HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of September 7, 2026.
-
Critical MikroTik Vulnerability – Patch Now, (Sun, Sep 6th)
— SANS ISC
Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and i… -
Attackers conceal phishing lures using invisible Unicode characters
— Bleeping Computer
Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security f… -
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
— The Hacker News
Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain… -
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
— The Hacker News
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer… -
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
— The Hacker News
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an onl… -
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
— Bleeping Computer
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smar… -
OpenAI admits it didn't disclose rogue AI wiki hijacking incident
— Bleeping Computer
OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and b… -
numbat – AI agent observability, (Fri, Sep 4th)
— SANS ISC -
Companies Have 6 Months to Prepare for Automated Attacks
— Dark Reading
Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, … -
AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
— Dark Reading
A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks. -
Insurers Search for Answers to Rein in Rogue AI
— Dark Reading
As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout. -
ISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (12724 in last 30 days).
Critical: 0 · High: 9 · Medium: 8 · Low: 3. View full dashboard →
-
CVE-2026-86232
— CVSS 6.3 (MEDIUM)
A weakness has been identified in itsourcecode Sales and Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /pages/sup_del.php?type=supplier. Executing a manipulation of the argu⦠-
CVE-2026-86231
— CVSS 3.7 (LOW)
A security flaw has been discovered in mwiede jsch up to 2.28.5. Affected is the function getRevokedKeys of the file src/main/java/com/jcraft/jsch/KnownHosts.java. Performing a manipulation of the argument known_hosts re⦠-
CVE-2026-86228
— CVSS 4.3 (MEDIUM)
A security vulnerability has been detected in JeecgBoot up to 3.9.3. This vulnerability affects the function exportXls of the file jeecg-boot/jeecg-boot-module/jeecg-boot-module-airag/src/main/java/org/jeecg/modules/aira⦠-
CVE-2026-86227
— CVSS 3.1 (LOW)
A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1. This affects the function kvstoreGetHashtable of the file src/kvstore.c. This manipulation of the argument didx causes out-of-bounds read. It is possi⦠-
CVE-2026-86226
— CVSS 3.5 (LOW)
A security flaw has been discovered in Projectwolds Online Attendance System 1.0. Affected by this issue is some unknown functionality of the file profile.php. The manipulation of the argument email results in cross site⦠-
CVE-2026-86225
— CVSS 7.3 (HIGH)
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The manipulation of the argument ⦠-
CVE-2026-86224
— CVSS 7.3 (HIGH)
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of the argument fname can l⦠-
CVE-2026-86223
— CVSS 7.3 (HIGH)
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqli_query of the file /admin/modal_add_coursea.php. Performing a manipulation of the argument course results⦠-
CVE-2026-86222
— CVSS 7.3 (HIGH)
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqli_query of the file /admin/modal_add_course2.php. Such manipulation of the argument course leads to s⦠-
CVE-2026-86221
— CVSS 7.3 (HIGH)
A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. The impacted element is the function mysqli_query of the file /admin/modal_add_course1.php. This manipulation of the argument course causes s⦠-
CVE-2026-86220
— CVSS 7.3 (HIGH)
A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. The affected element is the function mysqli_query of the file /admin/modal_add_course.php. The manipulation of the argument course res⦠-
CVE-2026-83534
— CVSS 6.4 (MEDIUM)
PostgreSQL Anonymizer contains a vulnerability in the anon.anonymize_database_parallel() function that allows the owner of a table to run arbitrary code with superuser privilege. The issue is fixed in PostgreSQL Anonymiz⦠-
CVE-2026-19634
— CVSS 6.4 (MEDIUM)
PostgreSQL Anonymizer contains a SQL injection vulnerability in two import functions. A user can create a malicious JSON document containing specially crafted object names. If a superuser subsequently calls anon.import_d⦠-
CVE-2026-19633
— CVSS 8.8 (HIGH)
PostgreSQL Anonymizer contains a vulnerability that allows unprivileged masked users to execute arbitrary code by abusing operators, domain casts, or view subqueries that carry untrusted expressions. When these objects a⦠-
CVE-2026-86217
— CVSS 5.3 (MEDIUM)
A vulnerability was detected in code-projects Hotel and Tourism Reservation in PHP 1.0. Affected is an unknown function of the file /ht/hotel_db%20(1).sql of the component Database Backup Handler. The manipulation result⦠-
CVE-2026-86216
— CVSS 4.3 (MEDIUM)
A security vulnerability has been detected in code-projects Hotel and Tourism Reservation in PHP 1.0. This impacts an unknown function of the file /ht/details.php. The manipulation of the argument room leads to cross sit⦠-
CVE-2026-86215
— CVSS 4.3 (MEDIUM)
A vulnerability was identified in Mstfakts College-Management-System. The affected element is an unknown function of the file Front-end/server.php of the component Logout Handler. Such manipulation of the argument log_ou⦠-
CVE-2026-86259
— CVSS 7.5 (HIGH)
OpenMAIC before 1.0.1 skips server-side request forgery validation in non-production builds, allowing unauthenticated attackers to reach cloud instance metadata services. Attackers can supply arbitrary provider URLs via ⦠-
CVE-2026-86258
— CVSS 5.9 (MEDIUM)
nbviewer through 1.0.1 contains a path traversal vulnerability in LocalFileHandler.can_show() that uses string-prefix comparison instead of proper path validation. Attackers can read files from sibling directories outsid⦠-
CVE-2026-86214
— CVSS 7.3 (HIGH)
A vulnerability was determined in Mstfakts College-Management-System. Impacted is an unknown function of the file Front-end/login.php. This manipulation of the argument email causes improper authentication. It is possiblâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · September 7, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment