← Back to Blog

Security News — 2 September 2026

A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 11 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 2 September 2026 · 33 items.

Government & Critical Vulnerability Advisories

CVEDatabase - Critical CVEs01 Sep

CVE-2026-84480 — CRITICAL (CVSS 9.3)

CVSS 9.3 CRITICAL WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can…

Read at source →
CVEDatabase - Critical CVEs01 Sep

CVE-2026-84479 — CRITICAL (CVSS 9.3)

CVSS 9.3 CRITICAL WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a…

Read at source →
CVEDatabase - Recent CVEs01 Sep

CVE-2026-84483 — MEDIUM (CVSS 6.9)

CVSS 6.9 MEDIUM WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens using the public site URL and current time. Attacke…

Read at source →
CVEDatabase - Recent CVEs01 Sep

CVE-2026-84482 — HIGH (CVSS 8.7)

CVSS 8.7 HIGH WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers can forge requests from siblin…

Read at source →
CVEDatabase - Recent CVEs01 Sep

CVE-2026-84481 — MEDIUM (CVSS 6.9)

CVSS 6.9 MEDIUM WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors. Attackers can send an un…

Read at source →
CVEDatabase - Recent CVEs01 Sep

CVE-2026-84478 — MEDIUM (CVSS 6.9)

CVSS 6.9 MEDIUM WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying directory traversal sequences in the code paramete…

Read at source →
CVEDatabase - Critical CVEs01 Sep

CVE-2023-54391 — CRITICAL (CVSS 9.3)

CVSS 9.3 CRITICAL Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user wit…

Read at source →
CVEDatabase - Critical CVEs01 Sep

CVE-2026-82954 — HIGH (CVSS 8.6)

CVSS 8.6 HIGH A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of the ar…

Read at source →
CISA Cybersecurity Advisories01 Sep

Rockwell Automation RSLinx Classic

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation RSLinx Classic are affected: RSLinx Cl…

Read at source →
CISA Cybersecurity Advisories01 Sep

Rockwell Automation Historian ME

View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution. The following versions of Rockwell Automation Historian ME are affe…

Read at source →
CISA Cybersecurity Advisories01 Sep

Rockwell Automation Logix Platform

View CSAF Summary The following versions of Rockwell Automation Logix Platform are affected: ControlLogix 5580 <=V33, V34.011-V34.014, V35.011-V35.013, V36.011-V36.012 (CVE-2026-9637, CVE-2026-9637, CVE-2026-9637, CVE-2026-9637) CompactLog…

Read at source →

Primary Threat Research & Vendor Intelligence

Independent Investigative Journalism & Breaking News

Krebs on Security01 Sep

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are availab…

Read at source →

Blue Team, Incident Response & Detection Engineering

TrustedSec Blog01 Sep

waf-fu, or Some Log Replay Nonsense

<p>AWS WAF logs are keeping receipts, including your session tokens. In this blog, we walk through the risk of default WAF logging configurations and the tool built to pull, analyze, and replay what gets left behind.</p>

Read at source →

Security Executive, Architecture & Policy

Schneier on Security01 Sep

What’s the Scam?

To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent people from subscribing addresses other than their own. Star…

Read at source →
Schneier on Security01 Sep

Leaked Russian Cyber-Operations Training Materials

This is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptogra…

Read at source →
Schneier on Security01 Sep

Rewiring Democracy Series on The Renovator

Nathan E. Sanders and I are writing a series of essays on real-world examples of democratic technologies for The Renovator . I haven’t been posting the full text on the blog because they’re a bit long, but here are links. Part 1 is about t…

Read at source →
← All blog posts