Cybersecurity News | Daily Recap [02 Sep 2026]

Cybersecurity News | Daily Recap [02 Sep 2026]
Daily Recap, Attackers are exploiting AI and application flaws—such as Langflow CVE-2026-0768 for unauthenticated RCE and credential theft, along with malicious .git configurations that can make agents like Claude, Codex, and Cursor execute attacker code—while vendors and defenders push new safeguards for AI logs and agent security. Across other sectors, SonicWall SMA 1000 is under active exploitation via CVE-2026-83548 and CVE-2026-83549, and incidents span credential phishing (including OAuth consent phishing), supply-chain abuse (JFrog Artifactory, Cleo Harmony), and major breaches affecting Aesto Health and Novocure. #Langflow #CVE-2026-0768 #Claude #SonicWallSMA1000 #CVE-2026-83548 #CVE-2026-83549 #JFrog #Artifactory #CleoHarmony #OAuthConsentPhishing #FBI #AestoHealth #Novocure

AI & App Exploits

  • Attackers are exploiting Langflow CVE-2026-0768 to achieve unauthenticated RCE and steal OpenAI, AWS, and secret-file credentials from vulnerable AI environments. – Langflow Keys, Langflow Exploit
  • Malicious .git configs can trick AI agents like Claude, Codex, and Cursor into running attacker code, highlighting a new supply-chain style risk for developer tools. – AI Configs
  • Anthropic detailed its incident response and launched enterprise safeguards so Claude logs can stay in customers’ cloud environments, while Palo Alto Networks acquired AI agent platform Console and Sevii pitched autonomous defense for AI-speed attacks. – Anthropic Safeguards, Claude Logs, Palo Alto Deal, Sevii Defense

Zero-Days & Exploitation

  • SonicWall SMA 1000 appliances are under active attack via zero-day flaws CVE-2026-83548 and CVE-2026-83549, with multiple reports confirming exploitation in the wild. – SonicWall Zero-Days, SonicWall Alert
  • Attackers are exploiting a critical JFrog Artifactory flaw shortly after disclosure to mint admin tokens and expand access. – JFrog Flaw
  • A fresh Cleo Harmony vulnerability has already seen an exploit published, increasing risk for exposed file-transfer systems. – Cleo Exploit

Credential Theft & Phishing

  • The FBI warned that attackers are targeting prominent people with deceptive OAuth consent phishing to steal account access and trusted app permissions. – OAuth Phishing, FBI Alert
  • Dropbox accounts were breached through a Lenovo email-verification flaw, showing how upstream verification issues can be abused for account takeover. – Dropbox Breach
  • Microsoft Defender incorrectly flagged legitimate Google search links as malicious, creating user confusion amid ongoing phishing pressure. – Defender False Positive

Malware & Botnets

  • U.S. authorities charged a Russian national for infecting 80,000 freelancers with malware, while a global operation dismantled Sality botnet infrastructure. – Freelancer Malware, Sality Takedown
  • Hackers abused the Faronics Deploy admin tool to install ScreenConnect, turning a legitimate management product into a remote-access delivery path. – Faronics Abuse

Fraud, Finance & Infrastructure

  • Breeze Comet executed hundreds of fraudulent transactions through Brazilian payment systems, underscoring the scale of regional financial abuse. – Fraud Wave
  • Hackers pushed a malicious Virtualizor update via BGP hijacking, combining routing abuse with software compromise. – Virtualizor Hijack, Virtualizor Update
  • A battery-storage cyberattack could resemble a badly tuned controller, highlighting how industrial incidents can blend into normal operations. – Battery Attack

Data Breaches & Privacy

  • Aesto Health said a breach affected over 9.5 million patients, while Novocure reported a separate incident impacting more than 1,400 cancer patients. – Aesto Breach, Novocure Breach
  • Sift launched an open-source secrets scanner that hunts credentials across Microsoft 365, Slack, and Jira to help reduce exposed secrets. – Sift Scanner

Public Sector & Policy

  • The U.S. Coast Guard established a maritime cybersecurity policy office as governments continue to formalize cyber defense for critical infrastructure. – Maritime Policy
  • CyberScoop reports also highlighted election-related concerns, including a whistleblower claim about USPS deploying untested mail-ballot systems and a separate Tina Peters election-role development in Shasta County. – USPS Systems, Shasta County
  • Five Venezuelans pleaded guilty in U.S. court to ATM jackpotting, closing another international fraud case. – ATM Case

Cybersecurity News | Daily Recap – hendryadrian.com