Latest cyber news, threats, security, and guidelines. Stack up.

Vulnerabilities

Wed 2 Sep

Cisco: unpatched Secure Email S/MIME flaws (CVE-2026-20354/20355); critical IOS XR and Nexus 9000 patches

SecurityWeek (3 September 2026) summarises Cisco’s 2 September advisory drop. Two medium-severity, publicly disclosed but unpatched issues in Secure Email S/MIME decryption — CVE-2026-20354 and CVE-2026-20355 — can let a MitM attacker obtain plaintext from encrypted gateway traffic; Cisco says all Secure Email devices on AsyncOS 16.5.0 or earlier with S/MIME enabled are affected and it is not aware of in-the-wild exploitation. The same day Cisco also shipped critical fixes for IOS XR (including CVE-2026-20274 and CVE-2026-20279 at CVSS 9.8 for memory-corruption / improper access-control classes) and Nexus 9000 series switches (CVE-2026-20212, CVSS 9.8: remote code execution with root via by-default accessible TCP ports), plus high-severity SIP phone DoS CVE-2026-20281 on Desk Phone 9800 / IP Phone 7800/8800 / Video Phone 8875. Primary vendor notice: cisco-sa-esa-smime-disc-dzw4rEdY and the 2 Sep publication notice. Apply available IOS XR / Nexus / phone patches; for Secure Email, follow Cisco’s advisory for workarounds until a fixed AsyncOS build ships.

Cisco SA: Secure Email S/MIME (CVE-2026-20354/20355)

vulnerabilities network australia

Advisories

Wed 2 Sep

StreamRat Android banking trojan pushed via Meta ads to Spanish-speaking users

ThreatFabric (2 September 2026) details StreamRat, an Android banking trojan promoted through a fake television-streaming campaign on Meta aimed at Spanish-speaking users. ThreatFabric estimates about 570,950 Meta accounts in the EU saw the ad at least once; infected-device totals are not published. After sideloading app.apk, the dropper seeks default Home-app status, a VPN permission that blackholes other apps' traffic during install, unknown-sources install rights, then Accessibility access for the StreamRat payload (keylogging, credential overlays, UI inspection, remote control) before talking to C2. ThreatFabric does not name an attributed actor. Users should refuse streaming APKs that request Home, VPN, or Accessibility controls unrelated to playback; enterprises with BYOD Android in AU/EU travel cohorts should watch for sideloaded streaming lures.

ThreatFabric StreamRat analysis (2 Sep 2026)

tech identity

Vulnerabilities

Wed 2 Sep

Rockwell Automation: CISA ICSA-26-244 batch (RSLinx Classic, Logix, FactoryTalk, more)

On 2 September 2026 CISA published a Rockwell Automation ICS advisory batch (ICSA-26-244-01 through ICSA-26-244-06) alongside Rockwell Trust Center advisories. ICSA-26-244-01 covers RSLinx Classic denial-of-service issues CVE-2026-9621, CVE-2026-9622, CVE-2026-9624 and CVE-2026-9625 (critical/high per SecurityWeek's read of the vendor set; exploitation can crash the RSLinx Classic service until restart). ICSA-26-244-03 covers Logix Platform CVE-2026-9637 (improper restriction of operations within memory buffer) with vendor CVSS 3.x 7.5 on ControlLogix 5580 and CompactLogix 5380 version ranges listed in the CISA advisory; CISA states it is not aware of public exploitation. SecurityWeek also notes FactoryTalk Historian RCE, FactoryTalk Activation Manager privilege issues, ArmorStart XSS/DoS, and ControlFLASH arbitrary code execution among the same Tuesday drop. Apply Rockwell patches or workarounds from the Trust Center; segment OT management hosts.

CISA ICSA-26-244-01 (RSLinx Classic, 2 Sep 2026)

vulnerabilities ot ics network

AI

Wed 2 Sep

Forescout: Claude-assisted port of WAGO PLC pre-auth RCE (CVE-2021-31886) to 750-831

Forescout Vedere Labs (covered by The Hacker News on 2 September 2026) reports researcher-guided use of Anthropic Claude to port a working pre-authentication RCE exploit for CVE-2021-31886 (Nucleus FTP USER-command stack buffer overflow, Siemens CVSS 9.8, TCP/21) from a WAGO 750-852 to a WAGO 750-831 on firmware V01.04.16, executing ARM shellcode on live hardware. The port needed sustained human steering; the final RCE stage cost about US$535.74 in API usage over roughly 8.5 hours. CERT@VDE advisory VDE-2021-050 says no updates are available for affected WAGO controllers and advises disabling/blocking FTP on port 21, segmentation, and traffic monitoring. A later session that tried to build a C2 implant bricked the PLC by writing flash-mapped memory. Forescout notes a skilled researcher might have finished the initial port without AI faster and cheaper. Old CVE, new AI-assisted exploit-port demonstration — useful for OT change-control and agentic-coding risk discussions.

Forescout Vedere Labs blog (Claude / WAGO PLC)

ai ot ics

Vulnerabilities

Wed 2 Sep

Chrome 152.0.7977.75/.76 and Firefox 155: critical UAF and high-severity browser fixes

Google's Stable Channel Update for Desktop (2 September 2026) promotes Chrome to 152.0.7977.75/.76 on Windows and Mac and 152.0.7977.75 on Linux with 26 security fixes. Critical: CVE-2026-84353 use-after-free in Shared Tab Groups and CVE-2026-84352 use-after-free in WebGL (both Google-reported). Nine High issues include FileSystem incorrect authorization (CVE-2026-84354), Skia information leak (CVE-2026-84359), Omnibox input validation (CVE-2026-84357), and several use-after-free / buffer issues in Proxy, Browser, Dawn, GPU and V8. Distinct from desk card cve-2026-79290 (earlier Chrome 152.0.7977.64/.65 Critical Aura/ANGLE set, 25 Aug). SecurityWeek says Mozilla shipped Firefox 155 the same day with patches for 29 defects including 13 high-severity use-after-free, sandbox escape, and memory-corruption issues. Update Chrome and Firefox promptly; this desk does not invent CVSS for Google's Critical labels.

Chrome Stable Channel Update for Desktop (2 Sep 2026)

vulnerabilities cloud

AI

Wed 2 Sep

Google Fairwind: Gemini 3.8 Flash Cyber for trusted defenders

Google launched the Fairwind Program (2 September 2026 posts) to give a limited set of trusted Google Cloud customers, government agencies, and cybersecurity partners early access to Gemini 3.8 Flash Cyber — Google's most capable cybersecurity model for vulnerability discovery and automated patching — paired with the CodeMender harness so defenders can find, verify, and fix issues in their own secure cloud environment. Google says it is working with more than 650 partners globally (examples named include CrowdStrike, Datadog, Menlo Security, Palo Alto Networks, and Snowflake). 3.8 Flash Cyber ships with a more permissive cyber-capability profile than general Gemini 3.8 Flash and is therefore limited to vetted defenders; Google states the focus is vulnerability fixing over offensive exploitation. Distinct from desk card openai-astra-critical-20260901 (OpenAI Critical cyber threshold) and from gemini-3-7-flash-2026.

Google Fairwind Program announcement

ai llm model

Vulnerabilities

Wed 2 Sep

LiteLLM MCP Streamable HTTP improper auth (CVE-2026-59822); CISA KEV

BerriAI LiteLLM GHSA-7488-6r32-c95q (CVE-2026-59822) is High: the MCP Streamable HTTP auth path could let an unauthenticated attacker establish an MCP session with an arbitrary Bearer token when OAuth2 passthrough fallback replaced failed key validation with an empty UserAPIKeyAuth object, exposing configured MCP tools and connected services. Affected versions before 1.84.0; fixed in 1.84.0. GHSA publishes CVSS 4.0 vector AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N; CISA KEV (2 Sep 2026) and The Hacker News cite 8.8. CISA added the CVE to KEV on evidence of active exploitation. Upgrade to 1.84.0+ or disable/block /mcp/ until patched.

GitHub GHSA-7488-6r32-c95q (LiteLLM)

vulnerabilities cloud ai

Vulnerabilities

Wed 2 Sep

Kestra OSS auth bypass via /configs suffix (CVE-2026-49869) → unauth RCE; CISA KEV

Kestra GHSA-5vc5-wxxq-3fjx (CVE-2026-49869) is Critical: AuthenticationFilter whitelists any path whose last segment is configs via endsWith("/configs"), so unauthenticated callers can hit flow/execution APIs and, with default script plugins, achieve remote code execution as root in the worker container. GHSA CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H (10.0). Affected through 1.3.20; patched in 1.0.45 and 1.3.21. CISA added it to KEV on 2 September 2026. Upgrade Kestra OSS immediately; do not expose the webserver to untrusted networks until patched.

