Hello! This is Shemihaza, your Sentinel. This recap covers 30 August to 5 September 2026.
Looking at the week's articles together, one thing connects them. Every one is about judging on a verifiable fact rather than on the other party's explanation. Whose name is on the bank account. Whether the emergency patch was applied. Which version number your admin screen actually shows. None of these depend on what anyone tells you.
Online safety this week
SNS investment scams: if the account is in a personal name, it is fraud
This article was built on an advisory published by Japan's National Consumer Affairs Center (NCAC) on 1 September 2026. Scammers use ads or direct messages claiming a celebrity will teach you how to make money, then move you into a messaging-app group. In the published cases, losses reach roughly 10 million yen.
There is one decisive test. The NCAC states it plainly: an ordinary stock or FX transaction never asks you to transfer money to a personal bank account, and if the account you are given is in an individual's name, it is fraud — do not transfer the money.
What makes this hard to spot is that the first withdrawal really does work. In one case, a victim bought two stocks at 500,000 yen each, sold them, and successfully withdrew about 300,000 yen. That is what earned their trust. They then sent about 4 million yen and could no longer reach anyone.
A small payout is what the scammer spends to buy your confidence. "I got money back once, so it must be real" is not a valid conclusion.
For engineers: this week's security alerts
Five articles. Two of them cover flaws that CISA confirmed as exploited and added to the KEV catalog.
Seen side by side, they make one point clearly: a high CVSS score and "fix this right now" are not the same thing. One item scores 10.0 with no reported exploitation; another scores 8.8 and is being attacked in the wild.
MapLibre GL JS CVE-2026-85061 (CVSS v3.1: 10.0 CRITICAL)
Affects the mapping library MapLibre GL JS at 6.4.0 and earlier. Sanitisation lets one dangerous attribute through, so script runs the moment the map's attribution control is rendered.
Update the npm package maplibre-gl to 6.4.1 or later. A page that merely displays a map is in scope.
LiteLLM CVE-2026-59822 (CVSS v3.1: 8.2 HIGH) - confirmed exploited
On 2 September 2026 CISA added LiteLLM's MCP authentication bypass and Starlette's Host header validation flaw to the KEV catalog. Update LiteLLM to 1.84.0 and Starlette to 1.0.1.
The Starlette issue scores a moderate 6.5, but it too is on the confirmed-exploited list.
Amelia (WordPress booking plugin) CVE-2026-9055 (CVSS v3.1: 9.8 CRITICAL)
In the Premium edition, versions 8.0 to 9.6.2, an unauthenticated attacker can rewrite the administrator password and take over the site. The fix is 9.6.3; the latest release is 9.8.1.
The catch is that the free and Premium editions use different version numbering. Do not go by "I think we were up to date" - check the version number in the admin screen.
PaperCut NG/MF CVE-2026-81578 (CVSS v4.0: 8.8 HIGH) - confirmed exploited
An attack chaining authentication bypass into remote code execution has been observed in the wild, and CISA added it to the KEV catalog on 31 August 2026.
The key point here is that the version number alone does not tell you whether you are safe. What matters is whether emergency patch Release 3 has been applied. Also make sure the admin interface is not reachable from the internet.
Nodemailer CVE-2026-82854 (CVSS v4.0: 2.3 LOW)
In this Node.js mail library, SMTP commands can be injected through envelope.size. It does not occur under the default configuration, and assessments are split between LOW and CRITICAL.
For a CVE like this, the right move is neither panic nor dismissal: check whether your own configuration meets the preconditions. If it does, update to 8.0.4 or later.
Also this week: AI in production
We covered LY Corporation's AI agent platform, Agent i. The interesting decision was setting the original multi-agent vision aside and building in-house the ability to reliably ship one agent first. The article sticks to what the official engineering blog and press release actually state.
This week's quiz - four questions
If you read this week's articles, you can spot all four. The first two are worth doing with family; the last two with colleagues.
📦This week's articles
- SNS investment scams: if the account is in a personal name, it is fraud↗
- MapLibre GL JS CVE-2026-85061: update to 6.4.1 or later↗
- LiteLLM CVE-2026-59822: update to 1.84.0 now↗
- Amelia (WordPress booking plugin) CVE-2026-9055: update to 9.6.3 or later↗
- LY Corporation's AI agent platform: Agent Builder and Agent Runtime↗
- PaperCut NG/MF CVE-2026-81578: apply emergency patch Release 3 now↗
- Nodemailer CVE-2026-82854: update to 8.0.4 or later↗
Three lines to forward to your family
- ▸An ad or DM where a celebrity offers to teach you how to make money is not that person. Their photo is being used without permission.
- ▸If you are told to transfer investment money to an account in an individual's name, it is fraud. A person's name instead of a company's means do not send it.
- ▸If you are told you must pay tax or fees before you can withdraw, do not pay. In Japan, call the Consumer Hotline 188 or the Police Consultation Line #9110.
If something has gone wrong
If you are thinking "I've made a mistake", start with the emergency guide for your situation. Work through it in order. There is nothing to be ashamed of.
These are Japan-wide helplines for people in Japan:
Consumer Hotline: 188 (no area code; connects you to your local consumer affairs centre)
Police Consultation Line: #9110 (connects you to the advice desk of your nearest police force)
- Emergency response guide by situation (Online Safety Guide)↗
- NCAC: advisory on celebrity-fronted investment offers on social media (published 1 September 2026, Japanese)↗
- FSA: register of licensed and registered financial businesses (Japanese)↗
- FSA: entities warned for conducting financial instruments business without registration (Japanese)↗
- NCAC: directory of consumer affairs centres in Japan (Japanese)↗
