1. OpenSearch SQL plugin deserialization flaw gives a read-only user code execution — CVE-2026-83497 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-092-aws/
2. BGP hijack pushed a malicious Virtualizor update onto hypervisor management servers — Virtualizor — https://www.virtualizor.com/blog/security-incident-bgp-hijacking/
3. McKesson breach ran from vishing calls through Okta into Salesforce and Snowflake — SC World — https://www.scworld.com/brief/mckesson-discloses-data-breach-after-shinyhunters-claims-theft-of-284-million-records
4. Password-spraying campaign hit AWS root accounts at more than 150 organizations — Datadog Security Labs — https://securitylabs.datadoghq.com/articles/aws-root-user-bruteforce-campaign/
5. Scanners are forging AI-crawler user agents to hunt for exposed credentials — Help Net Security — https://www.helpnetsecurity.com/2026/08/31/ai-crawlers-scan-exposed-credentials/
6. A honeypot posing as a free LLM endpoint caught a real coding agent handing over its tools — SANS ISC — https://isc.sans.edu/diary/rss/33298
7. Mirage Kitten hides two new cross-platform RATs in trojanized coding-challenge archives — Securelist — https://securelist.com/mirage-kitten-new-backdoors-noderabbit-pollcat/121244/
8. Researcher drops a working privilege-escalation exploit for Kaspersky Endpoint Security — SecurityWeek — https://www.securityweek.com/nightmare-eclipse-drops-hardbreacher-kaspersky-product-exploit/
9. Residential proxy networks rent out home connections with clean IP reputations — Ars Technica — https://arstechnica.com/security/2026/08/how-some-media-streaming-devices-open-home-networks-to-a-world-of-harm/
10. BREEZE COMET manipulates Brazilian banking software to move fraudulent transfers — Google Threat Intel — https://cloud.google.com/blog/topics/threat-intelligence/financially-motivated-threat-actor-breeze-comet-targets-brazil/
11. Guildma delivery is geofenced to Brazil and hides its payload in an alternate data stream — SANS ISC — https://isc.sans.edu/diary/rss/33300
12. Boston Scientific outage leaves newly implanted heart devices without remote monitoring — The Register — https://www.theregister.com/cyber-crime/2026/08/31/healthcare-cyberattacks-hit-pacemakers-and-millions-of-patient-records/5293537
13. OpenClaw 2.0 makes the agent harness easier to install and leaves security to the user — The Register — https://www.theregister.com/ai-and-ml/2026/08/31/openclaw-20-pours-glitter-on-slow-burning-security-dumpster-fire/5293492
14. CrowdSec 1.8.0 ships two denial-of-service fixes alongside new bot detection — Help Net Security — https://www.helpnetsecurity.com/2026/09/01/crowdsec-1-8-0-bot-detection/