CFToday Curated security signals.

Daily edition · 2026-09-02

Wednesday, 2 September 2026

64 items across 8 sections, selected from 4751 candidates over 6 runs. 110 carried the panel unanimously.

Show
Section

India

1

Indian organisations, regulators and infrastructure, pulled out of the sections below.

  1. India preparing rollout of agentic payments on UPI (opens in a new tab)

    Economic Times Tech ·AI Security ·fetched 2 Sep 2026, 07:37 UTC agreed2/3

    Why readThe world's largest retail payment rail is preparing to let AI agents spend without per-transaction approval, which sets the scale of the authorization problem practitioners will inherit.

    Reuters-style reporting from three unnamed sources says India is drafting a framework for AI agents to make small UPI payments without user approval on each transaction, putting a national payment rail behind agentic spending rather than a single provider's wallet. UPI cleared 24.51 billion transactions in the reference month, so any mandate model, spending cap or revocation path chosen here becomes the default that fraud and abuse teams have to work against. The story carries no technical detail on how agent identity, mandate limits or dispute handling would work, so treat it as a scoping signal rather than a design document.

  1. BGP hijack infecting networks caused by a comedy of errors that’s not funny at all (opens in a new tab)

    Ars Technica Security ·Dan Goodin ·fetched 2 Sep 2026, 11:38 UTC Must read agreed3/3

    Why readA supply-chain compromise executed by BGP hijack of Softaculous address space plus fraudulent TLS issuance, pushing malware as legitimate Virtualizor and cPanel-adjacent updates to hosting providers and data centres.

    Attackers exploited gaps in Hetzner Online's routing security posture to hijack IP space assigned to Softaculous, the UAE-based maker of Virtualizor and web software installation tooling, then obtained valid TLS certificates for the hijacked addresses via domain validation. With control of the update and billing infrastructure they served malware to downstream users as software updates. The combination of BGP hijack and DV certificate issuance to defeat transport trust is the part worth internalising: RPKI posture and certificate transparency monitoring are the controls that would have caught it.

    Also covered bySecurityWeek (opens in a new tab),Risky Business News (opens in a new tab).

  2. Peer Pressure: Inside the Sality Botnet Disruption Operation (opens in a new tab)

    CrowdStrike ·CrowdStrike Counter Adversary Operations ·fetched 2 Sep 2026, 07:37 UTC Must read agreed3/3

    Why readA peer-to-peer sinkholing operation executed on 31 August 2026 isolated roughly 15,000 Sality-infected machines and cut the operator's command channel.

    CrowdStrike's Counter Adversary Operations team, working with DOJ, FBI, DCIS, Shadowserver, Europol, Eurojust and police in Bulgaria, Hungary and Romania, disrupted the Sality P2P botnet by sinkholing at the peer layer rather than seizing central infrastructure. Sality has run for more than two decades and was being used to push payloads to over 15,000 infected hosts. If you have hosts in that population expect Shadowserver notification traffic, and the P2P sinkholing approach is the transferable part for anyone tracking decentralised botnets.

    Indicators3
    URLs
    hxxp://painelwebradiodigital[.]awardspace[.]info/v3/readme[.]pdf
    Domains
    forex2030[.]com kharkovforum[.]com

    Also covered byThe Record (opens in a new tab),The Register Security (opens in a new tab).

  3. Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon (opens in a new tab)

    Check Point Research ·stcpresearch ·fetched 2 Sep 2026, 11:38 UTC Must read Research agreed3/3

    Why readDocuments malicious Apache modules compiled onto compromised web servers that reverse-proxy visitors to phishing pages while traffic still appears to come from the legitimate government domain, with the site's own security headers stripped.

    Check Point tracks Gambling Goblin, a Chinese-speaking cybercrime cluster tied to the previously documented Earth Berberoka, running a campaign against Brazilian government and educational organisations since mid-2025. The operators install malicious Apache modules on victim servers to silently proxy traffic to attacker-controlled pages posing as Google Play, Microsoft Store and Amazon, stripping response security headers so injected content executes, and pair this with large-scale SEO manipulation to push gambling and betting sites. It marks a foreign operator moving into a market previously dominated by home-grown banking trojans, and the server-side module abuse is worth hunting for on any public web estate.

    Indicators13
    Hashes
    232ef6be134c2b7c14648aa193daf7e23e987477b8a40150dd77883947fdf017 088d0742a667f1acfc83edb94671a10b951f6745badec6d5c754ef594dddf815 88544d36beb6dc621c9376806836d0ad109ece64b589605d5674e0c86313d1c0 9d3085eac9a59a94f0473db5ec0173def8777d2f794da281fb1749389ae33cdb 263c14e84398339b25cd3e59da7e108340306fdbb8112bbe7dc0f07a71eb8a31 12af9d95c44e20a375148c25f8a2978a62ee95489134654c3537ccfb2d42120d 5af1bec4635e52da4909bf744ea4b7e4483ec944241218855212f4a9e3d48611 e8bb763bd10e727228ca9a8e3e6cf10bf4de4639b6be680a3abfb181a0adc052 fa7fc029ac13af2f3880151e9c408e9afadeba7b2cff01659806fb7c3c83288d c3c09fe219e10808f053e580628aeb87b1f00fc683c810aa828905fe03cda98f 2567d6b42dac97a391217ad22ee375f504d541940d3fbb9436a3f5e9bb23ab91 1829efbf7946e1a958779a3e7f1e50ca63fe61c6a2ddc177c14a7b0c5e10020a
    Domains
    playfootball[.]info
  4. I rented a car, and within hours, my driver's license was for sale (opens in a new tab)

    Ars Technica Security ·Dan Goodin ·fetched 2 Sep 2026, 23:39 UTC agreed2/3

    Why readThe infrared and ultraviolet captures are the detail that matters: stolen ID images now carry the data needed to clone documents that survive hologram and security feature checks.

    KrebsOnSecurity exposed Nexus, an identity theft service advertising scans of more than 153 million driver's licenses, alongside other document types, with victims including Krebs himself, an FBI assistant director and several security researchers plus the Ars reporter who wrote this piece. Each listing reportedly bundles front and back images in visible, infrared and ultraviolet spectrums, which is the material a counterfeiter needs to reproduce features that ordinary photocopies miss. For anyone running remote identity proofing or KYC, this raises the floor on what a document-image check can be assumed to prove.

  5. Kim Sooki again? This time, it was disguised as a request for seafood ingredients (opens in a new tab)

    AhnLab ASEC ·ATCP ·fetched 2 Sep 2026, 11:38 UTC Research agreed3/3

    Why readBreaks down a Kimsuky LNK lure named "[Royal Hotel Seoul] Request for Review of Seafood Ingredient Purchases.LNK" that drops a real HWP decoy while PowerShell registers a scheduled task and wipes its traces.

    AhnLab analysed a malicious LNK distributed to Korean targets and attributed to Kimsuky. Execution opens a legitimate HWP document so the victim sees an ordinary business request, while embedded PowerShell extracts system information, sends it out, pulls and runs follow-on commands, and registers a scheduled task for persistence before cleaning up artefacts. The lure theme and the decoy-plus-scheduled-task pattern are familiar, but the file naming and execution chain are concrete enough for detection work.

  6. Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 2 Sep 2026, 03:42 UTC agreed3/3

    Why readTwo previously undocumented cross-platform RATs, NodeRabbit and PollCat, delivered by Iranian actor Nimbus Manticore inside trojanized coding-challenge archives sent through LinkedIn.

    Kaspersky attributes NodeRabbit and PollCat to Nimbus Manticore, a shift from the group's earlier C, C++ and Go tooling toward Node.js and obfuscated JavaScript that extends its reach to Linux and macOS. Delivery is fake-recruiter spear-phishing on LinkedIn and job boards carrying trojanized coding-test archives. First NodeRabbit sample came from a system in Afghanistan, with later sightings in Egypt and Ethiopia, suggesting a wider targeting footprint than the group's usual regional focus.

    Indicators3
    Domains
    plugplay[.]azurewebsites[.]net rgbteller[.]azurewebsites[.]net wslwebui[.]azurewebsites[.]net
  7. Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency (opens in a new tab)

    Dark Reading ·Robert Lemos ·fetched 2 Sep 2026, 07:37 UTC agreed3/3

    Why readAn unpatched ownCloud flaw was enough to give attackers reactor databases, personnel records and credential stores at the Philippine nuclear agency.

    Attackers used a commodity, long-patched ownCloud vulnerability for initial access into the Philippine Nuclear Research Institute, then took reactor-related databases, staff records and stored credentials. The interest is not the technique but the target class: a national nuclear body still exposing a file-sharing appliance with a known bug. Worth checking your own ownCloud estate and any internet-facing file-share appliance for the same unpatched state.

  8. Leaked Russian Cyber-Operations Training Materials (opens in a new tab)

    Schneier on Security ·Bruce Schneier ·fetched 2 Sep 2026, 11:38 UTC agreed3/3

    Why readLeaked Bauman university records describe a formal recruitment-to-service pipeline feeding the GRU, the Main Operational Directorate and the 8th Directorate, with one 2024 graduate placed in Military Unit 74455 (Sandworm).

    The material frames Russian offensive cyber capability as an institutional force-generation system rather than a set of named threat groups, with students given supervised technical and ideological preparation before assignment to intelligence and cyber units. Aleksei Kondrashov, a 2024 Department No. 4 graduate, is linked to Unit 74455, the unit behind NotPetya and destructive operations against Ukraine. The reporting is careful that listed graduates represent reported unit placements, not evidence of participation in specific operations.

  9. Attackers are going after prominent individuals through OAuth phishing, FBI warns (opens in a new tab)

    Help Net Security ·Sinisa Markovic ·fetched 2 Sep 2026, 11:38 UTC agreed3/3

    Why readThe FBI's IC3 warns that OAuth consent phishing has been used since late 2025 to take persistent account access from prominent individuals, along with their relatives and personal contacts, without ever capturing a password.

    Rather than stealing credentials, the attackers get victims to grant a malicious application consent, which yields durable access to mail and files and survives password resets. Relatives and personal contacts are targeted alongside the principal, which widens the account set defenders need to cover. The practical response is auditing third-party app grants and tightening consent policy for high-risk users; the write-up is a summary of the IC3 alert, so go to the original for any indicators.

  10. New pro-Ukraine hacker group targets Russian companies with custom ransomware (opens in a new tab)

    The Record ·fetched 2 Sep 2026, 15:38 UTC agreed3/3

    Why readF6 attributes a new ransomware operation, VantaCore, to a rebrand of the pro-Ukrainian group Thor, with at least seven victims since August and a leak site standing up in early June.

    Russian security firm F6 reports that VantaCore, a ransomware operation hitting Russian organisations with custom malware and multimillion-dollar demands, is a rebrand of Thor, a pro-Ukrainian group credited with at least 12 attacks in 2025. Activity was first detected in August, though the data-leak site was created in early June. F6 assesses VantaCore as primarily financially motivated, in contrast to Thor's mix of extortion and destructive or politically motivated activity. This is a summary of the F6 report rather than the indicator detail itself.

  11. Iran attempted cyberattacks on range of U.S. infrastructure, sources say (opens in a new tab)

    Google News: incidents · NBC News ·fetched 2 Sep 2026, 11:38 UTC agreed2/3

    Why readNotice that Iranian operators have been probing US critical infrastructure across multiple sectors, useful as a targeting signal even though the reporting carries no technical detail.

    NBC News reports, citing unnamed sources, that Iran attempted cyberattacks against a range of US infrastructure targets. No sectors, victims, intrusion methods or outcomes are specified in the available reporting. Treat it as a prompt to check exposure and monitoring in likely target sectors rather than as actionable intelligence.

  12. Hackers expose donor data from Russian fundraisers for Ukrainians, political prisoners (opens in a new tab)

    The Record ·fetched 2 Sep 2026, 15:38 UTC agreed3/3

    Why readA single shared integration, Stripe wired into WooCommerce on WordPress, was the way into two separate civil society fundraisers, which makes it worth auditing if you run donation or auction sites on that stack.

    Davayte, which raises money for Ukrainian civilians, and You Are Not Alone, which supports Russian political prisoners, both disclosed mid-August compromises of their payment accounts. The attacker came in through the same place in each case: the Stripe and WooCommerce integration the projects used to run online auctions. Exposure was limited to donor email addresses plus, for some, the last four digits of cards and the issuing bank; full card numbers and cardholder names were not taken.

  1. SonicWall warns of actively exploited SMA1000 zero-day flaws (opens in a new tab)

    BleepingComputer ·Sergiu Gatlan ·fetched 2 Sep 2026, 07:37 UTC Must read agreed3/3

    Why readTwo SMA1000 zero-days are being chained for remote code execution right now, with over 400 appliances exposed and a hotfix available.

    SonicWall confirmed active exploitation of CVE-2026-83548, a maximum-severity command injection in the SMA1000 Appliance WorkPlace interface rooted in an SSRF weakness, chained with CVE-2026-83549, a command injection in the Appliance Management Console reachable with admin privileges. Affected models are the SMA1000 6210, 7210 and 8200v; SSL-VPN on SonicWall firewalls and the SMA 100 Series are not affected. Shadowserver tracks more than 400 exposed SMA1000 appliances, and SonicWall is urging immediate upgrade to the hotfix release.

    Also covered byRapid7 (opens in a new tab),Sophos Threat Research (opens in a new tab),SecurityWeek (opens in a new tab),The Hacker News (opens in a new tab),CISA KEV (opens in a new tab),The Register Security (opens in a new tab),CSO Online (opens in a new tab).

  2. CISA Adds Seven Known Exploited Vulnerabilities to Catalog (opens in a new tab)

    CISA Advisories ·CISA ·fetched 2 Sep 2026, 19:41 UTC CVE-2026-49869 EPSS 1.1% agreed3/3

    Why readSeven new KEV entries with a federal remediation deadline, including two SonicWall SMA1000 bugs and an auth bypass in BerriAI LiteLLM.

    CISA added CVE-2026-9586 (Sangoma Switchvox SQLi), CVE-2026-48710 (Starlette request smuggling), CVE-2026-49869 (Kestra OSS command injection), CVE-2026-59822 (BerriAI LiteLLM improper authentication), CVE-2026-82329 (JFrog Artifactory improper authentication) and the SonicWall SMA1000 pair CVE-2026-83548 and CVE-2026-83549 to the Known Exploited Vulnerabilities catalog. All are backed by evidence of active exploitation, and BOD 26-04 obliges FCEB agencies to remediate on the catalog timeline. The LiteLLM and Kestra entries are notable: exploited bugs in AI and workflow orchestration middleware that often sits behind weak network controls.

  3. Hackers exploit critical JFrog Artifactory flaw to forge admin tokens (opens in a new tab)

    BleepingComputer ·Bill Toulas ·fetched 2 Sep 2026, 19:41 UTC CVE-2026-82329 EPSS 1.2% agreed3/3

    Why readCVE-2026-82329, an authentication bypass in JFrog Artifactory's default self-managed configuration, is being exploited to mint admin tokens, which puts every artefact downstream systems pull automatically in scope.

    watchTowr observed unauthenticated attackers gaining administrative permissions on internet-reachable self-managed Artifactory instances; JFrog's advisory confirms the default configuration is affected but shares little else. The blast radius is the concern rather than the box itself, since admin access to a repository manager reaches signed and released artefacts that build pipelines trust implicitly. Patch, then audit tokens, admin accounts and recently published artefacts for tampering.

    Also covered byCSO Online (opens in a new tab),Dark Reading (opens in a new tab).

  4. Multiple vulnerabilities in SonicWall Secure Mobile Access (opens in a new tab)

    translated Multiples vulnérabilités dans SonicWall Secure Mobile Access (02 septembre 2026)

    CERT-FR (ANSSI) ·fetched 2 Sep 2026, 15:38 UTC CVE-2026-83548 EPSS 0.3% agreed2/3

    Why readTwo SonicWall SMA1000 flaws are being exploited now, and one of them, CVE-2026-83548, is a server-side request forgery reachable with no authentication at all.

    SonicWall's SNWLID-2026-0016 advisory of 1 September covers CVE-2026-83548, an unauthenticated SSRF rated critical, and CVE-2026-83549, arbitrary remote code execution available to an authenticated administrator, both confirmed under active exploitation. The vendor does not say whether the pair can be chained to take an appliance from unauthenticated to code execution, and CERT-FR calls that ambiguity out, so plan on the worst reading. Affected models are the SMA1000 6210, 7210 and 8200v; move 12.5.x builds to 12.5.0-02952 and anything older to 12.4.3-03526, then hunt for compromise rather than assuming patching closes the incident.

  5. CVE-2026-48710: Kludex Starlette, Kludex Starlette HTTP Request/Response Smuggling Vulnerability (opens in a new tab)

    CISA KEV ·fetched 2 Sep 2026, 19:41 UTC CVE-2026-48710 Exploited in the wild · patch by 2026-09-16 EPSS 2.1% agreed3/3

    Why readStarlette, the ASGI layer under FastAPI, is now a confirmed exploited KEV entry with a 16 September federal deadline and a chainable second bug.

    CVE-2026-48710 lets an attacker inject path segments into the Host header so Starlette reconstructs a URL whose path differs from the one actually routed, bypassing authentication that keys off the reconstructed path. CISA notes it can be chained with CVE-2026-42271. EPSS is only 0.021 but KEV listing means exploitation is confirmed; the remediation deadline is 2026-09-16 under BOD 26-04, and the blast radius covers anything built on FastAPI or Starlette directly.

  6. Hackers Actively Exploiting Critical Langflow RCE and Rails Vulnerability (opens in a new tab)

    Cybersecurity News ·Abinaya ·fetched 2 Sep 2026, 07:37 UTC CVE-2026-0768 EPSS 2.3% agreed3/3

    Why readCVE-2026-0768, an unauthenticated RCE in Langflow's custom component code validator, is in KEV and VulnCheck is seeing roughly 360 exploitation attempts against internet-facing sensors.

    VulnCheck canary systems logged exploitation of CVE-2026-0768 shortly after the bug entered the Known Exploited Vulnerabilities catalog, rising from more than 50 detections to around 360, with attacker behaviour running from reconnaissance through secret harvesting to code execution. The flaw sits in the code validator behind Langflow's custom component editor and needs no authentication; it was disclosed via ZDI in January and no public proof of concept was known when the attacks began. A Ruby on Rails issue is being worked the same way, so treat exposed Langflow instances as compromised until checked and pull them off the internet.

    Also covered bySecurity Affairs (opens in a new tab).

  7. Recently patched PaperCut zero-days used in data theft attacks (opens in a new tab)

    BleepingComputer ·Sergiu Gatlan ·fetched 2 Sep 2026, 07:37 UTC agreed3/3

    Why readTwo chainable PaperCut NG/MF flaws exploited as zero-days are now being used for data theft, with three rounds of emergency patches in five days.

    CVE-2026-81578 and CVE-2026-82078 can be chained to bypass authentication and achieve remote code execution on PaperCut NG and MF print servers, deployed across more than 70,000 organizations. PaperCut shipped emergency patches on Thursday, Friday and Tuesday, with CEO Chris Dance describing the first as a mitigation and the second as further hardening, and warning that more emergency releases may follow before a fully regression-tested build. Get servers off the internet and patched; assume data access on anything exposed.

  8. Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 2 Sep 2026, 15:38 UTC CVE-2026-9586 EPSS 1.1% agreed3/3

    Why readUnauthenticated SQL injection in Sangoma Switchvox SMB 8.3 (CVE-2026-9586, CVSS 9.3) is being exploited for RCE as the PostgreSQL superuser; patch is 8.4.0.2.

    The /pa endpoint in Sangoma Switchvox SMB Edition 8.3 (104997) parses XML starting with <PolycomIPPhone> and concatenates the user-controlled PhoneIP value straight into PostgreSQL queries, giving an unauthenticated attacker arbitrary SQL and code execution as the database superuser from a single crafted request. Sangoma shipped a fix in Switchvox 8.4.0.2 on 14 July 2026, and exploitation is now reported in the wild. EPSS sits low at 0.011, but that lags observed attacks on a VoIP appliance that is frequently internet-facing, so treat the patch as urgent and check /pa access logs.

    Also covered byCISA KEV (opens in a new tab),BleepingComputer (opens in a new tab),Help Net Security (opens in a new tab).

  9. CVE-2026-49869: Kestra Kestra OSS, Kestra OSS OS Command Injection Vulnerability (opens in a new tab)

    CISA KEV ·fetched 2 Sep 2026, 19:41 UTC CVE-2026-49869 Exploited in the wild · patch by 2026-09-05 EPSS 1.0% agreed3/3

    Why readKestra OSS workflow orchestrators can be made to create and run arbitrary workflows without credentials, which is unauthenticated RCE on a system that usually holds pipeline secrets.

    CVE-2026-49869 is an OS command injection in Kestra OSS allowing an unauthenticated remote attacker to create and execute arbitrary workflows. Orchestrators hold cloud credentials and database connection strings, so execution there is generally a path to the wider environment. KEV deadline is 2026-09-05; audit workflow creation history as well as patching, since exploitation leaves executed-workflow artefacts.

  10. CVE-2026-59822: BerriAI LiteLLM, BerriAI LiteLLM Improper Authentication Vulnerability (opens in a new tab)

    CISA KEV ·fetched 2 Sep 2026, 19:41 UTC CVE-2026-59822 Exploited in the wild · patch by 2026-09-16 EPSS 0.5% agreed3/3

    Why readLiteLLM's MCP Streamable HTTP endpoint accepts any Bearer token as a valid session, and it is now confirmed exploited with a 16 September deadline.

    CVE-2026-59822 is an improper authentication flaw letting an unauthenticated attacker establish an authenticated MCP session against BerriAI LiteLLM using an arbitrary Bearer token. Anyone who can reach the endpoint gets whatever tool access the proxy fronts, which in most LiteLLM deployments means model access plus registered MCP tooling. EPSS is low at 0.005, but KEV membership overrides that; remediate by 2026-09-16.

    Also covered byCybersecurity News (opens in a new tab).

  11. Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks (opens in a new tab)

    BleepingComputer ·Sergiu Gatlan ·fetched 2 Sep 2026, 07:37 UTC agreed3/3

    Why readPublic exploit code exists for an Exchange auth bypass that hands over every user's mailbox, and roughly 22,000 internet-facing servers are still unpatched.

    CVE-2026-62911, reported by Orange Tsai of DEVCORE and patched in the August 2026 Patch Tuesday, is an authentication bypass by capture-replay affecting Exchange Server 2016, 2019 and Subscription Edition. A low-privileged attacker on the server can elevate over the network and take over all mailboxes, reading and sending mail and pulling attachments; exploitation is low complexity but needs user interaction. NCSC-NL reported last week that exploit code is already circulating, and scan data still shows close to 22,000 exposed unpatched servers.

    Also covered byHelp Net Security (opens in a new tab).

  12. CVE-2026-66047 (CVSS 9.2): ProfilePress (wp-user-avatar) WordPress plugin before 4.17.2 contains an unauthenticated remote code execution vulnerability that allows unauthenticat (opens in a new tab)

    NVD ·fetched 2 Sep 2026, 19:41 UTC CVE-2026-66047 CVSS 9.2 EPSS 0.5% agreed3/3

    Why readUnauthenticated RCE in the ProfilePress WordPress plugin before 4.17.2 by brute-forcing a 32-bit connect token to install an arbitrary plugin.

    ProfilePress (wp-user-avatar) exposes a ppress_connect_process AJAX handler guarded only by a weak 32-bit connect token that an unauthenticated attacker can brute-force. With the token, the file request parameter takes an attacker-controlled URL and the plugin silently downloads, installs and activates it, yielding PHP execution as the web server user. Fixed in 4.17.2; WordPress plugin RCE with a public technical description reliably attracts mass scanning, so patch rather than schedule.

  1. Athena: Vulnerability-Affected Library Identification via Knowledge Graph Completion (opens in a new tab)

    arXiv cs.CR (AI) ·Phong Trinh Duy, Trang Dang Yen, Hung Nguyen-Huu, Bach Le ·fetched 2 Sep 2026, 03:42 UTC Research agreed3/3

    Why readTargets a data-quality problem that quietly breaks vulnerability management: over half of vulnerability database entries have missing or wrong affected-library fields.

    Athena models a vulnerability database as a knowledge graph linking CVEs, libraries, CWE types, CPE products and ecosystems, then treats missing affected-library data as a link prediction problem rather than text retrieval. A re-ranking stage rescores the graph completion candidates with a fine-tuned LLM augmented by graph embeddings, combining relational structure with textual signal. The framing matters for anyone whose SCA or inventory tooling inherits bad affected-library metadata from upstream feeds.

  2. SVP Is NP-Hard for Some Rank-2 Cyclotomic Modules (opens in a new tab)

    arXiv cs.CR (all) ·Jiaqi Liu, Yansong Feng, Yanbin Pan ·fetched 2 Sep 2026, 19:41 UTC Research agreed3/3

    Why readA hardness result for structured lattices that keeps the module rank fixed at two, which is closer to the shape of deployed post-quantum schemes than earlier NP-completeness proofs.

    The authors give a deterministic polynomial-time many-one reduction from Exact Cover by 3-Sets to decision SVP in the l2 norm over full-rank free submodules of O_K^2, where K is the qth cyclotomic field for primes q congruent to 3 mod 4. The interesting constraint is that module rank stays at two while the underlying Z-lattice rank grows as 2(q-1), and the proof handles closure under O_K multiplication using a mapping of the Bennett and Peikert Reed-Solomon lattice into a principal cyclotomic ideal plus a quadratic Gauss sum checker. Read it as foundational assurance work, not as a change to any deployment: exact SVP hardness says nothing directly about the approximation factors Kyber and Dilithium actually rest on.

  3. A SoK for SoCs: Reading the TI Leaves on AI for Cyber Threat Intelligence Generation and Sharing (opens in a new tab)

    arXiv cs.CR (AI) ·Saastha Vasan, Hadjer Benkraouda, Jizhou Chen, Leyan Pan ·fetched 2 Sep 2026, 03:42 UTC Research agreed3/3

    Why readNames the four concrete failure points practitioners hit when turning raw attack evidence into shareable intelligence, a stage the academic literature has largely skipped.

    The authors survey the CTI literature and find the collection and consumption stages well covered while generation and sharing is barely studied, then interview practitioners who actually do the work. Those practitioners describe a largely manual pipeline with four recurring problems: keeping sensitive information out of what gets shared, pulling indicators from noisy evidence, mapping observed behaviour to standardised TTPs, and reformatting the result for sharing platforms. The paper then decomposes the stage into four steps to give future tooling something to aim at.

  4. Our latest Linux Foundation Europe donation will build a more private digital world. (opens in a new tab)

    Google Safety & Security ·Abhi Shelat ·fetched 2 Sep 2026, 19:41 UTC agreed2/3

    Why readThe zero-knowledge proof library behind selective disclosure for digital IDs now sits under neutral stewardship, which changes whether you can build on it.

    Google has donated its Longfellow zero-knowledge proof library, open-sourced last year, to the Post-Quantum Cryptography Alliance under Linux Foundation Europe. The practical use case is proving a single attribute from a digital credential, age over 18 for example, without disclosing the rest of the document, with a post-quantum posture built in. The substance here is governance rather than cryptography: vendor-neutral stewardship and an auditable upstream are what make a library like this viable for identity deployments that cannot depend on one company's roadmap.

  5. Managing identity source transition for AWS IAM Identity Center (opens in a new tab)

    AWS Security ·Xiaoxue Xu ·fetched 2 Sep 2026, 23:39 UTC agreed2/3

    Why readOperational runbook for the one IAM Identity Center change that silently destroys every user, group and account assignment if you cut over without preparation.

    AWS walks through switching the identity source behind IAM Identity Center, covering moves between the built-in identity store, Active Directory and external IdPs, and the republished version adds Active Directory migration strategies and automation for recreating permission sets. The core point is that a cutover without an export and restore plan leaves users without access to accounts and applications until assignments are rebuilt by hand. Useful if you have this migration on your roadmap and largely inert otherwise, and it is vendor documentation rather than independent analysis.

DFIR

1
  1. Exfiltration in Plain Sight: How the SafePay Ransomware Group Abused OneDrive to Steal Data (opens in a new tab)

    Sygnia ·Sygnia ·fetched 2 Sep 2026, 11:38 UTC Research agreed3/3

    Why readShows how SafePay operators exfiltrated over OneDrive sync and, more usefully, what forensic residue the sync client left behind that let investigators prove data actually left.

    Sygnia's investigation covers SafePay ransomware using OneDrive as the exfiltration channel, moving data over ordinary HTTPS to a trusted SaaS endpoint that most egress controls and DLP will not question. The write-up focuses on proving exfiltration after the fact from sync client artefacts on the compromised server, and on the hunting logic that flags a trusted service behaving abnormally (a server-class host suddenly syncing to a personal tenant). It also makes the point that blocking one exfiltration attempt is not containment. Presented in a question-led format, so the depth of each answer varies.

  1. An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation (opens in a new tab)

    Unit 42 ·Renzon Cruz, Nicolas Bareil, Eric Semaan and Omar Jbari ·fetched 2 Sep 2026, 11:38 UTC Must read Research agreed3/3

    Why readFirst-hand incident data on an intrusion where the operator handed tactical execution to AI agents, including the artefacts that betrayed them.

    Unit 42 documents an attack that gained speed not from a zero-day but from agents that monitored, evaluated, acted and re-planned in real time across the chain: a public API endpoint for the foothold, an automated recon agent mapping internal microservices, sub-agents combing code repositories for hard-coded tokens and service passwords, then privilege takeover. The detectable residue is the useful part for defenders: structured Markdown files used to pass state between agents and sessions, plus custom operational scripts assessed as AI-generated from their UI elements. The operator also had the agent produce an 80-page technical audit of the victim's security posture, listing dozens of exploited findings.

  2. What's in Your Agent's Context? Context Privilege Escalation Attacks against AI Agent Harness (opens in a new tab)

    arXiv cs.CR (AI) ·Zichuan Li, Jian Cui, Ashley Chen, Xiaojing Liao ·fetched 2 Sep 2026, 03:42 UTC Must read Research agreed3/3

    Why readNames two concrete attack classes in how agent harnesses assemble context, where low-privilege attacker content is promoted into higher-privilege message roles or persists past its scope.

    A systematic study of context assembly in 12 real-world AI agent harnesses identifies MessageRole Context Privilege Escalation (attacker-controlled content from a low-privileged source landing in a higher-privileged message role) and Cross-Scope Context Privilege Escalation (content persisting beyond the context that introduced it). The framing is useful because it moves the problem from prompt wording to the harness plumbing that vendors keep proprietary. Anyone building or deploying agent frameworks should check both properties in their own context builder.

  3. $536 and 8 Hours: AI Learns to Attack a Different PLC (opens in a new tab)

    Security Affairs ·Pierluigi Paganini ·fetched 2 Sep 2026, 15:38 UTC Must read CVE-2021-31886 EPSS 3.0% agreed3/3

    Why readPuts real numbers on AI-assisted exploit development against industrial hardware: $536 and eight hours of Claude Code, with substantial researcher steering and one PLC bricked along the way.

    Forescout tested whether an AI agent could port a working exploit for CVE-2021-31886, a pre-authentication buffer overflow in the Nucleus FTP server, from a WAGO 750-852 PLC to the related but distinct 750-831, with no source code or debugger access. Working from a terminal, Ghidra and the physical device, the porting succeeded, but only with heavy hand-holding, and a later AI-generated payload permanently destroyed the hardware. The value is in the cost and effort figures, which put a floor under the capability question rather than leaving it to speculation, and in the reminder that target-specific addresses and offsets are still where this work gets hard.

  4. Workload Identification with Physical Side Channels for AI Governance (opens in a new tab)

    arXiv cs.CR (AI) ·Simone Gargiulo, Gabriel Kulp ·fetched 2 Sep 2026, 07:37 UTC Must read Research agreed3/3

    Why readShows an external observer can tell training from inference on an NVIDIA H200 at 97% accuracy purely from power draw, on model families never seen in training.

    930 five-second power traces sampled at roughly 10 MHz across seventeen open LLM families and twenty-five non-AI workloads separate training, inference and non-AI compute with 97% accuracy and 0.955 macro-F1, generalising to unseen model families. AI workload spectral content sits mostly below 20 kHz, with training the most distinctive class. The point that matters is trust: unlike on-chip NVML telemetry, which an operator can spoof or replay, a physical side channel can be measured without their cooperation, which makes it a candidate primitive for compute-governance verification and, read the other way, a side channel leaking what a datacentre is running.

  5. CVE-2026-82217 (CVSS 8.8): In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the AI "Agent Mode" file-change tools (writeFileContent, suggestFileContent, and the (opens in a new tab)

    NVD ·fetched 2 Sep 2026, 15:38 UTC CVE-2026-82217 CVSS 8.8 EPSS 0.4% agreed3/3

    Why readEclipse Theia Agent Mode resolved model-supplied file paths with no workspace containment, so indirect prompt injection writes to ~/.ssh/authorized_keys.

    In Theia 1.73.0 up to 1.75.0, the Agent Mode file-change tools (writeFileContent, suggestFileContent and the replacement and state helpers) accepted a path straight from model output, so ../.bashrc, an absolute path or a tilde-expanded path wrote or deleted files anywhere the backend OS user could reach. Agent Mode applies writes with no confirmation dialog, which turns an indirect prompt injection in any content the agent reads into code execution on the backend host via shell startup files or authorized_keys. This is a clean worked example of the failure mode every agentic IDE shares: tool arguments are attacker-influenced data and need containment checks on the tool side, not the model side.

  6. Delegation Without Trust: An Empirical Gap Analysis of Identity, Authorization, and Runtime Governance in Multi-Agent LLM Systems (opens in a new tab)

    arXiv cs.CR (AI) ·Panduranga Sai Varma Dantuluri, Jyotirmoy Sundi ·fetched 2 Sep 2026, 07:37 UTC Research agreed3/3

    Why readSets the correct bar for agent authorization: a fully prompt-injected agent must still not exceed the authority explicitly delegated to it, and shows a typical runtime fails every adversary tested.

    The threat model covers four adversaries in multi-agent delegation (confused deputy, token theft and replay, prompt-injection privilege escalation, and compromised sub-agents) and derives eight requirements a governed agent system must meet. A baseline runtime built to reflect common practice, broad bearer credentials with authorization decided inside the model, fails all four. The untrusted-model assumption is the useful takeaway for anyone designing agent identity and scoping today, since it moves enforcement out of the prompt and into the infrastructure.

  7. Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 2 Sep 2026, 11:38 UTC CVE-2021-31886 EPSS 2.9% agreed3/3

    Why readPuts numbers on AI-assisted exploit development: what porting a working pre-auth RCE to new ICS hardware actually cost in money, hours and broken equipment.

    Forescout's Vedere Labs used Claude to move a pre-authentication RCE for CVE-2021-31886, a stack overflow in the Nucleus FTP server's USER handling reachable on port 21, from one WAGO PLC to another, ending in attacker-supplied ARM shellcode running on live hardware. The work needed sustained human steering, and the final RCE stage alone burned $535.74 of API usage across an eight and a half hour session; a follow-on attempt to build a C2 implant wrote to flash-mapped memory and permanently bricked the device. CERT@VDE has no patch for the affected controllers and advises blocking or disabling FTP, segmenting, and watching traffic.

  8. AKRASIA: Stealthy Backdoor Attack on Reasoning-based Code LLMs (opens in a new tab)

    arXiv cs.CR (AI) ·Chou Jin Chua, Sarang Nambiar, Murali Srinivasan, Ezekiel Soremekun ·fetched 2 Sep 2026, 03:42 UTC Research agreed3/3

    Why readAn inference-time backdoor for reasoning code LLMs that reaches up to 99.34% attack success while keeping accuracy and hiding the trigger from both automated defenses and human readers.

    AKRASIA probes the victim model to build a code-level trigger, then uses in-context learning for backdoor installation and model unfaithfulness to generate plausible-looking reasoning that conceals it. Evaluated across four backdoor targets, six reasoning LLMs, three coding datasets and three defenses, it retains up to 98.82% ASR in 14 of 18 defense settings and hides the trigger from human inspection in up to 80% of settings. No weight modification is required, which puts it in reach of anyone who controls context.

  9. Defense-as-Skill: Evolving Runtime Guard Skill for Skill-Augmented Agents (opens in a new tab)

    arXiv cs.CR (all) ·Xiaofang Yang, Ziqi Miao, Dianbo Sui, Jing Shao ·fetched 2 Sep 2026, 03:42 UTC Research agreed3/3

    Why readMalicious agent skills persist in runtime context and fire only when workspace state makes the unsafe action look useful; this proposes a guard that is itself an installable skill, plus a 206-instance attack dataset.

    Skill-augmented agents load reusable skills as durable runtime context, which lets a malicious skill wait for a user task and workspace state that make leaking secrets, corrupting code or staging exfiltration appear legitimate, defeating pre-install vetting. SkillSonar implements the guard as an installable, inspectable skill that checks sensitive actions against the user's task boundary and routes each to allow, replan or confirm without patching the agent runtime. The authors release SCOPE-R, covering 6 risk families and 21 sub-categories with 206 attack-confirmed malicious instances and 43 benign tasks, which is the reusable part for anyone evaluating their own agent stack.

  10. TRIS: A Tri-Layer Retrieval Integrity Sieve Against Knowledge Poisoning (opens in a new tab)

    arXiv cs.CR (AI) ·Muhaimin Bin Munir, Akib Jawad Ononto, Nazia Shehnaz Joynab, Bhavani Thuraisingham ·fetched 2 Sep 2026, 03:42 UTC Research agreed3/3

    Why readA RAG poisoning defence with real numbers: black-box PoisonedRAG attack success drops from 67/87/64 percent to 3/14/4 percent on NQ, HotpotQA and MS-MARCO with Contriever at k=50.

    The Tri-Layer Sieve is retrieval middleware that filters poisoned passages through cross-embedding-space clustering with an independent judge model, structural detection of trigger-payload artefacts, and LLM consistency verification. The premise is that a poisoned document must simultaneously satisfy an embedding geometry, a trigger-payload structure and a generation objective, and rarely satisfies all three, a fragility the authors claim survives paraphrasing adaptive attackers. White-box HotFlip on Natural Questions falls from roughly 74 percent to 27.8 percent with the third layer enabled, so the defence is meaningfully weaker against gradient-guided attacks than against black-box poisoning.

  11. Transferable End-to-End Optimization for Indirect Long-Term Memory Poisoning in LLM Agents (opens in a new tab)

    arXiv cs.CR (AI) ·Chuanchao Zang, Jianing Wang, Wenyu Chen, Xiangtao Meng ·fetched 2 Sep 2026, 03:42 UTC Research agreed3/3

    Why readTreats long-term memory poisoning as an end-to-end optimization across write, retrieve and use stages rather than attacking each in isolation, which is why prior attacks underperform.

    PipePoison optimizes poisoned content against the full memory pipeline, using local shadow systems to collect per-stage feedback and chain-structured losses to find the stage that bottlenecks end-to-end success. The insight is that improvements aimed at retrieval can be erased by the write-side transformation and vice versa, so single-stage attack results understate the real risk. Relevant to anyone running agents with persistent memory over untrusted external content.

  12. Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks (opens in a new tab)

    The Register Security ·fetched 2 Sep 2026, 07:37 UTC agreed3/3

    Why readA working example of the credential exposure and detection gap around model inference keys, from an organisation whose day job is evaluating AI risk.

    METR disclosed two 2026 incidents: in March an attacker stole an API key for inference on public models and burned roughly 600,000 dollars of credits over three weeks before anyone noticed, and in May attackers systematically probed its public infrastructure, including an unsuccessful attempt to reach internal data through an inadvertently exposed endpoint. The March key belonged to a researcher without access to model data or credentials, and the reporting traces the exposure to a fail open authentication behaviour. METR says it found no evidence that sensitive information was reached in either case, but the three week dwell time on an unbounded spend is the transferable lesson: inference keys are billing credentials, and most organisations have no alerting on their burn rate.

  1. CISA scraps 6 free cybersecurity assessments for critical infrastructure operators (opens in a new tab)

    Cybersecurity Dive ·Eric Geller ·fetched 2 Sep 2026, 15:38 UTC agreed3/3

    Why readSix free federal assessments that critical infrastructure operators built into their review cycles are gone, so anyone who planned around them needs a replacement.

    CISA has confirmed that its regional staff will stop performing Cyber Resilience Reviews, Cyber Resilience Essentials surveys, Ransomware Risk Assessments, Incident Management Reviews, External Dependencies Management Assessments and Cyber Infrastructure Surveys. The agency frames the retirements as removing redundant legacy questionnaires. For operators, particularly smaller ones without budget for commercial equivalents, this removes a free external benchmark for resilience and ransomware readiness and narrows CISA's hands-on support role.

  2. Judge Rules DOD Unlawfully Retaliated Against Anthropic (opens in a new tab)

    EFF Deeplinks ·Matthew Guariglia ·fetched 2 Sep 2026, 03:42 UTC agreed3/3

    Why readA federal judge ruled the DOD's 'supply chain risk' designation of Anthropic was unlawful First Amendment retaliation, which sets a precedent for vendors that refuse specific government use cases.

    The court found that DOD labelled Anthropic a supply chain risk in retaliation for the company telling the US military it would not permit its technology to be used for mass surveillance of US persons, and that the designation violated the First Amendment. The ruling left open the broader question of whether a company's restrictions on how its technology may be used are themselves protected speech. For anyone running vendor risk or government contracting, it establishes that a federal supply-chain designation can be challenged when its motive is retaliatory, which matters well beyond AI vendors.

  3. The EU has begun enforcing the AI Act: first RFIs to model providers (opens in a new tab)

    Hacker News ·cdnsteve ·fetched 2 Sep 2026, 07:37 UTC 47 points agreed3/3

    Why readThe EU AI Office opened its first formal supervisory file under the AI Act, sending information requests on model security, external evaluations and post-market monitoring to frontier model providers.

    Henna Virkkunen confirmed on 29 August 2026 that the AI Office has sent formal requests for information to general-purpose AI model providers in several regions, reportedly including OpenAI, Anthropic and Google. GPAI obligations became enforceable on 2 August 2026, so Brussels acted within four weeks of gaining the power. The piece also corrects the viral reading: nothing here blocks a model from the EU market, but providers now have to evidence security testing, independent evaluation and market monitoring on demand.

  4. Texas and Florida Step Back from ALPRs (opens in a new tab)

    EFF Deeplinks ·Adam Schwartz ·fetched 2 Sep 2026, 19:41 UTC agreed3/3

    Why readTwo states pulled back on automated licence plate readers within days: Texas banned state funds for Flock cameras on 28 August, and Florida DOT ordered all ALPRs off state highway right-of-way within 30 days.

    Governor Abbott's order bars Texas state agencies from spending public funds on Flock cameras, landing as the Texas Tribune prepared an investigation showing a state agency had routed at least 30 million dollars into a surveillance network. On 31 August the Florida Department of Transportation revoked all existing ALPR permits, barred new ones, and set a 30 day removal deadline, citing the sharp rise in roadway deployments. For anyone running or buying surveillance data, the procurement and permitting ground has moved in two large states with hard deadlines attached.

  5. UK cyber bill targets AI users, not the vendors building it (opens in a new tab)

    The Register Security ·fetched 2 Sep 2026, 11:38 UTC agreed3/3

    Why readThe UK government has refused to bring frontier AI vendors into the scope of the Cyber Security and Resilience Bill, leaving obligations on the organisations that deploy AI rather than those that build it.

    Cybersecurity minister Baroness Lloyd of Effra told the Grand Committee that regulating AI service providers and frontier model developers under the Bill would not prevent hostile actors misusing their products, rejecting House of Lords amendments to that effect. The government points instead to the AI Security Institute's pre-release model testing and the voluntary AI Cyber Security Code of Practice that fed into the ETSI standard. For UK organisations the practical effect is that AI supply-chain risk stays their own compliance problem rather than the vendor's.

  6. Communicating Under Pressure: Best Practices for Service Providers (opens in a new tab)

    CISA Advisories ·CISA ·fetched 2 Sep 2026, 15:38 UTC agreed3/3

    Why readA joint CISA, FBI and international-partner template for what you say publicly during an IT or OT outage, and how to say it without cutting across containment or a law enforcement investigation.

    The guidance treats outage communications as a planned capability rather than an improvised one, setting clarity, accountability and transparency as the operating principles and breaking crisis messaging into elements you can pre-draft. Its most useful section for practitioners is the tension it names explicitly: disclosure obligations and public reassurance pull against operational security and containment, and it gives you a way to sequence both. It also flags cascading effects, where an outage at one provider produces alarm across interconnected customers, which is the case most single-organisation comms plans handle worst.

  7. Lords call for AI 'kill switch' powers in UK (opens in a new tab)

    BBC Technology ·fetched 2 Sep 2026, 15:38 UTC agreed3/3

    Why readTwo UK legislative moves that would put statutory shutdown powers over AI systems and data centres on the books, attached to the Cyber Security and Resilience Bill.

    Lord Tim Clement-Jones has tabled an amendment to the Cyber Security and Resilience Bill giving government the power to deactivate powerful AI systems and switch off data centres where national security is threatened; it is one of 65 amendments debated this week. Separately, Labour MP Alex Sobel introduces an AI Security Bill on 8 September, backed by ControlAI, which would make the UK the first G7 state to legislate a halt on superintelligent AI development. Both still need government backing to progress, so this is direction of travel rather than obligation.

  8. Telecom Industry Groups to Sixth Circuit: Overturn FCC Data Breach Rules (opens in a new tab)

    Google News: incidents · Broadband Breakfast ·fetched 2 Sep 2026, 23:39 UTC agreed3/3

    Why readTelecom trade groups are asking the Sixth Circuit to vacate the FCC's expanded data breach notification rules, which would change carrier reporting obligations if they win.

    Industry associations have taken the FCC's revised customer data breach notification rules to the Sixth Circuit, seeking to have them overturned. The rules broadened what carriers must report and shortened notification timelines, so the outcome determines whether telecom compliance programmes keep building to them or revert. The item is a short news report; the litigation itself is the fact worth tracking.

  9. U.S. or Korea? Coupang's data breach lawsuit faces key jurisdiction question. (opens in a new tab)

    Google News: incidents · Korea JoongAng Daily ·fetched 2 Sep 2026, 11:38 UTC agreed2/3

    Why readA live test of where breach litigation against a cross-listed foreign company gets heard, which shapes legal exposure for any firm with a US listing and offshore operations.

    Coupang's data breach lawsuit hinges on a forum question: whether the case belongs in US or Korean courts. The answer determines which discovery rules, damages theories and class mechanics apply, and by extension how much exposure a Korean operator with a US listing actually carries. Counsel and risk owners at similarly structured companies should watch how the court resolves it.

  1. McKesson Supplies 1 in 3 Hospital Prescriptions. Now It's Responding to a Cyberattack Linked to 284 Million Records (opens in a new tab)

    Google News: incidents · inc.com ·fetched 2 Sep 2026, 03:42 UTC Must read agreed3/3

    Why readMcKesson, which supplies one in three US hospital prescriptions, is responding to a cyberattack linked to 284 million records.

    A cyberattack at McKesson has been tied to 284 million records, at a distributor sitting in the supply path for roughly a third of hospital prescriptions in the United States. The concentration risk is the story: an incident here reaches every hospital and pharmacy downstream regardless of their own controls. Healthcare and any organisation with McKesson in its third-party register should expect questions this week about dependency and continuity, not just about data exposure.

    Also covered byhealthexec.com (opens in a new tab),Healthcare Dive (opens in a new tab).

  2. Criminals publish data of 8.7m people after airports hack (opens in a new tab)

    BBC Technology ·fetched 2 Sep 2026, 11:38 UTC Must read agreed3/3

    Why readManchester Airports Group refused to pay, and the extortion group has now dumped roughly half a terabyte covering 8.7 million people from Manchester, Stansted and East Midlands airports.

    Stolen records include contact details, vehicle registrations and postcodes, drawn from databases holding WiFi login and car parking data, and the group is offering the full set free to other criminals. MAG says it has contacted everyone affected, including customers with upcoming bookings, and is warning of secondary fraud aimed at travellers. This is the reference case for the non-payment endgame: the ransom was never paid and the data went public anyway, which every board in transport and hospitality will want walked through this week.

  3. Health data of more than 9.5 million people leaked from Aesto record system (opens in a new tab)

    The Record ·fetched 2 Sep 2026, 19:41 UTC Must read agreed3/3

    Why read9.5 million people notified in a healthcare data-migration vendor breach, with SSNs and financial account data taken from the vendor's AWS environment.

    Aesto, a Birmingham, Alabama company providing data migration and archiving for medical facilities changing EHR vendors, told HHS this week that more than 9.5 million people were affected by a December intrusion. Attackers were in its AWS infrastructure between 2 and 18 December, taking names, Social Security numbers, medical information, driver's licence numbers, financial account numbers and insurance data belonging to its customers' patients. The nine-month gap between the June customer warning and the scoped regulatory notification is the part peers and boards will ask about, alongside the familiar problem that the breached party is a third-party processor rather than the covered entity.

    Also covered byBleepingComputer (opens in a new tab).

  4. Nutex Health Says Patient Data Stolen, Hackers Threaten Leak (opens in a new tab)

    Infosecurity Magazine ·fetched 2 Sep 2026, 11:38 UTC agreed3/3

    Why readNutex Health told the SEC in an August 31 8-K that patient, employee, provider and financial data was exfiltrated and the attacker is threatening to publish it.

    The Texas-based healthcare provider filed an 8-K disclosing that an unauthorized third party accessed and exfiltrated information held on its servers, covering patients, employees, credentialed providers and business and financial records. The attacker has threatened to post the data externally, and Nutex says it is still assessing the full scope and will notify affected patients. Another extortion-driven healthcare disclosure landing through the SEC route, with the leak-site clock now the effective deadline.

    Also covered bySecurityWeek (opens in a new tab).

  5. Berlin refuses ransom demand after State network cyberattack (opens in a new tab)

    Google News: incidents · Escudo Digital ·fetched 2 Sep 2026, 07:37 UTC agreed3/3

    Why readBerlin's state government publicly refused a ransom demand after an attack on its network, a decision peers in public administration will be asked about.

    Following a cyberattack on the Berlin state network, authorities declined to pay the ransom demanded by the attackers. The report is short on technical detail, but the refusal itself is the fact worth having: a large regional government taking a public no-payment position sets an expectation other public bodies will be measured against.

  6. Investigation opened on OpenAI by Attorney General Austin Knudsen following data breach (opens in a new tab)

    Google News: incidents · kulr8.com ·fetched 2 Sep 2026, 07:37 UTC agreed3/3

    Why readMontana Attorney General Austin Knudsen has opened an investigation into OpenAI over a data breach, the kind of state-AG action boards now ask about by name.

    Knudsen's office opened a formal investigation into OpenAI following a breach affecting user data. State attorneys general moving on an AI provider matters beyond OpenAI's own customers: it signals that consumer-protection and breach-notification statutes are being applied to AI vendors, and organisations relying on those vendors will be asked what their contracts and notification paths look like.

  7. Luminus Health cyberattack disrupts Anne Arundel Medical Center (opens in a new tab)

    Google News: incidents · WBAL-TV ·fetched 2 Sep 2026, 23:39 UTC agreed3/3

    Why readA cyberattack on Luminis Health is disrupting operations at Anne Arundel Medical Center, one of Maryland's larger hospital systems.

    Local broadcast reporting that Luminis Health is dealing with a cyberattack affecting Anne Arundel Medical Center. No attribution, ransomware family or patient data impact has been stated yet. Healthcare peers should expect the diversion and downtime questions this raises to reach their own boards.

  8. Oncology Firm Novocure Announces Cyberattack and Data Breach (opens in a new tab)

    Google News: incidents · The HIPAA Journal ·fetched 2 Sep 2026, 15:38 UTC agreed3/3

    Why readNovocure, a listed oncology device firm, has disclosed a cyberattack with a data breach.

    Novocure has announced a cyberattack that resulted in a data breach. No attribution, technique or scope of affected records is given at this stage; the disclosure itself is the fact, and patient-data exposure at a device maker will draw regulatory attention under HIPAA.

    Also covered byBleepingComputer (opens in a new tab).

  9. Luminis Health facilities dealing with a cyberattack (opens in a new tab)

    Google News: incidents · Baltimore Sun ·fetched 2 Sep 2026, 15:38 UTC agreed3/3

    Why readLuminis Health, which runs Anne Arundel Medical Center and Doctors Community Medical Center in Maryland, is working through an active cyberattack.

    Luminis Health facilities are dealing with a cyberattack, reported locally with no attribution or technical detail yet. Active incidents at regional hospital systems typically mean diversion and downtime procedures, and the disclosure and notification questions follow within days.

  10. Minnesota Judicial Branch reports data breach at tech vendor (opens in a new tab)

    Google News: incidents · KTTC | Rochester, MN ·fetched 2 Sep 2026, 23:39 UTC agreed3/3

    Why readThe Minnesota Judicial Branch has disclosed a breach originating at a technology vendor, another third-party exposure in the court system supply chain.

    Local reporting that the Minnesota Judicial Branch notified of a data breach at one of its technology vendors. The vendor, the data categories and the number of affected individuals are not stated in the available text. Read alongside the Oregon appellate court disclosure the same day, which suggests a shared court case-management supplier is the common point.

  11. Case system used by Oregon's appellate courts part of data breach (opens in a new tab)

    Google News: incidents · Statesman Journal ·fetched 2 Sep 2026, 23:39 UTC agreed3/3

    Why readOregon's appellate court case management system is caught up in a data breach, the second US state judiciary to disclose one the same day.

    The Statesman Journal reports that the case system used by Oregon's appellate courts was part of a data breach. No vendor, data type or record count appears in the available text. The timing against the Minnesota Judicial Branch vendor breach is worth tracking for anyone whose organisation depends on the same court technology supplier.

  12. P&O ferry passengers hit by data breach during sailing (opens in a new tab)

    Google News: incidents · BBC ·fetched 2 Sep 2026, 03:42 UTC agreed3/3

    Why readP&O Ferries passengers were notified of a data breach mid-voyage, reported by the BBC.

    A data breach affecting P&O ferry passengers came to light while sailings were underway. The BBC report covers the disclosure and passenger impact rather than cause or attribution, making it a UK consumer-facing incident that transport and travel operators will be asked to compare themselves against.

Unverified claims posted by extortion groups on their own leak sites, not confirmed breaches. Listing is the group's assertion; many named organisations have not disclosed an incident, and some entries are false or recycled. Leak sites are never linked from here.

Claimed victimGroup SectorCountry Seen
Greenberg Traurig SilentRansomGroup Professional Services US 2 Sep 2026
G... ...g SilentRansomGroup - - 2 Sep 2026
S... M... SilentRansomGroup - - 2 Sep 2026
Cartrack Holdings direwolf Transportation ZA 2 Sep 2026
PTT Oil and Retail Business direwolf Energy & Utilities TH 2 Sep 2026
Ormond Beach Florida Wallstreet - US 2 Sep 2026
Asfaltos y Pavimentos S.A. (Asfalpasa) incransom Manufacturing ES 2 Sep 2026
Westfield Public School District incransom Education US 2 Sep 2026
Trucka incransom Transportation MX 2 Sep 2026
Policlinico Triestino incransom Healthcare IT 2 Sep 2026
Multiver Ltée incransom - CA 2 Sep 2026
Metales Panamericanos incransom Manufacturing PA 2 Sep 2026
Ville de Libercourt kairos Government & Defense FR 2 Sep 2026
N*************** insomnia - US 2 Sep 2026
PennFab akira Manufacturing - 2 Sep 2026
ScrubaDub Auto Wash Centers akira Retail & E-Commerce US 2 Sep 2026
Algra Group akira - NL 2 Sep 2026
part1.simplexengg.in Eclipse Technology IN 2 Sep 2026
Uak University qilin Education TR 2 Sep 2026 press coverage (opens in a new tab)
Royal Plaza On Scotts Eclipse Hospitality SG 2 Sep 2026
Seasia Infotech thegentlemen Technology IN 2 Sep 2026
Proliance Surgeons payoutsking Healthcare US 2 Sep 2026 press coverage (opens in a new tab)
specialtytextile.com incransom Manufacturing US 2 Sep 2026
Licindia medusalocker - IN 2 Sep 2026
Chip 1 Exchange aurora Technology US 2 Sep 2026
How this edition was made
Candidates fetched
4751
New after deduplication
720
Kept by the panel
143
Published
135
Generated
2 Sep 2026, 23:39 UTC