Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 02:20 03/09/2026 UTC
  • Vulnerability H score 81 Langflow code validator RCE flaw (CVE-2026-0768) Threat actors exploited Langflow’s CVE-2026-0768 for reconnaissance and credential harvesting, signaling fast-moving risk for any unpatched internet-exposed Langflow instance.
  • Data Leak H score 81 McKesson customer data exfiltration via third-party applications McKesson confirmed unauthorized access and data exfiltration via third-party applications, advancing the case from claim to confirmed impact for a subset of oncology and medical-surgical customers.
  • Advisory/Mitigation H score 58 SonicWall SMA1000 hotfix advisory Authorities carried out a Sality botnet sinkhole and domain seizures that disrupted the malware’s P2P control path, materially advancing disruption efforts against long-running infections.
  • Security Patch Release H score 32 Microsoft security patch release for CVE-2026-62911 Microsoft released a patch for CVE-2026-62911 in Exchange Server to close a mailbox-takeover authentication bypass where exploit code is already reported online.
  • Data Leak H score 71 Novocure employee and patient data exposure Novocure disclosed exposure of employee and patient data from a mid-August cyberattack, advancing incident scope and notification obligations despite no reported access to treatment devices.
Last updated: 21:25 02/09/2026 UTC
  • Incident H score 82 Manchester Airports Group (MAG) hit by network compromise FulcrumSec posted almost all of the stolen Manchester Airports Group (MAG) customer archive (~549GB), escalating the breach risk by moving from confirmation to public availability of sensitive traveler data.
  • Case Case score 89 Carhartt public leak after ShinyHunters extortion and Databricks linkage ShinyHunters’ dark web publication of stolen Carhartt records now exposes 12.9M+ accounts and links the intrusion to Carhartt’s Databricks analytics platform, raising fraud and identity-theft impact.
  • Data Leak H score 81 McKesson customer data exfiltration via third-party applications McKesson confirmed unauthorized access to third-party applications and data exfiltration affecting oncology and medical-surgical customers, advancing the case from threat claims to an official incident acknowledgment.
  • Vulnerability H score 81 Langflow code validator RCE flaw (CVE-2026-0768) Active exploitation of Langflow’s CVE-2026-0768 critical root RCE flaw for recon and credential harvesting increases immediate compromise risk for internet-exposed deployments.
  • Law Enforcement H score 75 U.S. DOJ-led Sality botnet takedown Authorities coordinated a peer-to-peer sinkhole and domain seizures to disrupt the long-running Sality botnet, breaking its P2P control path and limiting further payload delivery.
  • Exploitation Wave H score 56 JFrog Artifactory CVE-2026-82329 exploitation wave Threat actors are weaponizing JFrog Artifactory CVE-2026-82329 to mint admin tokens and enumerate users/groups, accelerating the shift from vulnerability disclosure to administrative takeover risk.

Latest updates

Browse →

Sangoma Switchvox active exploitation wave (CVE-2026-9586)

Exploitation Wave

Updated: 03.09.2026 00:00 · First: 03.09.2026 00:00 · 📰 1 src / 1 articles · H score: 41

CVE-2026-9586 is being exploited in a broad wave against internet-exposed Sangoma Switchvox systems, with repeated attempts and reverse-shell activity signaling immediate compromise risk for exposed deployments.

Sangoma Switchvox unauthenticated SQL injection SQL injection flaw (CVE-2026-9586)

Vulnerability

Updated: 03.09.2026 00:00 · First: 03.09.2026 00:00 · 📰 1 src / 1 articles · H score: 41

CVE-2026-9586 is being actively exploited in Sangoma Switchvox, exposing internet-facing VoIP systems to remote code execution through an unauthenticated SQL injection flaw. Researchers say most exposed systems have already been targeted or will be soon, and honeypots saw repeated attempts from 176.65.148.184 on August 30. Sangoma fixed the issue in Switchvox 8.4.0.2, and administrators are urged to upgrade and review logs for compromise indicators.

OpenAI Astra reaches Critical cybersecurity threshold with Daybreak Blue tester access

Security Tool/Service

Updated: 02.09.2026 21:27 · First: 02.09.2026 21:27 · 📰 1 src / 1 articles · H score: 18

OpenAI has moved Astra into a controlled tester-access phase after classifying it at the Critical cybersecurity capability threshold, raising the stakes for advanced AI-assisted offense and defense. The company plans to expose its most advanced cybersecurity features through Daybreak Blue while pairing the rollout with added safeguards against misuse. The event signals a tightly managed release of a named cyber-capable model rather than a general model announcement.

