Press "Enter" to skip to content

OSINT / CyberSec report 05.09.2026 00:09

1. Google released a security update to patch CVE-2026-85046, a high-severity type confusion vulnerability in the V8 engine that is currently being exploited in the wild (The Hacker News).

2. Over 440,000 exploit attempts have been recorded targeting critical remote code execution flaws in WordPress plugins Super Forms and Elementor Pro (The Hacker News).

3. Cisco issued patches for a critical vulnerability in Nexus 9000 switches, tracked as CVE-2026-20212, which allows unauthenticated remote attackers to execute code as root (The Hacker News).

4. SonicWall advised customers to apply patches for two new zero-day vulnerabilities affecting its SMA1000 series appliances (Reddit).

5. A sophisticated Python-based malware framework named BraZetsu is being used to turn compromised Windows hosts into inventory for an underground criminal marketplace (The Hacker News).

6. Thomson Reuters disclosed a breach of its C-Track court case management platform that exposed sensitive personal data and sealed court records across multiple U.S. states and Canada (The Hacker News).

7. A widespread RMM phishing campaign targeting 46 countries has been identified, with the United States being the primary target (The Hacker News).

8. Attackers compromised the infrastructure of Coder to push malicious Terraform modules containing credential-stealing code to users (Bleeping Computer).

9. GitGuardian researchers reported that the Shai-Hulud infostealer worm has evolved to scan for credentials across 469 distinct locations in developer environments (The Hacker News).

10. HPE released patches for a critical remote code execution vulnerability found in the ArubaOS-CX network operating system (Bleeping Computer).

11. Threat actors are leveraging the legitimate Node.js runtime to deploy malicious payloads in attacks targeting government and technology sectors (The Hacker News).

12. Digital forensic researchers identified that at least 14 Serbian opposition figures and activists have been targeted with advanced spyware (The Record).

13. The French data protection authority fined Hôpital privé de la Loire 500,000 euros following a data breach that exposed the information of 727,000 individuals (Bleeping Computer).

14. Plex urged users to immediately update their media servers and desktop clients to address multiple undisclosed security vulnerabilities (The Hacker News).

15. Anthropic acknowledged security failures in its AI models after reports indicated they had successfully hacked three organizations during testing (Reddit).

Be First to Comment

    Leave a Reply

    Your email address will not be published. Required fields are marked *