Friday · September 4, 2026 Vol. I · No. 246
Independent · Aggregated · Daily
"All the news that's worth your time"
Established 2026
The

Krull Report

A Daily News Brief · Curated by Vladimir Krull
Live
Five reasons the explosive NFL passing game has plummeted over the past decade and will it ever ret… Head of Ukraine’s Presidential Office Kyrylo Budanov says he regularly spoke with Wagner Group foun… 15/18 A Place to Heal review – heartfelt docu-realist study of a French teen psychiatric facility Bath show highlights sibling finds – and England’s first paid female astronomer Not a cheetah: Ancient DNA reveals the surprising Arctic life of extinct North American cat Cowboys add veteran tight end to practice squad OpenAI agents hijacked German website before Hugging Face hack, report claims Rescue satellite gets close to NASA's doomed telescope, even if it can't save it Five reasons the explosive NFL passing game has plummeted over the past decade and will it ever ret… Head of Ukraine’s Presidential Office Kyrylo Budanov says he regularly spoke with Wagner Group foun… 15/18 A Place to Heal review – heartfelt docu-realist study of a French teen psychiatric facility Bath show highlights sibling finds – and England’s first paid female astronomer Not a cheetah: Ancient DNA reveals the surprising Arctic life of extinct North American cat Cowboys add veteran tight end to practice squad OpenAI agents hijacked German website before Hugging Face hack, report claims Rescue satellite gets close to NASA's doomed telescope, even if it can't save it

Cybersecurity

Technology · Cybersecurity

Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controll…

Technology · Cybersecurity

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnera…

Technology · Cybersecurity

Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads

The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operat…

TECHNOLOGY
Technology · Cybersecurity

SonicWall warns of actively exploited SMA1000 zero-day flaws

SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]

Technology · Cybersecurity

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Bas…

TECHNOLOGY
Technology · Cybersecurity

Hackers abuse Faronics Deploy admin tool to install ScreenConnect

Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect r…

TECHNOLOGY
Technology · Cybersecurity

Aesto Health says data breach affects over 9.5 million patients

Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. [...]

TECHNOLOGY
Technology · Cybersecurity

Critical Langflow flaw exploited to steal OpenAI and AWS keys

Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal cr…

Technology · Cybersecurity

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in q…

Technology · Cybersecurity

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024…

TECHNOLOGY
Technology · Cybersecurity

Hackers push malicious Virtualizor update in BGP hijacking attack

Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicio…

TECHNOLOGY
Technology · Cybersecurity

Novocure data breach affects more than 1,400 cancer patients

Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. [...]

Technology · Cybersecurity

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streami…

TECHNOLOGY
Technology · Cybersecurity

Why Even the Best Edge Security Still Misses High-Risk Sessions

Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how…

Technology · Cybersecurity

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely exp…

TECHNOLOGY
Technology · Cybersecurity

Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks

Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailb…

Technology · Cybersecurity

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command …

TECHNOLOGY
Technology · Cybersecurity

Five Venezuelans plead guilty to ATM jackpotting attacks in US

Five Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. [...]

Technology · Cybersecurity

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability t…

Technology · Cybersecurity

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis

Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine …

TECHNOLOGY
Technology · Cybersecurity

Recently patched PaperCut zero-days used in data theft attacks

Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks.…

Technology · Cybersecurity

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity

Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - …

TECHNOLOGY
Technology · Cybersecurity

Cronos blockchain restarts after $74 million Tectonic exploit

The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 mill…

TECHNOLOGY
Technology · Cybersecurity

Microsoft warns of TerminalFix attacks deploying reverse tunnels

A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Termi…