# Archive
Browse past daily curated stories
Friday, September 04, 2026
-
1The Hacker News generalCISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
CISA added seven flaws to its KEV catalog, including CVE-2026-83548 (CVSS 10.0), a server-side request forgery vulnerability in SonicWall SMA 1000 appliances enabling unauthenticated remote access. Attackers are actively deploying reverse shells and crypto miners via these vulnerabilities. Security teams should treat SonicWall SMA 1000 appliances as an immediate priority given CISA's mandatory federal remediation deadlines.
-
2The Hacker News generalCritical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
Cisco patched CVE-2026-20212 (CVSS 9.8), a critical unauthenticated RCE flaw in 10 Silicon One-based Nexus 9000 switches, alongside an IOS XR hardening release covering 7 CVEs — two rated 9.8 — with no available workaround for any IOS XR version. The Nexus vulnerability allows a remote attacker to execute arbitrary code as root without authentication. Network defenders running affected Nexus 9000 or IOS XR gear should apply patches immediately given the CVSS scores and lack of mitigations.
-
3The Hacker News generalPegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
Citizen Lab, in collaboration with the SHARE Foundation, confirmed that a member of Serbia's student protest movement had their iPhone infected with NSO Group's Pegasus spyware via an iMessage zero-click exploit. This is part of a broader pattern: at least 14 Serbian opposition figures, politicians, and activists have been targeted with advanced spyware since December 2025. The findings reinforce that Pegasus zero-click delivery remains active and is being deployed against civil society targets in Europe.
-
4BleepingComputer generalSality botnet infrastructure dismantled in joint global takedown
International law enforcement and private partners disrupted the Sality botnet, a peer-to-peer malware network that operated for 23 years — one of the longest-running botnets in history. The takedown leveraged peer list manipulation and URL seizures against Sality's decentralized C2 infrastructure, which had historically resisted disruption. The operation is significant for demonstrating that even highly resilient P2P botnets can be dismantled through coordinated infrastructure manipulation.
-
5The Hacker News generalThomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
Thomson Reuters disclosed that its C-Track court case management platform (sold by West Publishing Corporation) was breached in March 2026, with unauthorized access to files from courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada — discovered on June 30, 2026. Exposed records may include SSNs and sealed court data, posing serious risks to individuals involved in sensitive legal proceedings. The 3-month discovery gap underscores persistent blind spots in breach detection for legal infrastructure providers.
-
6BleepingComputer generalCritical Elementor Pro flaw exploited to take over WordPress sites
CVE-2026-32475, a recently patched critical vulnerability in the Elementor Pro WordPress plugin, is being actively exploited to deploy webshells and execute arbitrary server-side commands. Given that Elementor Pro is installed on millions of WordPress sites, the attack surface is substantial. Security teams managing WordPress environments should verify plugin update status and audit for webshell indicators of compromise immediately.
-
7SecurityWeek generalOpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity Threshold
OpenAI's Astra model has become the first AI to cross what SecurityWeek describes as a 'critical cybersecurity threshold,' defined as the ability to independently discover and exploit zero-day vulnerabilities across well-defended systems. This milestone has significant implications for defenders, as it means frontier AI can now function as an autonomous offensive tool without human guidance. Security practitioners should factor AI-accelerated zero-day discovery into threat modeling and patching prioritization timelines.
-
8BleepingComputer generalHackers exploit critical JFrog Artifactory flaw to forge admin tokens
A critical authentication bypass flaw (CVE-2026-82329) in JFrog Artifactory is being actively exploited to forge admin tokens, granting full administrative access to artifact repositories. JFrog Artifactory is widely used in enterprise CI/CD pipelines, making compromised instances a high-value pivot point for supply chain attacks. Organizations running Artifactory should apply patches immediately and audit for unauthorized token creation in access logs.
-
9SecurityWeek general153 Million Driver License Images Offered on Dark Web
153 million U.S. and Canadian driver's license images are being offered for sale on dark web forums, allegedly stolen from IDScan.net, a digital ID verification service. The scale of this exposure — affecting a majority of North American licensed drivers — creates significant identity fraud and social engineering risk. Security teams at organizations using IDScan.net for identity verification should assess their exposure and notify affected users.
-
10Ars Technica Security generalBGP hijack infecting networks caused by a comedy of errors that’s not funny at all
A BGP hijacking incident resulted in a threat actor using a technically valid TLS certificate for Softaculous domains to redirect traffic and serve malicious Virtualizor software updates to production servers. The attack demonstrates how BGP route manipulation combined with legitimate-looking certificates can completely undermine software update trust chains. The incident is a practical case study in supply chain risk for infrastructure operators relying on third-party software delivery without additional integrity verification.