📰 DAILY THREAT BRIEFING
Monday, September 14, 2026
12 News Items
HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of September 14, 2026.

  1. Hackers exploit Tencent app flaw to deploy GrayRabbit malware
    — Bleeping Computer

    Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Me…
  2. Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
    — The Hacker News

    Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast finan…
  3. CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
    — The Hacker News

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise Scre…
  4. Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
    — Bleeping Computer

    The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CV…
  5. When the Whole Company Adopts AI: What It Does to Your SOC
    — The Hacker News

    Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in t…
  6. Hackers abused Claude to extract secrets from 1.8M Android apps
    — Bleeping Computer

    Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, …
  7. Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
    — Dark Reading

    Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.
  8. CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
    — Dark Reading

    A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and inciden…
  9. Why AI Is So Good at Scamming Humans
    — Dark Reading

    Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to in…
  10. The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)
    — SANS ISC

    I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acq…
  11. ISC Stormcast For Friday, September 11th, 2026 https://isc.sans.edu/podcastdetail/10090, (Fri, Sep 11th)
    — SANS ISC

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
  12. Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
    — SANS ISC

    [This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]

🪲 NVD — Last 20 Scored Vulnerabilities

Latest scored CVEs from the National Vulnerability Database (13441 in last 30 days).
Critical: 2 · High: 3 · Medium: 10 · Low: 5. View full dashboard →

  1. CVE-2026-90606
    — CVSS 9.9 (CRITICAL)

    A security vulnerability has been detected in Totolink A3002MU Hh-B20211125.1046. This issue affects the function formIpv6Setup of the file /boafrm/formIpv6Setup of the component boa. The manipulation of the argument sta…
  2. CVE-2026-90605
    — CVSS 9.9 (CRITICAL)

    A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. This vulnerability affects the function formFilter of the file /boafrm/formFilter of the component boa. Executing a manipulation of the argument ip6ad…
  3. CVE-2026-90604
    — CVSS 3.5 (LOW)

    A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the component Anchor Tag Handler. Performing a manipulation results in cross site scripting. Remote exploitation …
  4. CVE-2025-63842
    — CVSS 5.4 (MEDIUM)

    A Cross-Site Scripting (XSS) vulnerability in the web backend for the Repetico app 1.9.7.31 for Android allows a remote authenticated user to execute arbitrary JavaScript code in the app's context via crafted input in th…
  5. CVE-2024-53922
    — CVSS 5.7 (MEDIUM)

    An issue was discovered in the buffer queue driver in Samsung Automotive Processor Exynos Auto 8890, V7, V9, and V920. Lack of a length check leads to a Denial of Service in the kernel.
  6. CVE-2022-42917
    — CVSS 6.7 (MEDIUM)

    In FRRouting FRR before 8.5, the service user (usually frr) can escalate its privileges to root by monitoring the configuration directory (/etc/frr) and replacing config files upon creation with, for example, symlinks to…
  7. CVE-2026-90603
    — CVSS 7.3 (HIGH)

    A vulnerability was identified in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this issue is some unknown functionality of the file /api/upload-binary of the component S3 Upload. Such manipulation of th…
  8. CVE-2026-90602
    — CVSS 3.5 (LOW)

    A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is the function renderHistory of the file ImageStudio.js of the component Studio Components. This manipu…
  9. CVE-2026-90601
    — CVSS 7.3 (HIGH)

    A vulnerability was found in getzep graphiti up to 0.30.2. Affected is an unknown function of the file server/graph_service/main.py of the component REST API. The manipulation results in improper authentication. The atta…
  10. CVE-2026-90600
    — CVSS 6.3 (MEDIUM)

    A vulnerability has been found in itsourcecode Sales and Inventory System 1.0. This impacts an unknown function of the file /pages/inv_edit1.php. The manipulation of the argument ID leads to sql injection. The attack can…
  11. CVE-2026-15892
    — CVSS 5.3 (MEDIUM)

    The mcumgr SMP settings-management group handlers settings_mgmt_read(), settings_mgmt_write(), and settings_mgmt_delete() in subsys/mgmt/mcumgr/grp/settings_mgmt/src/settings_mgmt.c allocate a key_name buffer (and, for r…
  12. CVE-2026-15891
    — CVSS 7.5 (HIGH)

    The MQTT-SN client keepalive handler process_ping() in subsys/net/lib/mqtt_sn/mqtt_sn.c removes the gateway record after PINGREQ retries are exhausted. It invoked SYS_SLIST_PEEK_HEAD_CONTAINER(&client->gateways, gw, next…
  13. CVE-2026-90599
    — CVSS 4.3 (MEDIUM)

    A flaw has been found in Rizwan17 inventory-management-system up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. This affects an unknown function of the file includes/process.php. Executing a manipulation can lead to cross-…
  14. CVE-2026-90598
    — CVSS 6.3 (MEDIUM)

    A vulnerability was detected in jaygajera17 E-commerce-project-springBoot up to 5e74a46b4b70623d0e4a0c9c4aee3bd1777185d2. The impacted element is the function UserController.updateUser of the file UserController.java. Pe…
  15. CVE-2026-90597
    — CVSS 6.3 (MEDIUM)

    A security vulnerability has been detected in itsourcecode Sales and Inventory System 1.0. The affected element is an unknown function of the file /pages/sup_edit1.php. Such manipulation of the argument ID leads to sql i…
  16. CVE-2026-90596
    — CVSS 6.5 (MEDIUM)

    A weakness has been identified in embedded-graphics up to 0.8.2 on 32-bit. Impacted is the function ImageRaw::new/bytes_per_row of the file src/image/image_raw.rs. This manipulation causes integer overflow. The attack is…
  17. CVE-2026-52297
    — CVSS 2.9 (LOW)

    FFmpeg before 9.0 has an out-of-bounds read because there is insufficiently padded extradata in the MOV parsing path in mov_read_iacb in libavformat/mov.c.
  18. CVE-2026-52296
    — CVSS 2.9 (LOW)

    FFmpeg before 9.0 has an out-of-bounds read because of missing required padding in WMA extradata allocation paths in libavcodec/wmaenc.c.
  19. CVE-2026-35867
    — CVSS 3.1 (LOW)

    A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of the LB-LINK router AC1900_AZ2 V1.0.2 via shell metacharacters, if the device is deployed in a scenario where …
  20. CVE-2026-90595
    — CVSS 6.3 (MEDIUM)

    A security flaw has been discovered in wxiaoqi Spring-Cloud-Platform 1.0/2.2/3.0. This issue affects the function OnlineController.getOnlineInfo of the file aceModules/ace-admin/auth/controller/OnlineController.java. The…

Source: NVD CVE API 2.0


Generated by CryptXNet.ai Threat Intelligence Platform · September 14, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com