📰 DAILY THREAT BRIEFING
Saturday, September 12, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of September 12, 2026.

  1. Hackers abused Claude to extract secrets from 1.8M Android apps
    — Bleeping Computer

    Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, …
  2. Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
    — Dark Reading

    Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.
  3. Florida confirms DMV database breached via stolen police account
    — Bleeping Computer

    The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, sa…
  4. CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
    — Dark Reading

    A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and inciden…
  5. Why AI Is So Good at Scamming Humans
    — Dark Reading

    Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to in…
  6. Passkey-themed phishing attacks lead to Microsoft 365 data theft
    — Bleeping Computer

    Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social en…
  7. GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
    — The Hacker News

    GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild pr…
  8. Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
    — The Hacker News

    Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in…
  9. The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)
    — SANS ISC

    I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acq…
  10. Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
    — The Hacker News

    Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, pr…
  11. ISC Stormcast For Friday, September 11th, 2026 https://isc.sans.edu/podcastdetail/10090, (Fri, Sep 11th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  12. Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
    — SANS ISC

    [This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (14038 in last 30 days).
Critical: 0 · High: 7 · Medium: 7 · Low: 0. View full dashboard →

  1. CVE-2026-90461
    — CVSS 6.3 (MEDIUM)

    OpenStack Ironic through 38.0.0 may send a username and password to an unexpected remote host when Image Service is configured for HTTP(S) Basic Authentication.
  2. CVE-2026-54258
    — CVSS 6.5 (MEDIUM)

    ZoneMinder is a free, open source closed-circuit television software application. Versions prior to 1.36.39, 1.38.4, and 1.39.11 allow an authenticated low-privileged user with coarse `Events=View` and/or `Snapshots=View…
  3. CVE-2026-54248
    — CVSS 6.5 (MEDIUM)

    Doco-CD is a GitOps continuous delivery tool that automatically deploys and updates Docker Compose projects/services and Swarm stacks. Prior to version 0.90.1, a trust-boundary flaw in OCI artifact verification allowed a…
  4. CVE-2026-54241
    — CVSS 7.4 (HIGH)

    libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate the sample adaptive offset input-buffer size, allowing a crafted HEVC stream with larg…
  5. CVE-2026-54240
    — CVSS 7.4 (HIGH)

    libde265 is an open source implementation of the h.265 video codec. Versions prior to 1.1.1 use signed 32-bit arithmetic to calculate pixel offsets, allowing a crafted HEVC stream with large image dimensions to trigger a…
  6. CVE-2026-50018
    — CVSS 6.5 (MEDIUM)

    Hoverfly is an open source API simulation tool. Prior to version 1.12.8, remote post-serve actions use `http.DefaultClient` without any timeout configuration. When the remote endpoint is unreachable or intentionally slow…
  7. CVE-2026-50013
    — CVSS 7.5 (HIGH)

    Hoverfly is an open source API simulation tool. Prior to version 1.12.8, when Hoverfly is running in Diff mode, the `AddDiff()` function writes to the shared `responsesDiff` map without any synchronization (no mutex). Wh…
  8. CVE-2026-49846
    — CVSS 7.5 (HIGH)

    libks provides foundational support for signalwire C products. Prior to version 2.0.11, `clean_uri()` in libks's HTTP request parser fails to reject URIs whose path has more segments than its internal canonicalization bu…
  9. CVE-2026-48496
    — CVSS 6.2 (MEDIUM)

    OpenTelemetry eBPF Profiler is a production-scale agent for profiling applications across multiple programming languages. Starting in version 0.0.202527 and prior to version 0.0.202622, an unprivileged process can cause…
  10. CVE-2026-54174
    — CVSS 8.3 (HIGH)

    melange allows users to build apk packages using declarative pipelines. Apko prior to version 1.2.9, corresponding to melange prior to version 0.50.4, verified the control section hash (`.PKGINFO` etc.) against the signe…
  11. CVE-2026-54166
    — CVSS 7.1 (HIGH)

    Shelf is a platform for tracking physical assets. Prior to version 1.20.3, authenticated users with the `asset:import` permission can trigger server-side HTTP requests to attacker-controlled URLs through the Asset CSV Co…
  12. CVE-2026-49464
    — CVSS 8.1 (HIGH)

    NL Portal Backend Libraries provide backend components for Dutch government portals that interact with residents, customers, suppliers, and partner organizations. The `nl.nl-portal:taak` package from version 1.5.0 throug…
  13. CVE-2026-49439
    — CVSS 4.3 (MEDIUM)

    OpenRemote is an open-source internet-of-things platform. Prior to version 1.24.1, the predicted datapoint write endpoint allows users with only `read:assets` privileges to write predicted datapoints. Version 1.24.1 fixe…
  14. CVE-2026-45057
    — CVSS 4.9 (MEDIUM)

    matrix-sdk-ui provides GUI-centric utilities on top of matrix-rust-sdk. The message edit validation logic in the `matrix-sdk-ui` crate prior to 0.17.0 is missing a check: when replacing an encrypted event, the replaceme…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · September 12, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com