A curated dispatch from GajShield

The GajShield Gazette

Lead story
Also today
In brief

Fake Software Installers Turn Windows Security Features Against the Endpoint.

An active malware campaign using fake software download websites to impersonate well-known vendors demonstrates how effective social engine…

Sep 03, 2026

WordPress backup plugin flaw exposes millions of sites to takeover attacks

A high-severity vulnerability in the widely used All-in-One WP Migration and Backup plugin demonstrates how software intended to protect an…

Sep 03, 2026

CISA Adds Seven Known Exploited Vulnerabilities to Catalog

CISA's addition of seven vulnerabilities to its Known Exploited Vulnerabilities Catalog on September 2, 2026 is significant because the lis…

Sep 02, 2026

Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control

The discovery of the StreamRat Android banking trojan being distributed through advertisements on Meta platforms highlights how rapidly mal…

Sep 02, 2026

When the Web Server Becomes the Attacker: Malicious Apache Modules Hijack Trusted Government Websi

The discovery of malicious Apache modules being used to hijack Brazilian government and educational websites highlights a particularly dang…

Sep 02, 2026

Hackers exploit critical JFrog Artifactory flaw to forge admin tokens

The active exploitation of CVE-2026-82329 in JFrog Artifactory is a particularly serious software supply-chain risk because attackers are n…

Sep 02, 2026

Dropbox accounts breached through Lenovo email verification flaw

The compromise of approximately 5,000 Dropbox accounts through a flaw involving Lenovo ID is a strong example of how modern authentication …

Sep 02, 2026

SonicWall warns of actively exploited SMA1000 zero-day flaws

The actively exploited zero-day vulnerabilities affecting SonicWall SMA1000 appliances deserve immediate attention because secure remote-ac…

Sep 02, 2026

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

The active exploitation of CVE-2026-9586 in Sangoma Switchvox deserves urgent attention because it turns an internet-facing enterprise tele…

Sep 02, 2026

Leaked compliance records shatter anonymity of 291 crypto users by matching names directly to wallet activity

The Pocket Bitcoin breach is relatively small by victim count, affecting 291 customers, but the exposed data is unusually sensitive because…

Sep 02, 2026

Aesto Health Data Breach Exposes 95 Million Patient Records

The Aesto Health data breach is significant not only because of its scale but because it again demonstrates how healthcare organizations ac…

Sep 02, 2026