ZeroHour

Daily brief

AI-written briefings built from the classified stories, KEV additions, high-risk CVEs, incidents and model releases. Daily every morning; weekly recap on Mondays.

daily2026-09-09covers generated glm-5.3-flash

ZeroHour Daily Brief — 2026-09-09

Top story

Cisco Talos is tracking in-the-wild exploitation of CVE-2026-20079 (CVSS 10.0), an authentication bypass in Secure Firewall Management Center's web interface that lets unauthenticated attackers execute scripts and obtain root; three post-compromise clusters are active, including a Sandworm-linked APT and Qilin ransomware affiliates. The flaw is now in CISA's KEV. Pre-auth root on internet-facing firewall management, used by both espionage and ransomware actors, makes this today's urgent patch.

Exploitation & threats

  • BlueMoon kit shared by four China-linked clusters. Proofpoint reports at least four espionage groups — starting with TA412 (tied to Violet Typhoon/APT31) on August 28 — using a nearly identical kit chaining Chrome V8 type confusion (CVE-2026-85046), a V8 sandbox escape, and Windows ALPC escalation (CVE-2026-85880). Targets include US defense contractors, NGOs, mining firms, and Southeast Asian government agencies; APT31's first use deployed the GemStone backdoor.
  • KEV additions: Cisco FMC CVE-2026-20079, Chrome V8 CVE-2026-87491 (the seventh actively exploited Chrome zero-day of 2026), Citrix NetScaler CVE-2026-19490, and Fortinet CVE-2025-25249.
  • N-able N-central: CVE-2026-86218 (CVSS 10.0, pre-auth RCE) added to KEV on September 8 with a September 11 federal deadline; N-able confirmed exploitation in the wild.
  • LiteLLM: Wiz found the CVE-2026-59822 auth bypass (the MCP endpoint accepts any Bearer token) in KEV and confirmed exploitation via honeypots; 9.6% of ~3,074 internet-facing deployments used the default master key sk-1234 or no auth. It chains with CVE-2026-59821 RCE to cloud compromise.
  • AI-built PaperCut campaign: A likely Russian-speaking actor used an OpenAI Codex harness and a DeepSeek model to develop exploits for PaperCut NG/MF (CVE-2026-81578/82078) starting August 31, compromising 440+ instances at 395 organizations in 48 countries, with domain admin in as little as five minutes at 12 victims.

Patch priorities

  • Microsoft: Record September Patch Tuesday fixes 974 product CVEs (999 with third-party), including exploited zero-days CVE-2026-85880 (ALPC heap overflow, sandbox escape to SYSTEM) and CVE-2026-81963 (Update Stack EoP, KEV deadline September 22). Also patch unauthenticated Exchange RCE CVE-2026-55007, DNS bug CVE-2026-69730 (likely to be exploited), and 20 wormable bugs.
  • Chrome: Update to 153.0.8010.36/.37 for 230 fixes, including exploited V8 out-of-bounds write CVE-2026-87491.
  • Adobe: 172 fixes, including the max-severity StyleSmuggler zero-day CVE-2026-75650 — unauthenticated RCE in Magento/Adobe Commerce.
  • Cisco: FMC updates fix CVE-2026-20079 and CVE-2026-20316, the latter a low-privileged login flaw chainable for privilege escalation.
  • N-able: On-prem N-central needs 2026.3.1.14 (Hotfix 4, shipped September 5–6); all builds before it across 2025.4–2026.3 are affected.
  • MikroTik: RouterOS 7.24.2, 7.23.4, 6.49.21 (and 7.25 beta 3) fix six flaws, including the exploited MikroTrick SSH chain (CVE-2026-67276 + CVE-2026-86060) enabling unauthenticated takeover.
  • SAP: Onapsis flags CVE-2026-44756 — unauthenticated RCE in Extended Passport reachable from SAP GUI/RFC; 10,000+ internet-facing systems exposed, no exploitation observed yet.
  • Gitea: CVE-2026-60004 (CVSS 9.8, EPSS 86.8%, PoC available) — repository write access enables code injection via the diffpatch endpoint.

Breaches & incidents

  • AdaptHealth: 4,115,802 patients exposed after social engineering of a privileged third-party contractor account; compromise began June 5 and was disclosed in a July 2 SEC filing. ShinyHunters attributed.
  • Veradigm: Stolen vendor credentials were used against a Veradigm API to download patient data including SSNs; the Gentlemen gang claims 3.5 million patients.
  • Ransomware: 30 leak-site posts in 24 hours. Black Nevas was most active (seven victims including Abans Group, L'azurde, and Speed Group); the Gentlemen also listed Air Canada and PharmaEssentia; Qilin posted Mitsuwa Trading and Jet Specialty; Akira listed Kyodo USA.

AI

  • GPT-6 Astra: OpenAI's strongest model to date scores 99.9% on ARC-AGI-3 versus 7.8% for GPT-5.6 Sol, with standout 3D rendering, animation, and computer-use gains per Sebastian Raschka's review.
  • Navier–Stokes claim: OpenAI says an unreleased internal model running ~10,000 agents produced a claimed solution to the Millennium Prize problem in 88 hours; NYU's Tristan Buckmaster alleges OpenAI scooped joint work with Levent Alpöge, who had posted a proof for a simplified version the day before.
  • Distillation advisory: NSA, CISA, and FBI accuse DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of extracting billions of tokens from Claude, GPT-4/GPT-5, Gemini, and Grok 4 since late 2024 via fraudulent shared accounts, proxy routing, and prompt injection, mapped to MITRE ATLAS.
  • Releases: GPT-Image-2.5 (Flare/Sunburst), OpenEvidence Darwin, and open-weight Nex-N2.5-Pro/mini (Apache-2.0) are trending.

Watchlist

  • Nightwing estimates 22,000+ Exchange servers remain unpatched against CVE-2026-55007 exploit code.
  • BlueMoon adoption could widen — the Chrome-side flaws were patch-gap zero-days.
  • Watch for mass exploitation of the StyleSmuggler Magento zero-day.
  • SAP EPP CVE-2026-44756: 10,000+ exposed systems before wide scanning begins.
  • Federal KEV deadlines: N-able September 11, Microsoft September 22.

Stories in this brief