NeoShield Security logo NeoShield Security Quantum X

// GLOBAL CYBER DEFENSE FEED

Latest worldwide cybersecurity updates with instant mitigation guidance.

Auto-refreshes from official public security feeds and falls back safely if the remote feed is unavailable.

live Updated 2026-09-04 16:09
18

Tracked items

1

Critical alerts

1h

Cache refresh cycle

Live cyber update stream

highThe Hacker News

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The

Mitigation: Harden SPF/DKIM/DMARC, block sender infrastructure, inspect mailbox rules, and require MFA re-authentication.

Open source →

highBleepingComputer

Critical Citrix NetScaler auth bypass now leveraged in attacks

Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]

Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.

Open source →

highThe Hacker News

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are

Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.

Open source →

highThe Hacker News

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and

Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.

Open source →

lowBleepingComputer

Microsoft says some users can’t open the Teams desktop client

Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. [...]

Mitigation: Apply security updates, prioritize domain controllers and internet-facing Windows services, then monitor authentication anomalies.

Open source →

highBleepingComputer

39 New Methods That Compromise Passkey Authentication

Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography. [...]

Mitigation: Rotate exposed keys, remove unused permissions, enable secret scanning, and review cloud audit logs for abuse.

Open source →

criticalBleepingComputer

New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges

An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. [...]

Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.

Open source →

lowBleepingComputer

Exchange Online outage causes email delays, 'Server busy' errors

Microsoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains. [...]

Mitigation: Harden SPF/DKIM/DMARC, block sender infrastructure, inspect mailbox rules, and require MFA re-authentication.

Open source →

highThe Hacker News

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.

Open source →

lowThe Hacker News

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them. "We recommend all server owners and Desktop users

Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.

Open source →

lowSANS ISC

ISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.

Open source →

highCISA News

Rockwell Automation 1756-ENBT Module

View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-ENBT Module Improper Check for Unusual or Exceptional Conditions Background Cr

Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.

Open source →

highCISA News

Tycon Systems TPDIN-Monitor-WEB2 (Update A)

View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected: TPDIN-Monitor-WEB2 <2.4.5 (CVE-2026-61884, CVE-2026-55985) CVSS Vendor Equipment Vulnera

Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.

Open source →

highCISA News

Inductive Automation Ignition

View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects. The following versions of Inductive Automation Ignition are affected: Ignition <=8.1.53 (CVE-2026-77393) CVSS Vendor Equipment Vulnerabilities v3 8.8 Inductive Automation Inductive Automation Ignition Incorrect Default Permissions Background Critical Infrastructure Sectors: Critical Manufacturing,

Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.

Open source →

highCISA News

OPCFoundation OPC UA LocalDiscoveryServer (LDS)

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected: UA-LDS-Installers <1.04.420 (CVE-2026-77477) CVSS Vendor Equipment Vulnerabilities v3 4.6 OPCFoundation OPCFoundation OPC UA LocalDiscoveryServer (L

Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.

Open source →

highCISA News

Tycon Systems TPDIN-Monitor-WEB3

View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected: TPDIN-Monitor-WEB3 <=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684) CVSS Vendor Equipment Vulnerabilities v3 8.8 Tycon

Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.

Open source →

lowSANS ISC

Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)

[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program]

Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.

Open source →

lowSANS ISC

ISC Stormcast For Thursday, September 3rd, 2026 https://isc.sans.edu/podcastdetail/10080, (Thu, Sep 3rd)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.

Open source →

How to use Cyber Updates Manual & worked example — inputs, output, limits, what it does not do, and a worked example. Open the reference →