← Back to Blog
Security News
Security News — 4 September 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 11 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 4 September 2026 · 30 items.
Government & Critical Vulnerability Advisories
CVEDatabase - Recent CVEs04 Sep
CVSS 8.3 HIGH ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying crafted…
Read at source →
CVEDatabase - Recent CVEs04 Sep
CVSS 7.1 HIGH PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to crash the autopilot process. Attackers can invoke 'para…
Read at source →
CVEDatabase - Recent CVEs04 Sep
CVSS 6.0 MEDIUM PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race condition between task spawning and object deletion. Attackers can trigger the calibration process via sh…
Read at source →
CVEDatabase - Recent CVEs04 Sep
CVSS 8.5 HIGH Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 files w…
Read at source →
CVEDatabase - Critical CVEs04 Sep
CVSS 6.8 MEDIUM · Vendor: vmware Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spring Cloud Config Server's /monitor endpoint are not validated. This issue affects Sprin…
Read at source →
CVEDatabase - Critical CVEs04 Sep
CVSS 9.8 CRITICAL · Vendor: IBM IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulnerable to SQL injection. An unauthenticated attacker can execute arbitrary SQL statements and leve…
Read at source →
CVEDatabase - Critical CVEs04 Sep
CVSS 9.3 CRITICAL SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers can upload audio files with shel…
Read at source →
CVEDatabase - Critical CVEs04 Sep
CVSS 9.3 CRITICAL FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers can…
Read at source →
CISA Current Activity04 Sep
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability This type of vulnerability is a frequent a…
Read at source →
Primary Threat Research & Vendor Intelligence
Microsoft Security Blog04 Sep
As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models. The post How to secure edge AI in customer-owned…
Read at source →
Independent Investigative Journalism & Breaking News
BleepingComputer04 Sep
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses. [...]
Read at source →
Dark Reading04 Sep
Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but the situation will become more urgent very soon.
Read at source →
The Hacker News04 Sep
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the att…
Read at source →
BleepingComputer04 Sep
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]
Read at source →
The Hacker News04 Sep
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score…
Read at source →
The Hacker News04 Sep
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The atta…
Read at source →
BleepingComputer04 Sep
Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. [...]
Read at source →
BleepingComputer04 Sep
Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, re…
Read at source →
Dark Reading04 Sep
A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.
Read at source →
Dark Reading04 Sep
As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.
Read at source →
The Hacker News04 Sep
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type…
Read at source →
Blue Team, Incident Response & Detection Engineering
SANS Internet Storm Center (Handler Diary)04 Sep
Read at source →
Elastic Security Labs04 Sep
Getting data into a security platform is always easy; getting it back out is where vendors add cost, extra tooling, and latency, and it is the part of the evaluation most teams overlook.
Read at source →
Security Executive, Architecture & Policy
Schneier on Security04 Sep
Looks tasty . As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
Read at source →
Daniel Miessler04 Sep
A charcoal sketch of a student straining in a squat under a loaded barbell while a purple AI figure spots him with both hands held just off the bar/images/socratic-ai.webp/images/socratic-ai.webp I've been thinking about what AI should loo…
Read at source →
Daniel Miessler04 Sep
A sienna sketch of a man squatting under a giant open book he is lifting overhead, while a purple robot arm on a desk hands a striped summary sheet to a faint gray figure/images/cliffs-notes-for-everything.webp/images/cliffs-notes-for-ever…
Read at source →
Schneier on Security04 Sep
It won’t work : My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which th…
Read at source →
Schneier on Security04 Sep
It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia…
Read at source →
Schneier on Security04 Sep
We cannot forget that AI coding agents are not yet trustworthy : Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-fu…
Read at source →
Daniel Miessler04 Sep
A lone writer in warm sienna works at a desk on top of a purple machine that crushes his pages into tiny slips for a crowd below staring at their phones, while one person in sienna stands apart reading a full page/images/peak-human-readers…
Read at source →