{
  "schema_version": 2,
  "issue_date": "2026-09-08",
  "generated_at": "2026-09-08T23:18:08.568Z",
  "insight_context": {
    "schema_version": 2,
    "mode": "current",
    "checked_at": "2026-09-08T23:18:06.974Z",
    "report_date": "2026-09-08",
    "manifest_generated_at": "2026-09-08T21:02:20Z",
    "report_url": "https://ricomanifesto.github.io/SentryInsight/"
  },
  "articles": [
    {
      "id": "reporting-6e80b0fb56bf",
      "title": "Microsoft Plugs Nearly 1,000 Security Holes",
      "link": "https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/",
      "date": "2026-09-08T21:44:22.000Z",
      "source": "Krebs on Security",
      "summary": "Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.",
      "firstSeen": "2026-09-08T23:18:07.859Z"
    },
    {
      "id": "reporting-12654741403d",
      "title": "Patch Tuesday Sets Another Record With 974 CVEs",
      "link": "https://www.darkreading.com/vulnerabilities-threats/patch-tuesday-another-record-974-cves",
      "date": "2026-09-08T21:26:02.000Z",
      "source": "Dark Reading",
      "summary": "Attackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.",
      "firstSeen": "2026-09-08T23:18:07.859Z"
    },
    {
      "id": "reporting-dacffe4f40c9",
      "title": "Attackers Use Multi-Hop Google Redirects for Phishing Campaign",
      "link": "https://www.darkreading.com/cyberattacks-data-breaches/attackers-multi-hop-google-redirects-phishing-campaign",
      "date": "2026-09-08T21:03:46.000Z",
      "source": "Dark Reading",
      "summary": "Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.",
      "firstSeen": "2026-09-08T23:18:07.859Z"
    },
    {
      "id": "reporting-e1327ff1da81",
      "title": "OpenAI Agents Took Over Wiki Site Before Hugging Face Attack",
      "link": "https://www.darkreading.com/cyberattacks-data-breaches/openai-agents-wiki-site-hugging-face-attack",
      "date": "2026-09-08T20:36:15.000Z",
      "source": "Dark Reading",
      "summary": "Researchers and OpenAI disagree on whether the earlier incident involving DseWiki was a “hack” that the company did not disclose.",
      "firstSeen": "2026-09-08T23:18:07.859Z"
    },
    {
      "id": "reporting-44a5bf98b92e",
      "title": "DoppelCart fraud network uses 119,000 fake shops to steal credit cards",
      "link": "https://www.bleepingcomputer.com/news/security/doppelcart-fraud-network-uses-119-000-fake-shops-to-steal-credit-cards/",
      "date": "2026-09-08T20:35:14.000Z",
      "source": "Bleeping Computer",
      "summary": "A massive operation dubbed \"DoppelCart\" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details…",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-c5c4aee36770",
      "title": "The EU CRA's Real Question: What Shipped, and When Did You Know?",
      "link": "https://www.bleepingcomputer.com/news/security/the-eu-cras-real-question-what-shipped-and-when-did-you-know/",
      "date": "2026-09-08T20:24:16.000Z",
      "source": "Bleeping Computer",
      "summary": "The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements…",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-11f562db786d",
      "title": "Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit",
      "link": "https://www.bleepingcomputer.com/news/security/hackers-breach-f5-big-ip-apm-devices-to-deploy-linux-rootkit/",
      "date": "2026-09-08T20:08:55.000Z",
      "source": "Bleeping Computer",
      "summary": "A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk…",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-a9d06ef94cc0",
      "title": "Microsoft releases Windows 10 KB5122878 extended security update",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-windows-10-kb5122878-extended-security-update/",
      "date": "2026-09-08T18:49:19.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes…",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-983d80461afe",
      "title": "Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-patch-tuesday-fixes-966-flaws-2-zero-days/",
      "date": "2026-09-08T18:18:05.000Z",
      "source": "Bleeping Computer",
      "summary": "Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities…",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-ba85b5be00d0",
      "title": "Windows 11 cumulative updates KB5124008 & KB5122880 released",
      "link": "https://www.bleepingcomputer.com/news/microsoft/windows-11-cumulative-updates-kb5124008-and-kb5122880-released/",
