🚨 CISA KEV 1[−]
3 Sep KEVCISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto MinersThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows - CVE-2026-83548 (CVSS score: 10.0) - A ser…THEHACKERNEWS.COM
⚠️ VULNERABILITY DISCLOSURE 4[−]
3 SepFlipping AI’s kill switch.This week, Dave and Ben look at two major AI stories. The first involves Anthropic winning one of its legal challenges regarding the Pentagon designating the company as a supply chain risk. The second story looks at a recent law introduced in Congress that seeks to give CISA the …THECYBERWIRE.COM
3 SepI just want to give you $25 million!This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner…THECYBERWIRE.COM
3 SepSrsly Risky Biz: China's botnets are worth disruptingTom Uren and James Wilson talk about China’s long-term shift to getting private companies to build botnets for cyberespionage. A disruption effort from the US this week is good news, but China has been using these networks for a surprisingly long time and will rebuild. They also …RISKY.BIZ
3 SepResearcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike FalconThe security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0day privilege escalation that abuses the offic…THEHACKERNEWS.COM
🕵️ THREAT INTELLIGENCE 4[−]
3 SepISC Stormcast For Thursday, September 3rd, 2026 https://isc.sans.edu/podcastdetail/10080, (Thu, Sep 3rd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
3 SepWindows memory integrity switches on automatically for eligible devices in October 2026Beginning in October 2026, Windows quality updates start enabling memory integrity protection on eligible devices with little or no additional configuration. On machines where Virtualization-based Security is not already running, those same updates enable VBS too. Memory integrit…HELPNETSECURITY.COM
3 SepYour threat feed is someone else’s database: What ingesting malware intel at scale takesThe advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody mentions you is the operating manual, because the access was never the hard part. A threat feed is someone…HELPNETSECURITY.COM
3 SepWhen AI quietly breaks things, who pays?David Halbreich, an insurance recovery partner at Reed Smith, breaks down how AI companies should handle coverage gaps that come up as the industry grows. He covers straddle claims that fall between tail and go-forward D&O policies after a merger, how governance disclosures …HELPNETSECURITY.COM
📡 INFOSEC NEWS 1[−]
3 SepHoneypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program]
ISC.SANS.EDU