{"date_iso":"2026-09-01","date_human":"Tuesday, September 1, 2026","generated_utc":"2026-09-01 17:17 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Hackers Weaponize Microsoft Teams Help Desk Calls for Malware and Network Lateral Movement","link":"https://cybersecuritynews.com/hackers-weaponize-microsoft-teams/","reason":"Microsoft","category":"News","sources":["Any.Run Malware Analysis","Bleeping Computer","Cyber Security News","Malwarebytes Labs","Palo Alto Unit 42"],"coverage":5,"cve_ids":[],"summary":"Attackers are turning Microsoft Teams help desk calls into an entry point for malware and network compromise. A campaign tracked as Spring Ring used external accounts that resembled internal IT support to chat with\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Hackers-Weaponize-Microsoft-Teams-Help-Desk-Calls-for-Malware-and-Network-Lateral-Movement.webp","description":"Attackers are turning Microsoft Teams help desk calls into an entry point for malware and network compromise. A campaign tracked as Spring Ring used external accounts that resembled internal IT support to chat with employees, then call them and press for remote access or software execution. The activity ran from January through April 2026 and approached more than 150 employees at at least 10 organizations. Its danger lies in the human element: a familiar sounding technician and a live conversation can make an unexpected request feel urgent and legitimate. Analysts at Unit 42 identified the\u2026","related":[{"title":"TerminalFix looks like ClickFix, but delivers a very different payload","link":"https://www.malwarebytes.com/blog/news/2026/09/terminalfix-looks-like-clickfix-but-delivers-a-very-different-payload","source":"Malwarebytes Labs","date_rel":"5h ago"},{"title":"Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk","link":"https://any.run/cybersecurity-blog/major-cyber-attacks-august-2026/","source":"Any.Run Malware Analysis","date_rel":"10h ago"},{"title":"Microsoft says Windows 11 KB5120998 update resets mouse settings","link":"https://www.bleepingcomputer.com/news/security/microsoft-says-windows-11-kb5120998-update-resets-mouse-settings/","source":"Bleeping Computer","date_rel":"31 Aug"},{"title":"Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams","link":"https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/","source":"Palo Alto Unit 42","date_rel":"31 Aug"}]},{"title":"Attackers Abuse Trusted Cloud Services to Hide Phishing Attacks Against Financial Organizations","link":"https://cybersecuritynews.com/trusted-cloud-services-phishing-attacks/","reason":"Cloudflare","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Cybercriminals are increasingly weaponizing trusted cloud platforms such as Microsoft Azure, Google Firebase, Google Cloud Storage, Amazon Web Services, and Cloudflare to host phishing infrastructure aimed squarely at\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Attackers-Abuse-Trusted-Cloud-Services-to-Hide-Phishing.webp","description":"Cybercriminals are increasingly weaponizing trusted cloud platforms such as Microsoft Azure, Google Firebase, Google Cloud Storage, Amazon Web Services, and Cloudflare to host phishing infrastructure aimed squarely at the financial sector, making malicious traffic nearly indistinguishable from legitimate business activity. Security researchers describe this as a structural shift toward what some call Trusted Infrastructure Phishing , where every stage of an attack, from delivery to credential theft, runs through legitimate, enterprise-approved services rather than attacker-owned domains\u2026","related":[{"title":"Microsoft warns of TerminalFix attacks deploying reverse tunnels","link":"https://www.bleepingcomputer.com/news/security/microsoft-warns-of-terminalfix-attacks-deploying-reverse-tunnels/","source":"Bleeping Computer","date_rel":"22h ago"},{"title":"TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor","link":"https://thehackernews.com/2026/08/terminalfix-uses-fake-cloudflare.html","source":"The Hacker News","date_rel":"30 Aug"}]},{"title":"Hackers Abuse Real ChatGPT Links to Trick Windows Users Into Installing Malware","link":"https://cybersecuritynews.com/hackers-abuse-real-chatgpt-links/","reason":"Windows","category":"News","sources":["Cyber Security News","Microsoft Security"],"coverage":2,"cve_ids":["CVE-2026-62823","CVE-2026-65775","CVE-2026-65776"],"summary":"Windows users are being targeted through a malicious campaign that turns a ChatGPT shared link into the step of a malware infection. Rather than breaking into the AI platform, the operators place a deceptive message\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Hackers-Abuse-Real-ChatGPT-Links-to-Trick-Windows-Users-Into-Installing-Malware.webp","description":"Windows users are being targeted through a malicious campaign that turns a ChatGPT shared link into the step of a malware infection. Rather than breaking into the AI platform, the operators place a deceptive message inside a shared conversation and rely on victims to follow its instructions. The page claims that traffic is too high and directs visitors to a supposed backup site. That destination uses a fake human-verification screen and tells people to open the Windows Run dialog, paste a command, and press Enter. The action quietly starts a PowerShell-based download chain outside the\u2026","related":[{"title":"CVE-2026-65775 Windows Win32k Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65775","source":"Microsoft Security","date_rel":"31 Aug"},{"title":"CVE-2026-65776 Windows Win32k Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65776","source":"Microsoft Security","date_rel":"31 Aug"},{"title":"CVE-2026-62823 Windows DHCP Server Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-62823","source":"Microsoft Security","date_rel":"31 Aug"}]},{"title":"WatchGuard Patches Critical Vulnerabilities","link":"https://www.securityweek.com/watchguard-patches-critical-vulnerabilities/","reason":"Watchguard","category":"News","sources":["CCCS Alerts & Advisories","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely.","source":"SecurityWeek","date_rel":"8h ago","thumbnail":"","description":"","related":[{"title":"WatchGuard security advisory (AV26-865)","link":"https://cyber.gc.ca/en/alerts-advisories/watchguard-security-advisory-av26-865","source":"CCCS Alerts & Advisories","date_rel":"22h ago"}]},{"title":"Attackers Steal METR API Key and Consume AI Credits Worth About $600,000","link":"https://thehackernews.com/2026/09/attackers-steal-metr-api-key-and.html","reason":"Attackers Credits 600000","category":"News","sources":["Infosecurity Magazine","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"METR (short for Model Evaluation and Threat Research and pronounced \"Meter\"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks\u2026","source":"The Hacker News","date_rel":"8h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh2b-1gQHvYc7ZLc86QFtZ2LoJ7zFalpJtSy_e_laxiM_f4Ftnhuvp5eCJZRSk2NL_0tZAZAl2z1UPYfOBSTbdGOPOZexgt3GkuUqsrZPgFB2F-qG2Ir_c7Ioj6zcJVdWjzBo90HpcObPWan5eID2df6OXyn3F7-LRpdOvO8TfiZSp8L2j89p2UbsDi3zM4/s1600/metr.jpg","description":"METR (short for Model Evaluation and Threat Research and pronounced \"Meter\"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered \"two notable security incidents\" where external actors attempted to gain unauthorized access to its systems. No sensitive information is believed to","related":[{"title":"Attackers Steal METR API Key and Burn $600,000 in AI Credits","link":"https://www.infosecurity-magazine.com/news/attackers-steal-metr-api-key/","source":"Infosecurity Magazine","date_rel":"2h ago"}]},{"title":"Five Hackers Plead Guilty to ATM Jackpotting Attacks Using Malware to Dispense Cash","link":"https://cybersecuritynews.com/hackers-plead-guilty-to-atm-jackpotting-attacks/","reason":"Jackpotting Attacks Guilty","category":"News","sources":["Bleeping Computer","Cyber Security News"],"coverage":2,"cve_ids":[],"summary":"Five Venezuelan nationals have pleaded guilty in a U.S. federal case involving attempted ATM jackpotting attacks . This criminal technique uses malware to force cash machines to dispense money without legitimate\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Five-Hackers-Plead-Guilty-to-ATM-Jackpotting-Attacks-Using-Malware-to-Dispense-Cash-.webp","description":"Five Venezuelan nationals have pleaded guilty in a U.S. federal case involving attempted ATM jackpotting attacks . This criminal technique uses malware to force cash machines to dispense money without legitimate customer transactions. The case follows an FBI investigation into attempts to compromise ATMs in Wamego and Manhattan, Kansas, during December 2025. U.S. Attorney Ryan A. Kriegshauser said banks and financial institutions should take preventative steps as jackpotting incidents continue to increase across the United States. According to court documents , Luis Alberto Velasquez-Artigas\u2026","related":[{"title":"Five Venezuelans plead guilty to ATM jackpotting attacks in US","link":"https://www.bleepingcomputer.com/news/security/five-venezuelans-plead-guilty-to-atm-jackpotting-attacks-in-us/","source":"Bleeping Computer","date_rel":"8h ago"}]},{"title":"JFrog Artifactory Auth Bypass Exploited in Attacks to Gain Admin Access","link":"https://cybersecuritynews.com/jfrog-artifactory-auth-bypass-exploited/","reason":"CVE-2026-82329","category":"News","sources":["Cyber Security News","SecurityWeek"],"coverage":2,"cve_ids":["CVE-2026-82329"],"summary":"A critical authentication bypass vulnerability in JFrog Artifactory , tracked as CVE-2026-82329, is being actively exploited, allowing unauthenticated attackers with network access to gain administrator-level\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/JFrog-Artifactory-Auth-Bypass-Exploited-in-Attacks-to-gain-Admin-Access.webp","description":"A critical authentication bypass vulnerability in JFrog Artifactory , tracked as CVE-2026-82329, is being actively exploited, allowing unauthenticated attackers with network access to gain administrator-level privileges. WatchTowr said its intelligence team has observed attackers exploiting the issue and \u201cminting themselves admin tokens.\u201d An attacker with a valid administrator token could control the affected Artifactory environment, including repositories, user accounts, access permissions, build artifacts, and software packages stored in the platform. JFrog disclosed the vulnerability on\u2026","related":[{"title":"Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild","link":"https://www.securityweek.com/critical-jfrog-artifactory-vulnerability-reportedly-exploited-in-the-wild/","source":"SecurityWeek","date_rel":"7h ago"}]},{"title":"21,000+ Microsoft Exchange Servers Remain Exposed to Active CVE-2026-62911 Exploitation","link":"https://cybersecuritynews.com/exchange-servers-remain-exposed-2026-62911/","reason":"Exchange","category":"News","sources":["Bleeping Computer","Cyber Security News"],"coverage":2,"cve_ids":["CVE-2026-62911"],"summary":"Nearly 22,000 Microsoft Exchange servers worldwide are still running unpatched for CVE-2026-62911 , a critical authentication-bypass vulnerability that attackers can exploit to seize control of enterprise email\u2026","source":"Cyber Security News","date_rel":"4h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Exchange-Servers-CVE-2026-62911-Remain-Exposed.webp","description":"Nearly 22,000 Microsoft Exchange servers worldwide are still running unpatched for CVE-2026-62911 , a critical authentication-bypass vulnerability that attackers can exploit to seize control of enterprise email infrastructure. According to daily internet-wide scans published by the Shadowserver Foundation, exactly 21,899 unique IP addresses were flagged as vulnerable as of August 31, 2026, underscoring how slowly organizations are responding to one of this year\u2019s most consequential Patch Tuesday disclosures. CVE-2026-62911 Microsoft Exchange CVE-2026-62911 is classified as an authentication\u2026","related":[{"title":"Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks","link":"https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/","source":"Bleeping Computer","date_rel":"4h ago"},{"title":"Massive Microsoft 365 outage causes auth issues, service failures","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-online-outage-causes-email-failures-auth-issues/","source":"Bleeping Computer","date_rel":"31 Aug"}]},{"title":"Iranian cyber spies target aviation, fintech developers with new malware","link":"https://therecord.media/iranian-cyber-spies-target-aviation-fintech-new-malware","reason":"Kaspersky","category":"News","sources":["SecurityWeek","The Record"],"coverage":2,"cve_ids":[],"summary":"In a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia.","source":"The Record","date_rel":"4h ago","thumbnail":"http://cms.therecord.media/uploads/interview_computer_7aa40f8904.png","description":"","related":[{"title":"Nightmare Eclipse Drops \u2018HardBreacher\u2019 Kaspersky Product Exploit","link":"https://www.securityweek.com/nightmare-eclipse-drops-hardbreacher-kaspersky-product-exploit/","source":"SecurityWeek","date_rel":"31 Aug"}]},{"title":"PaperCut Exploitation Escalates to Active Intrusions","link":"https://www.securityweek.com/papercut-exploitation-escalates-to-active-intrusions/","reason":"CVE-2026-81578","category":"News","sources":["CISA Alerts & Advisories","SecurityWeek"],"coverage":2,"cve_ids":["CVE-2026-81578","CVE-2026-82078"],"summary":"CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog.","source":"SecurityWeek","date_rel":"11h ago","thumbnail":"","description":"","related":[{"title":"CISA Adds Two Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/08/31/cisa-adds-two-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"31 Aug"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-82693","vendor":"Tenda","product":"AC1206","severity":"CRITICAL","score":10.0,"description":"A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authentication. It is possible \u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82693"},{"id":"CVE-2026-82694","vendor":"Tenda","product":"AC1206","severity":"CRITICAL","score":10.0,"description":"A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The attack can be initiated\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82694"},{"id":"CVE-2026-82695","vendor":"Tenda","product":"AC18","severity":"CRITICAL","score":10.0,"description":"A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack can be launched remote\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82695"},{"id":"CVE-2026-82970","vendor":"WP Legal Pages","product":"WP Cookie Notice for GDPR, CCPA & ePrivacy Consent","severity":"CRITICAL","score":10.0,"description":"Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files.\n\nThis issue affects WP Cookie Notice for GDPR, CCPA & ePrivacy Consent: from n/\u2026","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82970"},{"id":"CVE-2026-81779","vendor":"Silk Themes","product":"Newspapers X","severity":"CRITICAL","score":10.0,"description":"Improper Validation of Specified Quantity in Input vulnerability in Silk Themes Newspapers X allows Malicious Software Implanted.\n\nThis issue affects Newspapers X: from 1.0.46 through 1.0.48.","cwe":"CWE-1284","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-81779"},{"id":"CVE-2026-81780","vendor":"hashthemes","product":"Hash Form","severity":"CRITICAL","score":10.0,"description":"Unauthenticated Arbitrary File Upload in Hash Form <= 1.4.2 versions.","cwe":"CWE-434","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-81780"},{"id":"CVE-2026-82971","vendor":"Apple","product":"Opera11","severity":"CRITICAL","score":10.0,"description":"A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi of the component CGI Script. This manipulation of the argument ipaddr causes command injection. The attack\u2026","cwe":"CWE-74","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82971"},{"id":"CVE-2026-82689","vendor":"D-Link","product":"DNS-320L","severity":"CRITICAL","score":9.9,"description":"A vulnerability was detected in D-Link DNS-320L, DNS-327L, DNS-340L and DNS-345 up to 20260717. Affected is an unknown function of the file /cgi-bin/isomount_mgr.cgi of the component ISO Image Handler. The manipulation of the argument upIso\u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82689"},{"id":"CVE-2026-82692","vendor":"D-Link","product":"DNS-340L","severity":"CRITICAL","score":9.9,"description":"A vulnerability was found in D-Link DNS-340L and DNS-345 up to 20260717. This affects an unknown part of the file /cgi-bin/iscsi_mgr.cgi. Performing a manipulation of the argument alias/username/password/volume_location results in os comman\u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-82692"},{"id":"CVE-2026-79748","vendor":"samanhappy","product":"mcphub","severity":"CRITICAL","score":9.9,"description":"MCPHub is a unified hub for centrally managing and dynamically orchestrating multiple MCP servers/APIs into separate endpoints with flexible routing strategies. Prior to version 0.12.15, the POST /api/servers and PUT /api/servers/:name endp\u2026","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-79748"}],"vendor_spikes":[{"vendor":"Unknown","count":84,"critical_count":7},{"vendor":"WordPress","count":27,"critical_count":1},{"vendor":"ash-project","count":20,"critical_count":0},{"vendor":"Microsoft","count":15,"critical_count":1},{"vendor":"ellite","count":13,"critical_count":0},{"vendor":"Apache","count":9,"critical_count":0},{"vendor":"samanhappy","count":7,"critical_count":1},{"vendor":"D-Link","count":6,"critical_count":5},{"vendor":"Red Hat","count":6,"critical_count":0},{"vendor":"joomshaper.com","count":5,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":17,"new_cve_count":324,"has_news_data":true,"has_cve_data":true}