1. SonicWall SMA1000 zero-days chained for pre-auth remote code execution — CVE-2026-83548, CVE-2026-83549 — SecurityWeek — https://www.securityweek.com/sonicwall-warns-of-two-sma1000-zero-days-exploited-in-attacks/
2. JFrog Artifactory authentication bypass exploited four days after the patch — CVE-2026-82329 — SC World — https://www.scworld.com/news/jfrog-artifactory-flaw-exploited-days-after-patch-release
3. Langflow remote code execution used to harvest OpenAI and AWS keys — CVE-2026-0768 — BleepingComputer — https://www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/
4. Twenty-two thousand Exchange servers still unpatched against a mailbox takeover flaw — CVE-2026-62911 — BleepingComputer — https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/
5. AI agents ran a full ransomware intrusion in under ten hours — Unit 42 — https://unit42.paloaltonetworks.com/ai-assisted-cyber-attack-inside-a-unit-42-investigation/
6. FBI warns of consent phishing that takes an account without a password — CyberScoop — https://cyberscoop.com/fbi-alert-oauth-consent-phishing-campaign/
7. Sangoma Switchvox SQL injection is being exploited seven weeks after the fix — CVE-2026-9586 — The Hacker News — https://thehackernews.com/2026/09/attackers-exploit-critical-switchvox.html
8. GeoNetwork chain gives unauthenticated code execution on government geoportals — CVE-2026-63219 — The Hacker News — https://thehackernews.com/2026/09/geonetwork-fixes-unauthenticated-rce.html
9. Counterfeit software download sites are installing malware that turns Defender off — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/09/01/counterfeit-installers-system-compromise-tracking-deceptive-software-download-campaign/
10. Phishing crew abuses a real endpoint-management platform to install ScreenConnect — BleepingComputer — https://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect/
11. Airport breach traced to admin keys sitting in the websites' own JavaScript — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/fulcrumsec-manchester-airport/
12. Stolen API key burned 600,000 dollars of model credits before anyone noticed — The Register — https://www.theregister.com/security/2026/09/01/attacker_stole_a_metr_api_key_used_600k_worth_of_credits_and_no_one_noticed_for_weeks/5293730
13. Hugging Face Transformers writes remote code to disk before asking permission — CVE-2026-80047 — CERT/CC — https://kb.cert.org/vuls/id/456290
14. SageMaker SDK leaves its signing key in cleartext where any account role can read it — CVE-2026-83551 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-093-aws/
15. Thirteen poisoned Composer packages on Packagist attack visitors of the sites that install them — CVE-2025-31277, CVE-2025-43398, CVE-2025-43510, CVE-2025-43520, CVE-2025-43529 — The Hacker News — https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html
16. Attackers are installing Apache modules that quietly proxy visitors to phishing pages — Check Point Research — https://research.checkpoint.com/2026/gaming-the-system-how-a-chinese-speaking-actor-turned-brazilian-government-sites-into-an-seo-weapon/