Breaking News – Cyber Threats – 2026-09-02 03:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-02 03:00 PDT
- GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
The Hacker News • 2026-09-02 02:18 • thehackernews.com
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals.The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31.
GeoNetwork originated at the United Nations Food and
https://thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html - Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
The Hacker News • 2026-09-02 02:10 • thehackernews.com
The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017.Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025, the U.S. Attorney’s Office for the Northern District of California
https://thehackernews.com/2026/09/extradited-russian-hacker-faces-charges.html - US charges Russian for infecting 80,000 freelancers with malware
BleepingComputer • 2026-09-02 02:06 • www.bleepingcomputer.com
A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. […]
https://www.bleepingcomputer.com/news/security/us-charges-russian-for-infecting-80-000-freelancers-with-malware/ - Sality botnet infrastructure dismantled in joint global takedown
BleepingComputer • 2026-09-02 01:00 • www.bleepingcomputer.com
International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. […]
https://www.bleepingcomputer.com/news/security/sality-botnet-infrastructure-dismantled-in-joint-global-takedown/ - Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
The Hacker News • 2026-09-02 00:47 • thehackernews.com
Forescout Research – Vedere Labs said it used Anthropic’s Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware.The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server’s handling of the USER command
https://thehackernews.com/2026/09/researchers-use-claude-to-port-pre-auth.html - Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials
The Hacker News • 2026-09-02 00:08 • thehackernews.com
Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution.The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as
https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html - Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads
The Hacker News • 2026-09-01 23:56 • thehackernews.com
The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation.The effort was undertaken on August 31, 2026, by authorities from the U.S., Bulgaria, Hungary, and Romania, in collaboration with private industry partners CrowdStrike and the Shadowserver Foundation. To that
https://thehackernews.com/2026/09/authorities-turn-salitys-p2p-network.html - SonicWall warns of actively exploited SMA1000 zero-day flaws
BleepingComputer • 2026-09-01 23:39 • www.bleepingcomputer.com
SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. […]
https://www.bleepingcomputer.com/news/security/sonicwall-warns-of-actively-exploited-sma1000-zero-day-flaws/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.