Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    InfoSec News Nuggets – 09/03/2026 – AboutDFIR

    September 3, 2026

    Microsoft: KB5120998 mouse reset bug affects only non-English PCs

    September 3, 2026

    Your Employee’s Password Appeared in an Infostealer Log. Now What?

    September 3, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»InfoSec News Nuggets – 09/03/2026 – AboutDFIR
    News

    InfoSec News Nuggets – 09/03/2026 – AboutDFIR

    adminBy adminSeptember 3, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

    A critical authentication bypass flaw in JFrog Artifactory, tracked as CVE-2026-82329 and carrying a CVSS score of 9.8, is being actively exploited to mint fraudulent admin tokens on self-managed instances running in their default configuration. Researchers observed attackers gaining administrative permissions without authentication, a foothold that could let them enumerate users and groups, alter security settings, and poison software artifacts trusted by downstream CI/CD pipelines. The vendor patched the issue on August 28 across several version branches, but because access tokens remain valid independent of the binary upgrade, organizations need to actively revoke old tokens rather than assume patching alone closes the exposure.
     

    Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

    Eight security flaws disclosed across seven command-line AI coding agents show that a repository’s own Git configuration can trigger command execution the moment an agent inspects it, often before any trust prompt is shown or the user has typed a single word. The issue centers on core.fsmonitor, a legitimate Git performance setting that agents query in the background to check branch and file status, letting a booby-trapped repository run code outside the tool’s sandbox and without approval. Fixes have shipped for goose, Claude Code, and Cursor, while Hermes Agent, Qwen Code, Grok Build, and a second execution path in Claude Code remained exploitable as of the most recent testing, underscoring how ordinary developer tooling plumbing has become a fresh attack surface for AI-assisted coding.
     

    Critical SonicWall SMA 1000 Flaws Enable Unauthenticated RCE

    Attackers are actively exploiting two newly disclosed zero-day vulnerabilities in SonicWall SMA 1000 series appliances that can be chained together for unauthenticated remote code execution. A maximum-severity server-side request forgery bug in the user-facing Work Place interface can be combined with a separate OS command injection flaw in the administrative console to hand an attacker full control of the device. SonicWall confirmed active exploitation in the wild and is urging customers running the affected 6210, 7210, and 8200v models to apply the released firmware immediately, check for indicators of compromise, and, if found, re-image hardware and reset all credentials, since these internet-facing edge devices have repeatedly proven attractive targets in recent years.
     

    Extortion Group Claims Manchester Airports Group Data Breach

    The extortion group FulcrumSec has claimed responsibility for stealing roughly 86 gigabytes of customer data from Manchester Airports Group, which owns Manchester, London Stansted, and East Midlands airports. The stolen information, pulled from a third-party-hosted database tied to car park, lounge, and Fast Track bookings as well as in-airport Wi-Fi sign-ups, includes email addresses, phone numbers, vehicle registrations, and postcodes, though no payment details were exposed. The airport operator refused a ransom demand, and while airport operations and passenger safety were unaffected, the group is reportedly moving to leak the data online after the failed extortion attempt.
     

    Over 5,000 Dropbox accounts have been hacked, and the attackers only needed an email address

    Roughly 5,000 Dropbox accounts were compromised after attackers discovered they could exploit a flaw in Lenovo’s email verification process to register a fraudulent Lenovo ID using nothing more than a victim’s email address, then use that identity to log into the associated Dropbox account without a password. The intrusion, which ran from August 4 to 21, succeeded largely because none of the affected accounts had two-factor authentication enabled, and in roughly a third of cases attackers viewed or downloaded stored files. Dropbox has since severed the Lenovo ID login integration, expired all sessions created through it, and now requires a Dropbox password even when signing in via Lenovo, while urging affected users to change passwords and enable multi-factor authentication.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleMicrosoft: KB5120998 mouse reset bug affects only non-English PCs
    admin
    • Website

    Related Posts

    News

    Microsoft: KB5120998 mouse reset bug affects only non-English PCs

    September 3, 2026
    News

    Your Employee’s Password Appeared in an Infostealer Log. Now What?

    September 3, 2026
    News

    Plex warns users to patch security vulnerabilities immediately

    September 3, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202677 Views

    How fraudsters target credit unions

    May 4, 202643 Views

    IP Address Investigations and Local OSINT

    March 20, 202640 Views
    Our Picks

    InfoSec News Nuggets – 09/03/2026 – AboutDFIR

    September 3, 2026

    Microsoft: KB5120998 mouse reset bug affects only non-English PCs

    September 3, 2026

    Your Employee’s Password Appeared in an Infostealer Log. Now What?

    September 3, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.