Google launches Gemini 3.8 Flash Cyber with Fairwind Program early access for defenders

Security Tool/Service

Updated: 02.09.2026 21:27 · First: 02.09.2026 21:27 · 📰 1 src / 1 articles · H score: 15

Google released Gemini 3.8 Flash Cyber and opened Fairwind Program access for trusted defenders, giving governments, healthcare providers, and telecommunications services earlier access to advanced cyber-model capabilities. The rollout is aimed at improving autonomous vulnerability discovery and helping defenders strengthen protections before new threats arrive. The event expands Google’s defensive AI offering and extends early access to selected security customers and partners.

Silver Fox bogus software-download websites campaign

Campaign

Updated: 02.09.2026 19:41 · First: 02.09.2026 19:41 · 📰 1 src / 1 articles · H score: 38

An active Silver Fox (aka Yinhu) campaign is using bogus software-download websites to impersonate trusted vendors and deliver malicious installers, exposing China-based multinational operations and Chinese-speaking users to compromise. The lure pages mimic legitimate software sites and drive downloads from infrastructure such as gehie246[.]com, while the payload chain uses wrapper installers or msiexec.exe to start execution. The activity has affected organizations in healthcare, manufacturing, gaming, technology, logistics, government, and education and includes defenses evasion such as disabling Microsoft Defender and tampering with Windows Update.

ValleyRAT malicious installer activity

Malware Activity

Updated: 02.09.2026 19:41 · First: 02.09.2026 19:41 · 📰 1 src / 1 articles · H score: 22

ValleyRAT installers delivered through bogus software-download websites are compromising Windows endpoints and reaching users seeking popular software. The operation has affected China-based multinational operations and Chinese-speaking users across multiple industries. Once launched, the payload sets persistence, weakens security protections, and establishes C2, raising the risk of follow-on intrusion and device compromise.

JFrog Artifactory actively exploited authentication bypass (CVE-2026-82329)

Vulnerability

Updated: 01.09.2026 20:53 · First: 01.09.2026 20:53 · 📰 2 src / 2 articles · H score: 56

CVE-2026-82329 is a critical authentication bypass in JFrog Artifactory that can let unauthenticated network attackers gain administrative privileges under default configuration. JFrog patched the flaw in Artifactory 7.161.20 on August 28, 2026, and the issue affects multiple self-managed release lines. The weakness sits in JFrog Access, where attackers can abuse credential-handling logic to mint admin-level access.

JFrog Artifactory CVE-2026-82329 exploitation wave

Exploitation Wave

Updated: 01.09.2026 20:53 · First: 01.09.2026 20:53 · 📰 2 src / 2 articles · H score: 56

Threat actors are conducting an active exploitation wave against JFrog Artifactory systems through CVE-2026-82329, turning an authentication bypass into administrative access. The abuse began days after public disclosure and is focused on internet-exposed instances. Attackers are already using the flaw to mint admin tokens and enumerate users, groups, credential sets and federated access topologies. The rapid post-patch weaponization raises the risk of downstream tampering in software supply chain environments.

Goose core.fsmonitor command execution flaw (CVE-2026-72718)

Vulnerability

Updated: 02.09.2026 17:06 · First: 02.09.2026 17:06 · 📰 1 src / 1 articles · H score: 17

goose fixed a repository-supplied command execution flaw in `core.fsmonitor`, leaving versions prior to 1.44.0 exposed until 1.44.0 shipped. GitHub assigned CVE-2026-72718 with a CVSS 4.0 7.0 score. A malicious repository could make goose run attacker code on the developer's machine before any model call or approval prompt.

OpenAI Codex core.fsmonitor command execution flaw (CVE-2026-19592)

Vulnerability

Updated: 02.09.2026 17:06 · First: 02.09.2026 17:06 · 📰 1 src / 1 articles · H score: 17

OpenAI Codex had a repository-supplied core.fsmonitor flaw that could run attacker-controlled commands outside the command sandbox and without user approval. A malicious repository with an intact .git/config could trigger code execution as the user, exposing local files and other account resources. OpenAI shipped fixes for affected Codex CLI and Desktop releases, and no exploitation has been reported.

CPR Apache and SSH compromise hunt guidance

Advisory/Mitigation

Updated: 02.09.2026 17:00 · First: 02.09.2026 17:00 · 📰 1 src / 1 articles · H score: 14

CPR issued hunting guidance for Apache and SSH environments after operators used rogue modules and masqueraded processes to hide phishing proxies on compromised sites. The recommended checks target hidden persistence that can redirect visitors and obscure tampering. The affected scope includes sites abused in the Brazilian SEO fraud campaign.

Gambling Goblin Brazilian SEO fraud campaign

Campaign

Updated: 02.09.2026 17:00 · First: 02.09.2026 17:00 · 📰 2 src / 2 articles · H score: 35

Check Point Research says Gambling Goblin is a Chinese-speaking cybercrime cluster running a sustained SEO fraud operation against Brazilian government and educational websites since mid-2025. The group installs malicious Apache modules on compromised web servers, uses them as a reverse proxy, strips Content-Security-Policy headers, and redirects visitors to phishing pages posing as Google Play, Microsoft Store, and Amazon. Those pages promote online gambling and sports betting, with the activity tied by Check Point to Earth Berberoka. The campaign also uses localized phishing pages and churned domains to keep the redirection infrastructure in play.

Lenovo ID email verification account-takeover security flaw

Vulnerability

Updated: 02.09.2026 15:30 · First: 02.09.2026 15:30 · 📰 1 src / 1 articles · H score: 51

A Lenovo ID email verification flaw let attackers register a Lenovo ID using a victim's email address and log into linked Dropbox accounts without the password. The weakness affected Dropbox users who relied on Lenovo Identity Provider Services for authentication, with accesses occurring between August 4 and 21. Dropbox and Lenovo mitigated the risk, and Dropbox now expires Lenovo-authenticated sessions and requires the Dropbox password for Lenovo ID authentication.

Dropbox hit by cyberattack

Incident

Updated: 02.09.2026 15:30 · First: 02.09.2026 15:30 · 📰 1 src / 1 articles · H score: 17

Dropbox confirmed an unauthorized account access incident that let an attacker log into affected users’ accounts without the password, creating takeover risk. The access path relied on fraudulent Lenovo IDs created through Lenovo’s email verification process and linked to Dropbox through Lenovo Identity Provider Services. Dropbox said the accesses occurred between August 4 and 21. The company expired Lenovo-authenticated sessions and now requires the Dropbox password for Lenovo ID authentication.

StreamRat Meta ad campaign targeting Spanish-speaking users

Campaign

Updated: 02.09.2026 15:22 · First: 02.09.2026 15:22 · 📰 1 src / 1 articles · H score: 48

A Meta ad campaign is pushing StreamRat to Spanish-speaking users, expanding exposure to an Android banking trojan that can steal credentials and take over devices. The lure focused on Spain and used a fake television-streaming theme to drive users toward an APK download flow. It reached an estimated 570,950 Meta accounts in the European Union at least once.

StreamRat Android banking trojan with remote-control capabilities

Malware Activity

Updated: 02.09.2026 15:22 · First: 02.09.2026 15:22 · 📰 1 src / 1 articles · H score: 42

The StreamRat Android banking trojan is being pushed through fake streaming ads on Meta and can yield near-complete device control, raising the risk of credential theft and remote abuse on infected Android phones. The operation focused on Spanish-speaking users and reached an estimated 570,950 Meta accounts in the EU. Infection required victims to sideload an APK and approve intrusive permissions. Once Accessibility access was granted, the malware could capture keystrokes, show credential-stealing overlays, take screenshots, and control the device remotely.

SonicWall SMA1000 hotfix advisory

Advisory/Mitigation

Updated: 02.09.2026 09:39 · First: 02.09.2026 09:39 · 📰 3 src / 3 articles · H score: 58

SonicWall has confirmed active exploitation of SMA1000 zero-days and released hotfixes for affected appliances. The attack chain involves CVE-2026-83548 in the Appliance WorkPlace interface and CVE-2026-83549 in the Appliance Management Console, enabling remote code execution on SMA 1000 models 6210, 7210, and 8200v. SonicWall says the fixes are available in 12.4.3-03526 and 12.5.0-02952, and advises customers to upgrade immediately and check for indicators of compromise. If compromise is found, SonicWall recommends re-imaging, changing all user and administrator passwords, and resetting TOTP tokens.

Microsoft Defender for Office 365 Safe Links blocks legitimate Google search links

Service Disruption

Updated: 02.09.2026 13:29 · First: 02.09.2026 13:29 · 📰 1 src / 1 articles · H score: 0

Microsoft Defender for Office 365 Safe Links is blocking legitimate Google search links as malicious, preventing users from opening them normally and triggering warning prompts. The issue is tied to an inaccurate security classification and is generating related alerts in Microsoft Sentinel and the Defender portal.

GeoNetwork unauthenticated RCE chain (multiple vulnerabilities)

Vulnerability

Updated: 02.09.2026 12:18 · First: 02.09.2026 12:18 · 📰 1 src / 1 articles · H score: 23

GeoNetwork's 4.4.x through 4.4.11 and 4.2.x through 4.2.16 releases now have a chained unauthenticated RCE flaw that can affect government geoportal backends. The issue combines CVE-2026-63219 and CVE-2026-58400 to let an anonymous attacker upload a malicious formatter and trigger command execution through Saxon XSLT. The project shipped fixes in 4.4.12 and 4.2.17 and urged users to upgrade quickly. No public exploitation in the wild was reported at disclosure.

GeoNetwork patch release for unauthenticated RCE chain (4.4.12, 4.2.17)

Security Patch Release

Updated: 02.09.2026 12:18 · First: 02.09.2026 12:18 · 📰 1 src / 1 articles · H score: 27

GeoNetwork shipped 4.4.12 and 4.2.17 to close a vulnerability chain that could lead to unauthenticated remote code execution in exposed deployments. The fix applies to 4.4.x through 4.4.11 and 4.2.x through 4.2.16, making the release relevant for government and agency geoportals and other public-facing catalogs. Administrators were told to upgrade to 4.4.12 or 4.2.17 as soon as possible.

TVRAT and DarkVNC phishing infection activity

Malware Activity

Updated: 02.09.2026 12:06 · First: 02.09.2026 12:06 · 📰 3 src / 3 articles · H score: 34

TVRAT and DarkVNC powered a phishing malware operation that used 255 fake accounts on a freelance platform to send malicious Microsoft Excel attachments with macros to about 80,000 users in 2016-2017. The campaign delivered malware that enabled remote control of infected computers through TeamViewer and VNC Viewer, and it also supported data theft. Court records tie the activity to Russian national Searzhudin Tamirlanovich Aktulaev, who was extradited from Cyprus and charged in the Northern District of California.

Aktulaev federal indictment and extradition for phishing-malware scheme

Law Enforcement

Updated: 02.09.2026 12:06 · First: 02.09.2026 12:06 · 📰 3 src / 3 articles · H score: 32

U.S. Department of Justice prosecutors say Searzhudin Tamirlanovich Aktulaev was extradited from Cyprus and faces a federal case over a 2016-2017 phishing-and-malware campaign tied to users of an unnamed freelance employment technology company. The indictment alleges he used about 255 fake accounts to send malicious Microsoft Excel attachments with macros to about 80,000 users. Those attachments allegedly delivered TVRAT and DarkVNC, which gave remote control of infected systems and sent stolen data to command-and-control servers. Prosecutors say the stolen material included e-commerce login credentials and personally identifiable information used for fraud and other criminal activity.

Aktulaev fake-account freelancer phishing campaign

Campaign

Updated: 02.09.2026 12:06 · First: 02.09.2026 12:06 · 📰 3 src / 3 articles · H score: 40

Searzhudin Tamirlanovich Aktulaev is the focus of a DoJ case over a 2016-2017 phishing campaign that used about 255 fake accounts on a freelance platform to send malicious Microsoft Excel attachments to about 80,000 users. The attachments prompted recipients to run a macro that downloaded malware, including TVRAT and DarkVNC, which enabled remote control of infected computers and the theft of e-commerce login credentials and PII. The platform was described as a well-known freelance employment technology company in the Northern District of California, and prosecutors said many infected systems were in the United States. Aktulaev was arrested in Cyprus in May 2025, extradited on August 28, 2026, and made his initial appearance in San Francisco on August 31, where he was remanded to federal custody.

Manchester Airports Group (MAG) hit by network compromise

Incident

Updated: 27.08.2026 19:12 · First: 27.08.2026 19:12 · 📰 2 src / 3 articles · H score: 82

Manchester Airports Group (MAG) confirmed a customer data breach that exposed travelers' records across Manchester, Stansted, and East Midlands airports. The stolen data included Wi‑Fi sign-ups and booking-related details, but payment details were not accessed. MAG said it contained the intrusion and temporarily suspended its Manage My Booking service while it notified law enforcement and warned customers about suspicious messages.

Sality botnet payload distribution and propagation activity

Malware Activity

Updated: 02.09.2026 09:56 · First: 02.09.2026 09:56 · 📰 2 src / 2 articles · H score: 62

The Sality botnet has operated since 2003 as a peer-to-peer (P2P) Windows malware network used to spread payloads and support credential theft, spam, proxy services, network exploitation, and DDoS attacks. CrowdStrike said the botnet could distribute malicious payloads to more than 15,000 infected devices worldwide, and that its version 3 and version 4 P2P networks were still active before disruption. In 2026, the U.S. DOJ, FBI, and DCIS and partners in Bulgaria, Hungary, and Romania seized Sality-linked domains and used peer-to-peer sinkholing to isolate infected machines and cut off control channels. CrowdStrike said the operation ended the operator’s control of the botnet and disrupted its payload delivery infrastructure.

U.S. DOJ-led Sality botnet takedown

Law Enforcement

Updated: 02.09.2026 09:56 · First: 02.09.2026 09:56 · 📰 2 src / 2 articles · H score: 75

The U.S. Department of Justice and international partners carried out a coordinated Sality botnet takedown, using peer-to-peer sinkholing and domain seizures across the U.S. and Europe to disrupt the malware's control path. CrowdStrike said the botnet has been active since 2003 and has infected over 15,000 devices. The operation also isolated infected machines and blocked further payload delivery to the botnet's peers. CrowdStrike said the still-active networks were mainly used to push EggJagger payloads in clipjacking attacks.

SonicWall SMA1000 command injection flaws (multiple vulnerabilities)

Vulnerability

Updated: 02.09.2026 09:39 · First: 02.09.2026 09:39 · 📰 3 src / 3 articles · H score: 57

SonicWall SMA 1000 appliances are facing active exploitation of CVE-2026-83548 and CVE-2026-83549, a vulnerability chain that can lead to remote code execution on affected devices. The flaws hit SMA 1000 models 6210, 7210, and 8200v and combine a pre-auth SSRF in the Appliance Work Place interface with a post-auth command injection in the Appliance Management Console (AMC). SonicWall released fixes in 12.4.3-03526 and 12.5.0-02952 and urged customers to upgrade, review for indicators of compromise, and re-image appliances or reset passwords and TOTP if compromise is found.

U.S. and Canadian drivers-license scans for sale on Nexus

Data Leak

Updated: 02.09.2026 01:40 · First: 02.09.2026 01:40 · 📰 1 src / 1 articles · H score: 76

The Nexus dark web service is selling 153 million+ drivers-license scans from people in the United States and Canada, exposing highly sensitive identity documents to buyers and increasing fraud and impersonation risk. The listings also include other identity documents, suggesting a broader cache of personal and government-issued records. The scale and resale format make the exposure immediately valuable to criminals and dangerous to affected individuals.

FBI New Orleans official investigation into idscan.net breach

Law Enforcement

Updated: 02.09.2026 01:40 · First: 02.09.2026 01:40 · 📰 1 src / 1 articles · H score: 62

The FBI New Orleans field office opened an official investigation into an apparent breach involving idscan.net, putting law-enforcement scrutiny on the source of the stolen license images. The inquiry comes as a dark web service is selling large volumes of identity-document scans tied to people in the United States and Canada.

Faronics Deploy adds anti-abuse measures after confirmed abuse

Security Tool/Service

Updated: 01.09.2026 23:53 · First: 01.09.2026 23:53 · 📰 1 src / 1 articles · H score: 34

Faronics tightened Faronics Deploy with additional anti-abuse measures after confirming malicious use of the platform, reducing abuse activity across the service. The response matters because the platform’s remote-deployment features were being used to obtain unauthorized administrative control and stage further access on endpoints.