Latest cyber news, threats, security, and guidelines. Stack up.

Vulnerabilities

Thu 3 Sep

CrowdStrike Falcon: FalconFlank local privilege-escalation demo; vendor investigating

The Hacker News (3 September 2026) reports researcher Chaotic Eclipse published FalconFlank, a public local privilege-escalation exploit demo that abuses CrowdStrike Falcon Sensor’s Office malicious-macros remediation path on fully updated Windows 11 25H2 and Windows Server 2025. The researcher said Falcon may already detect the demo code and that lab checks may need exclusions or obfuscation. A CrowdStrike spokesperson told THN the company is investigating, advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting, said customers remain protected through Cloud Anti-malware for Microsoft Office Files, and pointed operators to the FalconFlank Tech Alert in the CrowdStrike support portal. Review the portal alert, apply CrowdStrike guidance, and treat the public exploit code as high-signal for endpoint labs.

The Hacker News (3 Sep 2026)

vulnerabilities identity

Vulnerabilities

Thu 3 Sep

HPE ArubaOS-CX: critical unauth RCE (CVE-2026-73749) plus high-severity management flaws

BleepingComputer (3 September 2026) reports Hewlett Packard Enterprise patched a critical buffer-overflow remote code execution issue in ArubaOS-CX, tracked as CVE-2026-73749: an unauthenticated remote attacker can send crafted packets to an affected daemon and execute code with elevated privileges. HPE security bulletin hpesbnw05134en_us lists fixed builds by branch: 10.18.0001 → 10.18.1002+; 10.17.1021 and earlier → 10.17.1030+; 10.16.1051 and earlier → 10.16.1060+; 10.13.1180 and earlier → 10.13.1190+; 10.10.1180 and earlier → 10.10.1181+ (10.10.1181 is End of Maintenance and receives only critical internal fixes). The same bulletin covers about 23 further issues; Bleeping citing HPE places several authenticated management flaws (including CVE-2026-73750/73751/73752 and related) in the high range around 8.1–8.8. WA SOC advisory 20260909002 (9 September 2026, TLP:CLEAR) covers the same CVE-2026-73749 RCE (CVSS 9.8 Critical), lists the same fixed branches, and states it has not received reports of exploitation on Western Australian Government networks at the time of writing. Upgrade AOS-CX switches to the fixed release for your branch; restrict management-plane exposure until patched.

HPE security bulletin hpesbnw05134en_us

vulnerabilities network australia

Vulnerabilities

Thu 3 Sep

Elementor Pro ≤4.2.1 form upload bypass (CVE-2026-32475); ~190k blocked attempts

BleepingComputer (3 September 2026) and Wordfence (via The Hacker News, 4 September 2026) report active exploitation of CVE-2026-32475 in Elementor Pro for WordPress. Faulty validation of file-upload arrays in Elementor Pro forms (versions 4.2.1 and earlier) lets an attacker submit an empty first array element and a malicious PHP file as the second, so later files skip validation. The payload lands under /wp-content/uploads/elementor/forms/ and can be fetched to run commands. Elementor shipped 4.2.2 on 19 August 2026. Wordfence says it blocked about 190,000 exploit attempts against this CVE (and over 250,000 against Super Forms CVE-2026-14894 in the same wave — that CVE has its own desk card). Exploitation needs a published Elementor Pro Form widget with at least one File Upload field. Patchstack disclosed the issue earlier. Upgrade Elementor Pro to 4.2.2 or later; review uploads under elementor/forms for unexpected PHP; keep WAF rules current.

BleepingComputer (3 Sep 2026)

vulnerabilities cloud

Incidents

Thu 3 Sep

CNIL fines Hôpital privé de la Loire €500k after 727k-person EPR breach (summer 2025)

BleepingComputer (3 September 2026) reports France’s CNIL fined Hôpital privé de la Loire (HPL, Ramsay Santé group, Saint-Étienne) €500,000 for GDPR security and notification failures after a summer 2025 intrusion into the electronic patient record system exposed sensitive data of 524,867 patients plus 202,246 trusted third parties (about 727,000 people). CNIL findings cited include external physician access without VPN or multi-factor authentication, overly broad access once an account was compromised, lack of near-real-time monitoring that let exfiltration run for days, and failure to directly notify the trusted-third-party cohort (Articles 32 and 34 GDPR). A teen using the alias “Marak” claimed the path began with one doctor’s account and tried to sell the data; reporting says it was neither sold nor published. HPL strengthened controls during proceedings. Practitioners: remote clinical access needs MFA and VPN; least privilege on EPR; detection that catches multi-day bulk extract; notify every category of affected individual.

BleepingComputer (3 Sep 2026)

breaches identity

Advisories

Thu 3 Sep

Group-IB: BraZetsu Python Windows framework turns hosts into IAB marketplace inventory

The Hacker News (3 September 2026) summarises Group-IB research on BraZetsu, a modular Python-based Windows malware framework attributed to Portuguese-speaking operators tracked as Exilware. Unlike a simple infostealer, BraZetsu is described as a master toolkit for initial access brokers: it commercialises access to compromised hosts for Iberian and Latin American e-commerce and corporate targets, with modular staging and stealth that left some samples fully undetectable on VirusTotal at analysis time. Name blends Brazil with the Naruto character Zetsu. Defenders in those regions should hunt for the BraZetsu toolkit behaviours in Group-IB’s write-up, restrict script interpreters where policy allows, and treat brokered access listings as post-compromise inventory rather than the root cause.

The Hacker News (3 Sep 2026)

tech identity

Advisories

Wed 2 Sep

Australia: Voluntary Security Labelling Scheme for Smart Devices pilot launched (Burke / CTA)

Cyber Security Minister Tony Burke launched the pilot of Australia's Voluntary Security Labelling Scheme for Smart Devices (SLSSD) at the Connecting Technology Summit on 2 September 2026. The scheme is co-developed by the Department of Home Affairs and the Connected Technology Alliance (CTA), funded by Home Affairs, and sits under the 2023–2030 Australian Cyber Security Strategy. Labels give consumers an independently verified Level 1–4 security rating for consumer-grade smart-home IoT (TVs, doorbells/cameras, baby monitors, robot vacuums, solar inverters; not cars, medical devices, phones, tablets or PCs). Pilot vendors named: NetComm, Telstra, ASSA ABLOY/Lockwood, Electrolux; labs: Viden, Securus Consulting Group, Teron Labs, DEKRA, TÜV SÜD. Industry pilot phase from about October 2026; voluntary labels expected on products from 2027. Distinct from the mandatory Cyber Security (Security Standards for Smart Devices) Rules 2025 (commenced 4 March 2026) that require no default passwords, vulnerability reporting paths, and update-policy clarity, with a statement of compliance — the SLSSD badge is designed to surface that compliance. Primary: CTA Labelling Scheme page; wires: techpartner.news 3 Sep, ACS Information Age 8 Sep.

Connected Technology Alliance — Security Labelling Scheme for Smart Devices

australia

Advisories

Wed 2 Sep

REVSTEALER: Elastic documents four follow-on modules (wallet theft, clipper, proxy, XMRig)

Elastic Security Labs (2 September 2026) analyses REVSTEALER, an emerging Windows infostealer that hides backup C2 addresses in Polygon smart contracts, and documents four follow-on modules delivered by C2 tasking: ProManager (wallet-file and browser-extension theft, phishing overlays, password-aware input capture and payload delivery), WinUpdate (cryptocurrency-address replacement and mnemonic-shaped clipboard theft), SoftManager (reverse SOCKS5 proxy / backconnect over an encrypted WebSocket), and LockAppHost (XMRig miner deployment, competitor suspension, and persistence). The four modules share obfuscated configuration, VMProtect-style packing, and Polygon dead drops for replaceable settings including C2 endpoints and XMRig command lines. Elastic also covers CIS locale exclusion checks, sandbox scoring, credential harvesting, payload watermarking, and self-deletion. Observed distribution includes game-cheat social engineering — Elastic identified at least 17 YouTube channels promoting elitecheatsx.live and resight-cheats.net — plus builds whose names and metadata impersonate unrelated software (Slack, qBittorrent, SteelSeries GG, Blender, and others). Gen Threat Labs covered the family earlier in 2026. The Hacker News (6 September 2026) summarises the Elastic activity set. Primary: Elastic Security Labs Threat Command report.

Elastic Security Labs — REVSTEALER (2 Sep 2026)

tech identity

Advisories

Wed 2 Sep

Gambling Goblin: malicious Apache modules on .gov.br sites push betting pages

The Hacker News (2 September 2026) reports Check Point Research tracking Chinese-speaking cluster Gambling Goblin since mid-2025 installing malicious Apache modules on compromised Brazilian government and education web servers. Modules reverse-proxy visitors to phishing pages that spoof Google Play, Microsoft Store and Amazon while stripping security headers, mainly to inflate SEO for online gambling. ANY.RUN had previously noted at least 20 .gov.br municipal and police portals abused in related distribution. Hunt for unexpected Apache modules/loadable objects, outbound reverse-proxy behaviour, and stripped CSP/HSTS on public sites.

