Supply Chain Artifactory DevOps

JFrog Artifactory Under Attack: Unauthenticated Admin in Two HTTP Requests, Groovy Backdoors Survive the Patch

Wiz confirmed in-the-wild chaining of CVE-2026-42018, CVE-2026-42016, and CVE-2026-82329 against self-hosted Artifactory. Patching is not eviction — hunt plugins, admin accounts, and Access signing keys.

Cisco ISE Zero-Day

Cisco ISE CVE-2026-76460: CVSS 10.0 Auth Bypass Under Active Attack Gives Unauthenticated Root

Cisco disclosed CVE-2026-76460, a perfect-10 Identity Services Engine authentication bypass under active exploitation that lets an unauthenticated attacker reach root on ISE and ISE-PIC.

Web Hosting cPanel Backup

Acronis Backup CVE-2026-87886: Insecure Permissions on cPanel/Plesk Plugins Exploited for Root, Now in CISA KEV

CISA added CVE-2026-87886 on September 16. Acronis Backup plugins for cPanel/WHM and Plesk ship with incorrect file permissions that a local user can turn into root; Acronis reports limited targeted exploitation.

VMware vCenter Ransomware

CISA: VMware vCenter CVE-2026-59310 Is Now a Ransomware Bug — Unauthenticated Root via Syslog Traversal

CISA updated KEV over the weekend of 13–14 September to mark CVE-2026-59310 as ransomware-abused. The July vCenter Syslog directory traversal is unauthenticated RCE; assume compromise on any box that was reachable before you patched.

Cisco Email Security SQL Injection

Cisco Secure Email Gateway CVE-2026-76461: A Malicious Email Is Enough for Unauthenticated Root

CVE-2026-76461 is an actively exploited SQL injection in Cisco AsyncOS email parsing that turns a crafted message into root on Secure Email Gateway, with no login required.

ScreenConnect RMM CISA KEV

ScreenConnect CVE-2026-84869: Guest File Transfer Without Host Consent, Worm-Like VBS Spread, CISA KEV

CVE-2026-84869 (CVSS 9.9) lets files move and execute through an active ScreenConnect session without Host confirmation. Huntress saw worm-like VBS propagation; CISA added it to KEV on September 11.

GitLab DevOps CISA KEV

GitLab CVE-2026-85706: Unauthenticated File Read on the Commits API, CVSS 10.0, Already in CISA KEV

CVE-2026-85706 is a CVSS 10.0 unauthenticated arbitrary-file-read in GitLab CE/EE's repository commits API. CISA added it to KEV on September 11 — patch, hunt, then rotate what the GitLab process could see.

PaperCut Remote Code Execution CISA KEV

PaperCut NG/MF CVE-2026-81578 and CVE-2026-82078: Chained Pre-Auth RCE, Three Emergency Patches, CISA KEV

PaperCut confirmed zero-day exploitation of an auth bypass (CVE-2026-81578) chained with unsafe class loading (CVE-2026-82078). Skip leftover emergency builds — install 24.1.10, 25.0.13, or 26.0.5.

Citrix NetScaler Remote Code Execution

Citrix Called CVE-2026-8452 a DoS. watchTowr Got Root. CISA Gave Feds Until Saturday.

CVE-2026-8452 is a pre-auth heap overflow in NetScaler SAML handling. Citrix labelled it denial of service. watchTowr showed unauthenticated root. CISA added it to KEV on August 26 with a three-day deadline.

Zimbra Command Injection Email

Zimbra CVE-2026-73570: Unauthenticated SNMP Command Injection to the zimbra User, Exploited and on KEV

CVE-2026-73570 is OS command injection in Zimbra's SNMP/swatchdog path when zimbra-snmp and snmp_notify are on. CERT Polska saw exploitation; CISA added it to KEV on August 21. Upgrade to 10.1.20+.

ICS OT Security Siemens

NSA/CISA AA26-231A: Attackers Are Using AI-Written snap7 Scripts Against Internet-Exposed Siemens S7 PLCs

Joint advisory AA26-231A warns that actors are scanning for Siemens S7 PLCs and using AI-generated python-snap7 tools over S7comm/TCP 102. Inventory, un-expose port 102, patch, and hunt — this is not theoretical.

Windows VPN IPsec

CVE-2026-33824: Unauthenticated Windows IKE RCE on UDP 500/4500 Is Now Exploited — Four Months After the Patch

CISA added CVE-2026-33824 to KEV on August 18. A double-free in Windows IKE extensions lets anyone who can reach UDP 500 or 4500 run code with no login. Microsoft patched it in April.

Microsoft Zero-Day Lazarus

CVE-2026-68820: Lazarus Used a Windows afd.sys Zero-Day for Five Weeks to Drop FudModule

August Patch Tuesday's only in-the-wild bug is CVE-2026-68820, a use-after-free in afd.sys. Check Point tied it to Lazarus Operation Dream Job and the FudModule rootkit. CISA added it to KEV the same day.

Fortinet Ransomware CISA

Gunra Ransomware Is Walking In Through Old FortiOS Auth Bypasses — CISA/FBI/NSA Joint Alert

August's Gunra advisory says the RaaS crew still uses CVE-2024-55591 and CVE-2025-24472 for super-admin on FortiOS/FortiProxy, then MFA-bypass on VDI. If you never left 7.0.16, you are the initial-access path.

Cisco Firewall VPN

Cisco ASA/FTD CVE-2026-20349: Unauthenticated SSL VPN HTTP Request Reloads the Firewall — Exploited in August

CVE-2026-20349 lets anyone who can hit the Remote Access SSL VPN send a crafted HTTP request and reload ASA/FTD. No workaround. Cisco PSIRT confirmed exploitation in August; CISA added it to KEV the same week.

Metabase SQL Injection CISA KEV

Metabase CVE-2026-72898: CVSS 10.0 SQLi on /api/session/reset_password Gave Attackers Admin — Including Metabase Cloud

Metabase's own cloud was hit by a zero-day SQLi on the password-reset API. CVE-2026-72898 is unauthenticated admin. Upgrade to 0.58.24 / 0.59.21 / 0.60.17 / 0.61.11 / 0.62.9 / 0.63.5 (or 1.x twins), then truncate core_session.

N-able RMM MSP

N-able N-central CVE-2026-18577: Incomplete Auth Fix Gave Attackers God Mode Over MSP Consoles

CVE-2026-18577 is the leftover authentication bypass after N-able's first N-central fix. CISA gave federal agencies three days. Unauthenticated admin on the console is admin on every managed endpoint.

Data Breach Cybersecurity Vendors Supply Chain

Trellix Source Code Breach: RansomHouse Claims April 17 Intrusion, Vendor Confirms Repo Access

Ransomware Web Hosting Threat Intelligence

Sorry Ransomware Sweeps cPanel Hosts: 7,135 Servers Encrypted, Censys Says cPanel Is 80% of New Malicious IPs Today

Data Breach Education Ransomware

ShinyHunters Sets May 12 Deadline for Canvas / Instructure: 8,809 Schools, 275M Records, Per-School Ransom Demands

File Transfer Vulnerability Disclosure Enterprise

MOVEit Automation CVE-2026-4670: Unauthenticated Auth Bypass on the MFT Engine 1,400+ Customers Run

Web Hosting Vulnerability Disclosure Supply Chain

cPanel CVE-2026-41940: 64-Day Zero-Day, 44,000 Compromised IPs, and a Targeted Run at Southeast Asian Defence and MSPs

Apache Web Servers Vulnerability Disclosure

Apache HTTP Server 2.4.66 HTTP/2 Double-Free (CVE-2026-23918): A Single-Version Bug With RCE Potential

LLM Security SQL Injection Vulnerability Disclosure

LiteLLM CVE-2026-42208: Pre-Auth SQL Injection in the AI Gateway, Targeted Exploitation Within 36 Hours

Machine Learning Robotics Vulnerability Disclosure

Hugging Face LeRobot CVE-2026-25874: Unauthenticated Pickle RCE Over gRPC, Still Unpatched

GitHub DevOps Vulnerability Disclosure

One git push, Full Server: CVE-2026-3854 Let Anyone with Push Access RCE GitHub.com and Enterprise Server

APT DevOps Security Supply Chain

Tropic Trooper Turns VS Code Tunnels and GitHub Issues into a Stealth C2, Plants Trojanized SumatraPDF on Devs

Windows Privilege Escalation Vulnerability Research

PhantomRPC: Architectural Flaw in Windows RPC Lets Any Service Account Reach SYSTEM, and Microsoft Will Not Patch It

WordPress Vulnerabilities File Upload

Ninja Forms File Upload CVE-2026-0740 (CVSS 9.8) — 50,000 WordPress Sites Under Active Webshell Attack

ICS OT Security Modbus

Global Modbus/TCP Scanning Campaign Hits 14,426 Internet-Exposed PLCs in 70 Countries — Including Active Write Attempts

Identity Vishing Okta

ADT Confirms Breach: One Vishing Call → Okta SSO → 10M Salesforce Records — The ShinyHunters Playbook in Action

APT China Mongolia

GopherWhisper: China-Aligned APT Uses Slack, Discord, and Microsoft 365 Outlook as Command-and-Control

CISA KEV Vulnerabilities SimpleHelp

CISA Adds 4 Actively Exploited Flaws to KEV: SimpleHelp, Samsung MagicINFO, D-Link DIR-823X — May 8 Federal Deadline

AI Security SSRF LLM

LMDeploy SSRF (CVE-2026-33626) Weaponized Within 13 Hours of Disclosure — Your AI Inference Box Is a Metadata-API Probe

Cisco APT Firewall

FIRESTARTER: APT Backdoor on Cisco ASA/Firepower Devices Survives Patching — Federal Agency Confirmed Compromised

CrowdStrike Tenable SIEM

Your Security Tools Are the Vulnerability: Critical CrowdStrike LogScale (CVE-2026-40050) and High-Severity Tenable Nessus (CVE-2026-33694) Patches

Microsoft Defender Zero-Day Privilege Escalation

Defender BlueHammer (CVE-2026-33825) Now Actively Exploited — CISA KEV Deadline May 6

Supply Chain npm Bitwarden

Bitwarden CLI Backdoored in Ongoing TeamPCP Campaign — Shai-Hulud: The Third Coming

Supply Chain Docker DevSecOps

Checkmarx KICS Docker Hub and VS Code Extensions Poisoned in Fresh Supply Chain Attack

Supply Chain npm Developer Security

CanisterWorm: A Self-Propagating npm Worm Is Stealing Developer Tokens and Spreading Autonomously

ASP.NET Core Microsoft Cryptography

ASP.NET Core CVE-2026-40372: Out-of-Band Patch for Critical Cookie Forgery Flaw — Rotate Your Data Protection Keys

AI Security Prompt Injection IDE Security

Google Antigravity IDE: Prompt Injection Through find_by_name Turns File Search Into Full RCE

Supply Chain OAuth Data Breach

Vercel Breach Traced to Context.ai Supply Chain Compromise — Rotate Your Environment Variables Now

AI Security Remote Code Execution MLOps

SGLang CVE-2026-5760: A Malicious AI Model File Is Enough to Get RCE on Your Inference Server

ICS OT Security Healthcare

BRIDGE:BREAK — 20 New Vulnerabilities in Lantronix and Silex Serial-to-IP Converters Threaten OT and Hospital Networks

AI Security MCP Supply Chain

Anthropic's MCP Has a By-Design RCE Flaw Affecting 200,000 Servers — and Anthropic Won't Fix It

Patch Tuesday Microsoft Zero-Day

Microsoft's Massive April 2026 Patch Tuesday Fixes 167 Flaws Including Exploited SharePoint Zero-Day

ICS OT Security Patch Tuesday

ICS Patch Tuesday: Siemens, Schneider Electric, Rockwell and Five More Vendors Ship Critical Fixes

Active Exploitation Remote Code Execution Self-Hosted Tools

ShowDoc RCE Flaw CVE-2025-0520 Is Being Actively Exploited — Over 2,000 Servers Exposed

Supply Chain PHP Composer

PHP Composer Patches Two Command Injection Flaws in Perforce VCS Driver — Update to 2.9.6 Now

Supply Chain OpenAI Code Signing

OpenAI Revokes macOS Code Signing Certificate After North Korea-Linked Axios Supply Chain Attack

Android Malware RAT Residential Proxy

Mirax Android RAT Converts Infected Phones into Residential Proxies After Spreading via Meta Ads

CISA Vulnerability Patching

CISA Orders Federal Agencies to Patch 6 Actively Exploited Flaws in Fortinet, Microsoft, and Adobe

Browser Security Chrome Extensions Data Theft

108 Malicious Chrome Extensions Caught Stealing Google Tokens and Telegram Sessions

Chrome Session Security Cookie Theft

Google Chrome Now Makes Stolen Session Cookies Useless With Device Bound Session Credentials

Zero-Day Windows Privilege Escalation

Unpatched 'BlueHammer' Windows Zero-Day Lets Local Users Escalate to Admin — PoC Is Public

Supply Chain Malware Watering Hole

CPUID Website Breached — Trojanized CPU-Z and HWMonitor Downloads Delivered STX RAT for Six Hours

Zero-Day Adobe Reader Patching

Adobe Ships Emergency Patch for Acrobat Reader Zero-Day That Was Exploited for Five Months

WordPress Supply Chain Backdoor

Attackers Hijacked Smart Slider 3 Pro's Update Server to Push a Backdoor to 800,000 WordPress Sites

Vulnerability Python Remote Code Execution

Critical Marimo Python Notebook Flaw Exploited in Under 10 Hours After Public Disclosure

Patching Firewall Palo Alto Networks

Palo Alto Networks and SonicWall Release Patches for High-Severity Firewall and VPN Vulnerabilities

Zero-Day Adobe Reader Vulnerability

Adobe Reader Zero-Day Has Been Exploited Through Malicious PDFs Since Late 2025

OpenSSL Vulnerability Patching

OpenSSL Patches Seven Vulnerabilities Including a Data Leakage Flaw in RSASVE Key Encapsulation

Docker DevOps Vulnerability

Critical Docker Engine Flaw Lets Attackers Bypass Authorization Plugins and Access the Host

Phishing OAuth Microsoft 365

Device Code Phishing Attacks Have Surged 37x — Here's How to Stop Them

Linux Security PHP

How Attackers Are Hiding PHP Web Shells Inside HTTP Cookies on Linux Servers

Microsoft's Defender team uncovered a growing technique where attackers use HTTP cookies as a hidden command channel for PHP web shells — making them far harder to detect than traditional approaches.

Supply Chain DevOps AWS

How a Poisoned Trivy Update Gave Hackers the Keys to the European Commission's AWS

A supply chain attack against Trivy resulted in the European Commission losing 340 GB of data from its AWS environment — showing how dangerous a single compromised tool in a pipeline can be.

Vulnerability ShareFile Remote Code Execution

Critical ShareFile Vulnerabilities Allow Full RCE Without a Password — Patch Now

Two chained vulnerabilities in Progress ShareFile's Storage Zones Controller allow an unauthenticated attacker to go from zero access to full remote code execution on the server — no credentials needed.