CM-SEC
  • PROJECT-VICAT
PROJECT-VICAT

The Hacker News • 6th September 2026

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe.

The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as create privileged accounts.

"Observed post-exploitation activity included delivery of Windows registry h...
The Hacker News • 6th September 2026

Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel

A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox.

The activity was concentrated on DSEwiki, a German software developer wiki that runs on the ProWiki farm at wikiservice[.]at and had been edited about 20 times over the previous decade....
The Hacker News • 6th September 2026

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk.

The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets.

"Throughout our entire relationship with ShipMonk, we repeatedly requested and received written ass...
The Hacker News • 6th September 2026

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions.

The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code.

"A malicious actor with local administrative privileges on a virtual machine with VMXNET3 virtual network adapter...
The Hacker News • 6th September 2026

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment.

"Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said. "They should also treat all executions, including their inputs and outputs in your Cadence project, a...
The Hacker News • 6th September 2026

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5.

Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early because stores are being compromised right now," the company said.

As of September 6, Adobe has not publi...
The Hacker News • 5th September 2026

GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests

OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model."

The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under its Preparedness Framework.

"Astra is state-of-the-art on computer use, browsing, software engineering, cybersecurity, science, and professional work. Astra saturates FrontierMath Tier 4 with a 98% score," OpenAI said...
The Hacker News • 5th September 2026

Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild.

The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine.

"Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page," reads a description of the...
The Hacker News • 5th September 2026

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws.

The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them.

"We recommend all server owners and Desktop users update to the latest version as soon as possible," Plex said in an announcement this week. "If you're...
The Hacker News • 5th September 2026

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence.

The vulnerabilities in question are -

As with arbitrary file upload vulnerabilities of this kind, an attacker can leverage them to write a PHP web shell to the site and execute arbitrary code, which can then be abused to create administrator accounts, exfiltrate data, or seize control of the entire WordPress site.
It's worth noting that details abou...
The Hacker News • 5th September 2026

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors.

The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and the ability to replace the running binary.

Rapid7 Labs attributed the toolkit with medium confidence...
The Hacker News • 5th September 2026

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server.

The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are affected.

Exploitation requires an account carrying the REPLICATION attribute and a server running wi...
The Hacker News • 5th September 2026

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters.

"Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said.

The Windows maker said the findings show AI-era evasion techniques can be adapted by threat actors in tradi...
The Hacker News • 4th September 2026

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs.

The vulnerabilities are as follows -

The development comes after SonicWall disclosed that it "investigated a case indicating the active exploitation" of CVE-2026-83548 and CVE-2026-83549. According to reports from Horizon3.ai and watchTowr, unknown threat actors have been observed weaponizing CV...
The Hacker News • 4th September 2026

Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a proof-of-concept (PoC) for a privilege escalation flaw impacting Crowdstrike Falcon.

"FalconFlank is a 0-day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in a GitHub README file, adding the cybersecurity company may already have detections for the flaw by now....
The Hacker News • 4th September 2026

Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation.

"Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware," the Citizen Lab said. "We found high-confidence indicators of infection from a period across December 2025 – January 2026; however, this does not preclude the possibi...
The Hacker News • 4th September 2026

Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means

In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs.

Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have stopped trying to break trust relationships and started using the credentials that already make those r...
The Hacker News • 4th September 2026

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads.

According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026.

"The technique's appeal is that node.exe (the binary that runs Node.js) is a legitimate, signed developer tool," the Broadcom-owned cybersecurity divi...
The Hacker News • 4th September 2026

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries.

Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses fake documents to trick victims into installing legitimate remote monitoring and management (RMM) soft...
The Hacker News • 4th September 2026

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada.

West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names, Social Security numbers, driver's license numbers, dates of birth, medical information, and health i...
Cybersecurity and Infrastructure Security Agency C • 5th September 2026

CISA Adds One Known Exploited Vulnerability to Catalog | CISA

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.  
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance...
Cybersecurity and Infrastructure Security Agency C • 4th September 2026

Pyramid Solutions NetStaX EtherNet/IP Stack | CISA

View CSAF
Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.
The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack are affected:

CVE-2026-78012

An issue in the NetStaX EtherNet/IP Stack prior to v5.6.1 could allow a large Class 3 explicit-message request to exceed the application-side receive...
Cybersecurity and Infrastructure Security Agency C • 4th September 2026

Preparing for the Post-Quantum Era: A Call to Action | CISA

CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems, and critical assets from emerging quantum computing threats.  
The G7 Cyber Security Working Group’s call to action outlines five priorities for a successful transition to PQC:

CISA and the Group of Seve...
Cybersecurity and Infrastructure Security Agency C • 4th September 2026

IXON VPN Client | CISA

View CSAF
Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the computer running the client with elevated privileges.
The following versions of IXON VPN Client are affected:

CVE-2026-75925

Improper Neutralization of CRLF Sequences (CWE-93) in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged...
Cybersecurity and Infrastructure Security Agency C • 4th September 2026

Rockwell Automation ArmorStart LT | CISA

View CSAF
Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page.
The following versions of Rockwell Automation ArmorStart LT are affected:
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
CISA recommends users take defensive measures...
Cybersecurity and Infrastructure Security Agency C • 4th September 2026

Rockwell Automation ControlFLASH | CISA

View CSAF
Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level.
The following versions of Rockwell Automation ControlFLASH are affected:

CVE-2026-12663

A security issue exists within ControlFLASH, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting...
Cybersecurity and Infrastructure Security Agency C • 4th September 2026

Tycon Systems TPDIN-Monitor-WEB3 | CISA

View CSAF
Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information.
The following versions of Tycon Systems TPDIN-Monitor-WEB3 are affected:
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
CISA recommends users take defensive measures to minimize t...
Cybersecurity and Infrastructure Security Agency C • 4th September 2026

OPCFoundation OPC UA LocalDiscoveryServer (LDS) | CISA

View CSAF
Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands.
The following versions of OPCFoundation OPC UA LocalDiscoveryServer (LDS) are affected:
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
CISA recommends users take defensive measures to minimize the risk of exploitati...
Cybersecurity and Infrastructure Security Agency C • 4th September 2026

Inductive Automation Ignition | CISA

View CSAF
Successful exploitation of this vulnerability could allow any authenticated user to create projects.
The following versions of Inductive Automation Ignition are affected:

CVE-2026-77393

In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 se...
Cybersecurity and Infrastructure Security Agency C • 4th September 2026

Rockwell Automation 1756-ENBT Module | CISA

View CSAF
Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover.
The following versions of Rockwell Automation 1756-ENBT Module are affected:

CVE-2025-10478

A denial-of-service security issue exists in the Rockwell Automation 1756-ENBT module which is a ControlLogix EtherNet/IP bridge that enables communication between Logix 5000 controllers and Ethernet devices. An attacker could exploit this vulnerability by sending a crafted CIP pack...

© 2026 CM-SEC, LLC. All rights reserved.