Cyber Security Brief — 2026-09-03
Today's brief: Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon, plus more from the last few days.
A roundup of what's actually happened in security over the last couple of days — real incidents and newly disclosed vulnerabilities, not filler.
In the news
- Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon (The Hacker News) — The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowd…
- CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners (The Hacker News) — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs…
- Hackers exploit Sangoma Switchvox flaw to deploy reverse shells (BleepingComputer) — Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]
- WordPress backup plugin flaw exposes millions of sites to takeover attacks (BleepingComputer) — An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. [...]
- Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs (The Hacker News) — Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called th…
Newly published, high-severity CVEs
- CVE-2026-4357 (CVSS 10, CRITICAL) — The Embed HTML5 Game WordPress plugin through 1.3 does not properly restrict who can upload files via the plugin, as well as what can be uploaded, making it possible for unauthenticated attackers to upload PHP backdoors …
- CVE-2026-77009 (CVSS 9.9, CRITICAL) — The WatchMan-Site7 WordPress plugin through 4.2.0 does not restrict access to its debugging console, which executes user-supplied PHP code, allowing any authenticated user, such as a subscriber, to run arbitrary code on …
- CVE-2026-81294 (CVSS 9.8, CRITICAL) — Unauthenticated Privilege Escalation in Authorizer <= 3.15.1 versions.
- CVE-2026-84795 (CVSS 9.8, CRITICAL) — Craft CMS before 5.10.11 fails to validate the admin flag during user registration, allowing it to persist from deactivated admin accounts. Attackers can register with a deactivated admin's email address to inherit admin…
Source: NIST National Vulnerability Database.
How our own customers' sites are doing
We ran 0 Security Score scans across our customers in the past 7 days.
No findings recorded this week.
Nothing stood out — most sites checked out clean.
If any of the above sounds familiar, the fix is usually quick: missing security headers and outdated front-end libraries are the two most common findings we see, and both are typically a same-day fix. Run a free Security Score scan to see where your own site stands.
This brief is generated daily from CISA's KEV catalog, NIST's NVD, a small set of established security news feeds, and Hebrides Cyber's own (anonymised) scan data. Set AZURE_OPENAI_ENDPOINT/KEY/DEPLOYMENT for a narrative AI write-up instead of this templated summary — see src/lib/newsletter.ts.
$ ./get-your-score
Get a free Security Score for your site
Automated TLS, headers, DNS, and exposure checks — results in under a minute.
Request a free scan