HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of September 8, 2026.
-
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
— The Hacker News
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a boo… -
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
— Bleeping Computer
A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy… -
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
— The Hacker News
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other softw… -
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
— Bleeping Computer
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more… -
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
— The Hacker News
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It… -
Mathspace discloses data breach affecting over 1 million people
— Bleeping Computer
Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and … -
Critical MikroTik Vulnerability – Patch Now, (Sun, Sep 6th)
— SANS ISC
Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and i… -
numbat – AI agent observability, (Fri, Sep 4th)
— SANS ISC -
Companies Have 6 Months to Prepare for Automated Attacks
— Dark Reading
Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, … -
AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
— Dark Reading
A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks. -
Insurers Search for Answers to Rein in Rogue AI
— Dark Reading
As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout. -
ISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (12913 in last 30 days).
Critical: 3 · High: 10 · Medium: 4 · Low: 3. View full dashboard →
-
CVE-2026-86544
— CVSS 8.1 (HIGH)
knowns versions before 0.30.0 contain an authorization bypass vulnerability where mutating code actions are incorrectly classified as read-only operations. Attackers with read-restricted sessions can exploit code.replace⦠-
CVE-2026-86543
— CVSS 9.8 (CRITICAL)
knowns versions before 0.30.0 serve the management API without authentication on all network interfaces by default, with no password required on fresh installations. Attackers can access the unauthenticated /api/tunnel/s⦠-
CVE-2026-86542
— CVSS 9.1 (CRITICAL)
knowns before 0.30.0 fails to validate import names in the import routes, allowing unauthenticated attackers to write files outside the imports directory. Attackers can supply traversal sequences in the name parameter to⦠-
CVE-2026-86541
— CVSS 8.3 (HIGH)
knowns versions before 0.30.0 contain a path traversal vulnerability in the handleCodeReplace() function that allows attackers to overwrite arbitrary files outside the project root. Attackers can supply absolute paths or⦠-
CVE-2026-86540
— CVSS 7.8 (HIGH)
knowns versions before 0.30.0 fail to validate the settings.lsp.languages binary field in project configuration files, allowing attackers to execute arbitrary binaries by crafting a malicious .knowns/config.json file. Wh⦠-
CVE-2026-86539
— CVSS 7.2 (HIGH)
knowns through 0.33.0 contains a server-side request forgery vulnerability in the POST /api/embedding-models/test endpoint that issues outbound requests to caller-supplied destinations without validation. Attackers can e⦠-
CVE-2026-86538
— CVSS 7.5 (HIGH)
knowns versions before 0.30.0 contain a path traversal vulnerability in the POST /api/templates/preview endpoint that allows unauthenticated attackers to read arbitrary files. Attackers can supply directory traversal seq⦠-
CVE-2026-86439
— CVSS 8.8 (HIGH)
knowns versions before 0.30.0 fail to validate filesystem paths in MCP tool arguments, allowing attackers to read, create, overwrite and delete files outside the project directory. Attackers can supply path arguments con⦠-
CVE-2026-86438
— CVSS 7.2 (HIGH)
Lara Dashboard before 1.3.2 fails to authorize the MarketplaceModuleBrowser installModule Livewire action, allowing non-Superadmin administrators to install modules. Attackers can download and auto-activate arbitrary PHP⦠-
CVE-2026-86437
— CVSS 7.2 (HIGH)
Lara Dashboard before 1.3.2 authorizes the POST /admin/settings/core-upgrades/upload endpoint with only the settings.edit permission, allowing non-Superadmin administrators to upload and extract arbitrary zip archives ov⦠-
CVE-2026-86436
— CVSS 5.4 (MEDIUM)
Lara Dashboard before 1.3.2 fails to authorize access to the post-builder image and video upload endpoints, allowing authenticated accounts without content permissions to upload files. Attackers can upload polyglot files⦠-
CVE-2026-75650
— CVSS 10.0 (CRITICAL)
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exp⦠-
CVE-2026-86506
— CVSS 5.9 (MEDIUM)
In JetBrains GoLand before 2026.2.2.1 missing authentication on the GoLand profiler's injected pprof server exposed profiling data -
CVE-2026-86505
— CVSS 3.3 (LOW)
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust check leaked project metadata to JetBrains Marketplace -
CVE-2026-86504
— CVSS 7.8 (HIGH)
In JetBrains IntelliJ IDEA before 2026.2.2 missing project-trust confirmation before building a Dev Container allowed host-level code execution -
CVE-2026-86503
— CVSS 3.3 (LOW)
In JetBrains IntelliJ IDEA before 2026.2.2 opening an untrusted project could trigger SSRF via Kubernetes spec-source URL fetching -
CVE-2026-86502
— CVSS 8.4 (HIGH)
In JetBrains IntelliJ IDEA before 2026.2.2 missing TLS and authentication on the IJent gRPC server allowed local code execution on Remote Development hosts -
CVE-2026-86501
— CVSS 2.8 (LOW)
In JetBrains IntelliJ IDEA before 2026.2.2 terminal command input could be written to idea.log -
CVE-2026-86500
— CVSS 5.5 (MEDIUM)
In JetBrains YouTrack before 2026.1.14047 a missing escalation check let a user with project update permissions grant themselves Project Admin -
CVE-2026-86499
— CVSS 4.3 (MEDIUM)
In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · September 8, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment