Saturday · September 5, 2026 Vol. I · No. 247
Independent · Aggregated · Daily
"All the news that's worth your time"
Established 2026
The

Krull Report

A Daily News Brief · Curated by Vladimir Krull
Live
Putin says no strikes on Kiev have been carried out since midnight Trump continues to try to contribute to resolution of conflict in Ukraine — Putin Artificial Analysis overhauls its Intelligence Index after GPT-6 Astra scoring drew skepticism Russian air defenses down six Ukrainian drones Saturday Pavel Andrusca Shines In UFC Paris Debut After Accepting Nathaniel Wood Fight On Just Five Days’ No… UFC Paris ‘Hooker vs. Parnasse’ play-by-play, results & round scoring OpenAI confirms ‘wiki incident,’ says it’s ‘working on a framework’ for more disclosure Egyptian TV presenter among 12 sentenced to death for drug crime Putin says no strikes on Kiev have been carried out since midnight Trump continues to try to contribute to resolution of conflict in Ukraine — Putin Artificial Analysis overhauls its Intelligence Index after GPT-6 Astra scoring drew skepticism Russian air defenses down six Ukrainian drones Saturday Pavel Andrusca Shines In UFC Paris Debut After Accepting Nathaniel Wood Fight On Just Five Days’ No… UFC Paris ‘Hooker vs. Parnasse’ play-by-play, results & round scoring OpenAI confirms ‘wiki incident,’ says it’s ‘working on a framework’ for more disclosure Egyptian TV presenter among 12 sentenced to death for drug crime

Cybersecurity

TECHNOLOGY
Technology · Cybersecurity

Microsoft starts removing WMIC tool used by cybercriminals

Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released …

Technology · Cybersecurity

CISA Flags Actively Exploited Ray Flaw That Can Trigger Browser-Based RCE

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a critical flaw impacting Ray to its Known Exploited Vulnerabilities (KEV) catalog, citing evidenc…

Technology · Cybersecurity

Critical GitLab GraphQL Flaw Could Let Unauthenticated Attackers Delete Public Projects

GitLab has released security updates to address a critical vulnerability impacting its Community Edition (CE) and Enterprise Edition (EE) software that, under certain conditions, …

TECHNOLOGY
Technology · Cybersecurity

Hacker claims 3.6 million Azure account records stolen from major companies

A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised cred…

TECHNOLOGY
Technology · Cybersecurity

Pokémon Center data breach exposes customer info, cancels some orders

Pokémon Center is notifying customers in the United Kingdom and Germany that it suffered a third-party data breach after hackers stole customer personal and order information from…

Technology · Cybersecurity

Snowflake GitHub Actions Flaw Lets Crafted Issues Trigger Command Injection

Cybersecurity researchers at Wiz have disclosed a new GitHub Actions workflow injection vulnerability in Snowflake's public snowflakedb/snowflake-connector-net repository that it …

Technology · Cybersecurity

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code …

Technology · Cybersecurity

Cavern C2 Uses DNS and Google Apps Script to Blend Into Legitimate Traffic

Cybersecurity researchers have traced the continued evolution of the Cavern (aka Cav3rn) command-and-control (C2) framework used by Iranian nation-state hackers in attacks targeti…

TECHNOLOGY
Technology · Cybersecurity

Microsoft confirms GitHub is down worldwide

GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services. [...]

TECHNOLOGY
Technology · Cybersecurity

Certighost and the Privilege Hiding in Your Certificate Authority

CVE-2026-54121 lets a standard domain user turn your Enterprise CA into a Domain Controller. The patch is the easy part. The lesson is standing privilege, implicit trust, and trea…

Technology · Cybersecurity

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old bugs found fresh use, browser sessions became attack paths, and …

TECHNOLOGY
Technology · Cybersecurity

Windows Server 2022 reaches end of mainstream support in 60 days

Microsoft has reminded IT administrators that Windows Server 2022 is rapidly approaching its mainstream end date of October 2026, when it will switch to extended support. [...]

Technology · Cybersecurity

How MCP Servers Can Expose Enterprise Secrets

MCP servers can expose enterprise secrets through plaintext configuration files, over-permissioned access and prompt injection, often before security teams even know the server is…

TECHNOLOGY
Technology · Cybersecurity

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

Technology · Cybersecurity

Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access

Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a …

TECHNOLOGY
Technology · Cybersecurity

French tax authority data breach affects 678,000 individuals

The French Ministry of the Economy and Finance has disclosed a data breach after an attacker accessed the General Directorate of Public Finances (DGFiP) systems and stole data bel…

Technology · Cybersecurity

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is …

TECHNOLOGY
Technology · Cybersecurity

Microsoft working on Defender patch for ShieldBreak zero-day

Microsoft is working on a security patch for the "ShieldBreak" zero-day vulnerability disclosed last week by security researcher "Nightmare Eclipse" and now tracked as CVE-2026-69…

Technology · Cybersecurity

Suspected China-Nexus Actor Exploits VMware vCenter Flaw, Deploys Babuk-Derived Ransomware

Cybersecurity researchers have attributed the exploitation of a newly patched security flaw in Broadcom VMware vCenter to a suspected China-nexus advanced persistent threat (APT).…

TECHNOLOGY
Technology · Cybersecurity

SafePal data breach impacts 39,798 customers, stolen info for sale

Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a …

TECHNOLOGY
Technology · Cybersecurity

Anthropic confirms Claude is down in major outage affecting multiple services

Claude is experiencing a major outage, with users reporting login problems and degraded performance across several Anthropic services. [...]

TECHNOLOGY
Technology · Cybersecurity

Large-scale DDoS attacks disrupted Threema secure messaging service

Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. [...]

TECHNOLOGY
Technology · Cybersecurity

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the attacker to interactively con…

TECHNOLOGY
Technology · Cybersecurity

New Evooo1Bot Linux botnet turns routers into traffic relay nodes

A new Mirai-based modular Linux botnet malware called Evooo1Bot has been targeting internet-facing gateway devices, turning them into SOCKS5 traffic relay nodes. [...]