HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of September 5, 2026.
-
IDScan sued over alleged data breach affecting 153 million drivers
— Bleeping Computer
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to s… -
Companies Have 6 Months to Prepare for Automated Attacks
— Dark Reading
Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, … -
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
— The Hacker News
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead o… -
Critical Citrix NetScaler auth bypass now leveraged in attacks
— Bleeping Computer
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerabilit… -
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
— The Hacker News
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as th… -
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
— The Hacker News
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean orga… -
Microsoft says some users can’t open the Teams desktop client
— Bleeping Computer
Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Win… -
AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
— Dark Reading
A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks. -
Insurers Search for Answers to Rein in Rogue AI
— Dark Reading
As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout. -
ISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. -
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
— Unit 42
Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt o… -
Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)
— SANS ISC
[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program]
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (13216 in last 30 days).
Critical: 1 · High: 12 · Medium: 7 · Low: 0. View full dashboard →
-
CVE-2026-86100
— CVSS 6.4 (MEDIUM)
Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect targets when fetching remote files in the Upload from URL media feature. Authenticated attackers can supply URLs that pass initial validation but redire⦠-
CVE-2026-52775
— CVSS 8.8 (HIGH)
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki through the latest development branch contains a SQL injection vulnerability in ReactionManager::deleteUserReaction() that allows any authenticated⦠-
CVE-2026-52774
— CVSS 6.1 (MEDIUM)
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki's Bazar widget handler reflects the id GET parameter into HTML attributes using strip_tags() only. Because strip_tags() does not escape double quot⦠-
CVE-2026-52773
— CVSS 6.1 (MEDIUM)
YesWiki is a wiki system written in PHP. From version 4.1.0 to before version 4.6.6, YesWiki's archived-revision view reflects the time GET parameter into a hidden HTML input in handlers/page/show.php without escaping. B⦠-
CVE-2026-52772
— CVSS 5.5 (MEDIUM)
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, Bazar form-field templates still apply |raw('html') to field.label / field.hint in attribute and label-body contexts, resulting stored XSS in form renders.⦠-
CVE-2026-52771
— CVSS 8.3 (HIGH)
YesWiki is a wiki system written in PHP. From version 4.2.0 to before version 4.6.6, ApiController::deletePage() interpolates a page tag retrieved from the database into a DELETE FROM …_links WHERE to_tag = '$tag' quer⦠-
CVE-2026-52770
— CVSS 7.5 (HIGH)
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, YesWiki’s public Bazar entry-listing APIs are vulnerable to unauthenticated SQL injection in numeric query / queries filters. For Bazar fields whose valu⦠-
CVE-2026-52769
— CVSS 8.3 (HIGH)
YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, the POST /api/forms/{formId}/actor/inbox route – exposed publicly with acl:"public" – accepts an HTTP Signature header whose keyId para⦠-
CVE-2026-52767
— CVSS 8.2 (HIGH)
YesWiki is a wiki system written in PHP. From version 4.6.2 to before version 4.6.6, HttpSignatureService::verifySignature() checks the result of PHP's openssl_verify() with a loose boolean negation – if (!openssl_verify⦠-
CVE-2026-52766
— CVSS 9.1 (CRITICAL)
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the {{erasespamedcomments}} wiki action (actions/EraseSpamedCommentsAction.php) accepts a suppr[] array from POST and deletes every wiki page whose tag app⦠-
CVE-2026-52763
— CVSS 6.5 (MEDIUM)
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, the recentchanges action (actions/recentchanges.php) accepts a period argument from two disjoint parameter spaces. A whitelist validates only the URL form ⦠-
CVE-2026-86098
— CVSS 7.4 (HIGH)
ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerability in the ndpi_json_string_escape function that writes beyond caller-supplied buffer boundaries. Attackers can trigger the overflow by supplying cra⦠-
CVE-2026-86097
— CVSS 6.5 (MEDIUM)
PX4 Autopilot through 1.17.0 contains a null pointer dereference vulnerability in param_set_default_file() and param_set_backup_file() functions that allows attackers to crash the autopilot process. Attackers can invoke ⦠-
CVE-2026-86096
— CVSS 5.9 (MEDIUM)
PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability in TemperatureCalibration::start() due to a race condition between task spawning and object deletion. Attackers can trigger the calibration process via⦠-
CVE-2026-86095
— CVSS 7.8 (HIGH)
Unidata netcdf-c through 4.10.1 contains an out-of-bounds write vulnerability in NC4_HDF5_inq_attname() that copies HDF5 attribute names into a fixed 256-byte buffer without length validation. Attackers can craft HDF5 fi⦠-
CVE-2026-48019
— CVSS 8.9 (HIGH)
Laravel is a web application framework. Prior to versions 12.60.0 and 13.10.0, a CRLF injection vulnerability in Laravel's email validation, in combination with how Symfony Mailer and Symfony Mime handle certain characte⦠-
CVE-2026-86091
— CVSS 7.1 (HIGH)
ntopng before 6.7.260717 fails to check user privileges in the pools bulk-delete endpoint, allowing authenticated non-administrators to delete all host pools and member bindings. Attackers can issue POST requests to the ⦠-
CVE-2026-86090
— CVSS 7.1 (HIGH)
ntopng before 6.7.260717 fails to perform authorization checks in the delete endpoints and recipients REST v2 handlers. Authenticated non-administrator users can issue POST requests to irreversibly delete all configured ⦠-
CVE-2026-82684
— CVSS 8.1 (HIGH)
Tycon Systems TPDIN-Monitor-WEB3 versions 2.2.9 and prior are vulnerable to a Missing Authorization vulnerability. This could allow an attacker to extract system credentials, configurations, or flash contents. -
CVE-2026-77393
— CVSS 8.8 (HIGH)
In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts projeâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · September 5, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment