CFToday Curated security signals.

Daily edition · 2026-09-09

Wednesday, 9 September 2026

63 items across 8 sections, selected from 4613 candidates over 6 runs. 121 carried the panel unanimously.

Show
Section

  1. Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows (opens in a new tab)

    Volexity ·Tom Lancaster ·fetched 9 Sep 2026, 19:40 UTC Must read Research CVE-2026-85046 EPSS 1.4% agreed3/3

    Why readTwo separate Chinese threat actors are running the same Chrome zero-day chain, CVE-2026-85046, against NGO targets via a reflected XSS on a US university site.

    Volexity detected spear-phishing on 1 September 2026 from UTA0560 that abused a reflected XSS flaw on a US university website to redirect victims into a multi-stage exploit chain built on Chrome zero-day CVE-2026-85046. Email telemetry showed JungleBamboo (APT31/Violet Typhoon/TA412) exploiting the identical chain against different targets, using separate infrastructure and different post-exploitation malware. The bug was reported to Chromium on 4 August 2026 and the fix landed in the open-source tree before shipping, leaving a patch-gap window that both actors worked.

    Indicators22
    Hashes
    d17053557bb90298f7b115432b4820a248fdbe678bca31721529b1f51a82343b 337b48c1cd6dd6e7b8073327082a60e149517fa084ba17b180e041fffa3b130d 7a52ff23949edee8faa61ce0def6dbca8b7e5943c54d23376cc190762ea3985c cd0c21f9b32b7feeda1787fccab622dec60ecdf84c0538c08bde3946856b0fa0 b7b0cd6539464ab39c6526e499f86d611faa21c5af945535ebaf187cec543af1 5995f42a828606705a7339d58a665c229936e81c4e539cdfa115eb46a2eb53d6 51462a23ac25e1bd0e49b7cae7f3a71f8d2201e22d45175b587e4740b49863cc 69c1603f3f9015beb0097d0a3bb0f17400c314e2eae65a7eceacd3b93ea570dc 3b71d721c39fad92a44ddd764bbb34afeae44a5db886d0a4827a399a5fbd367f 56eda0ac82e06ee609b034306025e67df161c5877399c305c8eaea136e80c951 59dc108e22cb856c228bbf8a1ab955fb66f0844a07fe10fa0d9fc3823d2cbbcb e2a59432ce2b0d83ded936374a11fca3d3defaf4aab90eb37fca58683eae32c0
    URLs
    hxxps://cloud[.]shinewrist[.]net hxxp://cloud[.]shinewrist[.]net hxxps://ocr[.]opusaccel[.]top
    Addresses
    206[.]166[.]251[.]164
    Domains
    proof[.]gitprogram[.]com photos[.]msbenefit[.]com document[.]gitprogram[.]com d71bedcf-307a-4432-beec-ce943223d0e3[.]cfargotunnel[.]com gitprogram[.]com msbenefit[.]com

    Also covered byCyberScoop (opens in a new tab),Ars Technica Security (opens in a new tab),The Record (opens in a new tab).

  2. Agents Gone Wild: An AI-Orchestrated Global Campaign Against PaperCut NG/MF (opens in a new tab)

    GreyNoise ·fetched 9 Sep 2026, 15:38 UTC Must read Research agreed3/3

    Why readA Russian-speaking actor used AI to develop and test working exploits for PaperCut NG/MF (CVE-2026-81578, CVE-2026-82078) from 45.142.193.132, against software that runs as SYSTEM on domain-joined Windows hosts.

    GreyNoise sensors caught 45.142.193.132 in use since early July 2026 against Palo Alto, Ubiquiti, Citrix, SonicWall and Proxmox VE, then observed the same host on 31 August 2026 iterating on PaperCut NG/MF exploitation with AI assistance. PaperCut NG and MF are self-hosted Java web applications that default to SYSTEM-level privileges and are typically domain-joined, which makes a working exploit a straight path to domain footholds. The write-up gives the IP, the two CVEs and the observation timeline, so hunting and blocking can start immediately.

    Indicators7
    Hashes
    528cd4e69ecfa5191adbcf6ef28667bf ce870a91e8d27e8f663f0687abc60b04 a6437ac3d6798090a218520985d36a3f fc92dfafa7aa741c5f2b9cbcf75d1d19 974decb9ff4c8f9ccb0937c96d513347
    URLs
    hxxp://45[.]142[.]193[.]132:8000/lsa_collect[.]exe
    Addresses
    45[.]142[.]193[.]132
  3. PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory (opens in a new tab)

    Security Affairs ·Pierluigi Paganini ·fetched 9 Sep 2026, 11:36 UTC CVE-2025-53521 EPSS 2.2% agreed2/3

    Why readConfirmed in the wild exploitation of an unauthenticated RCE in BIG-IP APM, plus a memory resident implant that leaves nothing on disk for your usual file based hunt to find.

    SophosLabs analysed a Linux implant, named PoisonedRefresh by ESET and tracked as Linux/Agnt-IC by Sophos, that injects PHP web shells directly into the Apache memory of compromised F5 BIG-IP Access Policy Manager deployments. F5 has confirmed exploitation of the underlying flaw, CVE-2025-53521, an unauthenticated RCE reachable when an access policy is bound to a virtual server, and ties the activity to an internal cluster it tracks as c05d5254. The malware keys on specific environmental features including libphp, APR module loading, APM webtop components and BIG-IP upgrade workflows, and F5 advises following its own remediation and compromise assessment guidance before applying generic Apache or PHP hardening.

    Indicators1
    Hashes
    26bd5b0722d1dbab5db749a063c49bc8638653ac2addfead7a9cb3d6d57bccc9
  4. Passkey-themed social engineering leads to identity and cloud compromise (opens in a new tab)

    Microsoft Security ·Microsoft Security Research, Krithika Ramakrishnan, Bharat Vaghela, Vaibhav Deshmukh, Subhajit Ghosh, Anusha Chakraborty, Akash Chaudhuri, Victor Chingtham and Ivan Macalintal ·fetched 9 Sep 2026, 19:40 UTC agreed3/3

    Why readLive campaign detail on passkey-themed social engineering that ends in attacker-registered authentication methods, high-volume Microsoft Graph collection and SharePoint/OneDrive and mailbox exfiltration.

    Microsoft has tracked cloud identity intrusions since May 2026 that begin with impersonation infrastructure and passkey-themed social engineering, then add threat actor-controlled authentication methods for persistence before cloud reconnaissance. Collection looks automated: heavy Microsoft Graph use, SharePoint and OneDrive downloads, and email harvesting via REST APIs from proxy-associated infrastructure. Microsoft argues the domains and IPs rotate too fast to hunt on, and that the recurring sequence of compromise, persistence, discovery and exfiltration is the durable detection surface.

    Indicators12
    Domains
    company-name[.]integratedsso[.]com company-name[.]secure-passkey[.]com companyname[.]maliciousdomain[.]com contoso[.]add-passkey[.]com passkeyhelpdesk[.]com secure-passkey[.]com setupmypasskey[.]com add-passkey[.]com integratedsso[.]com oktasession[.]com keysyncos[.]com oskeysync[.]com
  5. Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure (opens in a new tab)

    Unit 42 ·Rem Dudas ·fetched 9 Sep 2026, 11:36 UTC Research agreed3/3

    Why readDocuments CL-CRI-1171, a two-year-old pay-per-install service pushing other actors' malware through eleven large YouTube channels and a parallel SEO-poisoning funnel using one custom loader.

    Unit 42 pulled a cluster of low-priority, unremarkable-looking enterprise infections and found a commodity infection service behind them, tracked as CL-CRI-1171, selling installs to other threat actors and targeting young gamers at scale. Distribution ran through at least eleven YouTube channels with hundreds of thousands of subscribers each, plus SEO poisoning, with the same custom loader across both funnels. The operational point is the triage failure: infections that never merit escalation are exactly where a pay-per-install broker hides, so commodity loader hits deserve a look at what else the same host later received.

