HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of September 2, 2026.
-
FBI Probes Service Selling 153M+ Drivers Licenses
— Krebs on Security
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from peop… -
Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
— SANS ISC
Introduction -
Attackers Pounce on Critical Artifactory Flaw Following Disclosure
— Dark Reading
CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected… -
Stronger Security Drives Ransomware Groups to Recruit From Within
— Dark Reading
Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cos… -
Hackers abuse Faronics Deploy admin tool to install ScreenConnect
— Bleeping Computer
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim co… -
Critical Langflow Flaw Exploited as Attacks on AI Platform Rise
— Dark Reading
The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention fr… -
Aesto Health says data breach affects over 9.5 million patients
— Bleeping Computer
Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. […] -
Critical Langflow flaw exploited to steal OpenAI and AWS keys
— Bleeping Computer
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework fo… -
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
— The Hacker News
Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, accordi… -
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
— The Hacker News
Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Bre… -
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
— The Hacker News
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript … -
ISC Stormcast For Tuesday, September 1st, 2026 https://isc.sans.edu/podcastdetail/10076, (Tue, Sep 1st)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (13000 in last 30 days).
Critical: 3 · High: 8 · Medium: 5 · Low: 0. View full dashboard →
-
CVE-2026-84483
— CVSS 5.3 (MEDIUM)
WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens using the public site URL and current time. Atta⦠-
CVE-2026-84482
— CVSS 8.8 (HIGH)
WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers can forge requests from s⦠-
CVE-2026-84480
— CVSS 9.8 (CRITICAL)
WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token ca⦠-
CVE-2026-84479
— CVSS 9.1 (CRITICAL)
WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against ⦠-
CVE-2026-84478
— CVSS 7.3 (HIGH)
WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying directory traversal sequences in the code param⦠-
CVE-2026-84477
— CVSS 5.4 (MEDIUM)
AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthenticated attackers can access remindMe.php to exec⦠-
CVE-2026-84476
— CVSS 7.5 (HIGH)
WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can rotate the header value per r⦠-
CVE-2026-84423
— CVSS 7.3 (HIGH)
A vulnerability has been found in Casdoor up to 4.0.0. This affects an unknown function of the file controllers/resource.go of the component upload-resource API. Such manipulation leads to missing authentication. It is p⦠-
CVE-2026-84208
— CVSS 7.5 (HIGH)
AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin's regions.json.php and cities.json.php endpoints. The country and region GET parameters are passed directly ⦠-
CVE-2026-84375
— CVSS 7.5 (HIGH)
js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing the merge key <<. An a⦠-
CVE-2026-84374
— CVSS 7.5 (HIGH)
Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the MaatwebsiteExcelFilesDisk::copy() method resolves the caller-controlled $destination supplie⦠-
CVE-2026-84373
— CVSS 5.9 (MEDIUM)
Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin exports in packages/mocker/src/node/interceptorPlugin.ts register the vitest⦠-
CVE-2026-84372
— CVSS 9.8 (CRITICAL)
Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RES⦠-
CVE-2026-84289
— CVSS 4.3 (MEDIUM)
A vulnerability was found in NousResearch hermes-agent up to 0.18.2. This vulnerability affects the function list_tools of the file tools/mcp_tool.py of the component MCP Tool. Performing a manipulation results in uncont⦠-
CVE-2026-84288
— CVSS 4.3 (MEDIUM)
A vulnerability has been found in NousResearch hermes-agent up to 0.18.2. This affects the function HermesACPAgent.prompt of the file acp_adapter/session.py of the component ACP Prompt Workflow. Such manipulation leads t⦠-
CVE-2026-83549
— CVSS 7.8 (HIGH)
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditiâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · September 2, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment