📰 DAILY THREAT BRIEFING
Sunday, September 13, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of September 13, 2026.

  1. CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
    — The Hacker News

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise Scre…
  2. Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
    — Bleeping Computer

    The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CV…
  3. When the Whole Company Adopts AI: What It Does to Your SOC
    — The Hacker News

    Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in t…
  4. OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
    — The Hacker News

    The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report publishe…
  5. Hackers abused Claude to extract secrets from 1.8M Android apps
    — Bleeping Computer

    Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, …
  6. Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
    — Dark Reading

    Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.
  7. Florida confirms DMV database breached via stolen police account
    — Bleeping Computer

    The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, sa…
  8. CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
    — Dark Reading

    A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and inciden…
  9. Why AI Is So Good at Scamming Humans
    — Dark Reading

    Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to in…
  10. The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)
    — SANS ISC

    I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acq…
  11. ISC Stormcast For Friday, September 11th, 2026 https://isc.sans.edu/podcastdetail/10090, (Fri, Sep 11th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  12. Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
    — SANS ISC

    [This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (13517 in last 30 days).
Critical: 1 · High: 7 · Medium: 10 · Low: 2. View full dashboard →

  1. CVE-2026-90651
    — CVSS 8.1 (HIGH)

    Socket Firewall (socketdev/socket-registry-firewall) in registry mode before 2.0.0 does not verify upstream TLS certificates by default. When the api_ssl_verify and upstream_ssl_verify configuration keys are omitted from…
  2. CVE-2026-90489
    — CVSS 3.5 (LOW)

    A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobinfo/insert. Such manipulation of the argument name/author leads to cross site scripting. The attack …
  3. CVE-2026-90488
    — CVSS 6.3 (MEDIUM)

    A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass of the file xxl-job-core/src/main/java/com/xxl/job/core/glue/GlueFactory.java. This manipulation cause…
  4. CVE-2026-90647
    — CVSS 7.4 (HIGH)

    ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 2.37 on Windows contains an improper certificate validation vulnerability in the IEC 60870-5-104 TLS client (Task Mode). This allows a network-positioned attac…
  5. CVE-2026-90487
    — CVSS 4.3 (MEDIUM)

    A vulnerability was found in Xuxueli xxl-job up to 3.4.2. Affected by this issue is some unknown functionality of the file xxl-job-admin/src/main/java/com/xxl/job/admin/business/controller/JobGroupController.java. The ma…
  6. CVE-2026-90486
    — CVSS 6.3 (MEDIUM)

    A vulnerability has been found in openstatusHQ openstatus up to f04c827112f30a11d571ebdad3892826034d6265. Affected by this vulnerability is an unknown functionality of the file apps/status-page/src/lib/proxy/resolve-cust…
  7. CVE-2026-79300
    — CVSS 3.5 (LOW)

    SEP sesam before 5.2.0.24 mishandles User Authorization with MFA. If AD authentication is configured and MFA is enforced, an attacker can create a second OTP access capability. SEP sesam and Active Directory handle usern…
  8. CVE-2026-90485
    — CVSS 5.5 (MEDIUM)

    A flaw has been found in IOBit Uninstaller 15.5.0.11. Affected by this issue is the function sub_11838 of the file IURegistryFilter.sys of the component IOCTL Dispatch Handler. This manipulation causes null pointer deref…
  9. CVE-2026-90616
    — CVSS 7.4 (HIGH)

    In Flatpak before 1.18.1, a malicious sandboxed app can obtain arbitrary read and write access to files on the host, which can be escalated to arbitrary code execution on the host, a different vulnerability than CVE-2026…
  10. CVE-2026-90560
    — CVSS 8.2 (HIGH)

    zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Atta…
  11. CVE-2026-90559
    — CVSS 7.5 (HIGH)

    snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed size. Attackers can supp…
  12. CVE-2026-90558
    — CVSS 9.8 (CRITICAL)

    sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets with oversized Call-…
  13. CVE-2026-90557
    — CVSS 6.1 (MEDIUM)

    Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a malicious savegame file…
  14. CVE-2026-90556
    — CVSS 7.8 (HIGH)

    Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers can craft malicious …
  15. CVE-2026-90555
    — CVSS 6.5 (MEDIUM)

    vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC headers with inflated sampl…
  16. CVE-2026-90554
    — CVSS 6.2 (MEDIUM)

    vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video input for NanoNemotronVL models. In nano_nemotron_vl.py, _extract_audio_from_videos calls load_audi…
  17. CVE-2026-90553
    — CVSS 7.8 (HIGH)

    vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers can craft a maliciou…
  18. CVE-2026-90552
    — CVSS 4.3 (MEDIUM)

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authenticated and unauthent…
  19. CVE-2026-90551
    — CVSS 5.3 (MEDIUM)

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_from_program API endpoint, allowing unauthenticated access to private playlist contents. Attackers can…
  20. CVE-2026-90550
    — CVSS 5.3 (MEDIUM)

    WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins mediaSession.json.php endpoint before returning video metadata. Unauthenticated attackers can reque…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · September 13, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com