ASCII smuggling challenges email phishing filters, Microsoft warnsLaura FrenchSeptember 4, 2026Invisible Unicode tag characters often used for AI prompt injection have appeared in high-volume phishing attacks.
New Linux toolkit found in trojanized HAProxy targeting South Korean organizationsSC StaffSeptember 4, 2026
Network SecurityHPE patches ArubaOS-CX switches vulnerable to remote code executionSteve ZurierSeptember 4, 2026HPE patched 35 ArubaOS-CX flaws, including a critical bug that could enable remote code execution.
Email security‘Empty envelope’ email attacks target company leadersLaura FrenchSeptember 4, 2026The technique bypasses RejectDirectSend by SMTP envelope sender blank.
PhishingPhishing campaign targets widely used RMM platforms in 46 countriesSteve ZurierSeptember 3, 2026Phishing attacks trick victims into installing legitimate RMM tools for remote access.
IdentityGrafana fixes critical SSRF flaw affecting Grafana MCP serversLaura FrenchSeptember 3, 2026An MCP caller could potentially reach unintended internal services leveraging the MCP server’s network position.
Vulnerability ManagementSonicWall advises customers to patch two new SMA1000 zero-daysSteve ZurierSeptember 2, 2026Attackers are chaining two SonicWall SMA1000 zero-days to gain remote code execution.
Threat ManagementMicrosoft identifies ‘TerminalFix’ campaign spreading Python reverse tunnelLaura FrenchSeptember 2, 2026The campaign uses DLL sideloading and PNG steganography to evade detection.
Application securityJFrog Artifactory flaw exploited days after patch releaseSteve ZurierSeptember 1, 2026Attackers exploited a JFrog Artifactory flaw days after its patch, threatening software supply chains.
MalwareRevStealer malware spread through fake Claude Opus 5 downloadLaura FrenchSeptember 1, 2026The Windows infostealer uses several evasion measures to remain mostly invisible to security systems.