HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of September 6, 2026.
-
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
— The Hacker News
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an onl… -
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
— The Hacker News
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat… -
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
— The Hacker News
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could… -
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
— Bleeping Computer
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smar… -
OpenAI admits it didn't disclose rogue AI wiki hijacking incident
— Bleeping Computer
OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and b… -
numbat – AI agent observability, (Fri, Sep 4th)
— SANS ISC -
IDScan sued over alleged data breach affecting 153 million drivers
— Bleeping Computer
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to s… -
Companies Have 6 Months to Prepare for Automated Attacks
— Dark Reading
Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, … -
AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
— Dark Reading
A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks. -
Insurers Search for Answers to Rein in Rogue AI
— Dark Reading
As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout. -
ISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. -
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
— Unit 42
Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt o…
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (12851 in last 30 days).
Critical: 6 · High: 3 · Medium: 11 · Low: 0. View full dashboard →
-
CVE-2026-86151
— CVSS 9.1 (CRITICAL)
A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os ⦠-
CVE-2026-86150
— CVSS 4.1 (MEDIUM)
A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. ⦠-
CVE-2026-86149
— CVSS 9.1 (CRITICAL)
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The⦠-
CVE-2026-86148
— CVSS 9.1 (CRITICAL)
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in ⦠-
CVE-2026-6554
— CVSS 5.5 (MEDIUM)
libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does not limit the number of loop iterations. In particular uncommon use cases ⦠-
CVE-2026-6244
— CVSS 5.5 (MEDIUM)
libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero. -
CVE-2026-31912
— CVSS 5.5 (MEDIUM)
libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer⦠-
CVE-2026-31911
— CVSS 5.5 (MEDIUM)
libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process. -
CVE-2026-18313
— CVSS 4.3 (MEDIUM)
rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious ⦠-
CVE-2026-18238
— CVSS 5.0 (MEDIUM)
The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of t⦠-
CVE-2026-0799
— CVSS 8.7 (HIGH)
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particul⦠-
CVE-2026-86192
— CVSS 6.5 (MEDIUM)
SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible docume⦠-
CVE-2026-86191
— CVSS 4.3 (MEDIUM)
SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying par⦠-
CVE-2026-86190
— CVSS 9.1 (CRITICAL)
WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated caller⦠-
CVE-2026-86189
— CVSS 9.8 (CRITICAL)
WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parame⦠-
CVE-2026-86188
— CVSS 7.2 (HIGH)
AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism. Attacke⦠-
CVE-2026-86187
— CVSS 5.9 (MEDIUM)
WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in m⦠-
CVE-2026-86186
— CVSS 6.5 (MEDIUM)
AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bo⦠-
CVE-2026-86185
— CVSS 8.0 (HIGH)
Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept ⦠-
CVE-2026-86184
— CVSS 9.8 (CRITICAL)
Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attackeâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · September 6, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment