Skip to content

Cybersecurity PSA

Top Cybersecurity News
NEWSVerified Cybersecurity PSA briefing
September 3, 2026·Top Cybersecurity News·1 min read

Preparing for the Post-Quantum Era: A Call to Action

TL;DR

CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect sensitive data, authentication systems,…

What happened CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to…

Voice options

Voice names come from your browser and device.

Open article → CISA Cybersecurity Advisories & Alerts ↗

What happened

CISA and the Group of Seven (G7) Cyber Security Working Group released Preparing for the Post-Quantum Era: A Call to Action highlighting the urgent need for organizations and governments to begin transitioning to post-quantum cryptography (PQC) to protect…

The G7 Cyber Security Working Group’s call to action outlines five priorities for a successful transition to PQC: Raising awareness of quantum risks and the importance of PQC; Developing national strategies that support PQC adoption and integration; Advancing…

Why it matters

Software updates can contain security, stability, and compatibility fixes, but the value of an update depends on what the vendor actually changed. Consumers and administrators should distinguish a routine release from a confirmed security emergency unless the source explicitly says exploitation or urgent remediation is involved.

What you should do

Use the vendor-supported update channel, install the applicable stable update, and restart the device or application when the update requires it. Organizations should test changes that affect managed fleets or production systems. Beta or preview channels should generally remain limited to systems intentionally used for testing.

Top Cybersecurity News
NEWSVerified Cybersecurity PSA briefing
September 3, 2026·Top Cybersecurity News·2 min read

Rockwell Automation 1756-ENBT Module

TL;DR

View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell…

What happened View CSAF Summary Successful exploitation of this vulnerability could crash the module. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell…

Voice options

Voice names come from your browser and device.

Open article → CISA Cybersecurity Advisories & Alerts ↗

What happened

View CSAF Summary Successful exploitation of this vulnerability could crash the module.

The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-ENBT Module Improper Check for Unusual or Exceptional Conditions Background Critical Infrastructure Sectors: Critical…

What is verified

An attacker could exploit this vulnerability by sending a crafted CIP packet, causing the module to crash.

View CVE Details Affected Products Rockwell Automation 1756-ENBT Module Vendor: Rockwell Automation Product Version: Rockwell Automation 1756-ENBT module: vers:all/* Product Status: known_affected Remediations Mitigation Rockwell Automation recommends that users upgrade to 1756-EN2T or 1756-EN4TR.

https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html Relevant CWE: CWE-754 Improper Check for Unusual or Exceptional Conditions Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Acknowledgments Rockwell Automation reported this vulnerability to CISA.

Why it matters

A security flaw matters when an attacker can use it to cross a trust boundary, gain access, run code, bypass authentication, or expose data. The exact risk depends on the affected product, vulnerable versions, exploit conditions, and whether exploitation has been observed. Those details should come from the cited source rather than assumption.

What you should do

Check the vendor or authoritative advisory for affected versions and remediation. Apply the recommended update or mitigation, restart devices or services when required, and prioritize internet-facing or privileged systems. If the source does not report active exploitation, do not treat exploitation as confirmed.

Top Attack
ALERTVerified Cybersecurity PSA briefing
September 3, 2026·Top Attack·2 min read

Pyramid Solutions NetStaX EtherNet/IP Stack

TL;DR

View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed. The following versions of…

What happened View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the…

Voice options

Voice names come from your browser and device.

Open article → CISA Cybersecurity Advisories & Alerts ↗

What happened

View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.

The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack are affected: EtherNet/IP Adapter DLL Kit (EIPA) EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE) EtherNet/IP Adapter Development Kit (EADK) EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE) EtherNet/IP…

What is verified

The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.

View CVE Details Affected Products Pyramid Solutions NetStaX EtherNet/IP Stack Vendor: Pyramid Solutions Product Version: Pyramid Solutions EtherNet/IP Adapter DLL Kit (EIPA):

Why it matters

A security flaw matters when an attacker can use it to cross a trust boundary, gain access, run code, bypass authentication, or expose data. The exact risk depends on the affected product, vulnerable versions, exploit conditions, and whether exploitation has been observed. Those details should come from the cited source rather than assumption.

What you should do

Check the vendor or authoritative advisory for affected versions and remediation. Apply the recommended update or mitigation, restart devices or services when required, and prioritize internet-facing or privileged systems. If the source does not report active exploitation, do not treat exploitation as confirmed.

Top Cybersecurity News
NEWSVerified Cybersecurity PSA briefing
September 3, 2026·Top Cybersecurity News·1 min read

Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability

TL;DR

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3)…

What happened A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and…

Voice options

Voice names come from your browser and device.

Open article → Cisco Security Advisories / PSIRT ↗

What happened

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges.

This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF).

What is verified

A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges.

The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.

Cisco has released software updates that address this vulnerability.

Why it matters

A security flaw matters when an attacker can use it to cross a trust boundary, gain access, run code, bypass authentication, or expose data. The exact risk depends on the affected product, vulnerable versions, exploit conditions, and whether exploitation has been observed. Those details should come from the cited source rather than assumption.

What you should do

Check the vendor or authoritative advisory for affected versions and remediation. Apply the recommended update or mitigation, restart devices or services when required, and prioritize internet-facing or privileged systems. If the source does not report active exploitation, do not treat exploitation as confirmed.

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access Top Attack
ALERTVerified Cybersecurity PSA briefing
September 3, 2026·Top Attack·2 min read

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

TL;DR

In this article Risk to enterprise environments Attack chain overview Mitigation and response recommendations Learn more Microsoft Threat Intelligence has observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT or helpdesk personnel and socially engineer users into…

What happened Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI package, which in turn stages a portable Node.js runtime and an obfuscated…

Voice options

Voice names come from your browser and device.

Open article → Microsoft Security Blog ↗

What happened

Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI package, which in turn stages a portable Node.js runtime and an obfuscated JavaScript implant that provides persistent…

Unlike commodity phishing that ends with an infostealer, this campaign follows a full hands-on-keyboard playbook.

What is verified

After the implant is deployed, the threat actor performs extensive host and Active Directory reconnaissance, periodically captures screenshots of the victim’s desktop, executes follow-on payloads through trusted Windows binaries, and pivots across the enterprise over Windows Remote Management…

The intrusion relies heavily on legitimate tooling, including Microsoft Teams, remote support software, Windows Installer, Node.js, and native administrative protocols, allowing the activity to blend into expected enterprise operations at nearly every stage.

The reconnaissance and lateral movement patterns observed: domain enumeration, server discovery, and WinRM pivoting toward identity systems, are consistent with intrusion activity that can precede data theft, extortion, ransomware deployment, or other follow-on objectives, in which threat actors…

Why it matters

The practical risk is that convincing impersonation and social-engineering tactics can turn a single message, login prompt, or support interaction into account takeover or financial fraud. Consumers should treat urgency, requests for credentials, and unexpected payment instructions as signals to verify independently.

What you should do

Verify unusual requests through a trusted channel you initiate yourself. Do not use phone numbers or links supplied in a suspicious message. Use multifactor authentication where available, avoid password reuse, and review account activity after any interaction that may have exposed credentials or payment information.

Top CISA CVE
CVE-2026-48710Kludex Starlette · CISA KEV
September 2, 2026·Top CISA CVE·2 min read

CISA adds CVE-2026-48710 affecting Kludex Starlette to its Known Exploited Vulnerabilities catalog

TL;DR

CISA added CVE-2026-48710 affecting Kludex Starlette to its Known Exploited Vulnerabilities catalog on September 2, 2026, which means CISA has evidence the vulnerability has been exploited in the wild. CISA’s required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

What happened CISA added CVE-2026-48710 affecting Kludex Starlette to its Known Exploited Vulnerabilities catalog on September 2, 2026. CISA vulnerability name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability Kludex Starlette contains a HTTP request/response smuggling vulnerability…

Voice options

Voice names come from your browser and device.

Open article → CISA Known Exploited Vulnerabilities ↗

What happened

CISA added CVE-2026-48710 affecting Kludex Starlette to its Known Exploited Vulnerabilities catalog on September 2, 2026.

CISA vulnerability name: Kludex Starlette HTTP Request/Response Smuggling Vulnerability

Kludex Starlette contains a HTTP request/response smuggling vulnerability that could allow attackers to inject paths into the host part, prepending the actual path leading to issues such as authentication bypass when the authentication depends on the reconstructed URL’s path. This vulnerability could be chaned with CVE-2026-42271.

Why it matters

Inclusion in CISA’s KEV catalog means the vulnerability has met CISA’s criteria for known exploitation in the wild. That makes it a higher-priority remediation signal than a vulnerability that is only theoretically exploitable.

CWE: CWE-444

What you should do

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA remediation due date for federal civilian agencies: September 16, 2026.

Additional CISA notes

This vulnerability affects an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/Kludex/starlette/security/advisories/GHSA-86qp-5c8j-p5mr ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-48710

Top Cybersecurity News
NEWSVerified Cybersecurity PSA briefing
September 2, 2026·Top Cybersecurity News·1 min read

Cisco IOS XR Software Security Hardening Release: September 2026

TL;DR

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were…

What happened As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases…

Voice options

Voice names come from your browser and device.

Open article → Cisco Security Advisories / PSIRT ↗

What happened

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review.

This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

What is verified

These vulnerabilities were found during internal testing and are not known to be actively exploited.

Cisco has released software updates that address these vulnerabilities.

This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM Security Impact Rating: Critical CVE: CVE-2026-20274,CVE-2026-20275,CVE-2026-20276,CVE-2026-20277,CVE-2026-20278,CVE-2026-20279,CVE-2026-20280

Why it matters

A security flaw matters when an attacker can use it to cross a trust boundary, gain access, run code, bypass authentication, or expose data. The exact risk depends on the affected product, vulnerable versions, exploit conditions, and whether exploitation has been observed. Those details should come from the cited source rather than assumption.

What you should do

Check the vendor or authoritative advisory for affected versions and remediation. Apply the recommended update or mitigation, restart devices or services when required, and prioritize internet-facing or privileged systems. If the source does not report active exploitation, do not treat exploitation as confirmed.

Chrome Beta for Desktop Update Top Attack
ALERTVerified Cybersecurity PSA briefing
September 2, 2026·Top Attack·1 min read

Chrome Beta for Desktop Update

TL;DR

The Chrome team is excited to announce the promotion of Chrome 154 to the Beta channel for Windows, Mac and Linux. Chrome 154.0.8037.0 contains our usual under-the-hood performance and stability tweaks, but there are also some cool new features to explore -…

What happened The Chrome team is excited to announce the promotion of Chrome 154 to the Beta channel for Windows, Mac and Linux. Interested in switching release channels? What is verified The community help forum…

Voice options

Voice names come from your browser and device.

Open article → Google Chrome Releases ↗

What happened

The Chrome team is excited to announce the promotion of Chrome 154 to the Beta channel for Windows, Mac and Linux.

Interested in switching release channels?

What is verified

The community help forum is also a great place to reach out for help or learn about common issues.

Chrome Release Team Google Chrome

Why it matters

Software updates can contain security, stability, and compatibility fixes, but the value of an update depends on what the vendor actually changed. Consumers and administrators should distinguish a routine release from a confirmed security emergency unless the source explicitly says exploitation or urgent remediation is involved.

What you should do

Use the vendor-supported update channel, install the applicable stable update, and restart the device or application when the update requires it. Organizations should test changes that affect managed fleets or production systems. Beta or preview channels should generally remain limited to systems intentionally used for testing.

Top CISA CVE
CVE-2026-59822BerriAI LiteLLM · CISA KEV
September 2, 2026·Top CISA CVE·2 min read

CISA adds CVE-2026-59822 affecting BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog

TL;DR

CISA added CVE-2026-59822 affecting BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog on September 2, 2026, which means CISA has evidence the vulnerability has been exploited in the wild. CISA’s required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

What happened CISA added CVE-2026-59822 affecting BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog on September 2, 2026. CISA vulnerability name: BerriAI LiteLLM Improper Authentication Vulnerability BerriAI LiteLLM contains an improper authentication vulnerability in the…

Voice options

Voice names come from your browser and device.

Open article → CISA Known Exploited Vulnerabilities ↗

What happened

CISA added CVE-2026-59822 affecting BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog on September 2, 2026.

CISA vulnerability name: BerriAI LiteLLM Improper Authentication Vulnerability

BerriAI LiteLLM contains an improper authentication vulnerability in the MCP Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token.

Why it matters

Inclusion in CISA’s KEV catalog means the vulnerability has met CISA’s criteria for known exploitation in the wild. That makes it a higher-priority remediation signal than a vulnerability that is only theoretically exploitable.

CWE: CWE-287, CWE-306

What you should do

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CISA remediation due date for federal civilian agencies: September 16, 2026.

Additional CISA notes

https://github.com/BerriAI/litellm/security/advisories/GHSA-7488-6r32-c95q ; BOD 26-04: https://www.cisa.gov/news-events/directives/bod-26-04-prioritizing-security-updates-based-risk ; Forensics Triage Requirements: https://www.cisa.gov/news-events/directives/bod-26-04-implementation-guidance-prioritizing-security-updates-based-risk ; https://nvd.nist.gov/vuln/detail/CVE-2026-59822

Top Cybersecurity News
NEWSVerified Cybersecurity PSA briefing
September 2, 2026·Top Cybersecurity News·2 min read

Communicating Under Pressure: Best Practices for Service Providers

TL;DR

Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages. Whether caused by cyber threat actors, human error, equipment…

What happened Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages.…

Voice options

Voice names come from your browser and device.

Open article → CISA Cybersecurity Advisories & Alerts ↗

What happened

Developed by CISA, the Federal Bureau of Investigation, and international partners, this guidance describes how organizations can plan and execute clear, timely, accurate, and audience-appropriate communications during IT and operational technology (OT) outages.

Whether caused by cyber threat actors, human error, equipment failure, or natural hazards, service outages can create disruption and societal panic even without speculation from end users and the public as added factors.

What is verified

The guidance emphasizes clarity, accountability, and transparency as core principles and details key elements of effective crisis messaging to inform affected stakeholders and the public while aligning with legal requirements, operational security, law enforcement, and containment efforts.

CISA’s CI Fortify initiative provides information and resources that help critical infrastructure organizations prepare to isolate and recover vital OT systems during a major cyber incident or crisis.

For emergency planning purposes, critical infrastructure owners and operators should assume that telecommunications services may be disrupted or otherwise unreliable, making it crucial for organizations to have crisis communications plans in place that integrate backup communication methods and…

Why it matters

Cybercrime prosecutions can reveal the scale, methods, and downstream impact of criminal campaigns, but a guilty plea or charge is not the same thing as a new breach notification. The security lesson is in the access methods, affected services, and types of information criminals were able to obtain.

What you should do

Organizations should use the case as a reason to review account protections, access logging, privileged access, and multifactor authentication on cloud and administrative systems. Consumers should pay attention to breach notifications from affected companies and take action based on the data those companies confirm was exposed.