Daily cybersecurity briefing

Top 10 Cybersecurity Stories for September 5, 2026

Previdian's NetScaler sensor logged PoC-matched requests against CVE-2026-19490 from three source IPs on September 3, and Arctic Wolf confirmed active exploitation of the PaperCut CVE-2026-81578/CVE-2026-82078 authentication-bypass-to-RCE chain in U.S. and European education institutions, with LSA collection tools and Meterpreter sessions observed on compromised hosts. Wordfence has blocked over 440,000 attempts against the unauthenticated file-upload RCEs in Super Forms (CVE-2026-14894, fixed in 6.3.314) and Elementor Pro (CVE-2026-32475, fixed in 4.2.2), both of which permit PHP web-shell deployment without credentials.

Compiled by the Slugnet Editorial System. Published Sep 5, 2026, 7:29 AM EDT

Audio briefing

Listen to this edition

A spoken version of today’s prioritized cybersecurity briefing.

  1. 01
    BleepingComputer

    Critical Citrix NetScaler auth bypass now leveraged in attacks

    What happened

    Previdian reported that attackers began targeting CVE-2026-19490, a critical Citrix NetScaler authentication bypass, after a proof-of-concept exploit was published. The company detected requests matching the exploit from three distinct source IPs on September 3, though it noted this evidence does not confirm successful compromise of real-world systems.

    Why it ranks #1

    Previdian detected requests matching the proof-of-concept exploit for CVE-2026-19490, a critical Citrix NetScaler authentication bypass, from three distinct source IPs on September 3, though the company noted this evidence does not confirm successful compromise of real-world systems.

    Who should care

    Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    What to do

    Patch all vulnerable Citrix NetScaler appliances to mitigate exploitation attempts targeting CVE-2026-19490.

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    product
    Status
    actively exploited
    Read the original source Link to this ranking Share on Bluesky Share by email
  2. 02
    The Hacker News

    Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

    What happened

    Arctic Wolf observed threat actors exploiting an authentication bypass and remote code execution chain in PaperCut (CVE-2026-81578 and CVE-2026-82078) to target U.S. and European education institutions. The attackers deployed credential-harvesting tools and Meterpreter payloads to extract registry hives and search configuration files for sensitive data.

    Why it ranks #2

    Arctic Wolf observed threat actors exploiting an authentication bypass and remote code execution chain in PaperCut (CVE-2026-81578 and CVE-2026-82078) to target U.S. and European education institutions, deploying credential-harvesting tools and Meterpreter payloads to extract registry hives and search configuration files for sensitive data.

    Who should care

    Identity and access teams, IT and platform operations, SOC and incident response teams

    What to do

    Restrict PaperCut internet exposure and monitor for cmd.exe, powershell.exe, or interpreters running whoami, tasklist, ver, or uname -a with pc-app.exe as the parent process.

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  3. 03
    The Hacker News

    Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

    What happened

    Wordfence reports that threat actors have launched over 440,000 exploit attempts against two critical remote code execution flaws in the WordPress plugins Super Forms and Elementor Pro. These unauthenticated file upload vulnerabilities, tracked as CVE-2026-14894 and CVE-2026-32475, allow attackers to deploy PHP web shells to seize control of affected sites.

    Why it ranks #3

    Wordfence reports that threat actors have launched over 440,000 exploit attempts against two unauthenticated remote code execution flaws in the WordPress plugins Super Forms and Elementor Pro, which allow attackers to deploy PHP web shells to seize control of affected sites.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    What to do

    Apply patches for CVE-2026-32475, scan for indicators of compromise, and audit for unexpected activity on affected WordPress sites immediately.

    Impact
    high
    Urgency
    immediate
    Confidence
    high
    Scope
    product
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  4. 04
    Rapid7 Blog

    DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors

    What happened

    Rapid7 Labs identified a Linux toolkit, attributed with medium confidence to DPRK APTs, that embeds a "ted backdoor" directly into HAProxy 2.8.12 builds to intercept web traffic and execute remote commands. The implant, which hooks the HTTP parser to hide C2 traffic from backend logs, was observed in campaigns targeting South Korean automotive and media organizations dating back to early 2025.

    Why it ranks #4

    Rapid7 Labs identified a Linux toolkit, attributed with medium confidence to DPRK APTs, that embeds a "ted backdoor" directly into HAProxy 2.8.12 builds to intercept web traffic and execute remote commands.

    Who should care

    Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  5. 05
    Schneier on Security

    AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks

    What happened

    Researchers at an Israeli startup identified 120 corporate domains where `llms.txt` files referenced unregistered code packages or domains. The researchers registered a handful of the unclaimed names and hosted packages that caused any machine executing them to reach out to their server, receiving a phone-home response from a Fortune 500 company within an hour. The parent process chains revealed that coding agents, including Claude, Codex, and Hermes, were involved in the installs, while the researchers noted that these agents treat vendor documentation as ground truth without verifying package ownership.

    Why it ranks #5

    Researchers registered unclaimed package names referenced in corporate llms.txt files, triggering phone-home responses from Fortune 500 machines where coding agents installed the untrusted code without verifying ownership.

    Who should care

    CISOs and security leaders, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  6. 06
    BleepingComputer

    39 New Methods That Compromise Passkey Authentication

    What happened

    Researchers have documented 39 distinct attack paths that compromise passkey authentication by targeting the surrounding infrastructure, including browsers, operating systems, and account recovery processes, rather than breaking the underlying FIDO2 cryptography. These techniques, which include assertion replay, UI spoofing, and unauthorized enrollment, allow attackers to manipulate legitimate authentication ceremonies or register new credentials on compromised devices. The findings indicate that phishing resistance at the protocol level does not protect against manipulation of the user interface, synchronization services, or help desk workflows.

    Why it ranks #6

    Researchers documented 39 distinct attack paths that compromise passkey authentication by targeting surrounding infrastructure such as browsers, operating systems, and account recovery processes, rather than breaking the underlying FIDO2 cryptography.

    Who should care

    Application security teams, Identity and access teams, IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  7. 07
    Help Net Security

    Most of the bugs Claude Mythos found have never been checked by a human

    What happened

    Anthropic directed Claude Mythos Preview at 281 open-source projects, generating 23,019 candidate vulnerabilities, of which external security firms reviewed 1,900 and confirmed 90.8% as valid. In a controlled benchmark, the model converted 72.4% of known crashes into working arbitrary code execution exploits, while 13 of the 14 severity mismatches among 27 CVE-assigned findings were overstated compared to independent CVSS scores.

    Why it ranks #7

    Anthropic’s Claude Mythos Preview generated 23,019 candidate vulnerabilities across 281 open-source projects, with external security firms confirming 90.8% of the 1,900 reviewed candidates as valid, while the model converted 72.4% of known crashes into working arbitrary code execution exploits in a controlled benchmark.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    high
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email
  8. 08
    The Hacker News

    PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

    What happened

    PostgreSQL released updates on August 13 to fix CVE-2026-6471, a 12-year-old logical decoding flaw that allows accounts with the REPLICATION attribute to execute arbitrary code as the database server's operating-system user. The vulnerability, present since PostgreSQL 9.4, permits attackers to load malicious libraries by bypassing standard path restrictions, a risk that persists in versions prior to 18.6, 17.11, 16.15, 15.19, and 14.24.

    Why it ranks #8

    PostgreSQL released updates on August 13 to fix CVE-2026-6471, a 12-year-old logical decoding flaw that allows accounts with the REPLICATION attribute to execute arbitrary code as the database server's operating-system user.

    Who should care

    Application security teams, IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    monitor
    Confidence
    high
    Scope
    product
    Status
    disclosed
    Read the original source Link to this ranking Share on Bluesky Share by email
  9. 09
    The Hacker News

    Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

    What happened

    Microsoft identified a high-volume phishing campaign that used invisible Unicode tag characters to split financial keywords, bypassing email filters that rely on literal string matching. The operation, which peaked at 2.37 million messages per day in February 2026, leveraged the ActiveCampaign platform to distribute AI-generated lures targeting Small Business Administration loan applicants.

    Why it ranks #9

    Microsoft identified a high-volume phishing campaign that used invisible Unicode tag characters to split financial keywords, bypassing email filters that rely on literal string matching.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    moderate
    Urgency
    near-term
    Confidence
    high
    Scope
    enterprise
    Status
    confirmed incident
    Read the original source Link to this ranking Share on Bluesky Share by email
  10. 10
    The Hacker News

    New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

    What happened

    Rapid7 Labs identified a Linux toolkit compiled directly into the HAProxy load balancers of two South Korean organizations, where it intercepts web traffic and serves altered pages to selected visitors. The implant, named "ted" in debug strings, operates by replacing the legitimate binary rather than exploiting a vulnerability, and Rapid7 attributed the activity to North Korean state-sponsored actors with medium confidence.

    Why it ranks #10

    Rapid7 Labs identified a Linux toolkit compiled directly into the HAProxy load balancers of two South Korean organizations, where it intercepts web traffic and serves altered pages to selected visitors.

    Who should care

    IT and platform operations, SOC and incident response teams

    Impact
    high
    Urgency
    monitor
    Confidence
    low
    Scope
    enterprise
    Status
    emerging
    Read the original source Link to this ranking Share on Bluesky Share by email