Cyber Security
CVE Vulnerability Alerts
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks
Andrew Doyle
September 2, 2026
Russian-speaking Aurora ransomware group leveraged Cursor AI coding assistant to conduct hands-on exploitation against 10 targets between April and May 2026.
Application Security
Five Critical WordPress Flaws Enable Site Takeover and RCE
Andrew Doyle
September 2, 2026
Five critical vulnerabilities in WPMU DEV Dashboard, Avada Theme, TranslatePress, Pods, and GiveWP allow authentication bypass, privilege escalation, and RCE.
Application Security
Anthropic Warns Infostealer Malware Hijacking Claude Sessions
Mitchell Langley
September 2, 2026
Anthropic warns Vidar, Lumma, StealC, RedLine, and AMOS malware are stealing Claude session tokens, enabling attackers to drain user credits fraudulently.
Cybersecurity
Boston Scientific Cyberattack Disrupts Manufacturing and Shipping
Gabby Lee
September 2, 2026
August 25 cyberattack hit Boston Scientific's on-premises IT, disrupting manufacturing, order processing, and some cardiac monitor remote activations.
CVE Vulnerability Alerts
FulcrumSec Claims 86GB Manchester Airports Data Breach
Mitchell Langley
September 1, 2026
FulcrumSec claims theft of 86 gigabytes from Manchester Airports Group, exposing booking data for 8.7 million customers from a third-party database breach.
Application Security
PaperCut Zero-Days Under Active Exploit Despite Two Patches
Andrew Doyle
September 1, 2026
CVE-2026-81578 and CVE-2026-82078 allow unauthenticated RCE on PaperCut NG/MF versions 24-26; WatchTowr found patch bypasses forcing second emergency patch.
Application Security
McKesson Breach: ShinyHunters Demands $55M for 284M Records
Gabby Lee
September 1, 2026
ShinyHunters demands $55 million for 284 million McKesson records containing PHI, prescriptions, and billing data; threatens release by September 1.
Cybersecurity
Slovenian Casino Operator Hit Resumes After Three-Day Shutdown
Gabby Lee
September 1, 2026
Hit casino operator reopened six Slovenian and Bosnian casinos after a three-day cyberattack shutdown, with gaming functions and loyalty systems still offline.
Application Security
Hasbro Data Breach Exposed 436+ Employee Records
Gabby Lee
September 1, 2026
Hasbro disclosed breach affecting 436+ Massachusetts employees, exposing names, national IDs, and financial data, tied to late March cyberattack.
Cybersecurity
Berlin Refuses Rhysida Ransom as Group Claims 5.7TB Data Theft
Andrew Doyle
September 1, 2026
Rhysida ransomware group demanded 30 bitcoin for 5.7 terabytes of Berlin state data, but Governing Mayor Kai Wegner flatly refused to negotiate or pay.
CVE Vulnerability Alerts
Two Nigerians Extradited to US for Sextortion That Killed Two Teens
Gabby Lee
September 1, 2026
Adebola Adekunle and Mudasiru Olawale were extradited from Nigeria on August 31 to face charges in sextortion schemes that killed two U.S. teens.
Application Security
Judge Rules Pentagon Actions Against Anthropic Unlawful
Gabby Lee
September 1, 2026
U.S. District Judge Rita Lin ruled Pentagon
Application Security
AI Research Org METR Loses $600K in Credits to Dual Breach Attacks
Mitchell Langley
September 1, 2026
METR disclosed two incidents where attackers stole API keys and consumed $600,000 in AI credits through fail-open authentication and targeted probing.
CVE Vulnerability Alerts
Russia-Aligned UAC-0099 Embeds Nuclear Weapon Text to Evade AI Tools
Andrew Doyle
September 1, 2026
Russian threat actor UAC-0099 deployed GuardBreaker technique, inserting safety-sensitive phrases into malware to trip AI security analysis mechanisms.
Application Security
360 Attacks Target Langflow and Rails Flaws Within 72 Hours
Andrew Doyle
September 1, 2026
VulnCheck recorded 360 exploitation attempts targeting CVE-2026-0768 in Langflow and Rails KindaRails2Shell CVE-2026-66066 within 72 hours of disclosure.
Cybersecurity
Five Venezuelan Nationals Plead Guilty to Kansas ATM Jackpotting
Gabby Lee
September 1, 2026
Five Venezuelan nationals pleaded guilty to ATM jackpotting conspiracy following December 2025 arrests for Tren de Aragua malware operations in Kansas.
Application Security
Cronos Blockchain Halts Network, Restores State After $74M Exploit
Andrew Doyle
September 1, 2026
Cronos validators halted the blockchain and restored chain state after attacker inflated TONIC token price 100x to borrow $74 million in August 31 exploit.
Application Security
JFrog Artifactory CVE-2026-82329 Exploited Days After Disclosure
Andrew Doyle
September 1, 2026
WatchTowr researchers observed attackers exploiting CVE-2026-82329 to mint admin tokens on JFrog Artifactory instances days after August 28 disclosure.
Application Security
WatchGuard Patches Five Critical RCE Flaws in Fireware and Dimension
Andrew Doyle
September 1, 2026
WatchGuard patched five CVSS 9.3 buffer overflow and privilege escalation flaws enabling unauthenticated remote code execution in Fireware and Dimension.
CVE Vulnerability Alerts
TerminalFix Campaign Uses Reverse Tunnels in ClickFix-Style Attacks
Gabby Lee
September 1, 2026
TerminalFix deploys multistage PowerShell attacks incorporating reverse tunnels into victim networks, using ClickFix social engineering to trick users.
CVE Vulnerability Alerts
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks
Andrew Doyle
September 2, 2026
CVE Vulnerability Alerts
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks
Andrew Doyle
September 2, 2026
CVE Vulnerability Alerts
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks
Andrew Doyle
September 2, 2026
Cybersecurity
Boston Scientific Cyberattack Disrupts Manufacturing and Shipping
Gabby Lee
September 2, 2026
TOP CYBERSECURITY HEADLINES
CVE Vulnerability Alerts
FulcrumSec Claims 86GB Manchester Airports Data Breach
Application Security
PaperCut Zero-Days Under Active Exploit Despite Two Patches
Application Security
McKesson Breach: ShinyHunters Demands $55M for 284M Records
This Week’s Security Spotlight
Application Security
Judge Rules Pentagon Actions Against Anthropic Unlawful
Gabby Lee
September 1, 2026
Application Security
AI Research Org METR Loses $600K in Credits to Dual Breach Attacks
Mitchell Langley
September 1, 2026
Cybersecurity
OpenAI Pauses Astra Work After Evaluation Flags Cyber Capabilities
Andrew Doyle
August 11, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
Boston Scientific Cyberattack Disrupts Manufacturing and Shipping
September 2, 2026
August 25 cyberattack hit Boston Scientific's on-premises IT, disrupting manufacturing, order processing, and some cardiac monitor remote activations.
FulcrumSec Claims 86GB Manchester Airports Data Breach
September 1, 2026
FulcrumSec claims theft of 86 gigabytes from Manchester Airports Group, exposing booking data for 8.7 million customers from a third-party database breach.
PaperCut Zero-Days Under Active Exploit Despite Two Patches
September 1, 2026
CVE-2026-81578 and CVE-2026-82078 allow unauthenticated RCE on PaperCut NG/MF versions 24-26; WatchTowr found patch bypasses forcing second emergency patch.
McKesson Breach: ShinyHunters Demands $55M for 284M Records
September 1, 2026
ShinyHunters demands $55 million for 284 million McKesson records containing PHI, prescriptions, and billing data; threatens release by September 1.
Slovenian Casino Operator Hit Resumes After Three-Day Shutdown
September 1, 2026
Hit casino operator reopened six Slovenian and Bosnian casinos after a three-day cyberattack shutdown, with gaming functions and loyalty systems still offline.
Hasbro Data Breach Exposed 436+ Employee Records
September 1, 2026
Hasbro disclosed breach affecting 436+ Massachusetts employees, exposing names, national IDs, and financial data, tied to late March cyberattack.
Berlin Refuses Rhysida Ransom as Group Claims 5.7TB Data Theft
September 1, 2026
Rhysida ransomware group demanded 30 bitcoin for 5.7 terabytes of Berlin state data, but Governing Mayor Kai Wegner flatly refused to negotiate or pay.
Two Nigerians Extradited to US for Sextortion That Killed Two Teens
September 1, 2026
Adebola Adekunle and Mudasiru Olawale were extradited from Nigeria on August 31 to face charges in sextortion schemes that killed two U.S. teens.
Judge Rules Pentagon Actions Against Anthropic Unlawful
September 1, 2026
U.S. District Judge Rita Lin ruled Pentagon
AI Research Org METR Loses $600K in Credits to Dual Breach Attacks
September 1, 2026
METR disclosed two incidents where attackers stole API keys and consumed $600,000 in AI credits through fail-open authentication and targeted probing.
Russia-Aligned UAC-0099 Embeds Nuclear Weapon Text to Evade AI Tools
September 1, 2026
Russian threat actor UAC-0099 deployed GuardBreaker technique, inserting safety-sensitive phrases into malware to trip AI security analysis mechanisms.
360 Attacks Target Langflow and Rails Flaws Within 72 Hours
September 1, 2026
VulnCheck recorded 360 exploitation attempts targeting CVE-2026-0768 in Langflow and Rails KindaRails2Shell CVE-2026-66066 within 72 hours of disclosure.
Five Venezuelan Nationals Plead Guilty to Kansas ATM Jackpotting
September 1, 2026
Five Venezuelan nationals pleaded guilty to ATM jackpotting conspiracy following December 2025 arrests for Tren de Aragua malware operations in Kansas.
Cronos Blockchain Halts Network, Restores State After $74M Exploit
September 1, 2026
Cronos validators halted the blockchain and restored chain state after attacker inflated TONIC token price 100x to borrow $74 million in August 31 exploit.
JFrog Artifactory CVE-2026-82329 Exploited Days After Disclosure
September 1, 2026
WatchTowr researchers observed attackers exploiting CVE-2026-82329 to mint admin tokens on JFrog Artifactory instances days after August 28 disclosure.
WatchGuard Patches Five Critical RCE Flaws in Fireware and Dimension
September 1, 2026
WatchGuard patched five CVSS 9.3 buffer overflow and privilege escalation flaws enabling unauthenticated remote code execution in Fireware and Dimension.
TerminalFix Campaign Uses Reverse Tunnels in ClickFix-Style Attacks
September 1, 2026
TerminalFix deploys multistage PowerShell attacks incorporating reverse tunnels into victim networks, using ClickFix social engineering to trick users.
SAP Patches Zero-Day in Commerce Cloud Data Hub Adapter
August 12, 2026
CVE-2026-58231 allows unauthenticated remote code execution across SAP Commerce Cloud. The flaw affects the Data Hub Adapter and carries CVSS 10.0 globally.
Gunra Ransomware Exploits Fortinet and Schneider Flaws for MFA Bypass
August 12, 2026
U.S. and South Korean intelligence agencies warn Gunra ransomware exploits Fortinet firewall flaws alongside a previously undocumented MFA bypass technique.
CISA Adds Metabase SQL Injection Zero-Day to KEV With Aug 14 Deadline
August 12, 2026
CISA adds CVE-2026-72898 Metabase SQL injection flaw to KEV, setting an August 14 patch deadline for federal agencies and urging enterprises to update.






















