📰 DAILY THREAT BRIEFING
Thursday, September 10, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of September 10, 2026.

  1. Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
    — Bleeping Computer

    Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management …
  2. AdaptHealth confirms 4.1 million people exposed in July cyberattack
    — Bleeping Computer

    Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attrib…
  3. Mythos Vulnerability Firehose Hits a Human Bottleneck
    — Dark Reading

    An analysis of Project Glasswing findings shows only a fraction have reached disclosure, and an even smaller number have been fixed.
  4. Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking
    — Bleeping Computer

    The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairin…
  5. US Government Accuses Chinese AI Firms of Distilling Frontier Models
    — Dark Reading

    US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce…
  6. U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
    — The Hacker News

    The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarante…
  7. Scans for Proxmox Servers, (Wed, Sep 9th)
    — SANS ISC

    About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment …
  8. Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
    — The Hacker News

    Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that c…
  9. Identity-Based AI Attack Threatens Security of Enterprise Data
    — Dark Reading

    "Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic request through an …
  10. Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
    — The Hacker News

    Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illi…
  11. Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
    — Unit 42

    An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks…
  12. ISC Stormcast For Wednesday, September 9th, 2026 https://isc.sans.edu/podcastdetail/10086, (Wed, Sep 9th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (14329 in last 30 days).
Critical: 3 · High: 6 · Medium: 11 · Low: 0. View full dashboard →

  1. CVE-2026-76562
    — CVSS 7.2 (HIGH)

    The Sidebar Manager Light plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'sbm_description' parameter in all versions up to, and including, 1.18 due to insufficient input sanitization and output…
  2. CVE-2026-4657
    — CVSS 6.4 (MEDIUM)

    The Easy Google Fonts plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the control_selectors meta field in all versions up to, and including, 2.0.4. This is due to the plugin registering the control_…
  3. CVE-2026-18594
    — CVSS 4.3 (MEDIUM)

    The Advanced Contact form 7 DB plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 2.1.3. This is due to the plugin not properly verifying that a user is authorized to perform…
  4. CVE-2026-18386
    — CVSS 4.9 (MEDIUM)

    The WP BackItUp Community Edition plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.1.0 via the 'backup_file' parameter parameter. This makes it possible for authenticated …
  5. CVE-2026-15823
    — CVSS 4.3 (MEDIUM)

    The Builderall Cheetah For Wp plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the disable() function in versions up to, and including, 3.0.2. The wp_ajax_ba_ch…
  6. CVE-2026-15820
    — CVSS 6.4 (MEDIUM)

    The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Photo Module 'attributes' Setting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and …
  7. CVE-2026-15796
    — CVSS 6.4 (MEDIUM)

    The Builderall for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'bg_video_service_url' Setting in all versions up to, and including, 3.0.2 due to insufficient input sanitization and out…
  8. CVE-2026-15019
    — CVSS 7.5 (HIGH)

    The Direct Download for WooCommerce plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.19 via the (top-level include) function. This makes it possible for unauthenticated at…
  9. CVE-2026-14873
    — CVSS 8.0 (HIGH)

    The Bulk Password Reset plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.3.3. This is due to the plugin not properly validating a user's identity pri…
  10. CVE-2026-87870
    — CVSS 6.4 (MEDIUM)

    The Ninja Forms – Scheduled Exports plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API Parameters (interval, format, emailTo) in all versions up to, and including, 3.0.3 due to insufficient in…
  11. CVE-2026-84063
    — CVSS 6.5 (MEDIUM)

    BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted upload of file with dangerous type. If this vulnerability is exploited, an arbitrary file may be uploaded by an attacker who can log in to the product,…
  12. CVE-2026-84062
    — CVSS 4.3 (MEDIUM)

    BurgerEditor 3.0.0 through 3.4.0 contains an issue with authorization bypass through user-controlled key. If this vulnerability is exploited, the content of the page may be altered by an attacker who can log in to the pr…
  13. CVE-2026-19584
    — CVSS 7.7 (HIGH)

    Velociraptor allows for the creation of notebook backups in its default enabled daily backup feature. When Velociraptor restores the backup, the notebook cell content is interpolated into a template with no ACL checks. T…
  14. CVE-2026-19583
    — CVSS 9.9 (CRITICAL)

    Velociraptor allows some sensitive artifacts to be gated by additional permissions. For example, the Linux.Sys.BashShell artifact allows arbitrary command execution on endpoints, and so it requires the EXECVE permission …
  15. CVE-2026-18351
    — CVSS 9.8 (CRITICAL)

    The Drag and Drop File Upload for Elementor Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.6.0 via the elementor_file_upload function. This is due to insufficien…
  16. CVE-2026-87933
    — CVSS 7.3 (HIGH)

    A vulnerability was found in DaveGamble cJSON up to 1.7.19. The affected element is the function cJSONUtils_MergePatch of the file cJSON_Utils.c. The manipulation results in use after free. The attack may be launched rem…
  17. CVE-2026-87931
    — CVSS 9.6 (CRITICAL)

    A vulnerability has been found in Behavioral Technology Group Pavlok Behavioral Conditioning Wearable up to 20260707. Impacted is an unknown function of the component Apple Notification Center Service Event Handler. The …
  18. CVE-2026-87926
    — CVSS 4.3 (MEDIUM)

    A flaw has been found in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This issue affects some unknown processing of the file index.php of the component Login Page. Executing a mani…
  19. CVE-2026-87925
    — CVSS 7.3 (HIGH)

    A vulnerability was detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This vulnerability affects the function storeCustomerOrderInvoice of the file includes/manage.php. Perf…
  20. CVE-2026-87924
    — CVSS 6.5 (MEDIUM)

    A security vulnerability has been detected in Rizwan17 inventory-management-system up to bfe78a330d01bb26b9daec5dc9ecd5c77900e03f. This affects an unknown part of the file includes/invoice_bill.php of the component Invoi…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · September 10, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com