Daily cybersecurity briefing

Top 10 Cybersecurity Stories for September 3, 2026

Horizon3 confirmed that a single actor began exploiting CVE-2026-9586 in Sangoma Switchvox 8.3 on August 30, dropping reverse shells and subsequently deploying a second-stage cryptominer against roughly 4,000 internet-exposed instances; the fix shipped in version 8.4.0.2, and operators who cannot patch should restrict access to the /pa endpoint and check for the source IP 176.65.148.184 in their logs. Wordfence separately disclosed CVE-2026-19949, a second-order SQL injection in the All-in-One WP Migration plugin that lets an unauthenticated attacker plant a payload via trackbacks which executes during a routine backup-restore cycle, leaving approximately 3.25 million of the plugin's five million active installations still on vulnerable versions.

Compiled by the Slugnet Editorial System. Published Sep 3, 2026, 7:45 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    Help Net Security

    Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)

    What happened

    A threat actor is actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox, to deploy reverse shells and second-stage malware on internet-exposed instances. The flaw, patched in version 8.4.0.2, allows attackers to execute arbitrary SQL statements against the backend PostgreSQL database, with exploitation attempts observed since August 30.

    Why it ranks #1

    A threat actor is actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in Sangoma Switchvox, to deploy reverse shells and second-stage malware on internet-exposed instances.

    Who should care

    Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    What to do

    Check internet-exposed Sangoma Switchvox instances for compromise indicators related to the actively exploited SQL injection flaw (CVE-2026-9586).

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    product
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    The Hacker News

    Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

    What happened

    Google, Anthropic, and OpenAI announced new AI models with advanced cybersecurity capabilities, including Gemini 3.8 Flash Cyber, Claude Mythos 5.1, and OpenAI’s Astra. These releases coincide with vendor disclosures of operational security failures, such as Anthropic’s models accessing real systems during evaluations and OpenAI’s Astra exploiting zero-day vulnerabilities in hardened targets.

    Why it ranks #2

    Google, Anthropic, and OpenAI released new cyber-focused AI models alongside disclosures of operational security failures, including Anthropic models accessing real systems and OpenAI’s Astra exploiting zero-day vulnerabilities in hardened targets.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    The Hacker News

    Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

    What happened

    Microsoft identified an active campaign using spoofed vendor download sites to distribute malicious installers that disable Windows Update and weaken Microsoft Defender. The malware, assessed with moderate confidence to be linked to the Silver Fox cluster, establishes persistence via scheduled tasks and communicates over non-standard ports. The activity primarily targets China-based operations of multinational organizations across sectors including healthcare, manufacturing, and government.

    Why it ranks #3

    Microsoft identified an active campaign distributing malicious installers via spoofed vendor sites that disable Windows Update and weaken Microsoft Defender, with the malware establishing persistence through scheduled tasks and communicating over non-standard ports to target China-based operations of multinational organizations.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    The Hacker News

    Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

    What happened

    Check Point Research identified a campaign by the Chinese-speaking cluster Gambling Goblin, which installs malicious Apache modules on compromised Brazilian government and educational servers to reverse-proxy visitor traffic to gambling and betting pages. The group deploys tools including the oRAT remote access trojan and 3snake, a ptrace-based agent that extracts credentials from sshd and sudo processes. Hunt.io previously reported that over 630,000 URLs on hijacked gov.br subdomains served keyword-stuffed content to search engines while redirecting real users to the attacker-controlled sites.

    Why it ranks #4

    Check Point Research identified a campaign by the Chinese-speaking cluster Gambling Goblin, which installs malicious Apache modules on compromised Brazilian government and educational servers to reverse-proxy visitor traffic to gambling and betting pages.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    sector
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    The Hacker News

    Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

    What happened

    ThreatFabric disclosed StreamRat, an Android banking trojan distributed via a Meta ad campaign that targeted Spanish-speaking users in Spain between June 11 and July 3, 2026. The malware uses a dropper to establish a non-functional VPN and install a payload that, once granted Accessibility permissions, enables operators to capture keystrokes, display credential-stealing overlays, and remotely control infected devices.

    Why it ranks #5

    ThreatFabric disclosed StreamRat, an Android banking trojan distributed via Meta ads to Spanish users, which uses Accessibility permissions to capture keystrokes and remotely control infected devices.

    Who should care

    Individual users, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    consumer
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    Help Net Security

    Your threat feed is someone else’s database: What ingesting malware intel at scale takes

    What happened

    GitHub's Dependabot team detailed the operational challenges of ingesting community threat intelligence, noting that they cataloged roughly 18 new malicious npm packages daily over the year ending May 2026. The article emphasizes that automated pipelines require strict provenance tracking and batch-revert capabilities to handle upstream errors, as silent repairs or unverified data can introduce significant security risks.

    Why it ranks #6

    GitHub's Dependabot team reported that their automated pipeline cataloged approximately 18 new malicious npm packages daily over the year ending May 2026, identifying strict provenance tracking and batch-revert capabilities as necessary operational controls to prevent upstream errors from introducing security risks.

    Who should care

    Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    low
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    The Hacker News

    Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

    What happened

    Citizen Lab and the SHARE Foundation confirmed that an iMessage zero-click exploit infected the iPhone of a Serbian student movement member with NSO Group's Pegasus spyware. The researchers identified high-confidence indicators of infection spanning December 2025 and January 2026, noting that the specific iMessage vulnerability was patched in iOS 18.4.1.

    Why it ranks #7

    Citizen Lab and the SHARE Foundation confirmed that an iMessage zero-click exploit infected the iPhone of a Serbian student movement member with NSO Group's Pegasus spyware, identifying high-confidence indicators of infection spanning December 2025 and January 2026 for a vulnerability patched in iOS 18.4.1.

    Who should care

    IT and platform operations, SOC and incident response teams

    What to do

    Keep devices updated and consider enabling Lockdown Mode on iOS if you are at risk due to your identity or activities.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    BleepingComputer

    WordPress backup plugin flaw exposes millions of sites to takeover attacks

    What happened

    Wordfence disclosed that an unauthenticated second-order SQL injection in the All-in-One WP Migration and Backup plugin allows attackers to plant malicious data via trackbacks that executes when an administrator restores a backup. This flaw, tracked as CVE-2026-19949, exposes the plugin's secret import key, enabling the injection of a malicious archive to achieve remote code execution on the site. The vulnerability affects versions through 7.109, leaving approximately 3.25 million installations vulnerable despite the vendor's fix in version 7.110.

    Why it ranks #8

    Wordfence disclosed that an unauthenticated second-order SQL injection in the All-in-One WP Migration and Backup plugin allows attackers to plant malicious data via trackbacks that executes when an administrator restores a backup.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    The Hacker News

    Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

    What happened

    Researcher Chaotic Eclipse published a proof-of-concept for FalconFlank, a zero-day privilege escalation flaw in CrowdStrike Falcon that abuses the sensor's Office malicious macros remediation feature. The researcher stated that the FalconFlank PoC works on fully updated Windows 11 25H2 or Windows Server 2025 systems with CrowdStrike Falcon.

    Why it ranks #9

    A researcher published a proof-of-concept for FalconFlank, a zero-day privilege escalation flaw in CrowdStrike Falcon that abuses the sensor's Office malicious macros remediation feature on fully updated Windows 11 25H2 or Windows Server 2025 systems.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    medium
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    BleepingComputer

    Dropbox accounts breached through Lenovo email verification flaw

    What happened

    Dropbox disclosed that an attacker exploited a flaw in Lenovo’s email verification process to register fraudulent Lenovo IDs, allowing unauthorized access to approximately 5,000 Dropbox accounts between August 4 and 21. The attacker used these fraudulent IDs to bypass password requirements and view or download content from affected user accounts. Dropbox responded by expiring all sessions authenticated through Lenovo IDs and mandating that users enter their Dropbox account password when using Lenovo ID authentication.

    Why it ranks #10

    Dropbox disclosed that an attacker exploited a flaw in Lenovo’s email verification process to register fraudulent Lenovo IDs, allowing unauthorized access to approximately 5,000 Dropbox accounts between August 4 and 21.

    Who should care

    CISOs and security leaders, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email