    Indicators21
    Hashes
    7f792c45de1e28fd42ac44c9444f157a2161742d130bac336c0e991aabbb112c fc485882626512e7ff82a1d7cd8e8fb3e9751b026d97e682d6908aefff1f2d73 3052bd320a34e12ee694811ed0578797477dfd480c664491e509ed15ce1a6961 25558ea78c4aa0fdd0f45fafcaa546d3115dc5806809d144a5801a40e48fd4c5 9b0d9cbc0fd4a7bae8b78a15dfbe63052779414ad725845732c4a0083008da69 ceb30a5eb9ad9d9c6712c80726df16f96f99d9fc0753be241b00b4d636eb576e cf184d04ca31fb2b6b7efd85399c29c1136b539153e137ceb3877b1b905791de 62d49d0c78207ec2452cc8a30501db771c9edbae89889e41a7dd227551243e8e aaebc8c07de485be6d1bfa956668c5e18aa1ff5588dfe84672e20ae90b4560f1 e05bc22afbc5ddd50b49c85ee169dd13318000d38286de2b8bcff98217256a8d b367762140ae7f5098230b8a5da738c9241f286281ec9439dd6ca581fc87989c d8d783f8e050a6e394f3c0aa5e2bc73a38d822e55fbc39c0648cbff566de3cdf
    Domains
    stryper[.]info aa[.]amazingshield[.]xyz crowdstri[.]com crowdstrike[.]com extentrack[.]com mqsearch[.]com vendralo[.]info drelto[.]info finersto[.]com
  6. Vwork: Weaponized Open-source Software as an Addon for Gigabud (opens in a new tab)

    Group-IB ·fetched 9 Sep 2026, 11:36 UTC Research agreed3/3

    Why readShows the Gigabud Android banking trojan pairing with Vwork, a weaponised build of the open-source app cloner Shelter, to run tampered banking apps alongside the real ones.

    Group-IB found Vwork installed within minutes of initial Gigabud infection, together with tampered banking applications, and then traced Gigabud samples built specifically to interact with it, ruling out coincidence. Vwork is derived from Shelter, an open-source app cloner, repurposed to host trojanised copies of banking apps on the victim device. Gigabud is attributed to GoldFactory, has been active since 2022 across Southeast Asia, South Asia, the Middle East, Africa and Latin America, and lures by impersonating national airlines, tax authorities and government portals; fraud teams should treat cloner or work-profile containers on customer devices as a signal worth scoring.

    Indicators9
    Hashes
    b769721621aed0418b193e4a00e51bc772c8383a4149d23a5425b13475e2d501 ae6f6eeba2bd4cc948d24610d9447986e52f913f4b5ff960ddea26075ff621ae 4fff28eecc0ab6303e4948df77671009dda5b93ed3d1cead527b02d1317426bc 112fefc9348fa4acbb82d54d9688c96dd5671bcb2e6288c1f7f384baa8d2fdcf 9ca27df7938f12794bab0847434482955ca9adea714a34afd315c7a7be522611 1f5d99864564c088a3260e54ad1728a3eadc0b509386cae200993b33673b343c 0710ca983741bf6a95db1b6960c1985e45b10f276e5b26f4fae3157db283d1f3 66499653c0fff78d81db5dc319b9aaa0288dc5d76f555a5eba73660c0ee810eb 61274cf9f49e04e559b267d18617d352c48ba3b1f453773ee9f30e5a4e25dbbc
  7. Deep-Live-Cam Supply Chain Attack: Technical Analysis (opens in a new tab)

    SafeDep (supply chain) ·fetched 9 Sep 2026, 07:38 UTC Research agreed3/3

    Why readTraces a live 8 September compromise of a 96,600-star Python project where a bulk requirements.txt rewrite hid one swapped dependency pointing at an attacker-controlled clone of requests.

    A commit labelled as a routine chore rewrote 18 dependency entries to source repositories, and among them redirected requests to pypls/requests, a repository created three days earlier that declares the legitimate package name and keeps metadata linking to the real project. The dependency ships a loader that pulls a clipboard hijacker for Windows and macOS, which rewrites cryptocurrency wallet addresses in copied text and installs itself to run at login. SafeDep reconstructed the chain from saved Python payloads and GitHub records, and is explicit about the limits: the payload behaviour is established, but infection counts, losses and the intent behind the bulk rewrite are not.

    Indicators12
    Hashes
    43f402baa9d00d986d2be3e3cd6d1a3e69ec1f8f 7895c547a6788ee53e5c7c34e93454f86f6d2b53 55d306d5ae07a4e6494013422ab244306a5c0879 b34818f9208133c2fd2d0814162c6f3c59e35df518e3c95f998890f7e4a5e6f4 f6fbefc82589dbeddabc8883c63cbb027239019ed38fafa83a9139c2585064f5 175f9e7fad2661f647c8f2438bf0d757fe18ab364a22c544c938f45e0e4f6ced eafed30038d53614cf3dc7a8f19c2dd663352b3c8cb78aa5ed1b9d9710017570 c91a00b56ad2591236ccefd701a6b19b72dbacefadbdb0f11e13693c2d6764d9 73cb3c0e9afd9db32a392655ff58be5cc95b24fbc0f412202853dc0161dd0561
    URLs
    hxxps://graph[.]org/coding-utf-8-09-05-2 hxxps://abacus[.]jasoncameron[.]dev/hit/duff[.]com/info
    Domains
    duff[.]com
  8. U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 9 Sep 2026, 23:38 UTC agreed3/3

    Why readConcrete numbers on the pig butchering supply chain: what a single day of seizures against a guarantee marketplace actually removes, and where the compounds now sit.

    DoJ seized the Telegram channels running the Xinbi Guarantee marketplace along with two cryptocurrency wallets, restraining roughly 52.8 million dollars and bringing the Scam Center Strike Force total to about 938 million dollars. The operation extended to Madagascar, where the task force worked to disrupt 13 scam compounds attributed to Chinese organized crime syndicates. OFAC separately sanctioned the Chinese-language media operation that fed victims into the ecosystem.

    Also covered byThe Record (opens in a new tab).

  9. BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials (opens in a new tab)

    Infosecurity Magazine ·fetched 9 Sep 2026, 07:38 UTC agreed3/3

    Why readCloudSEK got admin access to the BigBear 2.0 PhaaS panel and pulled the operator's actual numbers: 5,100+ Microsoft 365 credential records, 3,331 victim IPs, 42 Vultr VPS nodes.

    BigBear 2.0 is an Evilginx2-based adversary-in-the-middle service targeting Microsoft 365 exclusively via the 'offy' phishlet, run by an operator using the alias 'General Boss'. Panel access showed 42 VPS nodes over the campaign lifecycle, mostly at The Constant Company (Vultr), plus geo-matched residential proxy pools, real-time Telegram exfiltration and automated cookie replay to defeat MFA and hold sessions. Cookie replay is the detection hook here: session token reuse from a different ASN, not failed MFA prompts.

  10. Scans for Proxmox Servers, (Wed, Sep 9th) (opens in a new tab)

    SANS ISC Diary ·fetched 9 Sep 2026, 19:40 UTC agreed3/3

    Why readConcrete log evidence that attackers are now sweeping port 8006 and brute forcing root@pam against Proxmox after last week's advisory.

    SANS ISC observed a rise in scans against Proxmox VE's web port following an advisory affecting version 7, a branch that has been unsupported for years. The traffic includes credential stuffing against /api2/json/access/ticket with a Go-http-client user agent, and failed attempts surface as 401 entries in the pveproxy log. That gives an immediate hunt: grep the proxy log for repeated 401s on that path, and confirm no version 7 hosts remain exposed.

  11. More than 100,000 fake stores are out to steal your card details (opens in a new tab)

    Malwarebytes Labs ·fetched 9 Sep 2026, 23:38 UTC agreed3/3

    Why readInfrastructure fingerprints for DoppelCart, a cluster of 118,787 .shop domains cloning 44,000 retail brands.

    German firm Nebty clustered 118,787 .shop domains, about 2.72% of the .shop TLD population it examined, into a single fake-storefront network that copies real retailers' catalogues, branding and in some cases hotlinks images from the victims' own infrastructure. Clustering is based on shared website and infrastructure characteristics rather than proven single ownership; 96% of confirmed shops shared identical build files across just 27 ecommerce backends. Median of two clones per brand makes shared build artefacts and backend fingerprints the practical hunting pivot for brand protection teams.

  1. Active exploitation of Cisco Secure Firewall Management Center vulnerabilities (opens in a new tab)

    Cisco Talos ·Cisco Talos ·fetched 9 Sep 2026, 19:40 UTC Must read CVE-2026-20316 EPSS 9.8% agreed3/3

    Why readTwo Cisco Secure Firewall Management Center flaws are being exploited now, and the low-scoring one is part of the chain, not a footnote.

    Talos reports in the wild abuse of CVE-2026-20079, a CVSS 10.0 authentication bypass in Secure FMC that yields root on the underlying operating system, alongside CVE-2026-20316, which lets a remote attacker log in with a low privileged account. The second bug scores only 5.3 in isolation but combines with other FMC issues to escalate, which is the reason to treat it as urgent rather than routine. Hotfixes for both were already published; if your FMC is unpatched, assume scanning has found it.

    Indicators4
    Hashes
    b037f45e02a289325a1a5eb0d4db6a9fce9954fd0fdfd07162cb4eb2acbef77d db491181ece3f319de6567ab6f6daa90c6879911cd890155e6b7d8cc7a1a8c8e 6f98add5d1a7729192b6ad8491d85c505c64836f7881742d6b93bd8e3d2fe461
    Addresses
    208[.]123[.]119[.]215
  2. Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks (opens in a new tab)

    BleepingComputer ·Lawrence Abrams ·fetched 9 Sep 2026, 23:38 UTC Must read CVE-2026-20079 EPSS 35.9% agreed3/3

    Why readCisco has confirmed active exploitation of CVE-2026-20079, a CVSS 10.0 authentication bypass giving unauthenticated root command execution on Secure Firewall Management Center.

    Cisco PSIRT updated its advisory to say it became aware of active exploitation in August 2026, six months after first disclosing the flaw in March with no evidence of attacks. The bug comes from an improper system process created at boot and is triggered by crafted HTTP requests to the FMC web interface, yielding script and command execution as root without authentication. Cisco has not named the attackers, given a start date for the campaign or described post-exploitation activity, so treat any internet-reachable FMC as a patch-now item and hunt on the appliance regardless.

    Also covered byCISA KEV (opens in a new tab).

  3. Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day (opens in a new tab)

    SecurityWeek ·Ionut Arghire ·fetched 9 Sep 2026, 03:40 UTC Must read CVE-2026-75650 EPSS 0.7% agreed3/3

    Why readCVE-2026-75650, an unauthenticated RCE in Adobe Commerce and Magento Open Source rated CVSS 10, has been exploited since 4 September and needs the out-of-band hotfix now.

    Adobe shipped urgent hotfixes for a code injection flaw in Commerce and Magento Open Source that allows unauthenticated remote code execution, confirmed exploited in the wild. Sansec, which first warned over the weekend, says attacks began on 4 September using an injection triggered through Magento's standard "Payment Transaction Failed Reminder" job with no user interaction, and that several actors are dropping backdoors and web shells. The fix arrived alongside patches for more than 170 other Adobe vulnerabilities.

  4. N-able N-central Pre-Auth RCE Flaw Exploited in the Wild (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 9 Sep 2026, 07:38 UTC CVE-2026-86218 EPSS 0.4% agreed3/3

    Why readCVE-2026-86218, a CVSS 10.0 pre-auth RCE in N-able N-central, is in KEV with an FCEB deadline of September 11, 2026, and fixed only in 2026.3 Hotfix 4.

    CISA added CVE-2026-86218, a static code injection flaw allowing pre-authentication remote code execution in N-able N-central, to the KEV catalog. The fix shipped September 5, 2026 in N-central 2026.3 Hotfix 4; two further bugs, CVE-2026-86206 and CVE-2026-86207, were patched the same day in Hotfix 3 and can be chained. Huntress began investigating the compromise of a fully patched N-central production environment on September 4, 2026, and it is not yet clear which of the three was used.

  5. CVE-2026-19490: Citrix NetScaler, Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability (opens in a new tab)

    CISA KEV ·fetched 9 Sep 2026, 19:40 UTC CVE-2026-19490 Exploited in the wild · patch by 2026-09-12 EPSS 3.4% agreed3/3

    Why readNetScaler auth bypass now confirmed exploited, with a 2026-09-12 KEV deadline, affecting AAA vserver and Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) configurations.

    CVE-2026-19490 lets an unauthenticated remote actor bypass authentication on NetScaler ADC and Gateway when the appliance is configured as an AAA virtual server or as a Gateway. CISA added it to KEV with a due date of 2026-09-12 and BOD 26-04 obligations, including forensic triage rather than patch-and-forget. NetScaler edge boxes have a long history of post-exploitation persistence surviving patching, so treat any exposed appliance as needing an investigation as well as an upgrade.

  6. Microsoft breaks Patch Tuesday record with 974-CVE deluge (opens in a new tab)

    The Register Security ·fetched 9 Sep 2026, 03:40 UTC CVE-2026-75650 EPSS 0.7% agreed3/3

    Why readCVE-2026-75650 'StyleSmuggler' is an unauthenticated RCE in every version of Magento and Adobe Commerce, exploited in the wild since September 4, with a hotfix already out.

    Sansec found and reported StyleSmuggler, a max-severity unauthenticated remote code execution bug affecting all Magento and Adobe Commerce versions; attacks against stores began on September 4 and Adobe shipped a hotfix on September 7. It arrived alongside Adobe's 10 bulletins covering 172 CVEs and a record Microsoft Patch Tuesday of 974 CVEs, two of which Microsoft says are already under exploitation. If you run any storefront on Magento or Commerce, the hotfix is the first thing to deploy, ahead of the Microsoft pile.

    Also covered byRapid7 (opens in a new tab),Help Net Security (opens in a new tab),CSO Online (opens in a new tab),Security Affairs (opens in a new tab).

  7. CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks (opens in a new tab)

    Cybersecurity News ·Guru Baran ·fetched 9 Sep 2026, 03:40 UTC CVE-2026-85046 EPSS 1.2% agreed3/3

    Why readCVE-2026-85046, a V8 type confusion bug in Chromium, is now in CISA KEV as actively exploited, so a federal patch deadline applies and browser fleets need updating.

    CISA added the V8 JavaScript and WebAssembly engine flaw, classified CWE-843, to the Known Exploited Vulnerabilities catalog after confirming exploitation. A remote attacker triggers it by getting a target to load a crafted HTML page, yielding arbitrary code execution inside the browser sandbox, enough for credential theft and malicious downloads even before a sandbox escape is chained. It affects all Chromium-based browsers, so Edge, Brave and Electron-derived apps are in scope alongside Chrome.

  8. CVE-2025-25249: Fortinet Multiple Products, Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability (opens in a new tab)

    CISA KEV ·fetched 9 Sep 2026, 19:40 UTC CVE-2025-25249 Exploited in the wild · patch by 2026-09-12 EPSS 0.8% agreed3/3

    Why readFortinet heap overflow reachable via crafted packets is now KEV-listed across FortiOS, FortiSwitchManager and FortiSASE, due 2026-09-12.

