← Back to Blog
Security News
Security News — 5 September 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 5 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 5 September 2026 · 15 items.
Government & Critical Vulnerability Advisories
CVEDatabase - Recent CVEs05 Sep
CVSS 2.0 LOW A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The at…
Read at source →
CVEDatabase - Recent CVEs05 Sep
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Read at source →
CVEDatabase - Recent CVEs05 Sep
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Read at source →
CVEDatabase - Critical CVEs05 Sep
CVSS 9.4 CRITICAL A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The…
Read at source →
CVEDatabase - Critical CVEs05 Sep
CVSS 9.4 CRITICAL A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in o…
Read at source →
CVEDatabase - Recent CVEs05 Sep
CVSS 9.2 CRITICAL RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. E…
Read at source →
CVEDatabase - Critical CVEs05 Sep
CVSS 9.3 CRITICAL WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated callers…
Read at source →
CVEDatabase - Critical CVEs05 Sep
CVSS 9.3 CRITICAL WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath paramet…
Read at source →
Independent Investigative Journalism & Breaking News
The Hacker News05 Sep
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory…
Read at source →
The Hacker News05 Sep
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environ…
Read at source →
The Hacker News05 Sep
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-202…
Read at source →
BleepingComputer05 Sep
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]
Read at source →
The Hacker News05 Sep
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone n…
Read at source →
BleepingComputer05 Sep
OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security…
Read at source →
Blue Team, Incident Response & Detection Engineering
SANS Internet Storm Center (Handler Diary)05 Sep
Read at source →