A sample of recently analyzed articles from 30+ sources. Updated hourly.
Sep 03, 2026
AI Summary
Google GTIG and Mandiant expose Breeze Comet, a sophisticated Brazilian cybercrime group directly stealing funds from financial payment systems including Pix and Boleto via custom malware and insider recruitment.
Key Insights
- Custom malware arsenal: RealBreeze (LDAP brute force), LightPaint (VPN persistence), KickPlate (Windows service manipulation/registry), CobaltSpin (C2 tunnel through segmented financial networks)
- Initial access via password spraying, vishing impersonating IT support, insider recruitment, and rogue hardware devices plugged into retail network ports exploiting absent 802.1X NAC
- Post-compromise goal is direct abuse of Brazilian payment systems (Pix, Boleto, STR) — hundreds of fraudulent transactions executed within 24–48 hours of payment system access
Actionable Takeaways
Recommended actions and mitigation steps for your security team based on this article.
Priority assessment and integration with your existing security controls.
Read original article →
Sep 03, 2026
AI Summary
Thomson Reuters' C-Track court management platform was breached March–June 2026, exposing sealed court records and sensitive PII across 12+ U.S. states and Canada.
Key Insights
- Unauthorized access to C-Track (court case management SaaS) occurred from March through June 2026, with discovery on June 30 — approximately 90-day dwell time
- Data types exposed include names, Social Security numbers, driver's license numbers, medical information, dates of birth, health insurance information, and sealed/confidential court records
- Attack vector, threat actor identity, and total data volume remain undisclosed; Thomson Reuters engaged outside cybersecurity experts and law enforcement
Actionable Takeaways
Recommended actions and mitigation steps for your security team based on this article.
Priority assessment and integration with your existing security controls.
Read original article →
Sep 03, 2026
AI Summary
AIR Security launches from stealth with $50M funding, offering an AI agent firewall to secure the growing supply chain of AI add-ons, plugins, and MCP servers against prompt injection and supply chain compromise.
Key Insights
- AIR firewall performs deep analysis of AI add-ons, MCP servers, plugins, and skills — screening for external instruction sources, hidden behaviors, and typo-squatted packages before and after…
- Continuous trust evaluation enables automatic revocation across all dependent agents and workflows when a maintainer pushes a malicious update or an integration is later compromised
- Research identified AI Skills in the wild impersonating Anthropic and OpenAI, designed to bypass security reviews and execute arbitrary code — a prompt injection / supply chain hybrid attack vector
Actionable Takeaways
Recommended actions and mitigation steps for your security team based on this article.
Priority assessment and integration with your existing security controls.
Read original article →
Sep 03, 2026
AI Summary
A global RMM phishing campaign spanning 46 countries targets the US most heavily, using rapidly rotated Vercel infrastructure and legitimate RMM software to evade detection.
Key Insights
- Campaign uses 425 kit URLs across 240 hosts with 94% single-day rotation; persistent fingerprints include font1.woff2, icons8-microsoft-word-94.png, and secure.html→project/*.zip delivery chain
- Attackers abuse legitimate RMM software via phishing lures (CRA tax forms, UPS, Adobe PDFs, SSA themes) across education, technology, government, banking, and manufacturing sectors in 46 countries
- Detection must prioritize stable kit indicators and behavioral context over domain reputation or individual IOCs due to daily infrastructure rotation
Actionable Takeaways
Recommended actions and mitigation steps for your security team based on this article.
Priority assessment and integration with your existing security controls.
Read original article →
Sep 03, 2026
AI Summary
A decade-old PostgreSQL flaw (CVE-2026-6471, CVSS 7.2) allows a low-privilege replication account to load arbitrary code and escalate to superuser, patched in August 2026.
Key Insights
- CVE-2026-6471 (CVSS 7.2): missing authorization in PostgreSQL logical decoding allows REPLICATION-privileged user to dlopen arbitrary files, achieving RCE on Windows/Linux/macOS; patched in versions…
- Windows systems particularly exposed: attacker can host malicious DLL on remote SMB server via UNC path — no prior file placement on target required; check_restricted_library_name() security check…
- Post-exploitation chain: malicious plugin runs inside PostgreSQL server process, bypasses SQL permission model, escalates to superuser, modifies pg_hba.conf and preloaded libraries for persistence…
Actionable Takeaways
Recommended actions and mitigation steps for your security team based on this article.
Priority assessment and integration with your existing security controls.
Read original article →
This is just 5 articles. CyberSecNews analyzes 100+ daily.
Role-based scoring, CVE enrichment with EPSS/KEV, Syra AI assistant, real-time alerts on Slack/Teams, and 365 days of retention.
Start Free Trial — 14 Days →