Breaking News – Cyber Threats – 2026-09-01 13:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-01 13:00 PDT
- Aesto Health says data breach affects over 9.5 million patients
BleepingComputer • 2026-09-01 12:28 • www.bleepingcomputer.com
Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. […]
https://www.bleepingcomputer.com/news/security/aesto-health-says-data-breach-affects-over-95-million-patients/ - Critical Langflow flaw exploited to steal OpenAI and AWS keys
BleepingComputer • 2026-09-01 10:54 • www.bleepingcomputer.com
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. […]
https://www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/ - Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
The Hacker News • 2026-09-01 10:53 • thehackernews.com
Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr.The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory.
“JFrog Artifactory contains an authentication weakness that, under default
https://thehackernews.com/2026/09/attackers-exploit-critical-jfrog.html - What’s the Scam?
Schneier on Security • 2026-09-01 10:36 • www.schneier.comTo subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent people from subscribing addresses other than their own.
Starting last weekend, I have been receiving a lot of individual responses to those emails. Always one line:
Thank you for the positive impact your emails have had on my life.
Your emails are a game-changer.
Your emails are a constant reminder of why I subscribed.
Your emails rock.
Thank you for the time and…
https://www.schneier.com/blog/archives/2026/09/whats-the-scam.html - Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
The Hacker News • 2026-09-01 10:19 • thehackernews.com
Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024.Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as “specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers.” The adversary
https://thehackernews.com/2026/09/breeze-comet-executes-hundreds-of.html - Leaked Russian Cyber-Operations Training Materials
Schneier on Security • 2026-09-01 09:29 • www.schneier.comThis is interesting:
The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security.
[…]
The reporting also linked a 2024 Department No. 4 graduate, Aleksei Kondrashov, to Military Unit 74455, widely known as Sandworm.
That unit has been associated with destructive cyber activity against Ukraine and o…
https://www.schneier.com/blog/archives/2026/09/leaked-russian-cyber-operations-training-materials.html - Hackers push malicious Virtualizor update in BGP hijacking attack
BleepingComputer • 2026-09-01 07:45 • www.bleepingcomputer.com
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. […]
https://www.bleepingcomputer.com/news/security/hackers-push-malicious-virtualizor-update-in-bgp-hijacking-attack/ - Novocure data breach affects more than 1,400 cancer patients
BleepingComputer • 2026-09-01 07:28 • www.bleepingcomputer.com
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. […]
https://www.bleepingcomputer.com/news/security/novocure-data-breach-affects-more-than-1-400-cancer-patients/ - 13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
The Hacker News • 2026-09-01 07:07 • thehackernews.com
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices.“The injected code runs two operations against a site’s visitors: a mobile ad-fraud and gambling-redirect
https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html - Why Even the Best Edge Security Still Misses High-Risk Sessions
BleepingComputer • 2026-09-01 07:01 • www.bleepingcomputer.com
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisions. […]
https://www.bleepingcomputer.com/news/security/why-even-the-best-edge-security-still-misses-high-risk-sessions/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.