Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Mapping the malware blast radius a single alert won’t show you In this interview with Help Net Security, Mike Wiacek, founder and CTO of Stairwell, explains Backstory, an AI agent that takes a single alert and works outward to map how far a malware campaign spread. He walks through the research behind

Attackers have exploited a critical authentication bypass vulnerability, identified as CVE-2026-18577, in N-able N-central, a remote monitoring and management solution. This flaw allows unauthorized access to managed endpoints.
Separately, a pre-authentication remote code execution vulnerability was discovered in Bonita BPM, a workflow automation platform used in sectors like banking and government. Researchers at Novee found that a single unauthenticated web request could allow attackers to access an internal Bonita API and execute code on the server. This finding was presented at Black Hat USA 2026.
Another significant vulnerability, CVE-2026-66066, affects Ruby on Rails, a popular framework for web applications. This critical flaw, dubbed KindaRails2Shell, could enable attackers to read sensitive files from a server and, in some instances, achieve full control over it.
In other incidents, the Swiss Federal Office of Information Technology, Systems and Telecommunication (BIT) confirmed that vulnerabilities in their Microsoft SharePoint servers led to the compromise of approximately 200 login credentials.
Forescout’s Vedere Labs uncovered 15 vulnerabilities within TP-Link’s Omada networking platform. One attack chain leveraged the sequential nature of Omada router serial numbers, which are printed on devices and packaging. By guessing a serial number, attackers could query the Omada cloud to reveal a device’s MAC address and model, such as identifying ER605 routers from serials starting with 22460J500 or ER7206 models from 224608100. These vulnerabilities could allow attackers to hijack routers and intercept camera traffic.
Kaspersky ICS CERT reported approximately forty attacks on industrial organizations in the second quarter of 2026. One notable incident involved an Israeli food producer where intruders manipulated a refrigeration system by switching gas cooler and receiver valves to manual and pinning them open. This action caused liquid CO2 to flood and destroy compressors, necessitating a week-long rebuild and system recalibration with replacement units.
A phishing campaign impersonating Bank of America is actively targeting Windows users. The campaign aims to trick users into installing ScreenConnect remote access software and then employs tactics to make its uninstallation difficult.
In other security news, Palo Alto Networks’ Unit 42 developed an automated system called NOVA, which analyzed the source code of 3,915 open-source projects over two months. NOVA identified 14,090 vulnerabilities, each confirmed through its validation pipeline, and its findings were cross-referenced with public records.
Researchers at 1Password investigated the effectiveness of AI-generated vulnerability patches. They found that while frontier models often produce convincing code that may pass tests, only about one in four patches for six newly disclosed CVEs actually fixed the vulnerability. The remaining patches either addressed only part of the issue or introduced new flaws.
Cloudflare has open-sourced Cloudflare OS, an AI agent platform previously used internally since May. This platform tracks every resource an agent accesses and incorporates that context into its outputs. When an output is accessed, Cloudflare OS verifies that the user has permission to view the underlying data; for example, a dashboard built from a sensitive database table would remain hidden from users without access to that table.
OpenAI has updated its ChatGPT models, pushing GPT-5.6 Luna to free-tier users and GPT-5.6 Sol to Plus and Pro subscribers. The company has also removed text chat limits for free users and introduced new safeguards for teenagers.
Microsoft’s July 2026 Patch Tuesday was described as record-setting, with the highest volume of security patches ever released across nearly every product in its portfolio, addressing well over 600 CVEs. This has prompted discussions about the challenges of managing such a high volume of patches.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.