CFToday Curated security signals.

Daily edition · 2026-09-03 · latest

Thursday, 3 September 2026

36 items across 7 sections, selected from 2341 candidates over 3 runs. 34 carried the panel unanimously.

Show
Section

India

1

Indian organisations, regulators and infrastructure, pulled out of the sections below.

  1. NHRC seeks reports from MeitY, MIB, Delhi Police over Instagram CSAM ads (opens in a new tab)

    Economic Times Tech ·Governance, Risk & Compliance ·fetched 3 Sep 2026, 11:40 UTC agreed2/3

    Why readIndia's statutory rights commission has opened a formal accountability track against a platform's paid-advertising pipeline, which is the kind of pressure that reshapes moderation and reporting duties for anyone operating there.

    The National Human Rights Commission took cognizance under Section 12 of the Protection of Human Rights Act, 1993 and asked MeitY, the information and broadcasting ministry and Delhi Police for point-by-point action-taken reports. The trigger was BBC reporting that paid Instagram advertisements used phrases such as "rape video" and "child video" and redirected users to Telegram channels where the material was offered for sale. What makes it notable is the target: the ad review and monetisation path itself, not user-generated uploads, is now inside the scope of an Indian statutory inquiry.

  1. It sure looks like hackers breached a major ID card verification service (opens in a new tab)

    TechCrunch Security ·Zack Whittaker ·fetched 3 Sep 2026, 03:41 UTC Must read agreed3/3

    Why readA dark web lookup service is selling searches against a claimed 150 million US and Canadian driver's licenses and passports, with roughly half a million documents added daily, indicating live access to an identity verification provider rather than a static dump.

    Krebs launched the investigation after finding his own license in the Nexus database, and Zach Edwards confirmed the same for his; Secretary of Defense Pete Hegseth's photo also appears in the index, and the Department of Defense says it is evaluating the reports. The daily ingest rate is the important detail, because it points at an ongoing feed from a compromised KYC vendor rather than a one-off exfiltration. Any organisation that outsources document verification should be asking its provider directly whether it is the source.

  2. Impersonating IT support: how threat actors turn a remote session into enterprise-wide access (opens in a new tab)

    Microsoft Security ·Microsoft Security Research, Sagar Patil, Arlette Umuhire Sangwa, Jesse Birch and Ravikant Tiwari ·fetched 3 Sep 2026, 03:41 UTC Must read Research agreed3/3

    Why readFull hands-on-keyboard chain that starts with a Teams external-collaboration message impersonating helpdesk and ends in WinRM lateral movement, with the RMM-to-MSI-to-Node.js implant sequence spelled out.

    Microsoft Threat Intelligence tracked a human-operated campaign that abuses Microsoft Teams external collaboration to pose as IT support and talk users into granting an interactive remote session. Once an RMM tool gives control, PowerShell pulls down a silently installed MSI that stages a portable Node.js runtime and an obfuscated JavaScript implant for persistent C2. Post-implant activity includes host and Active Directory reconnaissance, periodic desktop screenshots, LOLBin execution of follow-on payloads, and pivoting over WinRM toward high-value assets, which gives defenders clear places to hunt: external Teams tenant policy, unexpected RMM installs, and node.exe running from user-writable paths.

    Indicators12
    Hashes
    4cfdcae6dd1d6d98b870c8f0654d504f2bf10479a117dc297de789c249dc389d a4d145a6347e47d40b3ca48af5c6dba01bf019d0110e31a44bb70fc77d1d1676 cc6d0f3f47afeba018173604e34f527e8413d3a54ffb35caed529bff49055ec5 0d2fc28af246f62f27e49207d1f64e236ad9ea029412b27877d1ae6c098e86e3 69e10e0cb7bb2137ebea12971adb02c662cf5543a4f8c9530812bcbf7b183a23 a135fe4df18c711097e69b4f27ea32a74a955160bf2fb12da841f21866d95d87
    Domains
    update1n5[.]blob[.]core[.]windows[.]net update1n6[.]blob[.]core[.]windows[.]net update1n7[.]blob[.]core[.]windows[.]net update1n9[.]blob[.]core[.]windows[.]net updatetmp[.]blob[.]core[.]windows[.]net dssdfvsdfvsdfvsdgbfbdvdzv[.]org
  3. Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America (opens in a new tab)

    Unit 42 ·Reese Lewis and Sara McBroom ·fetched 3 Sep 2026, 11:40 UTC Must read Research agreed3/3

    Why readDocuments two live intrusion sets in Latin America where the operators self-hosted NextChat on victim infrastructure and used AI to build tooling, tracked as CL-CRI-1131.

    Unit 42 details a campaign against a Mexican transportation organisation plus federal ministries and municipal water utilities in Mexico and Ecuador, run largely through living-off-the-land techniques and iterative batch scripts for data manipulation and exfiltration, with NextChat instances stood up on operational infrastructure. A second cluster hits the Brazilian financial sector through job-themed phishing against vulnerable web servers, using custom RATs, tunnelling tools and a Go-based SOCKS5 proxy whose iterative filenames suggest machine-assisted development. Self-hosted LLM front ends on attacker infrastructure are a concrete hunting artefact, as are the batch script patterns.

    Indicators9
    Hashes
    7d766942ef34542cee39c852286599958c4c2e23187010c4d38dbf88fcb40bf8 4e218e70afdbb116209ec0ebe8fc556e296e69648aa4e0425b83c0e863a8fee5 46ac289ce0c13666de616446f5d5a68da8bd150f4f065c3bec02f63776d3899c a38b2cf8beff32a276eed8783723ecf8cc53d7dc88669e1b998dddc4db6fe996 87bf8bc8b4a2cf34f0af1afe161f123a3d200e77f6c6f41b81bf6ae66ee172ec
    Addresses
    62[.]171[.]185[.]97 178[.]128[.]87[.]160 167[.]148[.]195[.]53
    Domains
    m-doxa-apodo[.]duckdns[.]org
  4. The Outsider Phishing Kit: A Resilient Threat in the Face of Law Enforcement Action (opens in a new tab)

    Group-IB ·fetched 3 Sep 2026, 07:38 UTC Must read Research agreed3/3

    Why readDocuments the Outsider Phishing Kit (局外人) run by the actor ChenLun: 267 ready-made templates, AiTM MFA interception, and over 100,000 phishing pages across 54+ countries between December 2025 and May 2026.

    Group-IB profiles a Chinese-language Phishing-as-a-Service platform whose kit ships adversary-in-the-middle capability, intercepting authentication flows to defeat multi-factor authentication, and whose operator kept running after law enforcement action. Scale is quantified: 267 templates, 100,000-plus pages identified over six months, targets in more than 54 countries. The report argues for disruption at the infrastructure and template stage rather than at the transaction, which gives fraud and brand-protection teams a different intervention point than the payment-time controls most of them run.

  5. Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons (opens in a new tab)

    Infosecurity Magazine ·fetched 3 Sep 2026, 03:41 UTC agreed3/3

    Why readCheck Point ties a Chinese-speaking crew it calls Gambling Goblin to compromised Brazilian government and education sites used as SEO fraud infrastructure, with custom Apache modules acting as a reverse proxy.

    Check Point Research documents a campaign running since mid-2025 in which Brazilian .gov and .edu sites are compromised and fitted with custom Apache modules that silently reverse-proxy traffic to serve gambling SEO content. CPR links the cluster with medium-to-high confidence to Earth Berberoka, the Chinese-speaking group Trend Micro documented in 2022, based on overlaps in tooling including oRAT, Chinese-language strings, operator artefacts and domains mimicking trusted tech brands. This is Infosecurity's write-up; the CPR report published 2 September is the version to read for indicators.

  6. Russia Turns to Sabotage, Cyberattacks Against Ukraine’s Allies (opens in a new tab)

    Google News: incidents · WSJ ·fetched 3 Sep 2026, 03:41 UTC agreed2/3

    Why readWSJ reports Russian activity shifting toward sabotage and cyber operations against Ukraine's allies rather than Ukraine itself, which moves European and NATO-country organisations up the target list.

    The reporting describes a change in emphasis, with physical sabotage and network intrusion aimed at states supporting Ukraine. For defenders in Europe, that argues for reviewing exposure in logistics, rail, energy, and defence supply chain assets, along with physical security at facilities that have not previously modelled state sabotage. The item is a headline-level pointer to WSJ reporting, so the underlying article is where the specifics live.

  7. Srsly Risky Biz: China's botnets are worth disrupting (opens in a new tab)

    Risky Business News ·fetched 3 Sep 2026, 07:38 UTC agreed2/3

    Why readFrames this week's US botnet disruption against China's long running practice of contracting botnet construction out to private companies, and flags a reported Qilin theft from the ATF's lawful intercept environment.

