A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 11 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 3 September 2026 · 27 items.
Government & Critical Vulnerability Advisories
CVEDatabase - Recent CVEs03 Sep
CVSS 2.1 LOW A weakness has been identified in RightNow-AI OpenFang up to 0.6.9. This vulnerability affects the function shell_exec of the file crates/openfang-runtime/src/tool_runner.rs. This manipulation causes uncontrolled memory alloca…
Read at source →
CVEDatabase - Recent CVEs03 Sep
CVSS 2.1 LOW A vulnerability was identified in simular-ai Agent-S up to 0.3.2. Affected by this issue is some unknown functionality of the file grounding.py of the component Model-generated GUI Action Execution Workflow. The manipulation l…
Read at source →
CVEDatabase - Recent CVEs03 Sep
CVSS 5.5 MEDIUM A vulnerability was determined in simular-ai Agent-S up to 0.3.2. Affected by this vulnerability is the function ImageData of the file gui_agents/s1/utils/ocr_server.py of the component OCR HTTP API. Executing a manipulatio…
Read at source →
CVEDatabase - Recent CVEs03 Sep
CVSS 2.1 LOW A vulnerability has been found in simular-ai Agent-S 0.3.1/0.3.2. This impacts an unknown function of the file code_agent.py of the component CodeAgent. Such manipulation leads to denial of service. The attack can be launched…
Read at source →
CVEDatabase - Critical CVEs02 Sep
CVSS 9.1 CRITICAL A flaw was found in submariner. In cert-auth mode, the connection configuration is built using free-form strings from the Custom Resource Definition (CRD) without proper validation. A malicious cluster can exploit this by…
Read at source →
CVEDatabase - Critical CVEs02 Sep
CVSS 6.4 MEDIUM · Vendor: vmware SerializingHttpMessageConverter deserializes the body of incoming HTTP requests with a raw java.io.ObjectInputStream and no class filtering. Any request with Content-Type application/x-java-serialized-objec…
Read at source →
CVEDatabase - Critical CVEs02 Sep
CVSS 5.6 MEDIUM · Vendor: broadcom Applications that deserialize execution contexts with Jackson2ExecutionContextStringSerializer are vulnerable to a deserialization attack if they use an untrusted data source for the job repository. The J…
Read at source →
CISA Current Activity02 Sep
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability CVE-2026-48710 Kludex Starlette HTTP Requ…
Read at source →
CISA Cybersecurity Advisories02 Sep
Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational t…
Read at source →
Independent Investigative Journalism & Breaking News
The Hacker News03 Sep
The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0day p…
Read at source →
The Hacker News03 Sep
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows -…
Read at source →
Dark Reading02 Sep
New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.
Read at source →
BleepingComputer02 Sep
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]
Read at source →
Dark Reading02 Sep
The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.
Read at source →
Dark Reading02 Sep
Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.
Read at source →
BleepingComputer02 Sep
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. [...]
Read at source →
The Hacker News02 Sep
Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. "The Fairwind Progr…
Read at source →
Dark Reading02 Sep
The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.
Read at source →
The Hacker News02 Sep
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises…
Read at source →
BleepingComputer02 Sep
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]
Read at source →
BleepingComputer02 Sep
Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and res…
Read at source →