Cyber Security Brief — 2026-09-01
Today's brief: Cronos blockchain restarts after $74 million Tectonic exploit, plus more from the last few days.
A roundup of what's actually happened in security over the last couple of days — real incidents and newly disclosed vulnerabilities, not filler.
In the news
- Cronos blockchain restarts after $74 million Tectonic exploit (BleepingComputer) — The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. [...]
- Microsoft warns of TerminalFix attacks deploying reverse tunnels (BleepingComputer) — A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]
- North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales (The Hacker News) — Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent i…
- Microsoft Exchange Online outage causes email failures, auth issues (BleepingComputer) — Microsoft is investigating a widespread service issue causing authentication issues, email delays and failures, and various other issues for Exchange Online customers. [...]
- OpenAI confirms ChatGPT outage as users report errors (BleepingComputer) — ChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks. [...]
Newly published, high-severity CVEs
- CVE-2026-82693 (CVSS 10, CRITICAL) — A vulnerability was determined in Tenda AC1206 15.03.06.23. This vulnerability affects the function TendaTelnet of the file /goform/telnet of the component Web UI. Executing a manipulation can lead to missing authenticat…
- CVE-2026-82694 (CVSS 10, CRITICAL) — A vulnerability was identified in Tenda AC1206 15.03.06.23. This issue affects the function R7WebsSecurityHandler of the file /goform/ate of the component Web UI. The manipulation leads to missing authentication. The att…
- CVE-2026-82695 (CVSS 10, CRITICAL) — A security flaw has been discovered in Tenda AC18 15.03.05.19. Impacted is an unknown function of the file /goform/telnet of the component Telnet Handler. The manipulation results in missing authentication. The attack ca…
- CVE-2026-82970 (CVSS 10, CRITICAL) — Unrestricted Upload of File with Dangerous Type vulnerability in WP Legal Pages WP Cookie Notice for GDPR, CCPA & ePrivacy Consent allows Using Malicious Files.
This issue affects WP Cookie Notice for GDPR, CCPA & ePriv…
Source: NIST National Vulnerability Database.
How our own customers' sites are doing
We ran 0 Security Score scans across our customers in the past 7 days.
No findings recorded this week.
Nothing stood out — most sites checked out clean.
If any of the above sounds familiar, the fix is usually quick: missing security headers and outdated front-end libraries are the two most common findings we see, and both are typically a same-day fix. Run a free Security Score scan to see where your own site stands.
This brief is generated daily from CISA's KEV catalog, NIST's NVD, a small set of established security news feeds, and Hebrides Cyber's own (anonymised) scan data. Set AZURE_OPENAI_ENDPOINT/KEY/DEPLOYMENT for a narrative AI write-up instead of this templated summary — see src/lib/newsletter.ts.
$ ./get-your-score
Get a free Security Score for your site
Automated TLS, headers, DNS, and exposure checks — results in under a minute.
Request a free scan