Friday · September 4, 2026 Vol. I · No. 246
Independent · Aggregated · Daily
"All the news that's worth your time"
Established 2026
The

Krull Report

A Daily News Brief · Curated by Vladimir Krull
Live
Head of Ukraine’s Presidential Office Kyrylo Budanov says he regularly spoke with Wagner Group foun… 15/18 A Place to Heal review – heartfelt docu-realist study of a French teen psychiatric facility Bath show highlights sibling finds – and England’s first paid female astronomer Not a cheetah: Ancient DNA reveals the surprising Arctic life of extinct North American cat OpenAI agents hijacked German website before Hugging Face hack, report claims Rescue satellite gets close to NASA's doomed telescope, even if it can't save it NetworkManager Works To Enforce AI Policy By Tricking AI Agents To Add A Canary - phoronix.com Russia proves at EEF that sanctions ineffective, Srbijagas CEO says Head of Ukraine’s Presidential Office Kyrylo Budanov says he regularly spoke with Wagner Group foun… 15/18 A Place to Heal review – heartfelt docu-realist study of a French teen psychiatric facility Bath show highlights sibling finds – and England’s first paid female astronomer Not a cheetah: Ancient DNA reveals the surprising Arctic life of extinct North American cat OpenAI agents hijacked German website before Hugging Face hack, report claims Rescue satellite gets close to NASA's doomed telescope, even if it can't save it NetworkManager Works To Enforce AI Policy By Tricking AI Agents To Add A Canary - phoronix.com Russia proves at EEF that sanctions ineffective, Srbijagas CEO says

Cybersecurity

Technology · Cybersecurity

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Sym…

Technology · Cybersecurity

Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means

In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environm…

TECHNOLOGY
Technology · Cybersecurity

Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs

Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026…

Technology · Cybersecurity

Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone

The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboratio…

Technology · Cybersecurity

Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation…

Technology · Cybersecurity

CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in …

TECHNOLOGY
Technology · Cybersecurity

Hackers exploit Sangoma Switchvox flaw to deploy reverse shells

Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]

TECHNOLOGY
Technology · Cybersecurity

WordPress backup plugin flaw exposes millions of sites to takeover attacks

An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affe…

Technology · Cybersecurity

Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new…

Technology · Cybersecurity

Fake Software Installers Disable Windows Update and Weaken Microsoft Defender

An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking t…

TECHNOLOGY
Technology · Cybersecurity

Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]

Technology · Cybersecurity

Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code

Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs o…

TECHNOLOGY
Technology · Cybersecurity

Ransomware protection for MSPs: A 6-point checklist for faster recovery

Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure…

Technology · Cybersecurity

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and edu…

Technology · Cybersecurity

BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access

Virtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtua…

TECHNOLOGY
Technology · Cybersecurity

Dropbox accounts breached through Lenovo email verification flaw

Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs. [..…

Technology · Cybersecurity

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

Cybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming c…

Technology · Cybersecurity

How to Secure Enterprise AI: From Adoption to Incident Readiness

The debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while meeting board-level pressure to…

Technology · Cybersecurity

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day atta…

TECHNOLOGY
Technology · Cybersecurity

Microsoft Defender flags legitimate Google search links as malicious

Microsoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links. [...]

Technology · Cybersecurity

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many gove…

Technology · Cybersecurity

Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malw…

TECHNOLOGY
Technology · Cybersecurity

US charges Russian for infecting 80,000 freelancers with malware

A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. [...]

TECHNOLOGY
Technology · Cybersecurity

Sality botnet infrastructure dismantled in joint global takedown

International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botn…