ZeroHour

Search: “mobile”

12 stories in the last 30d

Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People

FulcrumSec leaked about 550 GB of Manchester Airports Group data, exposing emails, phones and vehicle registrations of roughly 8.8 million people after a refused ransom.

Manchester Airports Group, operator of Manchester, London Stansted and East Midlands airports, confirmed a breach of a third-party database after extortion group FulcrumSec leaked roughly 550 GB of data. The exposed data includes about 8.8 million email addresses and phone numbers, 108,077 vehicle registration plates, 2.48 million purchases and 1.16 billion email events, with no payment-card data accessed. FulcrumSec claims it gained access using Iterable admin keys hardcoded in the frontend JavaScript of all three airport websites, a claim MAG has not confirmed. Have I Been Pwned added the incident to its breach database.

Security Affairs · 12d agoData breach

U.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog

CISA added actively exploited flaws in Cisco ISE, Acronis Backup, and Google Pixel (CVE-2026-76460, CVE-2026-87886, CVE-2026-58704) to its KEV catalog.

CISA added three actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2026-76460 (CVSS 10.0), an unauthenticated API authentication bypass in Cisco Identity Services Engine that Cisco confirms is being actively exploited; CVE-2026-87886, a local privilege escalation in the Acronis Backup plugins for cPanel/WHM and Plesk exploited in limited targeted attacks; and CVE-2026-58704 (CVSS 8.8), a Google Pixel cellular modem permission bypass exploited in limited, targeted attacks and patched in the September 2026 Pixel update. Under BOD 22-01, federal agencies must remediate KEV entries by the stated due dates. Google has not attributed the Pixel exploitation to any actor.

Security Affairsupdated · 1h agofirst · 1h agoExploit / PoC in the wild 19 sourcesCVE-2026-76460CVE-2026-87886CVE-2026-58704

Cisco warns customers of actively exploited zero-day in email gateways

Actively exploited Cisco Secure Email Gateway zero-day CVE-2026-76461 allows unauthenticated root command execution; CISA added it to KEV.

Cisco disclosed CVE-2026-76461, a zero-day in AsyncOS for Cisco Secure Email Gateway that was exploited before disclosure and lets unauthenticated remote attackers execute commands with root privileges on cloud and on-premises instances. CISA promptly added the flaw to its Known Exploited Vulnerabilities catalog, and Cisco has directly contacted cloud customers with indicators of compromise while deploying mitigations. Rapid7 and VulnCheck warn compromised gateways could enable silent email monitoring and internal pivoting from on-premises deployments.

CyberScoopupdated · 21h agofirst · 1d agoExploit / PoC in the wild 17 sourcesCVE-2026-76461

Beyond the Perimeter: Building Resilience Against Cloud and SaaS Supply-Chain Attacks

ShinyHunters exploited an Oracle PeopleSoft zero-day to steal data and extort roughly 100 organizations, including the Council of Europe, for up to $2.3M.

Between May and early June 2026, the ShinyHunters group exploited a critical zero-day in Oracle PeopleSoft across about 100 organizations and 300 instances worldwide, per reports cited by The Register. Stolen records included employee and student personal data, payroll, tax, financial and health information, plus immigration and passport documents. AgentCypher.ai estimates extortion demands of $400,000 to $2.3 million per victim, typically in Bitcoin; the Council of Europe refused to pay. The article uses the incident to argue for Zero Trust, supply-chain risk management, rapid patching, encrypted distributed backups and defined recovery-time objectives.

Cyber Security News · 5d agoData breach in the wild1

Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

Adobe patched over 170 flaws, including in-the-wild zero-day CVE-2026-75650 (CVSS 10) in Adobe Commerce/Magento enabling unauthenticated RCE and web shell deployments.

Adobe released fixes for more than 170 vulnerabilities across Experience Manager, Acrobat Reader, Photoshop and other products. The Commerce zero-day CVE-2026-75650 (CVSS 10) allows unauthenticated code injection leading to remote code execution and has been exploited since September 4. Sansec reported multiple threat actors deploying backdoors and web shells via the bug, dubbed StyleSmuggler, which triggers injected code through Magento's Payment Transaction Failed Reminder email. Adobe also patched critical Campaign Classic command injection CVE-2026-82004 and two critical ColdFusion RCE flaws (CVE-2026-48273, CVE-2026-75746).

SecurityWeek · 8d agoExploit / PoC in the wildCVE-2026-75650CVE-2026-82004CVE-2026-48273+1 CVEs1

Google Chrome Zero-day Vulnerability Exploited in the Wild (CVE-2026-85046)

Google patched 12 Chrome flaws including in-the-wild V8 zero-day CVE-2026-85046; CISA added it to the KEV catalog.

Google released Chrome 152.0.7977.82/.83 for Windows and Mac (152.0.7977.82 for Linux) fixing 12 vulnerabilities, including CVE-2026-85046, a type confusion flaw in the V8 JavaScript engine being exploited in the wild. CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities Catalog with a patch deadline of September 18, 2026. This is Chrome's sixth zero-day patched in 2026, following CVE-2026-2441, CVE-2026-3909, CVE-2026-3910, CVE-2026-5281 and CVE-2026-11645. The other 11 fixes include use-after-free, out-of-bounds, race condition and input validation flaws in Skia, WebGL, DevTools, Network, Compositing and other components.

Qualys ThreatPROTECT · 10d agoExploit / PoC in the wildCVE-2026-85046CVE-2026-2441CVE-2026-3909+14 CVEs

Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”

MikroTik RouterOS SSH auth-bypass chain MikroTrick (CVE-2026-67276 plus CVE-2026-86060) is actively exploited; patch to 7.24.2/7.23.5/6.49.21.

Attackers are actively exploiting a chain dubbed MikroTrick that combines CVE-2026-67276 (CVSS 9.2), an SSH authentication bypass in RouterOS RSA public key verification, and CVE-2026-86060, an SSH session privilege escalation, giving full admin control of internet-exposed MikroTik devices without the private key. Exploitation began around September 2, 2026, a day before MikroTik's September 3 patches, with confirmed compromises including creation of an 'ops' account; attacks traced to IPs 82.192.72.4 (Leaseweb) and 103.102.31.18. Fixed versions include 7.25beta3, 7.24.2, 7.23.4, 7.23.5 and 6.49.21. Defenders should check logs for failed logins with username '-2' and inspect /system history for ssh:-2@<IP> entries attached to configuration changes.

Security Affairs · 10d agoExploit / PoC in the wildCVE-2026-67276CVE-2026-860602

CISA Warns of SonicWall SMA1000 Vulnerabilities Active Exploitation (CVE-2026-83548 & CVE-2026-83549)

CISA added two actively exploited SonicWall SMA1000 flaws to KEV: pre-auth SSRF CVE-2026-83548 (CVSS 10) and post-auth RCE CVE-2026-83549; patch by September 5.

CISA added CVE-2026-83548 and CVE-2026-83549 to the Known Exploited Vulnerabilities Catalog with a September 5, 2026 patch deadline. CVE-2026-83548 is a critical (CVSS 10.0) pre-authentication SSRF in the SMA1000 Appliance Work Place interface; CVE-2026-83549 is a high (CVSS 7.8) post-authentication OS command injection leading to RCE in the Appliance Management Console. SMA1000 models 6210, 7210, and 8200v running 12.4.3-03453 or 12.5.0-02835 platform-hotfix and older are affected; fixes ship in 12.4.3-03526 and 12.5.0-02952. Qualys customers can detect vulnerable assets via QID 388624.

Qualys ThreatPROTECT · 13d agoExploit / PoC in the wildCVE-2026-83548CVE-2026-83549

SonicWall's SMA1000 boxes under active attack again

SonicWall warns attackers are chaining two SMA1000 zero-days, a CVSS 10.0 SSRF and command injection, to compromise VPN gateways.

SonicWall says attackers are actively exploiting two chained zero-days in SMA 1000 appliances: CVE-2026-83548, a pre-authentication SSRF rated CVSS 10.0, and CVE-2026-83549, a post-authentication OS command injection (CVSS 7.8) in the Appliance Management Console. Hotfixes are available for SMA 6210, 7210, and 8200v appliances with no workarounds; SonicWall recommends reimaging compromised devices, rotating passwords, and resetting TOTP tokens. NHS England assesses further exploitation as almost certain, following a similar exploited pair in July when CISA added CVE-2026-15409 to its KEV catalog.

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

SonicWall patches two actively exploited zero-days (CVE-2026-83548, CVE-2026-83549) in SMA 1000 VPN appliances, likely chained for code execution.

SonicWall fixed CVE-2026-83548 (CVSS 10.0), a pre-authentication SSRF in the Appliance Work Place interface, and CVE-2026-83549 (CVSS 7.8), a post-authentication OS command injection in the Appliance Management Console. The company investigated a case indicating active exploitation, suggesting attackers chained both bugs to execute arbitrary code on susceptible devices. Affected SMA 1000 models 6210, 7210, and 8200v require hotfixes 12.4.3-03526 or 12.5.0-02952; customers are urged to hunt for IoCs and re-image, reset credentials, and rotate TOTP if found.

The Hacker News · 15d agoExploit / PoC in the wildCVE-2026-83548CVE-2026-83549CVE-2026-15409+1 CVEs

CVE-2026-81578 + CVE-2026-82078 | PaperCut NG/MF Authentication Bypass and Unsafe Dynamic Class Loading Vulnerabilities

Two chained PaperCut NG/MF flaws, CVE-2026-81578 and CVE-2026-82078, enable pre-auth RCE, with active exploitation confirmed in customer environments.

PaperCut NG/MF is affected by CVE-2026-81578, an improper access control flaw (CVSS 4.0 8.8) allowing unauthenticated configuration changes, and CVE-2026-82078, an unsafe dynamic class loading flaw (CVSS 4.0 9.4) enabling arbitrary Java bytecode execution. Chained, they yield pre-authentication remote code execution on the PaperCut Application Server. PaperCut confirmed active exploitation and customer incidents, and Huntress observed exploitation starting August 26, 2026. Emergency Patch Release 2 is available for NG/MF v24-v26, with IOCs including suspicious pc-app.exe child processes, truncated server.log files, and AnyDesk installs.

Horizon3.ai · 15d agoExploit / PoC in the wildCVE-2026-81578CVE-2026-820781

Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data

CISA added actively exploited Oracle WebLogic flaw CVE-2026-21962 (CVSS 10.0) to its KEV catalog, letting unauthenticated attackers access or modify critical data.

CISA added CVE-2026-21962, a CVSS 10.0 improper access control flaw in Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in, to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. Oracle shipped patches in January 2026, and GreyNoise, CloudSEK, and SOCRadar have since reported exploitation attempts, including a lone IP scanning multiple WebLogic, Ivanti, GNU InetUtils, and GLPI vulnerabilities. The flaw is also among several exploited by a China-linked actor delivering the SNOWLIGHT downloader to government and commercial infrastructure in more than 100 countries. Federal civilian agencies must apply fixes by August 27, 2026 under BOD 26-04.

The Hacker News · 22d agoExploit / PoC in the wildCVE-2026-21962CVE-2020-14882CVE-2020-14883+2 CVEs1