📰 DAILY THREAT BRIEFING
Wednesday, September 2, 2026
12 News Items
THN · BleepingComputer · Krebs · Dark Reading · SANS

📰 Cybersecurity News Headlines

Top stories from leading cybersecurity publications as of September 2, 2026.

  1. FBI Probes Service Selling 153M+ Drivers Licenses
    — Krebs on Security

    A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from peop…
  2. Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
    — SANS ISC

    Introduction
  3. Attackers Pounce on Critical Artifactory Flaw Following Disclosure
    — Dark Reading

    CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected…
  4. Stronger Security Drives Ransomware Groups to Recruit From Within
    — Dark Reading

    Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cos…
  5. Hackers abuse Faronics Deploy admin tool to install ScreenConnect
    — Bleeping Computer

    Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim co…
  6. Critical Langflow Flaw Exploited as Attacks on AI Platform Rise
    — Dark Reading

    The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention fr…
  7. AI Model Evaluator METR Hit by Credential Theft, Probing
    — Dark Reading

    In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security…
  8. Aesto Health says data breach affects over 9.5 million patients
    — Bleeping Computer

    Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. […]
  9. Critical Langflow flaw exploited to steal OpenAI and AWS keys
    — Bleeping Computer

    Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework fo…
  10. Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
    — The Hacker News

    Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, accordi…
  11. Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
    — The Hacker News

    Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Bre…
  12. Hackers push malicious Virtualizor update in BGP hijacking attack
    — Bleeping Computer

    Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and…

Generated by HiveNet.ai Threat Intelligence Platform · September 2, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC