📡 Tech & Security Digest — 2026-09-03
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Hackers exploit Sangoma Switchvox flaw to deploy reverse shells — Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead t…
- Hackers exploit critical JFrog Artifactory flaw to forge admin tokens — A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide admin…
- Critical Langflow flaw exploited to steal OpenAI and AWS keys — Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building…
- SonicWall warns of actively exploited SMA1000 zero-day flaws — SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. […]…
- Dropbox accounts breached through Lenovo email verification flaw — Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo’s email verification process to regist…
Hacker News
- Six curl CVEs after OpenAI and Anthropic came back with zero (167 pts)
- Using Cloudflare Workers and reCAPTCHA v3 for a Static Site Contact Form (36 pts)
- Paint.net 5.2 alpha now runs on Linux (194 pts)
The Hacker News
- OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face — OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, add…
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure — Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watc…
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication — Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company…
- Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain — SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have be…
- Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server — cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which cou…
- PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions — PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print…
- Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE — Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow…
- Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials — Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remot…
- CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) …
- Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity — Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck.
The vulnerabilities i…