📝 Overview
A series of disclosures points to widening cyber risk across governments, software vendors and critical systems. The US has offered a reward for information on an Iranian alleged to have carried out attacks on critical infrastructure, while CISA has added seven exploited flaws amid reports of reverse shells and crypto miners. Separately, Thomson Reuters says a court software breach may have exposed Social Security numbers and sealed data, and security researchers have documented abuse of trusted software components, from Node.js runtime to malicious .git configurations targeting AI agents.
The US State Department is offering a $10 million reward for information on Amir Yaryab, whom it says leads the IRGC's cyber unit and oversees hacker groups including CyberAv3ngers. The announcement links him to cyberattacks on critical infrastructure.
Source: The Record from Recorded Future News
• Published: September 04, 2026
Thomson Reuters said unauthorized access to its C-Track court software may have exposed files containing sensitive personal and court-related data. The breach affected courts in multiple U.S. states, the U.S. Virgin Islands and Ontario (Canada).
Source: The Hacker News
• Published: September 03, 2026
Researchers said an RMM phishing campaign linked to Canada Revenue Agency lures is part of a wider operation spanning 46 countries. The United States accounted for the largest share of observed activity.
Source: The Hacker News
• Published: September 03, 2026
Attackers are using the legitimate Node.js runtime to deliver malware in targeted campaigns against government, technology and hospitality organizations. The technique helps malicious code blend in with normal system activity.
Source: The Hacker News
• Published: September 03, 2026
GitGuardian said a new Shai-Hulud infostealer variant now scans 469 credential locations across developer tools, cloud settings and AI configs. The expansion increases the risk of credential theft across software pipelines.
Source: The Hacker News
• Published: September 03, 2026
Citizen Lab and the SHARE Foundation said an iPhone used by a Serbian student protest member was infected with NSO Group's Pegasus spyware through a zero-click iMessage exploit. The findings point to a targeted surveillance operation.
Source: The Hacker News
• Published: September 03, 2026
A researcher released FalconFlank, a zero-day privilege-escalation flaw affecting CrowdStrike Falcon Sensor. The bug abuses malware-remediation features to gain elevated access.
Source: The Hacker News
• Published: September 03, 2026
CISA added seven exploited vulnerabilities to its Known Exploited Vulnerabilities catalog after reports of attackers using them to deploy reverse shells and crypto miners. The agency urged rapid patching.
Source: The Hacker News
• Published: September 03, 2026
Microsoft said a malware campaign is using fake software-download sites to distribute malicious installers that disable Windows Update and weaken Microsoft Defender. The activity has primarily affected Chinese-speaking users and multinational organizations in China.
Source: The Hacker News
• Published: September 02, 2026
Researchers found that malicious .git configurations can trick AI coding agents such as Claude, Codex and Cursor into running attacker-chosen commands. Several of the flaws remain unpatched.
Source: The Hacker News
• Published: September 02, 2026
The Canadian Centre for Cyber Security warns of two vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway, tracked as CVE-2026-19490 and CVE-2026-19489. One flaw may let a remote attacker bypass authentication on certain Gateway and AAA configurations, while the other can cause a buffer overflow and possible denial of service; the notice advises organisations to check whether their appliances match the affected settings.
Source: Alerts and advisories
• Published: September 05, 2026
Canada’s Cyber Centre has warned organizations to stay alert for cyberattacks during periods of geopolitical tension and major events, citing risks such as service disruption, website defacement and distraction from other malicious activity. It urged critical infrastructure and essential services to review their defences and incident response plans.
Source: Guidance, news and events
• Published: September 05, 2026
Google, Anthropic and OpenAI announced new cyber-focused AI models, safeguards and access programs for trusted defenders. The offerings are aimed at improving security work while limiting misuse.
Source: The Hacker News
• Published: September 02, 2026