Here are today’s top cybersecurity stories for Thursday, September 3, 2026.
Thomson Reuters Discloses Breach of US and Canadian Court Records
Thomson Reuters disclosed an unauthorized party accessed files from C-Track, a court case management platform operated by its West Publishing unit, during March 2026. The exposure reaches 24 court bodies across 11 US states, the US Virgin Islands, and Ontario, including the Ontario Superior Court of Justice. A subset of the exposed records lists names, Social Security numbers, driver’s license numbers, dates of birth, and medical information. Help Net Security | The Hacker News
Sangoma Switchvox SQL Injection Flaw Under Active Exploitation
CISA added CVE-2026-9586, a CVSS 9.3 unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition, to its Known Exploited Vulnerabilities catalog. The flaw lets an attacker execute arbitrary SQL statements as the backend PostgreSQL superuser without credentials, a path to remote code execution. Sangoma patched the issue in Switchvox 8.4.0.2 on July 14, 2026, and federal agencies face a September 5 remediation deadline. The Hacker News
CISA Adds Seven Flaws to Known Exploited Vulnerabilities Catalog
CISA added seven vulnerabilities to its KEV catalog based on evidence of active exploitation, including flaws in Sangoma Switchvox, Kludex Starlette, Kestra OSS, BerriAI LiteLLM, JFrog Artifactory, and two SonicWall SMA1000 appliance bugs. CISA says a threat actor used the Kestra OSS command injection flaw in late June to establish a reverse shell, enumerate Docker containers, and deploy a cryptocurrency miner. Remediation deadlines run from September 5 to September 16. CISA
Critical Flaws Patched in Cisco Nexus 9000 Switches and IOS XR Software
Cisco disclosed a CVSS 9.8 vulnerability in Nexus 9000 switches built on Silicon One ASICs, leaving two TCP ports reachable by default and letting an attacker who reaches the switch’s address execute code with root privileges. Cisco also patched two IOS XR flaws carrying the same CVSS score, covering memory-safety bugs and missing authentication for critical functions. Cisco published an access-control-list workaround for organizations unable to patch immediately. The Hacker News
Novocure Discloses Breach Affecting Cancer Patients and Employees
Oncology company Novocure says an August cyberattack exposed data belonging to more than 1,400 US cancer patients along with an undisclosed number of employees. Most affected patient records contained ID numbers without names, though fewer than 50 patients in the western United States had identifying and contact information exposed. Novocure says the attack did not reach its medical treatment devices or affect ongoing operations. BleepingComputer
Malicious Composer Packages Target Vietnamese Streaming Sites With iOS Spyware
Researchers identified 13 malicious Composer theme packages on the Packagist registry designed to inject JavaScript into Vietnamese movie and comic streaming sites. The injected code initiates delivery of spyware aimed at unpatched iOS devices visiting the compromised sites. The Hacker News
FBI Warns OAuth Consent Phishing Gives Attackers Persistent Account Access
The FBI’s Internet Crime Complaint Center warned attackers are using OAuth consent phishing to gain lasting access to email and files belonging to prominent individuals and their contacts. Victims are lured to a legitimate Google or Microsoft permission screen and grant a malicious application access by clicking allow, a step surviving a password change and undone only by revoking the application’s token. The campaign has run since late 2025. Help Net Security | CyberScoop
Google Launches Gemini 3.8 Flash Cyber for Vulnerability Discovery and Patching
Google introduced Gemini 3.8 Flash alongside Gemini 3.8 Flash Cyber, a specialized variant tuned to find software vulnerabilities and generate working patches. Access to the Cyber variant is restricted to governments, critical infrastructure operators, and software maintainers vetted through Google’s Fairwind Program. Google reports the model produces 2.6 times more correct Chrome vulnerability patches than the larger commercial models it tested against. Help Net Security
Windows to Enable Memory Integrity Protection Automatically Starting October
Microsoft says Windows quality updates will begin turning on memory integrity protection automatically for eligible devices starting in October 2026, requiring little or no additional configuration. The feature blocks a class of kernel-level attacks by preventing unsigned or improperly signed code from running in protected memory regions. Help Net Security
Stay tuned for today’s in-depth analysis posts.






