ZeroHour

Search: “rogue-endpoint”

19 stories

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Critical Cisco FMC Flaws Actively Exploited to Gain Root Access and Deploy Malware

Threat actors actively exploit Cisco FMC CVE-2026-20079 (CVSS 10.0) for root access, with clusters linked to Sandworm and Qilin ransomware.

Cisco Talos warns of active exploitation of CVE-2026-20079, a CVSS 10.0 authentication bypass in Cisco Secure Firewall Management Center allowing unauthenticated root-level code execution, and CVE-2026-20316 (CVSS 5.3), which permits login via a low-privileged static account for privilege escalation. Hotfixes are available now, with a broader hardening release planned for the week of September 14. Three post-compromise activity clusters were identified: UAT-12197 deployed a home.jsp web shell and cmd.jar command executor; UAT-11823, attributed with high confidence to a Sandworm-linked APT, deployed a Netcat reverse shell and Cyclops Blink; and UAT-11988 showed Qilin ransomware tactics including Active Directory enumeration and credential theft before deploying Qilin ransomware.

GBHackersupdated · 3d agofirst · 6d agoExploit / PoC in the wild 7 sourcesCVE-2026-20079CVE-2026-20316

Check Point Vulnerability Lets Remote Hackers Gain Root Access Without Authentication

Check Point patched CVE-2026-91843, a CVSS 9.8 pre-auth stack overflow granting remote root on Security Management and Log Servers.

Check Point released an urgent fix for CVE-2026-91843 (CVSS 3.1: 9.8), a stack-based buffer overflow triggered by an excessively long username during login that lets an unauthenticated remote attacker execute arbitrary code with root privileges. Affected products include Security Management Server, Multi-Domain Security Management Server, and Log Servers across releases from R80 through R82.20, with fixes delivered via LivePatch and urgent Take packages. The vendor reports no observed exploitation in the wild, and administrators are advised to verify patch deployment and restrict SmartConsole Trusted Clients.

Cyber Security Newsupdated · 6h agofirst · 18h agoVulnerability 8 sourcesCVE-2026-91843

GitLab Vulnerability Exploited One Day After Disclosure

WatchTowr observed in-the-wild exploitation of critical GitLab path traversal CVE-2026-85706 one day after disclosure, letting unauthenticated attackers read arbitrary files.

WatchTowr detected the first in-the-wild probes for CVE-2026-85706 (CVSS 10.0), an unauthenticated path traversal in GitLab CE/EE that allows arbitrary file reads via a single HTTP request, and warns mass exploitation is likely. Affected versions include 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2. The fresh patches also fix 17 other vulnerabilities, including CVE-2026-87719 (CVSS 9.9), an insecure deserialization flaw in the GraphQL subscription serializer exposing Advanced Search credentials, plus six high-severity bugs enabling RCE, CI/CD variable access, XSS, and denial of service.

SecurityWeekupdated · 2d agofirst · 5d agoExploit / PoC in the wild 18 sourcesCVE-2026-85706CVE-2026-877192· 1 read

Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain

The Hunter's Ledger tracked campaign UTA-2026-024 using Sliver C2, Domain Admin account creation, and Ethereum-based C2 rotation to compromise a US organization's Windows domain.

The Hunter's Ledger tracked an intrusion at one unnamed US organization as UTA-2026-024, staged from exposed server 193.233.202.17 with a Sliver beacon. Operators created a non-expiring Domain Admin account, enabled RDP with NLA disabled, dumped SAM, SYSTEM and SECURITY hives plus LSASS memory, and disabled eight endpoint protection services. A Node.js implant resolved its C2 server from an Ethereum smart contract that rotated domains five times in five months, while SYSTEM scheduled tasks with backdated dates and DNS allowlist manipulation provided persistence. The infrastructure ties to a confirmed ransomware incident, but no encryptor deployment was proven in this intrusion.

Cyber Security News · 9d agoThreat actor in the wild

Any user process can escalate to root

A disclosed local privilege escalation flaw allows any user process to escalate to root on the affected system.

A Lobsters-linked security write-up describes a vulnerability in which any user process can escalate its privileges to root. The feed text provides no product name, CVE identifier, CVSS score, or exploitation details, limiting available detail. Local privilege escalation flaws are commonly chained with other issues for full system compromise, so defenders should review the full write-up for affected versions and patches.

Lobsters · security · 16d agoVulnerability

Active exploitation of Cisco Secure Firewall Management Center vulnerabilities

Cisco Talos reports in-the-wild exploitation of critical FMC flaw CVE-2026-20079 by three clusters including a Sandworm-linked APT and Qilin ransomware affiliates.

Cisco Talos is tracking active exploitation of CVE-2026-20079 (CVSS 10.0), an authentication bypass in Cisco Secure Firewall Management Center that lets unauthenticated remote attackers execute scripts and obtain root access, and CVE-2026-20316 (CVSS 5.3), which permits low-privileged logins and can be chained for privilege escalation. Talos identified three post-compromise clusters: UAT-12197 deploying JSP web shells and a JAR command executor for credential theft; UAT-11823, an APT overlapping with Sandworm, deploying a Netcat reverse shell and Cyclops Blink malware; and UAT-11988, assessed as a ransomware operator with TTPs consistent with Qilin affiliates. Hotfixes are available, with a comprehensive hardening release due the week of September 14, 2026.

Exploits in the Wild for Citrix ADC and Citrix Gateway Directory Traversal Vulnerability CVE-2019

Unit 42 confirmed in-the-wild exploitation of CVE-2019-19781, a critical Citrix ADC/Gateway directory traversal flaw enabling unauthenticated file access and RCE.

CVE-2019-19781, a CVSS 9.8 directory traversal vulnerability, affects all supported versions of Citrix ADC and Citrix Gateway. Unit 42 captured multiple exploitation attempts in the wild and identified scanning activity from roughly 700 Shodan-exposed hosts. The flaw stems from improper pathname handling in Apache, allowing unauthenticated attackers to read sensitive files like smb.conf or achieve remote code execution via crafted XML. Palo Alto Networks released Threat Prevention signatures 57497 and 57570 on January 7, 2020, while Citrix published advisories CTX267027 and CTX267679 with responder policy mitigations pending a late-January patch.

Palo Alto Unit 42 · Aug 17, 2026Exploit / PoC in the wildCVE-2019-197811

Best Practices for Good Endpoint Hardening | Huntress

Huntress outlines endpoint hardening best practices, citing exposed RDP, RMM tool abuse, and ClickFix social engineering as common SMB intrusion paths.

Huntress published defensive guidance on endpoint hardening for small and mid-sized businesses, drawing on observations from its SOC. The post describes common intrusion vectors: internet-exposed RDP brute-forced by automated scanners, phishing emails delivering attacker-controlled remote monitoring and management (RMM) tools, with Huntress reporting a 277% spike in RMM abuse in 2025, and ClickFix attacks using fake CAPTCHA pages that trick users into running malicious commands. Recommended controls include scanning for exposed RDP, SSH, and VPN interfaces, removing unneeded local admin rights, enabling Windows Defender tamper protection, disabling SMBv1, and standardizing on one approved remote access tool, guided by CIS and NIST frameworks.

Huntress · 6d agoAdvisory

Hackers Exploit JFrog Artifactory Flaws to Bypass Authentication and Gain Admin Access

Wiz Research observes multiple attackers exploiting three JFrog Artifactory flaws, including default-configuration authentication bypass CVE-2026-82329, to gain admin access and deploy backdoors.

Attackers chain CVE-2026-42018 and CVE-2026-42016 to exchange anonymous JWTs for administrator-scoped tokens, or exploit CVE-2026-82329 directly via the registry join endpoint to obtain admin privileges under default configuration. Post-exploitation observed by Wiz includes persistent admin users created within five minutes, malicious Groovy plugins for command execution, and Rust-based backdoors dropped to /tmp, /var/tmp, and /dev/shm with C2 communications. Compromise exposes software artifacts, repository credentials, CI/CD integrations, and cluster secrets, creating supply chain risks. Fixed releases include 7.111.21, 7.117.28, 7.125.20, 7.133.29, 7.146.38, and 7.161.20.

GBHackersupdated · 3d agofirst · 6d agoExploit / PoC in the wild 7 sourcesCVE-2026-42016CVE-2026-42018CVE-2026-82329

cPanel LiteSpeed Web Server Vulnerability Allows Shared Server Users to Gain Root-Level Access

Critical LiteSpeed Enterprise flaw fixed in 6.3.7 lets low-privilege shared-hosting users escalate to root and bypass CageFS.

cPanel issued an urgent advisory for a critical privilege escalation in LiteSpeed Web Server Enterprise versions before 6.3.7, allowing a low-privilege shared-hosting account to gain root-level server control and bypass tenant isolation controls including CloudLinux CageFS. Root access would let attackers access other hosted sites, steal databases and credentials, deploy phishing pages, and install backdoors. Administrators are urged to upgrade to 6.3.7 immediately via lsup.sh and to review privileged account activity, cron jobs, SSH keys, and system binaries; no CVE identifier was published.

Cyber Security News · 1d agoVulnerability

[webapps] C-MOR 6.0104 - Cross-Site Scripting (XSS)

A proof-of-concept cross-site scripting exploit for C-MOR video surveillance software 6.0104 appeared on Exploit-DB.

Exploit-DB published a proof-of-concept cross-site scripting (XSS) exploit against C-MOR 6.0104, an IP video surveillance platform. The listing demonstrates script injection in the web interface, but the provided text contains no CVE identifier or indication of active exploitation. Successful XSS against the surveillance console could enable session hijacking or manipulation of the monitoring interface.

Exploit-DB · 17d agoExploit / PoC1

[webapps] C-MOR 6.0104 - Directory Traversal

A directory traversal proof-of-concept for video surveillance software C-MOR version 6.0104 has been published on Exploit-DB.

Exploit-DB entry 52666 discloses a directory traversal vulnerability in C-MOR version 6.0104, a video surveillance platform. The issue is listed under web application vulnerabilities. No CVE identifier or exploitation evidence is included in the listing.

Exploit-DB · 17d agoExploit / PoC

Cisco Warns of Critical ISE 0-Day Vulnerability Exploited in Attacksnew

Cisco confirms zero-day CVE-2026-76460 (CVSS 10.0) in ISE is under active exploitation, granting unauthenticated root command execution; patches released.

Cisco's PSIRT issued an urgent advisory for CVE-2026-76460, an authentication bypass via insufficient controls on an API endpoint in Cisco ISE and ISE-PIC, confirmed to be actively exploited with a CVSS score of 10.0. Exploitation can yield root-level command execution, enabling persistence, credential theft, and lateral movement from the network policy platform. Fixed releases are ISE 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, and 3.5 Patch 4; EOL version 3.0 requires migration, and iACLs offer only temporary mitigation. The flaw was discovered while resolving a TAC support case, and Cisco provides hunting guidance including access.log review and firewall log analysis.

Fortra security advisory (AV26-906)

Canada's Cyber Centre advises that Fortra GoAnywhere MFT Endpoint versions prior to 7.10.2 are affected by a path traversal vulnerability.

The Canadian Centre for Cyber Security issued advisory AV26-906 noting that Fortra GoAnywhere MFT Endpoint versions prior to 7.10.2 are affected by a path traversal vulnerability. The advisory was published September 10, 2026, referencing Fortra's own security advisory. No exploitation details or CVE id are provided; administrators are urged to review the links and apply the 7.10.2 update.

Canadian Centre for Cyber Security · 6d agoAdvisory

Shared Hosting at Risk: LiteSpeed Enterprise Bug Can Grant Root from a Single Tenant

Critical LiteSpeed Web Server Enterprise flaw (pre-6.3.7) lets a low-privilege shared-hosting tenant escape CageFS isolation and gain root; forced update urged.

cPanel warned that a critical privilege-escalation vulnerability in LiteSpeed Web Server Enterprise (fixed in 6.3.7) lets a malicious low-privilege website user bypass account isolation controls including CloudLinux CageFS and gain root on shared-hosting servers, enabling cross-tenant compromise. No CVE, severity rating, or technical details have been published, and it is unclear whether the flaw is being exploited. This is the third root-level LiteSpeed escape on cPanel servers since May, following CVE-2026-48172 and CVE-2026-54420, which were actively exploited and added to CISA's KEV catalog.

CVE-2026-78254: Apache Ant: Path traversal in ftp and scp tasks allows arbitrary file write

Apache Ant 1.2 before 1.10.18 ftp and scp tasks allow path traversal, letting malicious servers overwrite arbitrary files (CVE-2026-78254).

CVE-2026-78254 affects Apache Ant (org.apache.ant:ant) versions 1.2 before 1.10.18 and is rated moderate. The ftp and scp tasks download files from a remote server, and a malicious server can supply relative paths that write outside the dedicated target directory, overwriting attacker-chosen files with the permissions of the user running Ant. The issue is fixed in Apache Ant 1.10.18.

oss-security · 10d agoVulnerabilityCVE-2026-782541

Hackers Actively Exploiting FortiGate Firewalls to Deploy Custom Node.js Malware

Attackers actively exploit CVE-2025-25249 in FortiGate firewalls to deploy PivotC2, a Node.js RAT that decrypts VPN and admin credentials.

SOCRadar assesses with high confidence that threat actors are actively exploiting CVE-2025-25249, a CVSS 9.8 heap buffer overflow in the cw_acd daemon (CAPWAP, UDP 5246) affecting FortiOS 6.4-7.6.3 and FortiSwitchManager 7.0.x/7.2.x. Attackers deploy fortirun.bin and PivotC2, a Node.js post-exploitation framework that harvests configurations and decrypts SSL-VPN, wireless, and admin credentials using AES-256-CBC and AES-128-GCM. Over 30,000 FortiGate IPs were scanned and 178 devices compromised, including two confirmed full intrusions of US organizations with Exchange mailbox exfiltration to Wasabi storage. STRU attributes the campaign to a Russian-speaking, financially motivated cybercrime operator.

Cyber Security News · 8d agoExploit / PoC in the wildCVE-2025-252491

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

cPanel patched CVE-2026-67401, an SQL injection in EmailTrack letting an account with mail privileges run code as root on the server.

cPanel released an advisory on September 8 for CVE-2026-67401, an SQL injection in EmailTrack that allows an authenticated account holder with mail-related privileges to create files and execute code as root. All supported cPanel and WHM release lines (11.110, 11.134, 11.136, 11.138 and WP Squared 11.138.1.9) are affected, with fixed builds published for each. No public exploit or exploitation has been reported and the flaw is not yet in CISA's Known Exploited Vulnerabilities catalog. The advisory carries no CVSS score, and the CVE record had not been published as of September 9.

The Hacker News · 8d agoVulnerabilityCVE-2026-67401