Saturday · September 5, 2026 Vol. I · No. 247
Independent · Aggregated · Daily
"All the news that's worth your time"
Established 2026
The

Krull Report

A Daily News Brief · Curated by Vladimir Krull
Live
Glasner and Williams dispute VAR call over Forest handball Four Men Cry as Conor Benn Recalls Night He Almost Took His Life Williams goal 'should not have been disallowed' - Glasner Fulham booed off after third defeat in a row Putin says no strikes on Kiev have been carried out since midnight Trump continues to try to contribute to resolution of conflict in Ukraine — Putin Artificial Analysis overhauls its Intelligence Index after GPT-6 Astra scoring drew skepticism Russian air defenses down six Ukrainian drones Saturday Glasner and Williams dispute VAR call over Forest handball Four Men Cry as Conor Benn Recalls Night He Almost Took His Life Williams goal 'should not have been disallowed' - Glasner Fulham booed off after third defeat in a row Putin says no strikes on Kiev have been carried out since midnight Trump continues to try to contribute to resolution of conflict in Ukraine — Putin Artificial Analysis overhauls its Intelligence Index after GPT-6 Astra scoring drew skepticism Russian air defenses down six Ukrainian drones Saturday

Cybersecurity

Technology · Cybersecurity

GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE

A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL inje…

Technology · Cybersecurity

ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories

Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud services, AI tools, …

TECHNOLOGY
Technology · Cybersecurity

Hackers breach govt webmail while running parallel crypto fraud

The Jewelbug hacker group has been carrying out espionage operations targeting governments and militaries while also engaging in cryptocurrency fraud. [...]

TECHNOLOGY
Technology · Cybersecurity

Microsoft patches LegacyHive Windows zero-day vulnerability

Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday. [...]

TECHNOLOGY
Technology · Cybersecurity

AI 'watermark removers' flood the web. Almost none can prove they work.

Multiple 'watermark removers' have surfaced days after Anthropic began watermarking text generated by Claude, including an open source project with over 4,500 GitHub stars and pai…

TECHNOLOGY
Technology · Cybersecurity

Critical VMware vCenter RCE flaw exploited for reverse SSH access

A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence an…

TECHNOLOGY
Technology · Cybersecurity

Trezor discloses data breach affecting nearly 14,000 customers

Hardware wallet manufacturer Trezor disclosed a data breach affecting nearly 14,000 of its customers after ShipMonk, its shipping provider and logistics partner, got hacked. [...]

Technology · Cybersecurity

New PATCHCORD Backdoor Targets Afghan Telecom and Indian Critical Infrastructure

Afghan telecom providers and South Asian critical infrastructure organizations have emerged as the target of a new ongoing campaign that delivers a previously undocumented backdoo…

TECHNOLOGY
Technology · Cybersecurity

Who Vets AI’s Code? The Scale Challenge Facing Open Source Ingestion

AI coding tools can introduce unvetted or hallucinated open source dependencies faster than traditional security reviews can keep pace. ActiveState explains why organizations shou…

Technology · Cybersecurity

AmnesiaStealer Hijacks Chromium Sessions to Give Attackers Live Browser Control on macOS

Cybersecurity researchers have disclosed details of a new macOS-oriented, Rust-based information stealer called AmnesiaStealer that's capable of hijacking Chromium web browsers to…

TECHNOLOGY
Technology · Cybersecurity

White House taps security firms for offensive hack-back operations

A new White House memo signed by U.S. President Donald Trump instructs the National Coordination Center (NCC) to establish a program that would allow private security companies to…

Technology · Cybersecurity

WindRelay Android Malware Turns Victims' Phones Into NFC Relays for Payment Fraud

A previously unseen Android near field communication (NFC) relay malware family dubbed WindRelay is being deployed in conjunction with a known remote access trojan (RAT) called Sp…

TECHNOLOGY
Technology · Cybersecurity

WhatsApp rolls out new feature that flags potential scam messages

WhatsApp has begun rolling out a new optional "Scam Alert" feature, which uses a local machine learning model to warn users when scammers are targeting them. [...]

Technology · Cybersecurity

North Korean Remote Workers Are Infiltrating Government and Businesses: How to Expose Them Before Hiring

Companies are used to thinking about attackers as outsiders trying to break in. North Korean IT workers flip that model. They apply for jobs, pass interviews, receive legitimate c…

Technology · Cybersecurity

Attackers Exploit SharePoint Authentication Bypass After Public PoC Release

Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is C…

TECHNOLOGY
Technology · Cybersecurity

"City-Forum" data-theft attacks target Salesforce, ServiceNow portals

An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...]

TECHNOLOGY
Technology · Cybersecurity

Android malware combo takes out loans and relays victims' credit cards

A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time…

TECHNOLOGY
Technology · Cybersecurity

Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack cus…

TECHNOLOGY
Technology · Cybersecurity

Hundreds of fake Chrome VPN extensions route traffic through a proxy

More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a…

Technology · Cybersecurity

Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor

The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a nev…

TECHNOLOGY
Technology · Cybersecurity

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Security researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor softwa…

TECHNOLOGY
Technology · Cybersecurity

Lazarus hackers exploited Windows zero-day to target defense firms

North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]

TECHNOLOGY
Technology · Cybersecurity

FBI: Hackers target online accounts to steal nude photos

The FBI warns that cybercriminals are targeting adults' and children's social media and other online accounts to steal sexually explicit images or videos. [...]

Technology · Cybersecurity

737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One

A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traf…