{"date_iso":"2026-08-31","date_human":"Monday, August 31, 2026","generated_utc":"2026-08-31 19:29 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor","link":"https://thehackernews.com/2026/08/terminalfix-uses-fake-cloudflare.html","reason":"Cloudflare","category":"News","sources":["Bleeping Computer","Microsoft Security Blog","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. \"While traditional ClickFix campaigns direct\u2026","source":"The Hacker News","date_rel":"30 Aug","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhpxriybAzLw0daA0mtL3sZd04fy8Sal4s0mrBAz2-ksjwfP2V08YK_KbCJY57hKG28Kt6gn2mKq4HFSpkG2MNvA3Oz6MhNUe77_1Nvpahn2nnCFHPpxIlp5Ix4DvAZw08qXtxt1M-4zCtSENbBkODQyP_WDp9j3PXACc0XKYk1BK1K-2Xabho1cBPqerW9/s1600/cf-clickfix.jpg","description":"Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. \"While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply the same technique but direct users to Windows Terminal or PowerShell instead, increasing the likelihood that complex","related":[{"title":"Microsoft warns of TerminalFix attacks deploying reverse tunnels","link":"https://www.bleepingcomputer.com/news/security/microsoft-warns-of-terminalfix-attacks-deploying-reverse-tunnels/","source":"Bleeping Computer","date_rel":"37m ago"},{"title":"TerminalFix campaign deploys a reverse tunnel through multistage intrusion","link":"https://www.microsoft.com/en-us/security/blog/2026/08/28/terminalfix-campaign-deploys-reverse-tunnel-through-multistage-intrusion/","source":"Microsoft Security Blog","date_rel":"29 Aug"}]},{"title":"Security Risk Advisors Launches SCALR AI as a Free SOC AI Platform for Security Teams","link":"https://cybersecuritynews.com/security-risk-advisors-launches-scalr-ai-as-a-free-soc-ai-platform-for-security-teams/","reason":"Teams","category":"News","sources":["Cyber Security News","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Philadelphia, Pennsylvania, United States, August 24th, 2026, CyberNewswire Security Risk Advisors (SRA) , the authors of the free VECTR platform, announce today another great free platform launch: SCALR AI. Security\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhlNs2UqHnsAFAlqZtuvL-KE3if3sE9McjHt8EE3ugg2Emkbuo_INcKzo78XHtlW7Azmu9ClVTWjGCshYo9VBUNGaT_qIGDl8JGLYgHmhMZZLCXJCvdOnpCUud164-_Pur2lss2QUyc1MkTLOOnSPw5CQ6gWOZIf04tw8pPgz9llUedzp3o7YVcQKcgy6U/s1600/Insignary%20Launches%20Clarity%20On-Demand%20SBOMs,%20No%20Annual%20Commitment%20Required%20Toronto,%20Canada,%20July%2015th,%202026,%20CyberNewswire%20Enterprise-grade%20binary%20software%20verification%20for%20one%20proj%20-%202026-08-31T185731.35.webp","description":"Philadelphia, Pennsylvania, United States, August 24th, 2026, CyberNewswire Security Risk Advisors (SRA) , the authors of the free VECTR platform, announce today another great free platform launch: SCALR AI. Security teams can get SCALR AI for free, delivered through the Azure Marketplace. SCALR AI is an agentive workbench that automates time-consuming security work and ships with fully functional incident triage and enrichment, with AI-driven quality review built-in. There are no limits on the free license (such as local use), and the SCALR AI platform is available to CISO teams to deploy in\u2026","related":[{"title":"What the Hugging Face Incident Teaches Security Leaders About AI Agent Access","link":"https://www.securityweek.com/what-the-hugging-face-incident-teaches-security-leaders-about-ai-agent-access/","source":"SecurityWeek","date_rel":"7h ago"},{"title":"Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance","link":"https://thehackernews.com/2026/08/securing-claude-code-new-compliance-api.html","source":"The Hacker News","date_rel":"7h ago"}]},{"title":"Hackers Hide ValleyRAT Backdoor Inside Adware Targeting Users in China and India","link":"https://cybersecuritynews.com/hackers-hide-valleyrat-backdoor/","reason":"Windows","category":"News","sources":["Cyber Security News","Microsoft Security"],"coverage":2,"cve_ids":["CVE-2026-49177","CVE-2026-50344","CVE-2026-50448"],"summary":"Hackers are using adware to deliver ValleyRAT, a Windows backdoor. The campaign primarily affects users in China and India, turning a program expected to display ads into a route for spying, theft, and further malware\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Hackers-Hide-ValleyRAT-Backdoor-Inside-Adware-Targeting-Users-in-China-and-India.webp","description":"Hackers are using adware to deliver ValleyRAT, a Windows backdoor. The campaign primarily affects users in China and India, turning a program expected to display ads into a route for spying, theft, and further malware delivery. The installer changes its visible behavior according to its filename. One version installs a collaboration app, another installs a browser, and a third opens a meeting-download page. Those harmless-looking actions can keep a victim occupied while the malicious components are placed on the machine. Researchers at Securelist identified the activity after an apparent\u2026","related":[{"title":"CVE-2026-49177 Windows TCP/IP Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-49177","source":"Microsoft Security","date_rel":"5h ago"},{"title":"CVE-2026-50448 Windows NTFS Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50448","source":"Microsoft Security","date_rel":"5h ago"},{"title":"CVE-2026-50344 Windows OLE Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-50344","source":"Microsoft Security","date_rel":"5h ago"}]},{"title":"Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams","link":"https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/","reason":"Microsoft","category":"Threat Intel","sources":["Bleeping Computer","Palo Alto Unit 42"],"coverage":2,"cve_ids":[],"summary":"Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers.","source":"Palo Alto Unit 42","date_rel":"9h ago","thumbnail":"https://unit42.paloaltonetworks.com/wp-content/uploads/2026/08/01_Malware_Category_1920x900-5.jpg","description":"","related":[{"title":"Microsoft says Windows 11 KB5120998 update resets mouse settings","link":"https://www.bleepingcomputer.com/news/security/microsoft-says-windows-11-kb5120998-update-resets-mouse-settings/","source":"Bleeping Computer","date_rel":"9h ago"},{"title":"Microsoft asks users to ignore 'Antivirus is turned off' errors","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-asks-users-to-ignore-antivirus-is-turned-off-errors/","source":"Bleeping Computer","date_rel":"10h ago"}]},{"title":"Microsoft Investigating New Exchange Online Outage Tracked as EX1464935 [Updated]","link":"https://cybersecuritynews.com/microsof-new-exchange-online/","reason":"Exchange","category":"News","sources":["Bleeping Computer","Cyber Security News"],"coverage":2,"cve_ids":[],"summary":"Microsoft has opened an active investigation into a new Exchange Online disruption after a wave of user reports flagged access and mail-flow problems across the cloud-based email service. The incident, logged in the\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/Microsoft-Exchange-Online-Outage1.webp","description":"Microsoft has opened an active investigation into a new Exchange Online disruption after a wave of user reports flagged access and mail-flow problems across the cloud-based email service. The incident, logged in the Microsoft 365 admin center as EX1464935, began at 9:23 PM IST on August 31, 2026, with the company confirming at 9:25 PM IST that engineers were \u201cinvestigating user reports of Exchange Online issues\u201d. As of the latest update, the status remains listed as \u201cInvestigating,\u201d meaning Microsoft has not yet isolated a root cause or confirmed the scope of the disruption. The advisory\u2026","related":[{"title":"Microsoft Exchange Online outage causes email failures, auth issues","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-online-outage-causes-email-failures-auth-issues/","source":"Bleeping Computer","date_rel":"2h ago"}]},{"title":"HardBreacher PoC Claims Kaspersky Endpoint 0-Day Privilege Escalation on Windows 11","link":"https://cybersecuritynews.com/hardbreacher-kaspersky-zero-day/","reason":"Kaspersky","category":"News","sources":["Cyber Security News","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"HardBreacher\u2019s newly published PoC claims a local privilege-escalation flaw in Kaspersky Endpoint Security on fully patched Windows 11 systems, but the issue remains unverified and has not been publicly confirmed or\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/08/HardBreacher-Kaspersky-Zero-Day.webp","description":"HardBreacher\u2019s newly published PoC claims a local privilege-escalation flaw in Kaspersky Endpoint Security on fully patched Windows 11 systems, but the issue remains unverified and has not been publicly confirmed or assigned a CVE by Kaspersky. The project, published by a researcher, MSNightmare, describes the alleged flaw as a zero-day elevation-of-privilege vulnerability in Kaspersky\u2019s enterprise endpoint product. According to the repository\u2019s README, the proof of concept was tested on Windows 11 version 25H2 with Kaspersky Endpoint Security version 14.0.0.504. HardBreacher appears to\u2026","related":[{"title":"Nightmare Eclipse Drops \u2018HardBreacher\u2019 Kaspersky Product Exploit","link":"https://www.securityweek.com/nightmare-eclipse-drops-hardbreacher-kaspersky-product-exploit/","source":"SecurityWeek","date_rel":"4h ago"}]},{"title":"China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs","link":"https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html","reason":"Cisco","category":"News","sources":["Bleeping Computer","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS)\u2026","source":"The Hacker News","date_rel":"10h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjxYI5Ntk3CPoEGUHNQbd80hij-0QLnz3V_HBU3aXV-mvQq98IE6xsRlbuwZ2PNbbSV7dA-HlNfqRWj0_bd3XpQCOPt9R2gS3PJMm8lfMP_9IoKyhDNbY9NOotNDHO68v2DSUT_R-0UYTqZQc16DJM7OqS8_35iVUMqyy3GrUt7iMaIWz6iW6OSP2ddiDc/s1600/cisco-creds.jpg","description":"A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks. Sygnia, the incident response firm that investigated the intrusion, said the actor","related":[{"title":"Chinese Fire Ant hackers turn Cisco routers into spying platforms","link":"https://www.bleepingcomputer.com/news/security/chinese-fire-ant-hackers-turn-cisco-routers-into-spying-platforms/","source":"Bleeping Computer","date_rel":"4h ago"}]},{"title":"Anthropic warns infostealer malware is hijacking Claude sessions to drain usage","link":"https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-warns-infostealer-malware-is-hijacking-claude-sessions-to-drain-usage/","reason":"Infostealer Anthropic Malware","category":"News","sources":["Bleeping Computer","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"Anthropic is warning some Claude users that infostealer malware on their PCs has stolen active Claude login sessions, allowing attackers to access accounts and consume their usage.","source":"Bleeping Computer","date_rel":"30 Aug","thumbnail":"","description":"","related":[{"title":"Anthropic Warns Claude Users of Infostealer Malware Infections","link":"https://www.securityweek.com/anthropic-warns-claude-users-of-infostealer-malware-infections/","source":"SecurityWeek","date_rel":"7h ago"}]},{"title":"Google's Calling Lake Ontario 'Lake America' Now","link":"https://www.404media.co/google-maps-lake-america-lake-ontario-name-change/","reason":"Google","category":"News","sources":["404 Media","Bleeping Computer"],"coverage":2,"cve_ids":[],"summary":"On Thursday, Trump signed an executive order demanding Lake Ontario be renamed to Lake America. At the signing of the order, he sat next to a big poster board map of the Great Lakes, with a big red arrow labeling Lake\u2026","source":"404 Media","date_rel":"30 Aug","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/08/Screenshot-2026-08-30-at-8.42.47---AM.png","description":"On Thursday, Trump signed an executive order demanding Lake Ontario be renamed to Lake America. At the signing of the order, he sat next to a big poster board map of the Great Lakes, with a big red arrow labeling Lake Ontario as \"Lake America,\" with the words \"Making the Great Lakes Even Greater.\" The Canadian province of Ontario borders the north, west, and southwest sides of the lake, with New York State on the south and east.","related":[{"title":"Chrome Web Store extensions caught stealing crypto, browser data","link":"https://www.bleepingcomputer.com/news/security/chrome-web-store-extensions-caught-stealing-crypto-browser-data/","source":"Bleeping Computer","date_rel":"30 Aug"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-82542","vendor":"Tenda","product":"HG10","severity":"CRITICAL","score":10.0,"description":"A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buff\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82542"},{"id":"CVE-2026-82592","vendor":"D-Link","product":"DIR-825M","severity":"CRITICAL","score":9.9,"description":"A vulnerability was detected in D-Link DIR-825M 1.1.8. This affects the function sub_46725C of the file /boafrm/formDiskFormat of the component Disk Formatting Handler Endpoint. The manipulation of the argument partition results in stack-ba\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82592"},{"id":"CVE-2026-82593","vendor":"D-Link","product":"DIR-825M","severity":"CRITICAL","score":9.9,"description":"A flaw has been found in D-Link DIR-825M 1.1.8. This impacts the function sub_41802C of the file /boafrm/formLtefotaUpgradeFibocom of the component LTE Module Firmware Upgrade. This manipulation of the argument fota_url causes stack-based b\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82593"},{"id":"CVE-2026-82616","vendor":"TOTOLINK","product":"NR1800X","severity":"CRITICAL","score":9.9,"description":"A vulnerability was found in TOTOLINK NR1800X 9.1.0u.6681_B20230703. Impacted is the function setUploadSetting of the file /cgi-bin/cstecgi.cgi. The manipulation of the argument FileName results in stack-based buffer overflow. The attack ca\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82616"},{"id":"CVE-2026-82874","vendor":"ToolJet","product":"ToolJet","severity":"CRITICAL","score":9.9,"description":"ToolJet before v3.16.208 fails to validate that authenticated users belong to the organization specified in the organizationId path parameter of tooljet-db endpoints, allowing any Builder user to read, modify, and delete tables across tenan\u2026","cwe":"CWE-639","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82874"},{"id":"CVE-2026-82689","vendor":"D-Link","product":"DNS-320L","severity":"CRITICAL","score":9.9,"description":"A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of the argument upIso\u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82689"},{"id":"CVE-2026-58574","vendor":"Dell","product":"PowerStore 500T","severity":"CRITICAL","score":9.8,"description":"Dell PowerStore contains a Missing Authentication for Critical Function vulnerability. An unauthenticated attacker with network access to the restricted management interface could potentially exploit this vulnerability to read internal syst\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-58574"},{"id":"CVE-2026-82854","vendor":"nodemailer","product":"nodemailer","severity":"CRITICAL","score":9.8,"description":"Nodemailer before 8.0.4 is vulnerable to SMTP command injection through the unsanitized envelope.size parameter. When an application passes a custom envelope object with a size property containing CRLF characters to sendMail(), the value is\u2026","cwe":"CWE-93","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82854"},{"id":"CVE-2026-82855","vendor":"hulumi","product":"policies","severity":"CRITICAL","score":9.8,"description":"@hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppress violations by submitting unrelated compliant evidence. Attackers\u2026","cwe":"CWE-693","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82855"},{"id":"CVE-2026-82856","vendor":"hulumi","product":"policies","severity":"CRITICAL","score":9.8,"description":"@hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can use ForAnyValue:StringLike operators to hide wildcard GitHub Actions OIDC subject condit\u2026","cwe":"CWE-284","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82856"}],"vendor_spikes":[{"vendor":"ash-project","count":25,"critical_count":0},{"vendor":"Unknown","count":25,"critical_count":0},{"vendor":"D-Link","count":8,"critical_count":6},{"vendor":"Apache","count":8,"critical_count":0},{"vendor":"itsourcecode","count":7,"critical_count":0},{"vendor":"nodemailer","count":7,"critical_count":1},{"vendor":"ToolJet","count":7,"critical_count":3},{"vendor":"Linux Foundation","count":6,"critical_count":0},{"vendor":"WWBN","count":6,"critical_count":0},{"vendor":"hulumi","count":6,"critical_count":4}],"epss_risers":[],"developing_map":{},"trending_count":9,"new_cve_count":188,"has_news_data":true,"has_cve_data":true}