📡 Tech & Security Digest — 2026-09-04
Curated from Hacker News, security blogs, and tech publications.
BleepingComputer
- Critical Elementor Pro flaw exploited to take over WordPress sites — A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webs…
- Hackers exploit Sangoma Switchvox flaw to deploy reverse shells — Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead t…
- Hackers exploit critical JFrog Artifactory flaw to forge admin tokens — A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide admin…
Hacker News
- Hackers Had a Live Feed of Every ID Verification Company Scanned for over a Year (138 pts)
- Ask HN: Why were OpenAI, Claude, and Grok simultaneously down? (373 pts)
- OpenAI’s GPT-6 Astra on ARC-AGI-3 (210 pts)
Krebs on Security
- Two Alleged ‘TeamPCP’ Hackers Arrested in Australia — Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrati…
- Microsoft Plugs Nearly 400 Security Holes — Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including on…
- Microsoft Patches a Record 570 Security Flaws — Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple…
- Felons, Fraudsters Flog Offensive Cybersecurity Startup — A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right co…
The Hacker News
- Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day — Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild.
The high…
- Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure — Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watc…
- Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication — Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company…
- Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain — SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have be…
- Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws — Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence.
Th…
- Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials — Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remot…
- CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) …
- Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity — Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck.
The vulnerabilities i…
- ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions — The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running t…
- Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable — Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between…