Daily cybersecurity briefing

Top 10 Cybersecurity Stories for September 1, 2026

PaperCut shipped emergency patches for CVE-2026-81578 and CVE-2026-82078 after Defused confirmed active exploitation in which an actor chains the authentication bypass to dump Derby database tables, while Shadowserver tracks over 800 exposed NG and MF servers. VulnCheck logged 360 detections of CVE-2026-0768 and CVE-2026-66066 exploitation against Langflow and Rails hosts, with attackers harvesting API keys and cloud credentials from environment variables, and noted that a patched 8.1.3.1 server still executes the RCE gadget through variation-key Marshal deserialization.

Compiled by the Slugnet Editorial System. Published Sep 1, 2026, 8:10 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    The Hacker News

    Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

    What happened

    METR disclosed that attackers exploited a fail-open authentication vulnerability in a publicly exposed agent orchestration dashboard to steal an API key and consume approximately $600,000 worth of inference credits over three weeks. The threat actor also added an SSH key for persistent access, while a separate May incident involved systematic probing of public infrastructure that did not result in the exfiltration of non-public data.

    Why it ranks #1

    METR disclosed that attackers exploited a fail-open authentication vulnerability in a publicly exposed agent orchestration dashboard to steal an API key and consume approximately $600,000 worth of inference credits over three weeks.

    Who should care

    Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    BleepingComputer

    Recently patched PaperCut zero-days used in data theft attacks

    What happened

    PaperCut NG and MF print management servers are under active attack using two recently patched zero-day vulnerabilities, CVE-2026-81578 and CVE-2026-82078, which allow attackers to bypass authentication and execute remote code. Defused confirmed that threat actors are exploiting these flaws to dump database tables and steal data from compromised systems.

    Why it ranks #2

    Threat actors are actively exploiting recently patched zero-day vulnerabilities CVE-2026-81578 and CVE-2026-82078 in PaperCut NG and MF print management servers to bypass authentication, execute remote code, and steal data from compromised systems.

    Who should care

    CISOs and security leaders, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    The Hacker News

    Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

    What happened

    VulnCheck reported active exploitation of CVE-2026-0768 in Langflow and CVE-2026-66066 in Ruby on Rails, with detection counts rising from 50 to 360 within days. Attackers used these flaws to harvest environment variables, API keys, and SSH credentials, while also deploying cryptominers and remote access tools. VulnCheck reported that while the patched 8.1.3.1 server blocks the libvips file read, it does not neutralize the variation-key Marshal deserialization, allowing the RCE gadget to still execute given a valid signature.

    Why it ranks #3

    VulnCheck reported active exploitation of CVE-2026-0768 in Langflow and CVE-2026-66066 in Ruby on Rails, with detection counts rising from 50 to 360 within days as attackers harvested environment variables, API keys, and SSH credentials while deploying cryptominers and remote access tools.

    Who should care

    Cloud security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    The Hacker News

    ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions

    What happened

    Kaspersky identified a ValleyRAT backdoor campaign where the Silver Fox threat actor distributes malware disguised as the signed QN Wallpaper adware application. The installer uses DLL sideloading to execute a malicious libcef.dll within the trusted process, simultaneously disabling Windows Defender and establishing persistent access for data collection and remote control.

    Why it ranks #4

    Kaspersky identified a ValleyRAT campaign where Silver Fox distributes malware disguised as signed QN Wallpaper adware, using DLL sideloading to disable Windows Defender and establish persistent remote access.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    Help Net Security

    Threat actors are posing as AI crawlers to hunt for exposed credentials

    What happened

    GreyNoise identified a campaign where attackers forged user-agent strings for AI crawlers from OpenAI, Anthropic, Google, and Perplexity to scan websites for exposed credentials. The scanners targeted sensitive paths such as .env files and AWS credentials, but none of the traffic requested /robots.txt, a standard behavior for legitimate crawlers. GreyNoise published the 824 associated IP addresses and targeted paths to allow site owners to verify their own logs.

    Why it ranks #5

    GreyNoise identified a campaign in which attackers forged user-agent strings for AI crawlers from OpenAI, Anthropic, Google, and Perplexity to scan websites for exposed credentials in sensitive paths like .env files and AWS credentials, while omitting requests to /robots.txt, a standard behavior for legitimate crawlers.

    Who should care

    CISOs and security leaders

    Impact
    moderate
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    BleepingComputer

    Cronos blockchain restarts after $74 million Tectonic exploit

    What happened

    An attacker manipulated the price of the TONIC token on the Tectonic lending platform to borrow $74 million in real assets, though only approximately $6 million in Ethereum was successfully exfiltrated. The Cronos blockchain halted operations to freeze the exploit and has since restored its state to pre-incident levels, resuming block production.

    Why it ranks #6

    An attacker manipulated TONIC token prices on Tectonic to borrow $74 million, exfiltrating $6 million in Ethereum before Cronos halted operations, froze the exploit, and restored pre-incident state.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    Help Net Security

    LastPass enhancements improve visibility, governance, and control

    What happened

    LastPass announced a series of product updates for its Business Max offering, including always-on SaaS monitoring that maintains visibility through a permanent browser extension connection and more granular SaaS Protect controls for administrators. The company also launched a Mobile Smart Scanner to digitize physical credentials and completed the transition to a Unified Admin Console. Additionally, LastPass is automatically enrolling all consumer accounts in dark web monitoring, shifting the service from an opt-in to a proactive protection model.

    Why it ranks #7

    LastPass announced product updates for its Business Max offering, including always-on SaaS monitoring via a permanent browser extension, granular SaaS Protect controls, a Mobile Smart Scanner for physical credentials, a Unified Admin Console, and automatic dark web monitoring for all consumer accounts.

    Who should care

    CISOs and security leaders

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    SecurityWeek

    Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild

    What happened

    SecurityWeek reported that exploitation of the authentication bypass vulnerability CVE-2026-82329 in JFrog Artifactory began shortly after the flaw was publicly disclosed. JFrog reported that exploitation of the authentication bypass vulnerability CVE-2026-82329 began days after its public disclosure, though the source does not specify the scope of the compromise or identify the threat actor.

    Why it ranks #8

    JFrog reported that exploitation of the authentication bypass vulnerability CVE-2026-82329 in Artifactory began days after its public disclosure, though the source does not specify the scope of the compromise or identify the threat actor.

    Who should care

    Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    monitor
    Confidence
    medium
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    SecurityWeek

    9.5 Million Impacted by Aesto Health Data Breach

    What happened

    Hackers stole personal and health information from the healthcare technology company Aesto Health's AWS infrastructure. The breach impacted 9.5 million individuals.

    Why it ranks #9

    Hackers stole personal and health information from Aesto Health's AWS infrastructure, a breach that impacted 9.5 million individuals.

    Who should care

    CISOs and security leaders, Cloud security teams, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    medium
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    Help Net Security

    NIS2 compliance: Fixing IAM and access control before the 2026 audit

    What happened

    The NIS2 Directive is moving from transposition into enforcement across the EU, with October bringing legally binding deadlines for member states. Non-compliance exposes essential entities to fines of up to €10 million or 2% of global turnover, while management bodies face personal liability, including temporary bans from executive roles.

    Why it ranks #10

    The NIS2 Directive is moving from transposition into enforcement across the EU, with October bringing legally binding deadlines for member states.

    Who should care

    Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email