Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Sep 3, 2026·4m

Cyber Security News for September 3 2026 - Daily DefSec Brief

Show notes

1. Kestra workflow engine lets anyone run commands with no credentials at all — CVE-2026-49869 — CISA KEV — https://www.cisa.gov/known-exploited-vulnerabilities-catalog
2. GitSpawn lets a repository's own config run commands through your AI coding agent — CVE-2026-19592, CVE-2026-55607, CVE-2026-71963, CVE-2026-72718 — Manifold Security — https://www.manifold.security/blog/ai-coding-agents-git-hijack
3. Cisco Nexus 9000 switches take unauthenticated code execution as root — CVE-2026-20212 — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-notice-f2SiMFxl
4. LiteLLM accepts any bearer token as a valid MCP session — CVE-2026-59822 — BerriAI advisory — https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q
5. BadHost defeats authentication anywhere Starlette rebuilds the URL — CVE-2026-48710 — CCB Belgium — https://ccb.belgium.be/advisories/warning-vulnerability-starlette-framework-and-related-frameworks-fastapi-exposes
6. Exploit published for a Cleo Harmony authentication bypass — CVE-2026-84115 — SecurityWeek — https://www.securityweek.com/exploit-published-for-fresh-cleo-harmony-vulnerability/
7. Dropbox accounts opened through a flaw in Lenovo's email verification — BleepingComputer — https://www.bleepingcomputer.com/news/security/dropbox-accounts-breached-through-lenovo-email-verification-flaw/
8. Fake IT support on Teams now ends in a Node.js implant and hands-on-keyboard access — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/09/02/impersonating-it-support-threat-actors-turn-remote-session-into-enterprise-wide-access/
9. The Gentlemen ransomware turns off EDR and backups before encrypting — Cyber Security News — https://cybersecuritynews.com/the-gentlemen-ransomware/
10. Researcher publishes a CrowdStrike Falcon privilege-escalation exploit — Security Affairs — https://securityaffairs.com/198342/hacking/chaotic-eclipse-releases-crowdstrike-falcon-zeroday-falconflank.html
11. Windows starts switching memory integrity on by itself in October — Help Net Security — https://www.helpnetsecurity.com/2026/09/03/windows-memory-integrity-update/
12. One AI model completed a full cyber kill chain on its own in Booz Allen's tests — The Register — https://www.theregister.com/security/2026/09/02/claude-mythos-only-model-to-complete-full-cyber-kill-chain-experts-say/5294071
13. Attackers are self-hosting a chat interface on the infrastructure they compromise — Unit 42 — https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/
14. Chrome ships 26 fixes including two critical use-after-free bugs — CVE-2026-84352, CVE-2026-84353 — SecurityWeek — https://www.securityweek.com/chrome-and-firefox-updates-patch-dozens-of-vulnerabilities/
15. Teams and Outlook fail to launch on ARM Windows after the August updates — BleepingComputer — https://www.bleepingcomputer.com/news/microsoft/microsoft-teams-outlook-fail-to-launch-on-arm-based-windows-pcs/
16. A hundred and fifty-three million driver's licence scans are for sale — Ars Technica — https://arstechnica.com/security/2026/09/my-drivers-license-is-one-of-153-million-for-sale-on-a-new-dark-website/