← Latest brief

Security news.

·Morning Brief

Today's security landscape is marked by a surge in AI-related security concerns, from new funding for AI runtime security startups to attackers actively exploiting AI tools and platforms. Alongside this, significant vulnerabilities in popular software and a massive data breach involving driver's license images highlight the ongoing need for vigilant patching and robust identity verification.

THNKEV
Sep 3READ

CISA Adds Seven Exploited Flaws to KEV Catalog

CISA has added seven vulnerabilities, including a critical SonicWall SMA 1000 SSRF (CVE-2026-83548) and a Sangoma Switchvox SQL injection (CVE-2026-9586), to its Known Exploited Vulnerabilities catalog.

SECURITYWEEK
Sep 3READ

153 Million Driver License Images Offered on Dark Web

Digital scans of US and Canadian driver’s licenses, likely stolen from identity verification company IDScan.net, are being sold on the dark web, prompting an FBI investigation.

SECURITYWEEKVULN
Sep 3READ

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

A high-severity SQL injection flaw (CVE-2026-19949) in the All-in-One WP Migration and Backup plugin could allow unauthenticated attackers to achieve remote code execution on affected WordPress sites.

THNMALWARE
Sep 3READ

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool

Threat actors are actively leveraging the Node.js JavaScript runtime to deploy malicious payloads in targeted attacks against government, technology, and hotel sectors since February 2026.

DARK READING
Sep 3READ

'Breeze Comet' Tears Into Brazilian & Global Financial Systems

Brazil's most sophisticated threat group is exploiting vulnerabilities in the country's financial systems to directly steal funds.

THNMALWARE
Sep 3READ

Pegasus Zero-Click Spyware Infects Serbian Student Movement Member's iPhone

NSO Group's Pegasus spyware was found on an iPhone belonging to a Serbian student protest movement member, infected via an iMessage zero-click exploit.

SECURITYWEEKPATCH
Sep 3READ

Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities

Cisco has warned of publicly disclosed S/MIME flaws that could expose encrypted email content and released patches for critical IOS XR and Nexus bugs enabling remote code execution and authentication bypass.

BLEEPINGPATCH
Sep 3READ

Plex Warns Users to Patch Security Vulnerabilities Immediately

Plex has urged users to immediately update their desktop clients and media servers to patch multiple undisclosed security vulnerabilities.

Generated twice daily from public security RSS feeds. Informational only.