CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-02 12:15 UTC · REPORT BRIEF-20260902-121512
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Krebs on Security, BleepingComputer, The Hacker News, SecurityWeek, Troy Hunt
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
15/15
Stories Featured
5
Sources
10
Active KEV CVEs
25
IOC Indicators
Top Stories
01
SonicWall warns of actively exploited SMA1000 zero-day flaws
SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks.
SRC: BleepingComputer
2026-09-02
https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws/
02
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory. "JFrog Artifactory contains an authentication weakness that, under default.
SRC: The Hacker News
2026-09-01
https://thehackernews.com/2026/09/attackers-exploit-critical-jfrog.html
03
Recently patched PaperCut zero-days used in data theft attacks
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks.
SRC: BleepingComputer
2026-09-01
https://www.bleepingcomputer.com/news/security/recently-patched-papercut-zero-days-used-in-data-theft-attacks/
04
Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed infrastructure associated with the Russian-speaking cybercrime group, leading to the discovery of its.
SRC: The Hacker News
2026-08-31
https://thehackernews.com/2026/08/aurora-ransomware-operators-use-cursor.html
05
US charges Russian for infecting 80,000 freelancers with malware
A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware.
SRC: BleepingComputer
2026-09-02
https://www.bleepingcomputer.com/news/security/us-charges-russian-for-infecting-80-000-freelancers-with-malware/
06
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Russian cybersecurity company Kaspersky is tracking the.
SRC: The Hacker News
2026-09-01
https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html
07
China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
A China-nexus cyber espionage actor tracked as Fire Ant has expanded a long-running campaign beyond VMware hypervisors to compromise Cisco IOS XR routers, Terminal Access Controller Access-Control System (TACACS) servers, and Linux management hosts used to route, authenticate, and manage high-value networks. Sygnia, the incident response firm that investigated the intrusion, said the actor.
SRC: The Hacker News
2026-08-31
https://thehackernews.com/2026/08/china-linked-fire-ant-hijacks-cisco.html
08
Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017. Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025, the U.S. Attorney's Office for the Northern District of California.
SRC: The Hacker News
2026-09-02
https://thehackernews.com/2026/09/extradited-russian-hacker-faces-charges.html
09
FBI Probes Service Selling 153M+ Drivers Licenses
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) to…
SRC: Krebs on Security
2026-09-01
https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
10
Aesto Health says data breach affects over 9.5 million patients
Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals.
SRC: BleepingComputer
2026-09-01
https://www.bleepingcomputer.com/news/security/aesto-health-says-data-breach-affects-over-95-million-patients/
11
Novocure data breach affects more than 1,400 cancer patients
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack.
SRC: BleepingComputer
2026-09-01
https://www.bleepingcomputer.com/news/security/novocure-data-breach-affects-more-than-1-400-cancer-patients/
12
19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share similarities in code and tradecraft, with evidence indicating that the campaign may have been active.
SRC: The Hacker News
2026-08-28
https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html
13
Alleged TeamPCP Hackers Charged in Australia Over Major Supply Chain Attacks
The Australian Federal Police (AFP) has charged two Western Australian men with a combined total of 14 offences over their alleged role in TeamPCP, the cybercrime group behind the March 2026 compromise of the open-source security scanners Trivy and Checkmarx KICS and the AI gateway LiteLLM. Louis Michael Gaebler, 23, and Ruben Ian Thomson, 21, appeared in Perth Magistrates Court on August 27,.
SRC: The Hacker News
2026-08-27
https://thehackernews.com/2026/08/alleged-teampcp-hackers-charged-in.html
14
Hackers push malicious Virtualizor update in BGP hijacking attack
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers.
SRC: BleepingComputer
2026-09-01
https://www.bleepingcomputer.com/news/security/hackers-push-malicious-virtualizor-update-in-bgp-hijacking-attack/
15
Sality botnet infrastructure dismantled in joint global takedown
International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet.
SRC: BleepingComputer
2026-09-02
https://www.bleepingcomputer.com/news/security/sality-botnet-infrastructure-dismantled-in-joint-global-takedown/
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-82078 | NG/MF (PaperCut) | 2026-08-31 |
| CVE-2026-81578 | NG/MF (PaperCut) | 2026-08-31 |
| CVE-2023-49105 | ownCloud (ownCloud) | 2026-08-27 |
| CVE-2026-53362 | Kernel (Linux) | 2026-08-27 |
| CVE-2026-66384 | Artifactory (JFrog) | 2026-08-27 |
| CVE-2021-23758 | Ajax.NET Professional (Ajax.NET Professional) | 2026-08-26 |
| CVE-2015-3246 | Libuser (Red Hat) | 2026-08-26 |
| CVE-2015-5287 | Automatic Bug Reporting Tool (Red Hat) | 2026-08-26 |
| CVE-2022-0995 | Kernel (Linux) | 2026-08-26 |
| CVE-2026-8452 | NetScaler ADC and NetScaler Gateway (Citrix) | 2026-08-26 |
Infrastructure Indicators
evil-tokens[.]comoauth-steal[.]netmfa-phish[.]orgtoken-harvest[.]ioazure-phish[.]ccincron-c2[.]onion[.]toblackcat-leak[.]rulogin-auth[.]onlinenoreply@office365-verify[.]comsupport@docusign-review[.]net3a7b 8c0e 1234 5678 90ab cdef 1234 5678 90ab cdef 1234 5678 90ab cdef 1234 5678a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2185[.]220[.]101[.]xx45[.]153[.]240[.]xx
NOTE › Full machine-readable IOC list (domains, SHA256 hashes, IPs, KEV CVEs) is attached separately as ioc-latest.txt for import into SIEM / blocklist tooling. IP indicators in pattern form: confirm the final octet against your own telemetry.
[ OK ] Generated by Walternate · CRON: cyber-briefing
· 2026-09-02 12:15 UTC
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
