STORIES LAST WEEK
Google patches Chrome V8 zero-day exploited in the wild
Google patched CVE-2026-85046, a high-severity V8 type-confusion flaw already exploited in the wild. The fix landed in Chrome 152.0.7977.82/.83, making rapid browser rollout a priority for managed fleets. Chrome Releases, September 3, 2026
Citrix NetScaler authentication bypass draws exploitation attempts after PoC release
Attackers began probing CVE-2026-19490 after a credible PoC appeared, with sensors seeing attempts from three countries. The flaw can remotely bypass authentication on certain NetScaler Gateway or AAA configurations, putting exposed edge appliances at immediate risk. BleepingComputer, September 4, 2026
SonicWall confirms active exploitation of two SMA1000 flaws
SonicWall confirmed active exploitation of CVE-2026-83548 and CVE-2026-83549 in SMA1000 appliances. The pair combines a pre-authentication SSRF flaw with post-authentication RCE, and compromised systems may require reimaging plus credential and TOTP resets. SonicWall, September 1, 2026
OpenAI releases GPT-6 Astra with critical cybersecurity capability
OpenAI released GPT-6 Astra, its first broadly deployed model rated Critical for cybersecurity, meaning it can find unknown flaws and develop exploits across many well-protected systems. OpenAI says the release uses strengthened safeguards against cyber misuse. OpenAI, September 3, 2026
AI agents compress enterprise intrusion into less than 10 hours
Unit 42 investigated an intrusion where AI agents compressed more than 50 MITRE ATT&CK techniques into under 10 hours, harvesting secrets, seizing root credentials, and abusing CI/CD and cloud AI infrastructure after initial access. Unit 42, September 2, 2026
China-nexus Fire Ant turns Cisco routers and authentication systems into attack infrastructure
Sygnia says China-nexus Fire Ant turned Cisco IOS XR routers, TACACS infrastructure, and Linux management hosts into covert platforms for traffic collection, credential theft, evidence suppression, and pivots toward connected high-value environments. Sygnia, August 30, 2026
Attackers exploit JFrog Artifactory flaw to mint administrator tokens
Attackers began minting administrator tokens through CVE-2026-82329 days after disclosure. The authentication bypass affects self-hosted Artifactory under default configuration, creating a direct path into software repositories, build pipelines, and downstream supply-chain trust. SecurityWeek, September 1, 2026
Teams helpdesk impersonation campaign pivots toward domain controllers
Microsoft observed attackers impersonating IT staff through Teams, persuading users to grant remote access, then installing a Node.js-based implant. Operators used WinRM to pivot toward domain controllers and certificate authorities using legitimate administrative tooling. Microsoft Security Blog, September 2, 2026
Thomson Reuters C-Track breach exposes court files across U.S. and Canada
Thomson Reuters disclosed unauthorized access to C-Track files tied to courts in 11 U.S. states, the U.S. Virgin Islands, and Canada. The incident affected court records and personal information, underscoring third-party cloud concentration risk. Reuters, September 3, 2026
Phishers repurpose AI prompt-injection trick to hide words from email filters
Microsoft found a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized by AI prompt-injection research, to split lure words and evade content parsing. Defenders should verify whether mail pipelines normalize or flag these characters. Microsoft Security Blog, September 3, 2026
BREEZE COMET executes hundreds of fraudulent transactions through Brazilian payment systems
Mandiant says BREEZE COMET compromised privileged accounts and core financial applications, then executed two waves of hundreds of fraudulent transactions within 24 to 48 hours. The group targets payment systems, APIs, and banking software rather than end users. Google Cloud, September 1, 2026
Twelve-year-old PostgreSQL flaw turns replication access into server takeover
CVE-2026-6471, present since PostgreSQL 9.4, lets accounts with replication privileges load arbitrary libraries, leading to code execution, permanent superuser access, and persistence. Backup, CDC, and monitoring integrations can hold the required privilege. SecurityWeek, September 4, 2026
International operation disrupts Sality peer-to-peer botnet
A multinational operation disrupted the Sality peer-to-peer botnet through domain seizures and sinkholing. Active since 2003, Sality used infected systems for malware delivery, cryptocurrency theft, and cyberattacks, showing decentralized botnets can still be dismantled. U.S. Department of Justice, September 1, 2026
G7 and CISA urge organizations to start post-quantum migration now
The G7 Cyber Security Working Group and CISA urged organizations to begin post-quantum migration now, prioritizing sensitive systems and folding cryptographic upgrades into normal refresh cycles to reduce exposure to harvest-now-decrypt-later attacks. The Record, September 4, 2026
More cybersecurity news
- Last week’s news roundup
- More cybersecurity news
- All articles sponsored by NetworkTigers
About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com
