Cyber Security Brief — 2026-09-04
Today's brief: French hospital fined €500,000 after breach exposes data of 727,000, plus more from the last few days.
A roundup of what's actually happened in security over the last couple of days — real incidents and newly disclosed vulnerabilities, not filler.
In the news
- French hospital fined €500,000 after breach exposes data of 727,000 (BleepingComputer) — France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients' and their relatives' data. [...]
- Coder's registry infrastructure compromised to push malicious modules (BleepingComputer) — Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. [...]
- HPE patches critical ArubaOS-CX remote code execution flaw (BleepingComputer) — Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. [...]
- ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories (The Hacker News) — The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through …
- Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root (The Hacker News) — Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongsid…
Newly published, high-severity CVEs
- CVE-2026-85031 (CVSS 9.9, CRITICAL) — A vulnerability was found in TOTOLINK CP450 4.1.0. The impacted element is an unknown function of the file /cgi-bin/cstecgi.cgi. Performing a manipulation of the argument topicurl results in buffer overflow. Remote explo…
- CVE-2026-85154 (CVSS 9.8, CRITICAL) — WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. At…
- CVE-2026-85109 (CVSS 9.8, CRITICAL) — A vulnerability was determined in Tenda HG10 300001138. This issue affects the function formLogin of the file /boaform/formLogin of the component Boa Web Server. Executing a manipulation of the argument Username can lead…
- CVE-2026-85181 (CVSS 9.8, CRITICAL) — CAT uses Java String.hashCode as the sole integrity check for session cookies without server-side keying, allowing attackers to forge valid checksums offline. Attackers can set the x-forwarded-for header to bypass IP bin…
Source: NIST National Vulnerability Database.
How our own customers' sites are doing
We ran 0 Security Score scans across our customers in the past 7 days.
No findings recorded this week.
Nothing stood out — most sites checked out clean.
If any of the above sounds familiar, the fix is usually quick: missing security headers and outdated front-end libraries are the two most common findings we see, and both are typically a same-day fix. Run a free Security Score scan to see where your own site stands.
This brief is generated daily from CISA's KEV catalog, NIST's NVD, a small set of established security news feeds, and Hebrides Cyber's own (anonymised) scan data. Set AZURE_OPENAI_ENDPOINT/KEY/DEPLOYMENT for a narrative AI write-up instead of this templated summary — see src/lib/newsletter.ts.
$ ./get-your-score
Get a free Security Score for your site
Automated TLS, headers, DNS, and exposure checks — results in under a minute.
Request a free scan