Skip to content

Morning Brief

Thursday, September 3, 2026 · generated 2026-09-03 17:01 UTC · ~5 min read

Top developments

Microsoft to Expand Memory Integrity Protection Across Windows Devices

Microsoft will begin expanding memory integrity protection across eligible Windows devices in October 2026, automatically enabling a stronger kernel-level security baseline for more users and organizations. The change…

Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program…

Rockwell Automation 1756-ENBT Module

View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT…

New StreamRAT Android Trojan Gives Hackers Full Remote Control Through VNC and Accessibility

StreamRAT is a new Android banking trojan that gives criminals broad control of an infected phone. It pairs streaming offers with screen viewing, remote actions and deceptive login windows, turning an app download into…

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR…

The Agentic SOC – From AI Theater to Real Defense

Moving beyond "AI theater" with measurable KPIs: Security teams must distinguish between genuine value and "productivity theater." Success requires defining concrete KPIs—such as cost improvement, risk reduction, and…

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586…

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the…

Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. "Our…

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S…

Vulnerability watch

CVE-2026-4357 WordPress · Embed HTML5 Game CWE-434 CRITICAL 10.0

The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors on affected sites.

CVE-2026-77009 WordPress · WatchMan-Site7 CWE-94 CRITICAL 9.9

The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on the server.

CVE-2026-81294 Paul Ryan · Authorizer CWE-266 CRITICAL 9.8

Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.

CVE-2026-84795 craftcms · cms CWE-269 CRITICAL 9.8

Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit administrator privileges …

CVE-2025-9314 WordPress · Developer Tools CWE-434 CRITICAL 9.8

The Developer Tools WordPress plugin through 1.1.3 contains an unauthenticated arbitrary file upload vulnerability in the bundled SWFUpload component

CVE-2026-53611 AS203038 · looking-glass CWE-78 CRITICAL 9.8

Looking Glass is a modern, stateless network-diagnostic platform — a single self-contained Go binary that fronts a fleet of routers over SSH and exposes ping / traceroute / BGP lookups through a gRPC (ConnectRPC) API, an embedded SvelteKit …

CVE-2026-20212 Cisco · Cisco NX-OS Software CWE-1327 CRITICAL 9.8

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with&nbsp;root privileges. This vulnerability exists because TCP ports 43210 and 43211 ar…

CVE-2026-20274 Cisco · Cisco IOS XR Software CWE-664 CRITICAL 9.8

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that a…

CVE-2026-20279 Cisco · Cisco IOS XR Software CWE-284 CRITICAL 9.8

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening releases that a…

CVE-2026-19117 Delinea · Secret Server (On-Prem) CWE-290 CRITICAL 9.8

Under specific conditions, an attacker can register an attacker-controlled FIDO2 credential against a target account and then authenticate as that user. This issue affects on-premises deployments only.

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →