FR
live
section

Security

Ransomware gangs now exploit the unauthenticated IKEv2 RCE in WatchGuard Firebox firewalls

CISA updated its KEV entry on September 10, 2026 to confirm that CVE-2025-14733, an unauthenticated RCE in the WatchGuard Firebox iked process patched back in December 2025, is now used in ransomware attacks. With nearly 9,000 Fireboxes still exposed online, check your Fireware OS version and hunt for the indicators of compromise before the encryption starts.

Passkey-themed phishing drains corporate Microsoft 365 accounts

Microsoft documents attacks in which ShinyHunters and Helix-linked gangs impersonate the help desk to steer employees toward passkey-themed phishing pages, then exfiltrate Microsoft 365 data. The defense rests less on the passkey itself than on phishing-resistant authentication and session revocation.

PivotC2 RAT exploits CVE-2025-25249, a Fortinet heap overflow patched since January

Patched in January 2026, the CVE-2025-25249 heap overflow in the FortiOS cw_acd daemon has resurfaced exploited in the wild: CISA added it to the KEV catalog on September 9, 2026, after SOCRadar observed the PivotC2 RAT deployed on 178 devices. Network teams must upgrade exposed FortiOS trains before September 12, then strip out unnecessary fabric access.

ShieldCrash bypasses Microsoft Defender’s ShieldBreak fix to read files as SYSTEM

On September 9, 2026, researcher Chaotic Eclipse published ShieldCrash, a proof of concept that bypasses CVE-2026-69414 (ShieldBreak), the privilege-escalation flaw Microsoft claimed to have patched in Defender’s antimalware engine. Check your Malware Protection Engine version and treat the EDR itself as attack surface to monitor.

SAP patches OVERPASS and S4GET, two pre-auth flaws that run code on the SAP kernel

On September 9, 2026, SAP shipped fixes for four critical flaws, including CVE-2026-44756 (CVSS 10.0), a memory-corruption bug in Extended Passport processing that yields unauthenticated remote code execution across three protocols at once. Basis teams should patch the SAP kernel first, ahead of any network segmentation effort.

A Lenovo email-verification flaw opened 5,000 Dropbox accounts without a password

On September 2, 2026, Dropbox disclosed that an attacker accessed roughly 5,000 accounts by abusing a flaw in Lenovo’s email-verification process to register fraudulent Lenovo IDs — never needing the victim’s Dropbox password. Audit every identity-federation link you accept and require re-authentication on SSO sign-ins.

JSCeal Bypasses Google Authentication with Stolen Session Cookies

Check Point unpacks JSCeal, a compiled V8 JavaScript malware that replays stolen session cookies to open access to Google accounts without a password or second factor. Lock down sessions with security keys and device-bound credentials, and watch for cookie exfiltration.

A capture-replay auth bypass leaves 22,000 Exchange servers exposed

Disclosed on August 11, 2026, CVE-2026-62911 lets an attacker with some access replay a captured authentication to elevate privileges on Microsoft Exchange, and a public PoC is already circulating. Nearly 22,000 servers were still exposed at the end of August; if you are on Exchange 2016 without ESU, the fix is not an option — migration is.

A CVSS 10 flaw turns Kestra into an unauthenticated root shell

On September 2, 2026, CISA added CVE-2026-49869 to its KEV catalog: a CVSS 10 command injection in the open-source orchestrator Kestra, caused by a path comparison that lets any endpoint ending in ’configs’ through. Move to 1.0.45 or 1.3.21 before the September 5 federal deadline, then check whether the instance was already used as an entry point.

Chrome patches its sixth exploited zero-day of 2026, a V8 type confusion

On September 4, 2026, Google shipped an emergency Chrome update fixing CVE-2026-85046, a type confusion in the V8 engine already exploited in the wild and rated 8.8 on the CVSS scale. Update to Chrome 152.0.7977.82 or later and check every Chromium browser in your fleet, including Edge, Brave and Opera.

A poisoned .git/config runs code when Claude Code, Codex or Cursor opens a repository

Manifold Security disclosed on 2 September 2026 eight flaws across seven CLI coding agents: a repository delivered as an archive can trigger a local command on open, outside the sandbox and without approval, via Git’s core.fsmonitor setting. Disable core.fsmonitor by default and inspect .git/config before opening a received folder with an agent.

Attackers exploit CVE-2026-0768 in Langflow to siphon OpenAI and AWS keys

On September 1, 2026, VulnCheck observed mass exploitation of CVE-2026-0768, an unauthenticated remote code execution flaw in Langflow, used to harvest OpenAI and AWS keys from exposed instances. It is the sixth Langflow flaw exploited since January: any instance patched below 1.11.6 must be treated as compromised.

Two chained zero-days yield unauthenticated RCE on SonicWall SMA 1000 appliances

On September 1, 2026, SonicWall disclosed two flaws in the SMA 1000 line — a pre-authentication SSRF (CVE-2026-83548, CVSS 10) and an OS command injection (CVE-2026-83549) — already chained in the wild to reach remote code execution without credentials. Apply the hotfix now, and if compromise is confirmed, re-image the appliance instead of patching over the intrusion.

Fire Ant turns Cisco routers into covert spying platforms with invisible GRE tunnels

On August 31, 2026, Sygnia documented how the Chinese espionage group Fire Ant, which heavily overlaps UNC3886, pivoted from VMware hypervisors to Cisco IOS XR routers to intercept the traffic passing through them. An active GRE tunnel missing from the running config is enough to turn a transit router into a collection platform — and it means defenders must audit routers as vantage points, not as mere hops.

Gitoxide patches five parsing flaws that leak credentials and traverse directories

On August 30, 2026, the gitoxide project — the pure-Rust implementation of Git — shipped a bundled fix for five parsing vulnerabilities, including an HTTP credential leak and several submodule-based path traversals. The lesson for anyone pulling Rust libraries: memory safety is no substitute for input validation.

CVE-2026-8452, patched in June as a DoS, is an exploited pre-auth RCE on Citrix NetScaler

On 30 June 2026, Citrix rated CVE-2026-8452 as a memory overflow. On 14 August, WatchTowr showed it leads to pre-authentication code execution, and on 26 August CISA added it to the KEV catalog with a 29 August deadline. Appliances configured as VPN or AAA servers must be patched today, without waiting for official confirmation of exploitation.

CVE-2026-59310 turns VMware vCenter into a Babuk ransomware launchpad

A path-traversal flaw in VMware vCenter, rated CVSS 9.8, allows unauthenticated code execution and is already being exploited across 47 countries to drop Babuk-derived ransomware. The fix is two moves: patch without waiting for a maintenance window, and cut the management interface off from the rest of the network.

A 2023 ownCloud flaw resurfaces and opens files with no credentials at all

CVE-2023-49105, a WebDAV authentication flaw rated CVSS 9.8 and fixed by ownCloud in late 2023, is now being actively exploited — CISA added it to the KEV catalog on 27 August 2026. Inventory your exposed ownCloud 10.x instances, move to 10.13.1 or later, and treat them as possible compromises.

AiLock claims Hamilton Company and threatens to report the breach to regulators

On August 26, 2026, the AiLock ransomware group added Hamilton Company, a US laboratory-robotics specialist, to its leak site, threatening to publish the data unless negotiations begin. The detail that sets AiLock apart: its double extortion threatens to report the breach to regulators and share stolen data with competitors — pressure that changes the victim’s calculus.

One operator breached 14,530 Dahua cameras in 35 days — 89% without a password

Between June 17 and July 22, 2026, a single operator compromised more than 14,530 Dahua cameras by chaining brute force, a 2021 flaw and the vendor’s P2P relay — 89% of them with no authentication at all. Hunt.io’s investigation reveals a hard truth: connected video surveillance is an open door by design.

A WebLogic proxy plug-in patched in January is now under active exploitation

CVE-2026-21962, a CVSS 10.0 access-control flaw in Oracle’s WebLogic Server proxy plug-in that was fixed in the January 2026 CPU, landed in CISA’s KEV catalog on August 24 with confirmed active exploitation. Apply the January patch before August 27 and inventory your middleware tier, which vulnerability scans too often miss.

Trojanized npm packages ship RedC2 4.0, a Linux backdoor with an AI-assisted C2

On August 20, 2026, Trend Micro disclosed fourteen functional npm packages that drop RedShell, the Linux beacon of the RedC2 4.0 C2 framework, with no install hook and no exported function call. Audit your transitive dependencies and recent package additions before a single import compromises your servers.

Citrix NetScaler patches a critical remote authentication bypass (CVSS 9.3) exploitable without credentials

On August 19, 2026, Cloud Software Group published a bulletin for NetScaler ADC and NetScaler Gateway: CVE-2026-19490, a CVSS 9.3 authentication bypass exploitable remotely without credentials, and CVE-2026-19489, an 8.8 denial-of-service. Any internet-facing appliance needs an emergency upgrade, after triage driven by the SAML or vserver configuration.

Medusa ransomware tops 500 critical infrastructure victims, CISA warns

On August 18, 2026, the FBI, CISA and HHS updated their joint advisory on the Medusa ransomware: more than 500 critical infrastructure victims since 2021, up from 300 in March 2025. Defenders need to patch the exploited flaws and segment networks before the gang does it for them.

Password spraying surges 155× in 2026 by slipping through MFA blind spots

Huntress measured a 155× increase in password spraying attacks in the first half of 2026, driven by an LSHIY campaign that generated 81 million login attempts in two weeks through the ROPC flow. Security teams must disable ROPC and extend MFA to every authentication flow, with no exceptions.

Fortinet patches authentication bypasses in FortiWeb and FortiManager

On August 13, 2026 Fortinet shipped eight fixes, including a FortiWeb authentication bypass that lets an attacker log in with random credentials and a FortiManager flaw that allows impersonating a FortiGate. Teams running a firewall fleet should treat these two as top-priority patches.

Clop steals engineering data from Shell, GE and Philips through PTC Windchill

On August 14, 2026 Shell confirmed it is investigating a breach after Clop claimed it stole 89GB of data, including engineering drawings, through CVE-2026-12569 in PTC Windchill and FlexPLM. Exposed PLM teams need to check their instances and hunt for the JSP webshells dropped into the login directory.

Metabase Zero-Day CVSS 10.0 Grants Full Admin Access Without Authentication

On August 8, 2026, Metabase disclosed a maximum-severity SQL injection flaw (CVSS 10.0) that was already being exploited in the wild. The vulnerability lets unauthenticated attackers gain administrator privileges and drain every connected database. Self-hosted Metabase admins must patch, revoke sessions, and rotate all secrets immediately.

DOUBLECUP turns your browser cache into an arsenal — Russian loader‑as‑a‑service uses steganography to deliver CountLoader and a brand‑new RAT

On August 3, 2026, SOCRadar documented DOUBLECUP, a Russian loader-as-a-service active since June 2026 that hides malicious code in browser‑cached PNG images. The ClickFix chain delivers CountLoader to Windows and macOS alongside a previously undocumented DeviceManager RAT steered by smart contracts.

The Cyber Resilience Act Takes Effect — Every Software Dependency Must Be Documented, Signed, and Traceable Within 36 Months

EU Regulation 2024/2847, the Cyber Resilience Act, enters phased application starting in 2026. It requires every software vendor selling in the EU to produce a complete SBOM, fix known vulnerabilities within five business days, and notify critical incidents to ENISA within 24 hours. Here's what your organization must do before the first binding deadline.

A silent AI worm spreads through Copilot for Word — and Microsoft can’t patch it

On July 28, 2026, researcher Håkon Måløy published the first public demonstration of a document-borne AI worm capable of silently altering financial reports and self-propagating through Microsoft Copilot for Word. After 144 days of coordinated disclosure and two attempted fixes — including a model upgrade to GPT-5.6 — the vulnerability class remains exploitable.

API attacks became the number one data breach vector in 2026

99% of organizations experienced an API security incident in 2025. APIs now account for 43% of actively exploited vulnerabilities in CISA’s KEV catalog. Your API gateway is your new firewall — and you probably haven’t configured it.

June 2026 Was the Month Cybersecurity Broke Its Own Scale

Microsoft shipped its largest-ever Patch Tuesday, 24 billion stolen credentials surfaced on an exposed Elasticsearch cluster, and ransomware gangs claimed 721 new victims. Three records, one month — and none of them are a coincidence.

May 2026’s data breaches didn’t make headlines — and that’s the real problem

Mediaworks lost 8.5 TB of internal data to a ransomware group. Instructure paid ShinyHunters to keep 3.65 TB of Canvas data off the dark web. Across two weeks in May 2026, a cascade of breaches hit education, manufacturing, media, and retail — and barely anyone noticed. When breaches become background noise, the threat isn’t technical anymore. It’s apathy.

Ransomware Surges 48% in May 2026 as Global Attacks Decline

Check Point Research records 698 ransomware attacks worldwide in May 2026, a 48% year-over-year jump, even as overall attack volumes drop 7%. Fewer attacks, more impact — threat actors are getting better at doing more with less.

BreachForums Hacked — 325,000 Cybercriminal Accounts Exposed

On January 10, 2026, the BreachForums cybercrime bazaar suffered its own data breach: 324,000 user accounts with IP addresses, display names, and the forum’s official PGP key were published online. The leak is a goldmine for law enforcement and an operational catastrophe for members whose anonymity collapsed overnight.

AI-assisted cyberattacks now breach systems in 72 minutes

Attackers are deploying AI agents to automate reconnaissance, phishing, and exfiltration, compressing the breach-to-theft window to 72 minutes in the fastest observed cases. SOC teams that still rely solely on human-first triage are structurally unable to keep up.

Type at least two characters.

navigate open esc dismiss