HomeCybersecurity NewsCybersecurity news weekly roundup September 7, 2026
September 7, 2026

Cybersecurity news weekly roundup September 7, 2026

San Mateo, CA, September 7, 2026 — Developments, threats, and responses in the news last week

STORIES LAST WEEK

Google patches Chrome V8 zero-day exploited in the wild

Google patched CVE-2026-85046, a high-severity V8 type-confusion flaw already exploited in the wild. The fix landed in Chrome 152.0.7977.82/.83, making rapid browser rollout a priority for managed fleets. Chrome Releases, September 3, 2026

Citrix NetScaler authentication bypass draws exploitation attempts after PoC release

Attackers began probing CVE-2026-19490 after a credible PoC appeared, with sensors seeing attempts from three countries. The flaw can remotely bypass authentication on certain NetScaler Gateway or AAA configurations, putting exposed edge appliances at immediate risk. BleepingComputer, September 4, 2026

SonicWall confirms active exploitation of two SMA1000 flaws

SonicWall confirmed active exploitation of CVE-2026-83548 and CVE-2026-83549 in SMA1000 appliances. The pair combines a pre-authentication SSRF flaw with post-authentication RCE, and compromised systems may require reimaging plus credential and TOTP resets. SonicWall, September 1, 2026

OpenAI releases GPT-6 Astra with critical cybersecurity capability

OpenAI released GPT-6 Astra, its first broadly deployed model rated Critical for cybersecurity, meaning it can find unknown flaws and develop exploits across many well-protected systems. OpenAI says the release uses strengthened safeguards against cyber misuse. OpenAI, September 3, 2026

AI agents compress enterprise intrusion into less than 10 hours

Unit 42 investigated an intrusion where AI agents compressed more than 50 MITRE ATT&CK techniques into under 10 hours, harvesting secrets, seizing root credentials, and abusing CI/CD and cloud AI infrastructure after initial access. Unit 42, September 2, 2026

China-nexus Fire Ant turns Cisco routers and authentication systems into attack infrastructure

Sygnia says China-nexus Fire Ant turned Cisco IOS XR routers, TACACS infrastructure, and Linux management hosts into covert platforms for traffic collection, credential theft, evidence suppression, and pivots toward connected high-value environments. Sygnia, August 30, 2026

Attackers exploit JFrog Artifactory flaw to mint administrator tokens

Attackers began minting administrator tokens through CVE-2026-82329 days after disclosure. The authentication bypass affects self-hosted Artifactory under default configuration, creating a direct path into software repositories, build pipelines, and downstream supply-chain trust. SecurityWeek, September 1, 2026

Teams helpdesk impersonation campaign pivots toward domain controllers

Microsoft observed attackers impersonating IT staff through Teams, persuading users to grant remote access, then installing a Node.js-based implant. Operators used WinRM to pivot toward domain controllers and certificate authorities using legitimate administrative tooling. Microsoft Security Blog, September 2, 2026

Thomson Reuters C-Track breach exposes court files across U.S. and Canada

Thomson Reuters disclosed unauthorized access to C-Track files tied to courts in 11 U.S. states, the U.S. Virgin Islands, and Canada. The incident affected court records and personal information, underscoring third-party cloud concentration risk. Reuters, September 3, 2026

Phishers repurpose AI prompt-injection trick to hide words from email filters

Microsoft found a high-volume phishing campaign using invisible Unicode tag characters, a technique popularized by AI prompt-injection research, to split lure words and evade content parsing. Defenders should verify whether mail pipelines normalize or flag these characters. Microsoft Security Blog, September 3, 2026

BREEZE COMET executes hundreds of fraudulent transactions through Brazilian payment systems

Mandiant says BREEZE COMET compromised privileged accounts and core financial applications, then executed two waves of hundreds of fraudulent transactions within 24 to 48 hours. The group targets payment systems, APIs, and banking software rather than end users. Google Cloud, September 1, 2026

Twelve-year-old PostgreSQL flaw turns replication access into server takeover

CVE-2026-6471, present since PostgreSQL 9.4, lets accounts with replication privileges load arbitrary libraries, leading to code execution, permanent superuser access, and persistence. Backup, CDC, and monitoring integrations can hold the required privilege. SecurityWeek, September 4, 2026

International operation disrupts Sality peer-to-peer botnet

A multinational operation disrupted the Sality peer-to-peer botnet through domain seizures and sinkholing. Active since 2003, Sality used infected systems for malware delivery, cryptocurrency theft, and cyberattacks, showing decentralized botnets can still be dismantled. U.S. Department of Justice, September 1, 2026

G7 and CISA urge organizations to start post-quantum migration now

The G7 Cyber Security Working Group and CISA urged organizations to begin post-quantum migration now, prioritizing sensitive systems and folding cryptographic upgrades into normal refresh cycles to reduce exposure to harvest-now-decrypt-later attacks. The Record, September 4, 2026

More cybersecurity news

About NetworkTigers

NetworkTigers is the leader in the secondary market for Grade A, seller-refurbished networking equipment. Founded in January 1996 as Andover Consulting Group, the company originally built and re-architected data centers for Fortune 500 firms. Today, NetworkTigers provides consulting and network equipment to global government agencies, Fortune 2000 companies, and healthcare companies. Visit www.networktigers.com

Ben Walker
Ben Walker
Ben Walker is a freelance research-based technical writer. He has worked as a content QA analyst for AT&T and Pernod Ricard.

Popular Articles