# Archive
Browse past daily curated stories
Thursday, September 03, 2026
-
1Krebs on Security threat-intelFBI Probes Service Selling 153M+ Drivers Licenses
A dark web identity theft service is selling digital scans of over 153 million U.S. and Canadian driver's licenses, apparently siphoned from a Louisiana-based identity verification company. The FBI's New Orleans field office has opened an investigation, and KrebsOnSecurity confirmed victims' licenses are available for purchase. This represents one of the largest identity document breaches on record and directly threatens the integrity of KYC verification pipelines used across financial services.
-
2The Hacker News generalAttackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
SonicWall has patched two zero-day vulnerabilities in its SMA 1000 series VPN appliances — CVE-2026-83548 (CVSS 10.0, pre-auth SSRF) and CVE-2026-83549 — that threat actors are actively chaining to achieve unauthenticated remote code execution. Discovered internally by SonicWall's William Perry and Adam Babis, these follow earlier zero-day attacks on the vendor's edge devices this summer. SMA 1000 appliances are widely deployed as enterprise remote access gateways, making prompt patching critical.
-
3The Hacker News generalAuthorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads
On August 31, 2026, U.S., Bulgarian, Hungarian, and Romanian authorities — alongside CrowdStrike and the Shadowserver Foundation — dismantled the Sality botnet, a peer-to-peer malware network that had operated for 23 years. The operation turned Sality's own P2P infrastructure against itself through peer list manipulation and payload URL takedowns, cutting infected hosts off from operator commands. Sality's longevity stemmed from its decentralized architecture, which had previously resisted conventional takedown approaches.
-
4The Record threat-intelHealth data of more than 9.5 million people leaked from Aesto record system
Healthcare data company Aesto informed federal regulators that a cyberattack last December exposed sensitive personal and health information belonging to more than 9.5 million individuals. The breach was disclosed in filings with HHS, making it one of the largest healthcare data incidents of 2026. Security teams in the healthcare sector should audit third-party record management vendors, as Aesto operated as a backend records system for multiple providers.
-
5The Hacker News generalAttackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
CVE-2026-82329, a CVSS 9.8 authentication bypass in JFrog Artifactory, is being actively exploited just days after public disclosure, with attackers forging administrative tokens on affected instances. Watchtowr confirmed in-the-wild exploitation, noting the flaw stems from an authentication weakness present in default configurations. JFrog Artifactory is a widely used artifact repository in CI/CD pipelines, and admin-level compromise could enable supply chain attacks via poisoned build artifacts.
-
6The Hacker News generalBGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access
Threat actors executed a BGP hijack against Softaculous update infrastructure to deliver a malicious Virtualizor VPS management update package, establishing persistent root access on compromised hypervisors. The attack window ran from approximately August 28 at 20:57 UTC, and a hosting provider confirmed root-level compromise on 5 of 34 checked Virtualizor nodes. The use of a technically valid TLS certificate for Softaculous domains allowed the attack to bypass certificate validation checks, underscoring BGP's role as a critical trust dependency.
-
7CyberScoop generalPegasus, NoviSpy variant spyware found on devices of Serbian activists
Citizen Lab has forensically confirmed the first Pegasus infection of 2026, found alongside a NoviSpy variant on devices belonging to Serbian activists in what the SHARE Foundation describes as the largest wave of spyware surveillance in Serbia to date. The findings indicate continued proliferation of commercial surveillance tools against civil society outside their ostensible law enforcement use cases. Security practitioners working with at-risk communities should audit iOS and Android devices using Amnesty International's MVT tooling.
-
8The Hacker News generalAttackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
CVE-2026-9586, a CVSS 9.3 unauthenticated SQL injection flaw in Sangoma Switchvox SMB Edition 8.3 (build 104997), is being actively exploited to deploy reverse shells without credentials on enterprise VoIP infrastructure. The vulnerability allows full remote code execution on affected systems, which are commonly deployed for PBX functions in SMB environments. Organizations running Switchvox should apply available patches immediately and audit for indicators of reverse shell activity.
-
9BleepingComputer generalNearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Nearly 22,000 Microsoft Exchange servers exposed to the internet remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes on affected instances. The scale of exposure is particularly significant given Exchange's role as a primary email and calendar infrastructure component in enterprise environments. Administrators should cross-reference their Exchange deployments against Microsoft's patching guidance and prioritize internet-facing instances.
-
10The Hacker News generalMalicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Manifold Security disclosed eight security flaws across seven command-line AI coding agents — including Claude, OpenAI Codex, and Cursor — where malicious .git configuration files can execute attacker-supplied commands on a developer's machine at the user's privilege level, outside any sandbox and without an approval prompt. Four of the eight vulnerabilities remained unpatched at time of publication. The attack vector requires only that a developer clone or interact with a malicious repository, making this a realistic supply chain risk for development teams adopting AI coding assistants.