The Hacker News (2 Sep 2026)

vulnerabilities network

Vulnerabilities

Wed 2 Sep

Marimo pre-auth WebSocket terminal RCE (CVE-2026-39987); CVSS 9.8 — exploited to AWS/SSH bastion

Marimo GHSA-2679-6mx9-h9xc / NVD: CVE-2026-39987 is a pre-authentication RCE in the reactive Python notebook server. The /terminal/ws WebSocket lacks auth, giving an unauthenticated attacker a full PTY shell. NVD: versions prior to 0.23.0 affected; CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H); CVSS 4.0 9.3 also published. Exploit-DB 52673 (2 Sep 2026) shipped a public PoC (cited ≤0.20.4). UPDATE 15 September 2026 (Sysdig Threat Research; THN wire): Sysdig observed a skilled human operator exploit this CVE within hours of disclosure, pivoting from Marimo to AWS Secrets Manager then an SSH bastion in eight seconds with a hand-rolled Python toolkit (850+ interactive commands over ~9 hours; source IP 172.236.12.17 on first WS connect). Upgrade to 0.23.0+; never expose Marimo terminal WebSockets to the internet. Primary: Marimo GHSA / NVD; research: Sysdig; wire: THN.

Marimo GHSA-2679-6mx9-h9xc (CVE-2026-39987)

tech ai cloud

Vulnerabilities

Wed 2 Sep

Ghost CMS malicious-theme RCE (CVE-2026-29053); Metasploit module public

Exploit-DB entry 52676 (dated 2 September 2026) packages a Metasploit module for CVE-2026-29053: crafted Ghost CMS themes can execute arbitrary code on the host. The module lists affected releases from 0.7.2 through 6.19.0 and notes that for versions 5.105.0–5.130.5 and 6.0.0–6.10.3 it can also leverage a related 2FA bypass (CVE-2026-22594). Endor Labs write-up GHSA-cgc2-rcrh-qr5x is cited as the research reference. Upgrade Ghost past the fixed releases; restrict who can upload themes; review installed themes for unexpected Handlebars templates.

Endor Labs (Ghost CMS RCE)

vulnerabilities cloud

Incidents

Wed 2 Sep

Thomson Reuters C-Track: unauthorised access to court case files across US states, USVI and Ontario

West Publishing Corporation (Thomson Reuters Court Management Solutions) notified courts that an unauthorised party obtained files from the C-Track appellate case-management platform in March 2026; activity was discovered 30 June 2026. The Supreme Court of Ohio public statement says ten of twelve Ohio Courts of Appeals use C-Track hosted by the Court and managed by TRCMS; the 8th and 10th districts do not and are unaffected; TRCMS told the Court on 31 August 2026 that unauthorised access hit the production platform. The Hacker News (3 Sep) summarises West’s 2 September notice: courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario may be in scope; a subset of records could include names, SSNs, driver’s licence numbers, dates of birth, medical and health-insurance information; sealed or redacted material may be impacted for some courts; TRCMS says no evidence of fraud or misuse to date and offers Experian IdentityWorks (US) / TransUnion myTrueIdentity (Canada) monitoring via engagement B171847 and https://www.ctracknotification.com. Distinct from other court or identity cards on this desk.

Supreme Court of Ohio C-Track incident statement

breaches identity

Advisories

Wed 2 Sep

Citizen Lab: Pegasus zero-click via iMessage infected Serbian student activist’s iPhone

Citizen Lab (2 September 2026), with the SHARE Foundation, confirmed that an iPhone belonging to a member of Serbia’s student protest movement was infected with NSO Group’s Pegasus spyware via an iMessage zero-click exploit. High-confidence indicators cover December 2025–January 2026; Citizen Lab assesses the exploit was addressed in Apple iOS 18.4.1 (April 2025). SHARE has documented at least 14 recent Apple Threat Notifications among Serbian students, civil society and an opposition MP ahead of 2026 election cycles; Amnesty has separately described related Android spyware (NoviSpy-like) installed during detention. Primary: Citizen Lab research note. Recipients of Apple Threat Notifications should treat devices as presumed targeted and seek forensic help; keep iOS current.

Citizen Lab (2 Sep 2026)

breaches identity