Daily Digest

CISA Adds Exploited Flaws, Ransomware Hits Credit Union, Zero-Days Disclosed

September 5, 2026
7 articles (4 new, 3 updated)
21 min read

Summary

Critical Vulnerabilities Under Active Exploitation:

  • CISA Adds Seven Actively Exploited Flaws to KEV Catalog: CISA has updated its Known Exploited Vulnerabilities (KEV) catalog with seven new flaws, some requiring patching by September 5 and others by September 16, 2026. The update includes detailed technical analysis of AI infrastructure vulnerabilities used to steal API keys and deploy crypto miners, along with new detection and mitigation strategies.
  • Google Patches Actively Exploited Chrome V8 Zero-Day Flaw: The Chrome V8 zero-day, CVE-2026-85046, has been added to CISA's KEV catalog, mandating federal agencies to patch by September 18, 2026. This vulnerability also impacts other Chromium-based browsers, requiring users to update their respective browsers.

New Threats and Advisories:

  • Ransomware Groups Target Healthcare, Finance, and Government: The Akira ransomware group exfiltrated approximately 50GB of sensitive data from Gale Credit Union, including customer and employee personal information. The credit union is offering identity monitoring services to affected individuals.
  • Broadcom Patches Critical VMware VM Escape Vulnerabilities: Broadcom has released updates for VMware Workstation and Fusion to address two vulnerabilities, including a critical integer overflow flaw (CVE-2026-59346) that could allow code execution on the host system. Users are urged to update as no workarounds are available.
  • LockBit 5.0 Ransomware Claims Attack on Dutch Firm KALA Health: The LockBit 5.0 ransomware group has claimed responsibility for an attack on KALA Health, a Netherlands-based nutraceutical manufacturer. The group is threatening to release stolen data unless the company makes contact.
  • Cisco Patches Three Critical Flaws in IOS XR Network Software: Cisco has released patches for eight vulnerabilities in its IOS XR software, including three critical flaws (CVE-2026-20274, CVE-2026-20279, CVE-2026-20212) that could permit remote code execution or device reloads. While no active exploitation has been observed, immediate patching is recommended.
  • Researcher Drops 'FalconFlank' Zero-Day for CrowdStrike Falcon: A security researcher has publicly disclosed 'FalconFlank,' a zero-day exploit targeting the CrowdStrike Falcon endpoint security platform. This local privilege escalation exploit could allow a local attacker to gain SYSTEM-level privileges on fully updated Windows 11 and Windows Server systems.

Filter by Category

New Articles (4)

Updated Articles (3)

📢 Share This Publication

Help others stay informed about cybersecurity threats

📅 Daily Edition

Curated and deduplicated every day from dozens of trusted sources — giving you one clean, consolidated view of what matters in cybersecurity.

🔢 Deduplication Applied

Related stories are merged into a single evolving article rather than repeated as separate entries — cutting through noise so you only read what's new.

🔗 Full Articles Linked

Every entry links to its full enriched article — complete with MITRE ATT&CK mappings, extracted IOCs, and actionable detection and mitigation guidance.