HOT NEWS 2026 SEPTEMBER  January(174) February(168) March(221) April(222) May(261) June(255) July(156) August(518) September(0) October(0) November(0) December(0) | STATISTICS (7049)

DATE

NAME

INFO

CATEGORY

SUBCATE

30.9.26

CVE-2026-86950  Apple Multiple Products Out-of-Bounds Write Vulnerability: Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution. ECV ECV

30.9.26

CVE-2026-88771 Citrix NetScaler Improper Input Validation Vulnerability: Citrix NetScaler ADC and NetScaler Gateway contain an improper input validation vulnerability that could allow an unauthenticated attacker to execute arbitrary commands. ECV ECV

30.9.26

CVE-2026-88772 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability: Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for remote code execution or denial of service ECV ECV

30.9.26

CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability: WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution. ECV ECV

30.9.26

Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.This vulnerability is due to improper handling of URI encoding

VULNEREBILITY

VULNEREBILITY

30.9.26

Zecurit RMM Zecurit RMM Abuse Demands Attention: DocuSign Phishing Delivers a Signed Agent PHISHING PHISHING

30.9.26

Star Blizzard Star Blizzard refines phishing and malware delivery with the RedFlick technique APT APT

30.9.26

JSCEAL JSCEAL is malware that operates using the Node.Js environment. Threat actors entice users to click by advertising that installing the official program of a cryptocurrency exchange will result in rewards such as cryptocurrency. This malware attack is not limited to a specific time frame but has continued to target users in Korea up until recently. MALWARE JS

30.9.26

TOPHIT Part 2 CloudSEK found an attacker's control panel targeting vast.ai, a GPU rental marketplace. It rents containers beside victims to scan their networks. It reached one unprotected notebook and planted no miners. The panel exposed its own source code. MALWARE PYTHON

30.9.26

TOPHIT Part 1 CloudSEK found 85 malicious npm packages, published in three minutes, likely named to surface in search when developers mistype popular libraries. They give attackers remote command access. The same server hosts a GPU-hijacking panel. No victims confirmed. MALWARE PYTHON

30.9.26

MALFEX CloudSEK uncovered MALFEX, a long-running npm supply-chain campaign linked to a single operator, using malicious packages to deploy RATs and credential stealers. Two packages remain installable, including one malicious postinstall that evaded advisories for 14 months. MALWARE PYTHON

30.9.26

Branch Target Reuse: Practical Spectre-v2 Attacks in JIT Engines via Stale Branch Prediction Entries Self-Modifying Code (SMC) is the foundation of dynamic code generation in commodity JIT engines. Modern processors provide coherence mechanisms that ensure stale, overwritten code cannot be executed architecturally, but their guarantees during microarchitectural execution remain less understood.

PAPERS

PAPERS

30.9.26

CVE-2026-64507 x86/bugs: Enable IBPB flush on BPF JIT allocation

VULNEREBILITY

VULNEREBILITY

30.9.26

CVE-2026-64508 bpf: Support for hardening against JIT spraying

VULNEREBILITY

VULNEREBILITY

30.9.26

CVE-2026-63072 Fixed heap buffer overflow in CMS key unwrapping.

VULNEREBILITY

VULNEREBILITY

30.9.26

CVE-2026-63076 Fixed invalid pointer dereference in CMP server via crafted protectionAlg.

VULNEREBILITY

VULNEREBILITY

30.9.26

CVE-2026-63076 Fixed invalid pointer dereference in CMP server via crafted protectionAlg.

VULNEREBILITY

VULNEREBILITY

30.9.26

CVE-2026-54874 Fixed excessive memory use buffering DTLS records for a future epoch.

VULNEREBILITY

VULNEREBILITY

30.9.26

CVE-2026-75803 Fixed possibility of AEAD forgeries with empty ciphertext when using EVP_Cipher().

VULNEREBILITY

VULNEREBILITY

30.9.26

PhantomSub PhantomSub: Malicious npm Campaign Secretly Adds Users to WhatsApp Spam Channels MALWARE PYTHON

29.9.26

Kothamine Agent malware Security researchers at Malwarebytes reported on Kothamine Agent, a previously unknown Remote Access Trojan (RAT) targeting Windows environments. Programmed in C and C++, the malware operates via a dedicated loader that typically injects its dynamic-link library (DLL) payload into legitimate processes such as explorer.exe. ALERTS VIRUS

29.9.26

Lunex MaaS Campaign Targets Ukrainian Users A new campaign documented by Ontinue details the deployment of the Lunex information stealer, a malware-as-a-service platform currently targeting Ukrainian-speaking users. The intrusion begins with a deceptive CAPTCHA page that initiates a covert MSI installation. The ensuing loader leverages a Bring Your Own Vulnerable Driver (BYOVD) maneuver—abusing a vulnerable AMD driver (CVE-2023-20598)— an attempt to terminate endpoint security telemetry at the kernel level. ALERTS CAMPAIGN

29.9.26

RemControl – Android Banking Malware Group-IB has published a report on a previously undocumented Android banking trojan dubbed RemControl, which operates as a Malware-as-a-Service platform. The threat targets retail banking customers across Europe, the Middle East, and Canada by masquerading as a popular IPTV application. Distributed via malvertising that leads to fake app stores, the malware uses a local VPN service to block Google Play Protect and generates unique certificates for each installation to evade detection. ALERTS VIRUS

29.9.26

TokenGrabber infostealer A recent K7 Security Labs publication explores how the Malware-as-a-Service (MaaS) threat actors create and distribute customized info-stealers comprising of Python-driven tools alongside integrated data-theft modules. The malware builder utility leveraged by the attackers allows them to construct bespoke Windows executables compiled via Nuitka or PyInstaller, directly configuring delivery webhooks during creation. ALERTS VIRUS

29.9.26

DarkMe RAT Delivered via PIF Researchers at Huntress recently reported a campaign involving the DarkMe remote access trojan, which has notably shifted its initial delivery tactics. Previously attributed to the financially motivated Water Hydra group, this malware historically targeted forex traders, cryptocurrency users, and gambling platforms using sophisticated zero-day exploits. ALERTS VIRUS

29.9.26

Psychedelic Stealer malware Cybersecurity researchers at Arctic Wolf Labs uncovered an ongoing threat campaign abusing compromised Ukrainian commercial websites to distribute a novel malware variant dubbed Psychedelic Stealer. Attackers embed malicious iframes into trusted web pages, presenting visitors with deceptive Cloudflare verification prompts. This social engineering tactic coerces users into copying commands and launching them via the Windows Run dialog, fetching a malicious MSI installers. ALERTS VIRUS

29.9.26

Sauron - a new malware Loader on the threatscape Security researchers at DCSO recently identified a previously undocumented malware loader dubbed Sauron which has been used to compromise numerous organizations across Germany. Distributed via a Malware-as-a-Service commercial model, the loader serves as the final stage of intrusion chains initiated through social engineering and ClickFix campaigns. ALERTS VIRUS

29.9.26

ClosedQuorum - an autonomous AI Windows implant Cisco Talos reported on a novel Windows implant dubbed ClosedQuorum that leverages autonomous decision loop determining its post-compromise actions. By bypassing conventional attacker-controlled infrastructure or live operator prompts, the implant queries a panel of prominent commercial large language models (LLMs): DeepSeek, Qwen, Mistral, and Google Gemini. ALERTS VIRUS

29.9.26

Authlib library contains a signature‑verification bypass vulnerability Authlib (versions up to and including 1.7.2) contain a signature‑verification bypass in the JSON Web Signature (JWS) general JSON serialization handling. The JsonWebSignature.deserialize_json() function accepts a JWS object with an empty "signatures" array and treats the payload as successfully verified, allowing attackers to supply arbitrary forged content without possessing any key material. ALERT ALERT

29.9.26

IoDrv.sys IoDrv.sys is a hardware I/O driver with an embedded TOPSTAR OVERSEAS ELECTRONICS Co.,Ltd signature. Beazley Security identified this exact sample, renamed Redacted.sys, in an INC ransomware affiliate intrusion. VULNEREBILITY DRIVE

29.9.26

CVE-2026-88778 Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23. KEV KEV

29.9.26

CVE-2026-88777 Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior or Denial of Service KEV KEV

29.9.26

CVE-2026-88776 Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior or Denial of Service KEV KEV

29.9.26

CVE-2026-88775 Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to unpredictable or erroneous behavior or Denial of Service KEV KEV

29.9.26

CVE-2026-88774 Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression usage. KEV KEV

29.9.26

CVE-2026-88773 Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before 13.1-64.23. KEV KEV

29.9.26

CVE-2026-88772 Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability KEV KEV

29.9.26

CVE-2026-88771 Citrix NetScaler Improper Input Validation Vulnerability KEV KEV

29.9.26

CVE-2026-86950

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 26.7.1 and iPadOS 26.7.1, macOS Sequoia 15.8.1, macOS Tahoe 26.7.1. Processing a maliciously crafted file may lead to arbitrary code execution. Apple is aware of a report that this issue may have been exploited in an extremely sophisticated attack against specific targeted individuals on versions of iOS before iOS 27.

VULNEREBILITY

VULNEREBILITY

29.9.26

NeedyMantis NeedyMantis: Unpacking a post-compromise malware family used in targeted operations MALWARE MALWARE

29.9.26

Bitget Security Incident Bitget Security Incident Explained: Timeline, Impact and Security Response INCIDENT INCIDENT

28.9.26

Guide to Operational Technology (OT) Security

This document provides guidelines for establishing secure operational technology (OT) 1 while addressing OT’s unique performance, reliability, and safety requirements. OT encompasses a broad range of programmable systems and devices that interact with the physical environment or manage devices that do so.

Security guidance Security guidance

28.9.26

JADEPUFFER Storm-3168: Agentic-driven cloud attacks using compromised service principals GROUPS GROUPS

28.9.26

Cyber Security (CYBER); Implementation Guidelines for Quantum Random Number Generators IPRs essential or potentially essential to normative deliverables may have been declared to ETSI. The declarations pertaining to these essential IPRs, if any, are publicly available for ETSI members and non-members, and can be found in ETSI SR 000 314: "Intellectual Property Rights (IPRs); Essential, or potentially Essential, IPRs notified to ETSI in respect of ETSI standards", which is available from the ETSI Secretariat. Latest updates are available on the ETSI IPR online database. Security guidance Security guidance

28.9.26

CVE-2026-88772 Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service

VULNEREBILITY

VULNEREBILITY

28.9.26

CVE-2026-88771 Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute arbitrary commands.

VULNEREBILITY

VULNEREBILITY

27.9.26

CVE-2026-42608 [ZERO-DAY] Unauthenticated Path Traversal & Arbitrary File Write in FormFlash component.

VULNEREBILITY

VULNEREBILITY

27.9.26

CVE-2026-63077 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol

VULNEREBILITY

VULNEREBILITY

27.9.26

CVE-2025-6543 Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server

VULNEREBILITY

VULNEREBILITY

27.9.26

Lunex Lunex Unmasked: A New Information Stealer Deployed Through BYOVD MALWARE STEALER

27.9.26

x47.c x47.c botnet comes with 18 attack methods, including AI API draining BOTNET BOTNET

26.9.26

CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability KEV KEV

26.9.26

CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability KEV KEV

26.9.26

CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability KEV KEV

26.9.26

CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability KEV KEV

26.9.26

CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability KEV KEV

26.9.26

CVE-2021-27101 SQL injection via a crafted Host header

VULNEREBILITY

VULNEREBILITY

26.9.26

CVE-2021-27102 OS command execution via a local web service call

VULNEREBILITY

VULNEREBILITY

26.9.26

CVE-2021-27103 SSRF via a crafted POST request

VULNEREBILITY

VULNEREBILITY

26.9.26

CVE-2021-27104 OS command execution via a crafted POST request

VULNEREBILITY

VULNEREBILITY

26.9.26

CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability: Microsoft SharePoint contains a code injection vulnerability which could allow an authorized attacker to execute code over a network. ECV ECV

26.9.26

CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability: Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. ECV ECV

26.9.26

CVE-2026-71362 Adobe Commerce and Magento Incorrect Authorization Vulnerability : Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction. ECV ECV

26.9.26

CVE-2026-5430 WSO2 Multiple Products Path Traversal Vulnerability : WSO2 API Control Plane, API Manager, Traffic Manager & Universal Gateway contain a path traversal vulnerability that could allow for unrestricted file upload and lead to remote code execution. ECV ECV

26.9.26

Readwise Reader for Android, version 8.7.2, contains multiple XSS vulnerabilities Three cross-site scripting (XSS) vulnerabilities identified in Readwise Reader for Android version 8.7.2 are disclosed. An attacker with the ability to craft malicious documents or metadata can exploit these vulnerabilities by supplying poisoned content that bypasses sanitization. Successful exploitation could allow the attacker to execute arbitrary JavaScript within the application's WebView context and compromise the confidentiality and integrity of user data, including access to stored documents, credentials, and session tokens. ALERT ALERT

26.9.26

ViewSonic vCast media streaming service allows unauthenticated screen exfiltration and device compromise ViewSonic vCast software, which is included in ViewBoard smartboard devices, contains multiple vulnerabilities that an attacker can chained to achieve full device compromise. ALERT ALERT

26.9.26

Norwegian Cruise Line door access controller contains an improper authentication vulnerability Door access controllers used on Norwegian Cruise Line (NCL) ships contain an improper authentication vulnerability that permits a replayed unique identifer (UID) from a radio-frequency identification (RFID) device to grant unauthorized entry to areas secured by these controllers. ALERT ALERT

26.9.26

ZionSiphon Inside ZionSiphon: Darktrace’s Analysis of OT Malware Targeting Israeli Water Systems MALWARE OT

26.9.26

CARBONATO ​ThreatDown​ ​researchers​ ​uncovered​ ​CARBONATO,​ ​a​ ​Docker​ ​botnet​ ​built​ ​around​ ​an​ ​AI​ ​agent​ ​that​ ​compromises​ ​exposed​ ​Docker​ ​daemons,​ ​spreads​ ​across​ ​reachable​ ​hosts,​ ​and​ ​gives​ ​operators​ ​a​ ​Telegram-controlled​ ​tool​​ for​ ​post-compromise activity.​ BOTNET BOTNET

26.9.26

Rokarolla The Rokarolla Android banking trojan combines fake login screens, message collection, and remote device interaction. With the required permissions, it can steal credentials and manipulate legitimate app interfaces. MALWARE ANDROID

26.9.26

ORAX ORAX is a phishing-as-a-service (PhaaS) platform that uses WebSockets and live session control to capture MFA-authenticated Google Workspace sessions. PHISHING PHAAS

26.9.26

SLEEPWALKER Losing access to VirusTotal Intelligence at the start of the year was surprisingly productive. Unable to hunt for interesting new malware, I stopped adding to my “TODO” pile and finally worked through my backlog from last year. That led to a detailed examination of BeheMOF as well as the discovery of this malware. MALWARE BACKDOOR

26.9.26

GHAPPIER CloudSEK researchers uncovered GHAPPIER, a previously unreported loader operation spanning at least 65 public repositories, 73 infected files and 22 accounts. The investigation began with a compromised legitimate npm package whose malicious release carried valid provenance through trusted publishing. MALWARE LOADER

26.9.26

SleepyDuck In November 2025, we analyzed a small backdoor loose on Open VSX. SleepyDuck was unremarkable in every way but one: its header was an ASCII-art duck, and its C2 was a Solana smart contract the loader polled for tasking. It was a JavaScript file, a few kilobytes, executing fetched code in memory — a toy with a mascot. MALWARE BACKDOOR

26.9.26

AvisLoader Varonis Threat Labs discovered AvisLoader, a new Windows malware loader built to keep its command-and-control (C2) channel beyond the reach of traditional domain takedowns. MALWARE LOADER

25.9.26

Vshell Vshell: A Chinese-Language Alternative to Cobalt Strike HACKING HACKING

25.9.26

PamStealer PamStealer adapts again: a move to Swift with a server-side decryption chain MALWARE INFOSTEALER

25.9.26

CVE-2025-49113 (CVSS score: 9.9) - A deserialization of untrusted data vulnerability that allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php. (Fixed in June 2025)

VULNEREBILITY

VULNEREBILITY

25.9.26

CVE-2025-68461 (CVSS score: 7.2) - A cross-site scripting vulnerability via the animate tag in an SVG document. (Fixed in December 2025)

VULNEREBILITY

VULNEREBILITY

25.9.26

CVE-2026-48842 CVE-2026-48842 is a pre-authentication SQL injection flaw in Roundcube Webmail's virtuser_query plugin that exploits a preg_replace() backslash escape bypass. This article covers technical details, affected versions, and mitigation.

VULNEREBILITY

VULNEREBILITY

25.9.26

CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway that could allow unrestricted file upload and lead to remote code execution.

VULNEREBILITY

VULNEREBILITY

25.9.26

CVE-2026-71362 (CVSS score: 9.1) - An incorrect authorization vulnerability in Adobe Commerce and Magento that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.

VULNEREBILITY

VULNEREBILITY

25.9.26

CVE-2025-10184 CVE-2025-10184: OnePlus OxygenOS Telephony provider permission bypass (FIXED as of October 11, 2025)

VULNEREBILITY

VULNEREBILITY

25.9.26

Cisco Identity Services Engine Authentication Bypass Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on an affected device.

VULNEREBILITY

VULNEREBILITY

25.9.26

Psychedelic Stealer The Psychedelic Stealer: When a CAPTCHA Becomes an Installer MALWARE STEALER

25.9.26

ClickFix & Beyond Mapping the expanding family of user-assisted malware delivery techniques REPORT REPORT

24.9.26

AToolsKrnl64.sys Antiy ATool AToolsKrnl64.sys from the reported 2.0.26.819 package exposes process termination through IOCTL 0x99000050. Its caller check validates an Antiy-signed executable on disk and caches the accepted process, but does not verify the integrity of the running client. A modified genuine client can therefore pass this check and request termination of caller-selected processes. VULNEREBILITY DRIVE

24.9.26

BS_LED64.sys BS_LED64.sys is the BIOSTAR I/O driver distributed with VIVID LED DJ. CVE-2026-94128 identifies vulnerable IOCTL handling in VIVID LED DJ 4.0.2411.1500. The included driver version 10.0.2410.1000 exposes physical-memory read and write operations through IOCTLs 0x226040 and 0x226044. These operations map a caller-supplied 32-bit physical starting address with MmMapIoSpace without an address allowlist. VULNEREBILITY DRIVE

24.9.26

ClickFix Campaign Delivers ChainScript RAT Disguised as Spotify, Zoom and Teams Installers In a recent write-up, Blackpoint’s Adversary Pursuit Group (APG) details a previously undocumented Node.js remote access trojan tracked as ChainScript. Distributed through ClickFix social engineering lures disguised as legitimate corporate software like Spotify, Zoom, and Microsoft Teams, the malware deploys via custom Windows Installers that execute without requiring administrative rights. ALERTS CAMPAIGN

24.9.26

Macfinger ClickFix operation Latest SANS Internet Storm Center report examines an a recent operation dubbed the Macfinger ClickFix. This campaign compromises legitimate websites by injecting malicious scripts engineered specifically to profile visitors and exploit macOS systems. ALERTS OPERATION

24.9.26

Rapuncel Infostealer LastPass’s threat intelligence reported on a recent malware operation that mimicked more than forty brands on GitHub, including LastPass Authenticator. Dubbed Rapuncel, the infostealer was distributed through attacker-controlled infrastructure and the threat actors were leveraging a Microsoft-certified kernel driver in the attack chain. ALERTS VIRUS

24.9.26

VelvetCake malware delivered via Operation Conflict Compass SOCRadar Threat Research Unit reported on a cyberespionage initiative called Operation Conflict Compass, conducted by the North Korean threat group Vedalia (aka Konni). The campaign aimed to gather strategic intelligence regarding the progression of the Russia-Ukraine conflict, predominantly focusing on diplomatic institutions, non-governmental organizations, and think tanks. ALERTS VIRUS

24.9.26

New updates in the latest iteration of the Vidar Infostealer malware Vidar is an active information-stealing malware strain that systematically updates its evasion tactics to challenge security analysts and detection mechanisms. Latest research conducted by Zscaler ThreatLabz tracking iterations from version 2.0 through 3.4 illustrates that the threat actors continuously refine internal obfuscation while preserving core operational capabilities. In the most recent malware releases, sensitive strings are shielded through a proprietary virtual machine governed by an agile bytecode interpreter, deployed alongside an adaptable, ALERTS VIRUS

24.9.26

SideCopys' attack chain leads to RAT deployment Trellix analysts have documented the strategic shifts and operational scope of the threat group SideCopy, focusing on how their recent intrusions rely heavily on mshta.exe misuse to deploy remote access trojans (RATs). The attack sequence begins with phishing emails delivering suspicious ZIP archives. Unsuspecting targets extract and launch a malicious LNK shortcut file that fetches an HTML Application (HTA) hosted on remote adversary infrastructure. ALERTS VIRUS

24.9.26

HeavyGram and CrudeExclude malware distribution Group-IB cybersecurity researchers have identified novel variants of the HeavyGram and CrudeExclude malware strains. Expanding upon prior threat alerts and infrastructure seizures conducted by United States authorities, these operations are linked to an Iranian intelligence-affiliated adversary known as Handala Hack. Attackers typically lure targeted victims through messaging applications, delivering deceptive initial droppers that masquerade as legitimate software. ALERTS VIRUS

24.9.26

RatHat Android Malware In a recent write-up, Zimperium details RatHat, an Android malware family designed to harvest financial credentials, screen inputs, and two-factor authentication codes from compromised mobile devices. The malware is delivered mainly through smishing messages and malvertising that direct victims to fraudulent download portals hosting malicious APKs disguised as legitimate apps. ALERTS VIRUS

24.9.26

CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability: Check Point Security Gateway and Check Point Spark Firewall using Site to Site VPN or Remote Access VPN contain an improper certificate validation vulnerability which could allow an unauthenticated remote attacker to execute arbitrary code on the Gateway. ECV ECV

24.9.26

CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability: Check Point Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent contain a path traversal vulnerability that allows an unauthenticated attacker to upload and execute arbitrary scripts. ECV ECV

24.9.26

CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability: F5 BIG-IP APM contains a heap-based buffer overflow vulnerability when access policy and an OAuth profile are configured on a virtual server. This vulnerability could allow an unauthenticated attacker to perform remote code execution. ECV ECV

24.9.26

CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability: Arista VeloCloud Orchestrator (VCO) on-prem contains an improper input validation vulnerability that may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator. ECV ECV

24.9.26

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability: Zyxel GS1900 series switches contain a stack-based buffer overflow vulnerability in the CGI program which could allow a LAN-based, unauthenticated attacker to exploit the flaw and potentially execute OS commands via a crafted HTTP request. ECV ECV

24.9.26

CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability: Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. ECV ECV

24.9.26

CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability: Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. ECV ECV

24.9.26

CVE-2025-39964 Linux Kernel Race Condition Vulnerability: Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. ECV ECV

24.9.26

Enterprise Access Management EAM does not rotate RSA keys Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.2.6 and below. The product provides no supported mechanism to rotate its RSA key pair after deployment, meaning the same key pair is used indefinitely to generate the appliance's X.509 certificate. ALERT ALERT

24.9.26

Cinnamon's Kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers Cinnamon's Kotaemon (all versions up to v0.12.0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can read, delete, rename, or overwrite another user’s conversation data by supplying the correct ID. This results in high‑impact confidentiality, integrity, and availability violations. ALERT ALERT

24.9.26

sckit sckit, also known as the “supplychain.local worm”, is a Go implant framework that we found in two MemTensor packages on September 23, 2026. It runs on Linux, macOS, and Windows. MALWARE GO

24.9.26

RemControl Group-IB researchers have discovered a previously undocumented Android banking trojan, internally named RemControl by its operator, targeting retail banking customers across Western Europe, the Middle East, and Canada. MALWARE ANDROID AI

24.9.26

UNK_CondorFiltration Spraying in the Andes: TeamFiltration Returns to Exploit Forgotten Service Accounts GROUPS CLUSTER

24.9.26

CVE-2026-67276 RouterOS does not compare the complete RSA public key when matching an SSH authentication request to an authorized user key, checking the key type and modulus but omitting the exponent. Because signature verification uses the client-supplied key, an attacker knowing an authorized RSA modulus can supply a key with exponent one, forge a valid signature, and open an SSH command channel as the target user without the private key.

VULNEREBILITY

VULNEREBILITY

24.9.26

CVE-2026-67277 RouterOS accepts a "related" btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With "random-data=false", the sender transmits an uninitialized tail from a kernel packet buffer.

VULNEREBILITY

VULNEREBILITY

24.9.26

CVE-2026-67279 RouterOS SSH enters the connection protocol after a client-requested rekey even though user authentication was never attempted, allowing an unauthenticated client to open a session channel and send an exec request.

VULNEREBILITY

VULNEREBILITY

24.9.26

CVE-2026-67281 RouterOS WebFig contains an unauthenticated file-read vulnerability in the /jsproxy path where a newly allocated session retains a stale uninitialized principal pointer used for file authorization.

VULNEREBILITY

VULNEREBILITY

24.9.26

CVE-2026-86060 RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to reach the RouterOS login helper.

VULNEREBILITY

VULNEREBILITY

24.9.26

CVE-2026-67278 MikroTik RouterOS accepts malformed RSA/PKCS#1 v1.5 signatures across RSA-based services, including TLS/X.509 certificate validation and SSH host-key authentication.

VULNEREBILITY

VULNEREBILITY

23.9.26

Vendor-signed UEFI Shell applications allow Secure Boot bypass Vendor-signed UEFI Shell applications may allow an attacker to bypass Secure Boot protections by abusing commands such as mm (Memory Modify). ALERT ALERT

23.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that this vulnerability affects all Cisco

VULNEREBILITY

VULNEREBILITY

23.9.26

CVE-2026-80521 af_unix: Unlink scc_entry in unix_del_edge().

VULNEREBILITY

VULNEREBILITY

23.9.26

CVE-2026-94545 This candidate has been reserved by an organization or individual " "that will use it when announcing a new security problem. When the candidate has been " "publicized, the details for this candidate will be provided.

VULNEREBILITY

VULNEREBILITY

23.9.26

Berlin Data Leak In August 2026, the Rhysida extortion group breached Berlin’s state network and copied roughly 1.44 million files from two of the city-state’s Senate administrations. Berlin disconnected the affected departments on August 14, refused a ransom demand of 30 BTC, and on September 4 the group released the archive to public access on its Dark Web leak site. INCIDENT INCIDENT

23.9.26

Oracle Critical Security Patch Update Advisory - September 2026 A Critical Security Patch Update (CSPU) provides targeted, high-priority security fixes in a smaller, more focused format, making them easier to apply with minimal disruption. Critical Security Patch Updates complement Oracle’s existing quarterly cumulative Critical Patch Updates (CPUs). VULNEREBILITY SOFTWARE PATCH REPORTS

23.9.26

DarkMe RAT Huntress spotted the DarkMe malware in two separate incidents affecting different organizations on August 31, 2026. MALWARE RAT

23.9.26

Operation Conflict Compass Since 2009, the Democratic People’s Republic of Korea (DPRK) has fully integrated cyber operations into its national strategy, leveraging state-nexus threat groups to execute cyberespionage, conduct sabotage and influence operations, and generate revenue for state-sponsored nuclear weapons programs. OPERATION OPERATION

23.9.26

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability KEV KEV

23.9.26

CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability KEV KEV

23.9.26

CVE-2026-93616 Check Point Multiple Products Path Traversal Vulnerability KEV KEV

23.9.26

CVE-2026-93952 Arista VeloCloud Orchestrator Improper Input Validation Vulnerability KEV KEV

23.9.26

CVE-2026-94127 F5 BIG-IP APM Heap-based Buffer Overflow Vulnerability KEV KEV

23.9.26

CVE-2026-86296 A vulnerability was determined in D-Link DIR-822A A_101. This vulnerability affects the function strcpy of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.

VULNEREBILITY

VULNEREBILITY

23.9.26

ClosedQuorum CLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). While we do not have confirmation of in-the-wild deployment, artifacts from the binary were used to connect the developer to postings on criminal forums related to carding, dating back to 2025. MALWARE AI

23.9.26

CVE-2026-87902 Unauthenticated path traversal in page-template resolution leading to conditional RCE

VULNEREBILITY

VULNEREBILITY

23.9.26

CVE-2026-91843

A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.

VULNEREBILITY

VULNEREBILITY

23.9.26

CVE-2026-93616

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

VULNEREBILITY

VULNEREBILITY

23.9.26

Bifrost AI Gateway

Bifrost is a high-performance AI gateway that unifies access to 23+ providers (OpenAI, Anthropic, AWS Bedrock, Google Vertex, and more) through a single OpenAI-compatible API. Deploy in seconds with zero configuration and get automatic failover, load balancing, semantic caching, and enterprise-grade features.

VULNEREBILITY

VULNEREBILITY

23.9.26

CVE-2026-90898

Bifrost registers MCP clients through its management API. A stdio client is a command plus args. Bifrost starts that program in the gateway the moment the client is added. No MCP handshake required. The default is governance.auth_config.is_enabled=false.

VULNEREBILITY

VULNEREBILITY

22.9.26

CVE-2026-32996

This vulnerability in Veeam Agent for Microsoft Windows allows for Local Privilege Escalation.

VULNEREBILITY

VULNEREBILITY

22.9.26

CVE-2026-93952

Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an authorized attacker to elevate privileges locally.

VULNEREBILITY

VULNEREBILITY

22.9.26

CVE-2026-89775

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Handle negative S1 walk levels in VNCR TLB size evaluation Computing the effects of a TLB invalidation involves looking at the size of the mapping cached by the TLB.

VULNEREBILITY

VULNEREBILITY

22.9.26

CVE-2026-65660 Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. VULNEREBILITY VULNEREBILITY

22.9.26

AmdTools64.sys AMD Special Tools Driver AmdTools64.sys 1.7.16.219 exposes physical-memory mapping through IOCTL 0xFFF028A4. Static analysis confirms that the handler passes a caller-supplied physical address and length to MmMapIoSpace, constructs an MDL, and maps the range into the caller's user-mode address space with MmMapLockedPagesSpecifyCache, without a physical-range authorization check. VULNEREBILITY DRIVE

22.9.26

BigDiskBuster Windows Defender Update Denial of Service Vulnerability EXPLOIT EXPLOIT

22.9.26

Clop Hack ShinyHunters has turned the tables on rival cybercrime operation Clop (a.k.a. Cl0p), hijacking and defacing the ransomware gang’s own Dark Web leak site (DLS) OPERATION OPERATION

22.9.26

5G-Shark: A Network Security Auditor
for 5G Subscriber Privacy and
Unauthenticated Signalling Resilience
The fifth generation of mobile networks (5G) was standardised with an explicit mandate to close longstanding privacy and security gaps, mandating the concealment of the subscriber’s permanent identity, resistance to generational downgrade, and protection against location tracking.

PAPERS

PAPERS

22.9.26

CVE-2026-93485 Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Automattic WordPress core allows DOM-Based XSS VULNEREBILITY VULNEREBILITY

22.9.26

CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability KEV KEV

22.9.26

TASK#STOMP TASK#STOMP: PowerShell Backdoor for Document Theft and Remote Access MALWARE BACKDOOR

21.9.26

ClaudeBleed

ClaudeBleed Reopened: Browser Extensions Can Still Push Claude for Chrome to Read Your Gmail

HACKING

AI

21.9.26

Seven days of scans and probes and web traffic hitting my web server

Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website.

MALWARE TRAFFIC

MALWARE TRAFFIC

21.9.26

SmartApeSG ClickFix to Unidentified RAT to MeshAgent

Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website.

MALWARE TRAFFIC

MALWARE TRAFFIC

21.9.26

Codex ClickFix Campaign

When Trust Becomes the Payload in a Fake Codex ClickFix Campaign

CAMPAIGN

CAMPAIGN

21.9.26

ChainScript

ChainScript: Tracing a Node.js RAT Through the Blockchain

MALWARE

RAT

21.9.26

LLMShare

LLMShare: how attackers are turning AI chatbot pages into malware delivery platforms

HACKING

AI

21.9.26

On Identifying Adversarial Intent Injection in
AI-Native 6G Networks

AI-native 6G networks have brought IntentBased Networking (IBN) to the forefront, enabling high-level goals to be translated into network configurations. However, this abstraction opens new attack surfaces, primarily adversarial intent injection, where malicious policies are disguised within benign intent flows.

PAPERS

PAPERS

21.9.26

KelpDAO Incident  PDF

Tl;dr On April 18, 2026, KelpDAO was exploited for approximately $290M. Preliminary indicators suggest attribution to a highly-sophisticated state actor, likely DPRK’s Lazarus Group, more specifically TraderTraitor. This incident was isolated to KelpDAO’s rsETH configuration as a direct consequence of their single-DVN setup. There is zero contagion to any other cross-chain assets or applications.

INCIDENT

INCIDENT

20.9.26

CVE-2026-28326 SolarWinds Access Rights Manager was reported to be affected by an unauthenticated remote code execution vulnerability. The issue stems from a hardcoded static key. VULNEREBILITY VULNEREBILITY

19.9.26

TanStack Supply Chain Attack Analysis Every hack happens in a context where humans, business, technology, or society as a whole is evolving. What stings for CrowdSec is that many of us come from red-team pentesting backgrounds, have worked in cyber for decades, and have adopted a “cybersec” muscle memory in our daily work. So being caught leaking code is painful. INCIDENT INCIDENT

19.9.26

CVE-2026-58138 Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. VULNEREBILITY VULNEREBILITY

19.9.26

CVE-2026-45321 On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. VULNEREBILITY VULNEREBILITY

19.9.26

CVE-2025-39682 (CVSS score: 9.8) - An improper check for unusual or exceptional conditions vulnerability in the TLS receive path that could allow local authenticated users to trigger memory disclosure or denial-of-service (DoS). VULNEREBILITY VULNEREBILITY

19.9.26

CVE-2026-53266 (CVSS score: 8.8) - An out-of-bounds write vulnerability in the ebtables Source Network Address Translation (SNAT) Address Resolution Protocol (ARP) rewrite path that could allow a local attacker to trigger unintended system behavior, DoS, or local privilege escalation. VULNEREBILITY VULNEREBILITY

19.9.26

CVE-2025-39964 (CVSS score: 7.8) - A race condition vulnerability that could allow concurrent writes to the same AF_ALG socket, allowing a local attacker to crash the system or corrupt cryptographic operation results, causing DoS or data integrity issues. VULNEREBILITY VULNEREBILITY

19.9.26

LabubaRAT LabubaRAT is a custom, unsigned 64-bit Rust-based remote access trojan (RAT) identified by the Blackpoint Adversary Pursuit Group (APG), designed to masquerade as legitimate NVIDIA software while providing a full remote access feature set including command execution, file operations, screen capture, and SOCKS5 proxying. MALWARE RAT

19.9.26

Lemmings Data posted to a darknet forum by an account named okenit_hackers in October 2025 reveals that Russian actors have potentially upgraded their disinformation methods through the automated creation and management of fake personae. GROUPS GROUPS

19.9.26

ORAX ORAX is a phishing-as-a-service (PhaaS) platform that uses WebSockets and live session control to capture MFA-authenticated Google Workspace sessions. PHISHING PHAAS

19.9.26

SETTRA RANSOMWARE NOTE: This is a Continuous Analysis Report of Settra Ransomware Group. The frequent updates of the group shall be found in this same article chronologically. RANSOM RANSOM

19.9.26

Operation RapidRust In August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the group’s activity in January 2026, APT36 has maintained a high operational tempo and updated their tactics, techniques, and procedures (TTPs) in continued attacks targeting government and defense organizations in India and Afghanistan. OPERATION OPERATION

19.9.26

SpiceRAT Disclosure note: ahead of publishing this research on September 9, 2026, we notified the affected organizations and the relevant national CERTs, sharing a TLP:AMBER advance copy and holding publication to allow review. MALWARE RAT

19.9.26

CoSnitch See how meta-hacking got Microsoft Copilot to snitch on itself, exposing CoSnitch, a one-click flaw that silently exfiltrates data. VULNEREBILITY VULNEREBILITY

19.9.26

PhantomRaven CrowdStrike Counter Adversary Operations identified a financially motivated threat actor who works as a bug bounty hunter and who developed and distributed the JavaScript (JS)-based information stealer PhantomRaven via npm, a platform on which developers can access open-source packages to build applications and software. MALWARE JS

19.9.26

TeleClip SonicWall Capture Labs threat researchers have been tracking a Telegram bot malware capable of silently stealing cryptocurrency. The malware is a cryptocurrency clipboard hijacker and keylogger written in C (GCC/MinGW, native 64-bit PE). MALWARE BOT

19.9.26

Atomic macOS This article reviews an Atomic macOS (AMOS) stealer malware infection generated in a lab environment. While several sources have published articles analyzing AMOS stealer, the associated indicators constantly change. MALWARE MACOS

19.9.26

DirtyAH6 CVE-2026-80844 IPsec’s Authentication Header (AH) checks that packet data has not changed. Linux implements its IPv6 side in AH6, using the kernel’s XFRM code; before calculating or checking authentication data, AH6 changes some IPv6 fields into the expected form, including addresses in a routing header.

VULNEREBILITY

VULNEREBILITY

19.9.26

TUNderflow CVE-2026-81000 TUN and TAP are virtual network devices that move packets between the kernel and userspace through /dev/net/tun. Network devices built on top of other devices can pass down the receive headroom they need through ndo_set_rx_headroom(), and Open vSwitch can carry that value from another port to a TUN or TAP port.

VULNEREBILITY

VULNEREBILITY

19.9.26

PPPoEject CVE-2026-68121 PPPoE carries PPP sessions in Ethernet frames. On send, pppoe_sendmsg() builds an skb, copies in the payload, and asks the lower network device to create its hardware header before filling in the PPPoE header.

VULNEREBILITY

VULNEREBILITY

19.9.26

DiagSpill CVE-2026-74469 An SCTP association can have many peer transports, one for each peer address. sctp_diag reports SCTP socket and peer information through sock_diag, building a Netlink reply with one sockaddr_storage for each transport.

VULNEREBILITY

VULNEREBILITY

19.9.26

Sudeep Singh Tracking nation-state adversaries — hunting their malware, infrastructure and tradecraft across China-, Russia-, Iran-, Pakistan- and North Korea-nexus operations. GROUPS GROUPS

19.9.26

Click2Shell One month after XSS2Shell, we returned to WordPress Core looking for another pre-authentication RCE chain. This time there was no preauth XSS in Core. Instead we found a specially crafted preview link made WordPress install an attacker-selected catalog theme and load its PHP before activation.

VULNEREBILITY

VULNEREBILITY

19.9.26

North Korean "WaterPlum," commonly referred to as "Contagious Interview," Cyber Actor Group Targeting IT Professionals; Activities of North Korean IT Workers in Japan, the United States and Europe The North Korean "WaterPlum" cyber actor group (commonly referred to as “Contagious Interview”) conducts cyberattacks by infiltrating unsuspecting job seekers’ computer networks, harvesting sensitive information, and stealing cryptocurrency. WaterPlum is victimizing individual IT professionals in Japan, the United States, Europe, and other countries. IC3 IC3 INDUSTRY

19.9.26

Scammers Impersonating Law Enforcement and Government Officials in Fraud Schemes The FBI reiterates its warning to the public regarding ongoing widespread fraud schemes in which scammers impersonate US and foreign law enforcement or government officials to extort money or personally identifiable information (PII) from victims. This PSA is an update to Alert Number I-030722-PSA, published on 7 March 2022, titled, "FBI Warns of the Impersonation of Law Enforcement and Government Officials." IC3 IC3 PRESS

19.9.26

Iranian Cyber Targeting of Dissidents, Activists and Journalists CHOSEN BRICK is a malware family that has been used to target individuals around the world including in the UK, US and the Netherlands from at least 2025. CHOSEN BRICK enables Iranian state cyber actors to collect information on a target’s contacts, emails and social media messages, which could enable tracking of their movements. IC3 IC3 INDUSTRY

18.9.26

Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software engineering team has conducted

VULNEREBILITY

VULNEREBILITY

18.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected

VULNEREBILITY

VULNEREBILITY

18.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to

VULNEREBILITY

VULNEREBILITY

18.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an

VULNEREBILITY

VULNEREBILITY

18.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service

VULNEREBILITY

VULNEREBILITY

18.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilities Multiple vulnerabilities in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured

VULNEREBILITY

VULNEREBILITY

18.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the TCP DNS response handler to unexpectedly restart

VULNEREBILITY

VULNEREBILITY

18.9.26

Cisco IOS XR Software Security Hardening Release: September 2026 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities

VULNEREBILITY

VULNEREBILITY

18.9.26

Cisco Secure Email Gateway SQL Injection Vulnerability A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.This vulnerability is due to insufficient

VULNEREBILITY

VULNEREBILITY

18.9.26

CVE-2025-39964 Linux Kernel Race Condition Vulnerability KEV KEV

18.9.26

CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability KEV KEV

18.9.26

Dokploy is vulnerable to OS command injection Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and restoration processes. ALERT ALERT

18.9.26

CVE-2026-85889 Azure AI Foundry Elevation of Privilege Vulnerability

VULNEREBILITY

VULNEREBILITY

18.9.26

CVE-2026-85885 (CVSS score: 9.9) - A command injection vulnerability in Microsoft 365 Copilot that could allow an authorized attacker to elevate privileges over a network

VULNEREBILITY

VULNEREBILITY

18.9.26

CVE-2026-85878 (CVSS score: 9.9) - An improper authorization in Azure Database for PostgreSQL that could allow an authorized attacker to elevate privileges over a network

VULNEREBILITY

VULNEREBILITY

18.9.26

CVE-2026-87701 (CVSS score: 9.6) - An improper neutralization vulnerability in Azure Cosmos DB that could allow an authorized attacker to elevate privileges over a network

VULNEREBILITY

VULNEREBILITY

18.9.26

CVE-2026-62721 (CVSS score: 7.8) - An insufficient granularity of access control in Windows User-Mode Power Service (UMPS) that could allow an authorized attacker to elevate privileges locally and gain SYSTEM privileges.

VULNEREBILITY

VULNEREBILITY

18.9.26

CVE-2026-85921 (CVSS score: 8.2) - A double free vulnerability in Windows Secure Kernel Mode that could allow an authorized attacker to elevate privileges locally and gain Virtual Trust Level 1 (VTL1) privileges.

VULNEREBILITY

VULNEREBILITY

18.9.26

Plugin4Shell Plugin4Shell - Zero Click RCE Vulnerability found in top 4 most popular coding agents, millions of agents affected

VULNEREBILITY

VULNEREBILITY

18.9.26

WeaselBiscuit WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials MALWARE INFOSTEALER

18.9.26

RatHat The zLabs team has uncovered RatHat, a novel Android malware strain linked to threat actors that appear to be operating in China. RatHat incorporates novel techniques for persistence and leverage generative AI for operational control. MALWARE ANDROID AI

17.9.26

KREMLIN toolkit leveraged in malicious operation REF9334 Elastic Security Labs researchers have documented findings concerning a sophisticated Brazilian cybercrime operation tracked as REF9334 that impersonates roughly a dozen regional financial institutions to deploy rogue browser extensions.  ALERTS VIRUS

17.9.26

AutoIT delivery campaign distributing AsyncRAT malware Point Wild Threat Intelligence documented a sophisticated, multi-tiered intrusion chain that deploys AsyncRAT malware variant. The compromise initiates via a deceptive batch script masquerading as an invoice file. Upon execution, this launcher invokes a covert PowerShell instance that pieces together ten fragmented Base64 strings, eliminates obfuscating filler characters, and unscrambles the data using a repeating XOR key. ALERTS CAMPAIGN

17.9.26

VectraRAT - a new malware-as-a-service (MaaS) variant SOCRadar’s research team has identified VectraRAT, a novel Malware-as-a-Service (MaaS) platform engineered entirely from the ground up. Architecturally, the ecosystem pairs a Go-based central command hub with an integrated Vue3 management console and a native C++ Windows client, utilizing a custom binary MessagePack TCP protocol for communication. ALERTS VIRUS

17.9.26

Hagaseca THost9 - a multi-stage Android RAT Loader The Hagaseca malware cluster targets Android systems, exploiting vulnerable, internet-facing Android Debug Bridge (ADB) ports as well as containerized Redroid environments. As reported by Dark Atlas researchers, the intrusion chain relies on a specialized packer and launcher, exemplified by the THost9 APK build.  ALERTS VIRUS

17.9.26

VHDX malware distribution campaign Cybersecurity researchers from CYFIRMA uncovered a sophisticated malware operation mimicking India's Income Tax Department to compromise Windows systems. The adversaries deployed a number of fraudulent web domains designed to imitate authentic government revenue portals. The attack delivers its payload inside a virtual hard disk container (VHDX) masquerading as an official tax return utility.  ALERTS CAMPAIGN

17.9.26

PhantomRaven infostealer CrowdStrike researchers recently identified a financially motivated threat actor, operating legitimately as a bug bounty researcher, who distributed a JavaScript-based infostealer dubbed PhantomRaven. The actor targeted software developers on the open-source npm registry by uploading typosquatted packages that housed benign code, like a basic "Hello, world!" script. ALERTS VIRUS

17.9.26

KATARU IoT malware KATARU is a novel IoT malware built atop a conventional Mirai foundation. As reported by Nozomi Networks researchers, the botnet exhibits unusually sophisticated technical capabilities, integrating local privilege escalation exploits, anti-analysis routines, decoy traffic generation, and broad persistence mechanisms spanning Android, desktop, router, and embedded Linux environments. ALERTS VIRUS

17.9.26

CVE-2026-18574 An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server.

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-91843 CVE-2026-91843 - Stack overflow in login process to the Security Management and Log Servers

VULNEREBILITY

VULNEREBILITY

17.9.26

Protecting Tokens and Assertions from Forgery, Theft, and Misuse Implementation Recommendations for Agencies and Cloud
Service Providers
Security guidance Security guidance

17.9.26

Identifying and Mitigating
Living Off the Land Techniques
This guide, authored by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI), and the following agencies (hereafter referred to as the authoring agencies), provides information on common living off the land (LOTL) techniques and common gaps in cyber defense capabilities. Security guidance Security guidance

17.9.26

Using Cyber Decoys to
Strengthen Detection and
Response
This guidance explains how organizations can strengthen their cyber defenses by deploying realistic decoy systems and information assets to quickly detect and disrupt malicious activity inside their networks. It uses the MITRE Engage™ and MITRE ATT&CK® frameworks to provide practical, low-complexity steps for planning, implementing, and refining decoy operations that reduce time to detection and improve use of defensive resources. Security guidance Security guidance

17.9.26

SparroWock ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group MALWARE BACKDOOR

17.9.26

CHOSEN BRICK Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves. MALWARE BOT

17.9.26

HEAVYGRAM HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack MALWARE BACKDOOR

17.9.26

MovieReaper Torrent trackers have long been abused for distributing malicious software, disguised as popular films, games, and other content. Our previous research has shown that cybercriminals repeatedly turn torrents as an initial infection vector, using trojanized cracks and installers to reach a large number of users. MALWARE TROJAN

17.9.26

MLflow dspy and statsmodels flavors bypass pickle deserialization control A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels flavor does not apply the control. ALERT ALERT

17.9.26

Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment A vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation results in arbitrary code execution within the coding‑agent environment and access to connected source repositories. This vulnerability is tracked as CVE-2026-90999. ALERT ALERT

17.9.26

Iranian Cyber Targeting of Dissidents, Activists and Journalists CHOSEN BRICK is a malware family that has been used to target individuals around the world including in the UK, US and the Netherlands from at least 2025. CHOSEN BRICK enables Iranian state cyber actors to collect information on a target’s contacts, emails and social media messages, which could enable tracking of their movements. IC3 IC3 INDUSTRY

17.9.26

Update on Government of Iran Cyber Actors' Deployment of Telegram C2 to Push Malware to Identified Targets The Federal Bureau of Investigation (FBI) is releasing this FLASH to disseminate a detailed malware analysis of the HEAVYGRAM malware. IC3 IC3 INDUSTRY

17.9.26

CVE-2026-58704 Google Pixel Improper Authorization Vulnerability KEV KEV

17.9.26

CVE-2026-76460 Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability KEV KEV

17.9.26

CVE-2026-87886 Acronis Backup Incorrect Default Permissions Vulnerability KEV KEV

17.9.26

Cisco Advance Notification for Publication of September 16, 2026, Security Advisories On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device.This vulnerability is due to missing authorization checks. An

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine 802.1X Session Hijack and Information Disclosure Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an unauthenticated, local attacker to either conduct an authentication bypass or disclose sensitive information.For more information about these vulnerabilities, see the Details

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct SQL injections, modify data, or execute arbitrary commands on the underlying operating system on an affected device.For more information about these vulnerabilities,

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Authentication Bypass Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on an affected device.For more

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Authentication Bypass Vulnerability A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Authorization Bypass Vulnerabilities Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device.These vulnerabilities are

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Command Injection Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform command injection attacks on an affected device and execute arbitrary commands as the root user. To exploi

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Cross-Site Scripting Vulnerability A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface.This vulnerability exists because the web-based

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Hardening Release: September 2026 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in software hardening

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Information Disclosure Vulnerability A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.This vulnerability is due to

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Multiple Path Traversal Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to conduct path traversal attacks on an affected device.For more information about these vulnerabilities, see the

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine RADIUS Denial of Service Vulnerability A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.This vulnerability is due to improper handling of certain RADIUS requests. An attacker could

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Remote Code Execution Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit these vulnerabilities, the attacker must have valid administrative

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine SQL and HQL Injection Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct SQL or HQL injection attacks on an affected device.These vulnerabilities are due to insufficient validation of

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine SQL Injection Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to conduct SQL injection attacks on an affected device.For more information about these vulnerabilities, see the Details section of this advisory.Cisco has

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Identity Services Engine Vulnerabilities Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks on

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Integrated Management Controller Argument Injection Vulnerabilities Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco IOS XR Software Security Hardening Release: September 2026 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Nexus Dashboard Software Security Hardening Release: September 2026 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Email Gateway SQL Injection Vulnerability A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.This vulnerability is due to insufficient

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilities Multiple vulnerabilities in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that this vulnerability affects all Cisco

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the TCP DNS response handler to unexpectedly restart,

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software engineering team has conducted a

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Vulnerabilities Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated attacker to perform an sftunnel authentication bypass or sftunnel denial of service (DoS) attack.For more information

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device.This vulnerability is due to insecure

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Management Center Software sftunnel Root Arbitrary Code Execution Vulnerability A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root.This vulnerability exists because a registered sftunnel peer has

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Management Center Software Static Credential Vulnerability A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.This vulnerability is due

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Management Center Software Vulnerabilities Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software could allow a remote attacker to gain root access and perform session forgery or session impersonation.For more information about these vulnerabilities, see the

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Management Center Software Vulnerabilities Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software could allow a remote attacker to gain root access, download sensitive files, perform a SQL injection attack, or cause a denial of service (DoS) condition.For more information about these

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Service Vulnerability A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 2 Detection Engine to restart.This vulnerability is due to incomplete validation of

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco Secure Firewall Threat Defense Software TLS 1.3 Denial of Service Vulnerability A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.This vulnerability is due to

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection Vulnerability A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to inject arbitrary operating system commands.This vulnerability is due to improper validation of user-supplied input to the web-based management

VULNEREBILITY

VULNEREBILITY

17.9.26

Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or 'mce-annotation tox-comment

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-81736

If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-81563

A BIND resolver encountering an SVCB/HTTPS AliasMode record referencin ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-80274

If a BIND resolver sends a query for a DNSSEC-signed authoritative zon ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-78301

A malformed zone may contain an NS or DNAME node above its origin, whi ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-77692

An attacker can cause `named` to abort by sending a crafted DNS-over-H ..

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-77119

A validly signed NSEC3 from an unrelated sibling zone may be accepted ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-76163

If BIND is loaded with a "`named.conf`" file that contains no global " ..

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-75029

In a query response, an attacker may send `named` multiple copies of a ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-19941

An inapplicable NSEC record may be accepted by a `named` resolver as p ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-19668

A BIND recursive resolver may experience excessive resource consumptio ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-19667

If an attacker-controlled authoritative server can produce a negative ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-19666

On a resolver configured to use ``dns64``, if an applicable answer fro ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-19662

An attacker may be able to cause a `named` resolver to abort. The atta ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-19033

For a secondary zone with transfers restricted by TSIG, `named` may st ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2025-40777

If a `named` caching resolver is configured with `serve-stale-enable` ...

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-89026

The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens.

VULNEREBILITY

VULNEREBILITY

17.9.26

BragJack

BragJack: How We Hijacked 5 Of The World's Most Popular Browsers Using Their Built-In AI Assistants

HACKING

AI

17.9.26

CVE-2021-26855

Microsoft Exchange Server Remote Code Execution Vulnerability

VULNEREBILITY

VULNEREBILITY

17.9.26

CVE-2026-90894

Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials.

VULNEREBILITY

VULNEREBILITY

17.9.26

N0va Phishkit

N0va Phishkit Targets North America and Europe Through Microsoft Logins

PHISHING

PHISHING KIT

16.9.26

Inside Tajin Group’s Phishing and
Money Laundering Network

Tajin Group detailed its operational challenges and announced key plans and changes, showcasing its ability to adapt and evolve to conduct payment card theft and money laundering activities.

REPORT

REPORT

16.9.26

Tajin Group’s

Tajin Group detailed its operational challenges and announced key plans and changes, showcasing its ability to adapt and evolve to conduct payment card theft and money laundering activities.

GROUPS

GROUPS

16.9.26

GhostCode

In late August 2026, eSentire's Threat Response Unit (TRU) identified an active device code phishing campaign distributed through web contact forms. In the campaign, threat actors posed as a procurement officer of a legitimate business. TRU is tracking the device code phishing kit used in the campaign as "GhostCode".

CAMPAIGN

CAMPAIGN

16.9.26

Smish

A widespread smishing campaign was identified in which victims received fraudulent SMS messages impersonating official entities and were instructed to click a link inside the SMS in order to “complete a verification“, “settle an outstanding fee”, or “re-confirm delivery details”.

CAMPAIGN

CAMPAIGN

16.9.26

Pixel Update Bulletin—September 2026

The Pixel Update Bulletin contains details of security vulnerabilities and functional improvements affecting supported Pixel devices (Google devices). For Google devices, security patch levels of 2026-09-05 or later address all issues in this bulletin and all issues in the September 2026 Android Security Bulletin. To learn how to check a device's security patch level, see Check and update your Android version.

VULNEREBILITY

SOFTWARE PATCH REPORTS

16.9.26

CVE-2026-87886

Local privilege escalation due to insecure file permissions

VULNEREBILITY

VULNEREBILITY

16.9.26

CVE-2026-58704

In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

VULNEREBILITY

VULNEREBILITY

16.9.26

CVE-2026-78159

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array().

VULNEREBILITY

VULNEREBILITY

16.9.26

CVE-2026-78006

The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute before unserialize() is reached.

VULNEREBILITY

VULNEREBILITY

16.9.26

CVE-2026-5430

The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access.

VULNEREBILITY

VULNEREBILITY

16.9.26

KREMLIN

The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions

MALWARE

BANKING

15.9.26

Agentic Ransomware

Ransomware has always needed a human involved somewhere: an affiliate navigating a network by hand, or at minimum, a person who wrote the script the malware executed. Agentic ransomware breaks that assumption.

RANSOM

RANSOM

15.9.26

VectraRAT

SOCRadar’s Threat Research Unit (STRU) has documented VectraRAT, a Malware-as-a-Service platform built entirely from scratch rather than forked from leaked RAT code. Renting from $250 a month, it gives operators hidden-desktop control, keylogging, clipboard hijacking, browser credential theft, and a UAC bypass that elevates with no prompt.

MALWARE

RAT

15.9.26

CVE-2026-76461

Cisco Secure Email Gateway SQL Injection Vulnerability

VULNEREBILITY

VULNEREBILITY

15.9.26

CVE-2026-76461

Cisco Secure Email Gateway SQL Injection Vulnerability

KEV

KEV

15.9.26

Physical Memory Fault Injection Attacks on DDR5

Researchers reported a physical attack technique that they say can potentially undermine the integrity guarantees of AMD Secure Encrypted Virtualization – Secure Nested Paging (SEV-SNP) on systems using DDR5 memory. According to their report, an adversary who has privileged software access and physical access to the motherboard can insert a t hardware device between the processor and a DDR5 memory module.

ATTACK

ATTACK

15.9.26

DDRop: Active Memory Interposer Attacks on Confidential VMs
by Dropping DDR5 Writes

Trusted Execution Environments (TEEs) are increasingly deployed in the cloud to protect sensitive workloads through hardwareenforced isolation, remote attestation, and transparent memory encryption. However, to meet memory performance and size demands, modern TEEs omit cryptographic freshness guarantees, leaving them vulnerable to replay attacks by adversaries with physical memory access.

PAPERS

PAPERS

15.9.26

CVE-2024-21762

A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests

VULNEREBILITY

VULNEREBILITY

15.9.26

CVE-2026-60004 

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

VULNEREBILITY

VULNEREBILITY

15.9.26

Red Heron

Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit

GROUPS

GROUPS

13.9.26

CVE-2025-14733

An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer.

VULNEREBILITY

VULNEREBILITY

12.9.26

DoppelCart

DoppelCart: 119,000 Domains in What May Be the Largest Documented Fake-Shop Network

INCIDENT

INCIDENT

12.9.26

CVE-2026-58231

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-58240

SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system.

VULNEREBILITY

VULNEREBILITY

12.9.26

Distillation Attacks

Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks

ATTACK

AI

12.9.26

SloppyRAT malware

Researchers at Zscaler ThreatLabz uncovered SloppyRAT, an emerging malware strain linked to ransomware operators aiming to establish initial footholds and facilitate lateral network traversal across victim environments. Delivered primarily through multi-stage ClickFix delivery campaigns, this remote access trojan supplies attackers with an expansive suite of built-in, PowerShell-like commands alongside reverse SOCKS proxy capabilities.

ALERTS

VIRUS

12.9.26

Espionage Groups Deploy BlueMoon Exploit Chain

Researchers at Proofpoint recently reported on targeted spearphishing campaigns involving multiple state-aligned espionage groups utilizing a novel exploit framework dubbed BlueMoon. The campaigns primarily involve China-nexus threat groups, such as Sheathminer (aka APT31, TA412), targeting entities globally using newly staged infrastructure.

ALERTS

GROUP

12.9.26

Telegram-beaconing VBS downloader deploys ScreenConnect RMM

Symantec has observed a campaign using an unobfuscated VBScript downloader distributed as a fake Adobe plugin update. The script fingerprints the host, attempts to disable Windows Defender and Smart App Control through registry policy writes, and then invokes msiexec to install a remotely hosted MSI package that deploys the ConnectWise ScreenConnect client, giving the actor access.

ALERTS

VIRUS

12.9.26

Mantax Otax Android Malware

Researchers at Zimperium recently reported on Mantax Otax, a dual-function Android malware strain originating from threat actors based in Indonesia. The hybrid threat targets regional Android users by combining intrusive espionage tools and file-encryption capabilities into a single payload.

ALERTS

VIRUS

12.9.26

GoldFactory threat group abuses Android Work Profiles with Vwork clone tool

Cybersecurity researchers at Group-IB discovered a novel defense-evasion technique used by the threat group GoldFactory, creators of the Gigabud Android banking trojan. The operators pair their malware with Vwork, an adapted variant of the open-source utility Shelter that exploits Android’s Work Profile architecture.

ALERTS

GROUP

12.9.26

CL-CRI-1171 cybercrime operation

Unit 42 researchers uncovered an extensive, two-year cybercrime scheme designated as CL-CRI-1171. The group responsible functions as a commercial pay-per-install marketplace that distributes diverse payloads for third-party adversaries. The operation funnels traffic through two deceptive avenues: manipulated search engine results and influential gaming-focused YouTube channels.

ALERTS

CRIME

12.9.26

ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch index

An out-of-bounds (OOB) memory access vulnerability involving unchecked array indexing has been identified in the exllamav3_ext compute unified device architecture (CUDA) extension. Successful exploitation can lead to an immediate denial of service or application instability. This vulnerability is tracked as CVE-2026-84286.

ALERT

ALERT

12.9.26

CVE-2026-85706

GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

KEV

KEV

12.9.26

CVE-2026-42016

JFrog Artifactory Incorrect Authorization Vulnerability

KEV

KEV

12.9.26

CVE-2026-42018

JFrog Artifactory Improper Authentication Vulnerability

KEV

KEV

12.9.26

CVE-2026-84869

ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability

KEV

KEV

12.9.26

CVE-2026-85706

Path Traversal issue in repository commits API impacts GitLab CE/EE

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-87719

Insecure Deserialization issue in GraphQL subscription serializer impacts GitLab EE

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-88765

Buffer Overflow issue in Unicode conversion wrapper impacts GitLab EE

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-79708

Scheduled Pipeline Execution Policy test allows Developers to access protected CI/CD variables

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-78252

Cross-site Scripting issue in Markdown JSON table renderer impacts GitLab CE/EE

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-13210

Incorrect Authorization issue in CI/CD environment variable scope matcher impacts GitLab CE/EE

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2025-14871

Denial of Service issue in GraphQL complexity limiter impacts GitLab CE/EE

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-1168

Denial of Service issue in GraphQL complexity limiter impacts GitLab CE/EE

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2024-11222

Race Condition issue in Merge Request Pipelines impacts GitLab CE/EE

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-12910

Improper Authentication issue in SAML SSO sign-in restriction enforcement impacts GitLab CE/EE

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-82837

Insufficiently Protected Credentials issue in Workhorse senddata emitters impacts GitLab CE/EE

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-19619

Cross-site Scripting issue in Content Editor impacts GitLab CE/EE

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-86341

Access Control Implementation issue in protected environment approval rules impacts GitLab EE

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-86340

Authorization Bypass issue in protected environment approval rules impacts GitLab EE

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-7514

Missing Authorization issue in Generic Package Registry impacts GitLab CE/EE

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-8030

Improper Input Validation issue in Namespace Transfer impacts GitLab CE/EE

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-16794

Missing Authorization issue in Compliance Framework management impacts GitLab EE

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-3855

Improper Input Validation issue in Terraform State API impacts GitLab CE/EE

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-85706

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API.

VULNEREBILITY

VULNEREBILITY

12.9.26

Casbaneiro

In August 2026, FortiGuard Labs observed a Casbaneiro attack campaign targeting users in Latin America, using phishing emails and PDF files themed around fake invoices and legal notices as the initial stage.

MALWARE

BANKING

12.9.26

ShadowPane

ZeroBEC uncovered a phishing campaign we track as ShadowPane that uses browser-in-the-browser deception to make malicious RMM installations appear to originate from Adobe.

CAMPAIGN

CAMPAIGN

12.9.26

SloppyRAT

In June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being delivered through a multi-stage ClickFix infection chain.

MALWARE

RAT

12.9.26

MacSync

Executive Summary MacSync Stealer is a family of macOS information stealers and remote-access stagers designed to evade detection and sold commercially under a malware-as-a-service (MaaS) model. In the attack chain, MacSync binaries are native stagers and multi-part exfiltration engines....

MALWARE

MACOS

12.9.26

Gray Rabbits

One click. Three critical failures. One backdoor.

MALWARE

BACKDOOR

12.9.26

GuardBreaker

LLM-based code scanners won’t help attackers build a nuclear weapon, but that refusal could work in their favor

MALWARE

AI

12.9.26

CVE-2026-73693

(CWE-78): a contact-sheet handler runs an attacker-chosen filename through a shell, so a file uploaded with a command in its name executes it.

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-73694

(CWE-78): a superuser settings test endpoint passes an operator-supplied argument straight to a shell and reflects the output, a direct command channel.

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-73698

(CWE-89): a delegated (non-superuser) administrator turns a control-panel field into raw SQL, including stacked statements.

VULNEREBILITY

VULNEREBILITY

12.9.26

CVE-2026-73699

(CWE-502): a permission blob deserialized on every page load instantiates arbitrary classes, which the SQL injection above weaponizes into a file write.

VULNEREBILITY

VULNEREBILITY

11.9.26

Detecting and countering misuse of AI: September 2026

Over the past eight months, our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity. In this report, we share case studies from those operations and describe how malicious use of Claude has evolved since our previous threat reports in March, August, and November 2025.

REPORT

REPORT

11.9.26

AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disks

An incorrect permissions assignment vulnerability in the amwrtdrv.sys kernel driver, included with AOMEI Backupper 8.4.0, allows an unprivileged local user to perform arbitrary writes to the physical disk.

ALERT

ALERT

11.9.26

CVE-2026-67277

MikroTik RouterOS Missing Authentication for Critical Function Vulnerability

KEV

KEV

11.9.26

CVE-2026-86060

MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

KEV

KEV

11.9.26

Atomic macOS (AMOS) Stealer infection

Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website.

MALWARE TRAFFIC

MALWARE TRAFFIC

11.9.26

XWorm infection

Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website.

MALWARE TRAFFIC

MALWARE TRAFFIC

11.9.26

CVE-2026-82329

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

VULNEREBILITY

VULNEREBILITY

11.9.26

CVE-2026-42016

JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.

VULNEREBILITY

VULNEREBILITY

11.9.26

CVE-2026-42018

JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.

VULNEREBILITY

VULNEREBILITY

11.9.26

CVE-2021-38003

Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

VULNEREBILITY

VULNEREBILITY

11.9.26

Hagaseca

Hagaseca: Inside a Packed Android RAT Loader

MALWARE

RAT

11.9.26

Mantax Otax

Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration

RANSOM

RANSOM

10.9.26

CVE-2026-20079

Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability: Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.

ECV

ECV

10.9.26

CVE-2026-87491

Google Chromium V8 Out of Bounds Write Vulnerability: Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page.

ECV

ECV

10.9.26

CVE-2025-25249

Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability: Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.

ECV

ECV

10.9.26

CVE-2026-19490

Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability: Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.

ECV

ECV

10.9.26

CVE-2026-85880

Microsoft Windows Heap-Based Buffer Overflow Vulnerability: Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.

ECV

ECV

10.9.26

CVE-2026-86218

N-able N-central Static Code Injection Vulnerability: N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.

ECV

ECV

10.9.26

CVE-2026-81963

Microsoft Windows Link Following Vulnerability: Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.

ECV

ECV

10.9.26

CVE-2026-75650

Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability: Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.

ECV

ECV

10.9.26

CVE-2026-85046

Google Chromium V8 Type Confusion Vulnerability: Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

ECV

ECV

10.9.26

CVE-2026-83549

SonicWall SMA1000 Appliances OS Command Injection Vulnerability: SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

ECV

ECV

10.9.26

FBI Cyber Strategy

This Strategy sets the course for FBI Cyber Division to defend the American people and the nation’s critical infrastructure in cyberspace. It defines our priorities, objectives, and framework for countering malicious cyber activity directed at the United States.

IC3

IC3 INDUSTRY

10.9.26

China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies

China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy

IC3

IC3 INDUSTRY

10.9.26

MacSync Stealer deployment via ClickFix campaigns

MacSync Stealer is a commercial macOS malware framework functioning primarily as a stealthy stager and data-exfiltration engine. As reported by Seqrite analysts, the infection typically begins through malvertising or "ClickFix" social engineering schemes, wherein victims unwittingly paste malicious commands into Terminal after encountering counterfeit verification challenges or prompts.

ALERTS

VIRUS

10.9.26

Amatera stealer and ZigCryptoStealer among the payloads delivered in recent ClearFake WebDAV infection chain

Researchers at Cisco Talos reported on widespread credential- and cryptocurrency-harvesting operation centered on the Amatera stealer and attributed to a threat actor designated as UAT-10820.

ALERTS

VIRUS

10.9.26

Ted backdoor and CurlRAT activities in South Korea

Researchers at Rapid7 recently reported a campaign by suspected North Korean state-sponsored actors targeting the media and automotive sectors in South Korea. Seeking long-term espionage, the attackers initially compromise edge web servers—often through vulnerable groupware portals—to deploy a sophisticated Linux toolkit.

ALERTS

VIRUS

10.9.26

BL4CK SP1D3R Ransomware

BL4CK SP1D3R is a Windows ransomware family first publicly documented in July 2026. It encrypts user data, appends the .bl4ck extension, replaces the desktop wallpaper, sets a custom file-type icon, and drops ransom notes that direct the victim to a contact channel and a per-machine identifier.

ALERTS

RANSOM

10.9.26

Attackers impersonate IT support in Microsoft Teams to deploy persistent Node.js backdoors

Threat researchers at Microsoft have documented a targeted intrusion campaign that exploits Microsoft Teams communications.

ALERTS

VIRUS

10.9.26

Self-propagating Go-based Botnet enrolls vulnerable IoT devices for DDoS campaigns

A newly identified IoT botnet written in Go combines autonomous self-propagation with centralized remote execution to launch distributed denial-of-service (DDoS) campaigns.

ALERTS

BOTNET

10.9.26

Updated python-based NodeStealer variant distributed in the wild

Security researchers at Netscope have identified an updated variant of the Python-based NodeStealer malware. Originally developed to harvest web browser data and commercial Facebook accounts, the threat has evolved into comprehensive spyware.

ALERTS

VIRUS

10.9.26

Gambling Goblin threat group activities

Check Point Research has uncovered an extensive cyber campaign by a Chinese-speaking threat group named “Gambling Goblin,” an entity linked to the Earth Berberoka cluster.

ALERTS

GROUP

10.9.26

CVE-2026-19490

NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490

VULNEREBILITY

VULNEREBILITY

10.9.26

Gigabud

Vwork: Weaponized Open-source Software as an Addon for Gigabud

MALWARE

ANDROID

10.9.26

CVE-2026-85102

Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN

VULNEREBILITY

VULNEREBILITY

10.9.26

CVE-2026-85103

ASN.1 decoding heap overflow leading to a remote code execution

VULNEREBILITY

VULNEREBILITY

10.9.26

CVE-2025-25249

Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability

KEV

KEV

10.9.26

CVE-2026-1949

Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability

KEV

KEV

10.9.26

CVE-2026-8749

Google Chromium V8 Out of Bounds Write Vulnerability

KEV

KEV

10.9.26

CVE-2026-20079

Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel

KEV

KEV

10.9.26

Anubis Market

Anubis Market is a multi-category Dark Web marketplace operating as a Tor hidden service, with escrow-backed trading in Bitcoin (BTC) and Monero (XMR). Its visible category strip displays more than 11,000 listings, and while narcotics account for the largest share of physical goods, its Digital section is the single biggest category on the market.

CRYPTOCURRENCY

CRYPTOCURRENCY

9.9.26

CVE-2026-87491

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

VULNEREBILITY

VULNEREBILITY

9.9.26

CVE-2026-67401

Security: CVE-2026-67401 SQL Injection Vulnerability in cPanel's EmailTrack Functionality - September 8, 2026

VULNEREBILITY

VULNEREBILITY

9.9.26

CVE-2025-53521

When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.

VULNEREBILITY

VULNEREBILITY

9.9.26

ShieldCrash

Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak. While Microsoft fixed several things to prevent re-exploiting the issue, they missed a spot where ShieldBreak can still be exploited.

EXPLOIT

EXPLOIT

9.9.26

CVE-2026-44756

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination.

VULNEREBILITY

VULNEREBILITY

9.9.26

SAP Security Patch Day - September 2026

On 8th of September 2026, SAP security patch day saw the release of 19 new security notes. There is 1 update to previously released security note.

VULNEREBILITY

VULNEREBILITY

9.9.26

CVE-2026-55007

(CVSS score: 8.1) - A double free vulnerability in Microsoft Exchange Server that allows an unauthorized attacker to execute code over a network

VULNEREBILITY

VULNEREBILITY

9.9.26

CVE-2026-80097

(CVSS score: 8.6) - An improper authentication vulnerability in Microsoft Authenticator that allows an unauthorized attacker to elevate privileges locally

VULNEREBILITY

VULNEREBILITY

9.9.26

CVE-2026-69465

(CVSS score: 8.8) - A missing authorization vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network

VULNEREBILITY

VULNEREBILITY

9.9.26

CVE-2026-65669

(CVSS score: 9.6) - An injection vulnerability in SQL Server allows an unauthorized attacker to elevate privileges over a network

VULNEREBILITY

VULNEREBILITY

9.9.26

CVE-2026-69525

(CVSS score: 9.8) - A use-after-free vulnerability in Windows Remote Desktop Services that allows an unauthorized attacker to execute code over a network

VULNEREBILITY

VULNEREBILITY

9.9.26

CVE-2026-69595

(CVSS score: 9.8) - A use-after-free vulnerability in Windows Services for NFS ONCRPC XDR Driver that allows an unauthorized attacker to execute code over a network

VULNEREBILITY

VULNEREBILITY

9.9.26

CVE-2026-69730

(CVSS score: 9.8) - A use-after-free vulnerability in Windows DNS server that allows an unauthorized attacker to execute code over a network

VULNEREBILITY

VULNEREBILITY

9.9.26

CVE-2026-69829

(CVSS score: 9.8) - A heap-based buffer overflow vulnerability in Windows Shell that allows an unauthorized attacker to execute code over a network

VULNEREBILITY

VULNEREBILITY

9.9.26

CVE-2026-72979

(CVSS score: 9.8) - A use-after-free vulnerability in Windows DHCP Server that allows an unauthorized attacker to execute code over a network

VULNEREBILITY

VULNEREBILITY

9.9.26

CVE-2026-85880

(CVSS score: 7.8) - A heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC) that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges

VULNEREBILITY

VULNEREBILITY

9.9.26

CVE-2026-81963

(CVSS score: 7.8) - An improper link resolution vulnerability in the Windows Update Stack that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges

VULNEREBILITY

VULNEREBILITY

9.9.26

UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot

The UEFI Shell program may expose raw memory access capabilities that, if present in platform firmware for debugging or advanced support use cases, could be abused to undermine UEFI Secure Boot protections.

ALERT

ALERT

9.9.26

CVE-2026-75650

Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

VULNEREBILITY

VULNEREBILITY

9.9.26

CVE-2026-81963

Microsoft Windows Link Following Vulnerability

VULNEREBILITY

VULNEREBILITY

9.9.26

CVE-2026-85880

Microsoft Windows Heap-Based Buffer Overflow Vulnerability

VULNEREBILITY

VULNEREBILITY

9.9.26

CVE-2026-86218

N-able N-central Static Code Injection Vulnerability

VULNEREBILITY

VULNEREBILITY

9.9.26

CVE-2026-75650

Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

KEV

KEV

9.9.26

CVE-2026-81963

Microsoft Windows Link Following Vulnerability

KEV

KEV

9.9.26

CVE-2026-85880

Microsoft Windows Heap-Based Buffer Overflow Vulnerability

KEV

KEV

9.9.26

CVE-2026-86218

N-able N-central Static Code Injection Vulnerability

KEV

KEV

9.9.26

InTheBox

Technical Analysis of the Web Injects in Android Botnet Operations

HACKING

WEB

9.9.26

SURXRAT

SURXRAT is an actively developed Android Remote Access Trojan (RAT) commercially distributed through a Telegram-based malware-as-a-service (MaaS) ecosystem under the SURXRAT V5 branding.

MALWARE

RAT

9.9.26

TAXISPY RAT

TAXISPY RAT : Analysis of TaxiSpy RAT – Russian Banking – Focused Android Malware with Full Remote Control

MALWARE

RAT

9.9.26

GIGABUD RAT

Sophisticated Android Malware Strikes Users in Thailand, Philippines, and Peru

MALWARE

RAT

9.9.26

Trojan/Linux.MikeDor

Trojan/Linux.MikeDor

MALWARE

BACKDOOR

9.9.26

2026 THREAT HUNTING REPORT

CROWDSTRIKE 2026 THREAT HUNTING REPORT

REPORT

REPORT

9.9.26

BeatBanker

BeatBanker: A dual‑mode Android Trojan

MALWARE

ANDROID

9.9.26

PixRevolution

PixRevolution: The Agent-Operated Android Trojan Hijacking Brazil’s PIX Payments in Real Time

MALWARE

ANDROID

9.9.26

Slim Spider

SLIM SPIDER is an eCrime adversary that has been actively targeting Brazilian financial institutions since at least March 2026. The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment service Pix, digital asset platforms, and financial entities’ cloud environments. SLIM SPIDER’s primary tool is MikeDor, a custom cross-compiled, Go-...

GROUPS

GROUPS

9.9.26

TaxiSpy

Extended IOCs for TaxiSpy Android Banking Malware

MALWARE

SPY

8.9.26

Syslogk Rootkit

Detection and Removal of the Syslogk Rootkit in a Linux Environment

MALWARE

ROOTKIT

8.9.26

HVNC Backdoor

HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures

MALWARE

BACKDOOR

8.9.26

BigBear 2.0

CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries.

OPERATION

OPERATION

8.9.26

Operation GitPower

Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM

OPERATION

OPERATION

8.9.26

WeWorm

The first zero-click worm to spread through WeChat calls across iOS and Android.

MALWARE

WORM

8.9.26

CVE-2026-79678

A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced.

VULNEREBILITY

VULNEREBILITY

8.9.26

CVE-2026-76560

A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity.

VULNEREBILITY

VULNEREBILITY

8.9.26

CVE-2026-76578

A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry

VULNEREBILITY

VULNEREBILITY

8.9.26

CVE-2026-75650

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code.

VULNEREBILITY

VULNEREBILITY

8.9.26

BengalSEO

BengalSEO Part 1: Anatomy of the Operation

OPERATION

OPERATION

7.9.26

CVE-2026-13190

In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution.

VULNEREBILITY

VULNEREBILITY

7.9.26

CVE-2026-13186

In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution.

VULNEREBILITY

VULNEREBILITY

7.9.26

CVE-2026-13185

In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution.

VULNEREBILITY

VULNEREBILITY

7.9.26

CVE-2026-13184

In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains.

VULNEREBILITY

VULNEREBILITY

7.9.26

CVE-2026-13183

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values.

VULNEREBILITY

VULNEREBILITY

7.9.26

CVE-2026-13182

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.

VULNEREBILITY

VULNEREBILITY

7.9.26

CVE-2026-13181

In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments.

VULNEREBILITY

VULNEREBILITY

7.9.26

SourTrade

SourTrade: Browser-Assembled Malware Delivered Through Malvertising

CAMPAIGN

CAMPAIGN

7.9.26

CVE-2026-86218

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

VULNEREBILITY

VULNEREBILITY

7.9.26

CVE-2026-18577

An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs

VULNEREBILITY

VULNEREBILITY

7.9.26

CVE-2026-86206

A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4

VULNEREBILITY

VULNEREBILITY

7.9.26

CVE-2026-86207

An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs

VULNEREBILITY

VULNEREBILITY

7.9.26

JSCeal

Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode

MALWARE

JAVASCRIPT

6.9.26

Vulnerabilities in Mikrotik RouterOS software

During its own research, CERT Polska discovered vulnerabilities in MikroTik RouterOS software and participated in coordinating their disclosure. Details on how these vulnerabilities were found, along with other related information, are available in our separate article.

VULNEREBILITY

VULNEREBILITY

6.9.26

H1 2026 Malware and Vulnerability Trends

Malware and Vulnerability Trends

REPORT

REPORT

6.9.26

REVSTEALER ramps up

Elastic Security Labs details emerging infostealer targeting gamers

PAPERS

MALWARE

6.9.26

REVSTEALER

Elastic Security Labs deep dives into REVSTEALER, an emerging infostealer targeting browsers, wallets, and gaming accounts.

MALWARE

STEALER

6.9.26

StyleSmuggler

StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack

HACKING

HACKING

6.9.26

Acronis Cyberthreats Report, H2 2025

The Acronis Cyberthreats Report covers the global threat landscape as encountered by the Acronis Threat Research Unit (TRU) and Acronis sensors in the second half of 2025. General threat data (including malware, ransomware, web and email threats, vulnerabilities, etc.) presented in the report is gathered from January–December of 2025 and reflects threats targeting endpoints we observed in this time frame

REPORT

REPORT

5.9.26

CVE-2026-59347

HGFS stack buffer-overflow vulnerability

VULNEREBILITY

VULNEREBILITY

5.9.26

CVE-2026-59346

VMXNET3 integer-overflow vulnerability

VULNEREBILITY

VULNEREBILITY

5.9.26

Essential macOS Stealer infection

Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website.

MALWARE TRAFFIC

MALWARE TRAFFIC

5.9.26

Files for an ISC diary (Guildma/Astaroth infection)

Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website.

MALWARE TRAFFIC

MALWARE TRAFFIC

4.9.26

CVE-2026-85046

Google Chromium V8 Type Confusion Vulnerability

KEV

KEV

4.9.26

ASCII smuggling ASCII smuggling crosses over from AI prompt injection to phishing evasion HACKING AI

4.9.26

ted backdoor DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors MALWARE BACKDOOR

4.9.26

PostGREShell PostGREShell: The database powering much of the internet had an open door for 12 years VULNEREBILITY VULNEREBILITY

4.9.26

Zawoo Ransomware Researchers at CERTAINITY recently reported on Zawoo Team, a ransomware operation. The actor has been active since at least early August 2026 and brought its leak site online on 30 August, listing 19 victims at once, concentrated among small and micro enterprises in German-speaking Europe across engineering, industrial software, construction, hospitality and real estate. Access came through the victim's VPN using valid credentials for an already privileged account with no multi-factor authentication enforced, and no exploitation or escalation was observed. ALERTS RANSOM

4.9.26

Mirage Kitten Expands Toolset with Cross-Platform NodeRabbit and PollCat RATs In a recent write-up, Kaspersky details a campaign by the Iranian threat group Mirage Kitten targeting aviation, FinTech, and technology organizations across the Middle East and Africa. The threat actor recruits candidates on professional networking platforms and entices software engineers to download trojanized coding challenges hosted on cloud storage. ALERTS APT

4.9.26

SleepWalker backdoor SleepWalker is a stealthy Windows backdoor identified by an independent researcher at r136a1 that departs from typical malware by staying dormant rather than beaconing to an external command server. Disguised as a native Microsoft dynamic link library with falsified ESET metadata, the implant relies on DLL side-loading to run inside the official ESET Management Agent executable. ALERTS VIRUS

4.9.26

Node.js: Old Technique Makes a Comeback Between March and July 2026, attackers who compromised a technology start-up in Asia ran into a problem: almost every payload they attempted to deploy, including AdaptixC2 agents and Cobalt Strike Beacon, was blocked on the victim's network. Their response was to download the official Node.js installer from nodejs.org and use the trusted, signed runtime to execute a malicious implant. ALERTS VIRUS

4.9.26

GOLD SHERWOOD Operators Leverage Credential Abuse and EDR Killers in The Gentlemen Ransomware Attacks Researchers at Sophos recently reported on the post-exploitation tactics and intrusion mechanics associated with The Gentlemen Ransomware-as-a-service (RaaS) operations. This activity is attributed to the GOLD SHERWOOD threat group. Threat actors reportedly gain initial access through various means, such as exploiting unpatched edge devices or by leveraging compromised VPN user credentials without multi-factor authentication. ALERTS OPERATION

4.9.26

BraZetsu - a Python-based malware Discovered by Group-IB analysts and attributed with high confidence to the Brazilian cybercrime group Exilware, BraZetsu is a modular, Python-based malware framework designed specifically for Initial Access Brokers (IABs). The codebase suggest heavy reliance on generative AI during the development process. ALERTS VIRUS

4.9.26

Casdoor authentication server is vulnerable to authorization bypass Casdoor is an open-source Access Management (IAM) platform used to manage web applications. An authorization bypass vulnerability affects Casdoor versions 3.115.0 and earlier. ALERT ALERT

4.9.26

Cisco IOS XR Software Security Hardening Release: September 2026 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. VULNEREBILITY VULNEREBILITY

4.9.26

CVE-2025-34158 Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the server owner (and a /api/resources call reveals other servers accessible by that server owner). VULNEREBILITY VULNEREBILITY

4.9.26

CVE-2026-32475 Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1. VULNEREBILITY VULNEREBILITY

4.9.26

CVE-2026-14894 CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including executable PHP files, leading to remote code execution. (Fixed in version 6.3.314) VULNEREBILITY VULNEREBILITY

4.9.26

CVE-2026-85046 Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel. VULNEREBILITY VULNEREBILITY

4.9.26

Still Circling This is a collaborative follow-up to our original post, developed jointly with Emmanuel C., a security researcher not affiliated with LevelBlue, who contributed additional infrastructure and tooling findings based on an analysis of the same GitHub staging account. OPERATION OPERATION

3.9.26

BraZetsu Group-IB uncovers BraZetsu, a new Python-based Windows malware that serves as a master toolkit for Initial Access Brokers and powers a unique, AI-enhanced underground marketplace for commercializing compromised Iberian and Latin American targets. MALWARE PYTHON

3.9.26

FalconFlank FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in Crowdstrike Falcon Sensor, obviously by the time I drop this Crowdstrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique. EXPLOIT EXPLOIT

3.9.26

Communicating Under
Pressure: Best Practices for
Service Providers
Service outages impacting IT and operational technology (OT) systems can be damaging and disruptive for customers, network defenders, critical infrastructure
owners and operators, and the general public. During incidents that reach or exceed established thresholds, whether caused by malicious activity or a nonmalicious event, service providers must communicate effectively so end users can minimize operational impact. This guide outlines how to prepare for effective outage communications and key elements of clear, actionable messaging.
Best Practices Best Practices

3.9.26

Cisco IOS XR Software Security Hardening Release: September 2026 These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class - Common Weakness Enumeration (CWE) - and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping. VULNEREBILITY VULNEREBILITY

3.9.26

Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload. VULNEREBILITY VULNEREBILITY

3.9.26

Cisco Desk Phone 9800 Series, IP Phone 7800 and 8800 Series, and Video Phone 8875 with SIP Software Denial of Service Vulnerability A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. VULNEREBILITY VULNEREBILITY

3.9.26

Cisco Secure Email Secure/Multipurpose Internet Mail Extensions Ciphertext Decryption Vulnerabilities At the time of publication, these vulnerabilities affected Cisco Secure Email devices if they were running Cisco AsyncOS Software Release 16.5.0 or earlier and had S/MIME configured for communication between email gateways. VULNEREBILITY VULNEREBILITY

3.9.26

Cisco Advance Notification for Publication of September 2, 2026, Security Advisories Under the Cisco risk-based disclosure process, hardening releases and other security advisories are scheduled to publish on the first and third Wednesday of each month. To help customers prepare, we provide this seven-day advance notice of upcoming security vulnerability disclosures. However, this schedule is not a final commitment of releases. If updates are delayed or unforeseen changes arise, specific products may be removed and rescheduled. Products may also be added when releases are ready ahead of schedule. The latest status is available in the Revision History section of this advance notice. VULNEREBILITY VULNEREBILITY

3.9.26

Cisco Crosswork Security Hardening Release: August 2026 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. VULNEREBILITY VULNEREBILITY

3.9.26

CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. KEV KEV

3.9.26

CVE-2026-83549 (CVSS score: 7.8) - A post-authentication operating system command injection vulnerability in SonicWall SMA 1000 Appliances that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. KEV KEV

3.9.26

CVE-2026-9586 (CVSS score: 9.3) - An SQL injection vulnerability in Sangoma Switchvox that could allow an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution. KEV KEV

3.9.26

CVE-2026-82329 (CVSS score: 9.8) - An improper authentication vulnerability in JFrog Artifactory that under default configuration could allow an unauthenticated attacker with network access to obtain administrative privileges. KEV KEV

3.9.26

CVE-2026-48710 (CVSS score: 6.5) - An HTTP request/response smuggling vulnerability in Kludex Starlette that could allow attackers to inject paths into the host part, prepending the actual path, leading to issues such as authentication bypass when the authentication depends on the reconstructed URL's path. KEV KEV

3.9.26

CVE-2026-49869 (CVSS score: 10.0) - An operating system command injection vulnerability in Kestra OSS that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials. KEV KEV

3.9.26

CVE-2026-59822 (CVSS score: 8.8) - An improper authentication vulnerability in Berri LiteLLM's Model Context Protocol (MCP) Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. KEV KEV

3.9.26

CVE-2026-72718 Arbitrary command execution in goose CLI via `goose review` via git core.fsmonitor VULNEREBILITY VULNEREBILITY

2.9.26

RevStealer malware impersonates legitimate software RevStealer is an infostealer variant found to be commonly distributed under the disguise of trojanized Electron desktop application. As reported by researchers from Morphisec, this malware strain is primarily spread through game-cheat websites and fake GitHub repositories. ALERTS VIRUS

2.9.26

Fiasco Ransomware Symantec has collected and analyzed a ransomware binary that belongs to a likely new double-extortion ransomware actor who goes by the name of "Fiasco". They utilize a Rust-written Windows 64Bit PE to encrypt files and append a .secure extension. ALERTS RANSOM

2.9.26

KryBit Ransomware KryBit is a cross-platform Ransomware-as-a-Service (RaaS) that targets endpoints, virtual machines, and network storage spanning Windows, Linux, and VMware ESXi environments. As per a recent report from Picus Security, the attackers behind this ransomware variant are employing a double-extortion model, and exfiltrating sensitive data before encrypting sensitive files, appending them with a .KRYBIT extension and leaving a ransom note in the form of a .txt file. ALERTS RANSOM

2.9.26

Adware Sideloading Chain Deploys ValleyRAT Payload Kaspersky has published a report on a campaign distributing the ValleyRAT backdoor disguised as adware. The malware arrives through installer files that, depending on a naming variant, install a decoy application such as a collaboration tool or browser while covertly deploying a modified version of a legitimate Chinese wallpaper utility. They're using that utility for DLL sideloading, so the malicious library gets to run under cover of a signed process. ALERTS VIRUS

2.9.26

Virtualizor INCIDENT BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access INCIDENT INCIDENT

2.9.26

Mirax Mirax: a new Android RAT turning infected devices into potential residential proxy nodes MALWARE RAT

2.9.26

StreamRat Uncovering StreamRat: From Meta Ads to Full Device Takeover MALWARE RAT

2.9.26

CVE-2026-83548 A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations. VULNEREBILITY VULNEREBILITY

2.9.26

CVE-2026-83549 Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. VULNEREBILITY VULNEREBILITY

2.9.26

Hugging Face Transformers library writes remote code to disk prior to consent check A vulnerability in the Hugging Face Transformers library (versions 4.49.0 through 5.8.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. The library performs a remote module fetch and local cache write before evaluating the trust_remote_code consent prompt, violating the security contract enforced across other dynamic module-loading paths in the library. ALERT ALERT

2.9.26

Malicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing Since late 2025, malicious cyber actors have been targeting prominent victims, their family members, and personal acquaintances by directly messaging personal accounts with malicious links leveraging a technique known as "OAuth consent phishing." IC3 IC3

2.9.26

CVE-2026-63219 Unauthenticated file upload via missing authorization on formatter upload endpoint VULNEREBILITY VULNEREBILITY

2.9.26

CVE-2021-31886 A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) VULNEREBILITY VULNEREBILITY

2.9.26

CVE-2026-9586 An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. VULNEREBILITY VULNEREBILITY

2.9.26

Plump Spider's Operations New Details on Plump Spider's Operations in Pix Fraud Schemes OPERATION OPERATION

2.9.26

CVE-2026-82329 JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. VULNEREBILITY VULNEREBILITY

1.9.26

PrettyPrague GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability. Another zeroday in an antimalware provider, I'm not sure but I believe this vulnerability affect other GenDigital products as well (such as AVG, Norton...) EXPLOIT EXPLOIT

1.9.26

CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability  VULNEREBILITY VULNEREBILITY

1.9.26

CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability  VULNEREBILITY VULNEREBILITY

1.9.26

CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability  KEV KEV

1.9.26

CVE-2026-82078 PaperCut NG/MF Unsafe Reflection Vulnerability  KEV KEV

1.9.26

CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. VULNEREBILITY VULNEREBILITY

1.9.26

CVE-2026-66066 aka KindaRails2Shell (CVSS score: 9.5) - A vulnerability that could allow an unauthenticated attacker to read arbitrary files from the server, leak Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials, and API tokens, ultimately leading to remote code execution. VULNEREBILITY VULNEREBILITY