CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-07 12:55 UTC · REPORT BRIEF-20260907-125508
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: Ars Technica Security, BleepingComputer, Cyber Risk & Security, Help Net Security, Security Affairs, SecurityWeek
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
10
Stories Featured
8
Sources
10
Active KEV CVEs
46
IOC Indicators
Top Stories
01
Trezor data breach impact now reaches 81,000 customers
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. […].
critical
SRC: BleepingComputer
Mon, 07 Sep 2026 08:16:32 -0400
https://www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/
02
Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges. The post Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits appeared first on SecurityWeek.
critical
SRC: SecurityWeek
Mon, 07 Sep 2026 12:15:57 +0000
https://www.securityweek.com/nightmare-eclipse-drops-crowdstrike-nvidia-avast-zero-day-exploits/
03
North Korean Hackers Deploy New Linux Espionage Toolkit
The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The post North Korean Hackers Deploy New Linux Espionage Toolkit appeared first on SecurityWeek.
high
SRC: SecurityWeek
Mon, 07 Sep 2026 12:12:08 +0000
https://www.securityweek.com/north-korean-hackers-deploy-new-linux-espionage-toolkit/
04
OpenAI Agents Hijack Another Victim Website
OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach. The post OpenAI Agents Hijack Another Victim Website appeared first on SecurityWeek.
critical
SRC: SecurityWeek
Mon, 07 Sep 2026 12:03:04 +0000
https://www.securityweek.com/openai-agents-hijack-another-victim-website/
05
Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. The post Adobe Commerce Zero-Day Exploited to Backdoor Online Stores appeared first on SecurityWeek.
critical
SRC: SecurityWeek
Mon, 07 Sep 2026 11:58:37 +0000
https://www.securityweek.com/adobe-commerce-zero-day-exploited-to-backdoor-online-stores/
06
N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)
N-able released an emergency hotfix for CVE-2026-86218, a remote code execution (RCE) flaw affecting N-central, its remote monitoring and management (RMM) solution popular with managed service providers (MSPs). In its release notes, N-able described CVE-2026-86218 as a “critical-CVSS-rated vulnerability that could allow for pre-authenticated remote code execution on the N-central server.” N-able a
critical
SRC: Help Net Security
Mon, 07 Sep 2026 11:55:57 +0000
https://www.helpnetsecurity.com/2026/09/07/n-able-n-central-hotfix-cve-2026-86218/
07
DPRK-Linked Hackers Deploy Ted Backdoor and CurlRAT Against South Korean Firms
South Korean automotive and media organizations have been hit by a quiet Linux intrusion toolkit built for long-term access. The malware hides inside software that manages web traffic, allowing attackers to watch users, steal information, and change pages delivered through compromised servers. The operation appears designed for patience rather than disruption. Attackers likely entered through […]
high
SRC: Cyber Risk & Security
Mon, 07 Sep 2026 11:54:56 +0000
https://cybersecuritynews.com/dprk-linked-hackers/
08
Modified ScreenConnect Clients Used in Worm-Like Campaign
The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients. The post Modified ScreenConnect Clients Used in Worm-Like Campaign appeared first on SecurityWeek.
high
SRC: SecurityWeek
Mon, 07 Sep 2026 11:45:48 +0000
https://www.securityweek.com/modified-screenconnect-clients-used-in-worm-like-campaign/
09
The complex corporate web behind a $3.2 billion AI data center
When multiple companies are behind one project, who bears responsibility for problems?
medium
SRC: Ars Technica Security
Mon, 07 Sep 2026 11:00:03 +0000
https://arstechnica.com/ai/2026/09/the-ai-data-center-boom-is-causing-new-accountability-problems/
10
Roundcube Webmail Patches 12 Security Flaws, Including Zero-Click XSS and SSRF Bypass
Roundcube Webmail has released security updates for its 1.6 LTS and 1.7 branches, fixing 12 vulnerabilities that could expose users and servers to cross-site scripting, email header injection, cross-user data access, remote-content bypasses, and server-side request forgery attacks. The new releases, Roundcube 1.6.19 and 1.7.4, address flaws in how the open-source webmail platform processes email [
critical
SRC: Cyber Risk & Security
Mon, 07 Sep 2026 10:49:56 +0000
https://cybersecuritynews.com/roundcube-webmail-patches-12-security-flaws/
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-85046 | Chromium V8 (Google) | 2026-09-04 |
| CVE-2026-59822 | LiteLLM (BerriAI) | 2026-09-02 |
| CVE-2026-48710 | Starlette (Kludex) | 2026-09-02 |
| CVE-2026-49869 | Kestra OSS (Kestra) | 2026-09-02 |
| CVE-2026-82329 | Artifactory (JFrog) | 2026-09-02 |
| CVE-2026-9586 | Switchvox (Sangoma) | 2026-09-02 |
| CVE-2026-83548 | SMA1000 Appliances (SonicWall) | 2026-09-02 |
| CVE-2026-83549 | SMA1000 Appliances (SonicWall) | 2026-09-02 |
| CVE-2026-82078 | NG/MF (PaperCut) | 2026-08-31 |
| CVE-2026-81578 | NG/MF (PaperCut) | 2026-08-31 |
Indicators of Compromise (IOC)
[ OK ] Generated by Walternate · CRON: cyber-briefing
· 2026-09-07 12:55 UTC
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
