Security news

Latest security news

Tue, 1 Sept 2026

  1. FBI Probes Service Selling 153M+ Drivers Licenses

    A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.

    Krebs on Security
  2. Attackers Pounce on Critical Artifactory Bug Following Disclosure

    CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.

    CriticalUsed in attacksDark ReadingJFrog
  3. Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise

    The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.

    Dark Reading
  4. Erlang security advisory (AV26-870)

    Serial number: AV26-870 Date: September 1, 2026 As of September 1, 2026, Erlang is affected by vulnerabilities in the following product: OTP - Multiple versions The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. Erlang Security Advisories

    Canadian Centre for Cyber Security
  5. Rockwell Automation security advisory (AV26-869)

    Serial number: AV26-869 Date: September 1, 2026 As of September 1, 2026, Rockwell Automation is affected by vulnerabilities in the following products: 1756-ENBT Module All versions ArmorStart LT Prior to or equal to v2.001 CompactLogix 5380 / ControlLogix 5580 Prior to or equal to V33 V34.011 to V34.014 V35.011 to V35.013 V36.011 to V36.012 RSLinx Classic Prior to or equal to V4.50 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SD1797 | Security Advisory | Rockwell Automation | US SD1798 | Security Advisory | Rockwell Automation | US SD1794 | Security Advisory | Rockwell Automation | US SD1792 | Security Advisory | Rockwell Automation | US

    Canadian Centre for Cyber Security
  6. Mozilla security advisory (AV26-868)

    Serial number: AV26-868 Date: September 1, 2026 As of September 1, 2026, Mozilla is affected by vulnerabilities in the following products: Firefox ESR Versions prior to 115.40 Versions prior to 140.15 Versions prior to 153.2 Firefox Versions prior to 155 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Vulnerabilities fixed in Firefox ESR 115.40 — Mozilla Security Vulnerabilities fixed in Firefox ESR 140.15 — Mozilla Security Vulnerabilities fixed in Firefox ESR 153.2 — Mozilla Security Vulnerabilities fixed in Firefox 155 — Mozilla Mozilla Foundation Security Advisories — Mozilla

    Canadian Centre for Cyber SecurityFirefox
  7. WebPros security advisory (AV26-866)

    Serial number: AV26-866 Date: September 1, 2026 As of September 1, 2026, WebPros is affected by vulnerabilities in the following product: Plesk Prior to 18.0.79.9 Prior to 18.0.80.5 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. CVE-2026-67394: Vulnerability in Plesk allows privilege escalation to root

    Canadian Centre for Cyber Security
  8. White House Launches Pilot Program in Texas to Protect Water Infrastructure

    Project Watershed 250 will see water providers in Texas provided with federal and private sector cybersecurity resources amid rising nation-state threats

    Infosecurity Magazine

Mon, 31 Aug 2026

  1. WatchGuard security advisory (AV26-865)

    Serial Number: AV26-865 Date: August 31, 2026 As of August 27, 2026, WatchGuard is affected by vulnerabilities in the following products: Dimension Prior to 2.3.1 Fireware OS Prior to 12.12.2 Prior to 12.5.20 Prior to 2026.2.2 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. WatchGuard Security Advisories

    Canadian Centre for Cyber Security
  2. PaperCut security advisory (AV26-858) – Update 2

    Serial number: AV26-858 Date: August 28, 2026 Updated: August 31, 2026 As of August 27, 2026, PaperCut is affected by vulnerabilities in the following products: PaperCut MF Prior to v24 Emergency Patch Release 2 Prior to v25 Emergency Patch Release 2 Prior to v26 Emergency Patch Release 2 PaperCut NG Prior to v24 Emergency Patch Release 2 Prior to v25 Emergency Patch Release 2 Prior to v26 Emergency Patch Release 2 Update 1 Open-source reporting indicates that CVE-2026-81578 and CVE-2026-82078 are related to PaperCut MF and PaperCut NG are being exploited in the wild. Update 2 On August 31, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-81578 and CVE-2026-82078 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. URGENT Security Advisory: PaperCut NG/MF Security Bulletin (27 Aug 2026) CISA KEV: CVE-2026-81578 CISA KEV: CVE-2026-82078

    CriticalUsed in attacksCanadian Centre for Cyber SecurityPaperCut

About this news

1,264
Stories
33
Added in the last 24 hours
16
Critical in the last 7 days
4
Reported by several outlets