Articles
68 articles covering security advisories, vulnerabilities, and industry news.
JFrog Artifactory Under Attack: Unauthenticated Admin in Two HTTP Requests, Groovy Backdoors Survive the Patch
Wiz confirmed in-the-wild chaining of CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329 against self-hosted Artifactory. Patching is not eviction — hunt plugins, admin accounts, and Access signing keys.
Cisco ISE CVE-2026-76460: CVSS 10.0 Auth Bypass Under Active Attack Gives Unauthenticated Root
Cisco disclosed CVE-2026-76460, a perfect-10 Identity Services Engine authentication bypass under active exploitation that lets an unauthenticated attacker reach root on ISE and ISE-PIC.
Acronis Backup CVE-2026-87886: Insecure Permissions on cPanel/Plesk Plugins Exploited for Root, Now in CISA KEV
CISA added CVE-2026-87886 on September 16. Acronis Backup plugins for cPanel/WHM and Plesk ship with incorrect file permissions that a local user can turn into root; Acronis reports limited targeted exploitation.
CISA: VMware vCenter CVE-2026-59310 Is Now a Ransomware Bug — Unauthenticated Root via Syslog Traversal
CISA updated KEV over the weekend of 13–14 September to mark CVE-2026-59310 as ransomware-abused. The July vCenter Syslog directory traversal is unauthenticated RCE; assume compromise on any box that was reachable before you patched.
Cisco Secure Email Gateway CVE-2026-76461: A Malicious Email Is Enough for Unauthenticated Root
CVE-2026-76461 is an actively exploited SQL injection in Cisco AsyncOS email parsing that turns a crafted message into root on Secure Email Gateway, with no login required.
ScreenConnect CVE-2026-84869: Guest File Transfer Without Host Consent, Worm-Like VBS Spread, CISA KEV
CVE-2026-84869 (CVSS 9.9) lets files move and execute through an active ScreenConnect session without Host confirmation. Huntress saw worm-like VBS propagation; CISA added it to KEV on September 11.
GitLab CVE-2026-85706: Unauthenticated File Read on the Commits API, CVSS 10.0, Already in CISA KEV
CVE-2026-85706 is a CVSS 10.0 unauthenticated arbitrary-file-read in GitLab CE/EE's repository commits API. CISA added it to KEV on September 11 — patch, hunt, then rotate what the GitLab process could see.
PaperCut NG/MF CVE-2026-81578 and CVE-2026-82078: Chained Pre-Auth RCE, Three Emergency Patches, CISA KEV
PaperCut confirmed zero-day exploitation of an auth bypass (CVE-2026-81578) chained with unsafe class loading (CVE-2026-82078). Skip leftover emergency builds — install 24.1.10, 25.0.13, or 26.0.5.
Citrix Called CVE-2026-8452 a DoS. watchTowr Got Root. CISA Gave Feds Until Saturday.
CVE-2026-8452 is a pre-auth heap overflow in NetScaler SAML handling. Citrix labelled it denial of service. watchTowr showed unauthenticated root. CISA added it to KEV on August 26 with a three-day deadline.
Zimbra CVE-2026-73570: Unauthenticated SNMP Command Injection to the zimbra User, Exploited and on KEV
CVE-2026-73570 is OS command injection in Zimbra's SNMP/swatchdog path when zimbra-snmp and snmp_notify are on. CERT Polska saw exploitation; CISA added it to KEV on August 21. Upgrade to 10.1.20+.
NSA/CISA AA26-231A: Attackers Are Using AI-Written snap7 Scripts Against Internet-Exposed Siemens S7 PLCs
Joint advisory AA26-231A warns that actors are scanning for Siemens S7 PLCs and using AI-generated python-snap7 tools over S7comm/TCP 102. Inventory, un-expose port 102, patch, and hunt — this is not theoretical.
CVE-2026-33824: Unauthenticated Windows IKE RCE on UDP 500/4500 Is Now Exploited — Four Months After the Patch
CISA added CVE-2026-33824 to KEV on August 18. A double-free in Windows IKE extensions lets anyone who can reach UDP 500 or 4500 run code with no login. Microsoft patched it in April.
CVE-2026-68820: Lazarus Used a Windows afd.sys Zero-Day for Five Weeks to Drop FudModule
August Patch Tuesday's only in-the-wild bug is CVE-2026-68820, a use-after-free in afd.sys. Check Point tied it to Lazarus Operation Dream Job and the FudModule rootkit. CISA added it to KEV the same day.
Gunra Ransomware Is Walking In Through Old FortiOS Auth Bypasses — CISA/FBI/NSA Joint Alert
August's Gunra advisory says the RaaS crew still uses CVE-2024-55591 and CVE-2025-24472 for super-admin on FortiOS/FortiProxy, then MFA-bypass on VDI. If you never left 7.0.16, you are the initial-access path.
Cisco ASA/FTD CVE-2026-20349: Unauthenticated SSL VPN HTTP Request Reloads the Firewall — Exploited in August
CVE-2026-20349 lets anyone who can hit the Remote Access SSL VPN send a crafted HTTP request and reload ASA/FTD. No workaround. Cisco PSIRT confirmed exploitation in August; CISA added it to KEV the same week.
Metabase CVE-2026-72898: CVSS 10.0 SQLi on /api/session/reset_password Gave Attackers Admin — Including Metabase Cloud
Metabase's own cloud was hit by a zero-day SQLi on the password-reset API. CVE-2026-72898 is unauthenticated admin. Upgrade to 0.58.24 / 0.59.21 / 0.60.17 / 0.61.11 / 0.62.9 / 0.63.5 (or 1.x twins), then truncate core_session.
N-able N-central CVE-2026-18577: Incomplete Auth Fix Gave Attackers God Mode Over MSP Consoles
CVE-2026-18577 is the leftover authentication bypass after N-able's first N-central fix. CISA gave federal agencies three days. Unauthenticated admin on the console is admin on every managed endpoint.
Trellix Source Code Breach: RansomHouse Claims April 17 Intrusion, Vendor Confirms Repo Access
Sorry Ransomware Sweeps cPanel Hosts: 7,135 Servers Encrypted, Censys Says cPanel Is 80% of New Malicious IPs Today
ShinyHunters Sets May 12 Deadline for Canvas / Instructure: 8,809 Schools, 275M Records, Per-School Ransom Demands
MOVEit Automation CVE-2026-4670: Unauthenticated Auth Bypass on the MFT Engine 1,400+ Customers Run
cPanel CVE-2026-41940: 64-Day Zero-Day, 44,000 Compromised IPs, and a Targeted Run at Southeast Asian Defence and MSPs
Apache HTTP Server 2.4.66 HTTP/2 Double-Free (CVE-2026-23918): A Single-Version Bug With RCE Potential
LiteLLM CVE-2026-42208: Pre-Auth SQL Injection in the AI Gateway, Targeted Exploitation Within 36 Hours
Hugging Face LeRobot CVE-2026-25874: Unauthenticated Pickle RCE Over gRPC, Still Unpatched
One git push, Full Server: CVE-2026-3854 Let Anyone with Push Access RCE GitHub.com and Enterprise Server
Tropic Trooper Turns VS Code Tunnels and GitHub Issues into a Stealth C2, Plants Trojanized SumatraPDF on Devs
PhantomRPC: Architectural Flaw in Windows RPC Lets Any Service Account Reach SYSTEM, and Microsoft Will Not Patch It
Ninja Forms File Upload CVE-2026-0740 (CVSS 9.8) — 50,000 WordPress Sites Under Active Webshell Attack
Global Modbus/TCP Scanning Campaign Hits 14,426 Internet-Exposed PLCs in 70 Countries — Including Active Write Attempts
ADT Confirms Breach: One Vishing Call → Okta SSO → 10M Salesforce Records — The ShinyHunters Playbook in Action
GopherWhisper: China-Aligned APT Uses Slack, Discord, and Microsoft 365 Outlook as Command-and-Control
CISA Adds 4 Actively Exploited Flaws to KEV: SimpleHelp, Samsung MagicINFO, D-Link DIR-823X — May 8 Federal Deadline
LMDeploy SSRF (CVE-2026-33626) Weaponized Within 13 Hours of Disclosure — Your AI Inference Box Is a Metadata-API Probe
FIRESTARTER: APT Backdoor on Cisco ASA/Firepower Devices Survives Patching — Federal Agency Confirmed Compromised
Your Security Tools Are the Vulnerability: Critical CrowdStrike LogScale (CVE-2026-40050) and High-Severity Tenable Nessus (CVE-2026-33694) Patches
Defender BlueHammer (CVE-2026-33825) Now Actively Exploited — CISA KEV Deadline May 6
Bitwarden CLI Backdoored in Ongoing TeamPCP Campaign — Shai-Hulud: The Third Coming
Checkmarx KICS Docker Hub and VS Code Extensions Poisoned in Fresh Supply Chain Attack
CanisterWorm: A Self-Propagating npm Worm Is Stealing Developer Tokens and Spreading Autonomously
ASP.NET Core CVE-2026-40372: Out-of-Band Patch for Critical Cookie Forgery Flaw — Rotate Your Data Protection Keys
Google Antigravity IDE: Prompt Injection Through find_by_name Turns File Search Into Full RCE
Vercel Breach Traced to Context.ai Supply Chain Compromise — Rotate Your Environment Variables Now
SGLang CVE-2026-5760: A Malicious AI Model File Is Enough to Get RCE on Your Inference Server
BRIDGE:BREAK — 20 New Vulnerabilities in Lantronix and Silex Serial-to-IP Converters Threaten OT and Hospital Networks
Anthropic's MCP Has a By-Design RCE Flaw Affecting 200,000 Servers — and Anthropic Won't Fix It
Microsoft's Massive April 2026 Patch Tuesday Fixes 167 Flaws Including Exploited SharePoint Zero-Day
ICS Patch Tuesday: Siemens, Schneider Electric, Rockwell and Five More Vendors Ship Critical Fixes
ShowDoc RCE Flaw CVE-2025-0520 Is Being Actively Exploited — Over 2,000 Servers Exposed
PHP Composer Patches Two Command Injection Flaws in Perforce VCS Driver — Update to 2.9.6 Now
OpenAI Revokes macOS Code Signing Certificate After North Korea-Linked Axios Supply Chain Attack
Mirax Android RAT Converts Infected Phones into Residential Proxies After Spreading via Meta Ads
CISA Orders Federal Agencies to Patch 6 Actively Exploited Flaws in Fortinet, Microsoft, and Adobe
108 Malicious Chrome Extensions Caught Stealing Google Tokens and Telegram Sessions
Google Chrome Now Makes Stolen Session Cookies Useless With Device Bound Session Credentials
Unpatched 'BlueHammer' Windows Zero-Day Lets Local Users Escalate to Admin — PoC Is Public
CPUID Website Breached — Trojanized CPU-Z and HWMonitor Downloads Delivered STX RAT for Six Hours
Adobe Ships Emergency Patch for Acrobat Reader Zero-Day That Was Exploited for Five Months
Attackers Hijacked Smart Slider 3 Pro's Update Server to Push a Backdoor to 800,000 WordPress Sites
Critical Marimo Python Notebook Flaw Exploited in Under 10 Hours After Public Disclosure
Palo Alto Networks and SonicWall Release Patches for High-Severity Firewall and VPN Vulnerabilities
Adobe Reader Zero-Day Has Been Exploited Through Malicious PDFs Since Late 2025
OpenSSL Patches Seven Vulnerabilities Including a Data Leakage Flaw in RSASVE Key Encapsulation
Critical Docker Engine Flaw Lets Attackers Bypass Authorization Plugins and Access the Host
Device Code Phishing Attacks Have Surged 37x — Here's How to Stop Them
How Attackers Are Hiding PHP Web Shells Inside HTTP Cookies on Linux Servers
Microsoft's Defender team uncovered a growing technique where attackers use HTTP cookies as a hidden command channel for PHP web shells — making them far harder to detect than traditional approaches.
How a Poisoned Trivy Update Gave Hackers the Keys to the European Commission's AWS
A supply chain attack against Trivy resulted in the European Commission losing 340 GB of data from its AWS environment — showing how dangerous a single compromised tool in a pipeline can be.
Critical ShareFile Vulnerabilities Allow Full RCE Without a Password — Patch Now
Two chained vulnerabilities in Progress ShareFile's Storage Zones Controller allow an unauthenticated attacker to go from zero access to full remote code execution on the server — no credentials needed.