      "date": "2026-09-08T17:57:03.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features…",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-c529667c7a8f",
      "title": "ClickFix Campaigns Abuse Legitimate Services for Persistent Access",
      "link": "https://www.darkreading.com/endpoint-security/clickfix-campaigns-legitimate-services-persistent-access",
      "date": "2026-09-08T17:25:37.000Z",
      "source": "Dark Reading",
      "summary": "Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-3e128c49a676",
      "title": "ShinyHunters hackers claim breach of Florida \"DAVID\" DMV database",
      "link": "https://www.bleepingcomputer.com/news/security/shinyhunters-hackers-claim-breach-of-florida-david-dmv-database/",
      "date": "2026-09-08T16:35:47.000Z",
      "source": "Bleeping Computer",
      "summary": "The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as \"DAVID\" and stole over 200,000 records about drivers in the state…",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-6f67d45fa1d4",
      "title": "OpenAI says ChatGPT outage causes image generation errors",
      "link": "https://www.bleepingcomputer.com/news/technology/openai-says-chatgpt-outage-causes-image-generation-errors/",
      "date": "2026-09-08T16:28:42.000Z",
      "source": "Bleeping Computer",
      "summary": "OpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays when uploading files…",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-08a6dd084273",
      "title": "Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution",
      "link": "https://thehackernews.com/2026/09/slim-spider-steals-crypto-custody.html",
      "date": "2026-09-08T16:20:23.000Z",
      "source": "The Hacker News",
      "summary": "A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. \"The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment…",
      "firstSeen": "2026-09-08T20:57:02.729Z"
    },
    {
      "id": "reporting-ee826c08186e",
      "title": "August updates trigger 0xc0000409 errors on Windows Server 2016",
      "link": "https://www.bleepingcomputer.com/news/microsoft/august-updates-trigger-0xc0000409-errors-on-windows-server-2016/",
      "date": "2026-09-08T15:22:33.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-4e7dbf133d9c",
      "title": "SAP warns of maximum severity 'OVERPASS' kernel vulnerability",
      "link": "https://www.bleepingcomputer.com/news/security/sap-warns-of-maximum-severity-overpass-kernel-vulnerability/",
      "date": "2026-09-08T14:55:20.000Z",
      "source": "Bleeping Computer",
      "summary": "SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-a714f833a627",
      "title": "Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC",
      "link": "https://thehackernews.com/2026/09/liquid-hackers-return-3400-bitcoin.html",
      "date": "2026-09-08T14:54:30.000Z",
      "source": "The Hacker News",
      "summary": "Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds real bitcoin to back a token called L-BTC. The network is still paused, so holders cannot turn that token back into bitcoin. The 3,400 bitcoin was sent to a&…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-a96d08506a53",
      "title": "OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor",
      "link": "https://www.bleepingcomputer.com/news/artificial-intelligence/openai-says-gpt-6-astra-can-find-zero-days-but-is-also-harder-to-monitor/",
      "date": "2026-09-08T14:40:32.000Z",
      "source": "Bleeping Computer",
      "summary": "OpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the \"Critical level\" for cybersecurity capabilities…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-7233e2d9b1b1",
      "title": "ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account",
      "link": "https://thehackernews.com/2026/09/chatgpt-flaw-let-planted-prompt-send.html",
      "date": "2026-09-08T14:19:17.000Z",
      "source": "The Hacker News",
      "summary": "Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-c096727d1fae",
      "title": "Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours",
      "link": "https://thehackernews.com/2026/09/autonomous-ai-agents-compromise.html",
      "date": "2026-09-08T13:48:16.000Z",
      "source": "The Hacker News",
      "summary": "Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-7cfb420aff10",
      "title": "Adobe fixes critical Magento zero-day exploited to backdoor servers",
      "link": "https://www.bleepingcomputer.com/news/security/adobe-fixes-critical-magento-zero-day-exploited-to-backdoor-servers/",
      "date": "2026-09-08T13:34:47.000Z",
      "source": "Bleeping Computer",
      "summary": "Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-4dfc5b9bb611",
      "title": "Webinar: The forgotten Google Workspace access that can lead to a breach",
      "link": "https://www.bleepingcomputer.com/news/security/webinar-the-forgotten-google-workspace-access-that-can-lead-to-a-breach/",
      "date": "2026-09-08T12:40:48.000Z",
      "source": "Bleeping Computer",
      "summary": "Third-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches and which security controls can help fast-growing companies reduce their exposure…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-6c7e13172b77",
      "title": "Hackers build AI frameworks for widescale credential theft",
      "link": "https://www.bleepingcomputer.com/news/security/hackers-build-ai-frameworks-for-widescale-credential-theft/",
      "date": "2026-09-08T12:03:03.000Z",
      "source": "Bleeping Computer",
      "summary": "Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-457b9d586cea",
      "title": "Microsoft: Windows Server 2025 changes causing app crashes",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-windows-server-2025-changes-may-cause-app-crashes/",
      "date": "2026-09-08T11:57:51.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft warned customers last week that they may experience application crashes on some Windows Server 2025 due to recent memory management changes…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-9d6faaed701d",
      "title": "WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls",
      "link": "https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html",
      "date": "2026-09-08T11:54:29.000Z",
      "source": "The Hacker News",
      "summary": "Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-9f18a97b3fdc",
      "title": "What It Took to Reach 1 Billion Build Manifests",
      "link": "https://thehackernews.com/2026/09/what-it-took-to-reach-1-billion-build.html",
      "date": "2026-09-08T11:49:02.000Z",
      "source": "The Hacker News",
      "summary": "In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually behind them. The number itself is less interesting than the system that produced it, and why we had to fundamentally…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-9af5dfe944e1",
      "title": "FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials",
      "link": "https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html",
      "date": "2026-09-08T11:22:07.000Z",
      "source": "The Hacker News",
      "summary": "A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The…",
      "firstSeen": "2026-09-08T16:22:28.105Z"
    },
    {
      "id": "reporting-2fdb7e232890",
      "title": "Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell",
      "link": "https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html",
      "date": "2026-09-08T09:13:47.000Z",
      "source": "The Hacker News",
      "summary": "Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. \"This update resolves a critical…",
      "firstSeen": "2026-09-08T10:57:29.390Z"
    },
    {
      "id": "reporting-640afb9db3b2",
      "title": "BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams",
      "link": "https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html",
      "date": "2026-09-08T08:43:51.000Z",
      "source": "The Hacker News",
      "summary": "Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect…",
      "firstSeen": "2026-09-08T10:57:29.390Z"
    },
    {
      "id": "reporting-0d6572e08bb4",
      "title": "220 million traveler records exposed in Vietnam-linked APIS leak",
      "link": "https://www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/",
      "date": "2026-09-08T07:35:50.000Z",
      "source": "Bleeping Computer",
      "summary": "Exclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing names, passport numbers, dates of birth, nationalities, and flight details spanning 2017 to 2026. Researchers accessed the Vietnam-linked system through a cloud-based path using default credentials…",
      "firstSeen": "2026-09-08T10:57:29.390Z"
    },
    {
      "id": "reporting-86a44f9f81c5",
      "title": "Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing",
      "link": "https://thehackernews.com/2026/09/grindr-to-pay-26-million-to-settle-uk.html",
      "date": "2026-09-08T07:00:43.000Z",
      "source": "The Hacker News",
      "summary": "Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with third-parties. Grindr, which is the largest LGBTQ+ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising.",
      "firstSeen": "2026-09-08T10:57:29.390Z"
    },
    {
      "id": "reporting-6c94379fcb16",
      "title": "PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution",
      "link": "https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html",
      "date": "2026-09-07T18:12:09.000Z",
      "source": "The Hacker News",
      "summary": "Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. \"Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences…",
      "firstSeen": "2026-09-07T19:03:14.294Z"
    },
    {
      "id": "reporting-9dd82c8cbcbd",
      "title": "Magento StyleSmuggler zero-day exploited to deploy Linux backdoor",
      "link": "https://www.bleepingcomputer.com/news/security/magento-stylesmuggler-zero-day-exploited-to-deploy-linux-backdoor/",
      "date": "2026-09-07T16:50:29.000Z",
      "source": "Bleeping Computer",
      "summary": "A zero-day vulnerability dubbed \"StyleSmuggler\" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor…",
      "firstSeen": "2026-09-07T19:03:14.294Z"
    },
    {
      "id": "reporting-9c92a7066f1f",
      "title": "Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks",
      "link": "https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html",
      "date": "2026-09-07T15:51:56.000Z",
      "source": "The Hacker News",
      "summary": "Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff…",
      "firstSeen": "2026-09-07T19:03:14.294Z"
    },
    {
      "id": "reporting-71696e8a5894",
      "title": "BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations",
      "link": "https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/",
      "date": "2026-09-07T15:39:51.000Z",
      "source": "Bleeping Computer",
      "summary": "A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials…",
      "firstSeen": "2026-09-07T19:03:14.294Z"
    },
    {
      "id": "reporting-24d56919cba7",
      "title": "⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More",
      "link": "https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html",
      "date": "2026-09-07T14:36:07.000Z",
      "source": "The Hacker News",
      "summary": "Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management…",
      "firstSeen": "2026-09-07T19:03:14.294Z"
    },
    {
      "id": "reporting-c4d7fdfa6754",
      "title": "Mathspace discloses data breach affecting over 1 million people",
      "link": "https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/",
      "date": "2026-09-07T13:05:11.000Z",
      "source": "Bleeping Computer",
      "summary": "Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system…",
      "firstSeen": "2026-09-07T19:03:14.294Z"
    },
    {
      "id": "reporting-93b61032b3b3",
      "title": "Trezor data breach impact now reaches 81,000 customers",
      "link": "https://www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/",
      "date": "2026-09-07T12:16:32.000Z",
      "source": "Bleeping Computer",
      "summary": "Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers…",
      "firstSeen": "2026-09-07T19:03:14.294Z"
    },
    {
      "id": "reporting-c09a5ec87b1f",
      "title": "Your Cloud Security Checklist Doesn't Work the Way You Think It Does",
      "link": "https://thehackernews.com/2026/09/your-cloud-security-checklist-doesnt.html",
      "date": "2026-09-07T11:45:00.000Z",
      "source": "The Hacker News",
      "summary": "If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Here’s what the data looks like. How risk differs across cloud providers…",
      "firstSeen": "2026-09-07T19:03:14.294Z"
    },
    {
      "id": "reporting-3fabea4df5b3",
      "title": "Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts",
      "link": "https://thehackernews.com/2026/09/rogue-screenconnect-clients-spread-four.html",
      "date": "2026-09-07T11:36:39.000Z",
      "source": "The Hacker News",
      "summary": "Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake…",
      "firstSeen": "2026-09-07T19:03:14.294Z"
    },
    {
      "id": "reporting-ff2a8ecee2aa",
      "title": "Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released",
      "link": "https://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html",
      "date": "2026-09-07T11:20:14.000Z",
      "source": "The Hacker News",
      "summary": "A TantoSec proof-of-concept turns an AES-CBC \"padding oracle\" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities…",
      "firstSeen": "2026-09-07T19:03:14.294Z"
    },
    {
      "id": "reporting-210b28ee4697",
      "title": "ChatGPT can now connect to your personal apps to mimic writing style",
      "link": "https://www.bleepingcomputer.com/news/artificial-intelligence/chatgpt-can-now-connect-to-your-personal-apps-to-mimic-writing-style/",
      "date": "2026-09-07T10:36:37.000Z",
      "source": "Bleeping Computer",
      "summary": "OpenAI appears to be testing a new \"Writing Style\" feature for ChatGPT that can learn how you write by looking at examples from your connected apps…",
      "firstSeen": "2026-09-07T12:04:10.636Z"
    },
    {
      "id": "reporting-23a72d6695c4",
      "title": "Hackers exploit new MikroTik RouterOS flaws to hijack routers",
      "link": "https://www.bleepingcomputer.com/news/security/hackers-exploit-new-mikrotik-routeros-flaws-to-hijack-routers/",
      "date": "2026-09-07T10:32:40.000Z",
      "source": "Bleeping Computer",
      "summary": "Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet…",
      "firstSeen": "2026-09-07T12:04:10.636Z"
    },
    {
      "id": "reporting-7d32c779b299",
      "title": "ConnectWise warns of new ScreenConnect flaw without patch",
      "link": "https://www.bleepingcomputer.com/news/security/connectwise-warns-of-new-screenconnect-flaw-without-patch/",
      "date": "2026-09-07T10:06:38.000Z",
      "source": "Bleeping Computer",
      "summary": "ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week…",
      "firstSeen": "2026-09-07T12:04:10.636Z"
    },
    {
      "id": "reporting-d35595c1e92d",
      "title": "N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw",
      "link": "https://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html",
      "date": "2026-09-07T08:31:12.000Z",
      "source": "The Hacker News",
      "summary": "Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a…",
      "firstSeen": "2026-09-07T12:04:10.636Z"
    },
    {
      "id": "reporting-459bb4835d23",
      "title": "JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies",
      "link": "https://thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html",
      "date": "2026-09-07T07:53:04.000Z",
      "source": "The Hacker News",
      "summary": "Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. \"The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers,\" Check Point Research said in a…",
      "firstSeen": "2026-09-07T12:04:10.636Z"
    },
    {
      "id": "reporting-4a81effbff68",
      "title": "N-able patches max severity N-central flaw amid ongoing attacks",
      "link": "https://www.bleepingcomputer.com/news/security/n-able-patches-max-severity-n-central-flaw-amid-ongoing-attacks/",
      "date": "2026-09-07T06:17:41.000Z",
      "source": "Bleeping Computer",
      "summary": "N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform…",
      "firstSeen": "2026-09-07T12:04:10.636Z"
    },
    {
      "id": "reporting-a1bdcc187807",
      "title": "ChatGPT Astra is now rolling out to $20 Plus subscription",
      "link": "https://www.bleepingcomputer.com/news/artificial-intelligence/chatgpt-astra-is-now-rolling-out-to-20-plus-subscription/",
      "date": "2026-09-07T01:15:43.000Z",
      "source": "Bleeping Computer",
      "summary": "OpenAI is now rolling out ChatGPT Astra, its most powerful model to date, to those with a $20 Plus subscription, but there's no word on when free users will get access…",
      "firstSeen": "2026-09-07T03:53:32.859Z"
    },
    {
      "id": "reporting-bc441f97e571",
      "title": "Attackers conceal phishing lures using invisible Unicode characters",
      "link": "https://www.bleepingcomputer.com/news/security/attackers-conceal-phishing-lures-using-invisible-unicode-characters/",
      "date": "2026-09-06T14:23:46.000Z",
      "source": "Bleeping Computer",
      "summary": "Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters…",
      "firstSeen": "2026-09-06T15:15:04.374Z"
    },
    {
      "id": "reporting-bec3d4c719cb",
      "title": "Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication",
      "link": "https://thehackernews.com/2026/09/attackers-hijack-mikrotik-routers.html",
      "date": "2026-09-06T09:32:38.000Z",
      "source": "The Hacker News",
      "summary": "Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5. Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or…",
      "firstSeen": "2026-09-06T10:38:03.059Z"
    },
    {
      "id": "reporting-1a8ef3d227d4",
      "title": "Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner",
      "link": "https://thehackernews.com/2026/09/four-revstealer-linked-modules-disable.html",
      "date": "2026-09-06T08:34:20.000Z",
      "source": "The Hacker News",
      "summary": "Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and…",
      "firstSeen": "2026-09-06T10:38:03.059Z"
    },
    {
      "id": "reporting-9eeec10be375",
      "title": "Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores",
      "link": "https://thehackernews.com/2026/09/unpatched-magento-and-adobe-commerce.html",
      "date": "2026-09-05T20:14:47.000Z",
      "source": "The Hacker News",
      "summary": "Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. \"Sansec is…",
      "firstSeen": "2026-09-05T22:43:37.047Z"
    },
    {
      "id": "reporting-913cdf66682b",
      "title": "Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials",
      "link": "https://thehackernews.com/2026/09/attackers-breached-jetbrains-cadence.html",
      "date": "2026-09-05T16:52:33.000Z",
      "source": "The Hacker News",
      "summary": "JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. \"Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions,\" JetBrains said.",
      "firstSeen": "2026-09-05T17:13:46.205Z"
    },
    {
      "id": "reporting-e74c4bc78631",
      "title": "Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code",
      "link": "https://thehackernews.com/2026/09/critical-vmware-workstation-and-fusion.html",
      "date": "2026-09-05T16:05:08.000Z",
      "source": "The Hacker News",
      "summary": "Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. \"A…",
      "firstSeen": "2026-09-05T17:13:46.205Z"
    },
    {
      "id": "reporting-1305dd241c30",
      "title": "Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain",
      "link": "https://www.bleepingcomputer.com/news/security/over-5-400-hacked-sites-serve-clickfix-payloads-stored-on-the-blockchain/",
      "date": "2026-09-05T14:29:13.000Z",
      "source": "Bleeping Computer",
      "summary": "A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC)…",
      "firstSeen": "2026-09-05T14:54:13.288Z"
    },
    {
      "id": "reporting-28549037149e",
      "title": "Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted",
      "link": "https://thehackernews.com/2026/09/trezor-says-shipmonk-breach-exposed.html",
      "date": "2026-09-05T14:17:02.000Z",
      "source": "The Hacker News",
      "summary": "Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets…",
      "firstSeen": "2026-09-05T17:13:46.205Z"
    },
    {
      "id": "reporting-1503c662885b",
      "title": "OpenAI admits it didn't disclose rogue AI wiki hijacking incident",
      "link": "https://www.bleepingcomputer.com/news/security/openai-admits-it-didnt-disclose-rogue-ai-wiki-hijacking-incident/",
      "date": "2026-09-05T11:11:50.000Z",
      "source": "Bleeping Computer",
      "summary": "OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model \"misalignment\" rather than a security breach…",
      "firstSeen": "2026-09-05T14:54:13.288Z"
    },
    {
      "id": "reporting-1c98993ec175",
      "title": "Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel",
      "link": "https://thehackernews.com/2026/09/thousands-of-openai-agents-quietly.html",
      "date": "2026-09-05T07:55:10.000Z",
      "source": "The Hacker News",
      "summary": "A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs…",
      "firstSeen": "2026-09-05T10:18:23.257Z"
    },
    {
      "id": "reporting-c08f05268e88",
      "title": "Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities",
      "link": "https://thehackernews.com/2026/09/attackers-exploit-papercut-flaws-to.html",
      "date": "2026-09-05T07:31:53.000Z",
      "source": "The Hacker News",
      "summary": "Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as…",
      "firstSeen": "2026-09-05T10:18:23.257Z"
    }
  ]
}
