Archive
All articles, newest first. Page 5.

FortiSandbox Command Injection Grants Root RCE: Why the CVSS 6.7 Underrates the Risk
Trend Micro's Zero Day Initiative published advisory ZDI-26-645 detailing a command injection flaw in Fortinet FortiSandbox. The vulne…

Cisco Confirms CVE-2026-20079 in FMC Actively Exploited by Sandworm and Qilin
Cisco confirms active exploitation of CVE-2026-20079 in Secure Firewall Management Center. Two distinct threat clusters — APT Sandworm…

BlueMoon: The Shared Exploit Kit Accelerating the Race for Chrome Vulnerabilities
BlueMoon enabled four cyber-espionage groups to exploit the same Chrome zero-day through a roughly four-week patch-gap window, marking…

FTC Rescinds Health App Breach Policy: The Signal Is Political
The Federal Trade Commission has revoked its 2021 policy statement extending the Health Breach Notification Rule to health apps and co…

AMD, Arm, and Nvidia: September 9 Patches for GPU and AI Inference Vulnerabilities
On September 9, 2026, three chipmakers released coordinated security advisories: flawed GPU drivers and bugs in Nvidia's Triton Infere…

ShieldCrash: The Eleventh Microsoft Zero-Day That Renders the ShieldBreak Patch Useless
Nightmare Eclipse has released ShieldCrash, a new exploit that bypasses Microsoft's patch for ShieldBreak (CVE-2026-69414) in Microsof…

LiteLLM: 9.6% of Exposed Instances Vulnerable to Auth Bypass and RCE
CISA adds CVE-2026-59822 to KEV catalog: roughly 9.6% of public LiteLLM instances accept default master key or no authentication, with…

Veradigm: Vendor API Breach Exposes Millions of Patient Records
Veradigm disclosed a patient data breach caused by a compromised vendor API. The Gentlemen ransomware gang claims 3.5 million records,…

Gigabud Moves Banking Theft Into Work Profile: The Malware That Fools Fraud Detection
The GoldFactory group has weaponized a fork of the open-source Shelter app, dubbed Vwork, to clone banking apps inside hidden Android…

The Malware Marketplace That Weaponizes Banality to Evade SOCs
The CL-CRI-1171 cluster has operated for two years as a pay-per-install marketplace. Its deliberately generic loader flies under SOC r…

Hidden Pay-Per-Install Market: The CL-CRI-1171 Operation That Evaded SOCs for Two Years
Unit 42 has documented a pay-per-install marketplace operational since at least 2024. Tracked as CL-CRI-1171, the cluster distributed…

Adobe Patches StyleSmuggler: Actively Exploited Magento Zero-Day with CVSS 10.0
On September 9, 2026, Adobe released a security update for CVE-2026-75650, a zero-day vulnerability in Magento's template engine carry…

Your BAS Program Is Already Obsolete: When the Attack Changes Every 10 Hours
The median time from CVE disclosure to weaponized exploit has collapsed to roughly 10 hours in 2026. Blue Report 2026 data across 338…

BAS at Machine Speed: The Structural Collapse of Disclosure-to-Exploit
The window from disclosure to weaponized exploit has collapsed to roughly 10 hours. Defensive controls stop 69% of attacks, but only 1…

ZDI-26-617: Windows MIDI Service Becomes LPE Path to SYSTEM, Patch Released
On September 9, 2026, the Zero Day Initiative published advisory ZDI-26-617, documenting a vulnerability in Microsoft's Windows MIDI S…

OpenAI's Internal Package Manager Became a Covert Data-Theft Channel
Check Point Research uncovered a cross-account covert channel in OpenAI's internal JFrog Artifactory instance. Reader credentials perm…

CVE-2026-19780: RCE in Koha Puts Library Management Systems at Risk
An eval code injection flaw in the open-source Koha library system enables authenticated remote code execution. CVSS 8.8, patched acro…

CVE-2026-50696: ZDI and Microsoft Split on Windows IKEv2 Severity
ZDI rates it RCE SYSTEM; Microsoft calls it DoS Important. The CVE-2026-50696 discrepancy upends patch prioritization for security tea…

Record-Breaking Patch Tuesday: Microsoft Fixes 974 CVEs, Two Zero-Days Under Active Attack
Microsoft addressed a historic 974 vulnerabilities in September 2026. Two actively exploited zero-days enabling local privilege escala…

ShinyHunters Claims Florida DMV Breach, 200,000 Driver Records at Risk
ShinyHunters claims to have breached the Florida DMV's DAVID platform, threatening to release over 200,000 driver records. The group's…

SAP Patches OVERPASS: Maximum-Severity Kernel Bug Opens ERP Systems to Unauthenticated RCE
SAP released the September 2026 patch for CVE-2026-44756, a maximum-severity kernel vulnerability that allows unauthenticated remote c…

ChatGPT's Isolated Containers Could Talk: Cross-Account Data Exfiltration
Check Point Research demonstrated a covert data-exfiltration channel between code-execution sandboxes belonging to different ChatGPT a…

npm: Known Worm Evades Registry Malware Scanning After 111-Day Dormancy
The Shai-Hulud npm worm resurfaced on September 7, 2026 with the identical SHA-256 hash documented four months earlier, bypassing the…

BengalSEO Poisons Bing to Deliver Malware and Tech Support Scams Since 2015
The BengalSEO cybercrime group, operating from Rajasthan, India since at least 2015, systematically manipulates Bing search results th…