Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Friday, September 4, 2026

Here are today’s top cybersecurity stories for Friday, September 4, 2026.

Google Patches Chrome Zero-Day Under Active Attack
Google released Chrome 152.0.7977.82/83 to fix CVE-2026-85046, a CVSS 8.8 type confusion flaw in the V8 JavaScript engine already exploited in the wild. The bug lets an attacker execute code inside Chrome’s sandbox once a victim opens a crafted web page. CISA added the flaw to its Known Exploited Vulnerabilities catalog the same day. Help Net Security | SecurityWeek

12-Year-Old PostgreSQL Flaw Enables Full Server Takeover
Researchers disclosed CVE-2026-6471, dubbed PostGREShell, a missing-authorization bug in PostgreSQL logical decoding present since version 9.4 shipped in 2014. An account holding the REPLICATION privilege loads an arbitrary file as a decoding plugin and runs code as the server’s operating system account, gaining permanent superuser access. Patches ship in versions 18.6, 17.11, 16.15, 15.19, and 14.24. SecurityWeek

Storm Ransomware Group Claims Saskatchewan Construction Firm
The Storm ransomware group listed Petrocare Construction, a Saskatoon, Saskatchewan contractor, on its extortion leak site, threatening to publish stolen files unless the company makes contact. Petrocare builds commercial, industrial, wholesale, and retail petroleum facilities across Western Canada. No confirmed details on the volume or type of data taken have surfaced. DeXpose

Citrix NetScaler Authentication Bypass Now Under Active Exploitation
Attackers began exploiting CVE-2026-19490, a CVSS 9.3 authentication bypass affecting NetScaler ADC and Gateway, after a working proof-of-concept exploit appeared online. Security firms report exploitation attempts against unpatched systems from multiple source addresses. Citrix shipped fixes last month and urges immediate patching. The Hacker News

Coder Registry Breach Delivered Credential-Stealing Terraform Modules
Attackers compromised the Cloudflare-fronted infrastructure behind registry.coder.com and added rogue servers serving malicious Terraform modules for roughly 14 hours on August 31. The modules searched developer environments for cloud, CI/CD, and AI-tooling credentials and sent them to a lookalike domain. Coder says no customer data held in its own systems was affected. BleepingComputer

Unverified CrowdStrike Falcon Zero-Day Published as Proof of Concept
A researcher using the handle Nightmare Eclipse released proof-of-concept code named FalconFlank, claiming to escalate privileges to SYSTEM on fully patched Windows systems running CrowdStrike Falcon. The technique reportedly abuses Falcon’s malicious-macro remediation feature. CrowdStrike has not confirmed the flaw, assigned a CVE, or shipped a fix. BleepingComputer

WatchGuard Fixes Five Critical Firewall Vulnerabilities
WatchGuard patched more than 20 flaws across Fireware OS and Dimension, including three unauthenticated critical bugs in the iked process rated CVSS 9.3. A fourth critical flaw in Dimension lets a low-privileged administrator retrieve a Super Admin session ID from diagnostic logs. WatchGuard says it has not observed exploitation. SecurityWeek

Microsoft 365 Outage Disrupts Exchange Online and Teams
Microsoft confirmed an Exchange Online authentication issue causing email delays and “Server busy” errors for external mail, alongside a separate issue blocking some users from opening the Teams desktop client. Both issues surfaced over the past two days and remain under investigation. BleepingComputer

22-Year-Old BMC Flaw Leaves Thousands of Data Centers Exposed
Security firm Lava found more than 24,000 internet-accessible servers exposing authentication hashes before login through CVE-2013-4786, a decades-old flaw in Baseboard Management Controllers. The bug supports remote code execution and authentication bypass on some of the most privileged hardware inside a data center. Researchers report evidence of exploitation attempts in the wild. SecurityWeek

OpenAI Commits $1 Billion to Free Cyber Defense Access
OpenAI pledged $1 billion to subsidize access to its Daybreak cyber models for organizations defending water and wastewater systems, the electric grid, state and local government, community banks, and open-source projects. The program targets defenders lacking budget for enterprise-grade AI security tools. Help Net Security

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.