📰 DAILY THREAT BRIEFING
Tuesday, September 1, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of September 1, 2026.

  1. Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
    — SANS ISC

    Introduction
  2. Anthropic Users Hit by Infostealer Attacks, Session Thefts
    — Dark Reading

    A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of us…
  3. Cronos blockchain restarts after $74 million Tectonic exploit
    — Bleeping Computer

    The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform…
  4. 'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks
    — Dark Reading

    The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' netwo…
  5. The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)
    — SANS ISC

    One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure…
  6. Microsoft warns of TerminalFix attacks deploying reverse tunnels
    — Bleeping Computer

    A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicio…
  7. AI Model Rules Are Not Security Controls
    — Dark Reading

    OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.
  8. North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
    — The Hacker News

    Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities …
  9. Microsoft Exchange Online outage causes email failures, auth issues
    — Bleeping Computer

    Microsoft is investigating a widespread service issue causing authentication issues, email delays and failures, and various other issues for…
  10. ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More
    — The Hacker News

    The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted syst…
  11. ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
    — The Hacker News

    The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application,…
  12. Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
    — Unit 42

    Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The…

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (12569 in last 30 days).
Critical: 3 · High: 11 · Medium: 4 · Low: 2. View full dashboard →

  1. CVE-2026-83524
    — CVSS 9.9 (CRITICAL)

    A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to 20260704. This impacts the function exec of the file /xgatev1/system/datetime.php of the component Sy…
  2. CVE-2026-82971
    — CVSS 10.0 (CRITICAL)

    A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command i…
  3. CVE-2026-82957
    — CVSS 7.3 (HIGH)

    A vulnerability was found in hyperledger-firefly firefly up to 1.4.0. The impacted element is the function ValidateOptions of the file internal/events/webhooks/webhooks.go of the component Webhook Subscription. Performin…
  4. CVE-2026-82954
    — CVSS 9.9 (CRITICAL)

    A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the file packages/server/src/utils/traefik/application.ts of the component Settings. The manipulation of t…
  5. CVE-2026-82922
    — CVSS 7.3 (HIGH)

    A security vulnerability has been detected in ShopEx ECShop up to 2.5.1. This vulnerability affects the function flow_update_cart of the file /flow.php?step=update_cart. The manipulation of the argument rec_id leads to s…
  6. CVE-2026-82921
    — CVSS 7.3 (HIGH)

    A weakness has been identified in ShopEx ECShop up to 2.5.1. This affects the function check_img_type of the file admin/pack.php. Executing a manipulation of the argument pack_img can lead to unrestricted upload. It is p…
  7. CVE-2026-82882
    — CVSS 8.8 (HIGH)

    Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to retrieve admin API tokens. Attackers with any authenticated account can que…
  8. CVE-2026-82397
    — CVSS 7.5 (HIGH)

    Tornado is a Python web framework and asynchronous networking library. Prior to 6.5.8, Tornado parses application/x-www-form-urlencoded request bodies with urllib.parse.parse_qs in tornado/escape.py without passing max_n…
  9. CVE-2026-82396
    — CVSS 5.4 (MEDIUM)

    Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.25 and 3.0.8, src/Sulu/Bundle/MediaBundle/Controller/MediaStreamController.php allows the /media/{id}/download/{s…
  10. CVE-2026-82393
    — CVSS 7.5 (HIGH)

    pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash ch…
  11. CVE-2026-77353
    — CVSS 4.6 (MEDIUM)

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos allows authenticated users to inject arbitrary iCalendar properties and events into their exported .ics feed by embedd…
  12. CVE-2026-77352
    — CVSS 4.3 (MEDIUM)

    Wallos is an open-source, self-hostable personal subscription tracker. From version 2.0.0 to before version 5.0.0, any authenticated Wallos user (no admin rights required) can make the server open arbitrary outbound SMTP…
  13. CVE-2026-77351
    — CVSS 3.5 (LOW)

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, Wallos lets any authenticated user store an arbitrary SMTP host — including private and cloud-metadata IP addresses — in …
  14. CVE-2026-77348
    — CVSS 8.2 (HIGH)

    Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc, "SSRF via HTTP Proxy Environment Variable") hardened endpoints/logos/search.…
  15. CVE-2026-83596
    — CVSS 8.8 (HIGH)

    A flaw was found in WebKitGTK. Processing malicious web content can cause memory corruption due to improper memory handling.
  16. CVE-2026-82919
    — CVSS 7.3 (HIGH)

    A vulnerability was identified in cu silicon up to 0.1.5. Affected by this vulnerability is the function create_app of the file views.py of the component edit Endpoint. Such manipulation leads to missing authentication. …
  17. CVE-2026-82914
    — CVSS 7.3 (HIGH)

    A security flaw has been discovered in kishan0725 Hospital-Management-System 1.0. This vulnerability affects unknown code of the file /search.php. The manipulation of the argument Contact results in sql injection. It is …
  18. CVE-2026-82909
    — CVSS 4.3 (MEDIUM)

    A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler. Executing a manipula…
  19. CVE-2026-82908
    — CVSS 8.8 (HIGH)

    A vulnerability was found in MSI Dragon Center up to 2.0.155.0. Affected by this vulnerability is the function MmioWritePath in the library NTIOLib_X64.sys of the component MMIO Write Path Handler. Performing a manipulat…
  20. CVE-2026-82906
    — CVSS 3.7 (LOW)

    A flaw has been found in sdcb chats up to 1.12.0. This impacts the function DownloadPublic of the file src/BE/web/Controllers/Chats/Files/FileController.cs of the component Signed File Download Endpoint. This manipulatio…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · September 1, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com