Briefing — 7 September 2026

Monday 7 September: $320M Liquid BTC heist, alleged US DoW breach, Steam 29.7M leak, critical MikroTik CVE. Ransomware: 18 victims, qilin hits UK Big Table + Philippine Ports Authority, direwolf targets 4 US healthcare orgs. No new NCSC advisories.…

Briefing — 6 September 2026

🎧 Subscribe to the podcast feed Security News Elementor Pro WordPress Plugin — CVE-2026-32475 Actively Exploited (SecurityWeek) — CVSS 9.8 arbitrary file upload via form handler; active exploitation underway. Patch immediately. 5,400+ Sites Serving ClickFix Payloads via BNB Blockchain Smart Contracts (BleepingComputer) — Attackers use smart contracts as bulletproof payload…

Briefing — 5 September 2026

🎧 Listen to the episode  |  Subscribe to the podcast feed Security News Actively Exploited Sandbox RCE in All Chromium Versions (CVE-2026-85046) (NVD) — A critical sandbox escape and remote code execution vulnerability in all Chromium versions is being actively exploited; update Chrome and Edge immediately. Critical Citrix NetScaler Auth Bypass…

Briefing — 4 September 2026

🎧 Subscribe to the podcast feed Security News Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC (The Register) — A working proof-of-concept exploit for CrowdStrike Falcon has been published by a well-known vulnerability researcher; given Falcon's kernel-level privileges, this is a high-priority exposure…

Briefing — 3 September 2026

🎧 Subscribe to the podcast feed Security News METR Report on OpenAI / Hugging Face Hacking Incident (Hacker News / METR) — Independent researchers document how an attacker breached AI lab infrastructure at both OpenAI and Hugging Face, highlighting AI development pipelines as high-value targets. An AI-Assisted Cyber Attack: Inside a Unit…

Briefing — 2 September 2026

66 ransomware victims across 22 groups. SonicWall SMA1000 zero-days, Artifactory auth bypass, Philippines nuclear breach, Sality botnet takedown, and AI platform attacks.…