ZeroHour

Search: “Vigil”

40 stories in the last 24h

Smart search ranks by meaning as well as keywords (one row per story, last 45 days).

Mass Scanning Targets Exposed Vite Servers to Steal AWS Keys and Azure Tokens

Attackers mass-scanned exposed Vite dev servers exploiting CVE-2026-39364 to read .env files and steal AWS keys and Azure tokens, per F5 Labs honeynet data.

Honeynet telemetry recorded 807 session-grouped attacks and roughly 32,000 raw events in August 2026 against exposed Vite development servers. CVE-2026-39364 (CVSS 7.5) is an unauthenticated file-read flaw in Vite 7.1.0 through 7.3.2 and 8.0.5 that bypasses server.fs.deny via query parameters like ?raw and ?import&raw to return files in plaintext. Attackers also probed older Vite flaws CVE-2025-30208, CVE-2025-31125, and CVE-2024-45811, and used wordlists to locate .env files, AWS credential files, Azure token stores, and Terraform state across Linux, container, and web paths. Exposed secrets could enable lateral movement or full cloud account takeover.

GBHackersupdated · 2d agofirst · 2d agoExploit / PoC in the wild 4 sourcesCVE-2026-39364CVE-2025-30208CVE-2025-31125+1 CVEs

ZDI-26-631: NI LabVIEW VI File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability

ZDI disclosed CVE-2026-18444, an out-of-bounds read in NI LabVIEW VI file parsing that can disclose sensitive information, rated CVSS 3.3.

The Zero Day Initiative published advisory ZDI-26-631 describing an out-of-bounds read vulnerability in NI LabVIEW's parsing of VI files. Exploitation can disclose sensitive information and requires user interaction, such as visiting a malicious page or opening a malicious file. ZDI assigned the flaw a CVSS rating of 3.3.

ZDI-26-627: Backblaze Personal Computer Backup bztransmit Link Following Denial-of-Service Vulnerability

ZDI published ZDI-26-627 for a local denial-of-service flaw (CVE-2026-19820, CVSS 6.1) in Backblaze Personal Computer Backup's bztransmit component.

The Zero Day Initiative published advisory ZDI-26-627 describing a link-following denial-of-service vulnerability in the bztransmit component of Backblaze Personal Computer Backup. Local attackers must first execute low-privileged code on the target system to trigger the condition. The issue carries a CVSS score of 6.1 and is tracked as CVE-2026-19820.

The 12 Best Managed Detection & Response (MDR) Services, Compared and Priced

Buyer's guide compares 12 MDR services, naming Huntress best value, CrowdStrike Falcon Complete for response authority and Expel for transparency.

The article compares 12 managed detection and response providers across response authority, tool bundling and pricing, highlighting Huntress for published SMB pricing and CrowdStrike Falcon Complete for unilateral containment. It stresses the consolidation landscape: Sophos completed its acquisition of Secureworks in February 2025 for approximately $859 million, and Arctic Wolf closed its purchase of BlackBerry's Cylance endpoint assets the same month. It also warns that only full-response contract tiers isolate hosts and kill processes, while lower tiers only triage or guide.

GBHackersupdated · 8d agofirst · 8d agoIndustry 3 sources1

ZDI-26-587: Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

ZDI advisory ZDI-26-587 details a heap-based buffer overflow RCE (CVE-2026-19781, CVSS 7.8) in Ashlar-Vellum Cobalt VS file parsing, requiring user interaction.

The Zero Day Initiative released advisory ZDI-26-587 covering a heap-based buffer overflow in Ashlar-Vellum Cobalt's VS file parsing. A remote attacker can execute arbitrary code when the target opens a malicious file or visits a crafted page. ZDI rated the vulnerability CVSS 7.8 and assigned CVE-2026-19781.

The cybercrime supply chain has five stages, each with a price

Vigilant's CEO outlines the five-stage cybercrime supply chain, from $5-$50 credential logs through RaaS affiliates to laundering, plus cookie-based MFA bypass.

In a Help Net Security video, Vigilant CEO Chris Nyhuis argues the lone ransomware attacker image is 15 years out of date and describes five businesses inside the cybercrime supply chain. The stages are infostealer harvesters, brokers who verify and resell access, ransomware-as-a-service operators, affiliates who run intrusions, and launderers. He notes stolen credential logs sell for $5 to $50, broker listings stay under $1,000, and stolen session cookies let attackers bypass multi-factor authentication.

Help Net Security · 23d agoIndustry

HPE security advisory (AV26-909)

Canada's Cyber Centre relayed HPE advisories covering vulnerabilities in Aruba ClearPass Policy Manager and HPE IceWall products.

Canadian Centre for Cyber Security advisory AV26-909, dated September 10, 2026, flags vulnerabilities in HPE products disclosed on September 9, 2026. Affected products include Aruba ClearPass Policy Manager versions prior to or equal to 6.11.14 and 6.12.8, and multiple HPE IceWall versions and models. Bulletins cover multiple ClearPass vulnerabilities, a remote bypass of security restrictions in IceWall, and an IceWall denial-of-service vulnerability; administrators are urged to review the bulletins and apply updates.

Canadian Centre for Cyber Securityupdated · 16h agofirst · 6d agoAdvisory 2 sources

SafePal breach affects 39,798 customers, data allegedly for sale

SafePal disclosed a breach exposing order data of 39,798 customers via an order-tracking plug-in flaw; the data appears for sale online.

Cryptocurrency wallet maker SafePal exposed names, phone numbers, addresses and purchase details for 39,798 orders placed between March 2, 2025 and April 11, 2026, due to an authorization flaw in an order-tracking plug-in. Seed phrases, private keys, wallet passwords, payment cards and government IDs were not exposed, and no wallet or fund compromise was found. A threat actor is selling data on a cybercrime forum citing the same order window and count, and SafePal has taken down more than 30 phishing sites and notified customers on August 16.

Help Net Security · Aug 17, 2026Data breach in the wild

ZDI-26-591: NVIDIA TensorRT ONNX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

ZDI disclosed a heap-based buffer overflow RCE (CVE-2026-24272, CVSS 7.8) in NVIDIA TensorRT ONNX parsing, requiring user interaction to exploit.

The Zero Day Initiative published advisory ZDI-26-591 covering a heap-based buffer overflow in NVIDIA TensorRT's ONNX file parsing. Successful exploitation allows remote code execution when a user opens a malicious ONNX file or visits a crafted page. ZDI rated the vulnerability CVSS 7.8 and assigned CVE-2026-24272.

HBO Max’s verified Reddit account hijacked to spread malware

Cybercriminals hijacked HBO Max's verified Reddit account to run 108 ClickFix ads pushing AMOS and Amatera infostealers via fake HBO app sites.

Hudson Rock found that hijackers used HBO Max's verified Reddit account to run 108 malicious ads over roughly 48 hours promoting fake AI tools and macOS utilities. The ads led to HBO lookalike sites instructing victims to paste commands into Terminal or PowerShell, a ClickFix social-engineering technique ADAMnetworks dubbed PasteSwitch. macOS payloads included MacSync and AMOS infostealers targeting browser credentials, Telegram data, Apple Notes, passwords, and crypto recovery phrases; Windows users received the in-memory Amatera infostealer. The operation is also linked to cryptocurrency clipboard hijackers, and Reddit admins paused the ads and opened an investigation.

Malwarebytes Labs · 1d agoMalware in the wild 7 sources1

ZDI-26-593: NVIDIA TensorRT ONNX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

ZDI disclosed a second TensorRT heap-based buffer overflow RCE (CVE-2026-24268, CVSS 7.8) in ONNX file parsing, requiring user interaction.

The Zero Day Initiative published advisory ZDI-26-593 covering another heap-based buffer overflow in NVIDIA TensorRT's ONNX file parsing. A remote attacker can execute arbitrary code if the target opens a malicious file or visits a crafted page. ZDI rated the vulnerability CVSS 7.8 and assigned CVE-2026-24268.

Trump is giving data centers a pass to pollute

Former EPA officials warn that Trump-era deregulation to speed AI data center construction worsens pollution, citing 30 federal policy changes.

The Environmental Protection Network, a group of former EPA employees, released a report identifying 30 federal actions since January 2025 — 17 of which specifically mention AI or target data centers — that they say increase health risks from data center pollution. Trump's July 2025 AI Action Plan recommended streamlining regulations under the Clean Air Act, Clean Water Act, and Superfund law to expedite data center and chip factory permitting. A cited study from UC Riverside, Caltech, and Rochester Institute of Technology projects AI-related air pollution could cause up to 1,300 premature deaths and more than $20 billion in public health costs by 2028.

The Verge · AI · 4d agoAI policy2

25 Years of Mass Surveillance Is Enough

Bruce Schneier and Cindy Cohn argue post-9/11 mass surveillance expanded far beyond its counterterrorism justification and should be reevaluated for costs to rights.

An essay by Bruce Schneier and Cindy Cohn (originally in Lawfare) traces the post-9/11 shift from targeted surveillance to mass collection of telephone and internet metadata. It cites the Section 215 bulk phone records program, struck down in interpretation by the Second Circuit in 2015 and curtailed by the USA Freedom Act, and the NSA's Upstream program under Section 702 of the 2008 FISA Amendments Act, which ended content searches in 2017. The authors note mass surveillance now serves routine law enforcement and immigration actions, with FBI Director Kash Patel confirming purchases of Americans' data from brokers, and private systems like Flock license plate readers and venue facial recognition feeding government access.

Schneier on Security · 2d agoPolicy & legal

Severity Is Not a Strategy: What CISA BOD 26-04 Means for the Future of Federal Software Security

CISA's BOD 26-04 replaces severity-based federal patching with risk-based remediation deadlines of 3, 14, or 60 days.

CISA's Binding Operational Directive 26-04, released June 10, 2026, replaces BOD 19-02 and BOD 22-01 for Federal Civilian Executive Branch agencies and shifts remediation prioritization from CVSS scores to risk context. Agencies assess four factors: public exposure, KEV listing, exploit automatability, and whether exploitation grants partial or total asset control, resulting in 3-, 14-, or 60-day remediation windows or next-upgrade fixes. In CISA's first review at a large civilian agency, only 1% of vulnerabilities required three-day remediation while over 60% could wait for future system upgrades. The directive also requires forensic analysis when exploitation is suspected, and Checkmarx argues the same risk-based logic must extend upstream into software development and SBOM-driven exposure management.

Checkmarx · 7d agoPolicy & legal

The Government is Monitoring Anti

Fusion center bulletins reveal US law enforcement monitoring anti-Flock social media accounts and warning police ahead of the DeFlock Week of Action against license plate readers.

Public records requests by 404 Media and journalist Dan Boguslaw exposed intelligence bulletins from fusion centers in Colorado, Wisconsin, and Florida tracking anti-Flock sentiment, camera vandalism videos, and the DeFlock National Week of Action against automated license plate readers scheduled for August 16-22. The bulletins highlight Instagram accounts like Nomark.Project posting daily camera takedowns, and a device found during a June 25 traffic stop that could locate Flock cameras. Police are advised to increase patrols around ALPR locations and warned about upcoming DeFlock events, including 11 Florida cities signed up. DeFlock creator Will Freeman said the project never called for vandalism and that over 100 surveillance contracts have been canceled through civic engagement.

404 Media · Aug 12, 2026Policy & legal1

IDScan Confirms Data Breach Following 153 Million Driver’s Licenses Leaked on the Dark Web

IDScan.net confirms a breach after a marketplace advertised over 153 million US and Canadian driver's licenses, possibly exfiltrated continuously for over a year.

The Louisiana identity-verification firm detected unauthorized access on or around September 1, 2026, after the 'Nexus' identity theft service on the Exploit forum began advertising 170M+ people's records, including 153M+ driver's licenses, 10M+ ID cards, 3M+ travel documents, and 579,000 medical cards. Canadian records exceed 1.1 million, and the trove includes commercial licenses, Common Access Cards, and dispensary IDs, with a record for US Defense Secretary Pete Hegseth reportedly included. Nexus operators claim continuous exfiltration for over a year, with the license count growing by nearly 400,000 in 24 hours, suggesting the intrusion may be active. The FBI's New Orleans field office has opened a formal inquiry, and IDScan.net is offering free credit monitoring.

Cyber Security News · 6d agoData breach in the wild 4 sources

Surfshark VPN says hackers breached internal testing, proxy servers

Surfshark disclosed that hackers accessed misconfigured internal test and proxy servers, exposing build credentials but not customer data, VPN traffic, or production infrastructure.

Surfshark said a human error left an internal engineering test server reachable from the internet, exposing service configurations, build-related credentials, and portions of system binaries and code history. A separate proxy server used for content-accessibility optimization was also accessed, but it stored no user identity data, IP addresses, encryption keys, or browsing traffic. Suspicious activity was detected on August 31, contained on September 2, and remediation completed on September 5, with no evidence of credential misuse or spread to other systems. The company rotated impacted credentials, revoked exposed tokens, added monitoring and hardening, and commissioned an independent infrastructure audit; no customer action is required.

BleepingComputerupdated · 6d agofirst · 6d agoData breach in the wild 2 sources

ZDI-26-639: Oracle VirtualBox VMSVGA Heap-based Buffer Overflow Local Privilege Escalation Vulnerability

ZDI disclosed a heap-based buffer overflow in Oracle VirtualBox's VMSVGA component (CVE-2026-71116) enabling local privilege escalation.

Zero Day Initiative published ZDI-26-639, a CVSS 7.5 heap-based buffer overflow in the VMSVGA component of Oracle VirtualBox. Local attackers who already execute high-privileged code on the guest system can leverage the flaw to escalate privileges on affected installations. The vulnerability is tracked as CVE-2026-71116. No exploitation is reported.

CISA decides weekly vulnerability bulletin isn't necessary anymore

CISA will discontinue its weekly vulnerability bulletin on September 28, pushing users toward KEV, alerts, and CVE data under risk-based prioritization.

CISA announced its weekly vulnerability bulletin will stop on Monday, September 28, as part of a shift from static CVSS severity scores to a modern, risk-based approach detailed in a June Binding Operational Directive. The directive prioritizes federal remediation based on exposure, exploitation evidence, control granted by exploitation, and whether exploitation can be automated. CISA directs bulletin subscribers to rely instead on its Known Exploited Vulnerabilities catalog, cybersecurity alerts and advisories, and the CVE catalog, requiring users to enable those subscriptions in GovDelivery or Granicus to avoid missing critical notices.

The Register · Security · 14h agoPolicy & legal

Week in review: Compromised Zimbra servers, previously patched Citrix NetScaler flaw exploited

Help Net Security's weekly digest highlights 274 compromised Zimbra servers, Gitea and Citrix NetScaler KEV additions, a PaperCut zero-day, and a suspected Iran-linked power plant attack.

The roundup reports at least 274 internet-facing Zimbra instances compromised via CVE-2026-73570, critical Gitea CVE-2026-60004 added to CISA's KEV catalog after exploitation began, and previously patched Citrix NetScaler flaw CVE-2026-8452 exploited in the wild. It also covers PaperCut NG/MF zero-day attacks, a suspected Iran-linked shutdown of a UK power plant, an FBI seizure of domains tied to a China-linked group that hit NASA, DOJ and the Senate, a cyberattack disrupting Boston Scientific, and the Manchester Airports Group breach. Additional items include Chameleon SEO poisoning phishing, Android car head unit proxy botnet malware, ReliaQuest social engineering by ShinyHunters, fake OpenAI Codex macOS malware, and AI-related workforce and supply chain interviews.

[webapps] C-MOR 6.0104 - Directory Traversal

A directory traversal proof-of-concept for video surveillance software C-MOR version 6.0104 has been published on Exploit-DB.

Exploit-DB entry 52666 discloses a directory traversal vulnerability in C-MOR version 6.0104, a video surveillance platform. The issue is listed under web application vulnerabilities. No CVE identifier or exploitation evidence is included in the listing.

Exploit-DB · 17d agoExploit / PoC

12 Best Ransomware Protection Solutions Compared (2026): Features & Pricing

GBHackers compares 12 ransomware protection solutions for 2026, recommending layered stacks of EDR prevention, managed detection, containment, and guaranteed recovery.

The editorial comparison argues no single product stops ransomware, recommending a layered strategy across prevention, early detection, blast-radius containment, and clean recovery. CrowdStrike and SentinelOne are named best-in-class EDR, Huntress and Sophos MDR for managed 24/7 coverage, ColorTokens for microsegmentation containment, and Rubrik and Acronis for guaranteed recovery. The guide notes ransomware is now professionalized with double extortion and encryption sprints measured in minutes.

GBHackersupdated · 2h agofirst · 6d agoIndustry 12 sources1

Phishing Research Challenges Conventional Security Awareness Testing

Pistachio's 2.47 million phishing simulations across 1,200 organizations show click rates alone mislead, with 30% of IT staff clicking and leak rates more predictive.

Between June 2025 and May 2026, Pistachio sent 2.47 million simulated phishing attempts to more than 123,000 employees at over 1,200 organizations, analyzing click, credential-leak and reporting behavior. Click rates ranged from 26% in Design to 41% in Construction; 30% of tech development and IT staff clicked at least once, while financial services were the most resilient sector. The report argues that click rate alone creates a false sense of security and that combined click, leak and report trends are better resilience indicators.

SecurityWeek · 5d agoResearch

ZDI-26-636: Oracle Outside In Technology PostScript File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

ZDI disclosed a heap-based buffer overflow in Oracle Outside In Technology's PostScript parsing (CVE-2026-60412) enabling user-triggered remote code execution.

Zero Day Initiative published ZDI-26-636, a CVSS 7.8 heap-based buffer overflow in PostScript file parsing within Oracle Outside In Technology. Remote attackers can execute arbitrary code when the target opens a malicious file or visits a malicious page, making user interaction a requirement. The vulnerability is tracked as CVE-2026-60412. The advisory reports no exploitation.

The 12 Best Endpoint Detection & Response (EDR) Solutions, Compared and Priced

An editorial scorecard ranks 12 EDR platforms, with CrowdStrike and SentinelOne tied at 8.6/10 and telemetry retention identified as the hidden cost driver.

An editorial comparison scores twelve EDR platforms on detection, response, analyst burden, pricing transparency, and coverage. CrowdStrike and SentinelOne tie at 8.6/10, with Microsoft Defender for Endpoint close behind at 8.5 and described as effectively free in Microsoft 365 E5 estates. The guide argues that telemetry retention, not per-endpoint price, drives real cost, with fully-priced quotes frequently diverging 2-3x from headline rates. Managed detection offerings, including Cynet's bundled 24/7 SOC, factor into the buyer-fit rankings.

GBHackers · 8d agoIndustry 2 sources

ZDI-26-583: Clam AntiVirus 7z Archive Parsing Integer Overflow Remote Code Execution Vulnerability

Zero Day Initiative discloses CVE-2026-20215, an integer overflow in ClamAV's 7z archive parsing enabling remote code execution, rated CVSS 8.4.

The Zero Day Initiative published ZDI-26-583 for an integer overflow in Clam AntiVirus's 7z archive parsing. A remote attacker can execute arbitrary code when the antivirus processes a crafted archive, with attack vectors varying by implementation. The flaw is tracked as CVE-2026-20215 and rated CVSS 8.4. The advisory does not mention active exploitation.

ZDI Published Advisories · Aug 13, 2026VulnerabilityCVE-2026-202151

Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone

CERT/CC disclosed VU#859658: Skullcandy Dime 3 earbuds on firmware 1.0.0.28 accept unauthenticated Bluetooth pairing, letting nearby attackers hijack audio and microphone.

Skullcandy Dime 3 wireless earbuds (model S2DCW, firmware 1.0.0.28) accept Bluetooth Classic BR/EDR pairing requests from unknown devices without the owner activating pairing mode, a flaw linked to CVE-2025-20701 in Airoha Bluetooth audio SDK implementations and tracked as VU#859658 by CERT/CC. Attackers within Bluetooth range who know the device address can bond via the NoInputNoOutput configuration, establish A2DP or HFP/HSP connections, disrupt the owner's active audio session, and potentially capture live microphone audio. Firmware 1.0.0.30 addresses the issue, but Dime 3 earbuds do not support firmware updates through the Skullcandy mobile app, leaving affected users without a known upgrade path.

GBHackersupdated · 6d agofirst · 6d agoVulnerability 2 sourcesCVE-2025-207011

GNU security advisory (AV26-923)

Canadian Cyber Centre advisory AV26-923 flags a stack overflow in GNU libextractor before v1.15 via OLE2 files.

The Canadian Centre for Cyber Security issued advisory AV26-923 on September 15, 2026, covering CVE-2026-91752, a stack overflow vulnerability in GNU libextractor versions prior to 1.15 triggered via OLE2 file parsing. The Cyber Centre encourages users and administrators to review the provided links and apply necessary updates as they become available.

Canadian Centre for Cyber Securityupdated · 12h agofirst · 1d agoAdvisory 2 sourcesCVE-2026-91752

The Smishing Deluge: China-Based Campaign Flooding Global Text Messages

Unit 42 attributes a global smishing campaign with 194,000+ phishing domains impersonating tolls, banks, and couriers to the Smishing Triad.

Palo Alto Unit 42 attributes ongoing smishing texts about toll violations and package misdelivery to the Smishing Triad, targeting U.S. residents since April 2024. Researchers identified 194,345 FQDNs across 136,933 root domains registered since January 2024, mostly via Hong Kong registrar Dominet (HK) Limited with Chinese nameservers and hosting concentrated on U.S. cloud services. The decentralized campaign impersonates banking, cryptocurrency, e-commerce, healthcare, law enforcement, and social media services, and its scale points to a large phishing-as-a-service operation. Phishing pages harvest national ID numbers such as Social Security numbers, home addresses, payment details, and login credentials.

Palo Alto Unit 42 · Aug 17, 2026Phishing & fraud in the wild1

Critical Check Point Vulnerability Allows Remote Root Code Execution Without Authentication

Check Point patched CVE-2026-91843 (CVSS 9.8), an unauthenticated stack overflow enabling remote root code execution on Security Management and Log Servers.

Check Point issued a high-severity alert for CVE-2026-91843, a critical stack overflow (CVSS 9.8, solution sk1000155) in the unauthenticated login workflow of Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server. Successful exploitation grants an unauthenticated remote attacker root-level code execution. Affected releases span R80 through R82.20 with Jumbo Hotfix takes at or below specified levels (e.g., R82.20 Take 44, R81.20 Take 166), with several older versions end of support. A LivePatch is available and offline urgent bundles (R81.20-R82.20 Takes 28-29) were released; Smart-1 Cloud is already protected.

ChatGPT-using lawyer punished for citing fake testimony from made-up witnesses

New Mexico Supreme Court holds lawyer in contempt for filing a ChatGPT-generated brief citing fabricated witness testimony; fined $5,000 and referred to disciplinary board.

The New Mexico Supreme Court held criminal defense lawyer Stephen Aarons in direct contempt for filing a murder-appeal brief containing false testimony from wholly fabricated witnesses, including Officer Michelle Amarillo and Officer Sanchez, plus misrepresented legal authority. Aarons admitted feeding a computer-generated trial transcript into ChatGPT, powered by the OpenAI o3 model, and filing the output without verifying factual claims or telling his client. He was fined $5,000, referred to a disciplinary board, and barred from appearing before the court pending proceedings; the court struck all briefs and ordered new counsel for client Oscar Renee Sandoval.

Ars Technica · AIupdated · 5d agofirst · 5d agoAI safety & security 2 sources

Harnessing LLMs for Automating BOLA Detection

Unit 42's BOLABuster methodology uses LLMs to automate detection of broken object-level authorization vulnerabilities, uncovering flaws in Grafana, Harbor, and Easy!Appointments.

Palo Alto Unit 42 details BOLABuster, a methodology combining large language models with heuristics to automate detection of broken object-level authorization (BOLA) flaws, which traditional fuzzing and static analysis struggle to find. The approach uses LLM reasoning to understand application logic, map endpoint dependency relationships, and generate and interpret test cases. It found CVE-2024-1313 in Grafana, CVE-2024-22278 in Harbor, and 15 CVEs in Easy!Appointments. The team is continuing to hunt for BOLAs in open-source and internal projects.

Check Point security advisory (AV26-902)

Canada's Cyber Centre issued advisory AV26-902 warning of two Check Point RCE flaws, including VPN authentication bypass CVE-2026-85102.

The Canadian Centre for Cyber Security released advisory AV26-902 on September 9, 2026, covering vulnerabilities in Check Point Security Gateway, Spark Firewall with Site-to-Site or Remote Access VPN, and Security Management Server across multiple versions. CVE-2026-85102 is an authentication bypass and remote code execution flaw in Remote Access and Site-to-Site VPN, while CVE-2026-85103 is an ASN.1 decoding heap overflow enabling remote code execution. Administrators are urged to review the linked advisories and apply updates as they become available.

Persistent Attempts at Cyberespionage Against Southeast Asian Government Target Have Links to Alloy Taurus

Alloy Taurus (GALLIUM) compromised Southeast Asian government networks from 2022 to 2023 using Exchange web shells and undocumented .NET backdoors Reshell and Zapoa.

Unit 42 tracked persistent multiwave intrusions at a Southeast Asian government starting in early 2022 and continuing through 2023, attributing the activity with moderate confidence to Alloy Taurus (aka GALLIUM), a Chinese state-aligned espionage group. Attackers exploited Exchange Server vulnerabilities to deploy web shells including China Chopper, then ran reconnaissance with Fscan and WebScan, created administrative accounts, and installed undocumented .NET backdoors named Reshell and Zapoa. They established resilience by installing SoftEther VPN, brute-forced Active Directory credentials with Kerbrute, and dumped credential stores with GoDumpLsass and LsassUnhooker. The campaign reflects long-term espionage tradecraft to maintain a foothold.

Palo Alto Unit 42 · Aug 17, 2026Threat actor in the wild1

2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server

SAP patched two critical flaws, OVERPASS (CVE-2026-44756, CVSS 10.0) and S4GET (CVE-2026-58240), allowing unauthenticated attackers to execute OS commands on SAP hosts.

On SAP's September 2026 Security Patch Day, SAP released Security Notes 3747649 and 3759472 fixing two critical unauthenticated remote vulnerabilities found by Onapsis. CVE-2026-44756 ('OVERPASS', CVSS 10.0) is a memory corruption flaw in Extended Passport (EPP) deserialisation in the SAP Kernel; CVE-2026-58240 ('S4GET', CVSS 9.8) is a missing authentication check in the NetWeaver Message Server that lets attackers register as trusted cluster nodes. Successful exploitation of either can yield OS command execution as the SAP service account, leading to full system and business data compromise, and CERT-EU urges immediate patching. No in-the-wild exploitation is reported.

Manchester Airports Group breached, millions of customers’ data stolen

Manchester Airports Group confirmed attackers stole customer booking and WiFi signup data affecting about 8.7 million customers across three UK airports.

Manchester Airports Group (MAG) confirmed an unauthorized third party obtained customer data tied to car park, lounge and Fast Track bookings and WiFi sign-ups at Manchester, Stansted and East Midlands airports. Stolen data includes email addresses, phone numbers, vehicle registrations and postcodes; no payment or banking details were held in the affected systems. UK media reported roughly 8.7 million customers affected. The Manage My Booking portal was disabled as a precaution, authorities were informed, and airport operations were not disrupted.

Help Net Security · 17d agoData breach in the wild

ZDI-26-590: libwebsockets HTTP/2 HPACK Path Header Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability

ZDI disclosed CVE-2026-19773, an unauthenticated out-of-bounds write allowing remote code execution in libwebsockets HTTP/2 HPACK parsing, rated CVSS 9.8.

The Zero Day Initiative published advisory ZDI-26-590 for an out-of-bounds write vulnerability in libwebsockets' HTTP/2 HPACK path header parsing. A remote attacker can execute arbitrary code on affected installations without authentication. The flaw is tracked as CVE-2026-19773 and carries a CVSS score of 9.8.

Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023

FinCEN urged banks to report cyber scams after a study found $12.7 billion stolen from US victims of crypto investment scams since 2023.

FinCEN analyzed more than 33,000 cyber fraud incident reports filed by roughly 1,300 financial institutions between September 2023 and December 2025, finding about $12.7 billion in losses to cryptocurrency investment scams across all 50 states. Traditional banks reported about $6.4 billion in suspected scam activity and crypto firms about $5.5 billion. Scam activity is growing, with monthly reports rising nearly 11% as centers expand beyond Myanmar, Cambodia, and Laos. The US later sanctioned Xinbi Guarantee, a Telegram-based marketplace used to launder over $36 billion.

The Record · 6d agoPhishing & fraud

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Cisco urgently patched actively exploited zero-day CVE-2026-76460 (CVSS 10.0), an ISE authentication bypass enabling root command execution; CISA added it to KEV.

Cisco released emergency patches for CVE-2026-76460 (CVSS 10.0), a zero-day authentication bypass in an API endpoint of Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC), and confirmed active exploitation in the wild. Successful exploitation lets attackers bypass the web-based management interface and execute commands with root privileges, allowing them to hide or delete indicators of compromise. Fixed releases are ISE/ISE-PIC 3.5 Patch 4, 3.4 Patch 7, 3.3 Patch 12, 3.2 Patch 11, and 3.1 Patch 12; no workarounds exist beyond restricting traffic with infrastructure ACLs. CISA added the flaw to its Known Exploited Vulnerabilities catalog, giving US federal agencies three days to patch under BOD 26-04.

SecurityWeekupdated · 53m agofirst · 4h agoExploit / PoC in the wild 19 sourcesCVE-2026-76460