CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-08 12:41 UTC · REPORT BRIEF-20260908-124108
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: CISA KEV Catalog, CyberScoop, SecurityWeek, The Hacker News, The Hacker News (feedburner)
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
11
Stories Featured
5
Sources
10
Active KEV CVEs
43
IOC Indicators
Top Stories
01
N-able Patches Critical Zero-Day in N-central
Administrators are advised to check their deployments for newly created user accounts they don’t recognize.
The post N-able Patches Critical Zero-Day in N-central appeared first on SecurityWeek.
SRC: SecurityWeek
Tue, 08 Sep 2026 10:37:58 +0000
https://www.securityweek.com/n-able-patches-critical-zero-day-in-n-central/
02
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild.
The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026.
"This update resolves a critical
SRC: The Hacker News
Tue, 08 Sep 2026 14:43:47 +0530
https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html
03
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser.
"Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user promp
SRC: The Hacker News
Mon, 07 Sep 2026 23:42:09 +0530
https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html
04
Mathspace Data Breach Exposes Over 1 Million People
Hackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance.
The post Mathspace Data Breach Exposes Over 1 Million People appeared first on SecurityWeek.
SRC: SecurityWeek
Tue, 08 Sep 2026 10:47:36 +0000
https://www.securityweek.com/mathspace-data-breach-exposes-over-1-million-people/
05
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins.
The activity, which mainly singles out directors, vice presidents, and other executive staff
SRC: The Hacker News
Mon, 07 Sep 2026 21:21:56 +0530
https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html
06
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.
Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management
SRC: The Hacker News
Mon, 07 Sep 2026 20:06:07 +0530
https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html
07
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says.
FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software.
The
SRC: The Hacker News
Tue, 08 Sep 2026 16:52:07 +0530
https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html
08
MikroTik Patches Critical Flaws Chained to Hack Routers
Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices.
The post MikroTik Patches Critical Flaws Chained to Hack Routers appeared first on SecurityWeek.
SRC: SecurityWeek
Tue, 08 Sep 2026 11:15:00 +0000
https://www.securityweek.com/mikrotik-patches-critical-flaws-chained-to-hack-routers/
09
In most cities, nobody owns the whole network
July’s intrusions reached water controllers that sat on a cellular link no city network scan would find. Naming an owner and paying for the fix are decisions a utility can make this fiscal year, out of money it already applies for.
The post In most cities, nobody owns the whole network appeared first on CyberScoop.
SRC: CyberScoop
Tue, 08 Sep 2026 10:00:00 +0000
https://cyberscoop.com/water-utility-cybersecurity-network-segmentation-op-ed/
10
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams.
The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect
SRC: The Hacker News
Tue, 08 Sep 2026 14:13:51 +0530
https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html
11
Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with third-parties.
Grindr, which is the largest LGBTQ+ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising.
SRC: The Hacker News
Tue, 08 Sep 2026 12:30:43 +0530
https://thehackernews.com/2026/09/grindr-to-pay-26-million-to-settle-uk.html
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-85046 | Chromium V8 (Google) | 2026-09-04 |
| CVE-2026-59822 | LiteLLM (BerriAI) | 2026-09-02 |
| CVE-2026-48710 | Starlette (Kludex) | 2026-09-02 |
| CVE-2026-49869 | Kestra OSS (Kestra) | 2026-09-02 |
| CVE-2026-82329 | Artifactory (JFrog) | 2026-09-02 |
| CVE-2026-9586 | Switchvox (Sangoma) | 2026-09-02 |
| CVE-2026-83548 | SMA1000 Appliances (SonicWall) | 2026-09-02 |
| CVE-2026-83549 | SMA1000 Appliances (SonicWall) | 2026-09-02 |
| CVE-2026-82078 | NG/MF (PaperCut) | 2026-08-31 |
| CVE-2026-81578 | NG/MF (PaperCut) | 2026-08-31 |
Indicators of Compromise (IOC)
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
