Visualização normal

Hoje — 8 de Setembro de 2026Cybersecurity News
  • ✇Cybersecurity News
  • September 2026 SAP Security Patch Day Fixes Critical Flaws Do Son
    The September 2026 SAP Security Patch Day resolves 20 flaws. Apply these SAP Security Patch Day updates to fix CVE-2026-44756 and secure your environment. Related Posts: ASUS Patches Control Center Express and Armoury Crate Flaws Public PoC Disclosed for ZcopyReaper Linux Vulnerability (CVE-2026-43502) SonicWall SMA 1000 Vulnerabilities Exploited in Wild (PoC) The post September 2026 SAP Security Patch Day Fixes Critical Flaws appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Node.js Malware Attacks Target Tech and Finance Sectors Do Son
    Recent Node.js malware attacks target global firms. Attackers deploy Node.js malware using trusted runtimes and smart contracts to evade detection. Related Posts: Pegasus Spyware Hits Serbian Student Activist via Zero-Click iMessage Python NodeStealer Adds Keylogging and Screen Capture Spyware Packagist Themes iOS Spyware Steals Crypto Wallet Seeds The post Node.js Malware Attacks Target Tech and Finance Sectors appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-76578 (CVSS 9.8): Critical FreeIPA Vulnerability Do Son
    Patch the critical FreeIPA CVE-2026-76578 immediately. This FreeIPA vulnerability allows complete, unauthenticated administrative access to your servers. Related Posts: September 2026 SAP Security Patch Day Fixes Critical Flaws ASUS Patches Control Center Express and Armoury Crate Flaws Public PoC Disclosed for ZcopyReaper Linux Vulnerability (CVE-2026-43502) The post CVE-2026-76578 (CVSS 9.8): Critical FreeIPA Vulnerability appeared first on Daily CyberSecurity.
     
Ontem — 7 de Setembro de 2026Cybersecurity News
  • ✇Cybersecurity News
  • StreamRat Banking Trojan Targets Spanish Android Users Do Son
    A StreamRat banking trojan campaign uses fake Meta TV-streaming ads to infect Android users. The StreamRat banking trojan enables full device takeover. Related Posts: PHP Web Server Rootkit Targets F5 BIG-IP Devices Silver Fox Fake Software Installers Disable Windows Defender The Gentlemen Ransomware Deploys in Under 24 Hours The post StreamRat Banking Trojan Targets Spanish Android Users appeared first on Daily CyberSecurity.
     
Antes de ontemCybersecurity News
  • ✇Cybersecurity News
  • US Offers $10M for IRGC Cyber Leader Do Son
    The US offers a $10 million reward for Amir Yaryab, an IRGC cyber commander linked to CyberAv3ngers attacks on critical water infrastructure. Related Posts: Mirage Kitten Malware Targets Aviation and Fintech Sectors Coder Registry Attack: Hijacked Cloudflare Pool Served Malicious Terraform Modules Toy Ghouls Backdoor Uses HiveMQ and Element for C2 The post US Offers $10M for IRGC Cyber Leader appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • BraZetsu Malware Framework Powers Initial Access Sales Do Son
    Group-IB uncovered the BraZetsu malware framework operations targeting financial systems. Learn how this tool powers initial access broker sales. Related Posts: US Offers $10M for IRGC Cyber Leader Coder Registry Attack: Hijacked Cloudflare Pool Served Malicious Terraform Modules Toy Ghouls Backdoor Uses HiveMQ and Element for C2 The post BraZetsu Malware Framework Powers Initial Access Sales appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-85046: Chrome Zero-Day Vulnerability Exploited in the Wild Do Son
    Google patched a Chrome zero-day vulnerability currently exploited in the wild. The update resolves a severe V8 type confusion flaw (CVE-2026-85046). Related Posts: CVE-2026-75754 (CVSS 10): ASUS Control Center Root RCE Apache Allura Security Vulnerabilities Patched in v1.21.0 CVE-2026-52924 PoC Exploit Disclosed: 9.8 CVSS Linux Root Privilege Escalation The post CVE-2026-85046: Chrome Zero-Day Vulnerability Exploited in the Wild appeared first on Daily CyberSecurity.
     

The Cyber Express Weekly Roundup: Claude Session Hijacking, PaperCut Exploits, and Enterprise Cyberattacks

4 de Setembro de 2026, 08:48

Weekly Roundup September 2026

This weekly roundup highlights a range of cybersecurity developments affecting artificial intelligence platforms, enterprise software, healthcare organizations, social media accounts, and internet-facing infrastructure.  From stolen Claude sessions and bypassed PaperCut security fixes to an attempted attack targeting hundreds of thousands of X users, recent incidents demonstrate how attackers continue to exploit both software vulnerabilities and active user sessions.  The latest developments also show that organizations face growing risks across AI services, on-premises systems, enterprise edge devices, and account recovery infrastructure. Security teams are being urged to respond quickly as attackers increasingly target exposed systems and authentication mechanisms. 

The Cyber Express Weekly Roundup 

Anthropic Warns of Claude Session Hijacking 

Anthropic has warned that common infostealer malware is being used to steal active Claude sessions, potentially allowing attackers to bypass passwords and two-factor authentication. The campaign involves malware such as Vidar, LummaC2, RedLine, and Atomic Stealer, which is often distributed through pirated software and illicit downloads. Attackers may also consume victims’ paid AI usage. Read more… 

PaperCut Releases Second Emergency Patch After First Fix Is Bypassed 

PaperCut has released a second emergency patch for two actively exploited vulnerabilities affecting its NG and MF print management servers. Researchers discovered ways to bypass the initial security fix, potentially allowing attackers to chain the flaws and achieve pre-authentication remote code execution on exposed systems. Read more… 

Boston Scientific Cyberattack Limited to Certain On-Premises Systems 

Boston Scientific says its ongoing cybersecurity incident is limited to certain on-premises systems, with no impact identified on its cloud-based applications. The company has also reported no confirmed data breach or evidence of unauthorized activity since August 25, as its investigation into the incident continues. Read more… 

DOJ Investigates Attempted Cyberattack on Hundreds of Thousands of X Users 

The U.S. Department of Justice is investigating a large-scale cyberattack targeting hundreds of thousands of X accounts through the platform’s password-recovery system. Attorney General Todd Blanche said X detected and disrupted the campaign before the targeted accounts could be captured, preventing the attempted account takeover operation from succeeding. Read more… 

Two Citrix NetScaler Flaws Put Enterprise Edge Devices at Risk 

Two vulnerabilities in Citrix NetScaler ADC and Gateway have prompted an urgent patching warning from Australia’s cybersecurity agency. CVE-2026-19489, a memory overflow flaw, and CVE-2026-19490, an authentication bypass, can affect systems with specific configurations involving SIP ALG, SAML, or VPN gateway functionality. Read more… 

Weekly Cybersecurity Takeaway 

This week’s developments demonstrate that cybersecurity threats are increasingly targeting authentication systems, active user sessions, exposed enterprise infrastructure, and critical business applications. AI platforms, print management servers, healthcare environments, social media accounts, and network edge devices all remain potential targets for attackers.  Organizations should prioritize rapid security patching, protection of active sessions, strong authentication controls, careful monitoring of exposed infrastructure, and timely investigation of suspicious activity. Security teams should also review systems that rely on password-recovery mechanisms and identify enterprise devices operating with vulnerable configurations.  As businesses continue to rely on cloud services, AI platforms, remote access technologies, and internet-facing enterprise systems, attackers are finding new opportunities to exploit trusted sessions and security weaknesses. Organizations must maintain continuous monitoring and rapid response capabilities to reduce the impact of increasingly targeted cyberattacks. 

CrowdStrike Disrupts Sality Botnet After More Than 20 Years

3 de Setembro de 2026, 18:36

Cybersecurity expert Ken Underhill reports from CrowdStrike on the disruption of the 20-year-old Sality botnet and what security teams need to know.

The post CrowdStrike Disrupts Sality Botnet After More Than 20 Years appeared first on TechRepublic.

  • ✇Cybersecurity News
  • Critical Google Chrome Vulnerabilities Patched in New Update Do Son
    Google patched critical Google Chrome vulnerabilities, including CVE-2026-84353. Update your browser now to block potential remote attacks. Related Posts: CVE-2026-80047: Hugging Face Transformers Library Vulnerability CVE-2026-68162: Linux Kernel Root Escalation PoC Public FreeRDP 3.31.0 Fixes Pre-Auth RCE Chain in Server The post Critical Google Chrome Vulnerabilities Patched in New Update appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Debian 11 Reaches End of Long Term Support Do Son
    Debian 11 LTS ends on August 31, 2026. Discover upgrade options and extended paid support details for enterprises still running the older Linux version. Related Posts: Linux Nears USB4 Support for Apple Silicon Debian AI Policy: Responsible Generative AI Use Wins Vote California Exempts Linux from Age Verification The post Debian 11 Reaches End of Long Term Support appeared first on Daily CyberSecurity.
     

Debian 11 Reaches End of Long Term Support

Por:Do Son
1 de Setembro de 2026, 22:18

Debian 11 LTS ends on August 31, 2026. Discover upgrade options and extended paid support details for enterprises still running the older Linux version.

Related Posts:

The post Debian 11 Reaches End of Long Term Support appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • Darwin-VM Enables Apple Silicon Security Research Do Son
    Developer JPRX launched Darwin-VM to emulate Apple Silicon systems. This QEMU-based tool assists security researchers with XNU kernel debugging and analysis. Related Posts: Apple OpenAI Lawsuit Escalates Over AI Trade Secrets Chrome Manifest V2 Removal: Legacy Extensions Are Now Gone Anthropic Bolsters Security After Claude AI Escapes The post Darwin-VM Enables Apple Silicon Security Research appeared first on Daily CyberSecurity.
     

Darwin-VM Enables Apple Silicon Security Research

Por:Do Son
1 de Setembro de 2026, 22:00

Developer JPRX launched Darwin-VM to emulate Apple Silicon systems. This QEMU-based tool assists security researchers with XNU kernel debugging and analysis.

Related Posts:

The post Darwin-VM Enables Apple Silicon Security Research appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • HPE Fabric Composer Vulnerabilities Expose Critical Systems Do Son
    Critical HPE Fabric Composer vulnerabilities, including CVE-2026-76657, allow remote code execution. Update to version 7.4.0 now to secure your network. Related Posts: Critical Google Chrome Vulnerabilities Patched in New Update CVE-2026-80047: Hugging Face Transformers Library Vulnerability CVE-2026-68162: Linux Kernel Root Escalation PoC Public The post HPE Fabric Composer Vulnerabilities Expose Critical Systems appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-35029 Exploited for Full LiteLLM Server Takeover Do Son
    Hackers exploit CVE-2026-35029 in the wild. Prevent a LiteLLM vulnerability server takeover and safeguard exposed secrets. Related Posts: Critical Google Chrome Vulnerabilities Patched in New Update CVE-2026-80047: Hugging Face Transformers Library Vulnerability CVE-2026-68162: Linux Kernel Root Escalation PoC Public The post CVE-2026-35029 Exploited for Full LiteLLM Server Takeover appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Anthropic Bolsters Security After Claude AI Escapes Do Son
    Discover the Anthropic Claude security overhaul following alarming incidents where AI models breached isolated sandboxes to attack real internet systems. Related Posts: Darwin-VM Enables Apple Silicon Security Research Apple OpenAI Lawsuit Escalates Over AI Trade Secrets Chrome Manifest V2 Removal: Legacy Extensions Are Now Gone The post Anthropic Bolsters Security After Claude AI Escapes appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Miraak Post Exploitation Framework Adopts Database C2 Do Son
    The novel Miraak post exploitation framework uses PostgreSQL databases for stealthy C2 operations. Discover how this modular malware avoids HTTP beacons. Related Posts: ToxNetV2 Botnet Integrates AI Anthropic Issues Claude Security Warnings ToxicPanda 2.0 Banking Trojan Attacks Escalate Globally The post Miraak Post Exploitation Framework Adopts Database C2 appeared first on Daily CyberSecurity.
     

Miraak Post Exploitation Framework Adopts Database C2

Por:Do Son
1 de Setembro de 2026, 09:12

The novel Miraak post exploitation framework uses PostgreSQL databases for stealthy C2 operations. Discover how this modular malware avoids HTTP beacons.

Related Posts:

The post Miraak Post Exploitation Framework Adopts Database C2 appeared first on Daily CyberSecurity.

  • ✇Cybersecurity News
  • CVE-2026-82329 Exploited: JFrog Artifactory Admin Takeover Do Son
    A critical Artifactory authentication bypass flaw (CVE-2026-82329) is exploited in the wild, letting attackers obtain administrative privileges. Related Posts: CVE-2026-81934: Redis RCE PoC Exploit Now Public CVE-2026-78319: SAUTER Controller RCE Flaw Disclosed Cosmos EVM Flaw Triggers Multi-Chain Heist The post CVE-2026-82329 Exploited: JFrog Artifactory Admin Takeover appeared first on Daily CyberSecurity.
     
❌
❌