HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of September 14, 2026.
-
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
— Bleeping Computer
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Me… -
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
— The Hacker News
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast finan… -
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
— The Hacker News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise Scre… -
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
— Bleeping Computer
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CV… -
When the Whole Company Adopts AI: What It Does to Your SOC
— The Hacker News
Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in t… -
Hackers abused Claude to extract secrets from 1.8M Android apps
— Bleeping Computer
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, … -
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
— Dark Reading
Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI. -
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
— Dark Reading
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and inciden… -
Why AI Is So Good at Scamming Humans
— Dark Reading
Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to in… -
The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)
— SANS ISC
I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acq… -
ISC Stormcast For Friday, September 11th, 2026 https://isc.sans.edu/podcastdetail/10090, (Fri, Sep 11th)
— SANS ISC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. -
Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
— SANS ISC
[This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (13441 in last 30 days).
Critical: 2 · High: 3 · Medium: 10 · Low: 5. View full dashboard →
-
CVE-2026-90606
— CVSS 9.9 (CRITICAL)
A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument sta⦠-
CVE-2026-90605
— CVSS 9.9 (CRITICAL)
A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6ad⦠-
CVE-2026-90604
— CVSS 3.5 (LOW)
A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler. Performing a manipulation results in cross site scripting. Remote exploitation ⦠-
CVE-2025-63842
— CVSS 5.4 (MEDIUM)
A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user to execute arbitrary JavaScript code in the app's context via crafted input in th⦠-
CVE-2024-53922
— CVSS 5.7 (MEDIUM)
An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check leads to a Denial of Service in the kernel. -
CVE-2022-42917
— CVSS 6.7 (MEDIUM)
In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to⦠-
CVE-2026-90603
— CVSS 7.3 (HIGH)
A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of th⦠-
CVE-2026-90602
— CVSS 3.5 (LOW)
A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipu⦠-
CVE-2026-90601
— CVSS 7.3 (HIGH)
A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The atta⦠-
CVE-2026-90600
— CVSS 6.3 (MEDIUM)
A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the argument ID leads to sql injection. The attack can⦠-
CVE-2026-15892
— CVSS 5.3 (MEDIUM)
The mcumgr SMP settings-management group handlers settings_mgmt_read(), settings_mgmt_write(), and settings_mgmt_delete() in subsys/mgmt/mcumgr/grp/settings_mgmt/src/settings_mgmt.c allocate a key_name buffer (and, for r⦠-
CVE-2026-15891
— CVSS 7.5 (HIGH)
The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next⦠-
CVE-2026-90599
— CVSS 4.3 (MEDIUM)
A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the file includes/process.php. Executing a manipulation can lead to cross-⦠-
CVE-2026-90598
— CVSS 6.3 (MEDIUM)
A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. The impacted element is the function UserController.updateUser of the file UserController.java. Pe⦠-
CVE-2026-90597
— CVSS 6.3 (MEDIUM)
A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/sup_edit1.php. Such manipulation of the argument ID leads to sql i⦠-
CVE-2026-90596
— CVSS 6.5 (MEDIUM)
A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is⦠-
CVE-2026-52297
— CVSS 2.9 (LOW)
FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c. -
CVE-2026-52296
— CVSS 2.9 (LOW)
FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c. -
CVE-2026-35867
— CVSS 3.1 (LOW)
A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where ⦠-
CVE-2026-90595
— CVSS 6.3 (MEDIUM)
A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. Theâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · September 14, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment