The 48-hour period from September 1-2, 2026 revealed a critical security landscape dominated by authentication bypass vulnerabilities, healthcare sector breaches, and sophisticated supply chain attacks. Most concerning are multiple critical authentication bypass flaws in widely-deployed infrastructure including Proxmox Virtual Environment (CVE-2023-54391, CVSS 9.8), AOS-CX network switches (multiple CVEs), and Next.js web framework (CVE-2026-75604, CVSS 9.0). These vulnerabilities enable unauthenticated remote code execution and complete system compromise.
The healthcare sector suffered particularly severe impacts, with over 10 million patient records exposed across multiple breaches including Aesto Health (9.5M patients), Nutex Health, and Novocure. Ransomware groups demonstrated continued aggression with 30 new victims posted, including Manchester Airports Group and multiple healthcare facilities. Supply chain attacks escalated with threat actors hijacking BGP routing to deliver malicious Virtualizor updates and exploiting trusted software distribution channels including counterfeit installers and abuse of legitimate admin tools like Faronics Deploy and ScreenConnect.
Emerging threats include a massive identity theft service selling 153+ million US and Canadian driver's licenses, active exploitation of critical Langflow AI platform vulnerabilities for credential theft (CVE-2026-0768), and ClickFix/TerminalFix campaigns compromising 31 organizations while abusing blockchain infrastructure for C2 communications. The convergence of authentication bypasses, healthcare targeting, and AI platform exploitation represents a significant elevation in threat sophistication requiring immediate defensive action.
Multiple critical authentication bypass vulnerabilities discovered in enterprise infrastructure enabling unauthenticated remote access and code execution
Critical authentication bypass in Proxmox VE 7.0-8.0 allows unauthenticated attackers to authenticate as any enabled user without configured second factor by supplying arbitrary tfa-challenge value. Affects libpve-access-control before 8.0.4.
Next.js 13.4.0-15.5.24 and 16.3.3 on Windows fails to consistently escape backslashes in route segments, enabling path traversal attacks. CVSS 9.0 affecting Pages Router and App Router without Cache Components.
Aruba AOS-CX switches contain multiple critical authentication bypass vulnerabilities (CVE-2026-73779, CVE-2026-73777, CVE-2026-73778) allowing unauthenticated remote actors to circumvent authentication controls, with additional credential manager vulnerability (CVE-2026-73778) enabling unauthorized admin access.
WWBN AVideo fails to validate password recovery token expiration, allowing attackers to use expired tokens indefinitely to reset account passwords and gain full account access. CVSS 9.8 critical severity.
Authentication bypass flaw in JFrog's Artifactory repository manager enables attackers to gain admin-level access on affected systems. Active exploitation observed following disclosure.
Nearly 22,000 internet-exposed Microsoft Exchange servers remain unpatched against high-severity authentication bypass vulnerability allowing attackers to hijack all user mailboxes.
Active exploitation of AI development platforms and software supply chain vulnerabilities for credential theft and remote code execution
Unauthenticated remote code execution vulnerability in Langflow AI framework actively exploited to steal OpenAI, AWS keys, and other credentials. Attacks targeting low-code AI development platform increasing.
METR security nonprofit suffered credential theft attack resulting in consumption of $600,000 in public AI model credits through stolen API key.
Anthropic warns infostealers are stealing Claude session cookies to access users' accounts and consume usage at their expense, targeting AI platform credentials.
Two PaperCut NG/MF print management software vulnerabilities patched last week after zero-day exploitation now being abused in data theft attacks.
Sophisticated campaigns exploiting trusted software distribution channels and infrastructure to deliver malware
Hackers hijacked BGP routing for Virtualizor VPS management software update infrastructure, redirecting update requests to malicious servers delivering compromised updates. High-sophistication supply chain attack.
Microsoft Defender Experts tracks active campaign impersonating legitimate software vendors through look-alike download pages and regenerated installer archives to deliver malware. Extensive TTPs, IOCs, and mitigations shared.
Phishing actors abusing legitimate Faronics Deploy endpoint-management platform to gain remote administrative control and install ScreenConnect remote support software on victim computers.
ClickFix campaign using EtherHiding to dynamically update C2 servers by abusing Polygon blockchain as attacker-controlled address book. 31 organizations compromised.
New TerminalFix variant adapts familiar ClickFix fake CAPTCHA technique to deliver payload granting attackers access to victim's wider network infrastructure.
Multiple IP addresses distributing ConnectWise ScreenConnect installers (support.client.exe, ScreenConnect.ClientSetup.exe) via wget user-agent, indicating automated deployment for remote access.
Active Mirai botnet distribution from multiple IPs serving ELF binaries for ARM, MIPS, x86 architectures and shell scripts. Includes pingu.business domain infrastructure.
Major healthcare breaches and massive identity theft service expose millions of records
New identity theft service on dark web selling digital scans of more than 153 million driver's licenses from US and Canada. FBI investigating source of massive identity document database.
Aesto LLC (Aesto Health) disclosed data breach affecting over 9.5 million individuals. Major healthcare sector compromise impacting patient records.
UK's largest airport operator (Manchester, Stansted, East Midlands airports) added to Fulcrumsec ransomware leak site. Critical infrastructure targeting with potential operational impact.
Houston-based Nutex Health (27 micro-hospitals, 12 states) suffered cyberattack with data theft and extortion attempt affecting patient and employee data. Now listed by TheGentlemen ransomware group.
Healthtech company Novocure reports mid-August cyberattack exposed data of undisclosed number of employees and more than 1,400 US cancer patients.
Florida nonprofit workforce development organization compromised by TheGentlemen ransomware. Headquartered in West Palm Beach, leads workforce development initiatives.
Nation-state actors targeting critical infrastructure and employing sophisticated techniques
Fire Ant hacking operation used compromised Cisco routers as platform for additional attacks, compromising the trust layer systems depend on. Sophisticated supply chain and infrastructure targeting.
Threat actors exploited old, unpatched ownCloud vulnerabilities to gain initial access to Philippines nuclear agency, stealing reactor databases, personnel records, and credential stores.
Kaspersky discovered new NodeRabbit malware from Iranian cyber espionage actors targeting aviation and fintech developers in Afghanistan, Egypt, and Ethiopia.
Continued ransomware activity with insider recruitment trends and 30 new victims across multiple sectors
Security researchers observe uptick in insider-assisted ransomware attacks as stronger security drives groups to recruit from within target organizations. Malicious insiders pose threats costing companies millions.
Mount Vernon, WA home builder compromised by Akira ransomware. 27GB of corporate and client data threatened for release including employee personal information (passports, SSNs).
Krybit ransomware group posted 10 victims including Egyptian Seashell Hospital, UICC cancer organization, Vedantaa Institute of Medical Sciences, demonstrating continued healthcare targeting.
Novel attack vectors including crypto wallet draining, session hijacking, and multi-factor authentication bypasses
August attacks demonstrated rapid conversion of trusted business activity into risk through Microsoft 365 session abuse, legitimate remote-management tool exploitation, and business-themed files for corporate system access.
Multiple authenticated command injection vulnerabilities in AOS-CX CLI and API endpoints enable privileged OS command execution (CVE-2026-73767, CVE-2026-73766, CVE-2026-73768).
Fake GTA 6 leaked copy using wallet-draining code to steal cryptocurrency, tokens, and NFTs from eager fans. Social engineering targeting gaming community.
Five Venezuelan nationals pleaded guilty to ATM jackpotting attacks using malware to empty automated teller machines in series of physical malware deployment operations.
Financial sector warnings on AI cyber risk and data protection enforcement actions
Financial Stability Board chair Andrew Bailey calls cyber risk from frontier AI 'most immediate concern' to global financial system, urging preparation for severe scenarios involving simultaneous disruption across firms and shared technology dependencies.
Data Protection Commission fined Irish Health Safety and Environment authority over €600,000 for mismanagement of historical records at Westmeath hospitals.
These briefings are compiled from publicly available threat-intelligence feeds, which may include CISA KEV, NIST NVD, the GitHub Advisory Database (OSV), abuse.ch, and Wordfence Intelligence. Data-breach and credential-leak items may include data from Have I Been Pwned and ransomware.live.
CVE® is a registered trademark of The MITRE Corporation. CVE Records are © The MITRE Corporation, reproduced under the CVE Program Terms of Use. WordPress vulnerability data is provided by Wordfence Intelligence, © Defiant, Inc. Breach data from Have I Been Pwned is licensed under CC BY 4.0.