# Today's Top Stories
September 05, 2026
-
1BleepingComputer general Sep 04Critical Citrix NetScaler auth bypass now leveraged in attacks
CVE-2026-19490, a critical authentication bypass flaw in Citrix NetScaler, is now being actively exploited in the wild according to vulnerability intelligence firm Previdian. Security teams running NetScaler appliances should treat this as an emergency patching priority, as auth bypass vulnerabilities in widely deployed network infrastructure frequently precede large-scale breaches.
-
2The Hacker News general Sep 04Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google released Chrome 152.0.7977.82 to patch CVE-2026-85046, a high-severity (CVSS 8.8) type confusion bug in the V8 JavaScript/WebAssembly engine that is already being actively exploited in the wild — the 6th Chrome zero-day of 2026. All Chrome users and enterprise fleet managers should prioritize immediate updates, as V8 type confusion flaws are routinely leveraged for sandbox escapes and remote code execution.
-
3SecurityWeek general Sep 0412-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
CVE-2026-6471, dubbed PostGREShell, is a 12-year-old logical decoding flaw in PostgreSQL present since version 9.4 (2014) that allows an account with the REPLICATION attribute to execute arbitrary code as the OS user running the database. Affected versions include all PostgreSQL releases before 18.6, 17.11, 16.15, 15.19, and 14.24, meaning unpatched deployments face risks of database takeover and persistent backdoor installation.
-
4BleepingComputer general Sep 04New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
A researcher using the handle 'Nightmare Eclipse' released a public PoC exploit called FalconFlank that abuses CrowdStrike Falcon Sensor's malicious macro remediation feature to escalate privileges to SYSTEM on fully up-to-date Windows systems. The zero-day is particularly significant given CrowdStrike's ubiquitous deployment across enterprise security environments, making it a high-value target for attackers seeking to subvert endpoint detection tools.
-
5SecurityWeek general Sep 04HPE Patches Critical RCE Vulnerabilities in AOS-CX
HPE patched nearly two dozen vulnerabilities in ArubaOS-CX, collectively tracked as CVE-2026-73749 with a maximum CVSS score of 9.8, enabling remote code execution on affected network switches. Organizations running ArubaOS-CX in their network infrastructure should apply updates immediately given the critical severity and RCE potential.
-
ADSponsoredProtect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected → -
6The Hacker News general Sep 04Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft's Security Research team flagged a high-volume phishing campaign using invisible Unicode tag characters to split financial lure keywords like 'funding,' bypassing email security filters that parse message content. This technique, originally associated with AI prompt injection attacks, has now been weaponized at mass scale against email security tooling, requiring defenders to update filter logic beyond simple keyword matching.
-
7BleepingComputer general Sep 04IDScan sued over alleged data breach affecting 153 million drivers
Identity verification company IDScan faces multiple lawsuits after hackers allegedly breached the service and offered to sell data on more than 153 million driver's licenses. The breach affects a company that provides ID scanning services across numerous industries, meaning the compromised data likely spans a wide cross-section of the US population with high-fidelity identity documents.
-
8The Hacker News general Sep 04Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Wordfence documented over 440,000 exploit attempts targeting two critical WordPress plugin vulnerabilities: CVE-2026-14894 (CVSS 9.8) in Super Forms allowing unauthenticated arbitrary file upload, and a separate critical RCE flaw in Elementor Pro. The attack volume targeting these plugins indicates active, widespread exploitation campaigns that place millions of WordPress sites at risk.
-
9CyberScoop general Sep 03Attackers exploit zero-days in consistently besieged SonicWall product
SonicWall SMA 1000 appliances have now seen five actively exploited vulnerabilities since late 2025, with attackers continuing to target zero-days in the consistently besieged product line. Security teams relying on SonicWall SMA 1000 for remote access should evaluate compensating controls and patch cadence given the product's sustained exploitation history.
-
10SecurityWeek general Sep 03Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal
A hacker group leaked approximately 550GB of data belonging to Manchester Airports Group (MAG), affecting 8.8 million people, after the organization refused to pay a ransom demand. The attackers reportedly gained initial access via exposed admin keys, underscoring the persistent risk of credential and key exposure in large infrastructure operators.