    Uren and Wilson argue the takedown is worth doing but should be read as attrition rather than eviction, because the contractor model behind these espionage botnets has been running for years and will rebuild. The sharper item is the ATF breach, where Qilin appears to have taken data from CALEA systems, meaning a ransomware crew may now hold lawful intercept records. They also push back on the US water sector approach, where distributing free tools does little for utilities that have nobody to operate them.

  1. SonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs (opens in a new tab)

    Security Affairs ·Pierluigi Paganini ·fetched 3 Sep 2026, 11:40 UTC Must read CVE-2026-83549 EPSS 0.9% agreed3/3

    Why readTwo SonicWall SMA 1000 zero-days are confirmed exploited in the wild, including CVE-2026-83548, a CVSS 10.0 pre-auth SSRF, apparently chained with a post-auth command injection.

    CVE-2026-83548 is an unauthenticated SSRF in the Appliance Work Place interface that lets a remote attacker reach sensitive functionality and perform unauthorised operations; CVE-2026-83549 (CVSS 7.8) is an OS command injection in the Appliance Management Console reachable by an authenticated administrator under specific conditions, giving remote code execution. SonicWall says attackers appear to be chaining the two against internet-facing appliances and has shipped updates; the bugs were found in-house by William Perry and Adam Babis. Patch SMA 1000 now and treat exposed appliances as suspect, since a pre-auth entry point into an SSL VPN with active exploitation is a compromise assessment, not a maintenance window.

    Also covered byHelp Net Security (opens in a new tab).

  2. CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 3 Sep 2026, 07:38 UTC Must read CVE-2026-83548 EPSS 0.3% agreed3/3

    Why readSeven new KEV entries with a federal patch deadline, led by a CVSS 10.0 pre-auth SSRF in SonicWall SMA 1000 remote access appliances.

    CISA added seven flaws to the Known Exploited Vulnerabilities catalog, including CVE-2026-83548 (CVSS 10.0), an unauthenticated SSRF in SonicWall SMA 1000 appliances, and CVE-2026-83549 (CVSS 7.8), a post-auth OS command injection on the same product that yields RCE for an authenticated administrator. Also listed: CVE-2026-9586 (CVSS 9.3), an unauthenticated SQL injection in Sangoma Switchvox reachable in a single crafted request against the backend PostgreSQL database and escalating to RCE, and CVE-2026-82329 (CVSS 9.8), an improper authentication issue. Attacker payloads observed against these bugs include reverse shells and cryptocurrency miners, so exposed appliances should be treated as compromise candidates rather than simply patched.

  3. WordPress backup plugin flaw exposes millions of sites to takeover attacks (opens in a new tab)

    BleepingComputer ·Bill Toulas ·fetched 3 Sep 2026, 03:41 UTC Must read agreed3/3

    Why readCVE-2026-19949 is an unauthenticated second-order SQL injection in All-in-One WP Migration and Backup through version 7.109, reachable by planting crafted data via WordPress trackbacks.

    Wordfence details a second-order SQL injection in the All-in-One WP Migration and Backup plugin caused by incorrect parsing of escaped backslashes and quotation marks when the plugin rewrites database content during archive restoration. An unauthenticated attacker plants the payload through WordPress trackbacks; it fires later when an administrator exports and imports the site, both routine operations for this plugin, leading to code execution and site takeover. Versions through 7.109 are affected across a very large install base, so update and audit trackback content on sites where migrations are planned.

    Also covered byNVD (opens in a new tab).

  4. Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability (opens in a new tab)

    SecurityWeek ·Ionut Arghire ·fetched 3 Sep 2026, 11:40 UTC Must read CVE-2026-19949 EPSS 0.5% agreed3/3

    Why readCVE-2026-19949 in All-in-One WP Migration and Backup, installed on over three million WordPress sites, chains a second-order SQL injection to unauthenticated RCE.

    The plugin's archive restore path insufficiently escapes user input and does not properly prepare queries, so an attacker can submit two trackbacks to a public post to leak the secret key that protects the otherwise unauthenticated import operation, then use that key to restore a malicious .wpress archive and gain code execution. CVSS is 8.8 and Defiant is the reporting party. EPSS currently sits at 0.005 with no reported exploitation, but the install base and the full unauthenticated chain make patching urgent for anyone running it.

  5. CVE-2026-72001 (CVSS 8.6): Pangolin before 1.22.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to access any protected resource by suppl (opens in a new tab)

    NVD ·fetched 3 Sep 2026, 11:40 UTC CVE-2026-72001 CVSS 8.6 EPSS 0.3% agreed3/3

    Why readOne valid Pangolin share link authenticates you against any resource in any organization, defeating SSO, resource passwords, PINs, email allowlists and header auth alike.

    Pangolin before 1.22.0 passes an attacker-controlled URL parameter to the share-link authentication endpoint and omits the resource identifier from token verification, so the token is checked without being bound to what it grants access to. Anyone holding a single legitimate share link, including a former contractor or a leaked URL, can pivot to arbitrary protected resources across organizational boundaries. Pangolin is deployed as an internet-facing reverse proxy in front of self-hosted services, which is precisely where an auth bypass hurts most; upgrade to 1.22.0.

  6. CVE-2026-83497 (CVSS 8.7): Unrestricted deserialization of untrusted data in the cursor pagination component in the OpenSearch SQL plugin allows a remote authenticated user with (opens in a new tab)

    NVD ·fetched 3 Sep 2026, 11:40 UTC CVE-2026-83497 CVSS 8.7 EPSS 0.5% agreed3/3

    Why readA user with nothing more than read and search permissions gets remote code execution on OpenSearch by sending a crafted cursor to plugins/sql.

    The cursor pagination component in the OpenSearch SQL plugin deserializes untrusted data from the cursor parameter without restriction, turning the lowest-privilege authenticated role into full code execution on the server. Read-only access is routinely handed out to analysts, dashboards, and service accounts, so the privilege requirement is close to meaningless in most deployments. EPSS sits at 0.005 but in the 42nd percentile, the highest in today's batch, and the SQL plugin ships enabled in many stock OpenSearch installs.

  7. CVE-2026-53507 (CVSS 8.3): oasdiff-action is a GitHub Action that detects breaking changes in OpenAPI specs and post a review on every pull request. Before version 0.0.51, the o (opens in a new tab)

    NVD ·fetched 3 Sep 2026, 11:40 UTC CVE-2026-53507 CVSS 8.3 EPSS 0.3% agreed3/3

    Why readoasdiff-action before 0.0.51 resolved external $refs by default, so a fork pull request can make your runner fetch attacker-chosen URLs and read files.

    The GitHub Action shipped with allow-external-refs set to true, meaning a $ref inside a pull-request-supplied OpenAPI spec is fetched or read on the runner with no maintainer interaction. On public repositories that makes fork PRs an unauthenticated SSRF and structured-file disclosure primitive inside CI. Pin or bump to 0.0.51, and audit other spec-diffing actions for the same default.

  8. CVE-2026-53552 (CVSS 9.6): Goploy is an open-source automation deployment system. In versions 1.17.5 and prior, Project.AddFile, Project.EditFile, Project.RemoveFile, and Projec (opens in a new tab)

    NVD ·fetched 3 Sep 2026, 11:40 UTC Research CVE-2026-53552 CVSS 9.6 EPSS 0.2% agreed3/3

    Why readCross-namespace IDOR in Goploy <= 1.17.5 lets any low-privileged manager rewrite another project's git remote URL, which becomes RCE on the next deploy; no patch exists.

    Project.AddFile, EditFile, RemoveFile and Project.Edit in cmd/server/api/project/handler.go take a row id straight from the JSON body, and model.ProjectFile.GetData and model.Project.GetData filter only on that id, with no namespace ownership check. A user with the manager role or FileSync/EditProject permission in their own namespace can therefore read, write and delete files in any project on the install, and set a foreign project's git remote to a repository they control; Edit runs git remote set-url, so the next deploy pulls attacker code. No public patch at time of publication, so restrict who holds those roles or take the instance off shared access.

  9. CVE-2026-79748 (CVSS 9.9): MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing s (opens in a new tab)

    NVD ·fetched 3 Sep 2026, 07:38 UTC CVE-2026-79748 CVSS 9.9 EPSS 0.3% agreed3/3

    Why readAny authenticated MCPHub user, admin or not, can register a server config whose command is /bin/sh and get code execution as the hub's OS user, which is root in the published Docker image.

    The POST /api/servers and PUT /api/servers/:name endpoints in MCPHub write a server configuration and then spawn the configured stdio process through child_process.spawn. Authentication is enforced but authorization is not, and neither the command nor args fields are allowlisted, so a low privilege account turns into arbitrary local execution under the service account. Fixed in 0.12.15; EPSS is still low at 0.003, so this is a patch-on-schedule item rather than a fire drill unless you expose MCPHub to untrusted accounts.

  10. CVE-2026-75594 (CVSS 8.2): Kirby is an open-source content management system. Prior to 4.9.5 and 5.5.2, depending on the release line, Kirby's media handler in src/Cms/Media.php (opens in a new tab)

    NVD ·fetched 3 Sep 2026, 11:40 UTC CVE-2026-75594 CVSS 8.2 EPSS 0.5% agreed3/3

    Why readEncoded slashes in Kirby thumbnail filenames traverse out of the media directory, disclosing arbitrary .json file existence and deleting job files.

    Kirby\Cms\Media::thumb() in src/Cms/Media.php appended a path-bearing filename to an already-validated parent media directory, so on nginx, PHP's built-in server, or Apache with AllowEncodedSlashes on, %2f sequences escape the intended root. Response differences between existing and nonexistent thumbnail configurations leak whether a given .json exists, and a .json with a valid filename key returns the referenced image and deletes the job file. The file::version path in src/Filesystem/Asset.php accepted ../ too; fixed in 4.9.5 and 5.5.2.

  11. CVE-2026-61641 (CVSS 8.1): Wallos is an open-source, self-hostable personal subscription tracker. From version 4.0.0 to before version 4.9.6, Wallos's OIDC login links an incomi (opens in a new tab)

    NVD ·fetched 3 Sep 2026, 11:40 UTC CVE-2026-61641 CVSS 8.1 EPSS 0.3% agreed2/3

    Why readThe transferable lesson is worth more than the product: matching an OIDC email claim without checking email_verified converts any permissive identity provider into an unauthenticated admin takeover.

    Wallos from 4.0.0 up to 4.9.6 linked an incoming OIDC identity to an existing local account on the email claim alone, never checking whether the provider marked that address as verified. Against a multi-tenant provider, one with open self-registration, or one the attacker partly controls, a person with no Wallos account can assert the administrator's email address and be logged in as the administrator with no password. Patched in 4.9.6, and the same claim-trust mistake is worth grepping for in any application you have wired to external single sign-on.

  12. CVE-2026-79746 (CVSS 8.1): MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing s (opens in a new tab)

    NVD ·fetched 3 Sep 2026, 07:38 UTC CVE-2026-79746 CVSS 8.1 EPSS 0.3% agreed3/3

    Why readA bearer key scoped to one MCP server in MCPHub also opened every other server sharing that server's group, and the scope was never rechecked after the group connection was authorized.

    isBearerKeyAllowedForRequest granted access to a whole group route if any single member of that group appeared in the key's allowedServers list, rather than requiring the request target itself to match. Once the group level connection was up, allowedServers was not consulted again, so per server credential scoping was effectively decorative. Fixed in 1.0.31; anyone who has been issuing narrowly scoped MCPHub keys should assume those keys reached more than intended and rotate accordingly.

  1. Overcoming the Randomness-Utility Trade-off in Answering Differentially Private Linear Queries (opens in a new tab)

    arXiv cs.CR (all) ·Surendra Ghentiyala, Pritish Kamath, Ravi Kumar, Pasin Manurangsi ·fetched 3 Sep 2026, 11:40 UTC Research agreed2/3

    Why readShows the random bits needed to answer differentially private linear queries can drop to logarithmic in the query count without losing accuracy, which only matters where entropy is a metered resource.

    The authors construct a randomness-efficient analog of the Hardt and Talwar K-norm mechanism, answering d linear queries with O(d/epsilon) infinity-norm error while consuming only O(log d) expected random bits, and show this is optimal when epsilon is at most 1/d. A computationally efficient variant is also given, paying an O(log d) multiplicative penalty in error. It is pure theory with no implementation or deployment guidance; the one practical hook is settings where randomness is genuinely expensive, such as differential privacy layered on secure multiparty computation or entropy-starved enclaves.

DFIR

1
  1. Elcomsoft Quick Triage 2.2: Timeline, file system snapshot, and a plugin engine (opens in a new tab)

    ElcomSoft ·Oleg Afonin ·fetched 3 Sep 2026, 11:40 UTC agreed3/3

    Why readQuick Triage 2.2 adds a merged forensic timeline across six artefact groups, a metadata-only filesystem snapshot, and a plugin API for writing your own artefact parsers.

    The Timeline view normalises timestamps from browser history and downloads, SRUM data usage and registry network lists, recent files and folders, and application usage onto one sorted axis instead of leaving the examiner to interleave tables by hand. The filesystem snapshot captures metadata without file contents, which keeps the collection small enough to move off a scene. The release also brings MSA password attacks, OpenDocument parsing and recursive archive parsing in full-text search; the plugin engine is the part with the longest tail, since parsers no longer have to come from the vendor.

  1. Top AI coding agent security resources — September 2026 (opens in a new tab)

    Adversa AI ·fetched 3 Sep 2026, 07:38 UTC agreed2/3

    Why readPulls the post Black Hat coding agent findings into one place, including GhostJacking hitting 90% against a Claude Code configuration the vendor itself recommends and default GitHub Actions workflows from Anthropic, Google, and OpenAI all reaching remote code execution.

    The common failure across these results is that the agent trusts an input nobody in the stack treats as attacker controlled: GhostJacking uses a WAF's own block log as the delivery channel, so the firewall faithfully records a payload that the agent later executes while reviewing blocked traffic. The CI findings are the more immediate operational problem, since a single unauthenticated issue was enough against all three vendors' published default workflows, and Google rated its own Gemini CLI case a 10.0. This is curation rather than primary research and the source is a vendor, so read it as a pointer list into the underlying advisories and the 2,826 file skills benchmark rather than as the evidence itself.

  2. Claude Mythos only model to complete full cyber kill chain, experts say (opens in a new tab)

    The Register Security ·fetched 3 Sep 2026, 03:41 UTC Must read agreed3/3

    Why readBooz Allen's first Cyber Weapon Index found exactly one of 18 tested US and Chinese models completed a full kill chain autonomously, and predicts the rest get there within six months.

    In Booz Allen's testing, Anthropic's Claude Mythos was the only model to complete the full cyber kill chain autonomously, though the firm expects most of the other 17 US and Chinese models tested to reach the same weaponization level inside six months. OpenAI separately said its unreleased Astra model crossed its own critical cybersecurity capability threshold, meaning it is judged capable enough at finding and exploiting zero-days to pose a risk from misuse or misalignment. The index frames mainstream AI-enabled attacks from ransomware crews and state actors as imminent rather than speculative.

  3. The Implications of Linguistic Illegibility for LLM Security (opens in a new tab)

    arXiv cs.CR (AI) ·James Mickens ·fetched 3 Sep 2026, 07:38 UTC Research agreed3/3

    Why readArgues that chain-of-thought monitoring, constitutional self-critique and activation probing are unsound as security controls in principle, not just in practice, so isolation has to carry the guarantee.

    The paper introduces "linguistic illegibility" for cases where a model's externalised text or mechanistically-probed features do not represent its actual computation, which is math over activation spaces with lossy translation at each end. The consequence for defenders is direct: any control that depends on the model's linguistic self-reporting can never be complete, so the sandbox around an agent needs guarantees that do not rest on interpretability. A position paper rather than an empirical result, but it commits to a claim that agent-security architects can act on and dispute.

  4. SafeEvolve: Harness-Policy Co-Evolution from Agent Experience for Safety Alignment (opens in a new tab)

    arXiv cs.CR (AI) ·Qinghua Mao, Wanying Qu, Dadi Guo, Leitao Yuan ·fetched 3 Sep 2026, 11:40 UTC Research agreed3/3

    Why readProposes aligning LLM agent safety by co-evolving the harness (safety prompt and hierarchical skills) alongside the policy, rather than patching one or the other.

    SafeEvolve takes safety evidence from completed on-policy agent trajectories and converts it into bounded, component-level updates to the harness (safety prompts and hierarchical skills), producing harness artefacts the authors describe as auditable and reversible. On the model side it runs a two-stage SFT then RL loop, where harness-use SFT teaches the policy to actually invoke the evolved artefacts and harness-augmented RL shapes autonomous safety behaviour. The framing is useful for anyone building agent guardrails, since it treats runtime control and intrinsic model alignment as one system; the abstract as given carries no benchmark numbers, so the size of the gain is unverified here.

