📰 DAILY THREAT BRIEFING
Thursday, September 3, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of September 3, 2026.

  1. AI’s Vulnerability Surge May Be More Manageable Than First Feared
    — Dark Reading

    New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategie…
  2. Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
    — Bleeping Computer

    Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that …
  3. SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
    — Dark Reading

    The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.
  4. AI Gives Cybercriminals a Dangerous Time Advantage
    — Dark Reading

    Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for atta…
  5. WordPress backup plugin flaw exposes millions of sites to takeover attacks
    — Bleeping Computer

    An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execu…
  6. Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs
    — The Hacker News

    Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available …
  7. Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
    — The Hacker News

    An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "Th…
  8. Hackers exploit critical JFrog Artifactory flaw to forge admin tokens
    — Bleeping Computer

    A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that pro…
  9. Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
    — The Hacker News

    Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuratio…
  10. An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
    — Unit 42

    Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against ag…
  11. ISC Stormcast For Wednesday, September 2nd, 2026 https://isc.sans.edu/podcastdetail/10078, (Wed, Sep 2nd)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  12. FBI Probes Service Selling 153M+ Drivers Licenses
    — Krebs on Security

    A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from peop…

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (13012 in last 30 days).
Critical: 1 · High: 7 · Medium: 12 · Low: 0. View full dashboard →

  1. CVE-2026-84857
    — CVSS 5.3 (MEDIUM)

    A flaw has been found in sigoden aichat up to 0.30.4. This affects an unknown function of the file src/serve.rs of the component API Endpoint. This manipulation causes uncontrolled memory allocation. The attack can be in…
  2. CVE-2026-84856
    — CVSS 5.3 (MEDIUM)

    A vulnerability was detected in rowboatlabs rowboat up to 0.9.1. The impacted element is the function request.text/req.json of the file apps/rowboat/app/api/composio/webhook/route.ts of the component Composio Webhook End…
  3. CVE-2026-84852
    — CVSS 4.4 (MEDIUM)

    A security vulnerability has been detected in Reader Tools PDF Reader App 98.8 on Android. The affected element is the function ActSplashNew.handleDeeplink of the component File Handler. The manipulation of the argument …
  4. CVE-2026-84292
    — CVSS 7.5 (HIGH)

    fast-uri serializes the port component of a URI without validating it. When recomposing the authority, the userinfo and host components are escaped but the port is concatenated verbatim, so a port value that is not a seq…
  5. CVE-2026-82524
    — CVSS 7.2 (HIGH)

    UnoPim before 2.1.5 contains an authenticated file upload vulnerability that allows authenticated administrators to upload arbitrary PHP files through the TinyMCE image upload endpoint due to missing file extension and M…
  6. CVE-2026-75137
    — CVSS 6.1 (MEDIUM)

    UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover cleartext vault data from process memory even after the application has been locked. Attackers ca…
  7. CVE-2026-75136
    — CVSS 6.1 (MEDIUM)

    UpSignOn for Windows before 7.19.0 contains an insecure credential storage vulnerability that allows local attackers to retrieve the biometric unlock key stored in the Windows PasswordVault API without triggering any aut…
  8. CVE-2026-75135
    — CVSS 6.1 (MEDIUM)

    UpSignOn for Windows before 7.19.0 contains a sensitive data exposure vulnerability that allows local attackers to recover the master password and decrypt vault contents by reading a retained backup key from the process …
  9. CVE-2026-75134
    — CVSS 6.4 (MEDIUM)

    SEOWriting plugin for WordPress through 1.12.5 contains a stored cross-site scripting vulnerability that allows authenticated contributors to inject malicious JavaScript by exploiting an overly permissive KSES allowlist …
  10. CVE-2023-20577
    — CVSS 7.4 (HIGH)

    A heap overflow in SMM module may allow an attacker with access to a second vulnerability that enables writing to SPI flash, potentially resulting in arbitrary code execution.
  11. CVE-2023-20576
    — CVSS 7.7 (HIGH)

    Insufficient Verification of Data Authenticity in AGESA™ may allow an attacker to update SPI ROM data potentially resulting in denial of service or privilege escalation.
  12. CVE-2026-84841
    — CVSS 7.3 (HIGH)

    A security flaw has been discovered in tsi-coop tsi-dpdp-cms up to 0.5.0. This vulnerability affects unknown code. The manipulation results in client-side enforcement of server-side security. The attack can be launched r…
  13. CVE-2026-84840
    — CVSS 6.5 (MEDIUM)

    A vulnerability was identified in tsi-coop tsi-dpdp-cms up to 0.5.0. This affects an unknown part of the file InterceptingFilter.java of the component Bootstrap Setup Endpoint. The manipulation leads to missing authentic…
  14. CVE-2026-84839
    — CVSS 5.3 (MEDIUM)

    A vulnerability was determined in tsi-coop tsi-dpdp-cms up to 0.5.0. Affected by this issue is some unknown functionality of the file web.xml of the component Admin Console/DPO Compliance Console. Executing a manipulatio…
  15. CVE-2026-84382
    — CVSS 7.5 (HIGH)

    HTTPX2 is a next generation HTTP client for Python. Prior to 2.12.0, the HTTPX2 content decoders in src/httpx2/httpx2/_decoders.py fully inflate each gzip, deflate, br, or zstd network chunk before iter_bytes() or aiter_…
  16. CVE-2026-84381
    — CVSS 8.1 (HIGH)

    HTTPX2 is a next generation HTTP client for Python. Prior to 2.10.0, httpcore2 fails to start TLS in src/httpcore2/httpcore2/_sync/socks_proxy.py and src/httpcore2/httpcore2/_async/socks_proxy.py when the remote origin u…
  17. CVE-2026-19117
    — CVSS 9.8 (CRITICAL)

    Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as
    that user. This issue affects on-premises deployments only.
  18. CVE-2026-84833
    — CVSS 4.3 (MEDIUM)

    A vulnerability was found in ntegrals openbrowser up to 067fc45d649baa961750da8e2f4a75d87c5c75c8. Affected by this vulnerability is an unknown functionality of the file packages/core/src/agent/agent.ts of the component B…
  19. CVE-2026-84380
    — CVSS 5.6 (MEDIUM)

    HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, Request._prepare() in src/httpx2/httpx2/_models.py can add a body-derived Content-Length header to a request that already contains a caller-supplied Tr…
  20. CVE-2026-84379
    — CVSS 5.3 (MEDIUM)

    HTTPX2 is a next generation HTTP client for Python. Prior to 2.11.0, FileField.render_headers() in src/httpx2/httpx2/_multipart.py directly interpolates attacker-controlled content_type values and custom headers from the…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · September 3, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com