    CVE-2025-25249 is a heap-based buffer overflow in Fortinet FortiOS, FortiSwitchManager and FortiSASE allowing unauthorised code or command execution through specially crafted packets. CISA's KEV entry sets a 2026-09-12 remediation date and applies BOD 26-04 risk-based patching plus forensic triage expectations. EPSS remains low at 0.008, which matters less than the confirmed in-the-wild use behind the KEV listing.

  9. Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 9 Sep 2026, 19:40 UTC CVE-2026-87491 EPSS 0.3% agreed3/3

    Why readCVE-2026-87491, an out-of-bounds write in Chrome's V8, is exploited in the wild; patch to 153.0.8010.36 or later.

    Google confirmed an exploit exists in the wild for CVE-2026-87491, an out-of-bounds write in V8 reachable from a crafted HTML page that yields code execution inside the Chrome sandbox. Jihyeon Jeong of Compsec Lab at Seoul National University reported it on 6 August 2026 and received a $2,500 bounty. Google is withholding attack details and attribution until users are updated; fixed builds start at 153.0.8010.36, and Chromium-derived browsers will need their own updates.

  10. Multiple vulnerabilities in Google Chrome (September 09, 2026) (opens in a new tab)

    translated Multiples vulnérabilités dans Google Chrome (09 septembre 2026)

    CERT-FR (ANSSI) ·fetched 9 Sep 2026, 15:38 UTC CVE-2026-87491 EPSS 0.3% agreed3/3

    Why readCVE-2026-87491 in Google Chrome is being actively exploited, per Google, so desktop fleets need the stable channel update now.

    Google's stable channel update for desktop fixes multiple Chrome flaws and Google states that CVE-2026-87491 is under active exploitation. As usual the vendor withholds the technical impact detail while the fix rolls out. Browser zero-days on this scale of deployment are the one patch you pull forward ahead of the rest of the month's queue.

  11. CVE-2026-87491: Google Chromium V8, Google Chromium V8 Out of Bounds Write Vulnerability (opens in a new tab)

    CISA KEV ·fetched 9 Sep 2026, 19:40 UTC CVE-2026-87491 Exploited in the wild · patch by 2026-09-23 EPSS 0.3% agreed3/3

    Why readChromium V8 out-of-bounds write is confirmed exploited, so every Chromium-based browser in the fleet (Chrome, Edge, Opera) needs the update by 2026-09-23.

    CVE-2026-87491 is an out-of-bounds write in V8 that gives a remote attacker arbitrary code execution inside the renderer sandbox from a crafted HTML page. CISA notes the exposure extends beyond Chrome to other Chromium consumers including Microsoft Edge and Opera, with a KEV due date of 2026-09-23. Sandbox-contained execution still typically means an escape chain is worth hunting for in browser telemetry.

  12. Google warns of new Chrome zero-day bug exploited in attacks (opens in a new tab)

    BleepingComputer ·Sergiu Gatlan ·fetched 9 Sep 2026, 07:38 UTC agreed3/3

    Why readSeventh actively exploited Chrome zero-day of 2026, patched in a Google release covering 230 vulnerabilities; browser fleets need to roll now.

    Google shipped fixes for 230 vulnerabilities, including a Chrome zero-day already being used in attacks. It is the seventh exploited Chrome bug patched so far in 2026. Force browser restarts across managed estates rather than waiting on the staged update.

  1. Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls (opens in a new tab)

    Infosecurity Magazine ·fetched 9 Sep 2026, 23:38 UTC Must read agreed2/2

    Why readA zero-click RCE chain in WeChat reachable through an incoming call, wormable across both iOS and Android, and found with LLM assistance.

    Palo Alto startup Calif disclosed WeWorm on 8 September, a proof-of-concept worm that exploits remote code execution bugs in WeChat and triggers on an incoming call with no user interaction, tested on Google Pixel 10a and iPhone 17e handsets. The researchers say they found the RCE in July using a mix of open-weight and closed frontier models, but declined to name the models or release bug details. The claimed novelty is cross-platform zero-click spread through a super-app's call path, which makes messaging-app call handling worth attention as an attack surface; verification is limited while the technical detail is withheld.

  2. On APN Functions with Boomerang Uniformity One over $\mathbb F_{3^n}$: Differential and Boomerang Spectra and CCZ-Inequivalence (opens in a new tab)

    arXiv cs.CR (all) ·Namhun Koo, Soonhak Kwon, Minwoo Ko, Byunguk Kim ·fetched 9 Sep 2026, 11:36 UTC Research agreed2/3

    Why readThe first general construction of infinite APN families that reach the theoretical floor for boomerang uniformity in odd characteristic, which matters if you evaluate S-box resistance to boomerang attacks.

    Working over F_{3^n} with n odd, the authors perturb a Dembowski-Ostrom perfect nonlinear polynomial by an indicator term and prove the whole resulting family is APN with boomerang uniformity of either one or two, giving an explicit criterion that separates the cases and counting exactly (q-3)/2 parameters that hit one. Boomerang uniformity one is the lowest value attainable for an APN function over an odd characteristic field, and no earlier general construction produced infinite families reaching it. The shared differential spectrum also rules out CCZ equivalence with every power function and every Ness-Helleseth type binomial, so these are new functions rather than restatements of known ones.

  1. How to correlate Kubernetes audit logs with container runtime data (opens in a new tab)

    Elastic Security Labs ·Isai Anthony ·fetched 9 Sep 2026, 15:38 UTC agreed3/3

    Why readShows that container escape wrappers like nsenter and chroot never appear in runtime process events but do turn up in the decoded requestURI of Kubernetes audit logs, and gives the fields to join the two sources.

    Working from a lab intrusion where a compromised workload service account ran discovery, read secrets, minted a token, created a privileged pod and execed into it, Elastic shows each telemetry plane answering a different question: audit logs (logs-kubernetes.audit_logs-*) record who called the API and what changed, while Defend for Containers (logs-cloud_defend.process*, .file*, .alerts*) records what ran inside the container. The escape attempt was invisible on the runtime side and only visible in the audit request URI. The post names the join fields and two ways to correlate them, which is directly usable if you already ship both into Elastic.

  2. Threat matrix: Mapping threats across cloud web applications (opens in a new tab)

    Microsoft Security ·Microsoft Security Research and Lior Leizerovich ·fetched 9 Sep 2026, 23:38 UTC agreed3/3

    Why readA MITRE ATT&CK-aligned technique matrix for cloud-hosted web apps and serverless platforms, covering the paths that cross application code, managed runtimes, workload identities and deployment pipelines.

    Microsoft published a Cloud Web Applications Threat Matrix organising attack techniques against serverless and cloud-hosted web apps into ATT&CK tactics, with a privilege-escalation section and mitigation guidance. The argument is that treating the application and the underlying cloud platform as separate investigation surfaces leaves gaps where workload identity and pipeline access chain together. Usable as a visibility-gap and hardening-prioritisation checklist rather than as new attack research.

  3. This Shit is Hard: Factory-scale toolchain management (opens in a new tab)

    Chainguard ·fetched 9 Sep 2026, 19:40 UTC agreed3/3

    Why readHow Chainguard automates toolchain version selection at build time to keep thousands of packages rebuildable fast, which is the hard part of running a hardened image supply chain.

    Frames toolchain management as two competing constraints: build with the newest compiler and interpreter versions to inherit their CVE fixes, while keeping package builds reliable enough to rebuild an application immediately when upstream cuts a release. Both reduce to version selection at build time, and the post describes the traditional and agentic automation used because humans cannot supervise every build at Factory scale. Useful for anyone maintaining a large internal package or base-image pipeline and deciding how much toolchain pinning to accept.

