{"date_iso":"2026-09-04","date_human":"Friday, September 4, 2026","generated_utc":"2026-09-04 16:50 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters","link":"https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Cyber Security News","Dark Reading","SecurityWeek","The Hacker News"],"coverage":5,"cve_ids":[],"summary":"Microsoft is alerting of a \"high-volume phishing campaign\" that's using invisible Unicode tag characters to bypass email filters. \"Instead of using these characters to hide instructions from people while exposing them\u2026","source":"The Hacker News","date_rel":"52m ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjoD4eMYuhLT8HvcHbYe8A4hkhmDH1f4pIWTIm5AXKueqdpY1NS8yNiTtlzS4mdIS8PLY8_zM1uQDNpO1U49HCUoJT8nn2Bpb6krpcYpOSQ3H3Z6fUsm-UkoFvj8fk8oShK0eUhO6px8hox_ZzlnX8tu0pJKpJ3UAF2Vcb3XyBXjCt_8uD8OOkMMgUjv8Pc/s1600/emails.jpg","description":"Microsoft is alerting of a \"high-volume phishing campaign\" that's using invisible Unicode tag characters to bypass email filters. \"Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them,\" the Microsoft Security Research team said. The","related":[{"title":"In Other News: Microsoft\u2019s Cloud Patches, Hacked Dropbox Accounts, Guardio\u2019s $1.1B Valuation","link":"https://www.securityweek.com/in-other-news-microsofts-cloud-patches-hacked-dropbox-accounts-guardios-1-1b-valuation/","source":"SecurityWeek","date_rel":"30m ago"},{"title":"Microsoft says some users can\u2019t open the Teams desktop client","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-says-some-users-cant-open-the-teams-desktop-client/","source":"Bleeping Computer","date_rel":"2h ago"},{"title":"Microsoft 365 Phishing Technique Uses Empty Envelope Sender to Evade Direct Send Blocking","link":"https://cybersecuritynews.com/microsoft-365-phishing/","source":"Cyber Security News","date_rel":"4h ago"},{"title":"Microsoft: KB5120998 mouse reset bug affects only non-English PCs","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-kb5120998-mouse-reset-bug-affects-only-non-english-pcs/","source":"Bleeping Computer","date_rel":"3 Sep"},{"title":"Microsoft says KB5120998 Windows update resets desktop settings","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-says-kb5120998-windows-update-resets-desktop-settings/","source":"Bleeping Computer","date_rel":"3 Sep"},{"title":"Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users","link":"https://www.darkreading.com/cyberattacks-data-breaches/threat-gang-springs-vishing-attacks-microsoft-teams-users","source":"Dark Reading","date_rel":"2 Sep"}]},{"title":"New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic","link":"https://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.html","reason":"Linux","category":"News","sources":["CCCS Alerts & Advisories","Rapid7 Blog","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to\u2026","source":"The Hacker News","date_rel":"1h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgzLyhHupZwRy1pOQzT93Qhs5waZ8gqtlgDJUKgt1f37dz3KqIDDZY8uNo8QguZNccBHivdA_ecnY8cQUyhZQAvLH4APu3imxP-rwo2dYLZtKnJ92IkRPFmwepmJgRk9GrLrJiN_IbInwvNXaW7N5761YfEB1IIK4uDdNBTy6Koz8uXgOSXaQWixXM1Wts/s1600/HAProxy.jpg","description":"A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and","related":[{"title":"DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors","link":"https://www.rapid7.com/blog/post/tr-dprk-apts-ted-backdoor-curlrat-target-south-korean-media-automotive-sectors","source":"Rapid7 Blog","date_rel":"4h ago"},{"title":"SUSE Linux security advisory (AV26-882)","link":"https://cyber.gc.ca/en/alerts-advisories/suse-linux-security-advisory-av26-882","source":"CCCS Alerts & Advisories","date_rel":"21h ago"}]},{"title":"Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs","link":"https://thehackernews.com/2026/09/google-anthropic-and-openai-unveil.html","reason":"Google","category":"News","sources":["CCCS Alerts & Advisories","Infosecurity Magazine","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program\u2026","source":"The Hacker News","date_rel":"2 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiu5sAuC-e7tUigtaAj0gicqzy_kWZTZRujpV3IxqGW1wr_VCuXbKXG7M-nNIac5QO2GY_KtEQ8HfnUENc6JZpS8haeGQIvOH4EddDvrQTJwXY2kkZcz41JbeT1_YhVuyrArJV4sUB3hrT9dFIazMbT-_8hLxg0jrQzHLPLv_h3bNb98puP5yVwgA1zoIsQ/s1600/aiai.jpg","description":"Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. \"The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them","related":[{"title":"Google security advisory (AV26-883)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-883","source":"CCCS Alerts & Advisories","date_rel":"2h ago"},{"title":"Outsider Phishing Kit Survives Takedown With 700 New Pages","link":"https://www.infosecurity-magazine.com/news/outsider-phishing-kit-survives/","source":"Infosecurity Magazine","date_rel":"3 Sep"},{"title":"Google security advisory (AV26-874)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-874","source":"CCCS Alerts & Advisories","date_rel":"2 Sep"},{"title":"Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems","link":"https://thehackernews.com/2026/09/breeze-comet-executes-hundreds-of.html","source":"The Hacker News","date_rel":"1 Sep"}]},{"title":"Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials","link":"https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html","reason":"CVE-2026-9586","category":"News","sources":["CISA Alerts & Advisories","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-48710","CVE-2026-9586"],"summary":"Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586\u2026","source":"The Hacker News","date_rel":"2 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgb9lLZ-CHEFECU3vn2ObupuzweLn7l23dnUcs2Qd1H5hsxut3nQKqe6W3lbh_cSyVF4PDgdfuSauhpeMKmW6wZGYW3kpVdhTfWhfpISTtfRzw25VOSvJNR8dnh_WWKwyZ0VnWe8nndwwfnWN-gPSdqmLBhJW2vkqjCkfMo8Eo-sucoSIr6JMT-7HxHnsCw/s1600/admin.jpg","description":"Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as","related":[{"title":"Sangoma Switchvox Vulnerabilities Exploited in the Wild","link":"https://www.securityweek.com/sangoma-switchvox-vulnerabilities-exploited-in-the-wild/","source":"SecurityWeek","date_rel":"3h ago"},{"title":"CISA Adds Seven Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/02/cisa-adds-seven-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"2 Sep"}]},{"title":"AI's Vulnerability Surge May Be More Manageable Than First Feared","link":"https://www.darkreading.com/application-security/ai-vulnerability-surge-manageable-than-first-feared","reason":"Teams","category":"News","sources":["CyberScoop","Dark Reading","Microsoft Security Blog"],"coverage":3,"cve_ids":[],"summary":"New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams \u2014 if they have the right strategies.","source":"Dark Reading","date_rel":"2 Sep","thumbnail":"https://eu-images.contentstack.com/v3/assets/blt6d90778a997de1cd/blte6af1f929e3d31c4/6a9884c2f1ca2225aef25fe1/claude_FotoField_shutterstock.jpg?width=720&quality=80&disable=upscale","description":"","related":[{"title":"Why judgment is emerging as cybersecurity\u2019s defining skill","link":"https://cyberscoop.com/ai-security-operations-human-context-ciso-op-ed/","source":"CyberScoop","date_rel":"6h ago"},{"title":"Impersonating IT support: how threat actors turn a remote session into enterprise-wide access","link":"https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/","source":"Microsoft Security Blog","date_rel":"2 Sep"}]},{"title":"Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon","link":"https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html","reason":"Crowdstrike","category":"News","sources":["Bleeping Computer","CyberScoop","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a proof-of-concept (PoC) for a privilege escalation flaw\u2026","source":"The Hacker News","date_rel":"3 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmg6caSDWQVOPIIl9NAXS4ofXmOdWz1eIGPMKMLCbHXc_uWiv11QNh2k-f43JAoVVQNMQj54d2yqJ_iO9vzwIO8nvQIyxr7N6GDCKsYDmSJEpyjiUBsY-zhMcmfEsWcEqDrKvrEkXxQC1LPldFXkqbJHO81V7oHnsRtuyjMZKzubBjwrK_yQ2xT2om89Ja/s1600/windows-exploit.jpg","description":"The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a proof-of-concept (PoC) for a privilege escalation flaw impacting Crowdstrike Falcon. \"FalconFlank is a 0-day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor,\" the researcher said in","related":[{"title":"New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges","link":"https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/","source":"Bleeping Computer","date_rel":"3h ago"},{"title":"Dogged Russia-based botnet dismantled after 23-year run","link":"https://cyberscoop.com/sality-botnet-dismantled/","source":"CyberScoop","date_rel":"2 Sep"}]},{"title":"Podcast: We Spoke to an Amazon Worker Destroying Books for AI","link":"https://www.404media.co/podcast-we-spoke-to-an-amazon-worker-destroying-books-for-ai/","reason":"Amazon","category":"News","sources":["404 Media","Malwarebytes Labs"],"coverage":2,"cve_ids":[],"summary":"We start this week with Emanuel\u2019s follow-up to his Amazon book scanning story, in which he spoke to someone who worked in the Amazon warehouse which destroys books to train Amazon\u2019s AI products. After the break, Emanuel\u2026","source":"404 Media","date_rel":"2 Sep","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/09/maxresdefault-4.jpg","description":"We start this week with Emanuel\u2019s follow-up to his Amazon book scanning story, in which he spoke to someone who worked in the Amazon warehouse which destroys books to train Amazon\u2019s AI products. After the break, Emanuel and Sam tell us about the same few names appearing in LLM output over and over again. In the subscribers-only section, Joseph tells us why ICE is buying loads of data about \u2018voter fraud\u2019. Listen to the weekly podcast on Apple Podcasts , Spotify , or YouTube . Become a paid subscriber for access to this episode's bonus content and to power our journalism. If you become a paid\u2026","related":[{"title":"Free streaming boxes may be routing criminal traffic through your home","link":"https://www.malwarebytes.com/blog/news/2026/09/free-streaming-boxes-may-be-routing-criminal-traffic-through-your-home","source":"Malwarebytes Labs","date_rel":"7h ago"}]},{"title":"Hackers Use Popular Messaging Services to Control New Windows Backdoors","link":"https://cybersecuritynews.com/popular-messaging-services/","reason":"Windows","category":"News","sources":["Cyber Security News","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"A financially motivated threat group known as Toy Ghouls has begun using two custom Windows backdoors that communicate through popular messaging and broker services. The tools give attackers a discreet way to run\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Hackers-Use-Popular-Messaging-Services-to-Control-New-Windows-Backdoors.webp","description":"A financially motivated threat group known as Toy Ghouls has begun using two custom Windows backdoors that communicate through popular messaging and broker services. The tools give attackers a discreet way to run commands, collect system details, and maintain control over compromised devices. The campaign marks a change for the group, which had previously relied heavily on public tools and leaked ransomware builders. Its move to custom malware suggests a broader effort to stay inside victim networks longer while making activity harder for security teams to spot. Analysts at Securelist\u2026","related":[{"title":"BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory","link":"https://thehackernews.com/2026/09/brazetsu-malware-turns-compromised.html","source":"The Hacker News","date_rel":"3 Sep"}]},{"title":"Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day","link":"https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html","reason":"CVE-2026-85046","category":"News","sources":["Malwarebytes Labs","The Hacker News"],"coverage":2,"cve_ids":["CVE-2026-85046"],"summary":"Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8)\u2026","source":"The Hacker News","date_rel":"9h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjelmC2UuYemuI1nBeaecfPBZ1Bfb5nz6T51_OhCUPHJivX8ioIjrYMVtVsjsrcA0xbEe_O4iMthJ2xwXWJVhAb5CCJlhnJS4McM9IpmPww86RSznT3h7pg5DYOXlnwon616y-1s2qwbWbmR40B5JCvYbtwM8lD5Fk5yLHWS7IKmH5pXQ8qO4SfEasBhhsq/s1600/chrome-v8-exploit.jpg","description":"Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. \"Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote","related":[{"title":"Two critical Chrome flaws put users at risk on malicious websites","link":"https://www.malwarebytes.com/blog/bugs/2026/09/two-critical-chrome-flaws-put-users-at-risk-on-malicious-websites","source":"Malwarebytes Labs","date_rel":"2 Sep"}]},{"title":"Microsoft Confirms New Exchange Online Outage Delaying Emails from External Domains","link":"https://cybersecuritynews.com/exchange-online-outage-delaying-emails/","reason":"Exchange","category":"News","sources":["Bleeping Computer","Cyber Security News"],"coverage":2,"cve_ids":[],"summary":"Microsoft has confirmed a fresh Exchange Online incident, tracked as EX1467029, causing delays for users sending and receiving email messages from external domains. The company first acknowledged the disruption on\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Exchange-Online-Outage-Delaying-Emails.webp","description":"Microsoft has confirmed a fresh Exchange Online incident, tracked as EX1467029, causing delays for users sending and receiving email messages from external domains. The company first acknowledged the disruption on September 4, 2026, flagging it as a service degradation issue affecting Exchange Online, one of the most widely used business email platforms in the world. According to Microsoft\u2019s service health updates, the outage began around 3:49 PM GMT+5:30 and has continued through multiple status revisions issued that afternoon, with updates posted at 4:06 PM, 4:33 PM, and 5:56 PM. Affected\u2026","related":[{"title":"Exchange Online outage causes email delays, 'Server busy' errors","link":"https://www.bleepingcomputer.com/news/microsoft/exchange-online-outage-causes-email-delays-server-busy-errors/","source":"Bleeping Computer","date_rel":"4h ago"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-85061","vendor":"maplibre","product":"maplibre-gl-js","severity":"CRITICAL","score":10.0,"description":"MapLibre GL JS is an interactive vector tile map library for web browsers. Prior to 6.4.1, DOM.sanitize() in src/util/dom.ts iterates elem.attributes as a live NamedNodeMap while removeAttributes() removes attributes from the same collectio\u2026","cwe":"CWE-79","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-85061"},{"id":"CVE-2026-70352","vendor":"Microsoft","product":"Azure AI Language Authoring","severity":"CRITICAL","score":10.0,"description":"Missing authentication for critical function in Azure AI Language allows an unauthorized attacker to elevate privileges over a network.","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-70352"},{"id":"CVE-2026-83711","vendor":"Microsoft","product":"Entra","severity":"CRITICAL","score":10.0,"description":"Authorization bypass through user-controlled key in Microsoft Azure Active Directory B2C allows an unauthorized attacker to elevate privileges over a network.","cwe":"CWE-639","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-83711"},{"id":"CVE-2026-85031","vendor":"TOTOLINK","product":"CP450","severity":"CRITICAL","score":9.9,"description":"A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote exploitation of the attac\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":0.0058,"url":"https://cve.blackmesa.ca/?q=CVE-2026-85031"},{"id":"CVE-2026-85223","vendor":"D-Link","product":"DNS-340L","severity":"CRITICAL","score":9.9,"description":"A vulnerability was found in D-Link DNS-340L 1.01B04. Affected by this issue is some unknown functionality of the file /cgi-bin/dropbox.cgi of the component CGI Handler. Performing a manipulation of the argument callback_url/sync_interval r\u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-85223"},{"id":"CVE-2026-85154","vendor":"WWBN","product":"AVideo","severity":"CRITICAL","score":9.8,"description":"WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-85154"},{"id":"CVE-2026-85109","vendor":"Tenda","product":"HG10","severity":"CRITICAL","score":9.8,"description":"A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead to buffer overflow.\u2026","cwe":"CWE-119","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-85109"},{"id":"CVE-2026-85181","vendor":"dianping","product":"cat","severity":"CRITICAL","score":9.8,"description":"CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can set the x-forwarded-for header to bypass IP binding validation and \u2026","cwe":"CWE-565","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-85181"},{"id":"CVE-2026-84238","vendor":"WordPress","product":"YITH Request a Quote for WooCommerce Premium","severity":"CRITICAL","score":9.8,"description":"Unauthenticated Broken Access Control in YITH Request a Quote for WooCommerce Premium < 4.46.0 versions.","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-84238"},{"id":"CVE-2026-84753","vendor":"WPFunnels","product":"Mail Mint","severity":"CRITICAL","score":9.8,"description":"Unauthenticated PHP Object Injection in Mail Mint <= 1.31.0 versions.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-84753"}],"vendor_spikes":[{"vendor":"WordPress","count":29,"critical_count":4},{"vendor":"Linux","count":28,"critical_count":0},{"vendor":"themoos","count":18,"critical_count":5},{"vendor":"Microsoft","count":17,"critical_count":6},{"vendor":"Google","count":14,"critical_count":4},{"vendor":"moos-ivp","count":13,"critical_count":6},{"vendor":"misp","count":12,"critical_count":0},{"vendor":"Red Hat","count":11,"critical_count":0},{"vendor":"WWBN","count":11,"critical_count":1},{"vendor":"MongoDB","count":9,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":434,"has_news_data":true,"has_cve_data":true}