📰 DAILY THREAT BRIEFING
Wednesday, September 2, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of September 2, 2026.

  1. ISC Stormcast For Wednesday, September 2nd, 2026 https://isc.sans.edu/podcastdetail/10078, (Wed, Sep 2nd)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  2. Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
    — Dark Reading

    Threat actors exploited commodity in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credenti…
  3. FBI Probes Service Selling 153M+ Drivers Licenses
    — Krebs on Security

    A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from peop…
  4. Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
    — SANS ISC

    Introduction
  5. Attackers Pounce on Critical Artifactory Flaw Following Disclosure
    — Dark Reading

    CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected…
  6. Stronger Security Drives Ransomware Groups to Recruit From Within
    — Dark Reading

    Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cos…
  7. Hackers abuse Faronics Deploy admin tool to install ScreenConnect
    — Bleeping Computer

    Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim co…
  8. Aesto Health says data breach affects over 9.5 million patients
    — Bleeping Computer

    Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. […]
  9. Critical Langflow flaw exploited to steal OpenAI and AWS keys
    — Bleeping Computer

    Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework fo…
  10. Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
    — The Hacker News

    Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, accordi…
  11. Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
    — The Hacker News

    Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Bre…
  12. 13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
    — The Hacker News

    Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript …

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (12959 in last 30 days).
Critical: 2 · High: 10 · Medium: 6 · Low: 2. View full dashboard →

  1. CVE-2026-9055
    — CVSS 9.8 (CRITICAL)

    The Booking for Appointments and Events Calendar – Amelia (Premium) plugin for WordPress is vulnerable to Privilege Escalation in versions 8.0 – 9.6.2. This is due to insufficient validation of the attacker-controlled …
  2. CVE-2025-46418
    — CVSS 7.6 (HIGH)

    Westermo WeOS 5.x starting from 5.24 allows OS command injection via a media definition.
  3. CVE-2024-35585
    — CVSS 8.6 (HIGH)

    Oxford Nanopore MinKNOW before 24.06 relies on a client's source IP address for authentication.
  4. CVE-2026-3851
    — CVSS 6.4 (MEDIUM)

    The Divi theme for WordPress is vulnerable to Stored Cross-Site Scripting via the Dynamic Content feature's legacy JSON format in all versions up to, and including, 4.27.6. This is due to two compounding flaws: (1) the s…
  5. CVE-2026-84442
    — CVSS 4.4 (MEDIUM)

    A vulnerability was identified in MapQuest Get Directions App 10.16.1 on Android. This vulnerability affects the function getDataColumn of the file ExpoShareIntentModule.kt of the component com.mapquest.android.ace. The …
  6. CVE-2026-84441
    — CVSS 7.3 (HIGH)

    A security vulnerability has been detected in Piwigo up to 16.3.0. Affected by this issue is some unknown functionality of the file i.php of the component Image Derivative Handler. The manipulation leads to path traversa…
  7. CVE-2026-14982
    — CVSS 8.1 (HIGH)

    The WP File Download plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the delete function in all versions. This makes it possible for authenticated attackers, with…
  8. CVE-2026-14957
    — CVSS 7.5 (HIGH)

    In FIPS mode, Libreswan's add_decoded_cert() function calls CERT_ExtractPublicKey() and asserts that the result is not NULL. However, CERT_ExtractPublicKey() returns NULL when public key extraction fails, for example if …
  9. CVE-2026-84715
    — CVSS 8.8 (HIGH)

    FeatherPanel versions before 1.3.7.10 fail to validate permissions in the SubuserController updateSubuser handler, allowing authenticated subusers to modify their own permission records. A subuser with minimal permission…
  10. CVE-2026-84485
    — CVSS 7.5 (HIGH)

    APITable through 1.13.0-beta.1 exposes the internal organization loadOrSearch endpoint without authentication, allowing unauthenticated attackers to retrieve member names, email addresses, and team hierarchy. Attackers c…
  11. CVE-2026-84484
    — CVSS 7.5 (HIGH)

    ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP …
  12. CVE-2026-84438
    — CVSS 3.5 (LOW)

    A vulnerability was determined in OpenCart 4.1.0.3/4.1.0.4. This affects an unknown function of the file catalog/controller/account/edit.php of the component Autocomplete Workflow. This manipulation of the argument first…
  13. CVE-2026-84437
    — CVSS 3.5 (LOW)

    A vulnerability was found in OpenCart 4.1.0.3/4.1.0.4. The impacted element is an unknown function of the file catalog/controller/account/address.php of the component Autocomplete Workflow. The manipulation of the argume…
  14. CVE-2026-84431
    — CVSS 4.4 (MEDIUM)

    A vulnerability was detected in AirAsia MOVE App up to 12.47.1 on Android. This issue affects the function com.airasia.core.utils.RealPathUtil.getRealPath of the component com.airasia.mobile. Performing a manipulation of…
  15. CVE-2026-82968
    — CVSS 6.4 (MEDIUM)

    A flaw was found in the first-broker-login flow of the Keycloak identity management service. When a user links a social identity provider account to their local account, the verification proof generated is not strictly b…
  16. CVE-2026-84702
    — CVSS 7.5 (HIGH)

    facefusion through 3.6.1 fails to normalize job identifiers in get_job_file_name, allowing attackers to write files outside the jobs directory. Attackers can supply traversal sequences in the job identifier parameter thr…
  17. CVE-2026-84701
    — CVSS 5.4 (MEDIUM)

    NocoBase fails to sanitize rich text field values in the read renderer, allowing users with create permissions to store malicious HTML with event handlers. Attackers can write arbitrary markup through the collection API …
  18. CVE-2026-84700
    — CVSS 8.6 (HIGH)

    PikiwiDB (Pika) v3.5.7 exposes an internal protobuf replication server on a port derived from the client port plus 2000 (e.g. 11221 when the default client port 9221 is used) that does not authenticate incoming requests.…
  19. CVE-2026-84699
    — CVSS 9.1 (CRITICAL)

    Team Password Manager before 14.184.308 fails to enforce authentication requirements in the local account password reset flow. Unauthenticated attackers can reset local account passwords and authenticate as those users t…
  20. CVE-2026-84698
    — CVSS 6.5 (MEDIUM)

    PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_bench command that writes a four-byte block number into a user-supplied sized allocation. Attackers can invoke sd_bench with a block size below four b…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · September 2, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com