Week of 31 August to 6 September 2026
249 stories tracked from Monday to Sunday, Coordinated Universal Time (UTC): August 31 to September 06, 2026; +26 vs prior week; 10 Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) additions from Monday to Sunday, UTC: August 31 to September 06, 2026; 164 ransomware leak-site claims observed in tracked feeds (unverified) from Monday to Sunday, UTC: August 31 to September 06, 2026
Monday to Sunday, UTC. Permalink label: 2026-W36.
- vulnerabilities4 sourcesGoogle Releases Chrome Update to Patch Actively Exploited V8 Zero-DaySource ↗
Google released Chrome version 152.0.7977.82 on September 4, 2026, to address 12 vulnerabilities, including a type confusion flaw in the V8 JavaScript engine that is actively exploited in the wild. CVE-2026-85046 carries a CVSS score of 8.8 and enables remote code execution against unpatched browsers.
Grouped: similar headlines and the same Common Vulnerabilities and Exposures (CVE) record (CVE-2026-85046).
- vulnerabilities4 sourcesSonicWall Warns of Actively Exploited Vulnerabilities in SMA1000 AppliancesSource ↗
SonicWall disclosed two actively exploited zero-day vulnerabilities in SMA1000 remote access appliances that attackers chain together to achieve remote code execution. CVE-2026-83548, a critical pre-authentication server-side request forgery flaw in the Appliance Work Place interface (CVSS 10.0), is combined with CVE-2026-83549, a high-severity OS command injection in the Appliance Management Console (CVSS 7.8). The Cybersecurity and Infrastructure Security Agency (CISA) added both to its Known Exploited Vulnerability Catalog, with federal agencies required to patch by September 6, 2026.
Grouped: similar headlines and the same Common Vulnerabilities and Exposures (CVE) records (CVE-2026-83548, CVE-2026-83549).
- vulnerabilities4 sourcesAttackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 ActivitySource ↗
Threat actors are actively exploiting critical vulnerabilities in Langflow and Ruby on Rails to conduct credential-probing and command and control activities. CVE-2026-0768 in Langflow has a CVSS score of 9.8 and allows arbitrary Python code execution as the root user through insufficient input validation. A second critical flaw in Rails, CVE-2026-66066, is also being targeted in the campaign.
Grouped: similar headlines and the same Common Vulnerabilities and Exposures (CVE) record (CVE-2026-0768).
- vulnerabilities3 sourcesAL26-019 - Vulnerabilities impacting Citrix NetScaler ADC and NetScaler Gateway - CVE-2026-19490 and CVE-2026-19489Source ↗
The Canadian Centre for Cyber Security released an alert on September 4, 2026, warning of two vulnerabilities affecting Citrix NetScaler ADC and NetScaler Gateway appliances. CVE-2026-19490 is an authentication bypass affecting SAML Identity Provider (IdP) configurations that allows unauthenticated remote attackers to circumvent authentication controls, while CVE-2026-19489 is a buffer overflow that can cause memory corruption or denial of service. Affected versions include NetScaler ADC and NetScaler Gateway 14.1 prior to 14.1-73.32 and 13.1 prior to 13.1-63.21, with patched versions available from the vendor.
Grouped: similar headlines and the same names (CITRIX ADC, CITRIX GATEWAY, CITRIX NETSCALER ADC).
- vulnerabilities3 sourcesAttackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without CredentialsSource ↗
Threat actors actively exploit CVE-2026-9586, a critical unauthenticated SQL injection flaw in Sangoma Switchvox SMB Edition 8.3 that enables remote code execution without credentials. The vulnerability carries a CVSS score of 9.3 and is tracked on the Known Exploited Vulnerabilities (KEV) catalog. Attackers leverage this weakness to deploy reverse shells in enterprise VoIP environments.
Grouped: the same Common Vulnerabilities and Exposures (CVE) record (CVE-2026-9586) and the same names (SANGOMA SWITCHVOX, SANGOMA SWITCHVOX SMB EDITION).
- vulnerabilities31th August – Threat Intelligence ReportSource ↗
A weekly threat intelligence summary covering multiple high-impact incidents, including cyberattacks on Manchester Airports Group affecting 8.7 million customers, the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives, Boston Scientific, and McKesson disclosing a breach of 284 million patient records. The report documents artificial intelligence (AI) threats such as cryptographic context injection bypassing AI assistant safeguards, emergency patches for actively exploited PaperCut vulnerabilities enabling remote code execution, and campaigns by nation-state and cybercriminal groups targeting critical infrastructure and organizations across multiple sectors.
- vulnerabilitiesGoogle security advisory (AV26-883) – Update 1Source ↗
Google released Chrome version 152.0.7977.82 to address vulnerabilities including CVE-2026-85046, which has an 8.8 CVSS score and is being actively exploited in the wild. The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-85046 to its Known Exploited Vulnerabilities (KEV) Database on September 4, 2026.
- vulnerabilitiesNCSC-2026-0341 [1.00] [M/H] Kwetsbaarheden verholpen in Google ChromeSource ↗
Google patched multiple vulnerabilities in Chrome version 152.0.7977.82 affecting DevTools, Network, V8 JavaScript engine, and Transactions Platform on iOS. CVE-2026-85046 has a CVSS score of 8.8 and is publicly exploitable, allowing attackers to execute arbitrary code outside the sandbox, bypass access controls, read out-of-sandbox memory, and compromise web content isolation through specially crafted HTML pages.
- vulnerabilitiesAttackers Exploit PaperCut Flaws to Steal Credentials From Schools and UniversitiesSource ↗
Threat actors are actively exploiting two recently disclosed PaperCut vulnerabilities, an authentication bypass (CVE-2026-81578) and remote code execution (RCE) flaw (CVE-2026-82078), to target schools and universities in the U.S. and Europe. Arctic Wolf's Adversary Research Team observed attackers using the vulnerability chain to execute commands, conduct reconnaissance, and steal credentials from educational institutions.
- vulnerabilitiesCISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto MinersSource ↗
CISA added seven actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog on September 3, 2026, including CVE-2026-83548, a critical server-side request forgery flaw in SonicWall SMA 1000 appliances with a CVSS score of 10.0. Attackers are deploying reverse shells and cryptocurrency miners through these flaws.
| KryBit | 15 claims | +2 vs prior week |
| Qilin | 15 claims | -27 vs prior week |
| INC Ransom | 13 claims | +8 vs prior week |
| Akira | 11 claims | -1 vs prior week |
| Direwolf | 9 claims | +4 vs prior week |
| LockBit | 9 claims | +3 vs prior week |
| The Gentlemen | 9 claims | -12 vs prior week |
| Braincipher | 8 claims | +8 vs prior week |
| Silentransomgroup | 8 claims | -2 vs prior week |
| Storm | 8 claims | +4 vs prior week |
Leak-site claim data is unverified: RansomLook (CC BY 4.0).
- French Police Arrest Suspected ZeroBytes Hacker Over Tax Data TheftArrest · DataBreaches.net
French police arrested an 18-year-old man in August on suspicion of membership in ZeroBytes, a hacking collective linked to intrusions against French government agencies and private organizations. The Paris prosecutor's office made the case public in early September. The suspect faced formal charges connected to theft of tax data.
- U.S. and UK Launch First-of-Its-Kind Joint Alliance to Dismantle Global Scam CentersDisruption · U.S. Department of Justice
The U.S. Attorney’s Office for the District of Columbia, together with the Crown Prosecution Service of England & Wales and the National Crime Agency of the United Kingdom announced today the signing of a Memorandum of Understanding (MOU) between the Scam Center Strike Force and its United Kingdom counterparts. The MOU is the first-of-its kind related to international cooperation on disabling scam centers committing cryptocurrency and cyber-enabled investment fraud (CIF) and other schemes, which are ravaging the American people of approximately $10 billion in losses per year.
- Dogged Russia-based botnet dismantled after 23-year runSeizure · Takedown · Disruption · CyberScoop
Law enforcement, CrowdStrike, and the Shadowserver Foundation dismantled Sality, a Russia-based peer-to-peer botnet that had infected more than 11 million devices. CrowdStrike targeted the botnet's peer list and tricked the network into permanently severing operator access to infected machines, rendering the infrastructure unrecoverable. A coordinated effort involving the FBI, Justice Department, and authorities from Bulgaria, Hungary, Romania, and Europol seized Sality's domains and is working to identify and remediate infected devices.
- Eight Charged in Boone County Cyber Crime Investigation Involving Minors and Sex TraffickingIndictment · U.S. Department of Justice
The United States Attorney’s Office for the Western District of Missouri announced eight prosecutions arising from a proactive investigation by the Boone County Cyber Crimes Taskforce.
- Sality botnet infrastructure dismantled in joint global takedownSeizure · Takedown · Disruption · BleepingComputer
International law enforcement and private sector partners executed a coordinated takedown of Sality botnet infrastructure. The operation targeted the peer-to-peer (P2P) malware network to disrupt its command-and-control capabilities and operational footprint.
- Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware PayloadsTakedown · Disruption · The Hacker News
The U.S. Department of Justice coordinated with authorities in Bulgaria, Hungary, and Romania, along with CrowdStrike and the Shadowserver Foundation, to take down the Sality peer-to-peer (P2P) botnet on August 31, 2026. The operation disrupted the long-running malware infrastructure by turning its own network against it to prevent distribution of new payloads.
- Risky Bulletin: BGP hijack delivers malicious Virtualizor updatesTakedown · Disruption · Risky Business News
A Border Gateway Protocol (BGP) hijack was used to distribute malicious updates to Virtualizor hosting software, marking a sophisticated supply chain attack. The White House announced Project Watershed 250, and Indian authorities disrupted a Telegram-based doxing operation. Compromised Composer packages also delivered malware targeting iOS systems.
- Cops, CrowdStrike disrupt Sality botnet by poisoning the network and diverting into sinkholesSeizure · Disruption · The Register Security
International law enforcement agencies, CrowdStrike, and the Shadowserver Foundation disrupted Sality, a 23-year-old peer-to-peer botnet infecting more than 15,000 machines globally. The operation isolated infected devices by manipulating each bot's peer list, preventing the attacker from delivering malicious payloads and communicating with compromised machines. Over eight years, Sality primarily distributed EggJagger, clipboard-monitoring malware that redirected cryptocurrency transfers to attacker-controlled wallets, netting at least $150,000 in stolen funds.
- Russian National Indicted For Exploiting Online Platform Used For Freelance Employment And Distributing Malware To Thousands Of Victim Users Worldwide For Financial GainIndictment · U.S. Department of Justice
SAN FRANCISCO – A federal grand jury has indicted Searzhudin Tamirlanovich Aktulaev on charges of Conspiracy, Transmission of a Program, Information, Code, and Command to Cause Damage to a Protected Computer, and Aggravated Identity Theft, among other offenses
- Sality Malware Disrupted in International Cyber TakedownTakedown · Disruption · U.S. Department of Justice
The Department of Justice today announced a multinational operation involving actions in the United States, Bulgaria, Hungary, and Romania, in collaboration with private industry partners CrowdStrike and the Shadowserver Foundation, to disrupt the botnet and malware known as Sality and take down its infrastructure.
- Your Security Vendor May Not Be Telling You the Truth About Your MTTD – Here's WhyArrest · ReliaQuest
Many security vendors report Mean Time to Detect (MTTD) by starting the clock after logs are received and processed, rather than from the first observable attacker activity, which inflates detection speed metrics. Accurate MTTD measurement should begin when suspicious or malicious events first occur and end when an alert triggers, giving security leaders a true picture of detection capabilities across their entire stack. Inconsistent MTTD definitions across vendors prevent meaningful performance comparison and obscure real exposure windows that attackers can exploit.
- 31th August – Threat Intelligence ReportDisruption · Check Point Research
A weekly threat intelligence summary covering multiple high-impact incidents, including cyberattacks on Manchester Airports Group affecting 8.7 million customers, the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives, Boston Scientific, and McKesson disclosing a breach of 284 million patient records. The report documents artificial intelligence (AI) threats such as cryptographic context injection bypassing AI assistant safeguards, emergency patches for actively exploited PaperCut vulnerabilities enabling remote code execution, and campaigns by nation-state and cybercriminal groups targeting critical infrastructure and organizations across multiple sectors.
1 more qualifying action on the full feed.
- CVE-2026-83548SonicWall SMA1000 Appliancesdue
- CVE-2026-82329JFrog Artifactorydue
- CVE-2026-49869Kestra Kestra OSSdue
- CVE-2026-9586Sangoma Switchvoxdue
- CVE-2026-83549SonicWall SMA1000 Appliancesdue
- CVE-2026-82078PaperCut NG/MFdue
- CVE-2026-85046Google Chromium V8due
- CVE-2026-48710Kludex Starlettedue
- CVE-2026-81578PaperCut NG/MFdue
- CVE-2026-59822BerriAI LiteLLMdue
- CVE-2026-73570Synacor Zimbra Collaboration Suite (ZCS)EPSS exploit likelihood up 12 percentage points (0.32 now)
- CVE-2026-19490Citrix NetScalerAdded to VulnCheck KEV 2026-09-03
- CVE-2022-22274SonicWall sonicosEPSS exploit likelihood up 18 percentage points (0.76 now)
- CVE-2023-54391Proxmox Virtual EnvironmentAdded to VulnCheck KEV 2026-09-01
- CVE-2026-72898Metabase MetabaseEPSS exploit likelihood up 12 percentage points (0.94 now)
- claimligacancerguate.orgUnverified claim. Claimed by KryBit.
- claimseashellhospital.comUnverified claim. Claimed by KryBit.
- claimuicc.orgUnverified claim. Claimed by KryBit.
- claimtum.com.mxUnverified claim. Claimed by KryBit.
- claimwww.alphaplantes.comUnverified claim. Claimed by KryBit.
- claimreignwoodpark.comUnverified claim. Claimed by KryBit.
- claimorex.co.thUnverified claim. Claimed by KryBit.
- claimamptc.netUnverified claim. Claimed by KryBit.
- claimPhilippine Ports AuthorityUnverified claim. Claimed by Qilin.
- claimBauman Law GroupUnverified claim. Claimed by Qilin.
- claimJouvet SASUnverified claim. Claimed by Qilin.
- claimG&S TechnologiesUnverified claim. Claimed by Qilin.
- claimNolan Consulting GroupUnverified claim. Claimed by Qilin.
- claimColonial HyundaiUnverified claim. Claimed by Qilin.
- claimThe Big TableUnverified claim. Claimed by Qilin.
- claimAP CAPITAL PARTNERS LIMITEDUnverified claim. Claimed by Qilin.
- claimmyglobal.comUnverified claim. Claimed by INC Ransom.
- claimAsfaltos y Pavimentos S.A. (Asfalpasa)Unverified claim. Claimed by INC Ransom.
- claimWestfield Public School DistrictUnverified claim. Claimed by INC Ransom.
- claimTruckaUnverified claim. Claimed by INC Ransom.
Ransomware claim data is unverified: RansomLook (CC BY 4.0), with ransomware.live as a voluntarily credited failover.