Daily cybersecurity intelligence digest from CyberNetSec.io - September 5, 2026
📊 8 threat intelligence reports covering vulnerabilities, exploits, threat actors, and security advisories.
1. Google Patches Chrome Zero-Day CVE-2026-85046
Google has released an emergency security update for its Chrome browser to fix a high-severity type confusion vulnerability in the V8 JavaScript engine, tracked as CVE-2026-85046. The flaw is confirmed to be actively exploited in the wild, making it the sixth Chrome zero-day patched in 2026. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the vulnerability to its Known Exploited Vulnerabilities (KEV) catalog, mandating federal agencies to apply the patch by September 18, 2026. The update is available for Windows, macOS, and Linux users.
2. VMware Workstation & Fusion Critical Flaws Patched
Broadcom has issued security updates for VMware Workstation and Fusion to address two significant vulnerabilities. The most severe, CVE-2026-59346, is a critical-rated integer overflow bug with a 9.3 CVSS score that could allow an attacker with administrative rights on a guest virtual machine to execute code on the host system. A second high-severity flaw, CVE-2026-59347, was also patched. Broadcom has released version 26H1u1 to fix the issues and urges users to update, as no workarounds are available.
3. CISA KEV Catalog Updated with Seven New Flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added seven actively exploited vulnerabilities to its KEV catalog, mandating federal agencies to patch them on a strict timeline. The list includes critical flaws in products from LiteLLM (CVE-2026-59822), SonicWall (CVE-2026-83548), and JFrog Artifactory. The move follows evidence of threat actors exploiting these bugs to steal API keys, deploy crypto miners, and establish persistence. Deadlines for remediation are set for early and mid-September 2026.
4. Akira Ransomware Attacks Gale Credit Union
The Akira ransomware group has claimed responsibility for a cyberattack against Gale Credit Union, an Illinois-based financial institution. The group alleges it exfiltrated 50 gigabytes of sensitive data, including customer and employee Social Security numbers, financial account details, and passport information. The attack is a classic double extortion case, with the group threatening to leak the stolen data on its Tor leak site. Gale Credit Union is offering identity monitoring services to affected individuals.
5. LockBit 5.0 Ransomware Hits KALA Health
The prolific LockBit 5.0 ransomware group has claimed a cyberattack against KALA Health, a Netherlands-based manufacturer of nutraceutical products. The group announced the breach on its data leak site on September 4, 2026, employing its standard double extortion tactic by threatening to release stolen data unless the company establishes contact. The specific nature of the compromised data has not been disclosed. This attack underscores the indiscriminate nature of major ransomware operations, targeting organizations across all sectors.
6. Cisco IOS XR Critical Vulnerabilities Patched
Cisco has released security updates for its IOS XR software, which powers its carrier-grade routing platforms. The patches address eight vulnerabilities, three of which are rated critical with CVSS scores of 9.8. These critical flaws (CVE-2026-20274, CVE-2026-20279, CVE-2026-20212) could allow an unauthenticated, remote attacker to execute arbitrary code or cause a device to crash and reload. Cisco has found no evidence of active exploitation but strongly urges customers to apply the updates immediately.
7. CrowdStrike Falcon Zero-Day 'FalconFlank' Published
A security researcher has publicly disclosed 'FalconFlank,' a zero-day local privilege escalation (LPE) exploit targeting the CrowdStrike Falcon endpoint security platform. The exploit allegedly abuses a feature for remediating malicious Office macros on fully updated Windows 11 and Windows Server systems, allowing a local attacker to gain SYSTEM-level privileges. The vulnerability, which has not yet been assigned a CVE, highlights the risk of security tools themselves becoming an attack vector.
8. G7 & CISA Warn of 'Harvest Now, Decrypt Later' Quantum Threat
The G7 nations, in partnership with CISA, have issued a significant joint advisory urging both public and private sector organizations to begin migrating to post-quantum cryptography (PQC). The advisory warns that nation-state adversaries are likely already engaged in 'harvest now, decrypt later' campaigns, where they steal and store encrypted data today with the intent of decrypting it once cryptanalytically relevant quantum computers become a reality. The guidance recommends a proactive, phased approach to adoption.
📌 Subscribe to daily updates at CyberNetSec.io
All reports include detailed analysis, IOCs, mitigation strategies, and references.
Top comments (0)