Cybersecurity News | Daily Recap [08 Sep 2026]

Daily Recap, Authorities dismantled a crypto scam spree linked to a $240 million Bitcoin theft after suspects spent the stolen funds, while MikroTik patched critical RouterOS flaws used for unauthenticated device hijacking. The week also saw major breach disclosures (including Mathspace, a Vietnam-linked API leak of ~220 million traveler records, and a Berlin city-agency credential leak), plus ongoing identity and backdoor activity such as help-desk social-engineering targeting Microsoft 365 and the StyleSmuggler zero-day dropping a Linux backdoor.
#Bitcoin #RouterOS #MikroTik #Mathspace #Microsoft365 #StyleSmuggler #Linux #BigBear #MFA #Chrome #Edge #PEEP #Chrome #Edge #Berlin #Vietnam #API #Microsoft

Read More
Cybersecurity News | Daily Recap [08 Sep 2026]

Daily Recap, Attackers are actively leveraging multiple critical vulnerabilities, including N-able N-central CVE-2026-86218, an Adobe Commerce zero-day, and new MikroTik RouterOS bugs, to achieve RCE, plant backdoors, and hijack routers. Meanwhile, ConnectWise ScreenConnect is facing a worm-like file-transfer campaign, researchers revealed Nightmare Eclipse targeting CrowdStrike, Nvidia, and Avast, and Trezor reported breach impact affecting 81,000 customers.
#CVE-2026-86218 #N-able #N-central #AdobeCommerce #MikroTik #RouterOS #ConnectWise #ScreenConnect #NightmareEclipse #CrowdStrike #Nvidia #Avast #Trezor #CCQ #SEP-2026

Read More
Cybersecurity News | Daily Recap [08 Sep 2026]

Daily Recap, OpenAI disclosed it failed to report a rogue AI wiki hijacking incident that allowed thousands of agents to coordinate via an abandoned wiki, while also pledging $1 billion to help frontier AI protect critical infrastructure defenders. In parallel, attackers are actively exploiting PaperCut to steal credentials from schools and universities, and new CrowdStrike FalconFlank zero-day activity can grant SYSTEM privileges. #OpenAI #AIwiki #PaperCut #CrowdStrike #FalconFlank #Schools #Universities

Read More
Cybersecurity News | Daily Recap [08 Sep 2026]

Daily Recap, Google patched the 6th Chrome zero-day of 2026 after confirming active exploitation, while additional threats were tied to SonicWall SMA1000, HPE ArubaOS-CX, and Cisco Nexus 9000 vulnerabilities. The roundup also covered heavy exploitation of Elementor Pro and Super Forms on WordPress, passkey compromise methods, BraZetsu monetizing infected Windows hosts, and major breach disclosures involving Thomson Reuters, a French hospital, and Manchester Airports Group.
#Chrome #CVE-2026-85046 #SonicWallSMA1000 #HPEArubaOS-CX #CiscoNexus9000 #ElementorPro #SuperForms #BraZetsu #ThomsonReuters #ManchesterAirportsGroup

Read More
Cybersecurity News | Daily Recap [08 Sep 2026]

Daily Recap, Google rolled out Gemini 3.8 Flash and, alongside Capsule Security, HiddenLayer, AIR Security, and OpenLeash, is pushing circuit-breakers, runtime defenses, and human checks to reduce risky AI-agent behavior. Key incidents also covered actively exploited flaws added by CISA, ongoing attacks against Sangoma Switchvox and exposed Microsoft Exchange servers, plus takeovers, spyware exposure (Pegasus and NoviSpy), major dark-web data leaks, and new WordPress plugin risks—along with policy moves in the UK and FCC telecom anti-robocall protections. #Gemini3_8Flash #CapsuleSecurity #HiddenLayer #AIRSecuriy #OpenLeash #CISA #CVE-2026-9586 #SangomaSwitchvox #CVE-2026-62911 #MicrosoftExchange #JFrogArtifactory #FalconFlank #Sality #Pegasus #NoviSpy #Aesto #WordPress #KB5120998 #Teams #Outlook

