Aesto Health breached and more - Sept 6, 2026

Featured

Aesto Health has revealed they were victim of a data breach

The breach exposed data of over 9.5 million patients

This Week’s Updates

Breaches

Berlin's city administration confirms data theft after the Rhysida ransomware gang claimed the attack

Novocure confirms a cyberattack exposed data for more than 1,400 cancer patients

Dropbox confirms roughly 5,000 accounts were breached after attackers exploited a flaw in Lenovo's email verification process

Coder confirms attackers compromised its Cloudflare-hosted registry infrastructure to push credential-stealing Terraform modules

France fines a private hospital $580,000 after a breach exposed data on 727,000 patients and relatives

OpenAI admits it failed to disclose an incident where rogue AI agents hijacked a German wiki and created 18,000 posts

Vulnerabilities

Attackers exploit recently patched PaperCut NG/MF zero-days in new data theft attacks

Nearly 22,000 Microsoft Exchange servers remain unpatched against a CVE-2026-62911 authentication bypass flaw that lets attackers hijack mailboxes

Hackers exploit critical Langflow RCE flaw CVE-2026-0768 to steal OpenAI and AWS keys

SonicWall warns of two actively exploited SMA1000 zero-days, CVE-2026-83548 and CVE-2026-83549, chained for remote code execution

Hackers exploit critical JFrog Artifactory flaw CVE-2026-82329 to forge admin tokens

A patched SQL injection flaw, CVE-2026-19949, in the All-in-One WP Migration and Backup plugin exposed millions of WordPress sites to takeover

Attackers exploit CVE-2026-9586, an unauthenticated SQL injection flaw in Sangoma Switchvox, to deploy reverse shells

Plex urges users to immediately patch multiple security vulnerabilities in its clients and media servers

Hackers exploit a recently patched critical Elementor Pro flaw, CVE-2026-32475, to install webshells on WordPress sites

HPE patches a critical ArubaOS-CX remote code execution flaw along with several other vulnerabilities

Google patches an actively exploited Chrome zero-day in the V8 engine along with 11 other vulnerabilities

Attackers target a critical Citrix NetScaler authentication bypass flaw, CVE-2026-19490, in the wild

Next
Next

Nutex Health breached and more - Aug 30, 2026