Security news
Latest security news
Tue, 1 Sept 2026
- Attackers Pounce on Critical Artifactory Bug Following Disclosure
CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.
CriticalUsed in attacksDark ReadingJFrog - Stronger Security Drives Ransomware Groups to Recruit From Within
Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.
Dark Reading - Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise
The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.
Dark Reading - Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks
The model provider gave METR the credits for free. An actual customer would not have been so lucky
The Register - Firefox helps iPhone users bypass ads on web sites while making money showing its own ads
Baked-in Firefox ad blocking on iOS begins rolling out slowly today, and is off by default
The RegisteriOS, Firefox - AI Model Evaluator METR Hit by Credential Theft, Probing
In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.
Dark Reading - Anthropic pledges to try harder to keep models under control, asks partners to chip in
Security ... this time it will be different
The Register - Erlang security advisory (AV26-870)
Serial number: AV26-870 Date: September 1, 2026 As of September 1, 2026, Erlang is affected by vulnerabilities in the following product: OTP - Multiple versions The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. Erlang Security Advisories
Canadian Centre for Cyber Security - Rockwell Automation security advisory (AV26-869)
Serial number: AV26-869 Date: September 1, 2026 As of September 1, 2026, Rockwell Automation is affected by vulnerabilities in the following products: 1756-ENBT Module All versions ArmorStart LT Prior to or equal to v2.001 CompactLogix 5380 / ControlLogix 5580 Prior to or equal to V33 V34.011 to V34.014 V35.011 to V35.013 V36.011 to V36.012 RSLinx Classic Prior to or equal to V4.50 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SD1797 | Security Advisory | Rockwell Automation | US SD1798 | Security Advisory | Rockwell Automation | US SD1794 | Security Advisory | Rockwell Automation | US SD1792 | Security Advisory | Rockwell Automation | US
Canadian Centre for Cyber Security - Mozilla security advisory (AV26-868)
Serial number: AV26-868 Date: September 1, 2026 As of September 1, 2026, Mozilla is affected by vulnerabilities in the following products: Firefox ESR Versions prior to 115.40 Versions prior to 140.15 Versions prior to 153.2 Firefox Versions prior to 155 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Vulnerabilities fixed in Firefox ESR 115.40 — Mozilla Security Vulnerabilities fixed in Firefox ESR 140.15 — Mozilla Security Vulnerabilities fixed in Firefox ESR 153.2 — Mozilla Security Vulnerabilities fixed in Firefox 155 — Mozilla Mozilla Foundation Security Advisories — Mozilla
Canadian Centre for Cyber SecurityFirefox
About this news
- 1,383
- Stories
- 68
- Added in the last 24 hours
- 10
- Critical in the last 7 days
- 4
- Reported by several outlets