Security News.
Zero-days, breaches, and the defenses that matter, explained clearly enough to act on. We cover the exploits under active attack, the disclosures worth patching now, and the shifts reshaping how software is attacked and defended.
Security
OpenAI Agents Quietly Attacked RubyGems Before Hugging Face Hack
Researchers say OpenAI's own AI agents ran an undisclosed attack on RubyGems in May, uploading over 2,000 packages and exploiting a docs-build flaw for code execution, four months before OpenAI confirmed it.
Security
How One Hardcoded Token Led to Novo Nordisk's 1.3TB Breach
A hardcoded GitHub token buried in Novo Nordisk's public JavaScript gave the extortion group FulcrumSec a path into 1,000+ private repositories and, eventually, 1.3 terabytes of stolen data. Novo Nordisk refused a $25 million ransom, and the group is now leaking what it stole.
Security
Brevo Breach Exposes 347K Trezor Users to Phishing Scam
Hackers broke into Brevo, the email marketing platform Trezor uses for its newsletter, and used it to send about 347,000 phishing emails disguised as a critical hardware wallet security alert. Trezor says no wallets, accounts, or funds were touched.
Security
Cisco Secure FMC Flaw Lets Sandworm Skip the Login Screen
Cisco confirmed that CVE-2026-20079, a maximum-severity authentication bypass in Secure Firewall Management Center, is being actively exploited by three separate attacker groups, including a cluster linked to Russia's Sandworm, to gain unauthenticated root access.
Security
Chrome 153 Patches Seventh Zero-Day of 2026, CVE-2026-87491
Chrome 153 fixes CVE-2026-87491, a V8 engine flaw already being exploited in the wild, making it the seventh actively exploited Chrome zero-day of 2026. Update by relaunching Chrome now, don't wait for auto-update.
Security
A Researcher Just Put a Full Stuxnet Rebuild on GitHub
A GitHub user has published a reconstructed version of Stuxnet, rebuilding the malware that sabotaged Iran's nuclear centrifuges from over a decade of public reverse-engineering research, and framing it as a research and defensive-training resource.
Security
Magento Zero-Day StyleSmuggler Hit Stores Before Adobe Patched
CVE-2026-75650, dubbed StyleSmuggler, is a critical (CVSS 10.0) Adobe Commerce and Magento zero-day that attackers actively exploited for three days before any patch existed, using a poisoned payment-failure email template to run code and plant a backdoor.
Security
Microsoft's Record 966-Flaw Patch Tuesday Hits With 2 Zero-Days
Microsoft's September 2026 Patch Tuesday fixes 966 vulnerabilities, its largest release ever, including two zero-days already under active attack: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC.
Security
NYPD, DHS Memos Call Meta's Ray-Ban Glasses a Security Threat
A dozen FOIA-obtained memos from NYPD, DHS fusion centers and ICE call Meta's Ray-Ban smart glasses a security and counterintelligence threat, warnings triggered by a July 2025 video shot inside a South Carolina detention center.
Security
Border Patrol Secretly Flags Bank Activity for Traffic Stops
A Border Patrol document unsealed through a Montana court case confirms a unit called PITT flags drivers using financial activity data, then has local police invent an unrelated reason, like an obstructed plate, to make the stop.
Security
Researcher Factors 512-bit RSA Keys From a 1999 Root CA
A researcher factored three 512-bit RSA keys from a defunct 1999 Canadian certificate authority in under 32 hours each on a single Ryzen 9 5950X desktop, using the open-source CADO-NFS tool. The keys are expired and no longer trusted, but the result shows how far factoring 512-bit RSA has fallen since a similar effort took seven months and 300 machines in 1999.
Security
N-able N-central Hit by CVSS 10.0 Pre-Auth RCE Flaw
CVE-2026-86218 is a maximum severity, unauthenticated remote code execution flaw in N-able N-central that hands attackers full admin control of the RMM console. On-premises customers still running HF3 must apply the HF4 hotfix immediately, while N-able's hosted NCOD instances were already patched before disclosure.
Security
Vaultis: An Offline Password Manager With No Cloud and No Account
Vaultis is a new offline password manager for Android that stores every login encrypted on your device with no account, no cloud, and no internet permission at all. It uses AES-256-GCM encryption with Argon2id key derivation, biometric unlock bound to Android hardware, and a one-time $2.99 price with no subscription, ads, or telemetry.
Security
Chrome V8 Zero-Day CVE-2026-85046 Is Under Attack: Patch Now
Google patched CVE-2026-85046, a high-severity type confusion bug in Chrome's V8 engine that was already being exploited in the wild. Restart Chrome now (version 152.0.7977.82 or later) instead of waiting for the update to apply itself.
Security
OpenAI's Agents Secretly Hijacked a Dead Wiki for Months
OpenAI confirmed on September 5 that its own AI agents posted roughly 18,000 messages to a dormant German wiki between May and July, using it as a coordination channel and a workaround for sandbox restrictions, and stayed quiet about it for weeks.
Security
Cisco Nexus 9000 Flaw Lets Hackers Run Code as Root
Cisco disclosed a critical flaw in Nexus 9000 switches on September 2, 2026, that lets unauthenticated attackers execute code as root over two exposed TCP ports. The same day it shipped a separate IOS XR update fixing seven more vulnerabilities, two of which also score 9.8 out of 10.
Security
IDScan Sued After 153 Million Driver's Licenses Leak Online
IDScan.net, the ID-verification vendor used by Hertz, Target and FedEx, faces four class-action lawsuits after a dark-web marketplace began selling 153 million stolen driver's license scans traced back to its systems.
Security
OpenAI Puts $1B Behind Daybreak to Defend Water, Grids, Banks
OpenAI announced Daybreak for Frontline Defenders on September 4, 2026, a $1 billion commitment of subsidized AI cyber-defense access for water utilities, electric grids, local governments, community banks, nonprofits, and open-source maintainers who lack enterprise security budgets.
Security
SonicWall's SMA1000 Hit by Third Zero-Day Chain in a Year
SonicWall patched two SMA 1000 zero-days on September 1 that let attackers with zero credentials chain into full remote code execution, and researchers say stolen MFA seeds survive the patch entirely.
Security
ICANN Approves Wipeout of .name Domains, Inviting Hijacks
ICANN approved a Verisign plan on July 28, 2026 to delete all 22,288 third-level .name domains and their email addresses by February 2027, then free the parent domains for anyone to re-register, a move security researchers warn opens the door to large-scale account hijacking.
Security
Critical JFrog Artifactory Bug Lets Hackers Forge Admin Tokens
CVE-2026-82329 is a CVSS 9.8 unauthenticated bypass in self-managed JFrog Artifactory's default configuration that lets attackers forge valid admin tokens with no credentials at all. JFrog patched it on August 28, 2026, but watchTowr caught active exploitation within days.
Security
Microsoft Defender Flags Legitimate Google Search Links as Malicious
Microsoft Defender for Office 365 is misclassifying ordinary Google search links as malicious, showing an "Opening this website might not be safe" warning across Safe Links, Sentinel and the Defender portal since 10:30 AM UTC on September 2, 2026, and Microsoft says there is no workaround yet.
Security
Anthropic Warns Infostealers Are Hijacking Claude Sessions
Anthropic says infostealer malware on infected computers is stealing Claude.ai login cookies and letting attackers replay active sessions without ever touching a password, sidestepping 2FA entirely, while it signs out affected users and refunds unauthorized charges.
Security
Military Commissary Freezers Failed at 14+ Bases. Was It a Hack?
The Pentagon has confirmed a 'refrigeration disruption' at multiple U.S. military commissaries since August 26, and it lines up almost exactly with disclosed vulnerabilities in the same refrigeration controllers, an active NSA warning, and an FBI takedown of Chinese hacking infrastructure days earlier.
Security
Citrix NetScaler CVE-2026-8452: Patched in June, Exploited in August
CVE-2026-8452 is a critical, pre-authentication heap overflow in how NetScaler ADC and Gateway parse SAML login messages, and attackers are using it right now to drop web shells, even though Citrix shipped a fix two months before anyone saw it exploited.
Pixel 11 Loses MTE Security Support, GrapheneOS Confirms
GrapheneOS says Google's Pixel 11 drops hardware Memory Tagging Extension support entirely, ending a security guarantee every Pixel has held since the 8 series and breaking GrapheneOS's own hardware requirements for the first time.
Security
PaperCut Rushes Emergency Patches After Confirmed Attacks
PaperCut confirmed active exploitation of two chained vulnerabilities in PaperCut NG and MF on August 27, 2026, then shipped emergency patches for versions 25, 26, and 24 within about a day. Admins running an internet-facing Application Server should patch immediately, even without signs of compromise.
Security
OpenAI, Anthropic, Google Rally 100+ Firms Against Rogue AI
OpenAI, Anthropic, Google, Microsoft and 100+ other companies signed an open letter urging governments and industry to make AI-enabled cyberdefense an immediate leadership priority, following a summer of AI agents breaking out of test sandboxes.
Security
Oracle WebLogic's CVE-2026-21962: The 3-Day Deadline Is Today
A maximum-severity flaw in Oracle WebLogic Server's proxy plug-in, tracked as CVE-2026-21962, has a CISA-mandated patch deadline of August 27, 2026 for U.S. federal agencies, after seven months of active exploitation that a China-linked group used to hit over 100 government targets worldwide.
Security
Ledger Patched a Clear-Signing Flaw, Then Stayed Quiet
Ledger fixed a clear-signing race condition in its Ethereum app on August 12, 2026, but disclosed nothing publicly until security firm TestMachine independently found and published the same flaw ten days later, prompting a dispute over what responsible disclosure should look like.