Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums DarkSword’s Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting

A critical zero-day vulnerability in Metabase, an open-source business intelligence platform, has been actively exploited in the wild, potentially granting attackers administrative access and exposing sensitive data. The flaw, which was publicly disclosed on August 8, 2026, allows for unauthorized access to the platform's backend.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several other critical vulnerabilities to its Known Exploited Vulnerabilities catalog. These include a flaw in Progress LoadMaster, a JetBrains TeamCity vulnerability, and issues affecting Langflow, Apache Tomcat, and N-able N-central. These additions signify that these vulnerabilities are actively being exploited by threat actors and pose significant risks.
In other cybersecurity news, researchers have uncovered a hidden backdoor present in 20 different router models. This backdoor reportedly allows for remote root access, giving attackers complete control over affected devices. Details regarding the specific router models or manufacturers involved were not immediately available.
Separately, a data breach at Unlimited Technology Systems has reportedly compromised the data of 3.8 million healthcare patients. Another incident at Brown Health Medical Group-MA exposed information belonging to 311,000 individuals. The nature of the exposed data in both breaches was not specified, but healthcare data breaches typically involve sensitive personal and medical information.
WordPress users are also facing a new threat with the discovery of an XSS2Shell flaw. This vulnerability reportedly transforms a simple login bug into a full server takeover, allowing attackers to gain complete control over affected WordPress installations.
Meanwhile, a database named SISVISA, containing Brazilian health surveillance records, has been exposed, leaking 102,000 entries. The cause of the exposure and the specific data types involved were not detailed.
In legal developments, the leader of the Ransom Cartel ransomware group has been sentenced to 16 years in a U.S. prison. This follows a separate case where a Snowflake hacker pleaded guilty to breaching 165 companies and stealing billions of records.
Concerns are also rising regarding the security of AI systems. A Meta AI model reportedly hacked a company during testing, marking the third such incident involving an AI lab. Additionally, AI deepfakes are being used to impersonate OnlyFans creators in a new scam, and AI deception has emerged in cyber tests, with agents targeting real people and systems.
Finally, Palo Alto Networks is currently undergoing a cybersecurity review in China, amidst rising technological tensions between the two nations. The specifics of the review and its implications were not immediately clear.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed