Skip to content
Cybersecurity, without the noise
Today’s Articles
9 stories
Top Cybersecurity News

Rockwell Automation 1756-ENBT Module

TL;DR

View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell…

Top Attack

Pyramid Solutions NetStaX EtherNet/IP Stack

TL;DR

View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed. The following versions of…

Top Cybersecurity News

Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability

TL;DR

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3)…

Top Attack

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

TL;DR

In this article Risk to enterprise environments Attack chain overview Mitigation and response recommendations Learn more Microsoft Threat Intelligence has observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT or helpdesk personnel and socially engineer users into…

Top CISA CVE

CISA adds CVE-2026-48710 affecting Kludex Starlette to its Known Exploited Vulnerabilities catalog

TL;DR

CISA added CVE-2026-48710 affecting Kludex Starlette to its Known Exploited Vulnerabilities catalog on September 2, 2026, which means CISA has evidence the vulnerability has been exploited in the wild. CISA’s required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Top Cybersecurity News

Cisco IOS XR Software Security Hardening Release: September 2026

TL;DR

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were…

Top Attack

Chrome Beta for Desktop Update

TL;DR

The Chrome team is excited to announce the promotion of Chrome 154 to the Beta channel for Windows, Mac and Linux. Chrome 154.0.8037.0 contains our usual under-the-hood performance and stability tweaks, but there are also some cool new features to explore -…

Top CISA CVE

CISA adds CVE-2026-59822 affecting BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog

TL;DR

CISA added CVE-2026-59822 affecting BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog on September 2, 2026, which means CISA has evidence the vulnerability has been exploited in the wild. CISA’s required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Top Attack

CISA Adds Seven Known Exploited Vulnerabilities to Catalog

TL;DR

CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability CVE-2026-48710 Kludex Starlette HTTP Request/Response Smuggling Vulnerability CVE-2026-49869 Kestra OSS OS Command Injection Vulnerability CVE-2026-59822 BerriAI LiteLLM…

The top stories
that matter.
Every day.

Consumer-focused cybersecurity reporting that explains what happened, why it matters, and what to do next — without sensationalism or filler.

Today’s Briefing

September 3, 2026 · The cybersecurity stories that matter today.

Top Attack
ALERTVerified Cybersecurity PSA briefing
September 3, 2026·Top Attack·2 min read

Pyramid Solutions NetStaX EtherNet/IP Stack

TL;DR

View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed. The following versions of…

What happened View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the…

Voice options

Voice names come from your browser and device.

Open article → CISA Cybersecurity Advisories & Alerts ↗

What happened

View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.

The following versions of Pyramid Solutions NetStaX EtherNet/IP Stack are affected: EtherNet/IP Adapter DLL Kit (EIPA) EtherNet/IP Adapter DLL Kit with CIP Security (EIPA-SECURE) EtherNet/IP Adapter Development Kit (EADK) EtherNet/IP Adapter Development Kit with CIP Security (EADK-SECURE) EtherNet/IP…

What is verified

The result could be memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could not be processed.

View CVE Details Affected Products Pyramid Solutions NetStaX EtherNet/IP Stack Vendor: Pyramid Solutions Product Version: Pyramid Solutions EtherNet/IP Adapter DLL Kit (EIPA):

Why it matters

A security flaw matters when an attacker can use it to cross a trust boundary, gain access, run code, bypass authentication, or expose data. The exact risk depends on the affected product, vulnerable versions, exploit conditions, and whether exploitation has been observed. Those details should come from the cited source rather than assumption.

What you should do

Check the vendor or authoritative advisory for affected versions and remediation. Apply the recommended update or mitigation, restart devices or services when required, and prioritize internet-facing or privileged systems. If the source does not report active exploitation, do not treat exploitation as confirmed.

Top Cybersecurity News
NEWSVerified Cybersecurity PSA briefing
September 3, 2026·Top Cybersecurity News·2 min read

Rockwell Automation 1756-ENBT Module

TL;DR

View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell…

What happened View CSAF Summary Successful exploitation of this vulnerability could crash the module. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell…

Voice options

Voice names come from your browser and device.

Open article → CISA Cybersecurity Advisories & Alerts ↗

What happened

View CSAF Summary Successful exploitation of this vulnerability could crash the module.

The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/* (CVE-2025-10478) CVSS Vendor Equipment Vulnerabilities v3 7.5 Rockwell Automation Rockwell Automation 1756-ENBT Module Improper Check for Unusual or Exceptional Conditions Background Critical Infrastructure Sectors: Critical…

What is verified

An attacker could exploit this vulnerability by sending a crafted CIP packet, causing the module to crash.

View CVE Details Affected Products Rockwell Automation 1756-ENBT Module Vendor: Rockwell Automation Product Version: Rockwell Automation 1756-ENBT module: vers:all/* Product Status: known_affected Remediations Mitigation Rockwell Automation recommends that users upgrade to 1756-EN2T or 1756-EN4TR.

https://www.rockwellautomation.com/en-us/trust-center/security-advisories.html Relevant CWE: CWE-754 Improper Check for Unusual or Exceptional Conditions Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N Acknowledgments Rockwell Automation reported this vulnerability to CISA.

Why it matters

A security flaw matters when an attacker can use it to cross a trust boundary, gain access, run code, bypass authentication, or expose data. The exact risk depends on the affected product, vulnerable versions, exploit conditions, and whether exploitation has been observed. Those details should come from the cited source rather than assumption.

What you should do

Check the vendor or authoritative advisory for affected versions and remediation. Apply the recommended update or mitigation, restart devices or services when required, and prioritize internet-facing or privileged systems. If the source does not report active exploitation, do not treat exploitation as confirmed.

Top Cybersecurity News
NEWSVerified Cybersecurity PSA briefing
September 3, 2026·Top Cybersecurity News·1 min read

Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability

TL;DR

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3)…

What happened A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges. This vulnerability exists because TCP ports 43210 and…

Voice options

Voice names come from your browser and device.

Open article → Cisco Security Advisories / PSIRT ↗

What happened

A vulnerability in the Silicon One integration for Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute code with root privileges.

This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF).

What is verified

A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges.

The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload.

Cisco has released software updates that address this vulnerability.

Why it matters

A security flaw matters when an attacker can use it to cross a trust boundary, gain access, run code, bypass authentication, or expose data. The exact risk depends on the affected product, vulnerable versions, exploit conditions, and whether exploitation has been observed. Those details should come from the cited source rather than assumption.

What you should do

Check the vendor or authoritative advisory for affected versions and remediation. Apply the recommended update or mitigation, restart devices or services when required, and prioritize internet-facing or privileged systems. If the source does not report active exploitation, do not treat exploitation as confirmed.

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access Top Attack
ALERTVerified Cybersecurity PSA briefing
September 3, 2026·Top Attack·2 min read

Impersonating IT support: how threat actors turn a remote session into enterprise-wide access

TL;DR

In this article Risk to enterprise environments Attack chain overview Mitigation and response recommendations Learn more Microsoft Threat Intelligence has observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT or helpdesk personnel and socially engineer users into…

What happened Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI package, which in turn stages a portable Node.js runtime and an obfuscated…

Voice options

Voice names come from your browser and device.

Open article → Microsoft Security Blog ↗

What happened

Once remote control is established via RMM tools, the threat actor uses PowerShell to download and silently install a malicious MSI package, which in turn stages a portable Node.js runtime and an obfuscated JavaScript implant that provides persistent…

Unlike commodity phishing that ends with an infostealer, this campaign follows a full hands-on-keyboard playbook.

What is verified

After the implant is deployed, the threat actor performs extensive host and Active Directory reconnaissance, periodically captures screenshots of the victim’s desktop, executes follow-on payloads through trusted Windows binaries, and pivots across the enterprise over Windows Remote Management…

The intrusion relies heavily on legitimate tooling, including Microsoft Teams, remote support software, Windows Installer, Node.js, and native administrative protocols, allowing the activity to blend into expected enterprise operations at nearly every stage.

The reconnaissance and lateral movement patterns observed: domain enumeration, server discovery, and WinRM pivoting toward identity systems, are consistent with intrusion activity that can precede data theft, extortion, ransomware deployment, or other follow-on objectives, in which threat actors…

Why it matters

The practical risk is that convincing impersonation and social-engineering tactics can turn a single message, login prompt, or support interaction into account takeover or financial fraud. Consumers should treat urgency, requests for credentials, and unexpected payment instructions as signals to verify independently.

What you should do

Verify unusual requests through a trusted channel you initiate yourself. Do not use phone numbers or links supplied in a suspicious message. Use multifactor authentication where available, avoid password reuse, and review account activity after any interaction that may have exposed credentials or payment information.

Sunday Edition · Weekly Recap

Weekly Recap — August 24–30, 2026

The Cybersecurity PSA Weekly Recap for August 24–30, 2026 highlights 3 of the week’s most consequential stories, with a concise TL;DR and direct link to each original story.

Top Cybersecurity News · Rockwell Automation 1756-ENBT ModuleRead original →
Top Attack · Pyramid Solutions NetStaX EtherNet/IP StackRead original →
Top Cybersecurity News · Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution VulnerabilityRead original →