MyCyber News
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Last feed pull: Sep 6, 2026, 1:12 AM (UTC+3)
Latest stories
Healthcare Services
Spirit Cultural Exchange is a U. S. -based organization that provides international cultural exchange and J-1 visa programs for students, young professionals, teachers, and international participants. Its programs include Summer Work and Travel, internships, professional training, and teaching opportunities in the United States
OpenAI pledges $1B in subsidized Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. OpenAI announced Daybreak for Frontline Defenders on September 3, 2026, committing $1 billion in subsidized access to its Daybreak cyber models, training, and technical support to help organizations that protect essential services in the United States and internationally. “A $1 billion global commitment to expand subsidized access to Daybreak cyber models and products, training, technical support, and partnerships in the United States and internationally. ” reads the announcement The full announcement is at openai. com. The $1 billion is product credits and subsidized access, not a cash grant, targeted to be used over the next six months.
Rhysida in Germany - From an Early Ransomware Payload to the 2026 Stuttgart and Berlin Threat Landscape Technical analysis, threat profiling, and hunting opportunities for the Vanilla Tempest / Rhysida ecosystem In May 2026, Rhysida listed the city of Stuttgart on its data-leak site and demanded 5 BTC. Three months later, Berlin disclosed a significantly more serious compromise of parts of its state administration, with confirmed data exfiltration occurring before affected systems were disconnected from the Berlin state network. The technical details publicly available for the two incidents are very different. Stuttgart initially stated that it had no evidence confirming a cyber incident. The Rhysida leak-site entry therefore has to be treated as an attacker claim rather than proof of a particular intrusion chain.
CVE ID : CVE-2026-67278 Published : Sept. 5, 2026, 8:17 p. m. • 28 minutes ago Description : MikroTik RouterOS accepts malformed RSA/PKCS#1 v1. 5 signatures during X. 509 validation. Because its trust store includes an e=3 root CA, an attacker controlling or redirecting an outbound RouterOS TLS connection can use the root’s public certificate - without its private key - to forge a trusted intermediate and issue certificates for arbitrary hostnames, enabling TLS server impersonation. This issue was fixed in versions: 6. 49. 21 (Lont-term), 7. 23. 4 (Lont-term) and 7. 24. 2 (Stable) Severity: 6.3 • MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-67281 Published : Sept. 5, 2026, 8:17 p. m. • 27 minutes ago Description : RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization. An unauthenticated attacker can prepare the allocator so that the file-serving path dereferences this pointer with sufficient rights, then supply parent-directory components in an encrypted URI to escape the WebFig file namespace and disclose root-owned files, including configuration stores containing credentials. This issue was fixed in versions: 6. 49. 21 (Lont-term), 7. 23. 4 (Lont-term) and 7. 24. 2 (Stable) Severity: 8.7 • HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-86206 Published : Sept. 5, 2026, 8:17 p. m. • 27 minutes ago Description : A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026. 3 HF3 and 2026. 4 Severity: 6.9 • MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-67279 Published : Sept. 5, 2026, 8:17 p. m. • 27 minutes ago Description : RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request. On affected builds the server dispatches the command, enabling unauthenticated creation, overwrite, and reconstruction of files in the RouterOS managed file namespace, including support files containing configuration and diagnostic data. This issue was fixed in versions: 6. 49. 21 (Lont-term), 7. 23. 4 (Lont-term) and 7. 24. 2 (Stable) Severity: 6.9 • MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-67277 Published : Sept. 5, 2026, 8:17 p. m. • 28 minutes ago Description : RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer. A separate unchecked, inverted packet-size interval causes unsigned integer underflow, anomalously large fragmented output, and can restart the RouterOS kernel. This issue was fixed in versions: 6. 49. 21 (Lont-term), 7. 23. 4 (Lont-term) and 7. 24. 2 (Stable) Severity: 8.8 • HIGH
CVE ID : CVE-2026-86060 Published : Sept. 5, 2026, 8:17 p. m. • 27 minutes ago Description : RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper. This issue was fixed in versions: 6. 49. 21 (Lont-term), 7. 23. 4 (Lont-term) and 7. 24. 2 (Stable) Severity: 9.2 • CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-67276 Published : Sept. 5, 2026, 8:17 p. m. • 28 minutes ago Description : RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key. This issue was fixed in versions: 6. 49. 21 (Lont-term), 7. 23. 4 (Lont-term) and 7. 24. 2 (Stable) Severity: 9.2 • CRITICAL Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
Introduction Xloader is a stealer that was built on the FormBook malware family that first emerged in 2016; the rebranded Xloader was introduced in 2020. It is highly sophisticated malware that uses a combination of anti-analysis and obfuscation techniques, and it’s written in pure assembly, so there are minimal compiler artifacts. The infection chain used in this campaign is widely used to deliver multiple different malware families in a very similar way, with almost identical loader characteristics. The road to Xloader - d01a
CVE ID : CVE-2026-86207 Published : Sept. 5, 2026, 7:16 p. m. • 1 hour, 28 minutes ago Description : An authentication bypass in N-central Severity: 7.7 • HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-6554 Published : Sept. 5, 2026, 7:16 p. m. • 1 hour, 28 minutes ago Description : libpcap BPF interpreter treats the offset in the 'ja L' BPF instruction as a signed integer to implement looping via backward jumps, but it does not limit the number of loop iterations. In particular uncommon use cases a crafted filter program can cause the interpreter to loop infinitely. Severity: 5.5 • MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-31911 Published : Sept. 5, 2026, 7:16 p. m. • 1 hour, 28 minutes ago Description : libpcap BPF interpreter calls abort() if it encounters a BPF instruction that has an invalid opcode. In particular uncommon use cases a crafted filter program can terminate the OS process. Severity: 5.5 • MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-6244 Published : Sept. 5, 2026, 7:16 p. m. • 1 hour, 28 minutes ago Description : libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions does not check whether the immediate value is zero. In particular uncommon use cases a crafted filter program can cause a division by zero. Severity: 5.5 • MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-31912 Published : Sept. 5, 2026, 7:16 p. m. • 1 hour, 28 minutes ago Description : libpcap BPF interpreter detects neither reaching the end of the filter program buffer due to lack of a return instruction nor executing a jump instruction with an offset that translates to a pointer outside of the buffer. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading the OS process memory in the 32GiB around the buffer on 64-bit architectures and in the entire address space on 32-bit architectures. Severity: 5.5 • MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-18238 Published : Sept. 5, 2026, 7:16 p. m. • 1 hour, 28 minutes ago Description : The rpcap client code that processes a RPCAP_MSG_PACKET message received from the server incorrectly validates its headers. A malicious server can send a crafted message and cause the client to treat up to 20 bytes of the client process memory beyond the end of the buffer as if it was a part of the captured packet. Severity: 5.0 • MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-0799 Published : Sept. 5, 2026, 7:16 p. m. • 1 hour, 28 minutes ago Description : In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures. Severity: 8.7 • HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE ID : CVE-2026-18313 Published : Sept. 5, 2026, 7:16 p. m. • 1 hour, 28 minutes ago Description : rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_REQ or RPCAP_MSG_STARTCAP_REQ message received from the client, but it never frees the memory, so it leaks memory even under normal use. A malicious client can cause the server to leak memory substantially faster. Severity: 4.3 • MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U. S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078 , in attacks targeting schools and other education organizations in the U. S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed threat actors chaining an authentication bypass with remote code execution to run commands, perform reconnaissance and create privileged accounts. The activity shows how quickly attackers can turn newly disclosed vulnerabilities into real-world attacks, putting sensitive credentials and systems at risk.
leoschachter. com Leo Schachter Diamonds (USA/Global) Family diamond house since 1952, four generations; De Beers sightholder for 60+ years. Invented the branded diamond (THE LEO at Kay/Jared, ~2,000 stores) — a diamond sold like a Nike sneaker. Owns one of Botswana's largest cutting factories: 90% women, trained from scratch, plus its own doctor when 60% of staff were HIV-positive. Crisis context: lab-grown diamonds are squeezing the whole natural industry — the moat is now brand + story, not just stones.
karierazdrowit. pl zoominfo. com/c/zdrowit/535531700 Zdrowit S. A. is a family-owned Polish pharmacy chain with 100% Polish capital, operating since 2004 and headquartered in Bytom, Silesia, with over 1,000 employees across 40+ cities in southern and central Poland, aiming to become the largest pharmacy network in the region. The business is growing extremely fast, with 2024 net sales revenue up +83. 5%, though its net profit margin fell 10. 3% due to the costs of rapid expansion. The company is structured as a holding: individual pharmacies operate as separate Sp. z o. o. entities under Zdrowit S. A. , which is registered under KRS 0000704305 with a share capital of 1,197,432. 00 PLN. Its core workforce consists of pharmacists and pharmacy technicians hired across dozens of locations, supported by a small modern HQ team in Bytom covering data, IT, controlling and marketing.
veradigm. com zoominfo. com/c/veradigm-llc/471134180 3. 5+ million personal patient records with PII full name, address, social security number, email, address, phone number,guarantors PII ,Score Veradigm Inc. is a publicly traded American healthcare technology and data analytics company (OTC: MDRX), the former Allscripts, founded in 1986 and renamed Veradigm in January 2023, headquartered in Chicago with about 2,300–2,600 employees. Its core asset is one of the largest multi-EHR data networks in US healthcare — over 450,000 connected providers and 200M+ patient records — which it monetizes through three segments: Provider (EHR, practice management, revenue cycle: $473M in 2024), Payer (quality and risk adjustment analytics: $67. 3M) and Life Sciences (real-world data and AI-driven evidence: $54M).
lideraviacao. com. br zoominfo. com/c/líder-aviação/372493800 Líder Aviação is Latin America's largest business aviation company, founded in 1958 in Belo Horizonte, Brazil, as an air taxi with a single Cessna 170. Today: ~R$1. 2B revenue, 1,300+ staff, 50+ aircraft, 22 own bases; 42. 5% owned by US Bristow Group, run by the founder's third generation (President: Junia Hermont). A one-stop shop: charters (first booking app in Brazil), the region's largest FBO network, aircraft sales (exclusive HondaJet dealer, 1,000+ sold), a top MRO (authorized for Bell, HondaJet, Gulfstream) and offshore helicopter ops for Petrobras since 1973 (1M+ flight hours). Key edge: safety — the only Brazilian company with IS-BAO Stage 3, plus Argus Platinum and 5× Petrobras Peotram wins. First SAF flight in Brazilian business aviation (2024), now expanding into agribusiness and electric aviation.
Waqas reports: French authorities have detained an 18-year-old man suspected of belonging to ZeroBytes, a hacking group that claimed responsibility for several attacks targeting French government services and companies. The Paris prosecutor’s office disclosed the case on September 4, according to reports from French media. However, the suspect was arrested on August 18, formally placed… Source https://databreaches.net/2026/09/05/french-police-arrest-suspected-zerobytes-hacker-over-tax-data-theft/1post-1participantReadfulltopic
CVE ID : CVE-2026-82752 Published : Sept. 5, 2026, 6:17 p. m. • 2 hours, 27 minutes ago Description : Improper Validation of Specified Quantity in Input vulnerability in ash-project ash allows an attacker to store a value of arbitrary size in an attribute whose length constraint should bound it. Ash measures string length with Elixir's String. length/1, which counts Unicode graphemes, in the max_length and min_length constraints of Ash. Type. String (apply_constraints/2 in lib/ash/type/string. ex), in Ash. Resource. Validation. StringLength, and in the string_length expression function. A grapheme carries an unbounded number of combining marks, so a base character followed by a million combining acute accents is one grapheme and megabytes of data, and satisfies max_length: 2.
New Delhi–based private technology company incorporated in 2013. Its registered business classification is software publishing, consultancy and supply, including software development, maintenance and web-page design. Its network records also identify MEGA VELOCITY PVT LTD as an Internet/hosting network operator.
Meta AI glasses lawsuit widens over bystander recordings Cybernews
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A
CyberKendra reports: A security researcher known as Chaotic Eclipse has released FalconFlank, a proof-of-concept zero-day that escalates privileges on fully patched Windows machines running CrowdStrike Falcon. The researcher — who also uses the aliases Nightmare-Eclipse, MSNightmare, and INFINITE NIGHTMARE — published working exploit code to GitHub on September 3, 2026, without giving CrowdStrike advance notice. No CVE ID… Source https://databreaches.net/2026/09/05/falconflank-zero-day-hits-crowdstrike-falcon-sensor/1post-1participantReadfulltopic
Citizens Pay (also known as CTZPay) is a mobile digital wallet and payment platform in Myanmar powered by Myanmar Citizens Bank (MCB) and Capital Connect Limited. Compromised agent user information — total data size 30 GB. Price range $7,000 to $25,000. Victim domain https://ctzpay. com
From the porch to the nursery, Blurams has your home security needs covered.
Home National Institute of Standards and Technology (.gov)
NVIDIA continues building out more functionality around the open-source, upstream Nova kernel graphics driver within the Linux kernel. Making it out to the mailing list this Saturday is a set of 13 patches for introducing a NVIDIA vGPU manager and VFIO variant driver...
A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [... ]
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U. S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets
N/A