GitHub GHSA-5vc5-wxxq-3fjx (Kestra)

vulnerabilities cloud ai

Vulnerabilities

Wed 2 Sep

Starlette Host-header URL confusion / path smuggling (CVE-2026-48710); CISA KEV

Kludex Starlette GHSA-86qp-5c8j-p5mr (CVE-2026-48710) is an HTTP request/response path confusion: affected builds rebuild request.url from an unvalidated Host header, so a malformed Host can make request.url.path differ from the path the router actually dispatched. Middleware that authorises on request.url.path can be bypassed. GHSA rates Moderate; CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N (6.5). Affected through 1.0.0; patched in 1.0.1. CISA added it to the KEV catalog on 2 September 2026 based on evidence of active exploitation. Upgrade Starlette (and FastAPI stacks that pin it) to 1.0.1 or later; ensure front-end proxies reject malformed Host headers.

GitHub GHSA-86qp-5c8j-p5mr (Starlette)

vulnerabilities cloud

Advisories

Wed 2 Sep

Sality P2P botnet infrastructure disrupted in joint global takedown

BleepingComputer and SecurityWeek report a 2 September 2026 joint disruption of the long-running Sality peer-to-peer botnet. Europol, Eurojust, the U.S. DOJ, FBI and DCIS seized Sality-linked domains in the United States, with further seizures in Bulgaria, Hungary and Romania. CrowdStrike's Counter Adversary Operations, with law-enforcement and industry partners, sinkholed known super-peer lists that form the botnet's communication backbone, blocking file packs and URL packs that push payloads. CrowdStrike says Sality has been active since at least 2003, has infected more than 15,000 devices historically, and that the two still-active networks at takedown were mainly used to push EggJagger clipjacking payloads; earlier payload history spans credential theft, spam, proxies, exploitation and DDoS. BC quotes CrowdStrike that after more than two decades the botnet is now no longer able to push new malware payloads through those channels.

BleepingComputer

tech network

Vulnerabilities

Wed 2 Sep

SonicWall SMA1000: two zero-days chained for unauth RCE (CVE-2026-83548, CVE-2026-83549); CISA KEV

SonicWall's 2 September 2026 advisory SNWLID-2026-0016 (covered by SecurityWeek the same day) warns SMA1000 series secure remote access / SSL-VPN customers of two zero-days discovered and observed exploited internally. CVE-2026-83548 is a pre-authentication SSRF in the Appliance Work Place interface, rated CVSS 10. CVE-2026-83549 is an OS command injection in the Appliance Management Console (AMC), rated CVSS 7.8, that an authenticated attacker can use for arbitrary OS commands and potential RCE. SonicWall says both have been exploited and the pair can be chained for unauthenticated remote code execution. Affected models: SMA1000 6210, 7210 and 8200v. Hotfixes 12.4.3-03526, 12.5.0-02952 and higher patch both issues. SSL-VPN on SonicWall firewalls and SMA100 series products are not affected. CISA added both CVEs to the KEV catalog on 2 September 2026.

SonicWall PSIRT SNWLID-2026-0016

vulnerabilities network

Incidents

Tue 1 Sep

IDScan.net confirms cloud access tied to 153M+ licence dump; lawsuits ongoing

KrebsOnSecurity (1 September 2026) reported a dark-web identity-theft service branded Nexus advertising digital scans of more than 153 million US and Canadian driver’s licences plus millions of other ID cards, travel documents and medical cards. Krebs’s checks pointed to Louisiana identity-verification firm IDScan.net as the likely source; the company said it was investigating and the FBI New Orleans field office opened an inquiry. SecurityWeek (3 Sep) and Ars Technica (2 Sep) corroborated the listing. BleepingComputer (4 September 2026) reports multiple lawsuits against IDScan, with firms including Markovits, Stock & DeMarco and Hall Attorneys launching investigations into potential class-action litigation. Nexus appeared to shut shortly after Krebs published. Organisations that rely on third-party ID-scan vendors should treat this as a supply-chain identity risk. NEW 10 September 2026 (BleepingComputer): IDScan published a 4 September 2026 security notice (initially noindex) stating it learned on or around 1 September that an unauthorised party may have accessed or copied customer information in IDScan.net cloud accounts — full names and driver's licence or other government ID numbers — and that investigation continues with third-party specialists. This is the first public company confirmation tying the firm to the 153M+ licence dump reporting. UPDATE 16 September 2026 desk: primary_url switched to IDScan.net press notice (datePublished 4 Sep 2026) stating unauthorised access/copy of cloud customer info may include full names and driver's licence or other government ID numbers; free credit monitoring offered; cooperating with federal law enforcement. ACS Information Age (8 Sep) re-covered the dump for AU readers — no new scope beyond vendor notice.

IDScan.net — Notification of Data Security Incident (4 Sep 2026)

breaches identity