HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of September 4, 2026.
-
French hospital fined €500,000 after breach exposes data of 727,000
— Bleeping Computer
France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect pati… -
Large Enterprises Targeted in Fake Merger & Acquisition Scams
— Dark Reading
Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating… -
Coder's registry infrastructure compromised to push malicious modules
— Bleeping Computer
Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules c… -
What We Missed: Did ShinyHunters 'Breach' ReliaQuest?
— Dark Reading
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of Shiny… -
HPE patches critical ArubaOS-CX remote code execution flaw
— Bleeping Computer
Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote c… -
ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
— The Hacker News
The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why br… -
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
— The Hacker News
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauth… -
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
— The Hacker News
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an und… -
AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours
— Dark Reading
The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according… -
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
— Unit 42
Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt o… -
Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)
— SANS ISC
[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program] -
ISC Stormcast For Thursday, September 3rd, 2026 https://isc.sans.edu/podcastdetail/10080, (Thu, Sep 3rd)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (13099 in last 30 days).
Critical: 2 · High: 14 · Medium: 4 · Low: 0. View full dashboard →
-
CVE-2026-49509
— CVSS 4.4 (MEDIUM)
Out-of-bounds read vulnerability in Samsung Opensource Escargot allows Overread Buffers.This issue affects Escargot: 25648aef19187b3f87f4d9420b8d761453ad4630.
-
CVE-2026-85456
— CVSS 5.5 (MEDIUM)
MOOS-IvP through 24.8.1 fails to properly validate variable names extracted from alog files in the SplitHandler, allowing attackers to write files outside the split directory. Attackers can supply crafted alog files with⦠-
CVE-2026-85455
— CVSS 8.2 (HIGH)
MOOS core-moos through 10.4.0 contains a buffer over-read vulnerability in CMOOSCommPkt where a four-byte packet triggers out-of-bounds memory access during deserialization. Attackers can open a TCP connection to the MOO⦠-
CVE-2026-85454
— CVSS 6.1 (MEDIUM)
MOOS core-moos through 10.4.0 contains a buffer overflow vulnerability in CMOOSSerialPort::GetTelegram() that writes a NUL terminator one byte past the serial telegram stack buffer. Attackers controlling the serial line ⦠-
CVE-2026-85453
— CVSS 6.1 (MEDIUM)
MOOS core-moos through 10.4.0 fails to escape database contents when rendering MOOSDB HTTP pages, allowing attackers to inject malicious scripts. Any MOOS publisher can set variable values containing script payloads that⦠-
CVE-2026-85452
— CVSS 8.8 (HIGH)
MOOS ui-moos through 50b9c6c contains a buffer overflow vulnerability in ScopeTabPane.cpp and ScopeGrid.cpp where client and variable names are formatted into fixed 1024-byte buffers using sprintf without length validati⦠-
CVE-2026-85451
— CVSS 7.1 (HIGH)
MOOS core-moos through 10.4.0 contains a remote process termination vulnerability in the SuicidalSleeper component that uses a hard-coded passphrase for multicast command authorization. Any multicast-reachable peer can e⦠-
CVE-2026-85450
— CVSS 7.5 (HIGH)
MOOS core-moos through 10.4.0 contains a denial of service vulnerability in the MOOSDB HTTP server that creates unbounded connections and threads without limits. Attackers can open many connections and send endless heade⦠-
CVE-2026-85449
— CVSS 7.5 (HIGH)
MOOS-IvP pMarineViewer through 24.8.1 fails to limit the number of tracked node identities from NODE_REPORT messages, allowing attackers to exhaust memory by supplying unbounded distinct node names. Attackers can publish⦠-
CVE-2026-85448
— CVSS 7.5 (HIGH)
MOOS-IvP uFldShoreBroker through 24.8.1 fails to limit the number of claimed communities stored in parallel vectors within ShoreBroker::handleMailNodePing(). A single publisher can supply unbounded distinct community nam⦠-
CVE-2026-85447
— CVSS 7.5 (HIGH)
MOOS-IvP pRealm through version 24.8.1 accepts unbounded REALMCAST_REQ subscriptions without validating duration or variable list limits. Attackers can register long-lived pipeways with many variables to cause pRealm to ⦠-
CVE-2026-85446
— CVSS 7.5 (HIGH)
MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity creates a ledger entry and triggers all-pairs distribution work. Attackers can supply unbounded ⦠-
CVE-2026-85445
— CVSS 7.5 (HIGH)
MOOS-IvP through 24.8.1 contains a denial of service vulnerability in the Demuxer::addMuxPacket() function that trusts the packet count declared in mux headers without validation. Attackers can declare arbitrarily large ⦠-
CVE-2026-85444
— CVSS 7.5 (HIGH)
MOOS-IvP through 24.8.1 contains a buffer over-read vulnerability in isQuoted(), isBraced(), and isChevroned() functions that strip whitespace but index using the original string length. Attackers can send NODE_REPORT me⦠-
CVE-2026-85443
— CVSS 7.5 (HIGH)
MOOS core-moos through 10.4.0 contains a denial of service vulnerability in MOOSCommServer::ListenLoop() where the accept thread performs a blocking receive without timeout during the wire-protocol handshake. An attacker⦠-
CVE-2026-85442
— CVSS 7.5 (HIGH)
MOOS core-moos through 10.4.0 fails to validate packet length declarations in CMOOSCommPkt::OnBytesWritten(), allowing unauthenticated attackers to trigger unbounded buffer allocation by sending crafted wire packets. Att⦠-
CVE-2026-85441
— CVSS 7.5 (HIGH)
MOOS core-moos through 10.4.0 fails to validate that serialized string lengths are non-negative in CMOOSMsg::operator>>. Unauthenticated attackers can send a crafted message with a negative length value to the MOOSDB por⦠-
CVE-2026-85440
— CVSS 9.8 (CRITICAL)
MOOS core-moos through 10.4.0 contains a pre-authentication heap overflow vulnerability in MOOSCommPkt packet handling that allows remote attackers to write arbitrary data by declaring a negative packet length. Attackers⦠-
CVE-2026-85439
— CVSS 7.8 (HIGH)
MOOS-IvP through 24.8.1 contains a remote code execution vulnerability in alogsplit's SplitHandler::handlePreCheckSplitDir() function that fails to sanitize shell metacharacters in log file pathnames. Attackers can embed⦠-
CVE-2026-85438
— CVSS 9.8 (CRITICAL)
MOOS-IvP through 24.8.1 contains a buffer overflow vulnerability in StringToIvPFunction() where dimension, piece, and degree counts from encoded BHV_IPF payloads are used as allocation sizes and loop bounds without validâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · September 4, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment