Security news
Latest security news
Thu, 3 Sept 2026
- SonicWall urges immediate patching of chained vulnerabilities
Just weeks after a wave of ransomware attacks, new flaws in SMA1000 series appliances are being exploited.
Cybersecurity DiveSonicWall - Drowning in CVEs and thirsty for answers? Try CTEM
SPONSORED FEATURE: Boards want to know if they're less exposed than last quarter. Patching metrics aren't the solution
The Register - Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names
The Hacker News - AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours
The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers.
Dark Reading - F5 security advisory (AV26-878)
Serial Number: AV26-878 Date: September 3, 2026 As of September 2, 2026, F5 is affected by vulnerabilities in the following products: BIG-IP (all modules) Prior to 17.1.3.4 Prior to 17.5.1.8 Prior to 21.0.0.3 Prior to 21.1.0.1 BIG-IQ Prior to 8.4.2.1 NGINX Gateway Fabric Prior to 2.6.8 NGINX Ingress Controller Prior to 2026-lts-r5 Prior to 5.6.0 NGINX JavaScript 9.9 Prior to 1.0.1 APM Clients Prior to 7.2.6 BIG-IP APM Multiple versions The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. K000162872: Out-of-band Security Notification (September 2, 2026)
Canadian Centre for Cyber SecurityF5, Nginx - Outsider Phishing Kit Survives Takedown With 700 New Pages
Outsider phishing kit generated 700 new pages after a Google-led disruption
Infosecurity MagazineGoogle - Jenkins security advisory (AV26-877)
Serial Number: AV26-877 Date: September 3, 2026 As of September 2, 2026, Jenkins Project is affected by vulnerabilities in the following products: Jenkins ALL except 2.568.3 ALL except 2.580 Jenkins Allure Plugin Prior to or equal to 2.35.2 Jenkins Customizable Header Plugin Prior to or equal to 295.v2544b_ca_19b_97 Jenkins File Parameter Plugin Prior to or equal to 425.v3fa_801681b_5e Jenkins GitLab Plugin Prior to or equal to 1.9.16 Jenkins LDAP Plugin Prior to or equal to 807.809.vd3a_4e5e4ec98 Jenkins Microsoft Entra ID (previously Azure AD) Plugin Prior to or equal to 710.v0b_ff8e9cc2d2 Jenkins Parameterized Remote Trigger Plugin Prior to or equal to 3.2.2 Jenkins Performance Plugin Prior to or equal to 1015.v09ca_52b_3370e Jenkins Pipeline: Build Step Plugin Prior to or equal to 599.v4b_67ea_11b_152 Jenkins SAML Plugin Prior to or equal to 4.618.v441a_27fa_46d2 Jenkins Script Security Plugin Prior to or equal to 1412.v7737b_3405f86 Jenkins TICS Plugin Prior to or equal to 2025.1.1 Jenkins ThinBackup Plugin Prior to or equal to 2.1.4 Jenkins XebiaLabs XL Deploy Plugin Prior to or equal to 26.1.0 Jenkins update-center2 Prior to or equal to 3.18.3 The Cyber Centre encourages use
Canadian Centre for Cyber SecurityMicrosoft, GitLab, Jenkins - Cisco security advisory (AV26-876)
Serial Number: AV26-876 Date: September 3, 2026 As of September 2, 2026, Cisco is affected by vulnerabilities in the following products: Cisco IOS XR Software Multiple versions Cisco Nexus 9000 Series Switches Multiple products Cisco Desk Phone 9800 Series and Video Phone 8875 Prior to 5.0(1) IP Phone 7800 and 8800 Prior to 14.4(1)SR3 IP Phone 8845 and 8865 Prior to14.4(1)SR4 Wireless IP Phone 8821 Prior to 11.0(6)SR8 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability Cisco IOS XR Software Security Hardening Release: September 2026 Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability Cisco Security Advisories
Canadian Centre for Cyber SecurityCisco, iOS - CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation
CREST’s new AI-enabled penetration testing accreditation welcomes its first 10 providers
Infosecurity Magazine - Cybercrooks trawl Fishbrain to net password hashes
Armed with password hashes and salts, attackers could already be kraken those creds
The Register
About this news
- 1,393
- Stories
- 43
- Added in the last 24 hours
- 10
- Critical in the last 7 days
- 4
- Reported by several outlets