CRITICAL
The Hacker News
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google Chrome V8 engine contains an actively exploited type confusion vulnerability (CVE-2026-85046, CVSS 8.8) affecting versions prior to 152.0.7977.82. Immediate patching is required to prevent remote code execution through malicious web content.
▸ countermeasure Immediately update all Chrome instances to version 152.0.7977.82 or later across all endpoints
ArrayArrayArray
Open source advisory →
CRITICAL
The Hacker News
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
Thomson Reuters' C-Track court management platform was breached in March 2026, exposing sensitive court records including SSNs and sealed data across 11 U.S. states and Canadian jurisdictions. Immediate defensive actions required to protect affected individuals and systems.
▸ countermeasure Audit all C-Track instances in your organization for unauthorized access logs between March-June 2026
ArrayArrayArrayArray
Open source advisory →
CRITICAL
The Hacker News
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
BraZetsu is a Python-based malware framework that compromises Windows hosts and converts them into sellable access inventory for Initial Access Brokers. This represents a critical threat to enterprise security as it enables systematic monetization of network breaches.
▸ countermeasure Implement behavioral detection for Python-based malware execution on Windows endpoints
ArrayArrayArrayArray
Open source advisory →
CRITICAL
BleepingComputer
HPE patches critical ArubaOS-CX remote code execution flaw
HPE ArubaOS-CX contains a critical RCE vulnerability requiring immediate patching. Network switches running affected versions are at risk of unauthorized remote code execution.
▸ countermeasure Identify all ArubaOS-CX devices in your network inventory
ArrayArray
Open source advisory →
CRITICAL
BleepingComputer
Coder's registry infrastructure compromised to push malicious modules
Attackers compromised Coder's Cloudflare infrastructure to distribute malicious Terraform modules with credential-stealing capabilities. Organizations using Coder's registry may have downloaded compromised infrastructure-as-code containing embedded malware.
▸ countermeasure Audit all Terraform modules sourced from Coder's registry for suspicious credential access patterns
ArrayArrayArrayArray
Open source advisory →
CRITICAL
The Hacker News
Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Unauthenticated remote code execution as root affects Cisco Nexus 9000 Silicon One switches (CVE-2026-20212, CVSS 9.8). IOS XR also has 7 umbrella CVEs including two rated 9.8 with no available workarounds.
▸ countermeasure Immediately inventory all Cisco Nexus 9000 Silicon One-based switches in your environment
ArrayArrayArray
Open source advisory →
CRITICAL
The Hacker News
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
CISA has added seven actively exploited vulnerabilities to the KEV catalog, including a critical CVSS 10.0 SSRF flaw in SonicWall SMA 1000 appliances. Attackers are deploying reverse shells and crypto miners through these vulnerabilities.
▸ countermeasure Immediately inventory all SonicWall SMA 1000 appliances in your environment
ArrayArrayArrayArray
Open source advisory →
CRITICAL
The Hacker News
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
CrowdStrike Falcon Sensor contains a privilege escalation vulnerability (FalconFlank) exploitable through the office malicious macros remediation feature. Immediate patching and monitoring for exploitation attempts are required.
▸ countermeasure Immediately update CrowdStrike Falcon Sensor to the latest patched version
ArrayArray
Open source advisory →
CRITICAL
BleepingComputer
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. [...]
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
The Hacker News
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex Media Server and Desktop have patched multiple undisclosed security vulnerabilities in versions 1.43.3 and 1.115.0 respectively. Immediate patching is critical as CVE details are pending and exploitation risk is unknown.
▸ countermeasure Immediately update Plex Media Server to version 1.43.3 or later
ArrayArrayArray
Open source advisory →
HIGH
The Hacker News
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses
▸ countermeasure Harden SPF/DKIM/DMARC, block sender infrastructure, inspect mailbox rules, and require MFA re-authentication.
Open source advisory →
HIGH
CISA News
Tycon Systems TPDIN-Monitor-WEB3
View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected: TPDIN-Monitor-WEB3 <=2.2.9 (CVE-2026-77847, CVE-2026-82712, CVE-2026-82684) CVSS Vendor Equipment Vulnerabi
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
CISA News
OPCFoundation OPC UA LocalDiscoveryServer (LDS)
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected: UA-LDS-Installers <1.04.420 (CVE-2026-77477) CVSS Vendor Equipment Vulnerabilities v3 4.6 OPCFoundation OPCFoundation OPC UA Loc
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
CISA News
Inductive Automation Ignition
View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects. The following versions of Inductive Automation Ignition are affected: Ignition <=8.1.53 (CVE-2026-77393) CVSS Vendor Equipment Vulnerabilities v3 8.8 Inductive Automation Inductive Automation Ignition Incorrect Default Permissions Background Critical Infrastructure Sectors: Cri
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
CISA News
Tycon Systems TPDIN-Monitor-WEB2 (Update A)
View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety risk. The following versions of Tycon Systems TPDIN-Monitor-WEB2 (Update A) are affected: TPDIN-Monitor-WEB2 <2.4.5 (CVE-2026-61884, CVE-2026-55985) CVSS Vend
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
CISA News
Rockwell Automation 1756-ENBT Module
Rockwell Automation 1756-ENBT Module (all versions) contains an improper exception handling vulnerability (CVE-2025-10478) that can crash the module, requiring manual restart. This affects industrial control systems and requires immediate patching or mitigation.
▸ countermeasure Inventory all 1756-ENBT modules in your environment and document current firmware versions
ArrayArrayArray
Open source advisory →
HIGH
The Hacker News
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The
▸ countermeasure Harden SPF/DKIM/DMARC, block sender infrastructure, inspect mailbox rules, and require MFA re-authentication.
Open source advisory →
HIGH
BleepingComputer
Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
The Hacker News
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
The Hacker News
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
HIGH
BleepingComputer
39 New Methods That Compromise Passkey Authentication
Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography. [...]
▸ countermeasure Rotate exposed keys, remove unused permissions, enable secret scanning, and review cloud audit logs for abuse.
Open source advisory →
HIGH
The Hacker News
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including
▸ countermeasure Triage affected assets, validate exposure, apply available mitigations, increase logging, and document evidence for incident review.
Open source advisory →
MEDIUM
The Hacker News
GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests
GPT-6 Astra demonstrates advanced AI capabilities including computer use and software engineering that could be misused for exploitation. OpenAI has implemented safeguards to block PoC exploit requests, but organizations should monitor AI-assisted attack vectors and implement detection controls.
▸ countermeasure Monitor for AI-generated exploit code in security logs and endpoint telemetry
ArrayArrayArray
Open source advisory →
MEDIUM
SANS ISC
Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)
A honeypot deployment in Omaha detected reconnaissance and exploitation attempts against batch.py scripts, indicating active scanning for batch processing vulnerabilities. Organizations should review batch job configurations and access controls to prevent similar compromise.
▸ countermeasure Audit all batch.py and scheduled task configurations for excessive permissions
ArrayArrayArray
Open source advisory →