Several organizations, including River Bank & Trust, Indra Group, and Nidec, have recently fallen victim to ransomware attacks. These incidents have led to potential data exfiltration and service disruptions. Additionally, a new AI-driven ransomware technique has been demonstrated that exploits browser APIs to encrypt user files.

Several organizations across the financial, defense, and manufacturing sectors have recently disclosed ransomware attacks or data breaches. These incidents include a US financial institution, a Spanish defense contractor, a Japanese industrial manufacturer, and a US insurance firm's Japanese operations.
River Bank & Trust, a US financial institution, experienced a ransomware incident after an unauthorized actor accessed the network of its parent company, River Financial Corporation, on June 16. The bank confirmed the presence of ransomware on parts of its server environment and is currently evaluating whether personal data was accessed or exfiltrated.
Indra Group, a Spanish defense, aerospace, and technology contractor and a member of the NATO cyber coalition, confirmed a ransomware attack that impacted one of its subsidiaries. The Gentlemen ransomware gang claimed responsibility and threatened to leak allegedly stolen data. Indra Group, however, stated that the incident was contained and that service continuity was maintained.
Nidec, a Japanese electric motor and industrial manufacturer, disclosed a ransomware attack affecting the network of its Taiwanese subsidiary, Nidec Chaun Choung Technology. The BlackField group claimed responsibility for this attack, alleging the theft of over two terabytes of corporate data. This allegedly stolen data includes employee, financial, procurement, manufacturing, legal, and IT records.
Separately, US insurance firm Aflac disclosed a data breach affecting its Japan operations. Attackers accessed its policyholder portal between June 15 and June 25, exposing personal and financial data for nearly 4.4 million customers. The compromised information included policyholder details and premium payment account information.
In other cybersecurity news, researchers have identified new attack techniques and vulnerabilities. A browser-native ransomware technique, generated by a large language model, has been demonstrated to abuse Chrome's File System Access API. This method uses a fake image-enhancement page to trick users into granting folder access, subsequently reading, exfiltrating, and encrypting photos within the browser on Android and Windows devices.
Furthermore, shell command injection weaknesses were found in open-source AI coding agents, with 10 out of 11 popular tools failing to block obfuscated destructive commands. Simple rewrites allowed attackers to bypass filters and perform actions like file deletion. Only the Continue agent was noted to properly parse commands. Researchers also warned about attackers exploiting LLM phantom squatting by registering AI-generated domains to hijack traffic and deliver phishing attacks, recording 250,000 hallucinated domains and subsequent registrations, including an AI-built phishing kit named Montana Empire.
Several critical vulnerabilities have also been addressed. Oracle E-Business Suite is affected by CVE-2026-46817, a critical remote code execution flaw reportedly exploited against approximately 950 internet-exposed instances globally, which could grant attackers control over ERP systems. Linux kernel maintainers patched CVE-2026-46242, a "Bad Epoll" privilege escalation flaw affecting Linux servers, desktops, and Android devices. This race-condition use-after-free vulnerability allows unprivileged local users to gain root access, with a public exploit demonstrating reliable exploitation.
Citrix addressed CVE-2026-8451, a NetScaler ADC and NetScaler Gateway memory disclosure flaw impacting SAML Identity Provider configurations, with active exploitation observed less than 24 hours after disclosure, enabling attacks to leak session tokens. Progress also addressed CVE-2026-8037, a critical OS command injection flaw in Kemp LoadMaster load balancers with a CVSS score of 9.6. Exploitation attempts for this vulnerability began on June 29, potentially allowing unauthenticated remote code execution.
Threat intelligence reports highlighted a North Korea-aligned supply-chain campaign, PolinRider, which published 108 malicious packages and a Chrome extension across open-source registries, abusing VS Code auto-run tasks and hidden JavaScript loaders to deploy DEV#POPPER and OmniStealer. A partnership between the Vect ransomware group and TeamPCP, a supply chain credential-theft gang, was observed, industrializing ransomware delivery, with at least one Vect attack confirmed using TeamPCP-sourced credentials. The ChocoPoC campaign was also detected, weaponizing fake proof-of-concept exploits on GitHub and PyPI to infect vulnerability researchers with a Python RAT that steals files and browser data. Lastly, analysis of 3,000 live ClickFix payloads revealed rotating wrappers, custom command generation, and a Downloads-folder technique designed to bypass AMSI protections, indicating its evolution into an API-driven malware delivery ecosystem.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed