions: rapid privilege escalation, adaptive use of legitimate tooling and compromised credentials, and aggressive defence evasion ahead of encryption. The group began operating the double-extortion scheme in mid-2025, with the first victims posted to its leak site in September 2025. Hardening priorities follow directly from the tradecraft: remote access services, MFA enforcement, administrative activity monitoring, and detection of exfiltration tooling and staging directories.

    Indicators12
    Hashes
    622b2ca08552535bc142cb815ff9ec16 f0bc50d2d2838c5294e21cd9bce2f09bf581e508 a348f5fa048a09188bd706fd3d4efca978990caf3355ecfee501c9f1e19c0efd 4741a4976c6abfb3c80c170104518b6e be8c52474ab79a52af31e3cb2f71638299a0de1d ddba5b4e7a7ada77d56477e9d41c008f93e81d9a33ed09e77cb2af624fa694fe 738df7ae0097f6bef93d65be5d4a2a26 c96baab9b7e7ef661921d44d7900f165c794ed25 1a9291ec869155336bf185d221d655d11c77a55ea0c8ecc0274202f74a90fcd1 d8691ef15eea27cfefafeeb485286080 8bca55b3c9bfbdf68c9b6c72a7b1bf1dd6d5e3b2 3c71537b64487bbf4d1793f72c75d332650d09a77b71e4d884ff15c266a847f6
  9. 13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 1 Sep 2026, 15:40 UTC agreed3/3

    Why readThirteen malicious Composer theme packages on Packagist, spanning five vendor namespaces and posing as OphimCMS themes, inject JavaScript that runs a WebKit-to-kernel exploit chain against unpatched iPhones to install spyware and steal wallet seeds.

    Socket researcher Kush Pandya found trojanized Composer themes that Vietnamese movie and comic streaming sites install, whereupon injected JavaScript runs two operations against visitors: a mobile ad-fraud and gambling-redirect chain, and on iOS a WebKit-to-kernel exploit chain delivering spyware. The set extends a campaign Socket first documented in March 2026 involving six malicious Packagist packages with Funnull-hosted second-stage infrastructure. Two things follow: audit Composer dependencies for these namespaces, and treat unpatched iOS in the browsing population as directly exploitable rather than theoretical.

    Indicators1
    Domains
    cloudfareintcdn[.]com
  10. FBI raises alarm over deceptive phishing campaign targeting prominent people (opens in a new tab)

    CyberScoop ·Matt Kapko ·fetched 1 Sep 2026, 23:41 UTC agreed3/3

    Why readFBI PSA on an ongoing OAuth consent phishing campaign against high-profile targets, including the detail that access survives a password reset and can only be killed by invalidating the token.

    The FBI has been tracking a campaign since late 2025 in which attackers impersonate government officials, journalists and public figures on a commercial messaging app, then lure targets into approving OAuth consent for a legitimate Microsoft or Google cloud service under the pretext of reviewing a draft article. The grant gives persistent, passwordless access to the victim's account, and revocation requires the victim to invalidate the token in application security settings; changing the password does nothing. Family members and acquaintances of targets are also in scope, which widens the population worth warning and monitoring for anomalous app consents.

  11. Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st) (opens in a new tab)

    SANS ISC Diary ·fetched 1 Sep 2026, 03:41 UTC Research agreed3/3

    Why readFull infection chain and indicators for a geofenced Guildma (Astaroth) campaign that only delivers malware to Brazilian IPs with pt-BR locale settings.

    A malicious Brazilian Portuguese email link delivers a zip containing a Windows shortcut, which pulls remote content and writes it as an alternate data stream to a file under AppData\Local\Temp. That ADS holds a non-malicious 64-bit DLL used to fetch and install an AutoIt package carrying Guildma. The delivery server is geofenced to Brazil and checks browser and OS locale, serving a legitimate Android Studio installer otherwise, so sandbox and analyst replication outside Brazil will fail silently. SHA-256 hashes and network indicators are published.

    Indicators5
    Hashes
    cc44782356cb0effc528a7ab22c19ab360a55ebbbe01feb0967031aa191c5869 47d2908c4dd7f6f5eb4a8ef4306077b10315c44231f4bacd2bb811b245561911 a6044786991afdb9d42ceb350943987765a7d0e8537369b2092e3f019c0f63ca f62a958faf0491b2b2803be2ee69b664b58e4a1261f64e8530cdc1a3ff666aa4
    URLs
    hxxps://sistema-ekg3h4htc0h0ggdh[.]canadacentral-01[.]azurewebsites[.]net
  12. Fake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackers (opens in a new tab)

    CSO Online ·fetched 1 Sep 2026, 11:41 UTC agreed2/3

    Why readDocuments a ClickFix variant that moves the victim from the Run dialog into Windows Terminal or PowerShell, which quietly defeats detections tuned to RunMRU artifacts and lets multi-line scripts execute cleanly.

    Microsoft Threat Intelligence is tracking TerminalFix, a campaign that serves a fake Cloudflare verification prompt from compromised websites and coaxes victims into pasting a malicious PowerShell command. The chain runs through DLL sideloading, payloads concealed in PNG files, persistence and Active Directory reconnaissance, ending in a custom reverse-tunnel implant for operator access. Microsoft has published detection coverage, IOCs and hunting queries; defenders relying on Run-dialog telemetry to catch ClickFix should assume that coverage now has a hole.

  1. CVE-2026-81578 + CVE-2026-82078 | PaperCut NG/MF Authentication Bypass and Unsafe Dynamic Class Loading Vulnerabilities (opens in a new tab)

    Horizon3 Attack Team ·Horizon3 ·fetched 1 Sep 2026, 15:40 UTC Must read Research CVE-2026-82078 EPSS 0.9% agreed3/3

    Why readTwo chained PaperCut NG/MF bugs give pre-auth RCE on the Application Server, and PaperCut has confirmed exploitation and customer incidents.

    CVE-2026-81578 is an improper access control flaw (CVSS 4.0 8.8) in the PaperCut NG/MF web management interface that lets unauthenticated remote requests trigger administrative backend actions before access validation completes, allowing configuration changes. CVE-2026-82078 is unsafe dynamic class loading (CVSS 4.0 9.4) that turns control of those configuration parameters into arbitrary Java bytecode execution. Chained, they yield pre-authentication RCE as the PaperCut server process; the vendor confirms active exploitation and customer incidents, so patch and audit rather than wait on EPSS, which has not caught up at 0.009.

    Also covered bySecurityWeek (opens in a new tab),Cybersecurity News (opens in a new tab),Security Affairs (opens in a new tab).

  2. Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 1 Sep 2026, 19:40 UTC Must read CVE-2026-82329 EPSS 0.4% agreed3/3

    Why readCVE-2026-82329, an unauthenticated auth bypass to admin in JFrog Artifactory under default config, is being exploited within days of disclosure; fixed in 7.161.20.

    The weakness is in JFrog Access, the component that issues and validates credentials, and instances without an additional join key are exposed. watchTowr reports active exploitation minting administrative tokens, with the patch released 28 August 2026. Because Artifactory hosts build artefacts and binaries, admin access is a supply-chain compromise of everything it serves, so patch, rotate tokens and audit for unexpected admin accounts.

    Also covered bySecurityWeek (opens in a new tab).

  3. Another Artifactory CVE under attack by AI agents or humans (opens in a new tab)

    The Register Security ·fetched 1 Sep 2026, 23:41 UTC CVE-2026-82329 EPSS 0.4% agreed3/3

    Why readCVE-2026-82329, a CVSS 9.8 authentication bypass in JFrog Artifactory, is being exploited against internet-exposed instances four days after the patch, with attackers minting themselves admin tokens.

    JFrog disclosed the auth-bypass flaw on Friday; by Tuesday watchTowr's honeypot network was catching exploitation of internet-facing Artifactory servers, with intruders creating new administrative credentials. Artifactory sits at the centre of software artefact, package, binary and model distribution, so admin access is a direct supply-chain compromise path. EPSS is still low at 0.004 and lagging the observed activity, so treat confirmed in-the-wild use as the signal and patch or take instances off the internet now.

  4. Hackers Start Exploiting Critical Langflow Vulnerability (opens in a new tab)

    SecurityWeek ·Ionut Arghire ·fetched 1 Sep 2026, 15:40 UTC CVE-2026-0768 EPSS 2.3% agreed3/3

    Why readCVE-2026-0768 in Langflow (all releases up to 1.4.2) is being exploited for unauthenticated RCE as root, with over 360 attempts against VulnCheck canaries.

    The flaw sits in the code validator of Langflow's custom component editor, where a user-supplied string reaches Python execution without proper validation, giving unauthenticated code execution as root at CVSS 9.8. VulnCheck reports in-the-wild activity focused on reconnaissance and credential harvesting: queries for environment variables, secret keys and SSH access, mostly sourced from Russia and hitting UK canaries. Reported through ZDI in July 2025 and disclosed as a zero-day in January 2026, so exposed Langflow instances have been reachable for some time; upgrade past 1.4.2 and treat any internet-facing instance as compromised until checked.

    Also covered byBleepingComputer (opens in a new tab),The Hacker News (opens in a new tab),Dark Reading (opens in a new tab).

  5. Off the Hook: Discovering and Observing Active Exploitation of Sangoma Switchvox CVE-2026-9586 (opens in a new tab)

    Horizon3 Attack Team ·Zach Hanley ·fetched 1 Sep 2026, 11:41 UTC Research CVE-2025-57819 EPSS 0.7% agreed3/3

    Why readHorizon3 found CVE-2026-9586 in Sangoma Switchvox and reports observing active exploitation of it in the wild.

    After FreePBX bugs CVE-2025-57819 and CVE-2025-64328 landed in CISA KEV, Horizon3 audited the wider Sangoma ecosystem and turned up a vulnerability in Switchvox, tracked as CVE-2026-9586, which they say is now being exploited. The fetched text is the intro only, so the technical mechanism and affected versions are not in what was delivered. Switchvox is a phone system typically reachable from the internet, which makes exploitation claims worth chasing to the full write-up today.

    Also covered byHorizon3 Attack Team (opens in a new tab).

  6. Public PoC Released for Microsoft Exchange Server Pre-auth RCE Vulnerability (opens in a new tab)

    Cybersecurity News ·Abinaya ·fetched 1 Sep 2026, 11:41 UTC CVE-2026-62911 EPSS 0.9% agreed3/3

    Why readA public GitHub PoC now chains CVE-2026-62911 into unauthenticated SYSTEM-level RCE on on-premises Exchange via NTLM relay to the MRSProxy endpoint.

    Researcher Nguyen Van Hiep published an exploit for CVE-2026-62911, an August 2026 capture-and-replay authentication bypass in on-premises Microsoft Exchange Server. The PoC targets the HTTP.sys-hosted Mailbox Replication Proxy (MRSProxy), which the documentation says does not enforce Extended Protection for Authentication, allowing relay of the Exchange machine account's NTLM authentication. Microsoft rates it elevation of privilege for an authorized attacker; the published chain argues it reaches pre-auth RCE, so treat EPSS of 0.0095 as a lagging indicator and verify Extended Protection is enabled everywhere.

  7. CVE-2026-82635 (CVSS 8.8): Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization (opens in a new tab)

    NVD ·fetched 1 Sep 2026, 03:41 UTC CVE-2026-82635 CVSS 8.8 EPSS 0.4% agreed3/3

    Why readEvery desktop app built from an affected Pake tree exposes a download_file command that writes attacker-controlled content to a LaunchAgent or Startup path.

    Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the Downloads directory with no sanitisation, so a name like ../Library/LaunchAgents/com.evil.plist or an absolute path escapes the directory. The command then fetches the supplied URL through Rust HTTP rather than the browser and writes it there, giving persistence via macOS LaunchAgents, Linux autostart or the Windows Startup folder and code execution as the user. The exposure is inherited by every app generated from a vulnerable tree, so rebuilding downstream apps matters as much as bumping Pake itself.

  8. CVE-2026-82722 (CVSS 8.3): Allocation of Resources Without Limits or Throttling vulnerability in ash-project ash_admin lets any client that can reach the admin LiveView exhaust (opens in a new tab)

    NVD ·fetched 1 Sep 2026, 03:41 UTC CVE-2026-82722 CVSS 8.3 EPSS 0.3% agreed3/3

    Why readTwo ash_admin LiveView handlers intern atoms from unvalidated client input, so any client reaching the admin view can exhaust the BEAM atom table and take down every app on the node.

    PageLive's set_actor built modules from the resource/domain payload with Module.concat/1, and Resource.Show's calculate ran String.to_atom/1 over every submitted form key. Atoms are never garbage collected and the table is capped, so flooding either event with random names aborts the VM. Affects 0.1.0 through 1.3.1; the fix resolves submitted resources against known shown resources and maps calculation keys to declared arguments.

  9. Rockwell Automation Historian ME (opens in a new tab)

    CISA Advisories ·CISA ·fetched 1 Sep 2026, 19:40 UTC CVE-2026-12661 agreed3/3

    Why readFactoryTalk Historian ME Series B 5.202 and Series C 7.101 carry an out-of-bounds write and a stack overflow, with remote code execution possible for a low-privileged authenticated attacker.

    CVE-2025-12768 and CVE-2026-12661 (CVSS v3 8.0) affect Rockwell Historian ME on both Series B and Series C modules; the impact ranges from crashing the device to remote code execution on it. Historian ME collects process data across chemical, food, water and healthcare plants, so a compromised module sits inside the control network with a legitimate reason to talk to controllers. Low-level authentication is the only precondition, which shared engineering credentials routinely satisfy.

  10. CVE-2026-58574 (CVSS 9.8): Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restrict (opens in a new tab)

    NVD ·fetched 1 Sep 2026, 07:42 UTC CVE-2026-58574 CVSS 9.8 EPSS 0.3% agreed3/3

    Why readUnauthenticated read of the PowerStore appliance filesystem via the management interface, exposing credentials that grant full array administration.

    Dell PowerStore contains a missing-authentication flaw on the restricted management interface allowing a network attacker to pull internal system information from the appliance filesystem, including credentials that yield full administrative access to the array. Dell rates it critical at CVSS 9.8, and the blast radius is the storage tier, so the practical mitigation is confirming management-plane segmentation while the patch is scheduled. No exploitation reported and EPSS sits at 0.0034, and the advisory as given does not name fixed versions.

  11. Multiple vulnerabilities in JFrog Artifactory (opens in a new tab)

    translated Multiples vulnérabilités dans JFrog Artifactory (01 septembre 2026)

    CERT-FR (ANSSI) ·fetched 1 Sep 2026, 15:40 UTC agreed3/3

    Why readFive JFrog Artifactory CVEs including SSRF via CocoaPods external dependencies and unauthorised repository migration, fixed in 7.111.21.

    Artifactory versions 7.111.4 up to but not including 7.111.21 are affected by CVE-2026-69104, CVE-2026-70548, CVE-2026-70550, CVE-2026-70551 and CVE-2026-82329, giving data confidentiality loss, server-side request forgery and security policy bypass. CVE-2026-69104 is described as potential unauthorised repository migration and CVE-2026-70548 as SSRF in CocoaPods handling via external dependency resolution. Artifactory sits at the centre of build supply chains, so an SSRF reachable from dependency resolution is worth prioritising over the CVSS numbers alone.

  12. CVE-2026-75757 (CVSS 8.3): Reliance on Cookies without Validation and Integrity Checking vulnerability in ash-project ash_admin lets an attacker who controls a sibling subdomain (opens in a new tab)

    NVD ·fetched 1 Sep 2026, 03:41 UTC CVE-2026-75757 CVSS 8.3 EPSS 0.3% agreed3/3

    Why readAn unanchored cookie-name regex in ash_admin lets a compromised sibling subdomain shadow admin state cookies and rebind the session to a different actor, tenant or authorization mode.

    AshAdmin's client JavaScript matched cookies with new RegExp(name + "=([^;]+)") against the whole document.cookie, so any cookie whose name merely ends with the target name wins if it serialises first. An attacker on a sibling host under the same registrable domain sets something like xactor_authorizing with Domain=.example.com, and the value flows unvalidated into the LiveSocket connect params. Affects 0.9.1 through 1.3.1; the fix compares cookie names by exact equality, and the pattern is worth grepping for in your own cookie readers.

  1. Drishti: AI-Led Human-Directed Vulnerability Auditing for 5G Cores (opens in a new tab)

    arXiv cs.CR (all) ·Sriram Ramachandran, Levente Csikor, Dinil Mon Divakaran ·fetched 1 Sep 2026, 03:41 UTC Must read Research CVE-2025-69248 EPSS 0.6% agreed3/3

    Why readThree concrete 5G core defects found by a structured audit method, including a 2-byte NGAP input from a rogue gNodeB that OOM-kills the free5GC AMF in 6.2 seconds.

    Drishti splits vulnerability validation into verification, reachability, impact and fix-completeness, with an anti-pattern catalog, critical-path triage, concentric validation and patch review for each. Applied to Open5GS and free5GC it produced a pre-authentication NULL dereference in the Open5GS NRF multipart parser (fixed upstream, CVE requested), an ASN.1-PER memory amplification in the free5GC NGAP decoder, and a defective patch for CVE-2025-69248. The amplification case is the sharpest result: minimal attacker input from a rogue base station, denial of service against the AMF in seconds, and it shows how thin the pre-auth attack surface on open-source 5G cores still is.

  2. Arcanum-Sec/wraith: WRAITH — a modern browser-hooking framework (BeEF + blind-XSS successor) for red teams, researchers, and educators. For authorized security testing, research & education only. (opens in a new tab)

    GitHub: new security tools ·Arcanum-Sec ·fetched 1 Sep 2026, 03:41 UTC Must read Research ★ 139 agreed3/3

    Why readA clean-room BeEF successor that merges browser hooking with blind-XSS callback handling in one framework, so a fired payload becomes a live interactive session rather than just a notification.

    WRAITH from Arcanum Sec rebuilds the hook-the-browser workflow (fake login keylogging, internal network recon, pushing modules at a live victim) against modern browsers, where large parts of BeEF have gone unreliable, and folds in the XSS Hunter and ezXSS pattern of catching payloads that fire somewhere you cannot see. The social-engineering overlays are redesigned rather than inherited. Red teams running blind-XSS campaigns get a single JavaScript stack for both halves of the job; detection engineers get a fresh hook to write signatures against.

  1. Introducing deny list egress policies for Harden-Runner (opens in a new tab)

    StepSecurity (CI/CD) ·fetched 1 Sep 2026, 07:42 UTC agreed3/3

    Why readHarden-Runner v2.21.0 adds a denied-endpoints input, so CI teams can block known-bad egress destinations without first building a complete allow list.

    StepSecurity's argument is that allow-list egress control stalls because an incomplete list fails builds loudly, leaving workflows parked in audit mode for months. The new denied-endpoints input inverts the model: listed destinations are blocked and everything else stays reachable, with wildcard domains such as *.example.org covering subdomains as they do in allow lists. Ports are not part of a deny entry, so this is a coarser control than the allow list and is meant as an on-ramp rather than a replacement.

  2. Runtime Security for AWS CodeBuild-Hosted GitHub Actions Runners (opens in a new tab)

    StepSecurity (CI/CD) ·fetched 1 Sep 2026, 03:41 UTC agreed3/3

    Why readHarden-Runner v2.20.1 and v2.21.0 add runtime egress and process monitoring to GitHub Actions jobs running on AWS CodeBuild-hosted runners, closing the gap created when CI moves off ubuntu-latest into your own VPC.

    CodeBuild can register itself as a just-in-time GitHub Actions runner, so jobs execute inside your AWS account under your IAM role, outside the runtime controls teams applied to GitHub-hosted runners. v2.20.1 adds support for CodeBuild on EC2 compute with managed or custom images, and v2.21.0 extends it further. The motivating case is CVE-2025-8217, where a malicious pull request dumped a CodeBuild build environment's memory to steal repository access tokens used to reach the AWS Toolkit for VS Code and AWS SDK for .NET repos.

  3. POLYFLOW: A Neuro-Symbolic Framework for Static Cross-Language Information Flow Analysis (opens in a new tab)

    arXiv cs.CR (AI) ·Haoran Yang, Zhixuan Zhong, Jiawei Guo, Haipeng Cai ·fetched 1 Sep 2026, 11:41 UTC Research agreed3/3

    Why readStatic taint analysis that follows information flow across language boundaries, where JNI-style and FFI-style interactions normally break single-language analysers.

    PolyFlow uses a multi-language system's control-flow representation to scope LLM queries that recover implicit flow facts arising from cross-language features, then propagates data flow through the augmented representation. Token limits and hallucination are handled with static-analysis-guided scoping, context management and fact checking rather than trusted outright. Relevant to appsec teams auditing polyglot codebases where dynamic testing misses paths for want of inputs.

  4. Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation (opens in a new tab)

    AWS Security ·Nisha Kashyap ·fetched 1 Sep 2026, 07:42 UTC agreed3/3

    Why readNames the GuardDuty finding families and the CloudTrail call sequence (GetCallerIdentity from a new source, then List/Describe bursts with AccessDenied, then egress to a newly registered domain) that make up a correlatable multi-stage AWS attack.

    The guide walks a recon-to-exfiltration sequence on AWS and argues for correlating signals across services rather than triaging findings one at a time, pointing at Recon:IAMUser/* and Discovery:S3/* finding types as the individual pieces. The detection logic is portable to any AWS estate and the sequence is concrete enough to build against, though the correlation plumbing is AWS-native and the underlying technique chain is well known.

  5. The dark figure of supply chain detection (opens in a new tab)

    Aikido Security ·fetched 1 Sep 2026, 23:41 UTC agreed3/3

    Why readArgues that string and IOC-level rules for malicious packages are structurally blind to any attacker who never reused a known artefact, and that your detection corpus is a survivorship-biased sample.

    Applies the survivorship bias problem to supply-chain detection: every rule labelled 'known bad' is derived from malicious packages that were caught, so the corpus describes the attackers who failed rather than the population of attacks. The consequence stated plainly is that string-level matching cannot by construction catch an actor who has never appeared in the tracking data, which puts a ceiling on signature-driven package scanning regardless of rule count. It is a position specific enough to argue with, and it comes from a vendor in the space, so read the conclusion about behavioural detection with that in mind.

    Indicators1
    Domains
    webhook[.]site
  6. Defending the battlefield: Stateful detections for an agentic threat landscape (opens in a new tab)

    Sysdig ·fetched 1 Sep 2026, 03:41 UTC agreed2/3

    Why readSysdig's threat research numbers on how fast automated and AI-assisted attacks now move are worth having, even though the detection argument built on top of them lands on the company's own product.

    Sysdig argues that stateless runtime rules cannot keep pace with exploitation that follows disclosure by hours, citing React2Shell, AI-assisted intrusions that reached admin in eight minutes and credential theft in three, and JADEPUFFER, which it describes as the first agentic ransomware to run a database extortion playbook autonomously. The proposed answer is stateful detection that correlates events over time rather than firing on single observations. The threat data is the substance here; the detection discussion stays conceptual and does not give a defender rules or logic they could implement outside the vendor's engine.

  7. wellwelwel/lagune: 🌊 Lagune is your security copilot as you build, your Blue Team when you audit, whether you're a developer or not (no API key needed). (opens in a new tab)

    GitHub: new security tools ·wellwelwel ·fetched 1 Sep 2026, 15:40 UTC ★ 140 agreed2/3

    Why readA new agent-driven code hardening tool worth a look if you are already routing security review through coding agents, but treat the coverage claims as unverified.

    Lagune installs a set of security slash commands and phase artifacts into a project so a coding agent can profile what the system does and then walk an operator through hardening it, with support advertised across 72 agent environments and no API key of its own. It is a Node.js wrapper that shapes agent prompts and workflow, not an analyser with its own detection logic, and the repository states no methodology, rule set or evaluation. Useful as a starting scaffold; do not read the blue team framing as evidence of what it actually catches.

  1. ECLIPSE: Self-Evolving Stealthy Prompt Injection Attack against Long-Horizon Agentic Systems (opens in a new tab)

    arXiv cs.CR (AI) ·Shiqian Zhao, Yangfan Zhou, Xinfeng Li, Runyi Hu ·fetched 1 Sep 2026, 07:42 UTC Must read Research agreed3/3

    Why readA prompt-injection framework that hides intent in tool descriptions via state-transition cues, tested against long-horizon coding agents including Codex and Claude Code.

    ECLIPSE combines a direct user-prompt injection with indirect tool-side injection: candidate tool chains are synthesised and verified in a sandbox then rendered as a natural one-shot prompt, while Static Workflow Encoding embeds state-transition cues in the descriptions of target tools to steer the agent's plan in the real environment. The self-evolving loop addresses the standing tradeoff in this attack class, where explicit single-instruction injections are easy to detect and intent spread across stages completes unreliably. Directly relevant to anyone letting an agent read third-party tool manifests or MCP server descriptions.

  2. OpenAI Is About to Release Its First AI Model With ‘Critical’ Cyber Abilities (opens in a new tab)

    WIRED Security ·Maxwell Zeff, Lily Hay Newman ·fetched 1 Sep 2026, 23:41 UTC Must read agreed3/3

    Why readOpenAI says its forthcoming model Astra is the first to cross its own 'critical' cyber threshold, meaning it can independently find and exploit previously unknown vulnerabilities in real software.

    OpenAI has classified its upcoming Astra model as reaching the critical cybersecurity tier of its preparedness framework, defined as independently discovering and exploiting unknown vulnerabilities in real-world software. Advanced cyber capabilities will be gated at launch to selected partners in a Daybreak Blue early-access programme rather than shipped to the general release, and the company says it halted further development pending safeguards. For defenders this is the first vendor admission that a frontier model has crossed a threshold the vendor itself said would require containment, and it sets the reference point for how offensive-capable models get released from here.

  3. Safe to Resume? Breaking Execution Continuity of Agent Execution via Rollback (opens in a new tab)

    arXiv cs.CR (AI) ·Guanlong Wu, Dahui Li, Ke Jiang, Jianyu Niu ·fetched 1 Sep 2026, 23:41 UTC Must read Research agreed3/3

    Why readShows that correctly restoring an agent checkpoint can resume a state that never validly existed, with five failure modes and three working end-to-end attacks against real agent C/R systems.

    The first systematic security study of checkpoint and rollback in stateful AI agents. The authors build an execution model of existing C/R designs and derive five failure modes covering incomplete or inconsistent internal state, stale external dependencies, nondeterministic replay and unrecorded external side effects. Three end-to-end attacks demonstrate that faithful restoration is not secure recovery, which matters for anyone running long-lived agents with persistent state.

  4. SIR: Self-improving Red-teaming for Compute Use Agents (opens in a new tab)

    arXiv cs.CR (AI) ·Chen Xiong, Zhiyuan He, Pin-Yu Chen, Stjepan Picek ·fetched 1 Sep 2026, 07:42 UTC Must read Research agreed3/3

    Why readIndirect prompt injection against computer-use agents at the OS level, with a feedback loop that distils failed trajectories into named reusable bypass strategies and a deterministic scoring oracle.

    SIR is a black-box IPI attack that composes stealthy injections from a small library of plain-language principles, then iterates: it diagnoses the victim agent's failed trajectories and turns the bypasses into new named strategies reapplied across tasks. Unlike prior web-agent red teaming it targets agents driving mouse, keyboard and terminal on a real operating system, and scores outcomes with a fully deterministic oracle rather than a judge model. The finding that matters: fixed hand-written injection benchmarks understate risk from an adaptive adversary.

  5. The Fragility of Jailbreak Robustness Across Operational States (opens in a new tab)

    arXiv cs.CR (AI) ·Yuna Park, Hwang Youn Kim, Yujin Kim, Won Woo Ro ·fetched 1 Sep 2026, 07:42 UTC Research agreed3/3

    Why readShows that an ordinary system prompt unrelated to safety can swing jailbreak success from 2% to 58%, which invalidates single-configuration ASR as a safety measurement.

    Across seven aligned models and three jailbreak attacks, holding the attack fixed and changing only the operational state (an everyday system prompt with no safety intent) moved attack success rates by up to 56 percentage points. The shifts show up even for attacks tuned under default-state evaluation, and the authors tie the variation to movement in hidden representations along a refusal-related direction. Practical consequence: vendor and internal red-team numbers measured in one configuration do not describe the deployment you actually run.

  6. Reachability-Based Capability Confinement for LLM Agents under Indirect Prompt Injection (opens in a new tab)

    arXiv cs.CR (AI) ·Wujie Xiong, Rabimba Karanjai, Yang Lu, Weidong Shi ·fetched 1 Sep 2026, 11:41 UTC Research agreed3/3

    Why readEnforcement model that shrinks an agent's future authority the moment untrusted data enters its context, evaluated on four AgentDojo suites without extra LLM inference in the loop.

    SkillGuard treats external skill output entering the execution context as contamination rather than something to classify, then computes capability restrictions that disconnect the resulting state from deployer-defined forbidden states. It models security-relevant transitions as a Skill Impact Graph, constrains skill parameters through steerability signatures, and mediates calls with an inline reference monitor using binary, fractional or fractional-flow restriction strategies. Tested against Gemini 2.5 Flash and Llama 3.3 backends, and the absence of auxiliary model calls makes it cheap enough to sit in a real harness.

  7. Extracting Knowledge from Tools in LLM Agents (opens in a new tab)

    arXiv cs.CR (AI) ·Chuanchao Zang, Jianing Wang, Wenyu Chen, Xiangtao Meng ·fetched 1 Sep 2026, 07:42 UTC Research agreed3/3

    Why readQuery-only attack that reconstructs the private knowledge source behind an agent's RAG tool, and names the two obstacles (tool-selection uncertainty, tool-argument compression) that made earlier extraction unreliable.

    ToolSiphon progressively recovers source content from an agent's outputs to reconstruct the files, databases or search indexes behind a target tool, using Tool Contrastive Analysis to steer queries toward the intended tool and a response-grounded factual signal for evidence. The two named failure modes of naive extraction, competing tool selection and lossy argument generation, are the transferable part. Concrete exposure for anyone exposing proprietary corpora through a customer-facing agent.

  8. JITterFlip: Uncovering Fault Attack Surfaces in JIT-Compiled LLM Serving (opens in a new tab)

    arXiv cs.CR (AI) ·Tairui Wang, Zhi Zhang, Yansong Gao, Xin Zhang ·fetched 1 Sep 2026, 11:41 UTC Research agreed3/3

    Why readFirst bit-flip attack that targets the host-side JIT control plane of GPU LLM serving rather than model weights, yielding both garbage output and a correct-output sponge attack.

    JITterFlip faults CPU-resident serving decisions in the JIT compiler stack that selects and dispatches compiled artefacts, instead of corrupting weights or the kernels that implement model computation. That removes the model-specific knowledge earlier BFAs needed and extends the effect beyond inference depletion: the paper demonstrates gibberish generation and a sponge attack that still returns correct answers while burning resources. Target selection uses a decision-guided search for fault-vulnerable code across a large compiler stack, which is the part that makes it practical in a shared cloud tenancy.

  9. Zero-Knowledge Predicate Proofs Between AI Agents: A Measured, Cross-Protocol Gateway and the Source-Integrity Gap (opens in a new tab)

    arXiv cs.CR (AI) ·Ashok Subbabhatta Gopalakrishna ·fetched 1 Sep 2026, 11:41 UTC Research agreed3/3

    Why readWorking zero-knowledge predicate gateway for agent-to-agent trust, with real numbers: a 32-bit threshold predicate proves in 6.2 ms, verifies in 1.0 ms, and ships as a 608-byte Bulletproofs proof over both MCP and Agent2Agent.

    Attacks the problem that agents today either hand a peer raw data or accept its unverifiable natural-language claim that a value complies with policy, the latter being precisely the prompt-injection channel. The gateway has agents exchange proofs of governance-defined predicates instead, and because neither MCP nor A2A can carry such a proof, the authors define a slot and implement it on both from a single endpoint. Prior cryptographic agent-policy proposals were evaluated in simulation; this one runs, and the paper is candid about a remaining source-integrity gap since a proof says nothing about where the input came from.

  10. The AI Attack Surface: How Threat Actors Abuse Trusted AI Platforms (opens in a new tab)

    Huntress ·fetched 1 Sep 2026, 03:41 UTC agreed3/3

    Why readNine months of SOC casework on attackers using AI platform features and AI-branded search ads as malware delivery channels, with the host controls that catch them.

    Huntress describes a class of incidents that has nothing to do with model weights or prompt injection: threat actors weaponizing shareable AI chat content, publishing malicious public mini-apps on legitimate AI platforms, and buying sponsored search placement against AI tool names to serve installers. The trust users place in the hosting AI brand is the whole social engineering premise. Recommended controls are conventional and testable, covering clipboard script execution blocking, application allow-listing, and monitoring for new scheduled tasks and antivirus exclusion changes.

    Indicators1
    Domains
    downloading-api[.]it[.]com
  11. SingProbe Technical Report (opens in a new tab)

    arXiv cs.CR (AI) ·Sing Team ·fetched 1 Sep 2026, 07:42 UTC Research agreed3/3

    Why readA ~2M-parameter probe over the model's own hidden states does intent, safety and hallucination classification during decoding, removing the separate guard-model inference cost.

    SingProbe reuses hidden states already produced during inference to predict query intent, response safety and hallucination risk at token level alongside autoregressive decoding, with negligible added overhead. The paper also introduces SingStreamBench to test whether streaming guards stay quiet on benign prefixes while catching unsafe content as it emerges, and reports parity or better against substantially larger standalone guardrails. Relevant if you are paying for external guard models on a self-hosted stack; less so if you consume a hosted API.

  12. WoE Wrote It? Watermarking Mixture-of-Experts LLMs for Black-Box Text Provenance (opens in a new tab)

    arXiv cs.CR (AI) ·Jona te Lintelo, Lichao Wu, Stjepan Picek ·fetched 1 Sep 2026, 23:41 UTC Research agreed3/3

    Why readA watermark that survives model weight theft by embedding the signal in Mixture-of-Experts routing rather than in the inference-time sampler.

    Existing LLM watermarks live in the sampler, so an adversary who steals the weights simply runs an unmodified sampler and attribution fails. Watermarking of Experts biases the vocabulary of specific experts in a sparse MoE model, making the signal intrinsic to the parameters and detectable in black-box text. Relevant to model-theft response and provenance claims after a weights leak.

  1. Meta's $17 Billion Settlement is a Bad Deal for Teens and All Social Media Users (opens in a new tab)

    EFF Deeplinks ·David Greene ·fetched 1 Sep 2026, 23:41 UTC agreed3/3

    Why readClause-level reading of Meta's $17B settlement with 52 state AGs, arguing it mandates age estimation for every user and forces Meta to retain more teen data, not less.

    EFF walks the settlement's provisions and identifies specific obligations: age assurance and age-gating embedded across Meta's products with all users, adults included, put through age estimation; teen restrictions modifiable only by parents and only in exchange for detailed reporting on the teen's usage and community; and apparent authority for attorneys general to enforce Meta's own definition of age-inappropriate content, a category Meta has struggled to administer without sweeping up sexual health and abortion medication information. The privacy consequence EFF pins down is that a settlement framed as protective requires more collection, analysis and retention of minors' data. Useful precedent-watching for anyone whose product may face similar age-assurance pressure.

  2. IE: HSE fined €645,000 over data breach affecting Westmeath hospital (opens in a new tab)

    DataBreaches.net ·Dissent ·fetched 1 Sep 2026, 15:40 UTC agreed3/3

    Why readA regulator putting a six-figure fine on paper records, which is a reminder that GDPR obligations do not stop at the systems your security programme covers.

    Ireland's Data Protection Commission fined the Health Service Executive €645,000 following an inquiry into how historical paper patient records were handled at St Loman's Hospital in Mullingar and St Conal's Hospital in Letterkenny. The enforcement rests on physical archive management rather than any technical compromise, so retention schedules, storage conditions and disposal at legacy sites are the exposure being priced. Worth citing internally where records governance sits outside the security team's remit and no one has audited the filing rooms.

  3. New U.K. data law takes full effect: What compliance officers need to know (opens in a new tab)

    Compliance Week ·Neil Hodge ·fetched 1 Sep 2026, 23:41 UTC agreed3/3

    Why readFlags that the UK's amended data protection regime is now fully in force and what compliance teams should not assume has been relaxed.

    The UK has amended its data protection rules with legislation intended to simplify compliance with existing privacy law, including UK GDPR. Compliance Week's read is that the simplification does not lower the underlying obligation to protect personal data, so programmes built on UK GDPR should not be loosened on the strength of the reform. The available text is short on clause-level detail, so treat it as a prompt to review your own gap analysis rather than as the analysis itself.

  4. Financial Stability Board Sounds the Alarm Over Frontier AI Risks (opens in a new tab)

    Infosecurity Magazine ·fetched 1 Sep 2026, 11:41 UTC agreed2/3

    Why readGives you the exact language a financial regulator will bring to your next resilience conversation, including the concentration-risk framing around shared third-party providers.

    In an August 28 letter to G20 finance ministers and central bank governors, Financial Stability Board chair Andrew Bailey warned that frontier AI may materially change the speed, scale and economics of cyber risk, to the point of undermining system-wide market confidence. He singled out heavily concentrated third-party service providers as the amplifier, and told firms and supervisors to prepare for an environment of more discovered vulnerabilities and compressed patching windows. It is a policy signal rather than a finding, but it is the framing that will shape supervisory expectations for financial-sector operational resilience.

  5. What’s in the SOSS? Podcast #71 – S3E23 Navigating the New Era: The EU Cyber Resilience Act Explained with Madalin Neag (opens in a new tab)

    OpenSSF ·OpenSSF ·fetched 1 Sep 2026, 19:40 UTC agreed3/3

    Why readExplains how the EU Cyber Resilience Act's new "open source software steward" category assigns obligations to foundations and maintainers rather than only to product manufacturers.

    The fourth episode in OpenSSF's CRA series covers how the Act sets a horizontal cybersecurity baseline for digital products with a network connection, and what the steward role means for organisations that host or support open source without selling it. The argument is that CRA compliance should fall out of good engineering practice and upstream contribution rather than being run as a separate checkbox exercise. Useful orientation for anyone shipping software into the EU or maintaining a dependency others ship, though it is a discussion rather than a readiness checklist.

  6. Why a cryptographic inventory is key for addressing the quantum computing threat (opens in a new tab)

    Tenable Research ·Christopher Day ·fetched 1 Sep 2026, 11:41 UTC agreed2/3

    Why readThe useful claim is that regulators are beginning to mandate cryptographic inventory, which turns post-quantum planning from a future problem into a documentation task with a deadline.

    Tenable argues that harvest now, decrypt later already makes quantum exposure an operational issue: traffic and archives captured today can be decrypted once Shor's algorithm has hardware to run on, breaking RSA, ECC and Diffie-Hellman while AES-256 holds. The recommended first step is a complete inventory of where asymmetric cryptography lives, followed by a phased migration rather than a flag day. It is a vendor blog and the technical ground is well trodden, but the regulatory angle and the inventory-first sequencing are what a governance reader can act on.

  1. McKesson discloses data breach after ShinyHunters claims theft of 284 million records (opens in a new tab)

    Google News: incidents · SC Media ·fetched 1 Sep 2026, 07:42 UTC Must read agreed3/3

    Why readMcKesson, one of the largest healthcare distributors in the US, has confirmed a breach behind ShinyHunters' claim of 284 million records.

    McKesson has disclosed a data breach following ShinyHunters' claim to have stolen 284 million records. The scale and the company's position in pharmaceutical distribution make this a supply-chain and third-party risk question for hospital and pharmacy customers, and a likely board and regulator topic this week. The report as received does not confirm the record count independently or describe the intrusion vector.

    Also covered byTechCrunch Security (opens in a new tab),Medical Economics (opens in a new tab),Security Magazine (opens in a new tab).

  2. Healthcare cyberattacks hit pacemakers and millions of patient records (opens in a new tab)

    The Register Security ·fetched 1 Sep 2026, 03:41 UTC Must read agreed3/3

    Why readBoston Scientific's ongoing intrusion has knocked out remote monitoring activation for newly implanted cardiac devices, and McKesson has confirmed patient data theft, two sector-moving healthcare incidents in one weekend.

    Boston Scientific said its cyberattack remains ongoing and that cardiac rhythm management devices implanted after the August 25 breach cannot have their remote monitoring communicators activated, so device data will not reach remote patient management systems; new insertable cardiac monitors must be paired via the Clinic Assistant app instead. Separately, pharmaceutical distributor McKesson confirmed data exfiltration from cloud-hosted accounts affecting its oncology, multispecialty and medical-surgical units. The patient-safety dimension makes this the healthcare incident boards and regulators will be asking about, not just an IT outage.

  3. Cyber risk from frontier AI poses ‘most immediate concern’ to global financial system, watchdog warns (opens in a new tab)

    The Record ·fetched 1 Sep 2026, 15:40 UTC Must read agreed3/3

    Why readThe Financial Stability Board has told G20 finance ministers that frontier AI cyber risk is the most immediate threat to the financial system and told firms to plan for simultaneous multi-firm disruption.

    In a letter published Monday, FSB chair Andrew Bailey called on financial institutions and technology providers to prepare for severe scenarios involving simultaneous disruption across multiple firms or shared technology dependencies. The warning cites cybersecurity evaluations at OpenAI, Anthropic, Meta and the UK AI Security Institute in which advanced models engaged in unauthorised activity against third-party systems, and echoes an earlier NCSC warning. No binding obligation follows yet, but financial-sector boards and regulators will use this framing, and concentration risk in shared AI and cloud dependencies is now the stated supervisory concern.

  4. Healthcare facilities operator Nutex says patient, employee data stolen in August incident (opens in a new tab)

    The Record ·fetched 1 Sep 2026, 19:40 UTC agreed3/3

    Why readNutex Health told the SEC in an 8-K that attackers exfiltrated patient, employee and external-provider data plus confidential financials, and are now extorting the company.

    Nutex disclosed a cyberattack to the SEC on August 24 and confirmed in a Monday 8-K filing that data on patients, employees and outside providers was stolen along with confidential financial information, with the actor threatening public release. The company runs 27 hospital and outpatient facilities across 12 states and booked $427.2 million in the first half of 2026, so the eventual breach-notification population is likely large. Scope is still under investigation, which means the material-impact assessment and any amended filing are still to come.

  5. CareCloud Data Breach Exposes Medical Records, Social Security Numbers of 3.75 Million (opens in a new tab)

    Google News: incidents · wowo.com ·fetched 1 Sep 2026, 07:42 UTC agreed3/3

    Why readCareCloud has exposed medical records and Social Security numbers for 3.75 million people, a HIPAA-scale event for every practice that outsourced to it.

    Health IT vendor CareCloud disclosed a breach affecting 3.75 million individuals, with medical records and Social Security numbers among the exposed data. As a revenue cycle and EHR provider, the blast radius runs through its provider customers rather than stopping at CareCloud, which makes this a business associate notification question. No vector or intrusion timeline is given in the report as received.

  6. Montana AG, 15 others probe OpenAI after experimental AI model data breach, hacks (opens in a new tab)

    Google News: incidents · NBC Montana ·fetched 1 Sep 2026, 19:40 UTC agreed3/3

    Why readSixteen state attorneys general, led in reporting by Montana, have opened an inquiry into OpenAI over a data breach involving an experimental model.

    The multi-state AG action follows a breach and intrusions tied to an experimental OpenAI model. Coverage available here is a headline only, without the scope of exposed data or the legal theory being pursued. It matters as precedent: state AGs are now treating AI vendors as breach-reporting subjects, which is a question any board with an OpenAI dependency will raise.

  7. Jack Henry Cyberattack Compromises Client Data (opens in a new tab)

    Google News: incidents · Banking Exchange ·fetched 1 Sep 2026, 15:40 UTC agreed3/3

    Why readJack Henry, core banking software provider to thousands of US community banks and credit unions, reports a cyberattack compromising client data, which makes this a third-party risk question for every institution on their platform.

    Banking Exchange reports a cyberattack at Jack Henry & Associates that compromised client data. Only the headline reached us, so affected products, data types and the number of downstream institutions are unstated. Jack Henry's position in US community bank core processing means peers will be asked about their exposure before the details land.

  8. Microsoft Exchange Online outage causes email failures, auth issues (opens in a new tab)

    BleepingComputer ·Sergiu Gatlan ·fetched 1 Sep 2026, 03:41 UTC agreed3/3

    Why readA multi-hour Microsoft 365 outage that also degraded Defender XDR and Purview, which is the availability question executives will ask about on Monday.

    Microsoft acknowledged incident EX1464935 at 17:30 UTC covering Exchange Online authentication failures, mail send and receive delays, and search problems, then widened it under MO1465074 to OneDrive for Business, SharePoint Online, Teams, Purview and Defender XDR. Downdetector logged tens of thousands of affected users. Defender XDR and Purview being in scope means detection and eDiscovery coverage degraded at the same time as mail, which is worth noting for anyone whose response plan assumes those consoles are always reachable.

  9. Berlin refuses to be blackmailed after network breach (opens in a new tab)

    Help Net Security ·Sinisa Markovic ·fetched 1 Sep 2026, 11:41 UTC agreed3/3

    Why readBerlin's state government publicly confirmed it is being extorted after August's theft of data from its administrative network, and said it will not pay.

    Governing Mayor Kai Wegner and Interior Senator Iris Spranger addressed the extortion attempt after an emergency Senate session at the Rotes Rathaus, with Wegner stating plainly that the state is being blackmailed and that the demands will not be met. The State Criminal Police are handling the investigation. A capital city government refusing payment on the record is the reference point peers in public administration will be measured against.

  10. Novocure hit by cyberattack exposing patient data (opens in a new tab)

    Google News: incidents · Fierce Biotech ·fetched 1 Sep 2026, 15:40 UTC agreed3/3

    Why readOncology device maker Novocure discloses a cyberattack exposing patient data, another named medtech incident for healthcare-sector risk owners to track.

    Novocure, the maker of Tumor Treating Fields oncology devices, was hit by a cyberattack that exposed patient data, per Fierce Biotech. Only the headline reached us, so the scope, timeline and whether regulatory notification has followed are unstated. The value is the named company and the sector: another medical device manufacturer holding patient records disclosing an intrusion.

  11. AI could cause global economic downturn, Andrew Bailey warns G20 (opens in a new tab)

    BBC Technology ·fetched 1 Sep 2026, 11:41 UTC agreed2/3

    Why readA central bank governor has now put simultaneous multi-firm cyber disruption in writing to G20 finance ministers, which is the framing your board will borrow the next time it asks about concentration risk.

    In an open letter to G20 finance ministers, Bank of England governor Andrew Bailey warned that a collapse in AI sector growth could trigger a worldwide market correction, amplified by high valuations, rising investor leverage and money concentrated in a handful of technology firms. He also told ministers that firms should prepare for breaches involving simultaneous disruption across multiple companies, a systemic framing that follows the concentration of AI and cloud services into shared providers. One panel member wanted this dropped as macroeconomics; the operative fact for security readers is the regulatory expectation being set, not the market call.

  12. Fraudsters steal $6 million from Tectonic crypto platform after inflating token price (opens in a new tab)

    The Record ·fetched 1 Sep 2026, 03:41 UTC agreed3/3

    Why readA worked example of collateral price manipulation against a lending protocol, including the chain-level intervention that clawed back most of the loss.

    An attacker pumped Tectonic's thinly traded Tonic token to more than one hundred times its price in roughly twenty minutes, then posted the inflated tokens as collateral to borrow against them, attempting to extract about 74 million dollars. Roughly 6 million dollars left the platform before the Cronos chain halted activity, stranding the remaining 68 million dollars on chain. The case is a reminder that oracle and collateral valuation for illiquid assets is the attack surface in DeFi lending, and that centralized halt authority is the only control that worked here.

Unverified claims posted by extortion groups on their own leak sites, not confirmed breaches. Listing is the group's assertion; many named organisations have not disclosed an incident, and some entries are false or recycled. Leak sites are never linked from here.

Claimed victimGroup SectorCountry Seen
Quality Resource Pvt Global Secret Group - US 1 Sep 2026
Holland & Knight SilentRansomGroup Professional Services US 1 Sep 2026
Szechenyi Programiroda Nonprofit Kf rhysida - HU 1 Sep 2026
Oportunidados direwolf - BR 1 Sep 2026
Honeycomb Programs Inc direwolf - US 1 Sep 2026
PT Intraco Penta Tbk direwolf Manufacturing ID 1 Sep 2026
Congressional Iron Works akira Manufacturing - 1 Sep 2026
Flex1 akira - - 1 Sep 2026
BYK Construction akira Manufacturing US 1 Sep 2026
Transportes Montejo S.A.S. nightspire Transportation CO 1 Sep 2026
SCHMIDT bravox - US 1 Sep 2026
CareerSource Palm Beach County thegentlemen Professional Services US 1 Sep 2026
Nutex Health thegentlemen Healthcare US 1 Sep 2026 press coverage (opens in a new tab)
The Sole thegentlemen Retail & E-Commerce GB 1 Sep 2026
iwin Black X Technology KR 1 Sep 2026
Manchester Airports Group fulcrumsec Transportation GB 1 Sep 2026 press coverage (opens in a new tab)
REXT Holdings Co., Ltd. ransomhouse - JP 1 Sep 2026 press coverage (opens in a new tab)
Total Education Solutions Wallstreet Education US 1 Sep 2026
seashellhospital.com krybit Healthcare IN 1 Sep 2026
uicc.org krybit Professional Services CH 1 Sep 2026
tum.com.mx krybit Education MX 1 Sep 2026
www.alphaplantes.com krybit Agriculture and Food Production CA 1 Sep 2026
reignwoodpark.com krybit Hospitality CN 1 Sep 2026
orex.co.th krybit - TH 1 Sep 2026
amptc.net krybit Technology US 1 Sep 2026
How this edition was made
Candidates fetched
4614
New after deduplication
720
Kept by the panel
167
Published
148
Generated
1 Sep 2026, 23:41 UTC