📰 DAILY THREAT BRIEFING
Monday, September 7, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of September 7, 2026.

  1. ChatGPT Astra is now rolling out to $20 Plus subscription
    — Bleeping Computer

    OpenAI is now rolling out ChatGPT Astra, its most powerful model to date, to those with a $20 Plus subscription, but there's no word on when…
  2. Critical MikroTik Vulnerability – Patch Now, (Sun, Sep 6th)
    — SANS ISC

    Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and i…
  3. Attackers conceal phishing lures using invisible Unicode characters
    — Bleeping Computer

    Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security f…
  4. Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
    — The Hacker News

    Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain…
  5. Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
    — The Hacker News

    Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer…
  6. Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
    — The Hacker News

    Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an onl…
  7. Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
    — Bleeping Computer

    A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smar…
  8. numbat – AI agent observability, (Fri, Sep 4th)
    — SANS ISC
  9. Companies Have 6 Months to Prepare for Automated Attacks
    — Dark Reading

    Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, …
  10. AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
    — Dark Reading

    A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.
  11. Insurers Search for Answers to Rein in Rogue AI
    — Dark Reading

    As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.
  12. ISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (12759 in last 30 days).
Critical: 0 · High: 4 · Medium: 15 · Low: 1. View full dashboard →

  1. CVE-2026-86314
    — CVSS 6.2 (MEDIUM)

    Integer overflow in the source-bounds check in Memory::init() (src/runtime/Memory.cpp) in Samsung walrus on all platforms allows a remote attacker to cause an out-of-bounds heap read and denial of service via a crafted W…
  2. CVE-2026-86313
    — CVSS 7.8 (HIGH)

    Out-of-bounds write vulnerability in Samsung Opensource Walrus allows Overflow Buffers.

    This issue affects Walrus: af80e665ea49d9003695a66502f841ed1d8397e7.

  3. CVE-2026-86264
    — CVSS 4.3 (MEDIUM)

    A flaw has been found in sfturing ssm_pro up to 627f426331da8086ce8fff2017d65b1ddef384f8. Affected is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of the component Order Endp…
  4. CVE-2026-86263
    — CVSS 7.3 (HIGH)

    A vulnerability was detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This impacts the function orderRecordsService.cancelOrder of the file ssm_pro/src/main/java/cn/sfturing/web/OrderControl…
  5. CVE-2026-86262
    — CVSS 7.3 (HIGH)

    A security vulnerability has been detected in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects the function updateOrderSta1/updateOrderdiseaseInfo of the file ssm_pro/src/main/java/cn/sftu…
  6. CVE-2026-86261
    — CVSS 7.3 (HIGH)

    A weakness has been identified in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The impacted element is an unknown function of the file ssm_pro/src/main/java/cn/sfturing/web/OrderController.java of …
  7. CVE-2026-86260
    — CVSS 6.5 (MEDIUM)

    A security flaw has been discovered in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. The affected element is the function modifyPassWord of the file ssm_pro/src/main/java/cn/sfturing/web/CommonUserC…
  8. CVE-2026-86245
    — CVSS 6.3 (MEDIUM)

    A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_transac.php. Performing a manipulation of the argument compan…
  9. CVE-2026-86244
    — CVSS 4.3 (MEDIUM)

    A security vulnerability has been detected in FastAdmin up to 1.2.0.20210401_beta. Affected is the function register/login of the file application/index/controller/User.php of the component User Controller. Such manipula…
  10. CVE-2026-86241
    — CVSS 4.3 (MEDIUM)

    A weakness has been identified in liufee FeehiCMS up to 2.1.1. This impacts an unknown function of the file environments/prod/backend/config/main-local.php of the component Cookie Validation. This manipulation of the arg…
  11. CVE-2026-86240
    — CVSS 4.7 (MEDIUM)

    A security flaw has been discovered in liufee FeehiCMS up to 2.1.1. This affects the function catchImage of the file backend/widgets/ueditor/Uploader.php of the component UEditor. The manipulation of the argument source[…
  12. CVE-2026-86239
    — CVSS 5.3 (MEDIUM)

    A vulnerability was identified in liufee FeehiCMS up to 2.1.1. The impacted element is the function UeditorAction::init of the file backend/widgets/ueditor/UeditorAction.php of the component UEditor Widget. The manipulat…
  13. CVE-2026-86238
    — CVSS 4.3 (MEDIUM)

    A vulnerability was determined in projectworlds Online Examination System 1.0. The affected element is an unknown function of the file feedback.php of the component Feedback Form. Executing a manipulation of the argument…
  14. CVE-2026-86237
    — CVSS 5.3 (MEDIUM)

    A vulnerability was found in openagents-org openagents up to 0.8.19/0.9.3.post20. Impacted is the function test_default_model of the file sdk/src/openagents/sdk/transports/http.py. Performing a manipulation of the argume…
  15. CVE-2026-86236
    — CVSS 6.3 (MEDIUM)

    A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This issue affects some unknown processing of the file /pages/pro_transac.php?action=add. Such manipulation of the argument Name leads to sql…
  16. CVE-2026-86235
    — CVSS 6.3 (MEDIUM)

    A flaw has been found in itsourcecode Sales and Inventory System 1.0. This vulnerability affects unknown code of the file /pages/pos_transac.php?action=add. This manipulation of the argument Customer causes sql injection…
  17. CVE-2026-86234
    — CVSS 6.3 (MEDIUM)

    A vulnerability was detected in itsourcecode Sales and Inventory System 1.0. This affects an unknown part of the file /pages/cust_transac.php?action=add. The manipulation of the argument firstname results in sql injectio…
  18. CVE-2026-86233
    — CVSS 6.3 (MEDIUM)

    A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. Affected by this issue is some unknown functionality of the file /pages/us_del.php?type=user. The manipulation of the argument ID…
  19. CVE-2026-86232
    — CVSS 6.3 (MEDIUM)

    A weakness has been identified in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_del.php?type=supplier. Executing a manipulation of the argu…
  20. CVE-2026-86231
    — CVSS 3.7 (LOW)

    A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of the argument known_hosts re…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · September 7, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com