ZeroHour

Daily brief

AI-written briefings built from the classified stories, KEV additions, high-risk CVEs, incidents and model releases. Daily every morning; weekly recap on Mondays.

daily2026-09-14covers generated glm-5.3

ZeroHour Daily Brief — 2026-09-14

Top story

GitLab's CVE-2026-85706, a CVSS 10.0 path traversal in the repository commits API, was probed in the wild one day after its September 10 disclosure and now sits in CISA's KEV catalog (ZeroHour). A single unauthenticated crafted HTTP request reads arbitrary files — SSH keys, database credentials, deploy tokens, CI/CD variables. Patch now, not on schedule.

Exploitation & threats

  • Microsoft Patch Tuesday roundup: 973 flaws fixed, including actively exploited zero-days CVE-2026-85880 (Windows ALPC EoP) and CVE-2026-81963 (Update Stack EoP); FortiOS CAPWAP CVE-2025-25249 (9.8) deploys the PivotC2 Node.js RAT, exfiltrating Exchange mailboxes to Wasabi; a PAN-OS root RCE was also disclosed.
  • UNC3569 hits Tencent Sogou Input Method: CVE-2026-51990 one-click RCE chain (sgbiz: URI argument injection, unsandboxed Chromium 80 webview) drops GrayRabbit on hundreds of millions of installs; fixed in 16.3.0.3498.
  • Cisco and N-able zero-days: CVE-2026-20079 (Cisco FMC auth bypass) and CVE-2026-20316 exploited in the wild; N-able emergency-hotfixed pre-auth N-central RCE CVE-2026-86218; CERT Polska details six chained MikroTik RouterOS hijack bugs.
  • Microsoft fraud campaigns: 1M+ CEO-impersonation emails (Aug 3–5) with AI-tailored ServiceNow invoices drive ACH fraud at US accounts-payable teams; passkey-themed help-desk vishing since May hijacks cloud accounts for extortion.
  • Casbaneiro targets bank users in Argentina, Peru, Colombia, and Mexico via fake invoice emails, AutoIt staging, and RegSvcs.exe injection.
  • AsyncRAT campaign hides a .NET RAT inside Microsoft-signed charmap.exe via AutoIt abuse and process injection.
  • No new CISA KEV additions in the past 24 hours.

Patch priorities

  • CVE-2026-85706 — upgrade GitLab CE/EE to 19.1.8, 19.2.6, or 19.3.2+; exploitation is live.
  • Check Point VPN (Dutch NCSC): CVE-2026-85102 and CVE-2026-85103, both 9.8, allow unauthenticated RCE on Quantum, Spark, and management servers when VPN is enabled.
  • Dell DSA-2026-393: CVE-2026-70416 (CVSS 10) unauthenticated deserialization RCE in ObjectScale before 4.4.0.0 — full environment takeover.
  • Apache Storm: 13 CVEs fixed in 3.1.0, led by pre-auth Netty DoS CVE-2026-82435 and Nimbus arbitrary file read CVE-2026-82426, plus two setuid-root worker-launcher privescs.
  • Ubuntu USN-8749-1: CivetWeb URI/request flaws CVE-2025-55763 (DoS or code execution) and CVE-2025-9648 (DoS) on 22.04/24.04 LTS.
  • More CVSS 10s to triage: CVE-2026-75650 Adobe Commerce template injection (PoC public); CVE-2026-84869 ScreenConnect unauthorized file execution; CVE-2026-59971 MySQL MCP Server unauthenticated SQL; CVE-2026-80462 Chef Automate elevated access; CVE-2026-81648 CryptoPayment Gateway plugin; CVE-2026-87827 KGUARD DVR; Mistral Vibe CVE-2026-87985/CVE-2026-87987.
  • Canonical GRUB2: the serial command accepts arbitrary MMIO addresses even under Secure Boot lockdown — local grub.cfg control enables bypass; watch for a signed update.

Breaches & incidents

  • Nine leak-site posts in 24h: Qilin (Gilco Scaffolding, CARIDRO VAL DE LOIRE), ShinyHunters (Kimberly-Clark), Chess.com with 4,653,212 records listed, plus Strad Solutions, Navitrans, INCOR Group, kashkha.com, and a redacted audit-team victim.
  • Conti coder sentenced: Oleksii Lytvynenko gets four years; Conti hit 1,000+ organizations across 47 states and 31 countries, payouts above $150M.
  • Insider SIM-swapping: ex-AT&T Portland employee Kenneth Carter drew 16 months for swapping customers' numbers so criminals could intercept authentication codes.

AI

  • Amodei's "We Must Pace the Frontier" (Sept 12) proposes a three-part slowdown with permanent employee-level access for third-party evaluators; Altman, Musk, and Nadella endorsed, and Altman ruled out a 2026 OpenAI IPO. Trump and Speaker Johnson rejected the calls, warning restrictions could let China win.
  • Anthropic threat report: a Yemeni cell assessed highly likely Houthi-linked ran parallel Claude Code sessions to build guidance software for a 2,000+ km ballistic missile and an "R2000" hypersonic glide-vehicle concept, fragmenting tasks to evade safeguards.
  • AWS Deception Benchmark: 14,822 samples, 16 languages; leading models falsely flag 41–99% of safe code as vulnerable, and none met the sub-10% false-positive/false-negative bar.
  • AllSpark Iris agents: open-weight Iris-mini (35B) and Iris-pro (397B; 88.6 on BrowseComp) claim best-in-class results.
  • GPT-6 Astra beat Claude Fable 5.1 on Vending-Bench 2 ($15,515 vs. $5,422) and first beat the human-AI baseline on all five Drone-Bench subtasks; Fable 5.1 solved Urquhart's 1653 Cyphral Distich cipher in 44 minutes.
  • Also out: DeepSeek-V4.1-Flash (MIT) and OpenAI's GPT-Image-2.5 family.

Watchlist

  • Two pre-auth 9.8 Check Point RCEs with NCSC urgency — expect edge-device scanning waves.
  • Storm 3.0.x multi-tenancy: predictable Maven-derived blob keys (CVE-2026-82428) let one tenant substitute jars others execute.
  • NSA reorg: five mission centers reach full capability by January.
  • 47-day certificates by 2029 mean 8× renewals; 34% of firms already report expiry-caused outages.
  • AI agents close patch gaps: disclosure-to-exploit windows shrink fastest in OT/ICS.

Stories in this brief