Skip to content

Morning Brief

Tuesday, September 1, 2026 · generated 2026-09-01 17:17 UTC · ~5 min read

Top developments

Hackers Weaponize Microsoft Teams Help Desk Calls for Malware and Network Lateral Movement

Attackers are turning Microsoft Teams help desk calls into an entry point for malware and network compromise. A campaign tracked as Spring Ring used external accounts that resembled internal IT support to chat with…

Attackers Abuse Trusted Cloud Services to Hide Phishing Attacks Against Financial Organizations

Cybercriminals are increasingly weaponizing trusted cloud platforms such as Microsoft Azure, Google Firebase, Google Cloud Storage, Amazon Web Services, and Cloudflare to host phishing infrastructure aimed squarely at…

Hackers Abuse Real ChatGPT Links to Trick Windows Users Into Installing Malware

Windows users are being targeted through a malicious campaign that turns a ChatGPT shared link into the step of a malware infection. Rather than breaking into the AI platform, the operators place a deceptive message…

WatchGuard Patches Critical Vulnerabilities

Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely.

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks…

Five Hackers Plead Guilty to ATM Jackpotting Attacks Using Malware to Dispense Cash

Five Venezuelan nationals have pleaded guilty in a U.S. federal case involving attempted ATM jackpotting attacks . This criminal technique uses malware to force cash machines to dispense money without legitimate…

JFrog Artifactory Auth Bypass Exploited in Attacks to Gain Admin Access

A critical authentication bypass vulnerability in JFrog Artifactory , tracked as CVE-2026-82329, is being actively exploited, allowing unauthenticated attackers with network access to gain administrator-level…

21,000+ Microsoft Exchange Servers Remain Exposed to Active CVE-2026-62911 Exploitation

Nearly 22,000 Microsoft Exchange servers worldwide are still running unpatched for CVE-2026-62911 , a critical authentication-bypass vulnerability that attackers can exploit to seize control of enterprise email…

Iranian cyber spies target aviation, fintech developers with new malware

In a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia.

PaperCut Exploitation Escalates to Active Intrusions

CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog.

Vulnerability watch

CVE-2026-82693 Tenda · AC1206 CWE-287 CRITICAL 10.0

A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authentication. It is possible …

CVE-2026-82694 Tenda · AC1206 CWE-287 CRITICAL 10.0

A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated…

CVE-2026-82695 Tenda · AC18 CWE-287 CRITICAL 10.0

A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack can be launched remote…

CVE-2026-82970 WP Legal Pages · WP Cookie Notice for GDPR, CCPA & ePrivacy Consent CWE-434 CRITICAL 10.0

Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files. This issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/…

CVE-2026-81779 Silk Themes · Newspapers X CWE-1284 CRITICAL 10.0

Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted. This issue affects Newspapers X: from 1.0.46 through 1.0.48.

CVE-2026-81780 hashthemes · Hash Form CWE-434 CRITICAL 10.0

Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.

CVE-2026-82971 Apple · Opera11 CWE-74 CRITICAL 10.0

A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command injection. The attack…

CVE-2026-82689 D-Link · DNS-320L CWE-77 CRITICAL 9.9

A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of the argument upIso…

CVE-2026-82692 D-Link · DNS-340L CWE-77 CRITICAL 9.9

A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os comman…

CVE-2026-79748 samanhappy · mcphub CWE-862 CRITICAL 9.9

MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endp…

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →