Daily cybersecurity briefing

Top 10 Cybersecurity Stories for September 4, 2026

Elementor Pro's CVE-2026-32475, a file-upload array validation bypass in versions 4.2.1 and earlier, is under active exploitation—Wordfence blocked roughly 200,000 attempts between August 19 and 23—and the same week Google patched CVE-2026-85046, a V8 type-confusion zero-day (CVSS 8.8) confirmed exploited in the wild, requiring Chrome updates to 152.0.7977.82/.83. Separately, Coder disclosed that an attacker added unauthorized servers to its Cloudflare-backed registry on August 31, delivering malicious Terraform modules that exfiltrated provisioner secrets, cloud API keys, and database credentials to the lookalike domain coder-infra[.]com over a 14-hour window.

Compiled by the Slugnet Editorial System. Published Sep 4, 2026, 7:26 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    BleepingComputer

    Critical Elementor Pro flaw exploited to take over WordPress sites

    What happened

    Elementor Pro versions 4.2.1 and earlier are under active attack via CVE-2026-32475, a file-upload validation flaw that allows attackers to bypass security checks and deploy webshells. The vulnerability enables remote code execution by storing malicious PHP files in the `/wp-content/uploads/elementor/forms/` directory, a technique Wordfence has blocked in nearly 200,000 attempts since the August 19 patch. Administrators should upgrade to version 4.2.2 and inspect that directory for unauthorized PHP files to identify compromised systems.

    Why it ranks #1

    Elementor Pro versions 4.2.1 and earlier are under active attack via CVE-2026-32475, a file-upload validation flaw that allows attackers to bypass security checks and deploy webshells.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    What to do

    Upgrade to Elementor Pro 4.2.2 or later immediately and inspect the /wp-content/uploads/elementor/forms/ directory for rogue PHP files.

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    product
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    The Hacker News

    Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

    What happened

    Google released a security update for Chrome to patch CVE-2026-85046, a high-severity type confusion bug in the V8 engine that allows remote attackers to execute arbitrary code inside the sandbox. The vendor confirmed that an exploit for this vulnerability exists in the wild, prompting users to update to version 152.0.7977.82 or later on Windows, macOS, and Linux.

    Why it ranks #2

    Google released a Chrome update to patch CVE-2026-85046, a high-severity type confusion bug in the V8 engine that allows remote attackers to execute arbitrary code inside the sandbox, after confirming that an exploit for this vulnerability exists in the wild.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    What to do

    Update Chrome to 152.0.7977.82/.83 on Windows and macOS, or 152.0.7977.82 on Linux, for optimal protection.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    product
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    BleepingComputer

    HPE patches critical ArubaOS-CX remote code execution flaw

    What happened

    Hewlett Packard Enterprise patched CVE-2026-73749, a buffer overflow in the ArubaOS-CX network operating system that allows unauthenticated remote attackers to execute code with elevated privileges. The vulnerability affects multiple release branches, and HPE has not reported active exploitation or publicly available proof-of-concept code.

    Why it ranks #3

    Hewlett Packard Enterprise patched CVE-2026-73749, a buffer overflow in the ArubaOS-CX network operating system that allows unauthenticated remote attackers to execute code with elevated privileges.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    product
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    Help Net Security

    September 2026 Patch Tuesday forecast: All we need is more time

    What happened

    The source text does not contain any information regarding Microsoft Teams, QR codes, or external user message controls. The source text does not mention any feature in development for Android, desktop, iOS, or Mac platforms, nor does it reference a rollout in October 2026 to mitigate phishing risks associated with unverified external links.

    Why it ranks #4

    The source text does not contain any information regarding Microsoft Teams, QR codes, or external user message controls.

    Who should care

    Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    product
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    BleepingComputer

    Coder's registry infrastructure compromised to push malicious modules

    What happened

    Coder disclosed that attackers compromised its Cloudflare infrastructure to inject unauthorized servers into the registry.coder.com pool, delivering malicious Terraform modules to a subset of users between 07:35 and 21:45 UTC on August 31. These modified modules acted as information stealers, exfiltrating provisioner secrets, cloud API keys, and database credentials to the lookalike domain coder-infra[.]com.

    Why it ranks #5

    Coder disclosed that attackers compromised its Cloudflare infrastructure to inject unauthorized servers into the registry.coder.com pool, delivering malicious Terraform modules to a subset of users between 07:35 and 21:45 UTC on August 31.

    Who should care

    CISOs and security leaders, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    The Hacker News

    BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

    What happened

    Group-IB disclosed BraZetsu, a Python-based malware framework that enables initial access brokers to commercialize compromised Windows hosts through the Infected Marketplace. The toolkit uses generative AI to triage victim data, collect browser histories and digital certificates, and locate Brazilian CNAB financial files for potential payment fraud.

    Why it ranks #6

    Group-IB disclosed BraZetsu, a Python-based malware framework that enables initial access brokers to commercialize compromised Windows hosts through the Infected Marketplace by using generative AI to triage victim data, collect browser histories and digital certificates, and locate Brazilian CNAB financial files for potential payment fraud.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    Help Net Security

    Microsoft Teams is about to make QR code phishing much harder

    What happened

    Microsoft is preparing a feature for Teams that automatically obscures QR codes sent by external users, requiring recipients to manually reveal the image before scanning. Microsoft Teams will begin rolling out a feature in October 2026 for Android, desktop, iOS, and Mac that obscures QR codes from external senders to encourage more deliberate interaction with the code content and reduce the risk of phishing and fraud.

    Why it ranks #7

    Microsoft is rolling out a feature in October 2026 for Teams on Android, desktop, iOS, and Mac that automatically obscures QR codes sent by external users, requiring recipients to manually reveal the image before scanning to reduce the risk of phishing and fraud.

    Who should care

    Individual users, IT and platform operations, SOC and incident response teams

    Impact
    critical
    Urgency
    monitor
    Confidence
    high
    Scope
    consumer
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    The Hacker News

    Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

    What happened

    Cisco released patches for CVE-2026-20212, a binding to an unrestricted IP address vulnerability in 10 Silicon One-based Nexus 9000 switches that allows unauthenticated remote attackers to execute code as root. The flaw stems from unrestricted IP binding that leaves TCP ports 43210 and 43211 reachable in the default Layer 3 VRF instance, enabling direct access to the vulnerable service. Cisco has not reported active exploitation but advises customers to apply the fix or implement an infrastructure access control list to block traffic to these specific ports.

    Why it ranks #8

    Cisco released patches for CVE-2026-20212, a binding to an unrestricted IP address vulnerability in 10 Silicon One-based Nexus 9000 switches that allows unauthenticated remote attackers to execute code as root.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    Cisco Talos Blog

    The story behind the intelligence

    What happened

    Cisco Talos published a newsletter detailing the operational challenges of adversary engagement, including the use of multiple personas to interact with cybercriminals. The report also highlights the "AI safety penalty," where guardrails in frontier models block legitimate defensive forensic tasks, creating an asymmetry that favors attackers using unconstrained models.

    Why it ranks #9

    Cisco Talos published a newsletter describing how their team uses multiple personas to engage with cybercriminals and how AI safety guardrails in frontier models block legitimate defensive forensic tasks, creating an operational asymmetry that favors attackers using unconstrained models.

    Who should care

    Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    critical
    Urgency
    near-term
    Confidence
    medium
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    The Hacker News

    Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

    What happened

    Plex released updates for Media Server 1.43.3 and Desktop 1.115.0 to address multiple undisclosed security flaws, urging users to apply the patches immediately. The vendor has not detailed the specific vulnerabilities but noted that CVE identifiers have been requested.

    Why it ranks #10

    Plex released Media Server 1.43.3 and Desktop 1.115.0 to patch multiple undisclosed security flaws, urging users to apply the updates immediately while the vendor awaits assigned CVE identifiers.

    Who should care

    Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    product
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email