{"date_iso":"2026-09-02","date_human":"Wednesday, September 2, 2026","generated_utc":"2026-09-02 17:06 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users","link":"https://www.darkreading.com/cyberattacks-data-breaches/threat-gang-springs-vishing-attacks-microsoft-teams-users","reason":"Microsoft","category":"News","sources":["Any.Run Malware Analysis","Bleeping Computer","Cyber Security News","Dark Reading","Malwarebytes Labs","Palo Alto Unit 42"],"coverage":6,"cve_ids":[],"summary":"The \"Spring Ring\" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.","source":"Dark Reading","date_rel":"15m ago","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt3c8192b6490626c0/6a981a98644fc5665f78add9/phone-Brian_Jackson-Alamy.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Hackers Target US and EU Firms With Microsoft 365 Session Hijacking and RMM Abuse","link":"https://cybersecuritynews.com/microsoft-365-session-hijacking/","source":"Cyber Security News","date_rel":"1h ago"},{"title":"Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks","link":"https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/","source":"Bleeping Computer","date_rel":"1 Sep"},{"title":"TerminalFix looks like ClickFix, but delivers a very different payload","link":"https://www.malwarebytes.com/blog/news/2026/09/terminalfix-looks-like-clickfix-but-delivers-a-very-different-payload","source":"Malwarebytes Labs","date_rel":"1 Sep"},{"title":"Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk","link":"https://any.run/cybersecurity-blog/major-cyber-attacks-august-2026/","source":"Any.Run Malware Analysis","date_rel":"1 Sep"},{"title":"Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams","link":"https://unit42.paloaltonetworks.com/spring-ring-voice-phishing-campaigns/","source":"Palo Alto Unit 42","date_rel":"31 Aug"}]},{"title":"Google Launches Gemini 3.8 Flash Cyber to Identify and Auto-Patch Security Vulnerabilities","link":"https://cybersecuritynews.com/gemini-3-8-flash-cyber/","reason":"Google","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Cyber Security News","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"Google has unveiled Gemini 3.8, its latest reasoning and coding model family, introducing a specialized variant called Gemini 3.8 Flash Cyber that is purpose-built to autonomously discover software vulnerabilities and\u2026","source":"Cyber Security News","date_rel":"11m ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Gemini-3.8-Flash-Cyber.webp","description":"Google has unveiled Gemini 3.8, its latest reasoning and coding model family, introducing a specialized variant called Gemini 3.8 Flash Cyber that is purpose-built to autonomously discover software vulnerabilities and generate working patches for them. The release arrives just three weeks after Gemini 3.7 Flash, marking Google\u2019s third Flash-tier launch in six weeks, and both new models share the same underlying architecture while being tuned for different deployment scenarios. Google Launches Gemini 3.8 Flash Cyber The general-purpose Gemini 3.8 Flash targets long-horizon software engineering\u2026","related":[{"title":"Google security advisory (AV26-874)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-874","source":"CCCS Alerts & Advisories","date_rel":"2h ago"},{"title":"Microsoft Defender flags legitimate Google search links as malicious","link":"https://www.bleepingcomputer.com/news/security/microsoft-defender-flags-legitimate-google-search-links-as-malicious/","source":"Bleeping Computer","date_rel":"6h ago"},{"title":"Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems","link":"https://thehackernews.com/2026/09/breeze-comet-executes-hundreds-of.html","source":"The Hacker News","date_rel":"23h ago"}]},{"title":"Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products","link":"https://www.securityweek.com/rockwell-automation-patches-over-a-dozen-vulnerabilities-across-products/","reason":"Rockwell","category":"News","sources":["CCCS Alerts & Advisories","CISA Alerts & Advisories","CISA ICS Advisories","SecurityWeek"],"coverage":4,"cve_ids":[],"summary":"The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.","source":"SecurityWeek","date_rel":"4h ago","thumbnail":"","description":"","related":[{"title":"Rockwell Automation security advisory (AV26-869)","link":"https://cyber.gc.ca/en/alerts-advisories/rockwell-automation-security-advisory-av26-869","source":"CCCS Alerts & Advisories","date_rel":"22h ago"},{"title":"Rockwell Automation RSLinx Classic","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-01","source":"CISA Alerts & Advisories","date_rel":"1 Sep"},{"title":"Rockwell Automation Historian ME","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-06","source":"CISA Alerts & Advisories","date_rel":"1 Sep"},{"title":"Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-05","source":"CISA Alerts & Advisories","date_rel":"1 Sep"},{"title":"Rockwell Automation Historian ME","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-06","source":"CISA ICS Advisories","date_rel":"1 Sep"},{"title":"Rockwell Automation ControlLogix, CompactLogix, CompactLogix 5480, GuardLogix, Compact GuardLogix","link":"https://www.cisa.gov/news-events/ics-advisories/icsa-26-244-05","source":"CISA ICS Advisories","date_rel":"1 Sep"}]},{"title":"Another Artifactory CVE under attack by AI agents or humans","link":"https://www.theregister.com/security/2026/09/01/another-artifactory-cve-under-attack-by-ai-agents-or-humans/5293769","reason":"CVE-2026-82329","category":"News","sources":["Bleeping Computer","Dark Reading","The Hacker News","The Register Security"],"coverage":4,"cve_ids":["CVE-2026-82329"],"summary":"Security researchers reported that someone is exploiting CVE-2026-82329, a critical JFrog Artifactory authentication-bypass bug, just days after the vendor patched the 9.8-rated flaw. And we don't know if that someone\u2026","source":"The Register Security","date_rel":"19h ago","thumbnail":"https://image.theregister.com/?imageId=230216&width=800","description":"Security researchers reported that someone is exploiting CVE-2026-82329, a critical JFrog Artifactory authentication-bypass bug, just days after the vendor patched the 9.8-rated flaw. And we don't know if that someone is human. Artifactory is a widely used tool for managing software artifacts, packages, binaries, and AI models. It\u2019s also popular with AI agents that go rogue and need to communicate with each other while remaining undetected by their human babysitters. In July, OpenAI and JFrog revealed that OpenAI\u2019s models broke out of their cages to hack Hugging Face by exploiting Artifactory\u2026","related":[{"title":"Hackers exploit critical JFrog Artifactory flaw to forge admin tokens","link":"https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-jfrog-artifactory-flaw-to-forge-admin-tokens/","source":"Bleeping Computer","date_rel":"1h ago"},{"title":"Attackers Pounce on Critical Artifactory Bug Following Disclosure","link":"https://www.darkreading.com/application-security/attackers-pounce-critical-artifactory-flaw-disclosure","source":"Dark Reading","date_rel":"20h ago"},{"title":"Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure","link":"https://thehackernews.com/2026/09/attackers-exploit-critical-jfrog.html","source":"The Hacker News","date_rel":"23h ago"}]},{"title":"Dropbox Says 5,000 Accounts Were Compromised Through Lenovo ID Authentication Flaw","link":"https://cybersecuritynews.com/dropbox-lenovo-id-flaw/","reason":"Lenovo","category":"News","sources":["Bleeping Computer","Cyber Security News","The Register Security"],"coverage":3,"cve_ids":[],"summary":"Dropbox has disclosed that approximately 5,000 user accounts were compromised in August after attackers exploited a weakness involving its Lenovo ID sign-in integration. The incident highlights the security risks that\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Dropbox-Lenovo-ID-Flaw.webp","description":"Dropbox has disclosed that approximately 5,000 user accounts were compromised in August after attackers exploited a weakness involving its Lenovo ID sign-in integration. The incident highlights the security risks that can arise when cloud platforms trust third-party identity providers without requiring strong, account-level verification before granting access. According to notifications sent to affected users, unauthorized access occurred between August 4 and August 21, 2026. Dropbox said attackers were able to register Lenovo IDs using victims\u2019 email addresses due to an issue in Lenovo\u2019s\u2026","related":[{"title":"Legacy Lenovo login opens 5,000 Dropbox accounts to attackers","link":"https://www.theregister.com/security/2026/09/02/legacy-lenovo-login-opens-5000-dropbox-accounts-to-attackers/5293924","source":"The Register Security","date_rel":"2h ago"},{"title":"Dropbox accounts breached through Lenovo email verification flaw","link":"https://www.bleepingcomputer.com/news/security/dropbox-accounts-breached-through-lenovo-email-verification-flaw/","source":"Bleeping Computer","date_rel":"4h ago"}]},{"title":"Two critical Chrome flaws put users at risk on malicious websites","link":"https://www.malwarebytes.com/blog/bugs/2026/09/two-critical-chrome-flaws-put-users-at-risk-on-malicious-websites","reason":"Chrome","category":"Threat Intel","sources":["Malwarebytes Labs","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"Chrome is rolling out an update for its desktop browser. The update includes 26 security fixes, two of which Google rates as critical use-after-free vulnerabilities. The Stable channel has been updated to\u2026","source":"Malwarebytes Labs","date_rel":"5h ago","thumbnail":"","description":"Chrome is rolling out an update for its desktop browser. The update includes 26 security fixes, two of which Google rates as critical use-after-free vulnerabilities. The Stable channel has been updated to 152.0.7977.75/.76 for Windows and Mac, and 152.0.7977.75 for Linux. How to update Chrome If you don\u2019t want to wait for the rollout to reach you, manually updating is easy. The easiest option is to allow Chrome to update automatically. But you can end up lagging behind if you never close your browser or if something goes wrong with the update. To update manually, click the More menu (three\u2026","related":[{"title":"Chrome and Firefox Updates Patch Dozens of Vulnerabilities","link":"https://www.securityweek.com/chrome-and-firefox-updates-patch-dozens-of-vulnerabilities/","source":"SecurityWeek","date_rel":"7h ago"}]},{"title":"Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholes","link":"https://www.theregister.com/cyber-crime/2026/09/02/cops-crowdstrike-disrupt-sality-botnet-by-poisoning-the-network-and-diverting-into-sinkholes/5293795","reason":"Crowdstrike","category":"News","sources":["CyberScoop","The Register Security"],"coverage":2,"cve_ids":[],"summary":"International law enforcement agencies, working with CrowdStrike and Shadowserver Foundation, have disrupted Sality, a 23-year-old peer-to-peer botnet used to deliver malware to more than 15,000 machines worldwide. The\u2026","source":"The Register Security","date_rel":"17h ago","thumbnail":"https://image.theregister.com/?imageId=247072&width=800","description":"International law enforcement agencies, working with CrowdStrike and Shadowserver Foundation, have disrupted Sality, a 23-year-old peer-to-peer botnet used to deliver malware to more than 15,000 machines worldwide. The botnet has operated since 2003 and distributed all types of malicious code to victims, spanning credential theft, spam distribution, proxy services, network exploitation, and distributed denial-of-service (DDoS) attacks. For the past eight years, Sality\u2019s primary payload has been EggJagger, a tool that monitors clipboards for cryptocurrency wallet addresses, then silently\u2026","related":[{"title":"Dogged Russia-based botnet dismantled after 23-year run","link":"https://cyberscoop.com/sality-botnet-dismantled/","source":"CyberScoop","date_rel":"2m ago"}]},{"title":"Firefox on iPhone Can Now Block Ads and Trackers Without Installing an Extension","link":"https://cybersecuritynews.com/firefox-on-iphone-block-ads/","reason":"Firefox","category":"News","sources":["Cyber Security News","The Register Security"],"coverage":2,"cve_ids":[],"summary":"Mozilla has introduced a built-in Ad Blocker for Firefox on iOS, allowing iPhone users to block many third-party advertisements and ad-related trackers without downloading a separate browser extension. The new feature\u2026","source":"Cyber Security News","date_rel":"28m ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Firefox-on-iPhone-Can-Now-Block-Ads-and-Trackers-Without-Installing-an-Extension.webp","description":"Mozilla has introduced a built-in Ad Blocker for Firefox on iOS, allowing iPhone users to block many third-party advertisements and ad-related trackers without downloading a separate browser extension. The new feature is designed to reduce visual clutter from pop-ups, overlays, and third-party advertising scripts that can slow down browsing or interrupt users while reading web content. It is optional and disabled by default, giving users control over whether ad blocking is enabled in their browser. Firefox users on iPhone can activate the setting by opening Settings, selecting Browsing, and\u2026","related":[{"title":"Firefox helps iPhone users bypass ads on web sites while making money showing its own ads","link":"https://www.theregister.com/security/2026/09/01/firefox-helps-iphone-users-bypass-ads-on-web-sites-while-making-money-showing-its-own-ads/5293747","source":"The Register Security","date_rel":"20h ago"}]},{"title":"Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise","link":"https://www.darkreading.com/vulnerabilities-threats/critical-langflow-flaw-exploited-attacks-rise","reason":"CVE-2026-0768","category":"News","sources":["Bleeping Computer","Dark Reading","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-0768"],"summary":"The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.","source":"Dark Reading","date_rel":"20h ago","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blt036489a36358dea1/6a971529de036c92b216129d/aicoding-AreeSarak-Getty-2252848921.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Critical Langflow flaw exploited to steal OpenAI and AWS keys","link":"https://www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/","source":"Bleeping Computer","date_rel":"23h ago"},{"title":"Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity","link":"https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.html","source":"The Hacker News","date_rel":"1 Sep"}]},{"title":"Hackers push malicious Virtualizor update in BGP hijacking attack","link":"https://www.bleepingcomputer.com/news/security/hackers-push-malicious-virtualizor-update-in-bgp-hijacking-attack/","reason":"Virtualizor Hijacking Malicious","category":"News","sources":["Bleeping Computer","SecurityWeek"],"coverage":2,"cve_ids":[],"summary":"Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers.","source":"Bleeping Computer","date_rel":"1 Sep","thumbnail":"","description":"","related":[{"title":"Malicious Virtualizor Update Served via BGP Hijacking","link":"https://www.securityweek.com/malicious-virtualizor-update-served-via-bgp-hijacking/","source":"SecurityWeek","date_rel":"5h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-76657","vendor":"HP","product":"Fabric Composer","severity":"CRITICAL","score":10.0,"description":"Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacke\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-76657"},{"id":"CVE-2026-76658","vendor":"HP","product":"Fabric Composer","severity":"CRITICAL","score":10.0,"description":"A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attack\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-76658"},{"id":"CVE-2026-18550","vendor":"WordPress","product":"Nokri \u2013 Job Board WordPress Theme","severity":"CRITICAL","score":9.8,"description":"The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to insufficient reset token validation in the `nokri_reset_password()` f\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18550"},{"id":"CVE-2026-18765","vendor":"Teracity Software Technologies Inc.","product":"E-OSB","severity":"CRITICAL","score":9.8,"description":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection.\n\nThis issue affects E-OSB: before V02.26.07.08.01.","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18765"},{"id":"CVE-2026-18210","vendor":"Unknown","product":"Products's Store","severity":"CRITICAL","score":9.8,"description":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL Injection.\n\nThis is\u2026","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18210"},{"id":"CVE-2026-18808","vendor":"Klemsan Electrical Electronics Inc.","product":"KIO (Klemsan Internet Objects)","severity":"CRITICAL","score":9.8,"description":"Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection.\n\nThis issue affects KIO (Klemsan Internet Objects): before v1.9.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-18808"},{"id":"CVE-2026-78012","vendor":"Pyramid Solutions","product":"EtherNet/IP Adapter DLL Kit (EIPA)","severity":"CRITICAL","score":9.8,"description":"An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive buffer without generating an error or warning. The result could be memory corruption, a de\u2026","cwe":"CWE-121","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-78012"},{"id":"CVE-2026-73749","vendor":"HP","product":"AOS-CX","severity":"CRITICAL","score":9.8,"description":"Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected serv\u2026","cwe":"","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-73749"},{"id":"CVE-2023-54391","vendor":"Proxmox Server Solutions GmbH","product":"Proxmox Virtual Environment (VE)","severity":"CRITICAL","score":9.8,"description":"Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured s\u2026","cwe":"CWE-304","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2023-54391"},{"id":"CVE-2026-84372","vendor":"predis","product":"predis","severity":"CRITICAL","score":9.8,"description":"Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in Abstract\u2026","cwe":"CWE-93","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-84372"}],"vendor_spikes":[{"vendor":"HP","count":86,"critical_count":6},{"vendor":"Unknown","count":55,"critical_count":2},{"vendor":"WordPress","count":53,"critical_count":3},{"vendor":"Mozilla","count":34,"critical_count":2},{"vendor":"NVIDIA","count":30,"critical_count":0},{"vendor":"Google","count":28,"critical_count":5},{"vendor":"Elastic","count":20,"critical_count":0},{"vendor":"Erlang","count":16,"critical_count":0},{"vendor":"Red Hat","count":13,"critical_count":0},{"vendor":"Dell","count":13,"critical_count":1}],"epss_risers":[],"developing_map":{},"trending_count":15,"new_cve_count":505,"has_news_data":true,"has_cve_data":true}