Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
satellite_altDaily BriefCyber Threat Daily Brief — September 4, 2026
Today's briefing: 14 critical and 22 high-severity threats. A total of 47 detailed analyses covering vulnerabilities, threat actors, and geopolitical context.
Latest Reports
28 / 1172 results
highpublicGeopoliticalFrance fines hospital €500K for breach exposing 727,000 patient records
The enforcement action by France's CNIL represents a continuation of robust data protection regulatory activity under the EU's General Data Protection Regulation (GDPR) framework.
highbug_reportVulnerabilityCoder registry compromised via Cloudflare to deliver malicious Terraform modules
Coder registry infrastructure (registry.coder.com) accessed via compromised Cloudflare configuration. Users who downloaded Terraform modules between 07:35 and 21:45 UTC on August 31, 2026 potentially affected.
criticalbug_reportVulnerabilityHPE patches critical RCE in ArubaOS-CX network switches (CVE-2026-73749)
ArubaOS-CX network operating system on HPE Aruba enterprise switches. Affected versions: 10.18.0001, 10.17.1021 and earlier, 10.16.1051 and earlier, 10.13.1180 and earlier, 10.10.1180 and earlier.
highbug_reportVulnerability5,000 Dropbox accounts compromised; OAuth and Teams phishing campaigns active
Multiple attack vectors: 5,000+ compromised Dropbox accounts, Microsoft Teams users across 150+ employees in 10+ organizations, OAuth-based applications, and users of phishing-as-a-service kits (BlueKit, Outsider).
criticalbug_reportVulnerabilityCisco patches critical RCE in Nexus 9000 and 7 IOS XR umbrella CVEs
Cisco Silicon One-based Nexus 9000 switches (10 models, NX-OS 10.3(1) through 10.6(3s)) via CVE-2026-20212. All Cisco IOS XR releases across all platforms via 7 umbrella CVEs (CVE-2026-20274 through 20280), including XR7 (LNT) platforms: Cisco 8000 S…
highbug_reportVulnerabilityBraZetsu malware framework enables Initial Access Broker marketplace
Windows hosts in Iberian Peninsula and Latin America, particularly Brazil. Primary targets: e-commerce, corporate, financial, industrial, and law enforcement sectors. Browsers affected: Google Chrome, Microsoft Edge, Brave, Vivaldi, Opera.
criticalbug_reportVulnerabilityElementor Pro CVE-2026-32475 actively exploited for webshell uploads
Elementor Pro plugin for WordPress versions 4.2.1 and earlier. Affects sites with published Elementor Pro Form widgets containing File Upload fields. Over 6 million active installations potentially at risk.
highpublicGeopoliticalThomson Reuters C-Track breach exposes U.S. and Canadian court records
The March 2026 breach of Thomson Reuters' C-Track court case management platform represents a significant compromise of judicial infrastructure across multiple U.S. state and Canadian provincial jurisdictions.
highbug_reportVulnerabilityRMM phishing campaign hits 46 countries, US accounts for 45% of activity
Organizations across 46 countries, primarily United States (45% of activity), Canada, and others. Top targeted sectors: education, technology, government, banking, finance, and manufacturing.
highbug_reportVulnerabilityPlex urges immediate patching of undisclosed flaws in Media Server
Plex Media Server v1.43.2 and earlier, Plex Desktop client versions prior to 1.115.0. Affects all platforms including Windows, macOS, Linux, and NAS devices running Plex.
highbug_reportVulnerabilityAttackers abuse legitimate Node.js runtime to evade detection in attacks
Organizations using Node.js in their environments, particularly government departments, technology companies, hotels, fintech, e-commerce, professional services, and retail logistics.
highbug_reportVulnerabilityShai-Hulud infostealer now targets 469 credential locations in dev tools
Developer workstations, CI/CD pipelines, cloud configurations, AI tool configs, package registries (npm, GitHub, Docker), and any environment storing long-lived credentials or tokens.
highbug_reportVulnerabilityAI-assisted campaigns target Latin American orgs with data exfiltration
Organizations in Latin America, specifically: Mexican transportation sector, federal government ministries, municipal water utilities in Mexico and Ecuador (CL-CRI-1131); Brazilian financial sector (CL-CRI-1163).
highperson_alertThreat ActorNSO Group Pegasus deployed via zero-click iMessage exploit in Serbia
NSO Group is an Israeli cyber intelligence company that develops and sells Pegasus spyware to government clients. The company markets its surveillance technology as a tool for law enforcement and intelligence agencies to combat terrorism and crime.
highbug_reportVulnerabilityCrowdStrike Falcon zero-day FalconFlank allows privilege escalation
CrowdStrike Falcon Sensor on Windows 11 25H2 and Windows Server 2025 (all current versions). The vulnerability exploits the Office malicious macros remediation feature.
criticalbug_reportVulnerabilitySonicWall SMA 1000 SSRF flaw (CVE-2026-83548) exploited in the wild
SonicWall SMA 1000 Appliances. CVE-2026-83548 is a server-side request forgery (SSRF) vulnerability with CVSS 10.0, allowing remote unauthenticated attackers to gain unauthorized access. Specific affected versions not disclosed.
highbug_reportVulnerabilityAttackers abuse Microsoft Teams external chat to impersonate IT support
Microsoft Teams users in enterprise environments with external collaboration enabled. All organizations using Teams for business communication are at risk if users accept external contact requests and grant remote access via RMM tools or Quick Assist…
criticalbug_reportVulnerabilitySangoma Switchvox SQL injection exploited for remote code execution
Sangoma Switchvox VoIP platform versions prior to 8.4.0.2. Approximately 4,000 internet-exposed instances globally, primarily in the United States. Vulnerability CVE-2026-9586 affects the unauthenticated /pa HTTP endpoint.
criticalbug_reportVulnerabilityAll-in-One WP Migration plugin SQL injection enables site takeover
All-in-One WP Migration and Backup plugin for WordPress, versions through 7.109. Over 5 million active installations, with approximately 3.25 million sites (65%) still running vulnerable versions. Fixed in version 7.110.
highbug_reportVulnerabilitySilver Fox campaign uses fake installers to disable Windows Update
Windows systems globally, primarily China-based operations of multinational organizations and Chinese-speaking users across healthcare, manufacturing, gaming, technology, logistics, government, and education sectors.
criticalbug_reportVulnerabilityJFrog Artifactory auth bypass exploited to forge admin tokens
JFrog Artifactory self-managed instances in default configuration. Patched in versions 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20 (released August 28, 2026). JFrog Cloud environments already protected.
criticalbug_reportVulnerabilitySonicWall SMA1000 RCE vulnerabilities under active exploitation
SonicWall SMA1000 series appliances. Specific vulnerable versions not disclosed in available information. Vulnerabilities enable remote code execution.
criticalbug_reportVulnerabilityLangflow RCE vulnerability under active exploitation, patch immediately
Langflow (specific versions not disclosed in available data). The vulnerability affects Langflow installations exposed to network access. No CVE assigned yet.
highbug_reportVulnerabilityAI coding agents execute malicious Git config commands outside sandbox
Seven command-line AI coding agents: goose (fixed in 1.44.0), Codex CLI/Desktop (fixed in 0.131.0 / 26.519.x), Claude Code (partially fixed in 2.1.196, second path unpatched in 2.1.252+), Hermes Agent 0.18.2–0.21.0 (unpatched), Qwen Code 0.19.6–0.22.…
highperson_alertThreat ActorGambling Goblin Hijacks Brazilian Gov Sites via Malicious Apache Modules
Gambling Goblin is a Chinese-speaking cybercrime cluster tracked by Check Point Research since mid-2025. The group specializes in SEO manipulation at scale by compromising high-reputation domains, particularly Brazilian government (.gov.br) and educa…
criticalbug_reportVulnerabilityBGP hijack delivers malicious Virtualizor update with root backdoor
Virtualizor hypervisor management software (all versions) from Softaculous. Attack window: August 28, 2026 20:57 UTC to August 30, 2026 06:10 UTC. Any installation that checked for updates during this period may be compromised.
highperson_alertThreat ActorStreamRat Android Banking Trojan Spread via Meta Ads to EU Users
ThreatFabric is the cybersecurity research firm that discovered and analyzed the StreamRat campaign. The actual threat actor behind StreamRat remains unattributed.
criticalbug_reportVulnerabilitySonicWall SMA 1000 VPN zero-days exploited in chained attacks
SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances: models 6210, 7210, and 8200v running versions 12.4.3-03453 and older, or 12.5.0-02835 and older.