# Archive

Browse past daily curated stories

Sep 04 Sep 03 Sep 01 Aug 31 Aug 30 Aug 29 Aug 28 Aug 27 Aug 26 Aug 25 Aug 24 Aug 23 Aug 22 Aug 21 Aug 20 Aug 19 Aug 18 Aug 16 Aug 15 Aug 14 Aug 13 Aug 12 Aug 09 Aug 08 Aug 07 Aug 06 Aug 05 Aug 04 Aug 03 Aug 02

Friday, September 04, 2026

  1. 1
    0
    The Hacker News general
    CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

    CISA added seven flaws to its KEV catalog, including CVE-2026-83548 (CVSS 10.0), a server-side request forgery vulnerability in SonicWall SMA 1000 appliances enabling unauthenticated remote access. Attackers are actively deploying reverse shells and crypto miners via these vulnerabilities. Security teams should treat SonicWall SMA 1000 appliances as an immediate priority given CISA's mandatory federal remediation deadlines.

  2. 2
    0
    The Hacker News general
    Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

    Cisco patched CVE-2026-20212 (CVSS 9.8), a critical unauthenticated RCE flaw in 10 Silicon One-based Nexus 9000 switches, alongside an IOS XR hardening release covering 7 CVEs — two rated 9.8 — with no available workaround for any IOS XR version. The Nexus vulnerability allows a remote attacker to execute arbitrary code as root without authentication. Network defenders running affected Nexus 9000 or IOS XR gear should apply patches immediately given the CVSS scores and lack of mitigations.

  3. 3
    0
    The Hacker News general
    Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

    Citizen Lab, in collaboration with the SHARE Foundation, confirmed that a member of Serbia's student protest movement had their iPhone infected with NSO Group's Pegasus spyware via an iMessage zero-click exploit. This is part of a broader pattern: at least 14 Serbian opposition figures, politicians, and activists have been targeted with advanced spyware since December 2025. The findings reinforce that Pegasus zero-click delivery remains active and is being deployed against civil society targets in Europe.

  4. 4
    0
    BleepingComputer general
    Sality botnet infrastructure dismantled in joint global takedown

    International law enforcement and private partners disrupted the Sality botnet, a peer-to-peer malware network that operated for 23 years — one of the longest-running botnets in history. The takedown leveraged peer list manipulation and URL seizures against Sality's decentralized C2 infrastructure, which had historically resisted disruption. The operation is significant for demonstrating that even highly resilient P2P botnets can be dismantled through coordinated infrastructure manipulation.

  5. 5
    0
    The Hacker News general
    Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

    Thomson Reuters disclosed that its C-Track court case management platform (sold by West Publishing Corporation) was breached in March 2026, with unauthorized access to files from courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada — discovered on June 30, 2026. Exposed records may include SSNs and sealed court data, posing serious risks to individuals involved in sensitive legal proceedings. The 3-month discovery gap underscores persistent blind spots in breach detection for legal infrastructure providers.

  6. 6
    0
    BleepingComputer general
    Critical Elementor Pro flaw exploited to take over WordPress sites

    CVE-2026-32475, a recently patched critical vulnerability in the Elementor Pro WordPress plugin, is being actively exploited to deploy webshells and execute arbitrary server-side commands. Given that Elementor Pro is installed on millions of WordPress sites, the attack surface is substantial. Security teams managing WordPress environments should verify plugin update status and audit for webshell indicators of compromise immediately.

  7. 7
    0
    SecurityWeek general
    OpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity Threshold

    OpenAI's Astra model has become the first AI to cross what SecurityWeek describes as a 'critical cybersecurity threshold,' defined as the ability to independently discover and exploit zero-day vulnerabilities across well-defended systems. This milestone has significant implications for defenders, as it means frontier AI can now function as an autonomous offensive tool without human guidance. Security practitioners should factor AI-accelerated zero-day discovery into threat modeling and patching prioritization timelines.

  8. 8
    0
    BleepingComputer general
    Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

    A critical authentication bypass flaw (CVE-2026-82329) in JFrog Artifactory is being actively exploited to forge admin tokens, granting full administrative access to artifact repositories. JFrog Artifactory is widely used in enterprise CI/CD pipelines, making compromised instances a high-value pivot point for supply chain attacks. Organizations running Artifactory should apply patches immediately and audit for unauthorized token creation in access logs.

  9. 9
    0
    SecurityWeek general
    153 Million Driver License Images Offered on Dark Web

    153 million U.S. and Canadian driver's license images are being offered for sale on dark web forums, allegedly stolen from IDScan.net, a digital ID verification service. The scale of this exposure — affecting a majority of North American licensed drivers — creates significant identity fraud and social engineering risk. Security teams at organizations using IDScan.net for identity verification should assess their exposure and notify affected users.

  10. 10
    0
    Ars Technica Security general
    BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

    A BGP hijacking incident resulted in a threat actor using a technically valid TLS certificate for Softaculous domains to redirect traffic and serve malicious Virtualizor software updates to production servers. The attack demonstrates how BGP route manipulation combined with legitimate-looking certificates can completely undermine software update trust chains. The incident is a practical case study in supply chain risk for infrastructure operators relying on third-party software delivery without additional integrity verification.