Daily DefSec Brief
Daily DefSec Brief
Daily DefSec Brief·Sep 4, 2026·5m

Cyber Security News for September 4 2026 - Daily DefSec Brief

Show notes

1. Chrome patches a V8 zero-day that attackers are already using — CVE-2026-85046 — The Hacker News — https://thehackernews.com/2026/09/google-releases-chrome-update-to-patch.html
2. Coder's package registry served Terraform modules that steal credentials (malicious modules served 07:35–21:45 UTC, Mon 31 Aug, advisory GHSA-vx42-ghc9-gw65) — BleepingComputer — https://www.bleepingcomputer.com/news/security/coders-registry-infrastructure-compromised-to-push-malicious-modules/
3. HPE patches unauthenticated code execution in ArubaOS-CX switches (fixed in 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, 10.10.1181) — CVE-2026-73749 — BleepingComputer — https://www.bleepingcomputer.com/news/security/hpe-patches-critical-arubaos-cx-remote-code-execution-flaw/
4. Casdoor lets one tenant's admin act on every other tenant, with no patch available (3.115.0 and earlier) — CVE-2026-15630 — CERT/CC — https://kb.cert.org/vuls/id/889462
5. Cisco ships seven IOS XR flaws as one hardening release (no fixed release, upgrade to a release with SMUs, then apply them) — CVE-2026-20274, CVE-2026-20279 — Cisco PSIRT — https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM
6. Phishing hides lure words from email filters with invisible Unicode (strip U+E0000–U+E007F before applying signatures) — Microsoft Security — https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/
7. AWS patches command injection in the CodeCatalyst blueprints framework (@amazon-codecatalyst/blueprints.blueprint before 0.3.156) — CVE-2026-85012 — AWS Security Bulletin — https://aws.amazon.com/security/security-bulletins/rss/2026-095-aws/
8. A China-linked espionage crew is running its intrusions through AI agents — Security Affairs — https://securityaffairs.com/198417/ai/chinese-hackers-use-ai-agents-in-multi-country-cyber-campaign.html
9. BraZetsu packages a compromised Windows host into something an access broker can sell — The Hacker News — https://thehackernews.com/2026/09/brazetsu-malware-turns-compromised.html
10. Toy Ghouls runs its new backdoor's command channel over HiveMQ and Element — Securelist — https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/
11. Fourteen fake macOS installers deliver the OtterCookie remote access trojan — Jamf Threat Labs — https://www.jamf.com/blog/contagious-interview-trojanized-macos-installers/
12. A phishing kit produced 700 new pages in the month after its servers were seized — Infosecurity Magazine — https://www.infosecurity-magazine.com/news/outsider-phishing-kit-survives/
13. The 153 million driver's licence scans have a suspected source — Security Affairs — https://securityaffairs.com/198388/security/dark-web-service-nexus-sells-153m-drivers-licenses.html
14. Thomson Reuters breach exposed sealed court records across eleven states — The Hacker News — https://thehackernews.com/2026/09/thomson-reuters-court-software-breach.html
15. A fake acquisition, a forged NDA, and instructions not to tell your colleagues — Dark Reading — https://www.darkreading.com/cyberattacks-data-breaches/large-enterprises-fake-merger-acquisition-scams
16. An AI found 23,000 vulnerabilities and nobody has looked at 21,000 of them — Help Net Security — https://www.helpnetsecurity.com/2026/09/04/echo-claude-mythos-vulnerability-findings/