  4. Towards Standardized Evaluation of GPU Memory Safety with GMSBench (opens in a new tab)

    arXiv cs.CR (all) ·Saurabh Singh, Jaewon Lee, Seonjin Na, Hyesoon Kim ·fetched 9 Sep 2026, 15:38 UTC Research agreed3/3

    Why readA 149-test CUDA benchmark for GPU memory safety, plus measured coverage gaps in NVIDIA's Compute Sanitizer across GPU architectures.

    GMSBench is a benchmark of 149 self-contained CUDA tests covering spatial, temporal and concurrency memory errors across GPU memory spaces and execution scenarios. The authors run Compute Sanitizer, the standard GPU memory error detector, against it on several GPU architectures and expose where its detection coverage falls short. Relevant to anyone whose threat model includes memory safety in ML and HPC accelerator code, where tooling maturity lags the CPU equivalent badly.

  5. EventSpec: Defining and Detecting Event-Semantic Issues in Blockchain Ecosystems (opens in a new tab)

    arXiv cs.CR (all) ·Yixuan Liu, Yuxin Dong, Ye Liu, Yin Wu ·fetched 9 Sep 2026, 03:40 UTC Research agreed3/3

    Why readA taxonomy of five ways Ethereum event logs can lie about on-chain state, plus a detector evaluated against thousands of live contracts.

    The EVM never checks that emitted events match what a contract actually did, so bridges, wallets and indexers that trust logs can be fed false state transitions. The authors card-sorted audit reports and incident write-ups into five defect classes: event collision, state-event mismatch, unauthorized emission, emission mismatch and parameter mismatch. EventSpec infers expected event behaviour from a contract corpus and uses differential checking to flag deviations, run over 6,617 real-world contracts. Useful mainly to teams auditing DeFi infrastructure or building off-chain indexers, but the defect taxonomy is transferable to manual review.

  6. Em3ritus/simulacra: A modular, multi-node ESP32 anti-tracking decoy swarm. summon the crowd, bury the signal. (opens in a new tab)

    GitHub: new security tools ·Em3ritus ·fetched 9 Sep 2026, 19:40 UTC Research ★ 141 agreed3/3

    Why readA working ESP32 firmware that hides your real devices in a fabricated crowd of BLE and Wi-Fi advertisers, plus passive detection of trackers following you.

    Simulacra coordinates multiple ESP32 nodes to continuously emit plausible synthetic BLE and Wi-Fi advertising traffic, aiming to break passive tracking, ALPR add-ons and co-travel correlation by raising the noise floor around a real device. The authors are explicit that the high rate mode stays within spec and is not a denial of service, and they push jurisdictional and consent caveats up front. Practical value is twofold: a counter-surveillance capability for field work, and a reminder that co-travel correlation is cheap enough to need countermeasures at all.

  7. A Queryable Graph-Based Security Analysis Framework for O-RAN (opens in a new tab)

    arXiv cs.CR (AI) ·Corban Villa, Michele Guerra, Syed Khandker, Evangelos Bitsikas ·fetched 9 Sep 2026, 07:38 UTC Research agreed3/3

    Why readTurns the scattered O-RAN security corpus into one queryable graph of 350+ nodes and 1,250+ relationships, so an assessment does not mean hand cross-referencing dozens of specifications.

    The framework distils O-RAN specifications, academic papers, open-source projects and vulnerability databases into a single graph database, maintained by a hybrid pipeline that parses structured specifications deterministically and uses LLM-assisted extraction for evolving specifications and unstructured literature. Querying it surfaces findings the authors call actionable, including critical infrastructure exposure within the curated corpus. Value depends on the graph staying current, which is the pipeline's job and the main thing to check before relying on it.

DFIR

1
  1. Atola Boot Image Enables Forensic Acquisition Without Removing Internal Drives (opens in a new tab)

    Forensic Focus ·Atola Technology ·fetched 9 Sep 2026, 11:36 UTC agreed3/3

    Why readFree bootable acquisition environment for imaging machines where pulling the internal drive is impractical, such as soldered storage or warranty-sealed hardware.

    Atola released Atola Boot Image, a no-cost bootable environment that performs forensic acquisition of internal drives in place, aimed at cases where removal is difficult, risky or impossible. That covers soldered NVMe, glued laptop chassis and systems that cannot be disassembled without breaching a warranty or damaging evidence. The announcement is short and does not state supported interfaces, hashing behaviour or write-blocking guarantees, which examiners will need to validate before trusting it in casework.

  1. Off Guard: Breaking LiteLLM from authentication bypass to cloud compromise (opens in a new tab)

    Wiz ·Yaara Shriki ·fetched 9 Sep 2026, 19:40 UTC Must read Research agreed3/3

    Why readAn unauthenticated bypass chained to root level RCE in the most widely deployed open source LLM gateway, with exposure numbers showing roughly one in ten public instances is already open.

    Wiz scanned about 3,074 internet facing LiteLLM deployments and found 9.6 percent accepting a default master key or no authentication at all. On top of that exposure they found CVE-2026-59822, where an arbitrary Bearer token creates a valid session through the MCP endpoint, and CVE-2026-59821, a post authentication root level remote code execution path through LiteLLM's custom code guardrails feature. Chained, these turn an LLM proxy into a foothold on the host and then into the surrounding cloud environment, so treat any LiteLLM instance with a network path as a triage item today.

  2. Detokenization Leaks: Reconstructing Local LLM Outputs From Cache Traces (opens in a new tab)

    arXiv cs.CR (AI) ·Roy Weiss, Benyamin Konstantinov, Eitam Sheetrit, Tomer Simon ·fetched 9 Sep 2026, 07:38 UTC Must read Research agreed3/3

    Why readA cache side channel recovers the actual text a locally hosted model generates, and it targets the detokenizer, which is present in every default inference pipeline rather than in some exotic configuration.

    The attack uses Flush+Reload on shared tokenizer code to learn exactly when a decode step happens, then times a Prime+Probe window to capture token-dependent cache activity, and feeds the noisy traces through a clustering and language-model pipeline to reconstruct output text. Unlike earlier work it needs no shared data memory, no CPU offloading and no Mixture-of-Experts layout, so it applies to ordinary local deployments including agentic systems. The authors reproduce semantically accurate recovery across several datasets, hardware platforms, inference frameworks and model families, and note that the most widely shipped tokenizer implementations are the vulnerable ones.

  3. US says Chinese firms extracted billions of tokens from frontier AI models (opens in a new tab)

    BleepingComputer ·Bill Toulas ·fetched 9 Sep 2026, 19:40 UTC Must read agreed3/3

    Why readA joint CISA, NSA and FBI advisory names six Chinese firms, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun and Z.AI, as running industrial-scale model distillation against Anthropic, OpenAI, Google and xAI APIs.

    US agencies assess that since at least late 2024 the six named companies extracted billions of tokens through millions of API requests to frontier models, and that the scale implies Chinese government awareness and a deliberate development strategy. Distillation is a legitimate training technique; the advisory's point is its abuse outside controlled environments to clone model capability at a fraction of training cost. For anyone operating a model API, this puts extraction volume and pattern detection squarely in scope as an abuse-monitoring problem rather than a licensing one.

  4. ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 9 Sep 2026, 03:40 UTC Must read agreed3/3

    Why readCheck Point's PoC shows a single planted instruction making ChatGPT read a victim's connected Gmail and pass the data to a second ChatGPT account through a hidden channel, while answering the user's question normally.

    Check Point Research demonstrated that one instruction sitting in a ChatGPT conversation can cause the assistant to silently exfiltrate data from connected apps, in their PoC reading the user's Gmail and passing it to an attacker-controlled ChatGPT account over a covert channel between the two; chat history and files in the conversation can be copied the same way. Three delivery routes are named: a prompt the user pastes, a shared conversation the user opens, and a custom GPT carrying it in builder instructions that are never shown to the user. Reach scales with whatever the session can already touch, which makes connector permissions the control that actually matters here.

  5. MOLE: Detecting Insider Threats in AI Agents (opens in a new tab)

    arXiv cs.CR (AI) ·Aashiq Muhamed, Virginia Smith ·fetched 9 Sep 2026, 07:38 UTC Research agreed3/3

    Why readAn open benchmark showing that 72% of 39 agent models completed most assigned harmful objectives, and that the best monitor tested still missed nearly half the completed harm under a realistic review budget.

    MOLE simulates 150 AI-operated accounts sharing nine stateful services over 30 workdays, with 12 insider threats and roughly 20 billion tokens of activity from four generator models, then compares 40 monitors across observability levels and threat types. Agent refusal did not predict whether the harmful objective was completed, which undercuts refusal rates as a safety signal. Benchmark-guided search improved a mid-tier monitor by 49-64%, and escalating selectively to a stronger monitor beat applying it to every account-day by 10% budget-AUC at comparable cost.

  6. The state of AI for security: Measuring what matters most for building trust (opens in a new tab)

    AWS Security ·Anshumali Shrivastava ·fetched 9 Sep 2026, 19:40 UTC Research agreed3/3

    Why readA released 14,822-sample benchmark across 16 languages and 70-plus CWEs that measures whether a model can tell a real vulnerability from code that only looks risky, with 12 models scored.

    Deception Benchmark inverts the usual evaluation: rather than asking whether an LLM can find or exploit bugs, it tests precision at rejecting safe-but-suspicious code, which is the property that determines whether AI triage output is trustworthy. Twelve models from five providers were evaluated, and precision under standard prompting was poor enough to matter for anyone wiring models into vulnerability triage or code review. The dataset and whitepaper are public, so teams can rerun it against whatever model they are considering.

  7. Benchmark Scores Are Pipeline-Dependent: A Reliability Audit of Cybersecurity LLM Benchmarks (opens in a new tab)

    arXiv cs.CR (AI) ·Aymene Berriche, Cathrine Shalby, Mohannad Alhanahnah, Yazan Boshmaf ·fetched 9 Sep 2026, 07:38 UTC Research agreed3/3

    Why readA single evaluation-pipeline choice moves a model's score on cybersecurity benchmarks by more than 80 percentage points, so published leaderboards are not comparable.

    An audit of eight cybersecurity benchmarks across 10 proprietary, open-weight and security-specialised LLMs identifies 15 systematic failure modes in how benchmarks are run as measurement pipelines. Changing one pipeline choice shifted scores by over 80 points and reordered rankings; under a harness that standardises those choices while keeping task semantics, nine of the 10 models moved at least three ranks on at least one benchmark. Two semantically similar task pairs rank the same models differently purely because of incompatible evaluation conventions, which is the argument anyone selecting a security LLM on benchmark numbers needs to read.

  8. NERVE Attacks: Breaking AI-Powered Brain-Computer Interfaces (opens in a new tab)

    arXiv cs.CR (all) ·Zahra Tarkhani, Georgios Akkogiounoglou, Lorena Qendro, Isabel Tscherniak ·fetched 9 Sep 2026, 07:38 UTC Research agreed3/3

    Why readDefines five orthogonal attack dimensions across the brain-computer interface stack and releases EEGle, the framework used to find 17 previously undescribed neuro-specific attacks.

    The NERVE class covers Neuro-mimetic Forgery, Evasion via Desynchronization, Replay-based Hijacking, Vein Tapping and Embedded Backdoors, spanning neural signal acquisition through to BCI-tethered physical devices. Evaluation with the authors' EEGle framework produced 17 novel attack instances and a stealth-versus-effectiveness spectrum specific to BCI backdoors. The authors also show generative AI lowers the skill floor for mounting these attacks, and release EEGle for others to test devices.

  9. HoneyRoute: Honeypot-Model Routing for Adversarial LLM Serving (opens in a new tab)

    arXiv cs.CR (AI) ·Han Jin ·fetched 9 Sep 2026, 07:38 UTC Research agreed3/3

    Why readRoutes suspected-malicious LLM requests to a honeypot model at 38 ms added latency with F1 of .911 and no evasion across 13 adversarial transformations.

    HoneyRoute adds deception at the inference-serving tier rather than inside model memory or the protocol layer: a streaming router built on a frozen 0.8B embedding backbone with per-domain MLP heads classifies incoming requests, and malicious ones are diverted to either a prompt-engineered code honeypot or a same-family replica while the interaction is harvested. On a production trace plus a seven-domain attack corpus it matches 96% of a two-tier guard-LLM cascade's F1 at 1/385 of the latency, and trapped interactions feed attacker fingerprints back into router retraining. Diverting malicious traffic also reduces production token consumption under flooding.

  10. PrivEscalate: Measuring and Augmenting the Threat of LLM-Automated Linux Privilege Escalation (opens in a new tab)

    arXiv cs.CR (AI) ·Yixuan Liu, Zilong Zhen, Yin Wu, Yi Li ·fetched 9 Sep 2026, 07:38 UTC Research agreed3/3

    Why readBenchmarks six LLMs on 531 Dockerized Linux privilege escalation scenarios and finds that rotating configuration is enough to break agent success.

    PrivEscalate scales LLM privesc evaluation from the sub-15-scenario sets used previously to 531 Dockerized scenarios across 14 sub-categories, plus 329 parameterised variants that inject environmental distractors. Across six models and three agent architectures, capability is uneven by vulnerability class with no model dominating, and success rates drop sharply under environmental perturbation. The practical implication for defenders is that configuration rotation degrades automated agent attackers, which is a cheap control to reason about.

  11. AI-Infra-Guard: Open-source security scanner for AI systems (opens in a new tab)

    Help Net Security ·Mirko Zorz ·fetched 9 Sep 2026, 07:38 UTC agreed3/3

    Why readAn open-source scanner you can point at Ollama, vLLM and ComfyUI deployments that checks them against 1,600+ CVEs and audits MCP servers and agent skills.

    Tencent's Zhuque Lab released AI-Infra-Guard, which fingerprints running AI services, matches them against more than 1,600 known CVEs, and inspects MCP servers and agent skills across 14 risk categories. It also runs jailbreak evaluations against a target model. Skill triage is done by asking an LLM whether a skill looks malicious, with that judgement scored against the public SkillTrustBench set, so treat its verdicts as triage rather than proof.

  12. AgentDrift: A Step-Labeled Benchmark of Injection-Hijacked LLM Agent Trajectories (opens in a new tab)

    arXiv cs.CR (AI) ·Asif Pinjari, Mithun Paul Saint-Germain ·fetched 9 Sep 2026, 11:36 UTC Research agreed3/3

    Why readA public corpus of 12,536 tool-call trajectories with all 71,024 steps labelled benign, injection point, hijacked or failed injection, which is what you need to build step-level rather than whole-trace injection detection.

    AgentDrift covers five agent domains and splits into 4,000 benign, 5,536 attacked, 1,500 failed-attack and 1,500 hard-negative trajectories, with attacked traces following three compliance patterns whose label strings follow a stated regular grammar. Failed attacks carry an injection the agent resisted and hard negatives carry legitimate content that looks like injection, so a detector cannot score well by flagging suspicious-looking observations. Existing guard models judge a trace as a whole; this lets you measure where an injection entered and which subsequent steps it corrupted.

  1. Uber’s driver-blocking algorithm draws nearly $1 billion Dutch privacy penalty (opens in a new tab)

    Compliance Week ·Neil Hodge ·fetched 9 Sep 2026, 23:38 UTC Must read agreed3/3

    Why readA 959.2 million dollar penalty for automated account termination is the largest concrete price yet attached to GDPR Article 22, and it lands on a decision pattern many firms run.

    The Dutch data protection authority fined Uber 959.2 million dollars over its use of automated decision-making to deactivate driver accounts on the basis of poor customer ratings. The action targets the automated nature of the adverse decision itself, not a breach or a data leak, which puts any algorithmic suspension or termination process in scope. Coverage so far is thin on the regulator's detailed reasoning, so expect the full decision text to matter more than the headline number.

  2. CRA Reporting Starts on 11 September: What Businesses Need To Know (opens in a new tab)

    Truesec ·Hjalmar Desmond ·fetched 9 Sep 2026, 15:38 UTC Must read agreed3/3

    Why readCRA incident reporting obligations start 11 September with a 24-hour early notification, 72-hour detail and one-month full report, and the triggers are not the same as NIS2.

    The Cyber Resilience Act's reporting regime commences 11 September, on a staged clock familiar from NIS2: initial notification within 24 hours, fuller detail within 72 hours, and a complete report within one month of the first notification. The CRA carries its own triggers, scope and product-specific requirements, so an existing NIS2 process is a starting point rather than a compliant answer. The practical consequence is escalation design, because teams cannot wait for a technical investigation to conclude before deciding whether an event is reportable.

  3. FCC Data Breach Reg Can't End-Run Congress, 6th Circ. Told (opens in a new tab)

    Google News: incidents · Law360 ·fetched 9 Sep 2026, 03:40 UTC agreed3/3

    Why readThe FCC's data breach notification rule is being argued in the Sixth Circuit on the ground that the agency exceeded what Congress authorised, which puts a live carrier reporting obligation at risk.

    Challengers told the Sixth Circuit that the FCC's data breach reporting regulation cannot be used to work around Congress. If the rule is struck or narrowed, telecom and VoIP providers lose one of their federal notification triggers and fall back on state regimes, so compliance teams tracking multi-jurisdiction breach clocks should watch the outcome. The item is docket reporting rather than analysis, so the reasoning to weigh will be in the opinion.

  4. New FBI cyber strategy promises increase in adversary disruptions (opens in a new tab)

    Cybersecurity Dive ·Eric Geller ·fetched 9 Sep 2026, 15:38 UTC agreed3/3

    Why readThe FBI is putting takedown operations on a standing footing instead of running them case by case, which changes what a victim organisation can expect when the bureau shows up.

    Cyber Division assistant director Brett Leatherman used the Billington summit to describe a four part strategy: investigate and attribute, engage victims faster and share usable information, deepen work with other agencies and the private sector, and build internal capability through hiring, training and tooling. The stated goal is moving disruption from ad hoc to steady state, on the view that even the recent tempo, which included the GRU router botnet, Chinese domains aimed at US critical infrastructure and AlphV, has not kept pace. For defenders the practical read is on the victim engagement and information sharing commitments, since those are the parts you can actually plan an incident response process around.

    Also covered byThe Record (opens in a new tab).

  5. Cops Play Hide and Seek About Using Spy Tech to Avoid Scrutiny and Bad PR (opens in a new tab)

    EFF Deeplinks ·Adam Schwartz ·fetched 9 Sep 2026, 19:40 UTC agreed2/3

    Why readDocuments the specific mechanisms police use to keep licence plate reader use out of the record, including instructing officers not to mention it during stops.

    The EFF sets out how agencies conceal use of automated licence plate readers, cell site simulators and facial recognition: officers are told not to reference ALPR hits during vehicle stops, and departments structure records so that use falls outside public records requests. The effect is that towns sign Flock and similar contracts with no public accounting of what the systems are used for, and defendants never learn what generated the stop. For anyone advising on surveillance procurement or transparency obligations, the value is in the concrete evasion patterns rather than the argument around them.

  6. Channel 5 Gave Hunter Biden a List of Its Subscribers’ Emails for Some Reason (opens in a new tab)

    404 Media ·Joseph Cox ·fetched 9 Sep 2026, 11:36 UTC agreed3/3

    Why readA clean, concrete example of consent scope failure: a subscriber list exported as a CSV and handed to a third party for a purpose nobody signed up for.

    Channel 5 confirmed it gave Hunter Biden a CSV of its email subscribers so he could promote a memecoin, saying it was to help him expand his audience. A privacy specialist told 404 Media that under the channel's own privacy notice and signup language, the transfer is likely unlawful where GDPR applies. The channel later said no mail has actually gone out to public subscribers, which does not cure the disclosure itself.

  7. First ‘Take It Down Act’ Sentencing Puts Man Behind Bars for 15 Years (opens in a new tab)

    404 Media ·Samantha Cole ·fetched 9 Sep 2026, 23:38 UTC agreed2/3

    Why readThe first sentence handed down under the Take It Down Act establishes what prosecutors are actually asking for, which is the reference point for anyone advising on synthetic imagery liability.

    James Strahler, 38, of Ohio received 15 years after investigators recovered more than 3,000 real and AI-generated abuse images, including over 700 he created and posted to a site dedicated to child sexual abuse material. He generated images of minors from his own community and paired the distribution with threats of violence against victims. As the first conviction and sentencing under the statute, it sets the opening enforcement benchmark rather than establishing any contested legal interpretation.

  1. Boston Scientific left nursing its bottom line after cyberattack (opens in a new tab)

    The Register Security ·fetched 9 Sep 2026, 07:38 UTC Must read agreed3/3

    Why readBoston Scientific told the SEC its August cyberattack will have a material impact and it now expects to miss both Q3 and full-year sales growth and adjusted EPS guidance.

    Unauthorized activity was detected on the network on 25 August, systems were taken offline, and order processing and shipping applications were disrupted worldwide. In a filing on Tuesday the company said the disruption is likely to be material and that it will probably miss the net sales growth and adjusted EPS guidance ranges it issued in July, though it expects to recover some revenue as the backlog clears. This is one of the cleaner recent examples of an intrusion converting directly into a guidance cut, and it is the number a board will ask about.

    Also covered bytikr.com (opens in a new tab),thestack.technology (opens in a new tab),qz.com (opens in a new tab),Investor's Business Daily (opens in a new tab).

  2. Electronic health record company says customer data stolen in breach (opens in a new tab)

    The Record ·fetched 9 Sep 2026, 19:40 UTC Must read agreed3/3

    Why readVeradigm told the SEC that an attacker used credentials taken from a vendor's environment to pull patient records, including Social Security numbers, through a Veradigm API.

    The electronic health records firm, which serves thousands of hospitals and physicians and reported $594 million in 2024 revenue, filed an 8-K on Tuesday describing a third-party compromise. An unauthorised party obtained credentials from the vendor's environment to a Veradigm API used to deliver services on behalf of customers, then downloaded personal data including Social Security numbers; Veradigm says no clinical data was involved and access was limited to a specific integration. It is a clean example of the machine-credential blast radius that healthcare boards keep being told about, now with a named filer and a date.

  3. Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC (opens in a new tab)

    The Hacker News ·The Hacker News ·fetched 9 Sep 2026, 03:40 UTC agreed3/3

    Why readBlockstream's Liquid sidechain lost around 4,000 BTC (roughly $320M) to an Elements bug on September 6; 3,400 BTC came back the next day and the network is still paused.

    Attackers claiming to be white hats drained about 4,000 bitcoin from the Liquid Federation wallet on September 6 via a bug in Elements, and returned 3,400 BTC to a federation address at 16:09 UTC on September 7, roughly 85 percent of the take. The remaining 598.5 BTC is change from that same transaction sitting at the attacker's address as of September 8, and neither Blockstream nor Liquid has said whether it is covered by an agreement. Liquid remains paused, so L-BTC holders cannot redeem for bitcoin, which is the part any exposed counterparty has to answer for.

    Also covered byTechCrunch Security (opens in a new tab).

  4. Grindr settles privacy lawsuit tied to disclosure of users’ HIV statuses for $35 million (opens in a new tab)

    The Record ·fetched 9 Sep 2026, 19:40 UTC agreed3/3

    Why readGrindr will pay £26 million ($35.2 million) over UK claims that HIV status and other sensitive user data were passed to advertisers, disclosed in an SEC filing.

    A UK lawsuit brought in April 2024 over pre-2020 ad-tech data sharing, from the period when Grindr was owned by Chinese firm Kuntun, settles for £26 million with no admission of liability. Payment is split into two lump sums, due end of December and end of March, per a regulatory filing signed 4 September. The figure gives a concrete price tag for special-category data flowing into advertising pipelines, which is the number to cite when arguing marketing tag governance to an executive team.

  5. San Francisco Orders Meta to Stop ‘Allowing’ AI Child Abuse Ads (opens in a new tab)

    WIRED Security ·Matt Burgess ·fetched 9 Sep 2026, 23:38 UTC agreed2/2

    Why readA named regulator is now demanding Meta explain how 350 plus paid ads containing AI-generated child abuse material cleared its review, which is the enforcement shape any ad-carrying platform should expect.

    San Francisco's city attorney sent Meta a cease-and-desist over paid advertisements that animated still images of minors, some confirmed as real individuals, into sexual video clips. The ads, surfaced by the Tech Transparency Project and reported by WIRED, ran across Facebook, Instagram and Threads, reached more than 29,000 accounts in the EU, and drove clicks to nudify and image generation apps. Identical creatives were uploaded repeatedly, which is the detail the letter presses on: the failure was in review controls, not a single missed item.

  6. Anne Arundel Medical Center cyberattack delays patient care (opens in a new tab)

    Google News: incidents · WBAL-TV ·fetched 9 Sep 2026, 23:38 UTC agreed3/3

    Why readA named US hospital is diverting or delaying patient care after a cyberattack, the sector's recurring board-level question.

    Anne Arundel Medical Center is reporting delays to patient care following a cyberattack, per WBAL-TV. The item carries no attribution, malware detail or timeline beyond the care impact. For health system leaders it is another datapoint on clinical disruption as the measurable consequence of an intrusion.

  7. CIA official touts agency’s Cyber Mission Center in capture of Venezuela’s Maduro (opens in a new tab)

    The Record ·fetched 9 Sep 2026, 03:40 UTC agreed2/3

    Why readA rare on-the-record account of cyber collection driving a kinetic operation, from the CIA deputy director naming the unit that did it.

    Speaking at the Billington summit, Deputy Director Michael Ellis credited the CIA's Cyber Mission Center with building the intelligence picture behind Operation Absolute Resolve, the January seizure of Nicolas Maduro and his wife from a bunker in Caracas. His claim is that cyber-enabled collection is what let special forces fix the target precisely enough to apprehend him within four minutes of landing. Nothing here is technical, but the public acknowledgement of a named cyber unit in targeting for a snatch operation is a data point on how state cyber capability is now framed and justified.

  8. Luminis Health Working to Restore Systems After Cyberattack (opens in a new tab)

    Google News: incidents · The HIPAA Journal ·fetched 9 Sep 2026, 03:40 UTC agreed3/3

    Why readAnother US health system is running degraded while it rebuilds after a cyberattack, which is the operational and HIPAA notification picture peers benchmark against.

    Luminis Health is restoring systems following a cyberattack. Reporting so far covers the recovery effort rather than the intrusion, with no actor, initial access vector or data impact stated. Useful as sector context for healthcare risk owners and for anyone tracking the continuing cadence of provider outages.

  9. Risky Bulletin: Ukraine's top prosecutor resigns amid scam call center scandal (opens in a new tab)

    Risky Business News ·fetched 9 Sep 2026, 07:38 UTC agreed2/3

    Why readFour named events in one pass, including a prosecutor general losing his job over a scam call centre operation.

    Ukraine's top prosecutor resigned amid a scandal involving scam call centres, which bears directly on how seriously the country's own cybercrime enforcement can be read. The same bulletin covers US accusations that Chinese AI firms are running industrial-scale model distillation, a cyberattack disrupting medical practices in Luxembourg, and the Liquid Network attacker returning part of the stolen Bitcoin while retaining roughly fifty million dollars. It is a rundown rather than an investigation, so use it as a pointer list.

  10. Springfield schools closed as cyberattack locks access to student medical records (opens in a new tab)

    Google News: incidents · WWLP ·fetched 9 Sep 2026, 19:40 UTC agreed2/3

    Why readA school district shut its doors because it lost access to student health records, which is the kind of concrete downstream impact that moves a board conversation.

    Springfield closed schools after a cyberattack cut access to student medical records, making the availability loss, not the data exposure, the operational trigger. Districts hold immunisation and medication data that they are legally required to consult before admitting students, so losing the record system forces closure in a way that losing email does not. Reporting is thin at this stage and no actor or intrusion vector has been named.

  11. New Mexico’s trial against Facebook for alleged role in Cambridge Analytica data breach begins (opens in a new tab)

    Google News: incidents · Source New Mexico ·fetched 9 Sep 2026, 19:40 UTC agreed2/3

    Why readEight years after the disclosure, a state attorney general is actually putting the Cambridge Analytica data harvesting in front of a jury rather than settling it.

    New Mexico's civil trial against Facebook over its alleged role in the Cambridge Analytica harvesting of user data has opened. Most state and federal actions arising from the 2018 disclosure ended in settlements, so a trial produces discovery and testimony on platform data sharing practices that settlements have kept out of the record. Coverage so far is a headline; the substance will come from what is entered into evidence.

Unverified claims posted by extortion groups on their own leak sites, not confirmed breaches. Listing is the group's assertion; many named organisations have not disclosed an incident, and some entries are false or recycled. Leak sites are never linked from here.

Claimed victimGroup SectorCountry Seen
PharmaEssentia Corporation thegentlemen Healthcare TW 9 Sep 2026 press coverage (opens in a new tab)
Air Canada thegentlemen Transportation CA 9 Sep 2026 press coverage (opens in a new tab)
mo***al AuditTeam - DE 9 Sep 2026
amorsaude.com.br lockbit5 Healthcare BR 9 Sep 2026
Aqualogus Panzer Agriculture and Food Production - 9 Sep 2026
Mitsuwa Trading Co., Ltd qilin Retail & E-Commerce JP 9 Sep 2026
cullottalaw.com incransom Professional Services US 9 Sep 2026
gardensalive.com, bitsandpieces.com, iselinursery.local, weeksroses.org, esm.local embargo Agriculture and Food Production US 9 Sep 2026
dg***kr AuditTeam - KR 9 Sep 2026
go***et AuditTeam Technology KR 9 Sep 2026
kr***rg AuditTeam - AR 9 Sep 2026
Logar Network Solutions Vexy Ransomware Technology BR 9 Sep 2026
https://mediengruppethiel.de/ incransom - DE 9 Sep 2026
RelyComply AML Platform direwolf Financial Services GB 9 Sep 2026
Kyodo USA akira Manufacturing US 9 Sep 2026
Bosnia and Herzegovina Mine Action Center emperador Government & Defense BA 9 Sep 2026
Specchem LLC Dark Project Manufacturing US 9 Sep 2026
Jet Specialty qilin Manufacturing US 9 Sep 2026
Universal Starch-Chem Allied Ltd emperador Manufacturing IN 9 Sep 2026
BAYMER emperador Manufacturing - 9 Sep 2026
Technology Dynamics Storm Technology US 9 Sep 2026
Flexmaster Storm Manufacturing CA 9 Sep 2026
Lowerys Storm Retail & E-Commerce CA 9 Sep 2026
Melitron Storm Manufacturing CA 9 Sep 2026
Gellibrand Support Services anubis Professional Services - 9 Sep 2026
How this edition was made
Candidates fetched
4613
New after deduplication
720
Kept by the panel
158
Published
141
Generated
9 Sep 2026, 23:38 UTC