  5. CVE-2026-79408 (CVSS 9.8): An OS command injection vulnerability in MetaGPT 0.8.1 allows an attacker to execute arbitrary commands via the path argument of RepoParser.rebuild_cl (opens in a new tab)

    NVD ·fetched 3 Sep 2026, 11:40 UTC CVE-2026-79408 CVSS 9.8 EPSS 1.2% agreed3/3

    Why readUnauthenticated command injection in a widely forked LLM agent framework, worth an inventory check if anything in your estate points MetaGPT at repositories you do not control.

    CVE-2026-79408 is rated CVSS 9.8 for an OS command injection in MetaGPT 0.8.1, reachable through the path argument of RepoParser.rebuild_class_views() in metagpt/repo_parser.py. Because that value reaches a shell context, any workflow that lets an attacker influence the repository path being parsed yields arbitrary command execution with the agent process's privileges, which in agent deployments often means broad credential and network access. EPSS sits near one percent, so treat this as an internal exposure question rather than an active exploitation event.

  1. Cyberattack on Thomson Reuters Company Hits Courts in 11 States (opens in a new tab)

    Google News: incidents · Bloomberg Law News ·fetched 3 Sep 2026, 03:41 UTC Must read agreed3/3

    Why readA cyberattack on a Thomson Reuters company has disrupted court operations across 11 states, a third-party dependency your board will ask about.

    Courts in 11 states are affected by a cyberattack on a Thomson Reuters subsidiary, according to Bloomberg Law. The report establishes the scope by number of affected states; no attribution, intrusion detail or restoration timeline is given in the available text. This is a concentrated third-party dependency in the judicial sector, and peers relying on the same vendor stack should expect questions.

  2. Nearly 40m Tving accounts compromised in massive data breach: probe (opens in a new tab)

    Google News: incidents · The Korea Herald ·fetched 3 Sep 2026, 11:40 UTC agreed3/3

    Why readRoughly 40 million accounts at Korean streaming service Tving were compromised, per an official investigation, one of the largest consumer breaches disclosed in the country.

    An ongoing probe puts the number of compromised Tving accounts at close to 40 million, a figure larger than South Korea's adult population and therefore covering most of the domestic streaming market. Reporting is at the disclosure stage: no attack vector, intrusion window or data categories are confirmed in the text. Regulatory follow-up under Korean privacy law is the thing to watch, and the scale makes this a question executives in consumer-facing businesses in the region will be asked about.

  3. Luminus Health cyberattack forces Anne Arundel Medical Center to reroute patients (opens in a new tab)

    Google News: incidents · WBAL News Radio ·fetched 3 Sep 2026, 03:41 UTC agreed3/3

    Why readA ransomware-style disruption at Luminus Health pushed Anne Arundel Medical Center onto ambulance diversion, the clearest current example of an IT incident converting directly into degraded patient care.

    The attack hit the parent health system and forced patient rerouting at the medical center, with elective procedures affected. Diversion is the metric worth noting, because it shows downtime procedures failing to hold clinical capacity rather than merely inconveniencing back office systems. Attribution and the intrusion vector have not been published.

  4. Oncology firm Novocure says cyberattack exposed US patient records (opens in a new tab)

    Google News: incidents · Reuters ·fetched 3 Sep 2026, 11:40 UTC agreed3/3

    Why readNovocure, a Nasdaq-listed oncology device maker, has disclosed that a cyberattack exposed US patient records.

    Novocure says a cyberattack resulted in exposure of patient records belonging to US individuals. The Reuters item is at disclosure stage, without record counts, data categories, intrusion dates or attribution. As a listed healthcare device firm, the disclosure brings HIPAA breach notification and likely SEC materiality questions with it, which is the angle a board will raise.

  5. DaVita agrees to pay $15M to settle claims from data breach (opens in a new tab)

    Google News: incidents · Healthcare Dive ·fetched 3 Sep 2026, 07:38 UTC agreed3/3

    Why readPuts a number on healthcare breach litigation exposure: DaVita is paying $15M to settle claims from its data breach.

    Dialysis provider DaVita has agreed to a $15M settlement of claims arising from its data breach. The figure is the useful part, giving boards and insurers a recent comparable for class action exposure following a large healthcare incident. No technical detail on the intrusion itself in this coverage.

  6. FBI Probes Report That Data Breach Exposed Millions of US Driver's Licenses (opens in a new tab)

    Google News: incidents · GV Wire ·fetched 3 Sep 2026, 07:38 UTC agreed3/3

    Why readAn FBI investigation into a reported breach exposing millions of US driver's licenses, the kind of identity-data incident a board and a state regulator will both ask about.

    The FBI is investigating a reported data breach said to have exposed millions of US driver's licence records. The report is early and the coverage carries no detail on the holder of the data, the intrusion vector or the timeline. Identity documents at this volume drive downstream fraud and state notification obligations, so leaders in sectors that consume licence data for KYC should expect questions before the facts settle.

  7. North Dakota Supreme Court impacted by third-party data breach (opens in a new tab)

    Google News: incidents · KFYR-TV ·fetched 3 Sep 2026, 03:41 UTC agreed3/3

    Why readA state supreme court disclosing impact from a third-party breach, relevant if you are mapping vendor exposure across judicial and public sector systems.

    The North Dakota Supreme Court says it was affected by a breach at a third-party provider. Only the disclosure itself is reported; no vendor, data types or timeline are given in the available text. Worth watching alongside the wider court-system incident reported the same day.

  8. Data breach hit Montana state court system from March to June, chief justice says (opens in a new tab)

    Google News: incidents · KTVH ·fetched 3 Sep 2026, 03:41 UTC agreed2/3

    Why readMontana's chief justice confirms the state court system was breached for roughly four months before detection, a long dwell time in an environment holding sealed filings and juror data.

    The breach ran from March through June 2026 and was disclosed by the chief justice rather than by a technical incident report. Court systems hold sealed cases, victim details, and juror records, so the exposure question extends past standard PII notification. Detail on the intrusion path and on what was taken is not in this report.

  9. Two Maryland hospitals hit by cyberattack, compromising systems (opens in a new tab)

    Google News: incidents · WYPR ·fetched 3 Sep 2026, 03:41 UTC agreed2/3

    Why readA second Maryland hospital incident on the same day, which in context is almost certainly downstream of the Luminus Health compromise rather than a separate event.

    WYPR reports two Maryland hospitals with compromised systems following a cyberattack. The item is a headline only, with no attacker, vector, or scope detail, and it overlaps heavily with the Anne Arundel and Luminus Health reporting. Read it as corroboration of the wider regional impact, not as an independent incident.

Unverified claims posted by extortion groups on their own leak sites, not confirmed breaches. Listing is the group's assertion; many named organisations have not disclosed an incident, and some entries are false or recycled. Leak sites are never linked from here.

Claimed victimGroup SectorCountry Seen
America’s Food Basket Wallstreet Retail & E-Commerce US 3 Sep 2026
Engefitas Vexy Ransomware Energy & Utilities BR 3 Sep 2026
Petrocare Construction Storm Energy & Utilities CA 3 Sep 2026
Star Aviation, Inc Storm Transportation US 3 Sep 2026
GSAC Auto Financing Storm Financial Services US 3 Sep 2026
GSAC Storm - US 3 Sep 2026
Superior Ag Storm Agriculture and Food Production US 3 Sep 2026
Chicago Partners Wealth Advisors Storm Financial Services US 3 Sep 2026
Macquarrie Storm Financial Services AU 3 Sep 2026
SITES Medical Storm Healthcare US 3 Sep 2026
Greenberg Traurig SilentRansomGroup Professional Services US 2 Sep 2026
G... ...g SilentRansomGroup - - 2 Sep 2026
S... M... SilentRansomGroup - - 2 Sep 2026
Cartrack Holdings direwolf Transportation ZA 2 Sep 2026
PTT Oil and Retail Business direwolf Energy & Utilities TH 2 Sep 2026
Ormond Beach Florida Wallstreet - US 2 Sep 2026
Asfaltos y Pavimentos S.A. (Asfalpasa) incransom Manufacturing ES 2 Sep 2026
Westfield Public School District incransom Education US 2 Sep 2026
Trucka incransom Transportation MX 2 Sep 2026
Policlinico Triestino incransom Healthcare IT 2 Sep 2026
Multiver Ltée incransom - CA 2 Sep 2026
Metales Panamericanos incransom Manufacturing PA 2 Sep 2026
Ville de Libercourt kairos Government & Defense FR 2 Sep 2026
N*************** insomnia - US 2 Sep 2026
PennFab akira Manufacturing - 2 Sep 2026
How this edition was made
Candidates fetched
2341
New after deduplication
360
Kept by the panel
43
Published
43
Generated
3 Sep 2026, 11:40 UTC