highThe Hacker News
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The
Mitigation: Harden SPF/DKIM/DMARC, block sender infrastructure, inspect mailbox rules, and require MFA re-authentication.
Open source →
highBleepingComputer
Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]
Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source →
highThe Hacker News
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are
Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source →
highThe Hacker News
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and
Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source →
lowBleepingComputer
Microsoft says some users can’t open the Teams desktop client
Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. [...]
Mitigation: Apply security updates, prioritize domain controllers and internet-facing Windows services, then monitor authentication anomalies.
Open source →
highBleepingComputer
39 New Methods That Compromise Passkey Authentication
Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography. [...]
Mitigation: Rotate exposed keys, remove unused permissions, enable secret scanning, and review cloud audit logs for abuse.
Open source →
criticalBleepingComputer
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. [...]
Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source →
lowBleepingComputer
Exchange Online outage causes email delays, 'Server busy' errors
Microsoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains. [...]
Mitigation: Harden SPF/DKIM/DMARC, block sender infrastructure, inspect mailbox rules, and require MFA re-authentication.
Open source →
highThe Hacker News
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including
Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source →
lowThe Hacker News
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them. "We recommend all server owners and Desktop users
Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source →
lowSANS ISC
ISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source →
highCISA News
Rockwell Automation 1756-ENBT Module
View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-ENBT Module Improper Check for Unusual or Exceptional Conditions Background Cr
Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source →
highCISA News
Tycon Systems TPDIN-Monitor-WEB2 (Update A)
View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected: TPDIN-Monitor-WEB2 <2.4.5 (CVE-2026-61884, CVE-2026-55985) CVSS Vendor Equipment Vulnera
Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source →
highCISA News
Inductive Automation Ignition
View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects. The following versions of Inductive Automation Ignition are affected: Ignition <=8.1.53 (CVE-2026-77393) CVSS Vendor Equipment Vulnerabilities v3 8.8 Inductive Automation Inductive Automation Ignition Incorrect Default Permissions Background Critical Infrastructure Sectors: Critical Manufacturing,
Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source →
highCISA News
OPCFoundation OPC UA LocalDiscoveryServer (LDS)
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected: UA-LDS-Installers <1.04.420 (CVE-2026-77477) CVSS Vendor Equipment Vulnerabilities v3 4.6 OPCFoundation OPCFoundation OPC UA LocalDiscoveryServer (L
Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source →
highCISA News
Tycon Systems TPDIN-Monitor-WEB3
View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected: TPDIN-Monitor-WEB3 <=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684) CVSS Vendor Equipment Vulnerabilities v3 8.8 Tycon
Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source →
lowSANS ISC
Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)
[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program]
Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source →
lowSANS ISC
ISC Stormcast For Thursday, September 3rd, 2026 https://isc.sans.edu/podcastdetail/10080, (Thu, Sep 3rd)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Mitigation: Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source →