Sunday
2026-09-13Your source for daily security alerts from some of the best experts in the world.
Find the problems, secure your systems now!
Get these alerts in your inbox every morning. Subscribe
CONTENTS
MSRC Unclassified ( 53 )
TLDR InfoSec
Hacker News ( 21 )
Check Point Research
Cisco Talos
Bleeping Computer ( 15 )
CISA ( 2 )
Cisco Advisories
DataBreaches.net ( 8 )
Huntress Blog ( 5 )
CVEMon Intruder ( 10 )
Graham Cluley
Hacking Lab ( 3 )
Schneier on Security ( 4 )
Talos – Vulnerability Reports ( 2 )
Troy Hunt
WeLiveSecurity
Zero Day Initiative-Published ( 32 )
MSRC Unclassified
09/11 TOC Mariner – Race condition in V8 in Google Chrome prior to 153.0.8010.36…
09/11 TOC Mariner – Use after free in V8 in Google Chrome prior to 153.0.8010.36…
09/11 TOC Mariner – Use after free in V8 in Google Chrome prior to 153.0.8010.36…
09/11 TOC Mariner – Type confusion in V8 in Google Chrome prior to 153.0.8010.36…
09/11 TOC Mariner – UEFI BIOS embedded Shell can be used to bypass Secure Boot C…
09/11 TOC Mariner – vlan: fix skb_under_panic and races when toggling HW VLAN of…
09/11 TOC Mariner – KVM: s390: vsie: zero stale crypto bits CVE-2026-80921
09/11 TOC Mariner – xhci: dbgtty: Fix unregister on tty_register_driver() failur…
09/11 TOC Mariner – PCI: host-generic: Fix NULL pointer dereference on 32-bit CA…
09/11 TOC Mariner – Bluetooth: ISO: fix use-after-free of listener socket in iso…
09/11 TOC Mariner – io_uring: defer eventfd signaling when queued from a wakeup …
09/11 TOC Mariner – HID: core: fix number/pointer type confusion on long items C…
09/11 TOC Mariner – Apache Ant: Path traversal in ftp and scp tasks allows arbit…
09/11 TOC Mariner – Use after free in V8 in Google Chrome prior to 153.0.8010.36…
09/11 TOC Mariner – Type confusion in V8 in Google Chrome prior to 153.0.8010.36…
09/11 TOC Mariner – Bluetooth: btintel: Validate length before parsing diagnosti…
09/11 TOC Mariner – drm/vmwgfx: use check_add_overflow for shader size+offset bo…
09/11 TOC Mariner – ALSA: usb-audio: fix use-after-free in ump_to_endpoint() CVE…
09/11 TOC Mariner – ipvs: fix the checksum validations CVE-2026-80901
09/11 TOC Mariner – mailbox: mchp-ipc-sbi: Add null check for devm_kasprintf() C…
09/11 TOC Mariner – drm/vmwgfx: reject DX_BIND_QUERY without a DX context CVE-20…
09/11 TOC Mariner – drm/amdkfd: fix QID bit leak in pqm_create_queue() CVE-2026-…
09/12 TOC Mariner – Stack overflow in nscd due to unbounded alloca use CVE-2026-…
09/12 TOC Mariner – strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#…
09/12 TOC Mariner – strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereferenc…
09/12 TOC Mariner – strongSwan 4.5.0 through 6.0.7 has Incorrect Access Control …
09/12 TOC Mariner – strongSwan 5.1.3 through 6.0.7 has an infinite loop in the x…
09/12 TOC Mariner – libcharon in strongSwan 5.9.7 through 6.0.7 mishandles behav…
09/12 TOC Mariner – In PCRE2 before 10.48, pcre2_jit_match mishandles a previous…
09/12 TOC Mariner – PCRE2 before 10.48 has a pcre2_match out-of-bounds read duri…
09/12 TOC Mariner – PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern…
09/12 TOC Mariner – PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile…
09/12 TOC Mariner – PCRE2 before 10.48 has a pcre2_match out-of-bounds read afte…
09/11 TOC Microsoft Edge (Chromium-based) – Chromium: CVE-2026-84352 Use after f…
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.09/11 TOC Microsoft Edge (Chromium-based) – Chromium: CVE-2026-84330 UI misrepre…
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.09/11 TOC Microsoft Edge (Chromium-based) – Chromium: CVE-2026-84333 Use after f…
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.09/11 TOC Microsoft Edge (Chromium-based) – Chromium CVE-2026-85042: Use after …
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.09/11 TOC Microsoft Edge (Chromium-based) – Chromium CVE-2026-85043: Incomplete…
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.09/11 TOC Microsoft Edge (Chromium-based) – Chromium CVE-2026-85045: Race condi…
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.09/11 TOC Microsoft Edge (Chromium-based) – Chromium CVE-2026-85048: Use after …
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.09/11 TOC Microsoft Edge (Chromium-based) – Chromium CVE-2026-85049: Use after …
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.09/11 TOC Microsoft Edge (Chromium-based) – Chromium CVE-2026-85051: Type confu…
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.09/11 TOC Microsoft Edge (Chromium-based) – Chromium CVE-2026-85052: Out of bou…
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.09/11 TOC Microsoft Edge (Chromium-based) – Chromium CVE-2026-85053: Improper r…
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.09/11 TOC Microsoft Edge (Chromium-based) – Chromium CVE-2026-76036: Buffer ove…
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.09/11 TOC Microsoft Edge (Chromium-based) – Chromium CVE-2026-76039: Incorrect …
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.09/11 TOC Microsoft Edge (Chromium-based) – Chromium CVE-2026-76017: Use after …
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.09/11 TOC Microsoft Edge (Chromium-based) – Chromium CVE-2026-76018: Privilege …
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.09/11 TOC Microsoft Edge (Chromium-based) – Chromium CVE-2026-76019: Incorrect …
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.09/11 TOC Microsoft Edge (Chromium-based) – Chromium CVE-2026-76021: Use after …
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.09/11 TOC Microsoft Edge (Chromium-based) – Chromium CVE-2026-76022: Buffer ove…
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.09/11 TOC Microsoft Edge (Chromium-based) – Chromium CVE-2026-76023: Improper r…
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.09/11 TOC Microsoft Edge (Chromium-based) – Chromium CVE-2026-87491: Out of bou…
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Google is aware that an exploit for CVE-2026-87491 exists in the wild.TLDR InfoSec
09/10 TOC 150M IDScan breach , AdaptHealth 4.1M leak , Anthropic Discloses AI Ha…
Hacker News
09/13 TOC Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and …
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers09/12 TOC CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterO…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Details of the vulnerabilities are as follows – CVE-2026-42016 (CVSS score: 8.1) – An incorrect authorization09/12 TOC When the Whole Company Adopts AI: What It Does to Your SOC
Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from developers running coding agents and non-technical staff signing consumer AI tools into corporate09/12 TOC OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc S…
The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the09/11 TOC GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosur…
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under09/11 TOC Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude D…
Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself is a legitimate training method. It refers to a machine learning technique where a large, powerful AI model assumes the role of a “teacher” to09/11 TOC Claude Used to Automate Exploitation and Data Theft Across Multiple Vi…
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial09/11 TOC Russian State-Sponsored Hackers Use Claude to Rebuild Malware After De…
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 (where “GTG” stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight09/11 TOC Your Critical Vulnerabilities Might Not Be Your Biggest Risk
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that prevent an attacker09/11 TOC Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plan…
Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had not been updated were open to them.09/11 TOC China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYR…
A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims’ computers, security company Gen Digital said in research published Thursday. The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns09/11 TOC PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploi…
PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. “These are Regular Maintenance Releases (MR) that09/11 TOC Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransom…
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass09/10 TOC ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops…
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?†An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already09/10 TOC Google Play Early Access Abused to Push Thousands of Deceptive Android…
Bad actors are misusing Google Play’s Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven’t been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their09/10 TOC Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Una…
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only “under specific conditions” that it has not described. One flaw affects Check Point’s Security Gateways, its firewall appliances. The other affects those gateways and the Security09/10 TOC PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instan…
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from “45.142.193[.]132,” an IP address that has been linked to09/10 TOC Gigabud Creates Android Work Profiles to Hide From Banking App Malware…
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9. A work profile is a separate space that Android typically reserves for employer apps, and what’s inside it is kept separate from everything in the personal space. That09/10 TOC CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Fede…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below – CVE-2026-20079 (CVSS score: 10.0) – An authentication09/10 TOC Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example “sk-1234″…
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM’s own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway’s administrator credential. Anyone who holds it can read every09/10 TOC Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4…
Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents. The AI company said the incident dates back to January 2026 and involved an early version of Claude Opus 4.6 that breached “Check Point Research
09/10 TOC PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector
Executive Summary In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload (e.g. â€encrypt files in ~/Documentsâ€, “give me a biohazard recipeâ€, “ignore all previous instructions and…â€) is embedded in a specially crafted prose wrapper. An LLM with limited […]
The post PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector appeared first on Check Point Research.
Cisco Talos
09/10 TOC We’ve got one word for it, and it’s usually the wrong one
In this week’s Threat Source newsletter, Joe explores why the word “burnout” often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it.Bleeping Computer
09/12 TOC Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. […]09/11 TOC Hackers abused Claude to extract secrets from 1.8M Android apps
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. […]09/11 TOC Florida confirms DMV database breached via stolen police account
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. […]09/11 TOC Passkey-themed phishing attacks lead to Microsoft 365 data theft
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. […]09/11 TOC Artifactory flaws chained in attacks deploying backdoor malware
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. […]09/11 TOC How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surf…
Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures. […]09/11 TOC GitLab urges users to patch max severity path traversal flaw
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. […]09/11 TOC Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs
Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. […]09/11 TOC Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. […]09/11 TOC Conti ransomware gang member sentenced to 4 years in prison
A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. […]09/10 TOC New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. […]09/10 TOC September Windows Server updates break Remote Desktop Services
Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality. […]09/10 TOC Surfshark VPN says hackers breached internal testing, proxy servers
Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. […]09/10 TOC Microsoft Excel KB5002914 update breaks copy and paste for some users
Microsoft Excel users report that this week’s KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality. […]09/10 TOC AI-powered attack exploited PaperCut flaws to hack 395 organizations
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. […]CISA
09/10 TOC AVEVA Pipeline Integrity Monitor
09/10 TOC ST Engineering iDirect iQ-Series Terminals (Update A)Summary
Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session.
The following versions of AVEVA Pipeline Integrity Monitor are affected:
- AVEVA Pipeline Integrity Monitor <=2025_SP1_P1_build_7.1.9580.8513 (CVE-2026-81821, CVE-2026-81822, CVE-2026-81823, CVE-2026-81824)
CVSS Vendor Equipment Vulnerabilities v3 8.4 AVEVA AVEVA Pipeline Integrity Monitor Use of Hard-coded Cryptographic Key, Use of a Broken or Risky Cryptographic Algorithm, Missing Authorization, Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) Background
- Critical Infrastructure Sectors: Critical Manufacturing
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: United Kingdom
Vulnerabilities
CVE-2026-81821
The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to decrypt and view sensitive information.
Affected Products
AVEVA Pipeline Integrity Monitor
Vendor:
AVEVAProduct Version:
AVEVA Pipeline Integrity Monitor: <=2025_SP1_P1_build_7.1.9580.8513Product Status:
known_affectedRemediations
Vendor fix
AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected product versions or affected PIMBoards project files should take the following actions to mitigate the risk of exploit:Â
- Apply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate old project files.Â
- For project files that cannot be migrated (e.g. backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files.
- Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords.
Vendor fix
Important: PIMBoards Project Files migration from older versions to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 is one-way due to the changes in password hashing algorithms and end-user managed encryption keys.Mitigation
For more information, see AVEVA security bulletin AVEVA-2026-006.Â
https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdfRelevant CWE: CWE-321 Use of Hard-coded Cryptographic Key
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N 4.0 8.3 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N CVE-2026-81822
The vulnerability, if exploited, could allow a miscreant with read access to PIMBoards project files to reverse engineer PIMBoards users’ app-native passwords through computational brute-forcing of weak hashes, potentially allowing elevation to a PIMBoards administrator user.
Affected Products
AVEVA Pipeline Integrity Monitor
Vendor:
AVEVAProduct Version:
AVEVA Pipeline Integrity Monitor: <=2025_SP1_P1_build_7.1.9580.8513Product Status:
known_affectedRemediations
Vendor fix
AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected product versions or affected PIMBoards project files should take the following actions to mitigate the risk of exploit:Â
- Apply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate old project files.Â
- For project files that cannot be migrated (e.g. backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files.
- Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords.
Vendor fix
Important: PIMBoards Project Files migration from older versions to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 is one-way due to the changes in password hashing algorithms and end-user managed encryption keys.Mitigation
For more information, see AVEVA security bulletin AVEVA-2026-006.Â
https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdfRelevant CWE: CWE-327 Use of a Broken or Risky Cryptographic Algorithm
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 8.4 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N 4.0 8.3 HIGH CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N CVE-2026-81823
The vulnerability, if exploited, could allow an unauthenticated miscreant to perform read operations intended only for PIMBoards users, resulting in information disclosure. Write operations are not impacted.
Affected Products
AVEVA Pipeline Integrity Monitor
Vendor:
AVEVAProduct Version:
AVEVA Pipeline Integrity Monitor: <=2025_SP1_P1_build_7.1.9580.8513Product Status:
known_affectedRemediations
Vendor fix
AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected product versions or affected PIMBoards project files should take the following actions to mitigate the risk of exploit:Â
- Apply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate old project files.Â
- For project files that cannot be migrated (e.g. backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files.
- Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords.
Vendor fix
Important: PIMBoards Project Files migration from older versions to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 is one-way due to the changes in password hashing algorithms and end-user managed encryption keys.Mitigation
For more information, see AVEVA security bulletin AVEVA-2026-006.Â
https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdfRelevant CWE: CWE-862 Missing Authorization
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 5.3 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N 4.0 6.9 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-81824
The vulnerability, if exploited, could allow a miscreant to run arbitrary JavaScript code in a browser session of a PIMBoards user who was socially engineered to click on a malicious link.
Affected Products
AVEVA Pipeline Integrity Monitor
Vendor:
AVEVAProduct Version:
AVEVA Pipeline Integrity Monitor: <=2025_SP1_P1_build_7.1.9580.8513Product Status:
known_affectedRemediations
Vendor fix
AVEVA recommends that organizations evaluate the impact of these vulnerabilities based on their operational environment, architecture, and product implementation. Customers using affected product versions or affected PIMBoards project files should take the following actions to mitigate the risk of exploit:Â
- Apply AVEVA Pipeline Integrity Monitor 2025 SP1 P2 Security Update and migrate old project files.Â
- For project files that cannot be migrated (e.g. backups or transient copies), evaluate the risk of potential password leakage from these files and implement stricter read access controls to protect these unsafe files.
- Require AVEVA Pipeline Integrity Monitor PIMBoards users to change their passwords.
Vendor fix
Important: PIMBoards Project Files migration from older versions to AVEVA Pipeline Integrity Monitor 2025 SP1 P2 is one-way due to the changes in password hashing algorithms and end-user managed encryption keys.Mitigation
For more information, see AVEVA security bulletin AVEVA-2026-006.Â
https://www.aveva.com/content/dam/aveva/documents/support/cyber-security-updates/SecurityBulletin_AVEVA-2026-006.pdfRelevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’)
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 4.7 MEDIUM CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:N 4.0 6.3 MEDIUM CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:H/SA:H
Acknowledgments
- AVEVA reported vulnerabilities CVE-2026-81821 and CVE-2026-81822 to CISA.
- Adham Khairy Ramadan (0xadham) reported vulnerabilities CVE-2026-81823 and CVE-2026-81824 to AVEVA through HackerOne.Â
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.
Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
Locate control system networks and remote devices behind firewalls and isolating them from business networks.
When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most current version available. Also recognize VPN is only as secure as the connected devices.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
CISA also recommends users take the following measures to protect themselves from social engineering attacks:
Do not click web links or open attachments in unsolicited email messages.
Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.
Revision History
- Initial Release Date: 2026-09-10
Date Revision Summary 2026-09-10 1 Initial Republication of AVEVA security bulletin AVEVA-2026-006
Legal Notice and Terms of Use
Summary
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition.
The following versions of ST Engineering iDirect iQ-Series Terminals (Update A) are affected:
- Evolution iQ‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058)
- 3315‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058)
- 9‑Series terminals <=4.5.2.1 (CVE-2026-38059, CVE-2026-38057, CVE-2026-38056, CVE-2026-38058)
CVSS Vendor Equipment Vulnerabilities v3 8.8 ST Engineering iDirect ST Engineering iDirect iQ-Series Terminals Missing Authentication for Critical Function, Cross-Site Request Forgery (CSRF), Missing Authorization, Exposure of Sensitive System Information to an Unauthorized Control Sphere Background
- Critical Infrastructure Sectors: Communications, Defense Industrial Base, Energy, Government Services and Facilities, Transportation Systems
- Countries/Areas Deployed: Worldwide
- Company Headquarters Location: United States
Vulnerabilities
CVE-2026-38059
The iDirect iQ200 exposes the /api/identity and /api/ REST API endpoints without authentication. An unauthenticated attacker with network access can retrieve sensitive device information including the serial number, Device ID (DID), Terminal Private Key identifier (TPK), MAC address, and exact firmware version. The DID and TPK are used for satellite network authentication in the iDirect platform, potentially enabling terminal impersonation and network reconnaissance.
Affected Products
ST Engineering iDirect iQ-Series Terminals (Update A)
Vendor:
ST Engineering iDirectProduct Version:
ST Engineering iDirect Evolution iQ‑Series terminals: <=4.5.2.1, ST Engineering iDirect 3315‑Series terminals: <=4.5.2.1, ST Engineering iDirect 9‑Series terminals: <=4.5.2.1Product Status:
known_affectedRemediations
Mitigation
ST Engineering iDirect has fixed the vulnerabilities and recommend users update the software to version 4.5.3.0 or newer.Mitigation
Registered users are able to download patches from the iDirect Support Portal https://support.idirect.net.
https://support.idirect.net
- Restrict management interfaces to trusted networks (e.g., VPN, ACLs).
- Avoid exposing administrative APIs to the public internet.
- Enforce strong authentication practices.
- Monitor for anomalous API activity and unexpected device reboots.
Relevant CWE: CWE-306 Missing Authentication for Critical Function
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-38057
The iDirect iQ200 does not validate CSRF tokens on state-changing API endpoints after authentication. The /api/reboot endpoint accepts POST requests authenticated solely by a session cookie that lacks the SameSite attribute. A remote attacker can host a malicious web page that, when visited by an authenticated administrator, automatically submits a cross-site POST request causing an immediate device reboot and satellite link loss. Repeated attacks can sustain a denial-of-service condition.
Affected Products
ST Engineering iDirect iQ-Series Terminals (Update A)
Vendor:
ST Engineering iDirectProduct Version:
ST Engineering iDirect Evolution iQ‑Series terminals: <=4.5.2.1, ST Engineering iDirect 3315‑Series terminals: <=4.5.2.1, ST Engineering iDirect 9‑Series terminals: <=4.5.2.1Product Status:
known_affectedRemediations
Mitigation
ST Engineering iDirect has fixed the vulnerabilities and recommend users update the software to version 4.5.3.0 or newer.Mitigation
Registered users are able to download patches from the iDirect Support Portal https://support.idirect.net.
https://support.idirect.net
- Restrict management interfaces to trusted networks (e.g., VPN, ACLs).
- Avoid exposing administrative APIs to the public internet.
- Enforce strong authentication practices.
- Monitor for anomalous API activity and unexpected device reboots.
Relevant CWE: CWE-352 Cross-Site Request Forgery (CSRF)
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 8.1 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H 4.0 7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N CVE-2026-38056
A local privilege escalation vulnerability exists in the iDirect iQ200 VSAT terminal running firmware 23.0.1.0. The iQ200 is a rackmount satellite modem deployed across oil and gas, maritime, defense, and remote infrastructure as the primary, and often sole communications link for offshore rigs, vessels, and remote sites. Important context: the device ships from the factory with a pre-configured low-privilege local user account. This account is intended for field technicians who need shell access for maintenance and diagnostics but should not have full administrative control over the device. This built-in account provides the initial access required to exploit this vulnerability. No additional credentials need to be obtained or brute-forced.
Affected Products
ST Engineering iDirect iQ-Series Terminals (Update A)
Vendor:
ST Engineering iDirectProduct Version:
ST Engineering iDirect Evolution iQ‑Series terminals: <=4.5.2.1, ST Engineering iDirect 3315‑Series terminals: <=4.5.2.1, ST Engineering iDirect 9‑Series terminals: <=4.5.2.1Product Status:
known_affectedRemediations
Mitigation
ST Engineering iDirect has fixed the vulnerabilities and recommend users update the software to version 4.5.3.0 or newer.Mitigation
Registered users are able to download patches from the iDirect Support Portal https://support.idirect.net.
https://support.idirect.net
- Restrict management interfaces to trusted networks (e.g., VPN, ACLs).
- Avoid exposing administrative APIs to the public internet.
- Enforce strong authentication practices.
- Monitor for anomalous API activity and unexpected device reboots.
Relevant CWE: CWE-862 Missing Authorization
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H 4.0 9.4 CRITICAL CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVE-2026-38058
The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which contains MD5-crypt password hashes for the root SSH and web administration accounts. Any user with valid web credentials can extract these hashes and crack them offline using commodity hardware.
Affected Products
ST Engineering iDirect iQ-Series Terminals (Update A)
Vendor:
ST Engineering iDirectProduct Version:
ST Engineering iDirect Evolution iQ‑Series terminals: <=4.5.2.1, ST Engineering iDirect 3315‑Series terminals: <=4.5.2.1, ST Engineering iDirect 9‑Series terminals: <=4.5.2.1Product Status:
known_affectedRemediations
Mitigation
ST Engineering iDirect has fixed the vulnerabilities and recommend users update the software to version 4.5.3.0 or newer.Mitigation
Registered users are able to download patches from the iDirect Support Portal https://support.idirect.net.
https://support.idirect.net
- Restrict management interfaces to trusted networks (e.g., VPN, ACLs).
- Avoid exposing administrative APIs to the public internet.
- Enforce strong authentication practices.
- Monitor for anomalous API activity and unexpected device reboots.
Relevant CWE: CWE-497 Exposure of Sensitive System Information to an Unauthorized Control Sphere
Metrics
CVSS Version Base Score Base Severity Vector String 3.1 8.1 HIGH CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N 4.0 8.6 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Acknowledgments
- Ahmed Alqahtani of Aramco reported these vulnerabilities to CISA.
Legal Notice and Terms of Use
This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy).
Recommended Practices
CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities.
Minimize network exposure for all control system devices and/or systems, ensuring they are not accessible from the internet.
Locate control system networks and remote devices behind firewalls and isolating them from business networks.
CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
CISA also recommends users take the following measures to protect themselves from social engineering attacks:
Do not click web links or open attachments in unsolicited email messages.
Refer to Recognizing and Avoiding Email Scams for more information on avoiding email scams.
Refer to Avoiding Social Engineering and Phishing Attacks for more information on social engineering attacks.
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.
Revision History
- Initial Release Date: 2026-07-02
Date Revision Summary 2026-07-02 1 Initial Publication 2026-09-10 2 Update A – Updated Vulnerabilities and CVSS 4.0 score in Executive Summary. Added CVE-2026-38056 and CVE-2026-38058. Updated Mitigation section with newest product version.
Legal Notice and Terms of Use
Cisco Advisories
09/11 TOC Cisco IOS XR Software Security Hardening Release: September 2026
As part of Cisco’s ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. Â
These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class — Common Weakness Enumeration (CWE) — and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping.
Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-iosxr-qg64NcM
Security Impact Rating: Critical
CVE: CVE-2026-20274,CVE-2026-20275,CVE-2026-20276,CVE-2026-20277,CVE-2026-20278,CVE-2026-20279,CVE-2026-20280DataBreaches.net
09/12 TOC Not just Korea: Google leaked identifying info for sex crime victims a…
Shin Da-eun and Park Kang-su report: Korea was not the only country where victims who sent Google removal requests about illegally obtained sexual images ended up having their private information posted online, the Hankyoreh has confirmed. “Photos of me from when I was a minor were distributed without my consent. They were posted on an…09/12 TOC NYS DFS Issues New Cybersecurity Guidance on Risk Assessments for Fina…
New York State Department of Financial Services (DFS): September 10, 2026 New York State Department of Financial Services (DFS) Acting Superintendent Kaitlin Asrow today issued new cybersecurity guidance outlining the Department’s expectations for DFS-regulated entities’ on conducting risk assessments sufficient to inform their cybersecurity programs. The guidance outlines requirements regarding scope, frequency, and the role…09/11 TOC TX: Two Lamesa ISD employees arrested over security breach
Urijah Jaushlin reports: Two Lamesa ISD employees were arrested in connection with a law enforcement investigation involving allegations of a breach of computer security, according to a press release by the Lamesa Independent School District Friday morning. The Lamesa Police Department announced in a press release that authorities, along with the Texas Rangers, arrested 54-year-old…09/11 TOC Ukrainian National Sentenced to Four Years in Prison for Wire Fraud Co…
There’s an update to a previously reported case. From the Department of Justice, this press release: Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced today to four years in prison for conspiracy to commit wire fraud in connection with a conspiracy to deploy Conti, a ransomware variant that infected the computers of more than 1,000…09/11 TOC Personal Info Possibly Compromised at Japans Digital Agency
JiJi Press reports: Japan’s Digital Agency said Friday that about 246,000 sets of personal information, including the names and email addresses of government employees, may have been compromised through the unauthorized access of a network system operated by the agency. So far, no secondary damage such as the misuse of the possibly breached personal information…09/10 TOC FTC Withdraws Obsolete Policy Statement
From the Federal Trade Commission: The Federal Trade Commission rescinded the 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices. This controversial policy statement purported to apply the FTC’s Health Breach Notification Rule to health apps and connected devices that collect consumer health information. In 2024, however, the Commission updated the Health Breach Notification…09/10 TOC Korea raises data breach fines to 10% of revenue
Korea JoongAng Daily reports: Korea’s privacy regulator is sharply raising the cost of data breaches, aiming to push companies to treat data protection as a preventive investment rather than a routine cost of doing business. Starting Friday, companies found to have leaked the personal data of 10 million or more people through intent or gross negligence…09/10 TOC ShinyHunters expose 6.4M in attack on medical supplier McKesson
Connor Jones reports: McKesson’s cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP). The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the scale of the attack for the first time. ShinyHunters initially claimed to have stolen 284 million documents from the medical and pharmaceutical supply…Huntress Blog
09/15 TOC Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to…
A single X DM split into two malware chains: AMOS stealer on Mac, NetSupport Manager on Windows, see the Huntress SOC analyst breakdown.09/10 TOC Credential Theft: How Attackers Steal & Use Stolen Credentials
Learn what credential theft is, how attackers steal credentials, and how to prevent credential-based attacks with identity-focused defenses from Huntress.09/10 TOC Best Practices for Good Endpoint Hardening | Huntress
Learn what endpoint hardening is, why it matters, and best practices to reduce attack surface, control access, & stop common intrusion paths.09/10 TOC The 20 Most Common Passwords Hackers Target in 2026
See this year’s most common passwords, why they’re so easy to crack, and how a stronger password (or passphrase) habit keeps your accounts protected.09/10 TOC 35 Actionable Password Statistics for Businesses in 2026 | Huntress
The top password statistics might surprise you. Learn how common poor password hygiene is, plus tips to better protect your precious credentials.CVEMon Intruder
09/13 TOC CVE-2026-42016
Currently trending CVE – Hype Score: 14 – JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.09/13 TOC CVE-2026-42018
Currently trending CVE – Hype Score: 14 – JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.09/13 TOC CVE-2026-85706
Currently trending CVE – Hype Score: 13 – GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path …09/13 TOC CVE-2026-84869
Currently trending CVE – Hype Score: 13 – A condition in the ScreenConnect client may allow files to be transferred and executed through an active remote session without authorization or Host confirmation in certain circumstances. ScreenConnect servers are not impacted.09/13 TOC CVE-2026-81963
Currently trending CVE – Hype Score: 11 – Improper link resolution before file access (‘link following’) in Windows Update Stack allows an authorized attacker to elevate privileges locally.09/13 TOC CVE-2026-85102
Currently trending CVE – Hype Score: 2 – Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.09/13 TOC CVE-2026-85103
Currently trending CVE – Hype Score: 2 – A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems.09/13 TOC CVE-2026-86060
Currently trending CVE – Hype Score: 1 – RouterOS contains an argument-handling flaw in the SSH login path involving usernames that begin with a prohibited character, allowing for the trusted RouterOS policy mask to be changed, leading to privilege escalation. Exploitation requires an unauthenticated SSH session to …09/13 TOC CVE-2026-67277
Currently trending CVE – Hype Score: 1 – RouterOS accepts a “related” btest connection before the corresponding primary session has completed authentication. An unauthenticated client can use this state to start an IPv4 UDP test. With “random-data=false”, the sender transmits an uninitialized tail from a kernel packet …09/13 TOC CVE-2025-25249
Currently trending CVE – Hype Score: 1 – A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 …Graham Cluley
09/10 TOC Anne Hathaway admits leading $245 million crypto theft gang that spent…
Here’s a tip for any budding cybercriminals out there. If you’re going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don’t broadcast on a group chat every time you buy a Lamborghini, or blow half a million dollars on a single night out at a nightclub. Read more in my article on the Hot for Security blog.Hacking Lab
11/30 TOC PatchIsland: Orchestration of LLM Agents for Continuous Vulnerability …
10/31 TOC MTEscape: Bypassing Asynchronous Kernel MTE via Conventional Memory Co…
09/30 TOC Prism: A Multi-Team Orchestration of LLM Agents for Automatic Program …
Schneier on Security
09/11 TOC Friday Squid Blogging: Rotting Squid on a Beached California Boat
09/11 TOC My Talk at DEF CONSmells awful:
But an estimated 30 to 50 tons of dead squid remain inside the boat’s catch tank, where they have been decomposing for days. “That is nasty. I wouldn’t want to do that,†said commercial fisherman Dick Ogg of the Bodega Bay Fishermen’s Marketing Association.
Ogg said anyone familiar with the fishing industry understands what happens when a large catch sits for an extended period.
“If you think about what happens after four or five days, it’s a gooey mess,†he said.
The odor has become a defining feature of the operation, and the beach remains closed to the public while crews work on a removal plan…
09/11 TOC Cliff Stolls DEF CON TalkLast month, I gave a talk at DEF CON on AI hacking: what happens when AIs become hackers. It’s a combination of the potentialities I raised in my 2022 book A Hacker’s Mind and the lessons we’re learning from current AI models engaging in hacking behavior. I’m really proud of the talk, and the fact that it gained over 100K views on YouTube in just a few days.
Also online is an interview with me in the AI Village.
09/10 TOC AIs Compress Exploit TimelineIn August, Cliff Stoll gave a talk at DEF CON, remembering the wily hacker he stalked forty years ago.
Great fun.
Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it.
What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour of a security issue seems enough to give attackers enough info to find new exploits, we’re going to need to change the way we deal with security responses in open source.
Simon Willison comments:
Anil points out that this rate of discovery appears incompatible with existing open source embargo practices for new issues. If an issue can become an exploit this fast, we need to figure out new processes for keeping our communities safe…
Talos – Vulnerability Reports
09/12 TOC Microsoft Windows Cloud Files Mini Filter Driver CldiStreamCompleteReq…
09/12 TOC Microsoft Windows Cloud Files Mini Filter Driver CldiStreamPrepareRequ…
Troy Hunt
09/11 TOC Weekly Update 521: Breach Perception v. Reality
I think what really resonates with me this week is being able to completely turn the tables on perceptions around things like AI being the big bad hacking tool the news would have you believe. There’s the stat I talk about where it’s had literally 0%
WeLiveSecurity
09/10 TOC GuardBreaker: Derailing AI-assisted malware analysis with a code comme…
LLM-based code scanners won’t help attackers build a nuclear weapon, but that refusal could work in their favorZero Day Initiative-Published
09/10 TOC ZDI-26-679: Adobe Photoshop DCM JPEG Image Parsing Integer Overflow Re…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75862.09/10 TOC ZDI-26-678: Adobe Photoshop DCM File Parsing Integer Overflow Remote C…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75863.09/10 TOC ZDI-26-677: Adobe Photoshop DCM JPEG-LS Image Parsing Integer Overflow…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-75771.09/10 TOC ZDI-26-676: Adobe Acrobat Reader DC DigSig Use-After-Free Remote Code …
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81973.09/10 TOC ZDI-26-675: Adobe Acrobat Reader DC Annotation Use-After-Free Remote C…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81976.09/10 TOC ZDI-26-674: Adobe Acrobat Reader DC Annotation Out-Of-Bounds Write Rem…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81981.09/10 TOC ZDI-26-673: Adobe Acrobat Pro DC Doc Object Use-After-Free Remote Code…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81988.09/10 TOC ZDI-26-672: Adobe Acrobat Reader DC PDF File Parsing Integer Underflow…
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81977.09/10 TOC ZDI-26-671: Adobe Acrobat Reader DC Dialog Object Type Confusion Remot…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-80161.09/10 TOC ZDI-26-670: Adobe Acrobat Pro DC Doc Object Out-Of-Bounds Read Informa…
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81991.09/10 TOC ZDI-26-669: Adobe Acrobat Reader DC JBIG2 File Parsing Out-Of-Bounds R…
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81978.09/10 TOC ZDI-26-668: Adobe Acrobat Reader DC Annotation Use-After-Free Informat…
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-81984.09/10 TOC ZDI-26-667: Adobe Acrobat Reader DC Annotation Use-After-Free Remote C…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81975.09/10 TOC ZDI-26-666: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bound…
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-79910.09/10 TOC ZDI-26-665: Adobe Acrobat Reader DC Annots Report Use-After-Free Remot…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-79909.09/10 TOC ZDI-26-664: Adobe Acrobat Reader DC Annotation Use-After-Free Remote C…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81986.09/10 TOC ZDI-26-663: Adobe Acrobat Pro DC Annotation Use-After-Free Remote Code…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81989.09/10 TOC ZDI-26-662: Adobe Acrobat Reader DC Annotation Use-After-Free Remote C…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81990.09/10 TOC ZDI-26-661: Adobe Acrobat Reader DC Annotation Use-After-Free Remote C…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81985.09/10 TOC ZDI-26-660: Adobe Acrobat Reader DC Font Parsing Use-After-Free Inform…
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-80162.09/10 TOC ZDI-26-659: Adobe Acrobat Reader DC JPEG2000 File Parsing Out-Of-Bound…
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-80160.09/10 TOC ZDI-26-658: Adobe Acrobat Pro DC JPEG Parsing Integer Overflow Remote …
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Pro DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-81987.09/10 TOC ZDI-26-657: ASUS Control Center Express Agent Missing Authentication R…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of ASUS Control Center Express Agent. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-19397.09/10 TOC ZDI-26-656: PAPPL Job Processing Heap-based Buffer Overflow Remote Cod…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of PAPPL. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8.09/10 TOC ZDI-26-655: PAPPL Printer IPP Processing Stack-based Buffer Overflow L…
This vulnerability allows local attackers to escalate privileges on affected installations of PAPPL. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8.09/10 TOC ZDI-26-654: TrendAI Apex One Incomplete Cleanup Local Privilege Escala…
This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-71414.09/10 TOC ZDI-26-653: TrendAI Apex One Security Agent Cache Mechanism Time-Of-Ch…
This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-71415.09/10 TOC ZDI-26-652: TrendAI Apex One Security Agent Cache Mechanism Time-Of-Ch…
This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-71416.09/10 TOC ZDI-26-651: (Pwn2Own) OpenAI Codex External Control of System or Confi…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must open a malicious folder. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19593.09/10 TOC ZDI-26-650: (Pwn2Own) OpenAI Codex External Control of Configuration S…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19592.09/10 TOC ZDI-26-649: (Pwn2Own) OpenAI Codex Improper Neutralization of Control …
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must open a malicious folder. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19591.09/10 TOC ZDI-26-648: (Pwn2Own) OpenAI Codex External Control of System or Confi…
This vulnerability allows remote attackers to execute arbitrary code on affected installations of OpenAI Codex. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19590.
Content on this page is collected from remote sources by IPWorX but is not created by IPWorX. The contents belong to the creators and should be considered theirs for all legal purposes, we have no editorial control or responsibility over them. IPWorX does not represent or endorse the accuracy or reliability of any opinion, statement, or other information provided by any third party.
This page contains links to third-party websites. These links are provided solely for your convenience. IPWorX does not control, maintain, or endorse the content, accuracy, or reliability of any third-party resources, and you access them at your own risk.
Scripts and tools to help manage your network found, managed and
happily shared with documentation on usage at the IP WORk eXchange.
https://www.IPWorX.com
