CYBER THREAT INTEL
DAILY BRIEFING · 2026-09-03 12:15 UTC · REPORT BRIEF-20260903-121538
OPEN // LE
PERIOD: LAST 24 HOURS SOURCES: BleepingComputer, SecurityWeek, The Hacker News
TOP 10 LATEST CYBERSECURITY STORIES from the last 24 hours.
5/15
Stories Featured
3
Sources
10
Active KEV CVEs
25
IOC Indicators
Top Stories
01
OpenLeash Adds a Human Check to Risky AI Agent Actions
The security tool intercepts potentially dangerous agent actions, blocking clear threats and requesting human approval when intent is uncertain.
The post OpenLeash Adds a Human Check to Risky AI Agent Actions appeared first on SecurityWeek.
SRC: SecurityWeek
Wed, 02 Sep 2026 19:30:00 +0000
https://www.securityweek.com/openleash-adds-a-human-check-to-risky-ai-agent-actions/
02
WordPress backup plugin flaw exposes millions of sites to takeover attacks
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. […]
SRC: BleepingComputer
Wed, 02 Sep 2026 15:28:46 -0400
https://www.bleepingcomputer.com/news/security/wordpress-backup-plugin-flaw-exposes-millions-of-sites-to-takeover-attacks/
03
Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs
Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday. […]
SRC: BleepingComputer
Thu, 03 Sep 2026 04:55:25 -0400
https://www.bleepingcomputer.com/news/microsoft/microsoft-teams-outlook-fail-to-launch-on-arm-based-windows-pcs/
04
Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs
Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program.
"The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) ear
SRC: The Hacker News
Wed, 02 Sep 2026 23:57:49 +0530
https://thehackernews.com/2026/09/google-anthropic-and-openai-unveil.html
05
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.
"The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational orga
SRC: The Hacker News
Wed, 02 Sep 2026 22:11:06 +0530
https://thehackernews.com/2026/09/fake-software-installers-disable.html
Known Exploited — CISA KEV
| CVE | Product | Added to KEV |
|---|---|---|
| CVE-2026-59822 | LiteLLM (BerriAI) | 2026-09-02 |
| CVE-2026-48710 | Starlette (Kludex) | 2026-09-02 |
| CVE-2026-49869 | Kestra OSS (Kestra) | 2026-09-02 |
| CVE-2026-82329 | Artifactory (JFrog) | 2026-09-02 |
| CVE-2026-9586 | Switchvox (Sangoma) | 2026-09-02 |
| CVE-2026-83548 | SMA1000 Appliances (SonicWall) | 2026-09-02 |
| CVE-2026-83549 | SMA1000 Appliances (SonicWall) | 2026-09-02 |
| CVE-2026-82078 | NG/MF (PaperCut) | 2026-08-31 |
| CVE-2026-81578 | NG/MF (PaperCut) | 2026-08-31 |
| CVE-2023-49105 | ownCloud (ownCloud) | 2026-08-27 |
Infrastructure Indicators
evil-tokens[.]comoauth-steal[.]netmfa-phish[.]orgtoken-harvest[.]ioazure-phish[.]ccincron-c2[.]onion[.]toblackcat-leak[.]rulogin-auth[.]onlinenoreply@office365-verify[.]comsupport@docusign-review[.]net3a7b 8c0e 1234 5678 90ab cdef 1234 5678 90ab cdef 1234 5678 90ab cdef 1234 5678a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2 c3d4 e5f6 a1b2f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2 d3c4 b5a6 f1e2185[.]220[.]101[.]xx45[.]153[.]240[.]xx
NOTE › Full machine-readable IOC list (domains, SHA256 hashes, IPs, KEV CVEs) is attached separately as ioc-latest.txt for import into SIEM / blocklist tooling. IP indicators in pattern form: confirm the final octet against your own telemetry.
[ OK ] Generated by Walternate · CRON: cyber-briefing
· 2026-09-03 12:15 UTC
Download Indicators of Compromise (IOC)
For SOC/NOC ingestion, threat intelligence platforms, and SIEM integration.
