Cyber Security Brief — 2026-09-02
Today's brief: SonicWall warns of actively exploited SMA1000 zero-day flaws, plus more from the last few days.
A roundup of what's actually happened in security over the last couple of days — real incidents and newly disclosed vulnerabilities, not filler.
In the news
- SonicWall warns of actively exploited SMA1000 zero-day flaws (BleepingComputer) — SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]
- FBI Probes Service Selling 153M+ Drivers Licenses (Krebs on Security) — A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with…
- Hackers abuse Faronics Deploy admin tool to install ScreenConnect (BleepingComputer) — Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support softwar…
- Aesto Health says data breach affects over 9.5 million patients (BleepingComputer) — Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. [...]
- Critical Langflow flaw exploited to steal OpenAI and AWS keys (BleepingComputer) — Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, an…
Newly published, high-severity CVEs
- CVE-2026-18550 (CVSS 9.8, CRITICAL) — The Nokri - Job Board WordPress Theme for WordPress is vulnerable to Privilege Escalation via Account Takeover in all versions up to, and including, 1.6.6. This is due to insufficient reset token validation in the `nokri…
- CVE-2026-18765 (CVSS 9.8, CRITICAL) — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Teracity Software Technologies Inc. E-OSB allows SQL Injection.
This issue affects E-OSB: before V02.26.07.08.01.
- CVE-2026-18210 (CVSS 9.8, CRITICAL) — Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products's Store allows SQL…
- CVE-2026-18808 (CVSS 9.8, CRITICAL) — Improper Control of Generation of Code ('Code Injection') vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection.
This issue affects KIO (Klemsan Internet Objects): bef…
Source: NIST National Vulnerability Database.
How our own customers' sites are doing
We ran 0 Security Score scans across our customers in the past 7 days.
No findings recorded this week.
Nothing stood out — most sites checked out clean.
If any of the above sounds familiar, the fix is usually quick: missing security headers and outdated front-end libraries are the two most common findings we see, and both are typically a same-day fix. Run a free Security Score scan to see where your own site stands.
This brief is generated daily from CISA's KEV catalog, NIST's NVD, a small set of established security news feeds, and Hebrides Cyber's own (anonymised) scan data. Set AZURE_OPENAI_ENDPOINT/KEY/DEPLOYMENT for a narrative AI write-up instead of this templated summary — see src/lib/newsletter.ts.
$ ./get-your-score
Get a free Security Score for your site
Automated TLS, headers, DNS, and exposure checks — results in under a minute.
Request a free scan