Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 02:49 04/09/2026 UTC
  • Law Enforcement H score 75 U.S. DOJ-led Sality botnet takedown DOJ publicly announced a coordinated sinkholing and domain-seizure takedown of the Sality P2P botnet, disrupting long-running control paths and stopping further payload delivery to infected devices.
  • Exploitation Wave H score 59 CISA KEV multi-vulnerability exploitation wave CISA added seven exploited vulnerabilities to its KEV list, indicating ongoing attacker weaponization across multiple widely used products and expanding immediate patch urgency.
  • Data Leak H score 60 Hôpital privé de la Loire data breach A reported summer 2025 breach at Hôpital privé de la Loire disclosed sensitive medical data for hundreds of thousands of patients and triggered enforcement action, increasing privacy and downstream fraud risk.
  • Campaign H score 40 Aktulaev fake-account freelancer phishing campaign A California federal grand jury indicted Aktulaev over a freelancer phishing scheme that used malicious Excel attachments and remote-access malware to steal credentials and PII from about 80,000 victims.
  • Incident H score 26 Thomson Reuters hit by cyberattack Thomson Reuters disclosed that a C-Track incident exposed sensitive court records across Canada and the US, expanding the likely impact to identity and medical data.
  • Exploitation Wave H score 41 Sangoma Switchvox active exploitation wave (CVE-2026-9586) Horizon3 warned that most internet-exposed Sangoma Switchvox systems are already targeted or will be soon for CVE-2026-9586, signaling high near-term compromise risk.
Last updated: 20:35 03/09/2026 UTC

Latest updates

Browse →

Hôpital privé de la Loire data breach

Data Leak

Updated: 04.09.2026 01:01 · First: 04.09.2026 01:01 · 📰 1 src / 1 articles · H score: 60

A summer 2025 data breach exposed sensitive data from Hôpital privé de la Loire, affecting 524,867 patients and 202,246 trusted third parties. The leak involved the hospital’s electronic patient record system and put a large healthcare population at risk of privacy abuse and follow-on fraud. The exposure also triggered a €500,000 penalty from CNIL after investigators found major security failures.

CNIL fine against Hôpital privé de la Loire over GDPR breach

Regulatory/Legal Action

Updated: 04.09.2026 01:01 · First: 04.09.2026 01:01 · 📰 1 src / 1 articles · H score: 50

France’s CNIL fined Hôpital privé de la Loire €500,000 after finding GDPR security failures that contributed to a breach affecting patients and trusted third parties. The enforcement action covers a summer 2025 exposure that reached 524,867 patients and 202,246 trusted third parties. The penalty raises the compliance stakes for hospital systems handling sensitive health data.

Hôpital privé de la Loire hit by network compromise

Incident

Updated: 04.09.2026 01:01 · First: 04.09.2026 01:01 · 📰 1 src / 1 articles · H score: 54

Hôpital privé de la Loire suffered a data breach after an attacker accessed its electronic patient record system and extracted sensitive data tied to more than 727,000 people. The compromise exposed patient-related information and records connected to people who received care at the hospital or assisted patients there. It became a large-scale privacy incident because the intrusion reached core medical records and remained undetected long enough for data to be removed.

Malicious Terraform modules with credential-stealing code

Malware Activity

Updated: 03.09.2026 23:04 · First: 03.09.2026 23:04 · 📰 1 src / 1 articles · H score: 30

Malicious Terraform modules were delivered through a compromised registry and ran credential-stealing code, putting developer secrets and cloud credentials at risk. The modules were served during an August 31 delivery window and exfiltrated collected data to coder-infra[.]com. The activity targeted secrets in developer environments and provisioners, including API keys, CI/CD credentials, SSH keys, and OIDC tokens.

Coder hit by network compromise

Incident

Updated: 03.09.2026 23:04 · First: 03.09.2026 23:04 · 📰 1 src / 1 articles · H score: 38

Coder disclosed an infrastructure compromise of registry.coder.com that let attackers serve malicious Terraform modules to some users and potentially expose secrets on affected hosts. The altered delivery path ran through Cloudflare-backed infrastructure and affected requests made between 07:35 UTC and 21:45 UTC on Monday, August 31. Coder said the malicious files contained credential-stealing code and advised impacted users to rotate secrets, review logs, and purge cached packages.

ArubaOS-CX buffer overflow RCE (CVE-2026-73749)

Vulnerability

Updated: 03.09.2026 21:28 · First: 03.09.2026 21:28 · 📰 1 src / 1 articles · H score: 30

HPE patched CVE-2026-73749, a critical ArubaOS-CX buffer overflow that can let unauthenticated remote attackers reach code execution with elevated privileges on affected switches.

HPE ArubaOS-CX security bulletin (CVE-2026-73749)

Security Patch Release

Updated: 03.09.2026 21:28 · First: 03.09.2026 21:28 · 📰 1 src / 1 articles · H score: 31

HPE released a security bulletin for ArubaOS-CX that patches CVE-2026-73749, a buffer overflow that could let unauthenticated remote attackers reach remote code execution on affected switches. The bulletin lists fixed releases for 10.18.0001, 10.17.1021 and earlier, 10.16.1051 and earlier, 10.13.1180 and earlier, and 10.10.1180 and earlier. HPE also flagged 10.10.1181 as End of Maintenance, limiting its fix support for this critical issue.

Cisco IOS XR hardening release (umbrella CVEs)

Security Patch Release

Updated: 03.09.2026 18:52 · First: 03.09.2026 18:52 · 📰 1 src / 1 articles · H score: 14

Cisco released an IOS XR hardening update that covers all IOS XR releases, including XR7 (LNT), and bundles 7 umbrella CVEs. Two of the grouped flaws are rated 9.8, and Cisco says there is no workaround for any IOS XR version. Customers must upgrade to a release with SMUs and then apply those updates. Releases outside Cisco's support table require a TAC case before the fix path can be completed.

Cisco Nexus 9000 NX-OS patch release for CVE-2026-20212

Security Patch Release

Updated: 03.09.2026 18:52 · First: 03.09.2026 18:52 · 📰 1 src / 1 articles · H score: 14

Cisco released NX-OS patches for CVE-2026-20212, a critical flaw affecting 10 Silicon One-based Nexus 9000 switch PIDs. The bug lets an unauthenticated remote attacker reach TCP 43210/43211 and run code as root on exposed devices. Cisco also provided temporary mitigations — an iACL and a Live Protect shield — while customers use the Software Checker to find fixed releases.

Cisco Nexus 9000 unrestricted IP binding RCE (CVE-2026-20212)

Vulnerability

Updated: 03.09.2026 18:52 · First: 03.09.2026 18:52 · 📰 1 src / 1 articles · H score: 13

CVE-2026-20212 exposes Cisco Nexus 9000 switches to unauthenticated remote code execution through unrestricted IP binding on TCP 43210 and 43211. The flaw leaves those ports reachable in the default Layer 3 VRF instance, and crafted input can run as root or crash the S1HAL process and reload the device. Cisco said it was not aware of malicious use as of the September 2 disclosure. The affected scope includes 10 Silicon One-based Nexus 9000 PIDs and 45 NX-OS releases listed through Cisco's Software Checker.

BraZetsu Windows malware framework powering Infected Marketplace access sales

Malware Activity

Updated: 03.09.2026 18:26 · First: 03.09.2026 18:26 · 📰 1 src / 1 articles · H score: 23

The disclosure of BraZetsu shows a Python-based Windows malware framework being used to turn compromised hosts into tradable access inventory, increasing the value of each foothold for criminal buyers. The framework is tied to Exilware and the Infected Marketplace access-sale operation, where stolen access is monetized for a small deposit. It matters because the toolkit combines reconnaissance, host triage, and AI-assisted target prioritization to help attackers package compromised systems for resale.

Exilware runs an access-as-a-service marketplace for compromised hosts

Threat Actor Meta

Updated: 03.09.2026 18:26 · First: 03.09.2026 18:26 · 📰 1 src / 1 articles · H score: 29

Exilware is operating an access-as-a-service marketplace that monetizes compromised hosts and lets buyers purchase footholds, expanding downstream payload execution across victim systems.

Thomson Reuters hit by cyberattack

Incident

Updated: 03.09.2026 15:00 · First: 03.09.2026 15:00 · 📰 2 src / 2 articles · H score: 26

Thomson Reuters disclosed a cybersecurity incident in C-Track that exposed sensitive court records across Canada and the US. The activity was detected on June 30, and an investigation found that an unauthorized party obtained certain Canada court files tied to three Ontario courts. Affected records may include names, Social Security numbers, driver’s license numbers, medical information, dates of birth, and health insurance information.

AIR Security emerges from stealth with $50 million funding and AIR firewall

Commercial Activity

Updated: 03.09.2026 15:00 · First: 03.09.2026 15:00 · 📰 1 src / 1 articles · H score: 18

AIR Security has emerged from stealth with $50 million in funding and the launch of AIR, a firewall built for AI agents. The rollout expands the market for agent security tools as enterprises connect autonomous assistants to files, email, websites, and internal systems. AIR says its product is meant to reduce risks from poisoned content, malicious add-ons, and unauthorized access.

Thomson Reuters C-Track court records data leak

Data Leak

Updated: 03.09.2026 15:00 · First: 03.09.2026 15:00 · 📰 1 src / 1 articles · H score: 20

The Thomson Reuters C-Track data leak exposed sensitive court records across Ontario and 11 US states, creating privacy and fraud risk for people named in court files. Thomson Reuters said it detected activity on June 30 and later confirmed that an unauthorized party obtained certain files. The affected records may include names, Social Security numbers, driver’s license numbers, medical information, dates of birth, and health insurance information.

