A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.PaperCut Flaws Exploited in Attacks on U.S. and European SchoolsBroadcom Patches Critical VMware Workstation and Fusion VM-Escape VulnerabilitiesU.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalogCrooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million PeoplePostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server TakeoverChinese Hackers Use AI Agents in Multi-Country Cyber CampaignGoogle fixes the sixth actively exploited Chrome zero-day of 2026Dark Web Service Nexus Sells 153M+ Driver’s Licenses2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber OperatorsOpenAI Astra Brings Autonomous Zero-Day Exploitation to AISonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNs$536 and 8 Hours: AI Learns to Attack a Different PLCIran-linked APT Mirage Kitten Uses Fake Job Tests to Spread MalwareHackers Target Langflow in CVE-2026-0768 AttacksAttackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million RecordsChaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPragueFive Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting AttemptNorth Korea-linked IT Workers Are Getting Hired Inside Western CompaniesChaotic Eclipse Releases Kaspersky Zero-Day HardBreacherU.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalogValleyRAT: When Legitimate Software Becomes a Malware Delivery ToolChina-linked Fire Ant Hides Inside Trusted InfrastructureInfostealers Are Hijacking Claude Sessions and Draining SubscriptionsCritical GiveWP Flaw Lets Attackers Run Commands on WordPress ServersExtortion Group FulcrumSec Claims 86GB Manchester Airports Group Data TheftHackers Are Probing PaperCut Servers, and 47% Still Have No PatchInternational Press – NewsletterCybercrimeFulcrumSec claims Manchester Airports hack, theft of 86 GB of dataAurora ransomware targets ESXi, abuses Cursor Agent for exploitation FBI investigation leads to five Venezuelan nationals pleading guilty to attempting to jackpot Kansas ATMs FBI Probes Service Selling 153M+ Drivers LicensesTwo Nigerian Nationals Extradited from Nigeria to the United States to Face Sextortion Charges in North Carolina and Mississippi The Town 2025 ticketing data sold as a Ticketmaster breach Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon September 2, 2026 Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and UniversitiesASCII smuggling crosses over from AI prompt injection to phishing evasionMalwareHackers Steal Claude Login Sessions With Infostealer Malware to Hijack AccountsGryxa: The AI-Built Toolkit That Watches How You Remove ItValleyRAT masquerading as adware 13 Malicious Packagist Themes Deliver iOS Spyware That Steals Crypto Wallet Seeds Mini Shai-Hulud’s Latest Wave: 280 New Places It Hunts for Your Secrets HackingEclypsium flags 1,051 CVEs in infrastructure advisories Unauthenticated PHP Object Injection to Remote Code Execution on GiveWP Kaspersky zero-day exploit HardBreacher PrettyPrague: GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Same Target, Different Playbooks: Two Attackers, Two Different Paths to Pwning the AI Stack Can AI Create PLC Attacks? Yes, But It’s Not That Easy Yet Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack ChainFalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in Crowdstrike Falcon Cloud Sync Root RegistrationShieldBreak: Hunting Windows Defender Remediation Abuse and Cloud Files Hijacking Google Releases Chrome Update to Patch Actively Exploited V8 Zero-DayWhen Sorting Leads To Confusion Intelligence and Information Warfare Pegasus Spyware Infection of Serbian Pro-Democracy Student ActivistFire Ant Evolves: From Hypervisors to Trusted InfrastructureInsights into Suspected DPRK Workers: Red Flags to Look Out For Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set Leaked Russian Cyber-Operations Training Materials Threat Intelligence Report: University Leak Exposes Russia’s Military Cyber Training Pipeline Chinese-Speaking Operator Uses AI Agents to Target Government and Education Systems Across AsiaHow the Russians Got Inside My PhoneDPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors CybersecurityJudge says Pentagon’s measures against Anthropic were ‘illegal and baseless’ How AI could make it harder for governments to use hacking tools Own a gun? Go to church? Do yoga? AI can find out in seconds Path to Astra: critical capabilities and frontier safeguards PostGREShell: The database powering much of the internet had an open door for 12 years Fighting AI with AI: The US’s New Cyber Rules of Engagement ATM Flaws Reveal Key Weaknesses in the Software Supply Chain Follow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, newsletter)