Skip to content

Morning Brief

Wednesday, September 2, 2026 · generated 2026-09-02 17:06 UTC · ~5 min read

Top developments

Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users

The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.

Google Launches Gemini 3.8 Flash Cyber to Identify and Auto-Patch Security Vulnerabilities

Google has unveiled Gemini 3.8, its latest reasoning and coding model family, introducing a specialized variant called Gemini 3.8 Flash Cyber that is purpose-built to autonomously discover software vulnerabilities and…

Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products

The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.

Another Artifactory CVE under attack by AI agents or humans

Security researchers reported that someone is exploiting CVE-2026-82329, a critical JFrog Artifactory authentication-bypass bug, just days after the vendor patched the 9.8-rated flaw. And we don't know if that someone…

Dropbox Says 5,000 Accounts Were Compromised Through Lenovo ID Authentication Flaw

Dropbox has disclosed that approximately 5,000 user accounts were compromised in August after attackers exploited a weakness involving its Lenovo ID sign-in integration. The incident highlights the security risks that…

Two critical Chrome flaws put users at risk on malicious websites

Chrome is rolling out an update for its desktop browser. The update includes 26 security fixes, two of which Google rates as critical use-after-free vulnerabilities. The Stable channel has been updated to…

Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes

International law enforcement agencies, working with CrowdStrike and Shadowserver Foundation, have disrupted Sality, a 23-year-old peer-to-peer botnet used to deliver malware to more than 15,000 machines worldwide. The…

Firefox on iPhone Can Now Block Ads and Trackers Without Installing an Extension

Mozilla has introduced a built-in Ad Blocker for Firefox on iOS, allowing iPhone users to block many third-party advertisements and ad-related trackers without downloading a separate browser extension. The new feature…

Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise

The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.

Hackers push malicious Virtualizor update in BGP hijacking attack

Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers.

Vulnerability watch

CVE-2026-76657 HP · Fabric Composer CWE-287 CRITICAL 10.0

Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacke…

CVE-2026-76658 HP · Fabric Composer CWE-287 CRITICAL 10.0

A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attack…

CVE-2026-18550 WordPress · Nokri – Job Board WordPress Theme CWE-269 CRITICAL 9.8

The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to insufficient reset token validation in the `nokri_reset_password()` f…

CVE-2026-18765 Teracity Software Technologies Inc. · E-OSB CWE-89 CRITICAL 9.8

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection. This issue affects E-OSB: before V02.26.07.08.01.

CVE-2026-18210 Unknown · Products's Store CWE-89 CRITICAL 9.8

Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection. This is…

CVE-2026-18808 Klemsan Electrical Electronics Inc. · KIO (Klemsan Internet Objects) CWE-94 CRITICAL 9.8

Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO (Klemsan Internet Objects): before v1.9.

CVE-2026-78012 Pyramid Solutions · EtherNet/IP Adapter DLL Kit (EIPA) CWE-121 CRITICAL 9.8

An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a de…

CVE-2026-73749 HP · AOS-CX CRITICAL 9.8

Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected serv…

CVE-2023-54391 Proxmox Server Solutions GmbH · Proxmox Virtual Environment (VE) CWE-304 CRITICAL 9.8

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured s…

CVE-2026-84372 predis · predis CWE-93 CRITICAL 9.8

Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in Abstract…

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →