Daily DefSec Brief

Jerry Bell

A daily podcast covering the important cyber security news that IT and security teams need to know.

  1. 7h ago ·  Video

    Cyber Security News for September 14 2026 - Daily DefSec Brief

    1. GitLab path traversal at CVSS 10, now exploited — CVE-2026-85706 — Do: Upgrade GitLab, then grep for file.path — https://watchtowr.com/resources/rapid-reaction-gitlab-critical-path-traversal-vulnerability-cve-2026-85706/ 2. ScreenConnect file-transfer flaw now has a patch — CVE-2026-84869 — Do: Upgrade ScreenConnect to 26.6.5 — https://www.connectwise.com/company/trust/security-bulletins/2026-09-08-screenconnect-bulletin 3. Artifactory chain mints admins, drops a backdoor — CVE-2026-42018, CVE-2026-42016 — Do: Patch Artifactory, audit admin accounts — https://www.wiz.io/blog/artifactory-under-attack-in-the-wild-exploitation-of-cve-2026-42016-cve-2026-4201 4. Metasploit weaponizes five KEV flaws at once — CVE-2026-20079, CVE-2026-83549, CVE-2026-63077, CVE-2026-82078, CVE-2026-19295 — Do: Patch the five KEV flaws now weaponized — https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-goes-to-sixteen 5. Plesk restore race gives a customer root — CVE-2026-68488 — Do: Upgrade Plesk to 18.0.80.7 — https://support.plesk.com/hc/en-us/articles/43248932867351-Vulnerability-in-Plesk-s-Backup-Manager-symlink-race-during-restore-allows-root-privilege-escalation 6. Dell ObjectScale unauth RCE at CVSS 10 — CVE-2026-70416 — Do: Upgrade ObjectScale to 4.4.0.0 — https://securityonline.info/dell-objectscale-vulnerabilities-cve-2026-70416/ 7. Direct Send phishing lands as internal mail — Do: Set RejectDirectSend to true in M365 — https://www.infosecurity-magazine.com/news/hackers-us-business-hours-m365/ 8. Malware hosted on AI vendors' own domains — Do: Filter AI share links as user content — https://www.huntress.com/blog/ai-attack-surface 9. Fake agency request passed every email check — Do: Verify agency data requests out of band — https://www.bleepingcomputer.com/news/security/revolut-discloses-data-breach-exposing-financial-info-passports/ 10. 1.8 million APKs mined for hardcoded secrets — Do: Scan your shipped mobile apps for secrets — https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/ 11. Stolen police login opened a state DMV database — Do: Inventory external accounts into your systems — https://therecord.media/florida-shiny-hunters-motor-vehicle 12. Kiro wrote the edit before you approved it — CVE-2026-89332 — Do: Upgrade Kiro to 0.8.135, rotate creds — https://aws.amazon.com/security/security-bulletins/rss/2026-111-aws/ 13. 76% deployed Copilot, 43% reviewed permissions — Do: Review M365 oversharing before Copilot — https://www.infosecurity-magazine.com/news/organizations-skip-permissions-ai/ 14. IT staff clicked more than any other team — Do: Include IT in phishing simulations — https://www.securityweek.com/phishing-research-challenges-conventional-security-awareness-testing/ 15. OpenAI agent swarm ran the RubyGems attack — Do: Rotate RubyGems API keys from May — https://www.infosecurity-magazine.com/news/openai-agent-swarm-hacks-rubygems/

  2. 3d ago ·  Video

    Cyber Security News for September 11 2026 - Daily DefSec Brief

    1. Two MikroTik flaws exploited, deadline Sunday — CVE-2026-86060, CVE-2026-67277 — Do: Patch RouterOS, close SSH and btest — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. WatchGuard Firebox now in ransomware — CVE-2025-14733 — Do: Upgrade Fireware to 12.5.15 or later — https://www.scworld.com/news/cisa-watchguard-firebox-bug-exploited-in-ransomware-campaigns · NVD — https://nvd.nist.gov/vuln/detail/CVE-2025-14733 3. Two 9.8s in Check Point VPN certs — CVE-2026-85102, CVE-2026-85103 — Do: Apply Check Point's 9 September VPN fixes — https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html 4. AWS SSM agent leaks instance credentials — CVE-2026-89049 — Do: Upgrade SSM Agent to 3.3.4851.0 — https://aws.amazon.com/security/security-bulletins/rss/2026-107-aws/ 5. Backup driver writes below the OS — CVE-2026-12780 — Do: Block amwrtdrv.sys, confirm Secure Boot on — https://kb.cert.org/vuls/id/687587 · NVD — https://nvd.nist.gov/vuln/detail/CVE-2026-12780 6. AI closed the detection-evasion loop — Do: Weight behavioural detection over signatures — https://www.securityweek.com/anthropic-says-russian-hackers-used-claude-ai-to-automate-malware-evasion/ 7. BYOD calls end at the Graph API — Do: Alert on new MFA device registrations — https://www.darkreading.com/threat-intelligence/voice-callers-exploit-byod-microsoft-365-corporate-data 8. IDScan confirms the licence breach — Do: Ask vendors how long they keep the scan — https://www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153-million-stolen-drivers-licenses/ 9. Sogou input method drops a backdoor — CVE-2026-51990 — Do: Confirm Sogou is on an April 2026 build — https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html 10. Work profiles hide a banking trojan — Do: Test your app's checks inside a work profile — https://thehackernews.com/2026/09/gigabud-creates-android-work-profiles.html 11. Android ransomware plus spyware — Do: Block sideloading, alert on Accessibility grants — https://www.infosecurity-magazine.com/news/mantaxotax-android-malware/ 12. MCP tool descriptions act as instructions — Do: Review and pin your MCP tool descriptions — https://www.scworld.com/resource/when-english-becomes-exploit-code-the-hidden-risk-inside-mcp-servers 13. Root on the node forges workload identity — Do: Shorten SPIFFE credential lifetimes — https://unit42.paloaltonetworks.com/kubernetes-spiffe-spire-identity-spoofing/ 14. Passkeys move between managers — Do: Revisit passkeys now migration works — https://www.helpnetsecurity.com/2026/09/10/google-android-password-manager-transfer/ 15. Invoice fraud with an AI paper trail — Do: Call back on every payment-detail change — https://www.microsoft.com/en-us/security/blog/2026/09/10/protecting-organizations-ai-assisted-executive-impersonation-invoice-fraud/

  3. 4d ago ·  Video

    Cyber Security News for September 10 2026 - Daily DefSec Brief

    1. Cisco firewall manager exploited to root — CVE-2026-20079 (CVSS 10.0), CVE-2026-20316 — Do: Apply the Cisco Secure FMC hotfixes now — Cisco Talos — https://blog.talosintelligence.com/fmc-ongoing-exploitation/ 2. NetScaler auth bypass now actively exploited — CVE-2026-19490 (CVSS 9.3, NVD v4.0) — Do: Upgrade NetScaler to 14.1-73.32 or 13.1-63.21 — Rapid7 — https://www.rapid7.com/blog/post/etr-cve-2026-19490-critical-vulnerability-affecting-citrix-netscaler-adc-and-netscaler-gateway/ 3. Four spy crews, one shared exploit kit — CVE-2026-85046, CVE-2026-85880 — Do: Confirm Chrome 153 and September Windows landed — The Record — https://therecord.media/china-hackers-chrome-browser-zero-day-multiple-groups 4. FortiOS packet flaw added to CISA KEV — CVE-2025-25249 (CVSS 8.1) — Do: Upgrade FortiOS off the affected branches — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 5. Passkey social engineering ends in cloud takeover — Do: Alert on new auth methods added to accounts — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/09/09/passkey-themed-social-engineering-leads-identity-cloud-compromise/ 6. Shai-Hulud back past npm's scan — feishu-docx-mcp, bmc-i18n-extract-cli, blueai-cli, bmc-translate-utils — Do: Rotate npm tokens, install with --ignore-scripts — Aikido Security — https://www.aikido.dev/blog/shai-hulud-npm-resurfaces 7. Phishing page assembled inside the browser — Do: Alert on OAuth redirects leaving Microsoft — Help Net Security — https://www.helpnetsecurity.com/2026/09/10/browser-based-phishing-blob-urls-microsoft-oauth/ 8. Stealer logs yield replayable AI tokens — Do: Rotate AI provider keys after any stealer hit — https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html 9. Fortinet portal leaks a token-forging secret — CVE-2026-84390 (CVSS 9.6), CVE-2026-84388 (CVSS 9.1) — Do: Patch FortiPAM and the browser extension together — SecurityWeek — https://www.securityweek.com/fortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extension/ 10. Android patches 180 flaws in one month — Do: Push the September Android patch level — https://www.securityweek.com/androids-september-2026-updates-patch-180-vulnerabilities/ 11. AI workflows run on the wrong identity — Do: Run AI workflows as the requester — https://www.darkreading.com/threat-intelligence/identity-based-ai-attack-security-enterprise-data 12. Agent could turn off its own sandbox — CVE-2026-82533 (CVSS 9.6) — Do: Update DeepSeek Harness to 0.1.2-alpha.1 — https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html 13. Scanning and brute force on Proxmox — Do: Take Proxmox port 8006 off the internet —https://isc.sans.edu/diary/rss/33324 14. Vendor credentials opened an EHR API — Do: List vendors holding API credentials to you — The Record — https://therecord.media/electronic-health-record-company-says-customer-data-stolen-in-breach 15. Machine identities overtake phishing — Do: Inventory and expire non-human identities — https://www.infosecurity-magazine.com/news/nhis-number-one-corporate-entry/ 16. Contractor's admin account outlived him — Do: Match every admin account to a current person — The Register — https://www.theregister.com/security/2026/09/10/dental-contractor-set-up-secret-account-with-access-to-4000-patient-records-then-left-the-company/5295361 17. EU gives you 24 hours to report from Friday — Do: Name who files your EU 24-hour report — Dark Reading — https://www.darkreading.com/cybersecurity-operations/eu-cyber-resilience-act-reporting-requirements 18. Phishing from the vendor's own address — Do: List who can send mail as your domain — BleepingComputer — https://www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/

  4. 5d ago ·  Video

    Cyber Security News for September 9 2026 - Daily DefSec Brief

    1. Record 974-CVE Patch Tuesday, two zero-days live — CVE-2026-81963, CVE-2026-85880 (CVSS 7.8) — Do: Install September Windows updates now — SecurityWeek — https://www.securityweek.com/microsoft-patches-record-974-vulnerabilities-including-two-exploited-zero-days/ 2. Chrome 153 patches its seventh zero-day of 2026 — CVE-2026-87491 — Do: Push Chrome 153.0.8010.36, force restart — SecurityWeek — https://www.securityweek.com/chrome-153-patches-seventh-zero-day-of-2026/ 3. F5 BIG-IP rootkit hides its web shell in memory — CVE-2025-53521 (CVSS 9.8) — Do: Patch BIG-IP APM, then hunt memory — The Hacker News — https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html 4. Defender patch bypassed again, no fix yet — CVE-2026-69414 (the bypassed fix) — Do: No fix — watch SYSTEM-level file reads — Security Affairs — https://securityaffairs.com/198726/security/chaotic-eclipse-released-shieldcrash-a-poc-for-microsoft-defender-zero-day.html 5. SAP kernel flaw scores 10.0, no auth needed — CVE-2026-44756 (CVSS 10.0) — Do: Apply September SAP security notes — SecurityWeek — https://www.securityweek.com/sap-patches-critical-extended-passport-processing-vulnerability/ 6. Phishing chain hides inside Google's own redirects — Do: Hunt unauthorised ScreenConnect installs — Dark Reading — https://www.darkreading.com/cyberattacks-data-breaches/attackers-multi-hop-google-redirects-phishing-campaign 7. Ivanti patches ten flaws, two unauth RCE at 9.8 — CVE-2026-12744, CVE-2026-12745, CVE-2026-18851, CVE-2026-83527 — Do: Patch EPMM to 12.10.0.0 or 12.9.0.2 — Ivanti — https://www.ivanti.com/blog/september-2026-security-update 8. ClearFake runs its loader straight off WebDAV — Do: Block outbound WebDAV at the proxy — Cisco Talos — https://blog.talosintelligence.com/clearfake-webdav-infection-chain/ 9. New N-central chain creates its own admin account — CVE-2026-86206, CVE-2026-86207 — Do: Apply N-central 2026.3 Hotfix 3 — Rapid7 — https://www.rapid7.com/blog/post/ve-cve-2026-86206-cve-2026-86207-n-able-n-central-authentication-bypass-fixed 10. FreeIPA lets an anonymous client become admin — CVE-2026-76578, CVE-2026-13097, CVE-2026-76560, CVE-2026-79678 — Do: Update FreeIPA to 4.13.4 — The Hacker News — https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html 11. Extortion crews now steal the model itself — Do: Inventory model weights as crown jewels — The Register — https://www.theregister.com/research/2026/09/08/extortion-crews-have-their-eyes-on-high-value-ai-data-google-warns/5294640 12. VMware Workstation and Fusion guest escapes — CVE-2026-59346, CVE-2026-59347 — Do: Update VMware Workstation and Fusion — SC World — https://www.scworld.com/brief/broadcom-patches-critical-vmware-workstation-and-fusion-vm-escape-vulnerabilities 13. Planted prompt sent ChatGPT's Gmail data elsewhere — Do: Cut ChatGPT connector scopes back — Check Point Research — https://research.checkpoint.com/2026/the-shared-clipboard-inside-the-sandbox-cross-account-data-leakage-in-chatgpt/ 14. Android RAT worms through open ADB ports — Do: Disable ADB over TCP on managed Android — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/thost9-android-rat-packed-loader/ 15. UEFI shell in flash defeats Secure Boot — CVE-2026-20293, VU#718077 — Do: Set BIOS passwords, patch UCS firmware — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ucs-uefi-sb-bypass-eb6xC5GW 16. Military kills ad IDs — Do: Disable advertising IDs via MDM — Bitdefender — https://www.bitdefender.com/en-us/blog/hotforsecurity/us-military-turned-off-ad-tracking-phones 17. BleachBit's shredder skipped parts of the file — Do: Update BleachBit, wipe free space — Help Net Security — https://www.helpnetsecurity.com/2026/09/09/bleachbit-6-0-4-released/

  5. 6d ago ·  Video

    Cyber Security News for September 8 2026 - Daily DefSec Brief

    1. A maximum-severity Magento zero-day was exploited for three days before Adobe shipped a fix — CVE-2026-75650 — Do: Apply the APSB26-146 composer patch, then hunt — Adobe — https://helpx.adobe.com/security/products/magento/apsb26-146.html 2. MikroTik routers taken over through an SSH key check that ignores half the key — CVE-2026-67276, CVE-2026-67277 — Do: Update RouterOS, then audit SSH users and keys — CERT Polska — https://cert.pl/en/posts/2026/09/vulnerabilities-in-mikrotik-routeros-actively-exploited/ 3. N-able's fourth N-central hotfix in five weeks, and its own notices disagree on exploitation — CVE-2026-86218 — Do: Install N-central Hotfix 4, build 2026.3.1.14 — N-able — https://status.n-able.com/2026/09/06/n-central-2026-3-hotfix-4-cve-2026-86218/ 4. A phishing service beat MFA at 258 organisations and took 5,000 Microsoft 365 logins — Do: Move admins to phishing-resistant sign-in — BleepingComputer — https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/ 5. ConnectWise has no patch for a ScreenConnect file-transfer flaw, and rogue clients are spreading malware — Do: Deselect TransferFiles on every ScreenConnect role — ConnectWise — https://www.connectwise.com/company/trust/advisories 6. Attackers are phoning executives, posing as the help desk, and walking off with the session — Do: Give the help desk a caller-verification step — The Hacker News — https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html 7. One researcher dropped zero-days for Avast, CrowdStrike and Nvidia inside a week — Do: Disable Falcon's Office macro removal for now — SecurityWeek — https://www.securityweek.com/nightmare-eclipse-drops-crowdstrike-nvidia-avast-zero-day-exploits/ 8. A working exploit chain for Telerik is now public, two months after the patch — CVE-2019-18935, CVE-2026-13181 — Do: Upgrade Telerik UI to 2026.2.708 or later — The Hacker News — https://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html 9. A fake bookmarks extension turns Chrome and Edge into a command channel — Do: Hunt for extensions loaded outside the Web Store — The Hacker News — https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html 10. Nine years of passenger records sat in an Elasticsearch cluster anyone could reach — Do: Find search clusters answering from the internet — BleepingComputer — https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/ 11. Berlin refused a €2m ransom and Rhysida published nearly six terabytes — Do: Write down who refuses a ransom — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/rhysida-berlin-data-extortion/ 12. An unpatched Metabase handed over a million students' details — Do: Patch and gate your self-hosted BI tools — Help Net Security — https://www.helpnetsecurity.com/2026/09/08/mathspace-data-breach-metabase-vulnerability/ 13. The NCSC says most staff are already using AI you have not approved — Do: Publish an approved AI tool people will use — NCSC — https://www.ncsc.gov.uk/blog-post/shadow-ai 14. Ransomware negotiation has turned into a business process with its own staff — Do: Work out your own ransom number first — Help Net Security — https://www.helpnetsecurity.com/2026/09/08/ransomware-negotiation-tactics-video/ 15. A North Korean backdoor is compiled into the victim's own load balancer — Do: Verify HAProxy and daemons against their packages — Security Affairs — https://securityaffairs.com/198656/apt/north-korea-linked-hackers-hide-a-backdoor-inside-haproxy.html 16. The SEO agency poisoning your search results has been at it since 2015 — — The Hacker News — https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html

  6. Sep 4 ·  Video

    Cyber Security News for September 4 2026 - Daily DefSec Brief

    1. Chrome patches a V8 zero-day that attackers are already using — CVE-2026-85046 — The Hacker News — https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html 2. Coder's package registry served Terraform modules that steal credentials (malicious modules served 07:35–21:45 UTC, Mon 31 Aug, advisory GHSA-vx42-ghc9-gw65) — BleepingComputer — https://www.bleepingcomputer.com/news/security/coders-registry-infrastructure-compromised-to-push-malicious-modules/ 3. HPE patches unauthenticated code execution in ArubaOS-CX switches (fixed in 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, 10.10.1181) — CVE-2026-73749 — BleepingComputer — https://www.bleepingcomputer.com/news/security/hpe-patches-critical-arubaos-cx-remote-code-execution-flaw/ 4. Casdoor lets one tenant's admin act on every other tenant, with no patch available (3.115.0 and earlier) — CVE-2026-15630 — CERT/CC — https://kb.cert.org/vuls/id/889462 5. Cisco ships seven IOS XR flaws as one hardening release (no fixed release, upgrade to a release with SMUs, then apply them) — CVE-2026-20274, CVE-2026-20279 — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM 6. Phishing hides lure words from email filters with invisible Unicode (strip U+E0000–U+E007F before applying signatures) — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/ 7. AWS patches command injection in the CodeCatalyst blueprints framework (@amazon-codecatalyst/blueprints.blueprint before 0.3.156) — CVE-2026-85012 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-095-aws/ 8. A China-linked espionage crew is running its intrusions through AI agents — Security Affairs — https://securityaffairs.com/198417/ai/chinese-hackers-use-ai-agents-in-multi-country-cyber-campaign.html 9. BraZetsu packages a compromised Windows host into something an access broker can sell — The Hacker News — https://thehackernews.com/2026/09/brazetsu-malware-turns-compromised.html 10. Toy Ghouls runs its new backdoor's command channel over HiveMQ and Element — Securelist — https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/ 11. Fourteen fake macOS installers deliver the OtterCookie remote access trojan — Jamf Threat Labs — https://www.jamf.com/blog/contagious-interview-trojanized-macos-installers/ 12. A phishing kit produced 700 new pages in the month after its servers were seized — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/outsider-phishing-kit-survives/ 13. The 153 million driver's licence scans have a suspected source — Security Affairs — https://securityaffairs.com/198388/security/dark-web-service-nexus-sells-153m-drivers-licenses.html 14. Thomson Reuters breach exposed sealed court records across eleven states — The Hacker News — https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html 15. A fake acquisition, a forged NDA, and instructions not to tell your colleagues — Dark Reading — https://www.darkreading.com/cyberattacks-data-breaches/large-enterprises-fake-merger-acquisition-scams 16. An AI found 23,000 vulnerabilities and nobody has looked at 21,000 of them — Help Net Security — https://www.helpnetsecurity.com/2026/09/04/echo-claude-mythos-vulnerability-findings/

  7. Sep 3 ·  Video

    Cyber Security News for September 3 2026 - Daily DefSec Brief

    1. Kestra workflow engine lets anyone run commands with no credentials at all — CVE-2026-49869 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog 2. GitSpawn lets a repository's own config run commands through your AI coding agent — CVE-2026-19592, CVE-2026-55607, CVE-2026-71963, CVE-2026-72718 — Manifold Security — https://www.manifold.security/blog/ai-coding-agents-git-hijack 3. Cisco Nexus 9000 switches take unauthenticated code execution as root — CVE-2026-20212 — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-f2SiMFxl 4. LiteLLM accepts any bearer token as a valid MCP session — CVE-2026-59822 — BerriAI advisory — https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q 5. BadHost defeats authentication anywhere Starlette rebuilds the URL — CVE-2026-48710 — CCB Belgium — https://ccb.belgium.be/advisories/warning-vulnerability-starlette-framework-and-related-frameworks-fastapi-exposes 6. Exploit published for a Cleo Harmony authentication bypass — CVE-2026-84115 — SecurityWeek — https://www.securityweek.com/exploit-published-for-fresh-cleo-harmony-vulnerability/ 7. Dropbox accounts opened through a flaw in Lenovo's email verification — BleepingComputer — https://www.bleepingcomputer.com/news/security/dropbox-accounts-breached-through-lenovo-email-verification-flaw/ 8. Fake IT support on Teams now ends in a Node.js implant and hands-on-keyboard access — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/ 9. The Gentlemen ransomware turns off EDR and backups before encrypting — Cyber Security News — https://cybersecuritynews.com/the-gentlemen-ransomware/ 10. Researcher publishes a CrowdStrike Falcon privilege-escalation exploit — Security Affairs — https://securityaffairs.com/198342/hacking/chaotic-eclipse-releases-crowdstrike-falcon-zeroday-falconflank.html 11. Windows starts switching memory integrity on by itself in October — Help Net Security — https://www.helpnetsecurity.com/2026/09/03/windows-memory-integrity-update/ 12. One AI model completed a full cyber kill chain on its own in Booz Allen's tests — The Register — https://www.theregister.com/security/2026/09/02/claude-mythos-only-model-to-complete-full-cyber-kill-chain-experts-say/5294071 13. Attackers are self-hosting a chat interface on the infrastructure they compromise — Unit 42 — https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/ 14. Chrome ships 26 fixes including two critical use-after-free bugs — CVE-2026-84352, CVE-2026-84353 — SecurityWeek — https://www.securityweek.com/chrome-and-firefox-updates-patch-dozens-of-vulnerabilities/ 15. Teams and Outlook fail to launch on ARM Windows after the August updates — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-teams-outlook-fail-to-launch-on-arm-based-windows-pcs/ 16. A hundred and fifty-three million driver's licence scans are for sale — Ars Technica — https://arstechnica.com/security/2026/09/my-drivers-license-is-one-of-153-million-for-sale-on-a-new-dark-website/

  8. Sep 2 ·  Video

    Cyber Security News for September 2 2026 - Daily DefSec Brief

    1. SonicWall SMA1000 zero-days chained for pre-auth remote code execution — CVE-2026-83548, CVE-2026-83549 — SecurityWeek — https://www.securityweek.com/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks/ 2. JFrog Artifactory authentication bypass exploited four days after the patch — CVE-2026-82329 — SC World — https://www.scworld.com/news/jfrog-artifactory-flaw-exploited-days-after-patch-release 3. Langflow remote code execution used to harvest OpenAI and AWS keys — CVE-2026-0768 — BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/ 4. Twenty-two thousand Exchange servers still unpatched against a mailbox takeover flaw — CVE-2026-62911 — BleepingComputer — https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/ 5. AI agents ran a full ransomware intrusion in under ten hours — Unit 42 — https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/ 6. FBI warns of consent phishing that takes an account without a password — CyberScoop — https://cyberscoop.com/fbi-alert-oauth-consent-phishing-campaign/ 7. Sangoma Switchvox SQL injection is being exploited seven weeks after the fix — CVE-2026-9586 — The Hacker News — https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html 8. GeoNetwork chain gives unauthenticated code execution on government geoportals — CVE-2026-63219 — The Hacker News — https://thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html 9. Counterfeit software download sites are installing malware that turns Defender off — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/ 10. Phishing crew abuses a real endpoint-management platform to install ScreenConnect — BleepingComputer — https://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect/ 11. Airport breach traced to admin keys sitting in the websites' own JavaScript — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/fulcrumsec-manchester-airport/ 12. Stolen API key burned 600,000 dollars of model credits before anyone noticed — The Register — https://www.theregister.com/security/2026/09/01/attacker_stole_a_metr_api_key_used_600k_worth_of_credits_and_no_one_noticed_for_weeks/5293730 13. Hugging Face Transformers writes remote code to disk before asking permission — CVE-2026-80047 — CERT/CC — https://kb.cert.org/vuls/id/456290 14. SageMaker SDK leaves its signing key in cleartext where any account role can read it — CVE-2026-83551 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-093-aws/ 15. Thirteen poisoned Composer packages on Packagist attack visitors of the sites that install them — CVE-2025-31277, CVE-2025-43398, CVE-2025-43510, CVE-2025-43520, CVE-2025-43529 — The Hacker News — https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html 16. Attackers are installing Apache modules that quietly proxy visitors to phishing pages — Check Point Research — https://research.checkpoint.com/2026/gaming-the-system-how-a-chinese-speaking-actor-turned-brazilian-government-sites-into-an-seo-weapon/

Ratings & Reviews

5
out of 5
2 Ratings

About

A daily podcast covering the important cyber security news that IT and security teams need to know.