{
  "schema_version": 2,
  "issue_date": "2026-09-04",
  "generated_at": "2026-09-04T22:56:26.325Z",
  "insight_context": {
    "schema_version": 2,
    "mode": "current",
    "checked_at": "2026-09-04T22:56:25.151Z",
    "report_date": "2026-09-04",
    "manifest_generated_at": "2026-09-04T04:01:45Z",
    "report_url": "https://ricomanifesto.github.io/SentryInsight/"
  },
  "articles": [
    {
      "id": "reporting-5c7b6ad938ba",
      "title": "IDScan sued over alleged data breach affecting 153 million drivers",
      "link": "https://www.bleepingcomputer.com/news/security/idscan-sued-over-alleged-data-breach-affecting-153-million-drivers/",
      "date": "2026-09-04T16:56:45.000Z",
      "source": "Bleeping Computer",
      "summary": "Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses…",
      "firstSeen": "2026-09-04T20:34:21.553Z"
    },
    {
      "id": "reporting-6b5b7c851b25",
      "title": "Companies Have 6 Months to Prepare for Automated Attacks",
      "link": "https://www.darkreading.com/cybersecurity-operations/companies-six-months-prepare-automated-attacks",
      "date": "2026-09-04T15:57:31.000Z",
      "source": "Dark Reading",
      "summary": "Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but the situation will become more urgent very soon.",
      "firstSeen": "2026-09-04T20:34:21.553Z"
    },
    {
      "id": "reporting-ffe72a79b189",
      "title": "Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters",
      "link": "https://thehackernews.com/2026/09/phishing-campaign-sends-millions-of.html",
      "date": "2026-09-04T15:57:15.000Z",
      "source": "The Hacker News",
      "summary": "Microsoft is alerting of a \"high-volume phishing campaign\" that's using invisible Unicode tag characters to bypass email filters. \"Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them,\" the Microsoft Security Research team said. The…",
      "firstSeen": "2026-09-04T20:34:21.553Z"
    },
    {
      "id": "reporting-7483ae5401bd",
      "title": "Critical Citrix NetScaler auth bypass now leveraged in attacks",
      "link": "https://www.bleepingcomputer.com/news/security/hackers-target-critical-citrix-netscaler-auth-bypass-in-attacks/",
      "date": "2026-09-04T15:25:59.000Z",
      "source": "Bleeping Computer",
      "summary": "Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian…",
      "firstSeen": "2026-09-04T16:04:21.129Z"
    },
    {
      "id": "reporting-d7ed15b40cfe",
      "title": "PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution",
      "link": "https://thehackernews.com/2026/09/postgresql-fixes-12-year-old-logical.html",
      "date": "2026-09-04T15:20:19.000Z",
      "source": "The Hacker News",
      "summary": "PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are…",
      "firstSeen": "2026-09-04T20:34:21.553Z"
    },
    {
      "id": "reporting-b1ea25ffc370",
      "title": "New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic",
      "link": "https://thehackernews.com/2026/09/new-ted-backdoor-hides-inside-victims.html",
      "date": "2026-09-04T14:51:13.000Z",
      "source": "The Hacker News",
      "summary": "A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and…",
      "firstSeen": "2026-09-04T16:04:21.129Z"
    },
    {
      "id": "reporting-fface7014a8e",
      "title": "Microsoft says some users can’t open the Teams desktop client",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-says-some-users-cant-open-the-teams-desktop-client/",
      "date": "2026-09-04T14:30:15.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems…",
      "firstSeen": "2026-09-04T16:04:21.129Z"
    },
    {
      "id": "reporting-a1caa1ba3e69",
      "title": "39 New Methods That Compromise Passkey Authentication",
      "link": "https://www.bleepingcomputer.com/news/security/39-new-methods-that-compromise-passkey-authentication/",
      "date": "2026-09-04T14:01:11.000Z",
      "source": "Bleeping Computer",
      "summary": "Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography…",
      "firstSeen": "2026-09-04T16:04:21.129Z"
    },
    {
      "id": "reporting-beea4dd696f2",
      "title": "New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges",
      "link": "https://www.bleepingcomputer.com/news/security/new-crowdstrike-falconflank-zero-day-grants-system-privileges/",
      "date": "2026-09-04T13:22:01.000Z",
      "source": "Bleeping Computer",
      "summary": "An anonymous security researcher who uses the \"Nightmare Eclipse\" handle released a CrowdStrike Falcon zero-day exploit named \"FalconFlank\" that lets attackers escalate privileges on up-to-date Windows systems…",
      "firstSeen": "2026-09-04T16:04:21.129Z"
    },
    {
      "id": "reporting-e611d74c39b6",
      "title": "AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?",
      "link": "https://www.darkreading.com/vulnerabilities-threats/ai-ending-era-hidden-vulnerabilities-are-vendors-ready",
      "date": "2026-09-04T13:00:00.000Z",
      "source": "Dark Reading",
      "summary": "A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.",
      "firstSeen": "2026-09-04T16:04:21.129Z"
    },
    {
      "id": "reporting-1fc275a61f10",
      "title": "Exchange Online outage causes email delays, 'Server busy' errors",
      "link": "https://www.bleepingcomputer.com/news/microsoft/exchange-online-outage-causes-email-delays-server-busy-errors/",
      "date": "2026-09-04T12:22:30.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains…",
      "firstSeen": "2026-09-04T16:04:21.129Z"
    },
    {
      "id": "reporting-ffe71b2571f9",
      "title": "Insurers Search for Answers to Rein in Rogue AI",
      "link": "https://www.darkreading.com/cyber-risk/insurers-search-answers-rogue-ai",
      "date": "2026-09-04T12:15:03.000Z",
      "source": "Dark Reading",
      "summary": "As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.",
      "firstSeen": "2026-09-04T22:56:25.525Z"
    },
    {
      "id": "reporting-dc2f42c91d09",
      "title": "Google warns of new Chrome zero-day flaw exploited in attacks",
      "link": "https://www.bleepingcomputer.com/news/security/google-warns-of-new-chrome-zero-day-flaw-exploited-in-attacks/",
      "date": "2026-09-04T11:48:17.000Z",
      "source": "Bleeping Computer",
      "summary": "Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities…",
      "firstSeen": "2026-09-04T16:04:21.129Z"
    },
    {
      "id": "reporting-7eb26d7003dc",
      "title": "Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws",
      "link": "https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html",
      "date": "2026-09-04T08:48:45.000Z",
      "source": "The Hacker News",
      "summary": "Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including…",
      "firstSeen": "2026-09-04T11:02:21.932Z"
    },
    {
      "id": "reporting-08f9037c31db",
      "title": "Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws",
      "link": "https://thehackernews.com/2026/09/plex-urges-immediate-updates-after.html",
      "date": "2026-09-04T07:35:14.000Z",
      "source": "The Hacker News",
      "summary": "Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them. \"We recommend all server owners and Desktop users…",
      "firstSeen": "2026-09-04T11:02:21.932Z"
    },
    {
      "id": "reporting-49749711ba07",
      "title": "Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day",
      "link": "https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html",
      "date": "2026-09-04T07:18:47.000Z",
      "source": "The Hacker News",
      "summary": "Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. \"Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote…",
      "firstSeen": "2026-09-04T11:02:21.932Z"
    },
    {
      "id": "reporting-09bf1e9a868f",
      "title": "GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests",
      "link": "https://thehackernews.com/2026/09/gpt-6-astra-scores-100-on-exploitbench.html",
      "date": "2026-09-04T06:47:52.000Z",
      "source": "The Hacker News",
      "summary": "OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the \"world's most intelligent and aligned model.\" The development comes days after the artificial intelligence (AI) company said the model had reached the \"Critical\" cybersecurity capability threshold under its Preparedness Framework. \"Astra is state-of-the-art on computer use, browsing, software engineering…",
      "firstSeen": "2026-09-04T11:02:21.932Z"
    },
    {
      "id": "reporting-0310538b67d5",
      "title": "French hospital fined €500,000 after breach exposes data of 727,000",
      "link": "https://www.bleepingcomputer.com/news/security/french-hospital-fined-500-000-after-breach-exposes-data-of-727-000/",
      "date": "2026-09-03T22:01:37.000Z",
      "source": "Bleeping Computer",
      "summary": "France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients' and their relatives' data…",
      "firstSeen": "2026-09-03T23:08:35.390Z"
    },
    {
      "id": "reporting-b38f4c9e8193",
      "title": "Large Enterprises Targeted in Fake Merger & Acquisition Scams",
      "link": "https://www.darkreading.com/cyberattacks-data-breaches/large-enterprises-fake-merger-acquisition-scams",
      "date": "2026-09-03T20:18:14.000Z",
      "source": "Dark Reading",
      "summary": "Threat actors behind the \"Phantom Deal\" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-25f09ace8141",
      "title": "Coder's registry infrastructure compromised to push malicious modules",
      "link": "https://www.bleepingcomputer.com/news/security/coders-registry-infrastructure-compromised-to-push-malicious-modules/",
      "date": "2026-09-03T20:04:24.000Z",
      "source": "Bleeping Computer",
      "summary": "Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-657cfe30a45c",
      "title": "What We Missed: Did ShinyHunters 'Breach' ReliaQuest?",
      "link": "https://www.darkreading.com/cybersecurity-operations/what-we-missed-did-shinyhunters-breach-reliaquest",
      "date": "2026-09-03T19:42:39.000Z",
      "source": "Dark Reading",
      "summary": "In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-d0cdf0878d94",
      "title": "HPE patches critical ArubaOS-CX remote code execution flaw",
      "link": "https://www.bleepingcomputer.com/news/security/hpe-patches-critical-arubaos-cx-remote-code-execution-flaw/",
      "date": "2026-09-03T18:28:12.000Z",
      "source": "Bleeping Computer",
      "summary": "Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-eae08603ec40",
      "title": "ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories",
      "link": "https://thehackernews.com/2026/09/threatsday-ceo-phishing-kits-5k-dropbox.html",
      "date": "2026-09-03T18:02:47.000Z",
      "source": "The Hacker News",
      "summary": "The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough. There is also…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-9f1cf6b5657f",
      "title": "What the AI Warning Letter Completely Missed",
      "link": "https://www.darkreading.com/cyberattacks-data-breaches/ai-warning-letter-missed-people",
      "date": "2026-09-03T17:23:14.000Z",
      "source": "Dark Reading",
      "summary": "The recent AI warning letter is right about the \"window,\" but it omits naming who is coming through it or, critically, who will close it.",
      "firstSeen": "2026-09-04T20:34:21.553Z"
    },
    {
      "id": "reporting-10869e1cb2f9",
      "title": "Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root",
      "link": "https://thehackernews.com/2026/09/critical-cisco-nexus-9000-flaw-lets.html",
      "date": "2026-09-03T15:52:07.000Z",
      "source": "The Hacker News",
      "summary": "Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-9d9736b815d5",
      "title": "BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory",
      "link": "https://thehackernews.com/2026/09/brazetsu-malware-turns-compromised.html",
      "date": "2026-09-03T15:26:47.000Z",
      "source": "The Hacker News",
      "summary": "Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. \"Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-3ffce2a0f361",
      "title": "Microsoft: KB5120998 mouse reset bug affects only non-English PCs",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-kb5120998-mouse-reset-bug-affects-only-non-english-pcs/",
      "date": "2026-09-03T15:22:33.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-f413fd637fae",
      "title": "OpenAI confirms ChatGPT is down ahead of 'Astra' model launch",
      "link": "https://www.bleepingcomputer.com/news/artificial-intelligence/openai-confirms-chatgpt-is-down-ahead-of-astra-model-launch/",
      "date": "2026-09-03T15:13:29.000Z",
      "source": "Bleeping Computer",
      "summary": "ChatGPT and Codex are experiencing a major outage, with users reporting errors across nearly every major ChatGPT feature…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-e3d842837729",
      "title": "Anthropic confirms Claude is down, multiple models affected",
      "link": "https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-confirms-claude-is-down-multiple-models-affected/",
      "date": "2026-09-03T15:02:52.000Z",
      "source": "Bleeping Computer",
      "summary": "Claude is experiencing an outage, with users encountering elevated errors when sending requests to multiple Anthropic AI models…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-12bd6356b4bc",
      "title": "Critical Elementor Pro flaw exploited to take over WordPress sites",
      "link": "https://www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-exploited-to-take-over-wordpress-sites/",
      "date": "2026-09-03T14:52:20.000Z",
      "source": "Bleeping Computer",
      "summary": "A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-9fe0a5b02090",
      "title": "Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data",
      "link": "https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html",
      "date": "2026-09-03T14:39:05.000Z",
      "source": "The Hacker News",
      "summary": "Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-95772abdc7f4",
      "title": "AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours",
      "link": "https://www.darkreading.com/cyberattacks-data-breaches/ai-machine-speed-2-week-attack-10-hours",
      "date": "2026-09-03T14:38:49.000Z",
      "source": "Dark Reading",
      "summary": "The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers.",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-e41d05713645",
      "title": "Your Employee’s Password Appeared in an Infostealer Log. Now What?",
      "link": "https://www.bleepingcomputer.com/news/security/your-employees-password-appeared-in-an-infostealer-log-now-what/",
      "date": "2026-09-03T13:50:59.000Z",
      "source": "Bleeping Computer",
      "summary": "Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-7779cf691df0",
      "title": "Microsoft says KB5120998 Windows update resets desktop settings",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-says-kb5120998-windows-update-resets-desktop-settings/",
      "date": "2026-09-03T12:16:32.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft has confirmed that desktop settings are lost or reset on some Windows devices after installing the KB5120998 August 2026 preview update…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-1c7b98ba020f",
      "title": "'Breeze Comet' Tears Into Brazilian & Global Financial Systems",
      "link": "https://www.darkreading.com/threat-intelligence/breeze-comet-brazilian-global-financial-systems",
      "date": "2026-09-03T12:00:00.000Z",
      "source": "Dark Reading",
      "summary": "Brazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket.",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-54e49c42f26d",
      "title": "US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries",
      "link": "https://thehackernews.com/2026/09/us-becomes-top-target-in-rmm-phishing.html",
      "date": "2026-09-03T11:58:00.000Z",
      "source": "The Hacker News",
      "summary": "An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-66a18096b023",
      "title": "Plex warns users to patch security vulnerabilities immediately",
      "link": "https://www.bleepingcomputer.com/news/security/plex-warns-users-to-patch-security-vulnerabilities-immediately/",
      "date": "2026-09-03T11:02:22.000Z",
      "source": "Bleeping Computer",
      "summary": "Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-0ffead6ad9f8",
      "title": "Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks",
      "link": "https://thehackernews.com/2026/09/attackers-turn-trusted-nodejs-runtime.html",
      "date": "2026-09-03T10:43:01.000Z",
      "source": "The Hacker News",
      "summary": "Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. \"The technique's appeal is that node.exe (the…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-28b73ab00490",
      "title": "Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means",
      "link": "https://thehackernews.com/2026/09/shai-huluds-reach-just-grew-to-469.html",
      "date": "2026-09-03T10:36:39.000Z",
      "source": "The Hacker News",
      "summary": "In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs. Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-5b6af534cfb2",
      "title": "Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-teams-outlook-fail-to-launch-on-arm-based-windows-pcs/",
      "date": "2026-09-03T08:55:25.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-b6e02e043855",
      "title": "Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone",
      "link": "https://thehackernews.com/2026/09/pegasus-zero-click-spyware-exploit.html",
      "date": "2026-09-03T08:43:17.000Z",
      "source": "The Hacker News",
      "summary": "The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. \"Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware,\" the Citizen Lab said. \"We found high-confidence indicators of…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-21d7fb2ca2b3",
      "title": "Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon",
      "link": "https://thehackernews.com/2026/09/researcher-releases-falconflank-poc.html",
      "date": "2026-09-03T06:26:59.000Z",
      "source": "The Hacker News",
      "summary": "The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a proof-of-concept (PoC) for a privilege escalation flaw impacting Crowdstrike Falcon. \"FalconFlank is a 0-day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor,\" the researcher said in…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-bf0dadca2770",
      "title": "CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners",
      "link": "https://thehackernews.com/2026/09/cisa-adds-seven-exploited-flaws-as.html",
      "date": "2026-09-03T05:19:04.000Z",
      "source": "The Hacker News",
      "summary": "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows - CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-013d5372927c",
      "title": "AI's Vulnerability Surge May Be More Manageable Than First Feared",
      "link": "https://www.darkreading.com/application-security/ai-vulnerability-surge-manageable-than-first-feared",
      "date": "2026-09-02T21:14:06.000Z",
      "source": "Dark Reading",
      "summary": "New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-b6a094e0db0f",
      "title": "Hackers exploit Sangoma Switchvox flaw to deploy reverse shells",
      "link": "https://www.bleepingcomputer.com/news/security/hackers-exploit-sangoma-switchvox-flaw-to-deploy-reverse-shells/",
      "date": "2026-09-02T21:00:13.000Z",
      "source": "Bleeping Computer",
      "summary": "Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution…",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    },
    {
      "id": "reporting-1ae2c66d0e1d",
      "title": "SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE",
      "link": "https://www.darkreading.com/vulnerabilities-threats/sonicwall-sma-1000-zero-days-unauthenticated-rce",
      "date": "2026-09-02T20:43:59.000Z",
      "source": "Dark Reading",
      "summary": "The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.",
      "firstSeen": "2026-09-03T20:47:03.143Z"
    }
  ]
}