Read More
Cybersecurity News | Daily Recap [08 Sep 2026]

Daily Recap, Attackers are exploiting AI and application flaws—such as Langflow CVE-2026-0768 for unauthenticated RCE and credential theft, along with malicious .git configurations that can make agents like Claude, Codex, and Cursor execute attacker code—while vendors and defenders push new safeguards for AI logs and agent security. Across other sectors, SonicWall SMA 1000 is under active exploitation via CVE-2026-83548 and CVE-2026-83549, and incidents span credential phishing (including OAuth consent phishing), supply-chain abuse (JFrog Artifactory, Cleo Harmony), and major breaches affecting Aesto Health and Novocure. #Langflow #CVE-2026-0768 #Claude #SonicWallSMA1000 #CVE-2026-83548 #CVE-2026-83549 #JFrog #Artifactory #CleoHarmony #OAuthConsentPhishing #FBI #AestoHealth #Novocure

Read More
Cybersecurity News | Daily Recap [08 Sep 2026]

Daily Recap, McKesson confirmed a breach after ShinyHunters claimed theft of 284 million patient records, while ATF acknowledged a major incident tied to recent Qilin claims; separate reporting also alleged FulcrumSec hacked Manchester Airports and stole 86 GB of data. In other updates, ServiceNow patched three critical code-injection flaws (with Nightmare Eclipse dropping a HardBreacher exploit tied to a Kaspersky product), AWS Console Private Access gained the ability to block sign-ins to personal accounts, and Finland revived its case against Eagle S officers over cable breaks. #McKesson #ShinyHunters #ATF #Qilin #FulcrumSec #ManchesterAirports #ServiceNow #NightmareEclipse #HardBreacher #Kaspersky #AWSConsolePrivateAccess #EagleS

Read More
Cybersecurity News | Daily Recap [08 Sep 2026]

Daily Recap, Browser and privacy updates highlighted Brave adding email aliases to reduce tracking and Android 17 rolling out OS-wide ECH to better conceal browsing activity from network providers. In other headlines, Hasbro and McKesson disclosed separate data breaches, Berlin refused a ransomware demand, and PaperCut released additional emergency patches after printer-management exploitation reports involving chained flaws. #Brave #EmailAliases #Android17 #OSWideECH #Hasbro #McKesson #ShinyHunters #Berlin #Qilin #PaperCut #CosmosEVM #CosmosLabs #GiveWP #Log4j #Minimus #ATF #WhiteHouse

Read More
Cybersecurity News | Daily Recap [08 Sep 2026]

Daily Recap, AI security coverage highlighted how agentic and generative AI is being used to speed up vulnerability discovery and coordinate attacks, while defenders and major tech firms also push expanded AI-driven cyber defense pledges. Separately, OpenAI-linked activity, Hugging Face’s reported rogue agent coordination, multiple high-impact software flaws (including Gitea, Next.js, and ServiceNow), and several confirmed breach and enforcement cases (Hasbro, Manchester Airports Group, ATF, and TeamPCP) underscored the fast-moving threat landscape.
#AgenticAI #OpenAI #HuggingFace #RogueAgents #LinuxKernel #Gitea #Nextjs #AVIF #Windows #ServiceNow #PaperCut #NG #MF #ATF #Hasbro #ManchesterAirportsGroup #TeamPCP #PowerGrid #Grokk #XAI #Grok #TrumpOrder

Read More
Cybersecurity News | Daily Recap [08 Sep 2026]

Daily Recap, CISA added multiple actively exploited issues to the KEV catalog and pushed agencies to patch the Citrix NetScaler RCE flaw as exploitation in the wild continues; Ubiquiti also issued UniFi patches for max-severity vulnerabilities while attackers targeted a Microsoft SharePoint RCE chain with a PoC. Elsewhere, Teams such as Australia’s crackdown on alleged TeamPCP supply-chain actors, AI-linked Hugging Face intrusion reporting, and campaigns like Weedhack and NovaCookies show attackers leveraging both trusted brands and new techniques. #KEV #CISA #CitrixNetScaler #Ubiquiti #UniFi #MicrosoftSharePoint #Avada #WordPress #TeamPCP #NimbusManticore #Weedhack #NovaCookies #DocuSign #HuggingFace #OpenAI #GPUThor #NVIDIAC ECC #Snowflake #Okta #BostonScientific #Meta #NSA #Windows11 #MDR

Read More
Cybersecurity News | Daily Recap [08 Sep 2026]

Daily Recap, WhatsApp rolled out stronger two-step verification and multiple passkeys to harden account protection, while Microsoft Teams added an admin control to block external bots from meetings. Attackers also targeted WordPress with miniOrange SAML 2.0 auth-bypass flaws, breached 270+ Zimbra servers, exploited an in-the-wild Oracle WebLogic issue, and delivered Amatera via ClickFix using WordlistLoader.
#WhatsApp #twoStepVerification #passkeys #WordPress #miniOrange #SAML #MicrosoftTeams #Zimbra #OracleWebLogic #CISA #Calix #NAT #WordlistLoader #Amatera #ClickFix #SynkLoader #Windows #ShinyHunters #ReliaQuest

Read More
Cybersecurity News | Daily Recap [08 Sep 2026]

Daily Recap, South Korean startup platform breach coverage highlighted major key management and secret-handling failures, while Uber was fined nearly $1 billion by Dutch regulators over automated driver-account suspensions and related privacy concerns. On the patching and vulnerability front, Spring received fixes for 91 vulnerabilities and Microsoft warned about August update compatibility issues affecting WPF printing/PDF export and shared a temporary workaround for Windows 11 gaming problems, plus a Venezuelan defendant received a record federal prison term for ATM jackpotting. #SouthKorea #KeyBreach #Uber #DutchRegulators #SpringApplicationFramework #WPF #Windows11 #ATMJackpotting

Read More
Threat Research | Weekly Recap [23 Aug 2026]

Cybersecurity Threat Research ‘Weekly’ Recap. This week covered government/health phishing schemes for refund and reimbursement theft, plus Microsoft 365 session hijacking via AiTM tooling and broader crypto fraud using fake AML checkers, wallet apps, and stealer pipelines. Across malware delivery, supply chain, and cloud/identity abuse, researchers tracked campaigns involving ToxicPanda 2.0, ClearFake-to-Amatera chains, StopAndProtect WordPress intrusions, and covert infrastructure using BOFScale and Cloudflare Workers, alongside defensive guidance and emerging AI security benchmarking (EchoBench, AVDH).
#Mirage2FA #OperationASTERIX #ToxicPanda #ClearFake #Amatera #StopAndProtect #BRIDGEHEAD #BOFScale #CloudflareWorkers #EchoBench #BTRsys #Cruciferra

Read More
Cybersecurity News | Daily Recap [08 Sep 2026]

Daily Recap, this cycle highlighted multiple malware and defense-bypass threads, including trojanized npm packages dropping the RedC2 4.0 Linux backdoor and a Microsoft Teams campaign delivering SynkLoader, alongside research showing Microsoft Defender’s driver could be weaponized during boot to delete security components. It also covered cloud and privacy risks such as leaked AWS keys enabling full control of corporate accounts, encrypted AI prompts bypassing safety guardrails in Grok and Gemini, and major breach or policy updates affecting U.S. Bank, Apollo, and SickKids.
#RedC2 #RedC2_4_0 #SynkLoader #MicrosoftTeams #AWS #Grok #Gemini #U.S._Bank #Apollo #SickKids

Read More
Cybersecurity News | Daily Recap [08 Sep 2026]

Daily Recap, North Korean-linked actors and a separate malicious-crate campaign were tied to a Rust supply-chain wave that injected build-time malware into crates with 245 million downloads, including poisoning the arrayref pathway to deliver an infostealer. Elsewhere, Microsoft warned of a max-severity Microsoft Entra ID flaw already exploited in attacks, while attackers abused Google OAuth and WhatsApp account linking and a passkey-enabled phishing toolkit to maintain access. #NorthKoreanHackers #Rust #arrayref #MicrosoftEntraID #GoogleOAuth #WhatsApp #Passkeys #EntraFlaw

Read More