📰 DAILY THREAT BRIEFING
Sunday, September 6, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of September 6, 2026.

  1. Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
    — The Hacker News

    Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an onl…
  2. Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
    — The Hacker News

    JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat…
  3. Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
    — The Hacker News

    Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could…
  4. Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
    — Bleeping Computer

    A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smar…
  5. OpenAI admits it didn't disclose rogue AI wiki hijacking incident
    — Bleeping Computer

    OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and b…
  6. numbat – AI agent observability, (Fri, Sep 4th)
    — SANS ISC
  7. IDScan sued over alleged data breach affecting 153 million drivers
    — Bleeping Computer

    Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to s…
  8. Companies Have 6 Months to Prepare for Automated Attacks
    — Dark Reading

    Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, …
  9. AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
    — Dark Reading

    A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.
  10. Insurers Search for Answers to Rein in Rogue AI
    — Dark Reading

    As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.
  11. ISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  12. Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America
    — Unit 42

    Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt o…

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (12851 in last 30 days).
Critical: 6 · High: 3 · Medium: 11 · Low: 0. View full dashboard →

  1. CVE-2026-86151
    — CVSS 9.1 (CRITICAL)

    A vulnerability was detected in Tenda CP3 27.5.57.101. The affected element is the function sub_2F77E8 of the file Apis/system.c of the component Network Configuration Management. Performing a manipulation results in os …
  2. CVE-2026-86150
    — CVSS 4.1 (MEDIUM)

    A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. …
  3. CVE-2026-86149
    — CVSS 9.1 (CRITICAL)

    A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The…
  4. CVE-2026-86148
    — CVSS 9.1 (CRITICAL)

    A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in …
  5. CVE-2026-6554
    — CVSS 5.5 (MEDIUM)

    libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does not limit the number of loop iterations. In particular uncommon use cases …
  6. CVE-2026-6244
    — CVSS 5.5 (MEDIUM)

    libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero.
  7. CVE-2026-31912
    — CVSS 5.5 (MEDIUM)

    libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer…
  8. CVE-2026-31911
    — CVSS 5.5 (MEDIUM)

    libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process.
  9. CVE-2026-18313
    — CVSS 4.3 (MEDIUM)

    rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious …
  10. CVE-2026-18238
    — CVSS 5.0 (MEDIUM)

    The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of t…
  11. CVE-2026-0799
    — CVSS 8.7 (HIGH)

    In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particul…
  12. CVE-2026-86192
    — CVSS 6.5 (MEDIUM)

    SiYuan versions before v3.8.2 fail to properly filter private attribute-view cell values in the getAttributeViewKeys endpoint. Publish readers can retrieve hidden KeyValues payloads from rows bound to inaccessible docume…
  13. CVE-2026-86191
    — CVSS 4.3 (MEDIUM)

    SiYuan versions before v3.8.2 contain an information disclosure vulnerability in the getAttributeViewKeysByID endpoint that allows publish readers to enumerate private attribute view key definitions without verifying par…
  14. CVE-2026-86190
    — CVSS 9.1 (CRITICAL)

    WWBN AVideo contains a broken access control vulnerability in videoViewsInfo endpoints that returns complete user records including password hashes, recovery tokens, and live session identifiers to unauthenticated caller…
  15. CVE-2026-86189
    — CVSS 9.8 (CRITICAL)

    WWBN AVideo contains a path traversal vulnerability in notify.ffmpeg.json.php that allows unauthenticated attackers to write files to arbitrary locations by supplying a caller-chosen path in the avideoRelativePath parame…
  16. CVE-2026-86188
    — CVSS 7.2 (HIGH)

    AVideo with YPTSocket plugin enabled contains a cross-site scripting vulnerability allowing unauthenticated attackers to execute arbitrary JavaScript in other users' browsers via the websocket callback mechanism. Attacke…
  17. CVE-2026-86187
    — CVSS 5.9 (MEDIUM)

    WWBN AVideo generates passwords for external-login accounts using rand() instead of a cryptographic generator, producing only 31-bit integers. Attackers with access to password hashes can recover plaintext passwords in m…
  18. CVE-2026-86186
    — CVSS 6.5 (MEDIUM)

    AVideo API fails to enforce rate limits when clients send a bot User-Agent header, allowing attackers to bypass all eight protected operations including login brute-force protection. Attackers can send requests with a bo…
  19. CVE-2026-86185
    — CVSS 8.0 (HIGH)

    Bilibili Desktop through 1.18.0 disables TLS certificate verification process-wide and executes unsigned remote JavaScript configuration without integrity checks. An attacker in an on-path network position can intercept …
  20. CVE-2026-86184
    — CVSS 9.8 (CRITICAL)

    Lara Dashboard before 1.3.0 contains an authentication bypass vulnerability in the screenshot-login route that allows unauthenticated attackers to authenticate as any user by email when APP_ENV is not production. Attacke…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · September 6, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com