Cybersecurity News Digest — September 4, 2026

An unauthenticated root RCE hits Cisco Nexus 9000 switches, Thomson Reuters discloses a five-month-old breach that exposed sealed court records across a dozen jurisdictions, and a Microsoft Teams vishing campaign nets 150+ victims.

Today’s stories run on three different clocks: a switch vulnerability patched before anyone’s seen it exploited, a breach disclosed five months after the fact, and a social-engineering campaign that’s likely still running right now. Here’s what’s new since yesterday’s digest.

Vulnerability watch: Critical, unauthenticated root RCE in Cisco Nexus 9000 switches

Cisco disclosed CVE-2026-20212 on September 2 — a CVSS 9.8 flaw in the Silicon One ASIC integration used by ten Nexus 9000 product variants. TCP ports 43210 and 43211 are reachable by default through the switch’s Layer 3 VRF instance, and an unauthenticated attacker who can reach either port can send crafted input that executes as code with root privileges. A failed or partial exploitation attempt can also crash the switch’s S1HAL process and force a reload, so this is a denial-of-service risk even for attackers who don’t get code execution. Cisco found the bug while working a TAC support case and, as of September 3, says it has no evidence of public exploitation or proof-of-concept code. Nexus 3000, Nexus 7000, non-Silicon-One 9000 models, and Nexus 9000 Fabric Switches in ACI mode are not affected. Cisco Security Advisory · eSecurity Planet · The Hacker News

Nexus 9000 gear frequently sits at the core of data center and AI fabric networks — an unauthenticated root shell there is about as bad as it gets on that tier of hardware. If patching isn’t immediate, apply infrastructure ACLs that deny inbound traffic to TCP 43210/43211 on your switch management IPs today. “No known exploitation yet” is a description of this morning, not a risk rating — CVEs this severe tend to get a working exploit and a KEV listing within days once someone reverses the patch.

Breach watch: Thomson Reuters discloses C-Track breach — SSNs and sealed court records exposed

Thomson Reuters disclosed that an unauthorized party obtained files from C-Track, a court case management platform used by courts in Alabama, Kentucky, Montana, Nevada, New Hampshire, North Dakota, Ohio, Pennsylvania, South Carolina, Tennessee, Wyoming, the U.S. Virgin Islands, and Ontario, Canada. Access occurred in March 2026; the company says it detected unauthorized activity on June 30 and brought in outside cybersecurity experts and law enforcement before disclosing publicly on September 2 — more than five months after the access and over two months after detection. Exposed records may include names, Social Security numbers, driver’s license numbers, dates of birth, medical information, and health insurance information, and at some courts may extend to confidential, redacted, or sealed case files. Thomson Reuters is offering 12 months of credit monitoring — Experian IdentityWorks for U.S. residents, TransUnion myTrueIdentity for Canadian residents. Help Net Security · The Hacker News · Infosecurity Magazine

Sealed and redacted court records exist behind protective orders for real reasons — domestic violence cases and juvenile records among them — so exposure there is a different category of harm than a typical PII leak. If your organization relies on a third-party platform to hold regulated or court-sealed data on your behalf, this is a reminder that your breach-notification clock and your vendor’s disclosure timeline don’t run at the same speed; know what your contract actually requires them to tell you, and by when.

Threat watch: “Spring Ring” vishing campaign turns Microsoft Teams into an attack surface

Researchers detailed a coordinated voice-phishing operation, dubbed Spring Ring, that ran between January and April 2026 and reached more than 150 employees across at least ten companies in different industries. Attackers used Microsoft Teams accounts external to the target organization to open a chat impersonating internal IT help desk staff, then followed up with a live vishing call to talk the victim into launching a remote monitoring and management (RMM) tool or custom malware. In a more advanced variant, the attackers pivoted from that initial foothold into a full NTLM relay attack against the organization’s domain controller, achieving domain compromise. Telemetry cited alongside the report shows phishing alerts originating from collaboration platforms like Teams rose to 42% of all phishing alerts in the first four months of 2026, up from 30% in the prior four months. Help Net Security · Unit 42 · Dark Reading

If your tenant allows external Teams users to message employees by default, that’s the control worth checking this week — restrict external access or require admin consent for unknown senders. Pair it with plain user guidance: IT will not cold-chat or cold-call you asking you to install remote-access software, full stop. Watch for unexpected RMM installs and anomalous NTLM authentication against domain controllers as detection signals, since both show up well before a breach announcement does.

Final thought

A switch bug caught before exploitation, a breach disclosed five months after the intrusion, and a live campaign that’s probably still working today — three different timelines, one shared lesson: attackers go after whatever gets trusted by default, whether that’s an open management port, a vendor holding your records, or a chat message that looks like it came from your own help desk. If you want a second set of eyes on your detection coverage for any of these, see our how-to guides or book a discovery call.