ZeroHour

Daily brief

AI-written briefings built from the classified stories, KEV additions, high-risk CVEs, incidents and model releases. Daily every morning; weekly recap on Mondays.

daily2026-09-13covers generated glm-5.3

Top story

Proofpoint reports that a new exploit kit, BlueMoon, is chaining two Chrome V8 zero-days (CVE-2026-85046, CVE-2026-87491) with a Windows ALPC privilege-escalation zero-day (CVE-2026-85880), and that multiple espionage groups are adopting it rapidly (Proofpoint reports multiple espionage groups rapidly adopting BlueMoon). China-linked Violet Typhoon (APT31) first used it on August 28 against US NGOs and mining/commodity trading firms; all three flaws were patched between September 3 and this week's Patch Tuesday. Volexity independently documents the same chain by UTA0560 and JungleBamboo, with victims lured via reflected-XSS holes on legitimate US university sites (Volexity reports China-linked UTA0560 and JungleBamboo chained Chrome zero-day CVE-2026-85046 with kernel flaws to spy on NGOs).

Exploitation & threats

Patch priorities

  • Check Point VPN: The Dutch NCSC rates exploitation of CVE-2026-85102 (certificate validation) and CVE-2026-85103 (ASN.1 heap overflow) as high-impact and imminent — patch Security Gateways now (Dutch NCSC warns exploitation is imminent for critical Check Point VPN RCE flaws).
  • Browser/OS zero-days: Confirm Chrome 153.0.8010.36+ and September Patch Tuesday rollout; CVE-2026-87491 (CVSS 8.8) is in active BlueMoon chains.
  • KEV additions: Apply the Artifactory, ScreenConnect (CVE-2026-84869), and RouterOS fixes — or isolate until patched.
  • Plesk Obsidian for Linux: CVE-2026-68488 is a symlink race in Backup Manager restores giving root; fixed after 18.0.80.6/18.0.79.10 (CVE-2026-68488 in Plesk Backup Manager).
  • VLC 3.0.x: Update past 3.0.23 — CVE-2026-56711 (crafted PNG, CVSS 8.6) and CVE-2026-73324 (RTSP leak) affect 3.0.0–3.0.23 (Two VLC 3.0 flaws).
  • CVSS 10 with PoCs: CVE-2026-75650 (Adobe Commerce template injection, PoC 1) and CVE-2026-85706 (GitLab CE/EE, PoC 6).

Breaches & incidents

  • ShinyHunters exploited an Oracle PeopleSoft zero-day against ~100 organizations and 300 instances in May–early June, stealing payroll, health, and immigration data; extortion demands reached $2.3M, including from the Council of Europe (ShinyHunters exploited an Oracle PeopleSoft zero-day).
  • Revolut disclosed KYC data — passports, licenses, verification selfies, IBANs, and full transaction histories including Bitcoin activity — to an attacker using a legitimate government email domain with valid authentication credentials (Revolut leaked KYC documents and full transaction histories); it confirmed the incident September 12 (Revolut handed over KYC documents).
  • Google exposed identifying information of sex-crime victims who filed image-removal requests worldwide, not only in Korea (Google exposed identifying information of sex crime victims).
  • Ransomware leak sites posted 22 victims in 24h: krybit claimed 13 including capricornlogistics.com and eac-airports.com; other notables are INCOR Group (doommageddon), Canadian Mental Health Association (storm), and Axdia International (rhysida).

AI

Watchlist

Stories in this brief