🛡️ Cyber Times — CISO Intelligence Update
Wednesday, 02 September 2026 · Coverage: 01 Sep 2026 08:00 IST → 02 Sep 2026 08:00 IST
The high-confidence sweep produced 33 publishable records. This edition presents 10 source-linked updates across 2 security domains; 7 are marked for priority review.
🛡️ Vulnerabilities Worth Attention
CVE-2026-76658 — A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain…
CRITICAL — NVD CVSS 10.0 (critical). A vulnerability has been identified in the SSH daemon of HPE Networking Fabric Composer that could allow an unauthenticated remote attacker to gain administrative access to vulnerable AFC hosts. Successful exploitation could allow an attacker to execute arbitrary commands as a privileged user on the underlying operating system leading to complete system compromise.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 02 Sep 2026 01:47 IST Sources: NVD
CVE-2026-76657 — Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent…
CRITICAL — NVD CVSS 10.0 (critical). Vulnerabilities have been identified in the API of HPE Networking Fabric Composer that could potentially allow an unauthenticated remote attacker to circumvent existing authentication controls. Successful exploitation could allow an attacker to gain administrative privileges leading to complete compromise of the HPE Networking Fabric Composer host.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 02 Sep 2026 01:47 IST Sources: NVD
CVE-2026-84147 — This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint
CRITICAL — NVD CVSS 10.0 (critical). This vulnerability exists in the ERP system due to improper authentication controls and inadequate file type validation at the API endpoint. An unauthenticated remote attacker could exploit this vulnerability by uploading arbitrary files to a web accessible directory on the targeted system Successful exploitation of this vulnerability could allow the attacker to execute arbitrary code and…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 01 Sep 2026 18:50 IST Sources: NVD
CVE-2026-84372 — Predis is a flexible and feature-complete Redis and Valkey client for PHP
CRITICAL — NVD CVSS 9.8 (critical). Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an already serialized RESP buffer in AbstractAggregateConnection::write() by splitting it with explode(“\r\n”) instead of honoring RESP length prefixes. Attacker-controlled keys or values containing…
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 02 Sep 2026 03:47 IST Sources: NVD
CVE-2026-73749 — Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input
CRITICAL — NVD CVSS 9.8 (critical). Multiple vulnerabilities exist in a daemon of AOS-CX that may allow for improper processing of malformed input. An unauthenticated remote attacker could exploit these vulnerabilities by sending specially crafted packets to the affected service. Successful exploitation could result in remote code execution with elevated privileges.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 02 Sep 2026 02:48 IST Sources: NVD
CVE-2026-18808 — Improper Control of Generation of Code (‘Code Injection’) vulnerability in Klemsan Electrical Electronics Inc
CRITICAL — NVD CVSS 9.8 (critical). Improper Control of Generation of Code (‘Code Injection’) vulnerability in Klemsan Electrical Electronics Inc. KIO (Klemsan Internet Objects) allows Code Injection. This issue affects KIO (Klemsan Internet Objects): before v1.9.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 01 Sep 2026 19:47 IST Sources: NVD
CVE-2026-18210 — Improper neutralization of special elements used in an SQL command (‘SQL injection’) vulnerability in TRtek Technological Products Computer Software Hardware…
CRITICAL — NVD CVSS 9.8 (critical). Improper neutralization of special elements used in an SQL command (‘SQL injection’) vulnerability in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company Products’s Store allows SQL Injection. This issue affects Products’s Store: before 030631b2.
Defender action: Confirm affected versions in the asset inventory, review the vendor advisory, and prioritize remediation by exposure.
Validation: primary source · Published: 01 Sep 2026 19:47 IST Sources: NVD
🧪 Threat Intelligence & Attack Research
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
INFORMATIONAL — An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat. The post Counterfeit installers to system compromise…
Defender action: Review the linked evidence, confirm organizational exposure, and update detections or mitigations where applicable.
Validation: direct source · Published: 02 Sep 2026 04:18 IST Sources: Microsoft Security
Financially Motivated Threat Actor BREEZE COMET Targets Brazil
INFORMATIONAL — Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity…
Defender action: Review the linked evidence, confirm organizational exposure, and update detections or mitigations where applicable.
Validation: direct source · Published: 01 Sep 2026 19:30 IST Sources: Google Threat Intelligence
Cybersecurity IR Workshop: The workshop you shouldn’t miss
INFORMATIONAL — Cyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response. The post Cybersecurity IR Workshop: The workshop you shouldn’t miss appeared first on Microsoft Security Blog .
Defender action: Review the linked evidence, confirm organizational exposure, and update detections or mitigations where applicable.
Validation: direct source · Published: 02 Sep 2026 00:25 IST Sources: Microsoft Security
💡 Defensive Priority
Open the linked primary or corroborating evidence before changing production systems. Confirm asset exposure, use vendor guidance for remediation, and retain the source links with the operational change record.
Collection: 2,808 records inspected · 136 passed collection filters · 33 passed the high-confidence evidence gate · 27/28 source endpoints available. Automated intelligence is a triage aid; verify exposure and remediation against the linked primary advisory.