📰 DAILY THREAT BRIEFING
Friday, September 11, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of September 11, 2026.

  1. New Android malware encrypts files, steals data, and harasses victims
    — Bleeping Computer

    A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spa…
  2. Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
    — Dark Reading

    Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHu…
  3. September Windows Server updates break Remote Desktop Services
    — Bleeping Computer

    Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 20…
  4. Surfshark VPN says hackers breached internal testing, proxy servers
    — Bleeping Computer

    Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. […]
  5. ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
    — The Hacker News

    A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for …
  6. Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit
    — Dark Reading

    The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.
  7. Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
    — The Hacker News

    Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and p…
  8. Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
    — SANS ISC

    [This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]
  9. Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
    — The Hacker News

    Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company sa…
  10. ISC Stormcast For Thursday, September 10th, 2026 https://isc.sans.edu/podcastdetail/10088, (Thu, Sep 10th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  11. The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE
    — Unit 42

    Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload i…
  12. EU Cyber Resilience Act to Enforce New Reporting Requirements
    — Dark Reading

    Starting Friday, European organizations will have just 24 hours to notify the EU government any time they discover serious product security …

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (13758 in last 30 days).
Critical: 2 · High: 17 · Medium: 1 · Low: 0. View full dashboard →

  1. CVE-2026-77807
    — CVSS 7.5 (HIGH)

    The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]`…
  2. CVE-2026-87958
    — CVSS 8.1 (HIGH)

    IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.
  3. CVE-2026-86093
    — CVSS 7.5 (HIGH)

    IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer …
  4. CVE-2026-86087
    — CVSS 4.3 (MEDIUM)

    IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system.
  5. CVE-2026-84889
    — CVSS 8.8 (HIGH)

    IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
  6. CVE-2026-82107
    — CVSS 9.6 (CRITICAL)

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.
  7. CVE-2026-82100
    — CVSS 9.6 (CRITICAL)

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.
  8. CVE-2026-82099
    — CVSS 8.8 (HIGH)

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
  9. CVE-2026-82098
    — CVSS 8.8 (HIGH)

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
  10. CVE-2026-82097
    — CVSS 8.8 (HIGH)

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.
  11. CVE-2026-82095
    — CVSS 8.8 (HIGH)

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
  12. CVE-2026-82092
    — CVSS 8.8 (HIGH)

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
  13. CVE-2026-81941
    — CVSS 8.8 (HIGH)

    IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a fl…
  14. CVE-2026-81940
    — CVSS 8.8 (HIGH)

    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.
  15. CVE-2026-81554
    — CVSS 8.8 (HIGH)

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
  16. CVE-2026-81551
    — CVSS 8.8 (HIGH)

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.
  17. CVE-2026-81550
    — CVSS 8.8 (HIGH)

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
  18. CVE-2026-81540
    — CVSS 8.5 (HIGH)

    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.
  19. CVE-2026-81268
    — CVSS 8.1 (HIGH)

    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.
  20. CVE-2026-81265
    — CVSS 7.5 (HIGH)

    IBM Langflow OSS 1.0.0 through 1.11.5.

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · September 11, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com