Daily cybersecurity intelligence digest from CyberNetSec.io - September 1, 2026
📊 8 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.
1. JFrog Artifactory Auth Bypass (CVE-2026-82329) Exploited
A critical authentication bypass vulnerability, CVE-2026-82329, in self-hosted JFrog Artifactory instances is being actively exploited. The flaw allows unauthenticated attackers to gain administrative privileges. Patches were released on August 28, 2026, and organizations are urged to update immediately as attackers are observed creating admin tokens in the wild.
2. McKesson Data Breach Attributed to ShinyHunters Group
US healthcare giant McKesson has confirmed a cyberattack involving data theft from its third-party applications. The ShinyHunters extortion group has claimed responsibility, alleging they stole 1TB of data, including 284 million patient records, and are demanding a $55 million ransom. The breach reportedly occurred between August 21 and August 25.
3. Langflow RCE Vulnerability (CVE-2026-0768) Actively Exploited
A critical remote code execution (RCE) vulnerability, CVE-2026-0768 with a CVSS score of 9.8, in the Langflow AI low-code platform is being actively exploited. The flaw allows unauthenticated attackers to execute arbitrary code with root privileges, leading to reconnaissance and credential theft. Attacks have been observed originating from Russia.
4. METR AI Research Firm Reports Two Major Security Incidents
AI safety non-profit METR disclosed two security incidents. In March 2026, a stolen API key was used to fraudulently consume approximately $600,000 in AI credits. In May, a separate, sustained campaign involved automated probing of its public infrastructure, credential stuffing, and phishing.
5. SAUTER Building Controller RCE Flaw (CVE-2026-78319) Disclosed
A critical remote code execution vulnerability (CVE-2026-78319, CVSS 9.8) affects SAUTER building automation controllers. The flaw, a TOCTOU race condition, could allow unauthenticated attackers to take full control of devices managing HVAC and other essential building systems. Patches are available.
6. EU Cyber Resilience Act Reporting Rules Effective Sept 11, 2026
Manufacturers of connected products sold in the EU must comply with the Cyber Resilience Act's (CRA) new reporting obligations starting September 11, 2026. The rules mandate reporting actively exploited vulnerabilities and severe incidents affecting their products to ENISA within 24 hours.
7. AI Used to Port PLC Exploit, Lowering Bar for OT Attacks
Researchers used AI to port an RCE exploit (CVE-2021-31886) between two different WAGO PLC models in just over 8 hours for about $535. This demonstrates how AI can accelerate the development of attacks against critical infrastructure and operational technology (OT) systems.
8. Large-Scale Phishing Campaign Uses Debt-Relief Vishing Tactics
A large-scale phishing campaign has targeted over 9,000 organizations with 24,700 debt-relief-themed emails in two weeks. The attack uses social engineering to trick victims into calling scammer-controlled phone numbers (vishing) to steal financial data and other personal information.
📌 Subscribe to daily updates at CyberNetSec.io
All reports include detailed analysis, IOCs, mitigation strategies, and references.
Top comments (0)