← Back to Blog
Security News
Security News — 11 September 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 3 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 11 September 2026 · 6 items.
Government & Critical Vulnerability Advisories
CVEDatabase - Recent CVEs11 Sep
CVSS 2.4 LOW Flextype CMS versions 0.9.9 through 1.0.0-alpha.3 fail to HTML-escape plugin directory names in the dependency error page rendered by getValidPluginsDependencies(). Attackers with write access to the plugins directory can crea…
Read at source →
CVEDatabase - Recent CVEs11 Sep
CVSS 4.2 MEDIUM The nscd service in the GNU C Library 2.3.4 onwards may crash due to a stack overflow when a malicious DNS server returns too large a response for a DNS query, resulting in degraded DNS resolution for the system. Exploitati…
Read at source →
CVEDatabase - Recent CVEs11 Sep
CVSS 4.4 MEDIUM A flaw was found in GStreamer's gst-plugins-good isomp4 plugin. When processing a specially crafted MP4 or MOV file containing CEA-608 closed-caption data, an integer overflow in 32-bit unsigned arithmetic can bypass a boun…
Read at source →
CVEDatabase - Recent CVEs11 Sep
CVSS 7.1 HIGH strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control in the eap-ttls and eap-peap plugins because there can be a missing or mismatched inner EAP identity.
Read at source →
Independent Investigative Journalism & Breaking News
Dark Reading11 Sep
The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.
Read at source →
Blue Team, Incident Response & Detection Engineering
SANS Internet Storm Center (Handler Diary)11 Sep
Read at source →