Modern enterprise work no longer follows a neat path through a single network perimeter. Attackers move along the user’s workflow—email to chat, browser sessions into SaaS, and identity prompts toward the data those systems expose—revealing gaps in traditional security architectures.
The takeaway for defenders: treat identity, access paths, and data flows as the control plane. Security monitoring and enforcement must be “workspace-aware” so protections travel with the user session and the data it can reach.
Source: Check Point Blog
FBI probes a dark-web service selling 153M+ driver’s license scans tied to a major ID verification provider
A new identity theft service is reportedly selling digital scans of more than 153 million U.S. and Canadian driver’s licenses. KrebsOnSecurity reports the FBI has launched an official inquiry into the source of the images, and evidence suggests the data may have been siphoned from a widely-used Louisiana-based identity verification company.
If confirmed, this would represent an extreme scale of identity fraud enablement—where stolen documents can fuel account takeovers, synthetic identities, and downstream financial and criminal abuse.
Source: KrebsOnSecurity
Infostealers target Claude: session cookies stolen to hijack accounts and drain AI usage
Anthropic has warned that infostealers are stealing Claude session cookies from compromised users to access accounts and consume usage at the victim’s expense. This shifts “AI account takeover” closer to mainstream credential theft—except the monetizable asset is model access rather than only email or banking.
Defenders should assume cookie/session theft is feasible even with strong passwords and implement tighter endpoint protections, session anomaly detection, and rapid session invalidation for suspected compromises.
Source: Malwarebytes Blog
Malware campaign: “TerminalFix” CAPTCHA lure leads to access targeting the victim’s wider network
A familiar “ClickFix” fake CAPTCHA social-engineering scheme has been adapted into a new payload delivery flow called TerminalFix. The malicious page appears like a routine challenge but results in execution that can provide attackers broader access beyond a single machine.
The key risk is that “simple” web lures are increasingly used as staging steps for wider intrusions—so organizations should treat successful CAPTCHA-page interaction as an endpoint compromise indicator, not a dead-end scam.
Source: Malwarebytes Blog
Critical Langflow flaw (CVE-2026-0768) is being exploited: unauthenticated remote Python code execution
Attackers have begun exploiting a critical Langflow vulnerability tracked as CVE-2026-0768 (CVSS 9.8). The issue allows unauthenticated attackers to remotely execute Python code on systems using affected versions.
Given the move from disclosure to exploitation momentum, defenders should prioritize patching, constrain network exposure to the affected service, and monitor for signs of Python execution and follow-on activity immediately after upgrades.
Source: Security Affairs
JFrog Artifactory auth bypass (CVE-2026-82329) reported exploited within days—supply chain risk spikes
A critical JFrog Artifactory vulnerability (CVE-2026-82329) is reportedly being exploited in the wild just days after patch release. The flaw is an authentication bypass that could enable attackers to mint administrative tokens, turning a software supply chain component into a privileged control point.
This is a reminder that build and artifact services must be treated like production identity systems: enforce segmentation, monitor administrative token creation, and verify integrity of deployed artifacts during incidents.
Source: SecurityWeek
Chasing the root cause: CISA argues for eliminating vulnerability classes, not just patching CVEs
CISA’s review argues that treating vulnerabilities as an endless queue of individual fixes is exactly what attackers exploit. Instead, the agency recommends reducing “root causes” during development by eliminating entire vulnerability categories where feasible.
For security leadership, this supports shifting investment from purely reactive patch governance toward secure-by-design practices, safer defaults, and development-time guardrails that prevent recurring classes of flaws.
Source: Help Net Security
You May Also Be Interested In...
SonicWall warns of two SMA1000 zero-days exploited in attacks (CVE-2026-83549, CVE-2026-83548)
SANS ISC Stormcast for Wednesday, September 2nd, 2026
FBI probe / idscan.net exposure allegations: more on the 153M+ driver’s license dataset