Skip to content

Morning Brief

Friday, September 4, 2026 · generated 2026-09-04 16:50 UTC · ~5 min read

Top developments

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them…

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to…

Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program…

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586…

AI's Vulnerability Surge May Be More Manageable Than First Feared

New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.

Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a proof-of-concept (PoC) for a privilege escalation flaw…

Podcast: We Spoke to an Amazon Worker Destroying Books for AI

We start this week with Emanuel’s follow-up to his Amazon book scanning story, in which he spoke to someone who worked in the Amazon warehouse which destroys books to train Amazon’s AI products. After the break, Emanuel…

Hackers Use Popular Messaging Services to Control New Windows Backdoors

A financially motivated threat group known as Toy Ghouls has begun using two custom Windows backdoors that communicate through popular messaging and broker services. The tools give attackers a discreet way to run…

Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8)…

Microsoft Confirms New Exchange Online Outage Delaying Emails from External Domains

Microsoft has confirmed a fresh Exchange Online incident, tracked as EX1467029, causing delays for users sending and receiving email messages from external domains. The company first acknowledged the disruption on…

Vulnerability watch

CVE-2026-85061 maplibre · maplibre-gl-js CWE-79 CRITICAL 10.0

MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collectio…

CVE-2026-70352 Microsoft · Azure AI Language Authoring CWE-306 CRITICAL 10.0

Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-83711 Microsoft · Entra CWE-639 CRITICAL 10.0

Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.

CVE-2026-85031 TOTOLINK · CP450 CWE-119 CRITICAL 9.9 · EPSS 0%

A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote exploitation of the attac…

CVE-2026-85223 D-Link · DNS-340L CWE-77 CRITICAL 9.9

A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval r…

CVE-2026-85154 WWBN · AVideo CWE-269 CRITICAL 9.8

WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a…

CVE-2026-85109 Tenda · HG10 CWE-119 CRITICAL 9.8

A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow.…

CVE-2026-85181 dianping · cat CWE-565 CRITICAL 9.8

CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can set the x-forwarded-for header to bypass IP binding validation and …

CVE-2026-84238 WordPress · YITH Request a Quote for WooCommerce Premium CWE-862 CRITICAL 9.8

Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.

CVE-2026-84753 WPFunnels · Mail Mint CWE-502 CRITICAL 9.8

Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →