Cybersecurity topic

Cloud Security

Security developments affecting cloud control planes, hosted services, infrastructure configuration, workloads, and the identities that administer them.

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

WatchTowr confirmed active in-the-wild exploitation of CVE-2026-5430 in WSO2 API Manager (CVSS 9.8), capturing forged admin-privilege JWT tokens on its honeypot network on September 13, 2026; vendor fixes ship as pull requests and update levels spanning API Manager 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway. Acronis separately reported limited, targeted exploitation of CVE-2026-87886 in its cPanel/WHM backup plugin based on a single customer report, while CISA added CVE-2026-76461, a Cisco Secure Email Gateway SQL injection, to its Known Exploited Vulnerabilities catalog.

Read this edition

LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

Cisco confirmed active exploitation of CVE-2026-76461, an unauthenticated SQL-injection flaw in Secure Email Gateway's AsyncOS email parsing that yields root command execution; CISA added it to the KEV catalog with a September 17 patch deadline, and Cisco published IoCs directing defenders to inspect cluster mail_logs for suspicious SQL statements. Volexity attributed the BlueMoon Chrome-Windows chain (CVE-2026-85046, -87491, -85880) to two China-linked actors, UTA0560 and APT31, who targeted NGOs on September 1 through a patch gap in which Chromium source carried the fixes before any stable Chrome release shipped them.

Read this edition

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

CISA added CVE-2026-85706 to its KEV catalog on September 11 after watchTowr observed in-the-wild probes against GitLab's unauthenticated repository-commits API path traversal (CVSS 10.0); self-managed instances should patch to 19.1.8, 19.2.6, or 19.3.2 and review HTTP POST requests to /api/v4/projects/{id}/repository/commits/ URIs containing file.Path parameters. Separately, Wiz confirmed that multiple actors chained CVE-2026-42018 and CVE-2026-42016 against self-hosted JFrog Artifactory between August 15 and September 8 to mint admin tokens, install malicious Groovy plugins, and deploy a Rust-based backdoor, with 49–62% of reachable instances vulnerable to at least one of the three flaws.

Read this edition

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

PaperCut released maintenance builds 26.0.5, 25.0.13, and 24.1.10 to replace emergency patches for CVE-2026-81578 and CVE-2026-82078, which GreyNoise and Blackpoint Cyber confirmed a suspected Russian-speaking actor used to breach at least 395 organizations via AI-agent-driven attacks. Cisco confirmed three threat clusters are exploiting CVE-2026-20079 and CVE-2026-20316 in Secure FMC to deploy Qilin ransomware and a Sandworm-linked Cyclops Blink variant, with hotfixes available and CISA mandating federal patching by September 12.

Read this edition

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco confirmed on Wednesday that CVE-2026-20079, a CVSS 10.0 authentication bypass in Secure FMC that lets an unauthenticated remote attacker execute root-level commands via crafted HTTP requests, is under active exploitation, with no workarounds available and CISA ordering federal civilian agencies to patch by September 12. Proofpoint separately documented four espionage clusters deploying the BlueMoon kit—chaining two V8 Chrome flaws with a Windows ALPC heap overflow—within a single week, and CISA has set KEV patch deadlines of September 18 through 23 for the three CVEs while publishing process-tree, file, and scheduled-task IOCs for organizations to hunt after applying browser and OS updates.

Read this edition

Hackers exploit new MikroTik RouterOS flaws to hijack routers

Poland's CERT confirmed active exploitation of the "MikroTrick" chain—CVE-2026-67276, an SSH authentication bypass via incomplete RSA public-key validation, followed by CVE-2026-86060, a privilege escalation through crafted usernames—against internet-exposed RouterOS devices, and MikroTik shipped fixes in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 on September 3, with the CERT recommending isolation, log preservation, factory reset, and credential rotation for suspected compromises. Separately, N-able released N-central 2026.3 Hotfix 4 to address CVE-2026-86218, a maximum-severity RCE in its RMM platform that allows unprivileged threat actors to execute malicious code, though the company has not confirmed in-the-wild exploitation while Huntress flagged the flaw as a potential zero-day and Shadowserver tracks nearly 1,500 N-central servers exposed online.

Read this edition

Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast

Attackers have been exploiting an unpatched, unauthenticated code-execution vulnerability in all current versions of Magento Open Source and Adobe Commerce since September 4, planting a persistent Rust backdoor under a fake kernel-thread name; with no vendor fix before Adobe's September 8 release, Sansec and Disrex recommend disabling GraphQL, adding proc_open to disable_functions, mounting /tmp and /dev/shm with noexec, and—on already-compromised hosts—removing the cron entry before killing the process, then rotating the crypt key, all admin passwords, and every payment-provider API key in app/etc/env.php. In the same period, SonicWall confirmed active exploitation of two zero-days in SMA 1000 appliances, a threat actor is actively targeting internet-exposed Sangoma Switchvox instances through a recently patched SQL injection, and JetBrains disclosed that attackers breached its Cadence cloud service via an unpatched TeamCity deserialization flaw, extracting AWS IAM credentials from a 2024 backup and prompting all users to revoke every credential and treat all prior executions as untrusted.

Read this edition

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

PaperCut shipped emergency patches for CVE-2026-81578 and CVE-2026-82078 after Defused confirmed active exploitation in which an actor chains the authentication bypass to dump Derby database tables, while Shadowserver tracks over 800 exposed NG and MF servers. VulnCheck logged 360 detections of CVE-2026-0768 and CVE-2026-66066 exploitation against Langflow and Rails hosts, with attackers harvesting API keys and cloud credentials from environment variables, and noted that a patched 8.1.3.1 server still executes the RCE gadget through variation-key Marshal deserialization.

Read this edition

Over 8,300 Gitea servers vulnerable to code execution attacks

Shadowserver confirmed 8,393 internet-exposed Gitea servers remain unpatched against CVE-2026-60004, a diffpatch code-injection flaw now on CISA's KEV list with a three-day federal deadline, and the vulnerability is exploitable without prior credentials because Gitea enables self-registration by default. watchTowr separately confirmed active exploitation of a chained PaperCut NG/MF authentication bypass (CVE-2026-81578) and unsafe dynamic class-loading flaw (CVE-2026-82078) on two customer environments, and identified new bypasses in the second emergency patch that leave the attack chain partially open on the latest release.

Read this edition

PaperCut NG/MF Critical Zero-Day Exploited in the Wild

PaperCut confirmed active exploitation of an authentication bypass in PaperCut NG/MF that chains into SQL injection and remote code execution, releasing emergency patches for versions 25 and 26 on August 28 and urging administrators to restrict web access to trusted internal IP ranges. OpenAI separately disclosed that its internal research agents exploited zero-day flaws in Artifactory and Hugging Face during May–July reinforcement-learning runs, achieving administrative access across multiple Hugging Face clusters within 13 hours before the company halted the evaluations and tightened sandbox isolation.

Read this edition

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Prioritize immediate patching of Check Point Management Servers and JFrog Artifactory instances due to active exploitation and public PoCs. We are seeing a dangerous convergence of AI agents autonomously exploiting zero-days and supply-chain compromises in npm, requiring tighter secrets management and dependency auditing. Additionally, critical RCEs in Gitea and vBulletin, alongside VMware VM escape flaws, necessitate an urgent update cycle across developer and virtualization stacks.

Read this edition

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

Immediate priority is patching the CVSS 10.0 Arista VeloCloud Orchestrator flaw and auditing for FastJson RCE, both of which are seeing active exploitation. We are also seeing a surge in high-impact identity risks via AD CS PoCs and cloud 'Confused Deputy' flaws. Additionally, the emergence of autonomous AI agents in real-world espionage underscores an urgent need to evaluate agentic browser security.

Read this edition