Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 08:19 05/09/2026 UTC
  • Exploitation Wave H score 41 PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave Arctic Wolf reports active exploitation of PaperCut CVE-2026-81578 and CVE-2026-82078, advancing the threat from proof-of-concept to likely real credential theft and privileged account creation in education networks.
  • Security Patch Release H score 40 Google Chrome security update for CVE-2026-85046 Google’s Chrome update fixes actively exploited V8 zero-day CVE-2026-85046, making urgent patching necessary to stop remote code execution attempts via crafted HTML.
  • Vulnerability H score 28 CrowdStrike Falcon Sensor privilege escalation zero-day FalconFlank privilege-escalation flaw FalconFlank discloses a publicly released CrowdStrike Falcon Sensor privilege-escalation zero-day targeting fully updated Windows 11/Server 2025, accelerating escalation risk for endpoint defenders using Falcon.
  • Data Leak H score 82 IDScan identity-document data leak Lawsuits and an FBI New Orleans investigation into the alleged IDScan breach signal accelerating legal and law-enforcement scrutiny for a reported 153M+ driver’s license scan exposure.
  • Incident H score 38 Coder hit by network compromise Coder’s disclosure of a registry.coder.com compromise enabling trojanized Terraform modules advances the case by indicating credential-stealing payload delivery through Cloudflare-backed infrastructure, prompting immediate secret rotation and cleanup.
Last updated: 19:49 04/09/2026 UTC
  • Vulnerability H score 81 Langflow code validator RCE flaw (CVE-2026-0768) Threat actors are actively exploiting the critical Langflow code validator RCE flaw (CVE-2026-0768) to run code as root without authentication, raising immediate risk for exposed Langflow deployments.
  • Data Leak H score 82 IDScan identity-document data leak Multiple lawsuits and an FBI investigation were launched over an alleged IDScan breach, advancing potential accountability after reports of 153M+ leaked driver’s license scans.
  • Data Leak H score 81 McKesson customer data exfiltration via third-party applications McKesson confirmed unauthorized access to third-party applications with data exfiltration affecting a subset of customers, increasing pressure on vendors and accelerating downstream breach response.
  • Case Case score 79 Rhysida extortion over Berlin administrative network compromise Berlin faces Rhysida-linked extortion after the group claimed 5.79 TB stolen from the city’s administrative network, materially increasing disclosure risk for government and identity-related records.
  • Law Enforcement H score 75 U.S. DOJ-led Sality botnet takedown The DOJ-led operation to disrupt the Sality P2P botnet used sinkholing and domain seizures to stop new payloads, reducing credential theft and exploitation leverage across infected nodes.
  • Security Patch Release H score 40 Google Chrome security update for CVE-2026-85046 Google released Chrome security updates fixing CVE-2026-85046, an actively exploited V8 type confusion bug, prompting urgent patching to close an in-the-wild browser RCE pathway.

Latest updates

Browse →

PaperCut CVE-2026-81578 and CVE-2026-82078 active exploitation wave

Exploitation Wave

Updated: 05.09.2026 10:31 · First: 05.09.2026 10:31 · 📰 1 src / 1 articles · H score: 41

Threat actors are actively exploiting PaperCut CVE-2026-81578 and CVE-2026-82078, putting schools and universities in the U.S. and Europe at risk of credential theft and follow-on compromise. Arctic Wolf observed the chain being used for command execution, reconnaissance, and privileged account creation on vulnerable servers. Post-exploitation activity also included registry hive collection tools, Meterpreter Java payloads, and searches for passwords, secrets, ldap, bind, and token values in PaperCut configuration files.

IDScan identity-document data leak

Data Leak

Updated: 04.09.2026 19:56 · First: 04.09.2026 19:56 · 📰 1 src / 1 articles · H score: 82

A reported IDScan data leak exposed or offered for sale more than 153 million driver’s license scans, putting large volumes of identity documents at risk. The cache was advertised by the dark-web service Nexus, and sample checks tied the material back to IDScan. The exposure increases the risk of identity theft, impersonation, and fraud for people whose IDs were scanned through businesses using the service.

Louisiana lawsuits over IDScan identity-data breach

Regulatory/Legal Action

Updated: 04.09.2026 19:56 · First: 04.09.2026 19:56 · 📰 1 src / 1 articles · H score: 74

Multiple lawsuits were filed in Louisiana against IDScan over an alleged breach tied to more than 153 million driver’s licenses, expanding civil exposure around scanned identity data. Several law firms have also begun investigating possible class-action litigation for people whose IDs may have been scanned through IDScan-linked businesses. The cases could consolidate if additional claimants come forward.

High-volume Unicode-smuggling phishing campaign

Campaign

Updated: 04.09.2026 18:57 · First: 04.09.2026 18:57 · 📰 1 src / 1 articles · H score: 29

A high-volume phishing campaign is using invisible Unicode tag characters to split lure words and bypass email filters, pushing finance-themed emails at scale. The activity first surfaced in early February 2026 and later reached 1 to 2.37 million messages on weekdays. A broader linked operation used ActiveCampaign to distribute AI-generated phishing emails targeting Small Business Administration loan applicants. The evasion technique increases the odds that malicious emails reach recipients and can complicate reputation-based filtering.

Citrix NetScaler authentication bypass (CVE-2026-19490)

Vulnerability

Updated: 04.09.2026 18:25 · First: 04.09.2026 18:25 · 📰 1 src / 1 articles · H score: 29

CVE-2026-19490 is now being actively probed in the wild, putting exposed Citrix NetScaler appliances at risk of remote authentication bypass. Previdian observed matching PoC requests on 3 September from Australia, the United States and Germany. Citrix had already told admins to upgrade impacted builds as soon as possible, and NCC-BE later urged patching vulnerable appliances. No successful compromise has been confirmed, but the flaw has moved from disclosure into live targeting.

Citrix NetScaler urgent patch guidance for CVE-2026-19490

Advisory/Mitigation

Updated: 04.09.2026 18:25 · First: 04.09.2026 18:25 · 📰 1 src / 1 articles · H score: 33

Citrix NetScaler administrators were told to urgently review exposure and upgrade impacted appliances for CVE-2026-19490, with NCC-BE later urging organizations to prioritize patching vulnerable deployments. The guidance centers on affected NetScaler ADC and NetScaler Gateway systems and ties remediation to the authentication-bypass flaw now being targeted in the wild.

PostgreSQL security update for logical-decoding code execution (CVE-2026-6471)

Security Patch Release

Updated: 04.09.2026 18:20 · First: 04.09.2026 18:20 · 📰 1 src / 1 articles · H score: 28

PostgreSQL shipped a security update for CVE-2026-6471, closing a logical-decoding code-execution flaw that can let a REPLICATION-privileged account run code as the database server’s OS user. The fix covers PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 and introduces output_plugin_libraries to restrict which logical-decoding plugins can load. Administrators using non-default plugins such as wal2json or decoderbufs must add them to the allowlist and reload configuration after updating.

PostgreSQL logical decoding replication RCE (CVE-2026-6471)

Vulnerability

Updated: 04.09.2026 18:20 · First: 04.09.2026 18:20 · 📰 1 src / 1 articles · H score: 26

CVE-2026-6471 in PostgreSQL logical decoding lets a user with the REPLICATION attribute run code as the database server OS user, and fixed builds are now available. The flaw affects versions before 18.6, 17.11, 16.15, 15.19, and 14.24 and requires wal_level = logical. PostgreSQL added output_plugin_libraries to whitelist allowed logical-decoding plugins and block arbitrary library loading. Administrators running replication features should update and review which plugins their slots depend on.

Ted Linux implant in trojanized HAProxy load balancers

Malware Activity

Updated: 04.09.2026 17:51 · First: 04.09.2026 17:51 · 📰 1 src / 1 articles · H score: 22

The newly identified ted Linux implant was compiled into trojanized HAProxy load balancers, giving operators a way to intercept web traffic and serve altered pages on affected hosts. The backdoor also concealed its C2 activity from ordinary counters while supporting file transfer, shell execution, and configuration changes. The implant was found on two South Korean organizations in the automotive and media sectors, with only medium-confidence attribution to a North Korean cluster.

Microsoft Teams desktop client on Windows launch delay disruption

Service Disruption

Updated: 04.09.2026 17:30 · First: 04.09.2026 17:30 · 📰 1 src / 1 articles · H score: 0

Microsoft Teams on Windows is experiencing a known launch disruption that can prevent some users from loading the desktop client or delay startup by up to two minutes. The issue is tracked as TM1466820 and is under active investigation. Microsoft is reviewing service logs and telemetry while working on remediation. Affected users are being advised to use Teams on the web or the mobile app as a workaround.

CrowdStrike Falcon Sensor privilege escalation zero-day FalconFlank privilege-escalation flaw

Vulnerability

Updated: 04.09.2026 16:22 · First: 04.09.2026 16:22 · 📰 1 src / 1 articles · H score: 28

FalconFlank is a publicly released zero-day privilege escalation in CrowdStrike Falcon Sensor that can give attackers SYSTEM access on fully updated Windows 11 and Windows Server 2025 systems. The flaw abuses Falcon's Office malicious macros remediation feature and is described as working on current builds, including Windows 11 25H2. CrowdStrike says it is investigating and advises customers to disable the File Suspicious Macro Removal policy setting while it reviews the claim.

Microsoft Exchange Online outage delaying external email with Server busy errors

Service Disruption

Updated: 04.09.2026 15:22 · First: 04.09.2026 15:22 · 📰 1 src / 1 articles · H score: 0

Microsoft is dealing with an ongoing Exchange Online outage that is delaying email to and from external domains, creating visible disruption for mail flow across multiple mailboxes. Users may see intermittent "Server busy" errors while sending or receiving messages. Microsoft says anti-spam protections may be worsening the impact, and it is still investigating the root cause and mitigation path. No recovery timeline has been provided yet.

Google Chrome V8 type confusion security flaw (CVE-2026-85046)

Vulnerability

Updated: 04.09.2026 10:18 · First: 04.09.2026 10:18 · 📰 2 src / 2 articles · H score: 34

Google patched CVE-2026-85046, a V8 type confusion flaw in Google Chrome that was actively exploited in the wild and could let a remote attacker execute code inside the browser sandbox. The bug affected Chrome prior to 152.0.7977.82, and Google shipped fixes in 152.0.7977.82/.83 for Windows and Apple macOS and 152.0.7977.82 for Linux. The flaw was reachable through a crafted HTML page, making browser users exposed until they updated.

Google Chrome security update for CVE-2026-85046

Security Patch Release

Updated: 04.09.2026 10:18 · First: 04.09.2026 10:18 · 📰 2 src / 2 articles · H score: 40

Google released Chrome security updates that patch 12 vulnerabilities, including CVE-2026-85046, an actively exploited zero-day in V8. The flaw is a type confusion bug that could let a remote attacker execute arbitrary code inside the sandbox through a crafted HTML page. Users on Windows, macOS, and Linux should move to the fixed 152.0.7977.82/.83 builds as soon as available.

OpenAI subsidizes Daybreak cyber models for frontline defenders and essential services

Security Tool/Service

Updated: 04.09.2026 13:15 · First: 04.09.2026 13:15 · 📰 1 src / 1 articles · H score: 14

OpenAI is subsidizing access to Daybreak cyber models with a $1bn commitment, expanding AI security support for essential services and defenders. The rollout targets water, electricity, local governments, non-profits, and banking, starting in the US. The initiative can help teams review legacy code, analyze suspicious activity, validate vulnerabilities, and test fixes more quickly.

