Sam's News β security β 2026-09-04¶
Security¶
8 IDScan Data Breach Exposes 153 Million Driver's Licenses¶
Identity verification company IDScan faces multiple lawsuits after hackers allegedly breached the system and stole 153 million driver's licenses.
Sources: BleepingComputer RSS
8 HPE Patches Critical RCE Vulnerabilities in AOS-CX Switches¶
HPE patched 34 CVEs in Aruba AOS-CX, including nearly two dozen critical remote code execution flaws with CVSS 9.8 that allow unauthenticated attackers to execute commands via malformed packets. Additional updates address 22 high-severity and 11 medium-severity vulnerabilities across multiple AOS-CX versions.
- ~24 critical RCE vulnerabilities, CVSS score 9.8, tracked as CVE-2026-73749
- Unauthenticated attacker can achieve RCE with elevated privileges via crafted packets
- 34 total CVEs patched; also includes 22 high-severity and 11 medium-severity flaws
- Affects AOS-CX versions 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, 10.10.1181
- No known exploitation in the wild; majority discovered internally by HPE
Sources: SecurityWeek AI Web Searched
8 Citrix NetScaler critical authentication bypass exploited in active attacks¶
Attackers are actively exploiting CVE-2026-19490, a critical authentication bypass vulnerability in Citrix NetScaler.
Sources: BleepingComputer RSS
7.5 PostgreSQL hit by 12-year-old vulnerability enabling server takeover¶
PostgreSQL is affected by a decade-old security vulnerability that permits complete server compromise through logical decoding.
Sources: securityaffairs.com RSS, The Hacker News RSS Update to: Decade-old PostgreSQL vulnerability enables backup account backdoor access
7 Virtual Machines Insufficient to Contain Advanced AI Agents¶
Security researchers, including Bruce Schneier, found that standard virtual machines lack sufficient containment for advanced AI agents like GPT 5.6-Cyber, as even benign features such as display functionality introduce exploitable vulnerabilities. The findings suggest fundamental reassessment of sandboxing quality in software stacks used by cyber-enabled AI agents.
- Standard VMs insufficient to contain GPT 5.6-Cyber and similar advanced agents
- Display functionality and other benign VM features introduce exploitable attack surface
- Cyber-enabled AI agents' software stack requires fundamental sandboxing reassessment
Sources: Schneier on Security AI Web Searched
7 OpenAI Pledges $1 Billion Daybreak Initiative for Critical Infrastructure AI Security¶
OpenAI announced the Daybreak initiative, pledging $1 billion to provide subsidized AI capabilities, training, and technical assistance to critical infrastructure defenders.
Sources: SecurityWeek RSS
7 CISA warns of old ownCloud vulnerability after Philippine nuclear data theft report¶
CISA flagged an old ownCloud vulnerability following reports of a data theft incident involving Philippine nuclear information.
Sources: TechRepublic RSS
7 High-volume phishing campaign uses invisible Unicode to bypass email filters¶
Microsoft reported a large-scale phishing campaign exploiting invisible Unicode tag characters to evade email security filters and deliver financial fraud lures.
- High-volume phishing campaign started February 9, 2026
- Uses invisible Unicode tag characters (U+E0000βU+E007F) to split keywords like 'funding'
- Technique adapted from AI prompt injection research
- Microsoft Defender detections elevated for approximately three months
- Most flagged messages caught by layered protections rather than single Unicode signals
Sources: The Hacker News RSS Update to: Unicode smuggling technique adapted for email phishing evasion
7 SonicWall warns of actively exploited vulnerabilities in SMA1000 appliances¶
SonicWall issued warnings about actively exploited security vulnerabilities affecting its SMA1000 remote access appliances.
Sources: The HIPAA Journal RSS Update to: SonicWall SMA 1000 Critical Zero-Day Enables Unauthenticated Remote Compromise
6 Astra launches, CISA cuts programs, McKesson breach in security briefing¶
Recent developments include OpenAI's Astra launch, CISA program reductions, and a confirmed McKesson data breach.
Sources: CISO Series RSS