← Back to Blog
Security News
Security News — 1 September 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 9 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 1 September 2026 · 27 items.
Government & Critical Vulnerability Advisories
CVEDatabase - Critical CVEs31 Aug
CVSS 8.6 HIGH A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.php of the component System…
Read at source →
CVEDatabase - Critical CVEs31 Aug
CVSS 9.3 CRITICAL A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command in…
Read at source →
CVEDatabase - Recent CVEs31 Aug
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accidental usage.
Read at source →
CVEDatabase - Critical CVEs31 Aug
CVSS 8.6 HIGH A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the ar…
Read at source →
CVEDatabase - Recent CVEs31 Aug
CVSS 5.5 MEDIUM A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Subscription. Performing a…
Read at source →
CVEDatabase - Recent CVEs31 Aug
CVSS 5.5 MEDIUM A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flow_update_cart of the file /flow.php?step=update_cart. The manipulation of the argument rec_id leads to sql…
Read at source →
CVEDatabase - Recent CVEs31 Aug
CVSS 5.5 MEDIUM A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.php. Executing a manipulation of the argument pack_img can lead to unrestricted upload. It is poss…
Read at source →
CVEDatabase - Critical CVEs31 Aug
CVSS 8.5 HIGH A vulnerability has been found in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected by this issue is some unknown functionality of the file /cgi-bin/usb_device.cgi of the component CGI Handler. Such man…
Read at source →
CISA Current Activity31 Aug
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability CVE-2026-82078…
Read at source →
Primary Threat Research & Vendor Intelligence
Palo Alto Unit 4231 Aug
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on…
Read at source →
Independent Investigative Journalism & Breaking News
Dark Reading12 Nov
Read at source →
Dark Reading08 Oct
Read at source →
Dark Reading31 Aug
A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
Read at source →
BleepingComputer31 Aug
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. [...]
Read at source →
Dark Reading31 Aug
The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.
Read at source →
BleepingComputer31 Aug
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]
Read at source →
The Hacker News31 Aug
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected wor…
Read at source →
BleepingComputer31 Aug
Microsoft is investigating a widespread service issue causing authentication issues, email delays and failures, and various other issues for Exchange Online customers. [...]
Read at source →
BleepingComputer31 Aug
ChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks. [...]
Read at source →
The Hacker News31 Aug
The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even…
Read at source →
The Hacker News31 Aug
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their anti…
Read at source →
The Hacker News31 Aug
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Secur…
Read at source →
Blue Team, Incident Response & Detection Engineering
SANS Internet Storm Center (Handler Diary)01 Sep
Introduction
Read at source →
SANS Internet Storm Center (Handler Diary)31 Aug
One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session &#;x2…
Read at source →
SANS Internet Storm Center (Handler Diary)31 Aug
Read at source →
Security Executive, Architecture & Policy
Schneier on Security31 Aug
It sure seems like it. The stores confirmed to be affected include Fort Irwin , Calif.; F.E. Warren Air Force Base , Wyo.; Fort Huachuca , Ariz.; Naval Station Newport , R.I.; Columbus Air Force Base , Miss.; and Travis Air Force Base , Ca…
Read at source →
Schneier on Security31 Aug
Someone hid AI instructions into a legal filing. Alternate link .
Read at source →