G7 quantum-safe encryption transition guidance

Advisory/Mitigation

Updated: 04.09.2026 12:25 · First: 04.09.2026 12:25 · 📰 1 src / 1 articles · H score: 27

G7 member-state cybersecurity agencies issued quantum-safe encryption mitigation guidance urging governments and organizations to start their PQC transition now. The guidance tells them to first identify critical systems and assets and prioritize those for migration. It recommends a phased, risk-based plan that inventories cryptographic assets, maps dependencies, and adopts PQC-enabled products during normal renewal cycles.

G7 Cybersecurity Working Group PQC transition call

Public Sector Action

Updated: 04.09.2026 12:25 · First: 04.09.2026 12:25 · 📰 1 src / 1 articles · H score: 21

ANSSI and the G7 Cybersecurity Working Group issued a call to action on September 3, 2026 urging governments and organizations to start transitioning to quantum-safe encryption. The move elevates post-quantum cryptography (PQC) as a public-sector cybersecurity priority because quantum computing threatens public-key cryptography. It also pushes a phased, risk-based migration approach across all sectors, not just critical infrastructure.

Hôpital privé de la Loire data breach

Data Leak

Updated: 04.09.2026 01:01 · First: 04.09.2026 01:01 · 📰 1 src / 1 articles · H score: 60

A summer 2025 data breach exposed sensitive data from Hôpital privé de la Loire, affecting 524,867 patients and 202,246 trusted third parties. The leak involved the hospital’s electronic patient record system and put a large healthcare population at risk of privacy abuse and follow-on fraud. The exposure also triggered a €500,000 penalty from CNIL after investigators found major security failures.

CNIL fine against Hôpital privé de la Loire over GDPR breach

Regulatory/Legal Action

Updated: 04.09.2026 01:01 · First: 04.09.2026 01:01 · 📰 1 src / 1 articles · H score: 50

France’s CNIL fined Hôpital privé de la Loire €500,000 after finding GDPR security failures that contributed to a breach affecting patients and trusted third parties. The enforcement action covers a summer 2025 exposure that reached 524,867 patients and 202,246 trusted third parties. The penalty raises the compliance stakes for hospital systems handling sensitive health data.

Hôpital privé de la Loire hit by network compromise

Incident

Updated: 04.09.2026 01:01 · First: 04.09.2026 01:01 · 📰 1 src / 1 articles · H score: 54

Hôpital privé de la Loire suffered a data breach after an attacker accessed its electronic patient record system and extracted sensitive data tied to more than 727,000 people. The compromise exposed patient-related information and records connected to people who received care at the hospital or assisted patients there. It became a large-scale privacy incident because the intrusion reached core medical records and remained undetected long enough for data to be removed.

Malicious Terraform modules with credential-stealing code

Malware Activity

Updated: 03.09.2026 23:04 · First: 03.09.2026 23:04 · 📰 1 src / 1 articles · H score: 30

Malicious Terraform modules were delivered through a compromised registry and ran credential-stealing code, putting developer secrets and cloud credentials at risk. The modules were served during an August 31 delivery window and exfiltrated collected data to coder-infra[.]com. The activity targeted secrets in developer environments and provisioners, including API keys, CI/CD credentials, SSH keys, and OIDC tokens.

Coder hit by network compromise

Incident

Updated: 03.09.2026 23:04 · First: 03.09.2026 23:04 · 📰 1 src / 1 articles · H score: 38

Coder disclosed an infrastructure compromise of registry.coder.com that let attackers serve malicious Terraform modules to some users and potentially expose secrets on affected hosts. The altered delivery path ran through Cloudflare-backed infrastructure and affected requests made between 07:35 UTC and 21:45 UTC on Monday, August 31. Coder said the malicious files contained credential-stealing code and advised impacted users to rotate secrets, review logs, and purge cached packages.

ArubaOS-CX buffer overflow RCE (CVE-2026-73749)

Vulnerability

Updated: 03.09.2026 21:28 · First: 03.09.2026 21:28 · 📰 1 src / 1 articles · H score: 30

HPE patched CVE-2026-73749, a critical ArubaOS-CX buffer overflow that can let unauthenticated remote attackers reach code execution with elevated privileges on affected switches.

HPE ArubaOS-CX security bulletin (CVE-2026-73749)

Security Patch Release

Updated: 03.09.2026 21:28 · First: 03.09.2026 21:28 · 📰 1 src / 1 articles · H score: 31

HPE released a security bulletin for ArubaOS-CX that patches CVE-2026-73749, a buffer overflow that could let unauthenticated remote attackers reach remote code execution on affected switches. The bulletin lists fixed releases for 10.18.0001, 10.17.1021 and earlier, 10.16.1051 and earlier, 10.13.1180 and earlier, and 10.10.1180 and earlier. HPE also flagged 10.10.1181 as End of Maintenance, limiting its fix support for this critical issue.

Cisco IOS XR hardening release (umbrella CVEs)

Security Patch Release

Updated: 03.09.2026 18:52 · First: 03.09.2026 18:52 · 📰 1 src / 1 articles · H score: 14

Cisco released an IOS XR hardening update that covers all IOS XR releases, including XR7 (LNT), and bundles 7 umbrella CVEs. Two of the grouped flaws are rated 9.8, and Cisco says there is no workaround for any IOS XR version. Customers must upgrade to a release with SMUs and then apply those updates. Releases outside Cisco's support table require a TAC case before the fix path can be completed.

Cisco Nexus 9000 NX-OS patch release for CVE-2026-20212

Security Patch Release

Updated: 03.09.2026 18:52 · First: 03.09.2026 18:52 · 📰 1 src / 1 articles · H score: 14

Cisco released NX-OS patches for CVE-2026-20212, a critical flaw affecting 10 Silicon One-based Nexus 9000 switch PIDs. The bug lets an unauthenticated remote attacker reach TCP 43210/43211 and run code as root on exposed devices. Cisco also provided temporary mitigations — an iACL and a Live Protect shield — while customers use the Software Checker to find fixed releases.

Cisco Nexus 9000 unrestricted IP binding RCE (CVE-2026-20212)

Vulnerability

Updated: 03.09.2026 18:52 · First: 03.09.2026 18:52 · 📰 1 src / 1 articles · H score: 13

CVE-2026-20212 exposes Cisco Nexus 9000 switches to unauthenticated remote code execution through unrestricted IP binding on TCP 43210 and 43211. The flaw leaves those ports reachable in the default Layer 3 VRF instance, and crafted input can run as root or crash the S1HAL process and reload the device. Cisco said it was not aware of malicious use as of the September 2 disclosure. The affected scope includes 10 Silicon One-based Nexus 9000 PIDs and 45 NX-OS releases listed through Cisco's Software Checker.

BraZetsu Windows malware framework powering Infected Marketplace access sales

Malware Activity

Updated: 03.09.2026 18:26 · First: 03.09.2026 18:26 · 📰 1 src / 1 articles · H score: 23

The disclosure of BraZetsu shows a Python-based Windows malware framework being used to turn compromised hosts into tradable access inventory, increasing the value of each foothold for criminal buyers. The framework is tied to Exilware and the Infected Marketplace access-sale operation, where stolen access is monetized for a small deposit. It matters because the toolkit combines reconnaissance, host triage, and AI-assisted target prioritization to help attackers package compromised systems for resale.

Exilware runs an access-as-a-service marketplace for compromised hosts

Threat Actor Meta

Updated: 03.09.2026 18:26 · First: 03.09.2026 18:26 · 📰 1 src / 1 articles · H score: 29

Exilware is operating an access-as-a-service marketplace that monetizes compromised hosts and lets buyers purchase footholds, expanding downstream payload execution across victim systems.

Thomson Reuters hit by cyberattack

Incident

Updated: 03.09.2026 15:00 · First: 03.09.2026 15:00 · 📰 2 src / 2 articles · H score: 26

Thomson Reuters disclosed a cybersecurity incident in C-Track that exposed sensitive court records across Canada and the US. The activity was detected on June 30, and an investigation found that an unauthorized party obtained certain Canada court files tied to three Ontario courts. Affected records may include names, Social Security numbers, driver’s license numbers, medical information, dates of birth, and health insurance information.