Cybersecurity News | Daily Recap [03 Sep 2026]

Cybersecurity News | Daily Recap [03 Sep 2026]
Daily Recap, Google rolled out Gemini 3.8 Flash and, alongside Capsule Security, HiddenLayer, AIR Security, and OpenLeash, is pushing circuit-breakers, runtime defenses, and human checks to reduce risky AI-agent behavior. Key incidents also covered actively exploited flaws added by CISA, ongoing attacks against Sangoma Switchvox and exposed Microsoft Exchange servers, plus takeovers, spyware exposure (Pegasus and NoviSpy), major dark-web data leaks, and new WordPress plugin risks—along with policy moves in the UK and FCC telecom anti-robocall protections. #Gemini3_8Flash #CapsuleSecurity #HiddenLayer #AIRSecuriy #OpenLeash #CISA #CVE-2026-9586 #SangomaSwitchvox #CVE-2026-62911 #MicrosoftExchange #JFrogArtifactory #FalconFlank #Sality #Pegasus #NoviSpy #Aesto #WordPress #KB5120998 #Teams #Outlook

AI Security

  • Google rolled out Gemini 3.8 Flash to challenge larger AI models at lower cost, while Capsule Security, HiddenLayer, AIR Security, and OpenLeash launched or funded tools to add circuit-breakers, runtime defense, and human checks for risky AI agents – Gemini Flash, AI Circuit Breaker, AI Runtime, AIR Security, OpenLeash
  • Google, Anthropic, and OpenAI unveiled new cyber AI models, safeguards, and access programs as vendors race to make AI safer for security use cases – Cyber AI
  • New reporting asked who pays when AI quietly breaks things, highlighting coverage gaps and insurance questions around AI-driven failures – AI Insurance

Vulnerabilities & Exploitation

  • CISA added 7 exploited flaws to its watchlist as attackers deploy reverse shells and crypto miners, underscoring active exploitation across enterprise products – CISA Flaws
  • Sangoma Switchvox is under active attack, with exploitation of CVE-2026-9586 used to deliver reverse shells – Switchvox Flaw, Reverse Shells
  • Hackers are also exploiting a critical JFrog Artifactory flaw to forge admin tokens, putting artifact repositories at risk – JFrog Flaw
  • Nearly 22,000 Microsoft Exchange servers remain exposed to critical CVE-2026-62911, and a Rockwell Automation patch cycle fixed more than a dozen vulnerabilities across products – Exchange Flaw, Rockwell Patches
  • Plex urged users to patch newly disclosed security vulnerabilities immediately, amid broader concerns over fast-moving product flaws – Plex Patch
  • CrowdStrike Falcon was shown vulnerable by a new FalconFlank proof of concept demonstrating privilege escalation – FalconFlank PoC

Malware, Botnets & Spyware

  • A Russian national was indicted for a malware campaign that infected 80,000 freelancers, with reports saying he faces up to 20 years in prison – Freelance Malware, 20 Years
  • The long-running Russia-based Sality botnet was dismantled after a 23-year run, marking a major takedown of persistent malware infrastructure – Sality Botnet
  • Pegasus and a NoviSpy variant were found on devices used by Serbian activists, highlighting ongoing targeted spyware abuse – Spyware Found
  • Fake software installers were used to disable Windows Update and weaken Microsoft Defender, making compromise easier for follow-on malware – Fake Installers

Data Breaches & Exposure

  • More than 153 million driver license images were offered on the dark web, while a separate leak exposed health data for over 9.5 million people from the Aesto record system – Driver IDs, Aesto Leak
  • A record-system breach and other data exposure incidents continue to show the scale of identity and health-data risk across large platforms – Health Leak

Cloud, Web & Enterprise Security

  • Over 3 million WordPress sites were affected by a migration plugin vulnerability, and a separate backup plugin flaw exposed millions more to takeover attacks – WP Migration, WP Backup
  • Microsoft issues also hit day-to-day users, with a KB5120998 mouse reset bug affecting only non-English PCs and Teams/Outlook failing to launch on ARM-based Windows devices – KB5120998, ARM Apps

Policy & Infrastructure

  • The UK moved to block high-risk tech suppliers from critical infrastructure, while the FCC proposed a consumer rating approach for telecom anti-robocall protections – UK Policy, FCC Robocalls

Threat Intelligence

  • One report explored how ingesting malware intelligence at scale turns a threat feed into someone else’s database, emphasizing the operational burden of large-scale threat intel pipelines – Threat Feed

Cybersecurity News | Daily Recap – hendryadrian.com