AIR Security launches AIR firewall for enterprise AI-agent supply chains

Security Tool/Service

Updated: 03.09.2026 15:00 · First: 03.09.2026 15:00 · 📰 1 src / 1 articles · H score: 18

AIR Security emerged from stealth with AIR, a firewall for AI agents that evaluates add-ons before and after deployment to reduce supply-chain risk. The product targets skills, plugins, MCP servers, and add-ons that can hide external instructions, malicious behavior, or typo-squatted packages. Enterprises can also revoke trust across dependent agents and workflows when a component becomes malicious, vulnerable, or unapproved.

RMM phishing campaign spanning 46 countries

Campaign

Updated: 03.09.2026 14:58 · First: 03.09.2026 14:58 · 📰 1 src / 1 articles · H score: 30

A rotating RMM phishing campaign now spans 46 countries, increasing the risk of unauthorized remote-access installation and making detection harder. The United States is the top target, accounting for about 45% of observed activity. Attackers use fake documents, including CRA tax forms, shipping notices, invoices, and Social Security themes, to push victims toward legitimate remote monitoring and management software. Rapidly changing disposable infrastructure, including Vercel, helps the operation evade tracking.

Microsoft Teams and new Outlook launch failures on ARM-based Windows devices

Service Disruption

Updated: 03.09.2026 11:55 · First: 03.09.2026 11:55 · 📰 1 src / 1 articles · H score: 0

Microsoft is working to fix a Windows update issue that causes Microsoft Teams and new Outlook for Windows to fail to launch or close unexpectedly on ARM-based Windows 11 devices, disrupting access for affected users. The problem affects systems such as Surface Pro 11 and Surface Laptop 7 after August 11, 2026 updates, and Microsoft has issued a temporary workaround while a permanent fix is still pending.

Recurring advanced-spyware targeting of political and civic figures in Serbia since early 2026

Trend

Updated: 03.09.2026 11:43 · First: 03.09.2026 11:43 · 📰 2 src / 2 articles · H score: 7

At least 14 people in Serbia have been targeted with advanced spyware since early 2026, concentrating risk on student movement members, activists, an opposition MP, and a local councilor. The pattern includes Pegasus and NoviSpy cases across iPhone and Android devices, pointing to sustained surveillance pressure on politically visible people rather than a one-off compromise. A new forensic report says a Serbian student protest member's iPhone was infected with NSO Group's Pegasus through an iMessage zero-click exploit that the researchers believed had been patched by Apple in iOS 18.4.1. The notification was among at least 14 documented by the SHARE Foundation, and the case was linked to ongoing targeting ahead of 2026 election cycles.

Member of Serbia's student protest movement hit by network compromise linked to NSO Group

Incident

Updated: 03.09.2026 11:43 · First: 03.09.2026 11:43 · 📰 2 src / 2 articles · H score: 9

A member of Serbia's student protest movement was infected on an iPhone with NSO Group's Pegasus through an iMessage zero-click exploit. The forensic review by Citizen Lab and the SHARE Foundation found high-confidence indicators of infection across December 2025 – January 2026, and the attack was believed to have been patched by Apple in iOS 18.4.1. The compromise fits a broader pattern of mercenary spyware targeting people linked to Serbia's protest movement and civil society ahead of 2026 election cycles.

Sality botnet payload distribution and propagation activity

Malware Activity

Updated: 02.09.2026 09:56 · First: 02.09.2026 09:56 · 📰 3 src / 3 articles · H score: 62

The Sality P2P botnet has operated for more than 20 years and was disrupted in a US-led operation on August 31 with support from Bulgaria, Hungary, Romania, Europol, CrowdStrike, and the Shadowserver Foundation. The action used sinkholing and seizures of Sality-linked domains to cut off the botnet’s control infrastructure. CrowdStrike said Sality enabled payload delivery to over 15,000 infected machines, while Europol said it had reached over one million infected machines at its peak and linked more than 11 million unique IP addresses over two decades. The activity supported credential theft, spam distribution, proxy services, network exploitation, DDoS attacks, and crypto-theft.

Kaspersky endpoint security Windows 14.0.0.504 HardBreacher privilege escalation privilege-escalation flaw

Vulnerability

Updated: 03.09.2026 09:26 · First: 03.09.2026 09:26 · 📰 1 src / 1 articles · H score: 30

A public HardBreacher PoC exposes a privilege escalation in Kaspersky's endpoint security product for Windows 14.0.0.504, creating local permission-escalation risk and product instability on affected systems.

SonicWall SMA1000 command injection flaws (multiple vulnerabilities)

Vulnerability

Updated: 02.09.2026 09:39 · First: 02.09.2026 09:39 · 📰 3 src / 4 articles · H score: 59

SonicWall SMA 1000 appliances are facing active exploitation of CVE-2026-83548 and CVE-2026-83549, a vulnerability chain that can lead to remote code execution on affected devices. The flaws hit SMA 1000 models 6210, 7210, and 8200v and combine a pre-auth SSRF in the Appliance Work Place interface with a post-auth command injection in the Appliance Management Console (AMC). SonicWall released fixes in 12.4.3-03526 and 12.5.0-02952 and urged customers to upgrade, review for indicators of compromise, and re-image appliances or reset passwords and TOTP if compromise is found.

CISA KEV multi-vulnerability exploitation wave

Exploitation Wave

Updated: 03.09.2026 08:19 · First: 03.09.2026 08:19 · 📰 1 src / 1 articles · H score: 59

CISA's KEV list gained seven exploited flaws, signaling active abuse across SonicWall SMA 1000, Sangoma Switchvox, JFrog Artifactory, Starlette, Kestra OSS, and LiteLLM. Attackers were observed weaponizing some of the vulnerabilities to deploy reverse shells, mint admin tokens, and install cryptocurrency miners. The wave also reached AI infrastructure and exposed systems that operators were told to patch on an accelerated schedule.

Sangoma Switchvox active exploitation wave (CVE-2026-9586)

Exploitation Wave

Updated: 03.09.2026 00:00 · First: 03.09.2026 00:00 · 📰 1 src / 1 articles · H score: 41

CVE-2026-9586 is being exploited in a broad wave against internet-exposed Sangoma Switchvox systems, with repeated attempts and reverse-shell activity signaling immediate compromise risk for exposed deployments.

Sangoma Switchvox unauthenticated SQL injection SQL injection flaw (CVE-2026-9586)

Vulnerability

Updated: 03.09.2026 00:00 · First: 03.09.2026 00:00 · 📰 1 src / 1 articles · H score: 41

CVE-2026-9586 is being actively exploited in Sangoma Switchvox, exposing internet-facing VoIP systems to remote code execution through an unauthenticated SQL injection flaw. Researchers say most exposed systems have already been targeted or will be soon, and honeypots saw repeated attempts from 176.65.148.184 on August 30. Sangoma fixed the issue in Switchvox 8.4.0.2, and administrators are urged to upgrade and review logs for compromise indicators.

OpenAI Astra reaches Critical cybersecurity threshold with Daybreak Blue tester access

Security Tool/Service

Updated: 02.09.2026 21:27 · First: 02.09.2026 21:27 · 📰 1 src / 1 articles · H score: 18

OpenAI has moved Astra into a controlled tester-access phase after classifying it at the Critical cybersecurity capability threshold, raising the stakes for advanced AI-assisted offense and defense. The company plans to expose its most advanced cybersecurity features through Daybreak Blue while pairing the rollout with added safeguards against misuse. The event signals a tightly managed release of a named cyber-capable model rather than a general model announcement.

Google launches Gemini 3.8 Flash Cyber with Fairwind Program early access for defenders

Security Tool/Service

Updated: 02.09.2026 21:27 · First: 02.09.2026 21:27 · 📰 1 src / 1 articles · H score: 15

Google released Gemini 3.8 Flash Cyber and opened Fairwind Program access for trusted defenders, giving governments, healthcare providers, and telecommunications services earlier access to advanced cyber-model capabilities. The rollout is aimed at improving autonomous vulnerability discovery and helping defenders strengthen protections before new threats arrive. The event expands Google’s defensive AI offering and extends early access to selected security customers and partners.

Silver Fox bogus software-download websites campaign

Campaign

Updated: 02.09.2026 19:41 · First: 02.09.2026 19:41 · 📰 1 src / 1 articles · H score: 38

An active Silver Fox (aka Yinhu) campaign is using bogus software-download websites to impersonate trusted vendors and deliver malicious installers, exposing China-based multinational operations and Chinese-speaking users to compromise. The lure pages mimic legitimate software sites and drive downloads from infrastructure such as gehie246[.]com, while the payload chain uses wrapper installers or msiexec.exe to start execution. The activity has affected organizations in healthcare, manufacturing, gaming, technology, logistics, government, and education and includes defenses evasion such as disabling Microsoft Defender and tampering with Windows Update.

ValleyRAT malicious installer activity

Malware Activity

Updated: 02.09.2026 19:41 · First: 02.09.2026 19:41 · 📰 1 src / 1 articles · H score: 22

ValleyRAT installers delivered through bogus software-download websites are compromising Windows endpoints and reaching users seeking popular software. The operation has affected China-based multinational operations and Chinese-speaking users across multiple industries. Once launched, the payload sets persistence, weakens security protections, and establishes C2, raising the risk of follow-on intrusion and device compromise.