Cybersecurity topic

Malware

Analysis of stealers, backdoors, loaders, botnets, cryptominers, destructive payloads, and other malicious software, including delivery, persistence, capabilities, and defensive indicators.

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

Cisco confirmed active exploitation of CVE-2026-76460, an authentication bypass in an ISE API endpoint that lets a remote unauthenticated attacker bypass the web management interface; the fix requires upgrading to 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4, and no workarounds exist. The Shadowserver Foundation separately observed active exploitation of CVE-2026-89026 in Issabel Framework, where a hard-coded HS256 JWT signing key in pbxapi/index.php lets an unauthenticated attacker forge bearer tokens and execute arbitrary OS commands as the Asterisk user; a patch shipped August 1, 2026, replaces the key with one stored in /etc/issabel.conf.

Read this edition

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

WatchTowr confirmed active in-the-wild exploitation of CVE-2026-5430 in WSO2 API Manager (CVSS 9.8), capturing forged admin-privilege JWT tokens on its honeypot network on September 13, 2026; vendor fixes ship as pull requests and update levels spanning API Manager 4.1.0 through 4.6.0, API Control Plane, Traffic Manager, and Universal Gateway. Acronis separately reported limited, targeted exploitation of CVE-2026-87886 in its cPanel/WHM backup plugin based on a single customer report, while CISA added CVE-2026-76461, a Cisco Secure Email Gateway SQL injection, to its Known Exploited Vulnerabilities catalog.

Read this edition

LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

Cisco confirmed active exploitation of CVE-2026-76461, an unauthenticated SQL-injection flaw in Secure Email Gateway's AsyncOS email parsing that yields root command execution; CISA added it to the KEV catalog with a September 17 patch deadline, and Cisco published IoCs directing defenders to inspect cluster mail_logs for suspicious SQL statements. Volexity attributed the BlueMoon Chrome-Windows chain (CVE-2026-85046, -87491, -85880) to two China-linked actors, UTA0560 and APT31, who targeted NGOs on September 1 through a patch gap in which Chromium source carried the fixes before any stable Chrome release shipped them.

Read this edition

Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited

Cisco confirmed that state-sponsored and ransomware actors are actively exploiting CVE-2026-20079, an authentication bypass in Secure Firewall Management Center, and N-able shipped an emergency hotfix for CVE-2026-86218, a pre-auth RCE in N-central already exploited in the wild. Sophos separately reported a Linux rootkit on compromised F5 BIG-IP APM appliances that keeps its web shell in memory to evade disk-based detection, while the Dutch NCSC issued an imminent-exploitation warning for two Check Point VPN flaws (CVE-2026-85102, CVE-2026-85103) for which no public proof-of-concept exists yet.

Read this edition

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

CISA added five actively exploited flaws to its KEV catalog—two JFrog Artifactory authorization bugs chained with CVE-2026-82329 to install Rust backdoors and malicious Groovy plugins on self-hosted servers, a ScreenConnect client flaw (CVE-2026-84869) used to push VBScript payloads to newly connected hosts, and two RouterOS flaws exploited in a chain CERT Polska calls MikroTrick—alongside N-able N-central's CVE-2026-86218, a pre-authentication static code injection (CVSS 10.0) fixed in 2026.3 Hotfix 4 with an FCEB patch deadline of September 11. The F5 BIG-IP APM in-memory web shell (c05d5254), which F5 linked to the reclassified CVE-2025-53521 RCE, is described by Sophos and ESET as designed to survive upgrade images because it hooks Apache's apr_dso_load to inject the shell into the libphp module in memory, evading disk-based integrity checks, and the UK NCSC advises investigating for compromise regardless of when the system was updated.

Read this edition

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

CISA added CVE-2026-85706 to its KEV catalog on September 11 after watchTowr observed in-the-wild probes against GitLab's unauthenticated repository-commits API path traversal (CVSS 10.0); self-managed instances should patch to 19.1.8, 19.2.6, or 19.3.2 and review HTTP POST requests to /api/v4/projects/{id}/repository/commits/ URIs containing file.Path parameters. Separately, Wiz confirmed that multiple actors chained CVE-2026-42018 and CVE-2026-42016 against self-hosted JFrog Artifactory between August 15 and September 8 to mint admin tokens, install malicious Groovy plugins, and deploy a Rust-based backdoor, with 49–62% of reachable instances vulnerable to at least one of the three flaws.

Read this edition

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

PaperCut released maintenance builds 26.0.5, 25.0.13, and 24.1.10 to replace emergency patches for CVE-2026-81578 and CVE-2026-82078, which GreyNoise and Blackpoint Cyber confirmed a suspected Russian-speaking actor used to breach at least 395 organizations via AI-agent-driven attacks. Cisco confirmed three threat clusters are exploiting CVE-2026-20079 and CVE-2026-20316 in Secure FMC to deploy Qilin ransomware and a Sandworm-linked Cyclops Blink variant, with hotfixes available and CISA mandating federal patching by September 12.

Read this edition

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google shipped fixes for an actively exploited V8 out-of-bounds write (CVE-2026-87491) enabling sandboxed code execution via crafted HTML, and Microsoft's September cumulative update closes two confirmed zero-days—CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC—both granting SYSTEM to low-privilege authenticated users. SAP's newly patched CVSS 10.0 kernel flaw (CVE-2026-44756) permits unauthenticated remote code execution with administrative privileges across web, GUI, and RFC layers, and Onapsis warns that no network control or authorization boundary stops it because the vulnerable deserialization runs before any authentication step.

Read this edition

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

Adobe shipped the VULN-39341 hotfix for CVE-2026-75650 (StyleSmuggler), a template-injection flaw in Magento's payment-reminder pipeline that Sansec confirmed under active exploitation since September 4, with threat actors deploying a Rust-based Linux backdoor and a PHP web shell; Adobe requires both the patch and encryption-key rotation across affected Adobe Commerce and Magento Open Source versions through 2.4.9-2026-aug. In the same window, CERT Polska confirmed active exploitation of the MikroTrick chain (CVE-2026-67276 and CVE-2026-86060) against SSH-enabled MikroTik RouterOS devices, fixed in 6.49.21, 7.23.4, and 7.24.2, while Google patched a V8 type-confusion zero-day (CVE-2026-85046) under active exploitation in Chrome 152.0.7977.82.

Read this edition

Hackers exploit new MikroTik RouterOS flaws to hijack routers

Poland's CERT confirmed active exploitation of the "MikroTrick" chain—CVE-2026-67276, an SSH authentication bypass via incomplete RSA public-key validation, followed by CVE-2026-86060, a privilege escalation through crafted usernames—against internet-exposed RouterOS devices, and MikroTik shipped fixes in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 on September 3, with the CERT recommending isolation, log preservation, factory reset, and credential rotation for suspected compromises. Separately, N-able released N-central 2026.3 Hotfix 4 to address CVE-2026-86218, a maximum-severity RCE in its RMM platform that allows unprivileged threat actors to execute malicious code, though the company has not confirmed in-the-wild exploitation while Huntress flagged the flaw as a potential zero-day and Shadowserver tracks nearly 1,500 N-central servers exposed online.

Read this edition

Week in review: Claude accounts compromised through infostealer, Patch Tuesday forecast

Attackers have been exploiting an unpatched, unauthenticated code-execution vulnerability in all current versions of Magento Open Source and Adobe Commerce since September 4, planting a persistent Rust backdoor under a fake kernel-thread name; with no vendor fix before Adobe's September 8 release, Sansec and Disrex recommend disabling GraphQL, adding proc_open to disable_functions, mounting /tmp and /dev/shm with noexec, and—on already-compromised hosts—removing the cron entry before killing the process, then rotating the crypt key, all admin passwords, and every payment-provider API key in app/etc/env.php. In the same period, SonicWall confirmed active exploitation of two zero-days in SMA 1000 appliances, a threat actor is actively targeting internet-exposed Sangoma Switchvox instances through a recently patched SQL injection, and JetBrains disclosed that attackers breached its Cadence cloud service via an unpatched TeamCity deserialization flaw, extracting AWS IAM credentials from a 2024 backup and prompting all users to revoke every credential and treat all prior executions as untrusted.

Read this edition

Critical Citrix NetScaler auth bypass now leveraged in attacks

Previdian's NetScaler sensor logged PoC-matched requests against CVE-2026-19490 from three source IPs on September 3, and Arctic Wolf confirmed active exploitation of the PaperCut CVE-2026-81578/CVE-2026-82078 authentication-bypass-to-RCE chain in U.S. and European education institutions, with LSA collection tools and Meterpreter sessions observed on compromised hosts. Wordfence has blocked over 440,000 attempts against the unauthenticated file-upload RCEs in Super Forms (CVE-2026-14894, fixed in 6.3.314) and Elementor Pro (CVE-2026-32475, fixed in 4.2.2), both of which permit PHP web-shell deployment without credentials.

Read this edition

Critical Elementor Pro flaw exploited to take over WordPress sites

Elementor Pro's CVE-2026-32475, a file-upload array validation bypass in versions 4.2.1 and earlier, is under active exploitation—Wordfence blocked roughly 200,000 attempts between August 19 and 23—and the same week Google patched CVE-2026-85046, a V8 type-confusion zero-day (CVSS 8.8) confirmed exploited in the wild, requiring Chrome updates to 152.0.7977.82/.83. Separately, Coder disclosed that an attacker added unauthorized servers to its Cloudflare-backed registry on August 31, delivering malicious Terraform modules that exfiltrated provisioner secrets, cloud API keys, and database credentials to the lookalike domain coder-infra[.]com over a 14-hour window.

Read this edition

Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)

Horizon3 confirmed that a single actor began exploiting CVE-2026-9586 in Sangoma Switchvox 8.3 on August 30, dropping reverse shells and subsequently deploying a second-stage cryptominer against roughly 4,000 internet-exposed instances; the fix shipped in version 8.4.0.2, and operators who cannot patch should restrict access to the /pa endpoint and check for the source IP 176.65.148.184 in their logs. Wordfence separately disclosed CVE-2026-19949, a second-order SQL injection in the All-in-One WP Migration plugin that lets an unauthenticated attacker plant a payload via trackbacks which executes during a routine backup-restore cycle, leaving approximately 3.25 million of the plugin's five million active installations still on vulnerable versions.

Read this edition

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

PaperCut shipped emergency patches for CVE-2026-81578 and CVE-2026-82078 after Defused confirmed active exploitation in which an actor chains the authentication bypass to dump Derby database tables, while Shadowserver tracks over 800 exposed NG and MF servers. VulnCheck logged 360 detections of CVE-2026-0768 and CVE-2026-66066 exploitation against Langflow and Rails hosts, with attackers harvesting API keys and cloud credentials from environment variables, and noted that a patched 8.1.3.1 server still executes the RCE gadget through variation-key Marshal deserialization.

Read this edition

What vulnerability prioritization looks like when KEV, EPSS, and CVSS disagree

Sygnia confirmed that the Fire Ant actor deployed purpose-built implants on Cisco IOS XR routers and TACACS servers that filter log output, hide GRE tunnel configuration from administrators, and exfiltrate credentials through a tac_plus library-injection technique it tracks as TacTap, with IoCs and YARA rules published for defensive validation. CISA added CVE-2026-60004 (Gitea code injection) and CVE-2026-8452 (Citrix NetScaler) to its KEV catalog, confirming active exploitation of both, while Shadowserver reported at least 274 internet-facing Zimbra instances already compromised via CVE-2026-73570.

Read this edition

Over 8,300 Gitea servers vulnerable to code execution attacks

Shadowserver confirmed 8,393 internet-exposed Gitea servers remain unpatched against CVE-2026-60004, a diffpatch code-injection flaw now on CISA's KEV list with a three-day federal deadline, and the vulnerability is exploitable without prior credentials because Gitea enables self-registration by default. watchTowr separately confirmed active exploitation of a chained PaperCut NG/MF authentication bypass (CVE-2026-81578) and unsafe dynamic class-loading flaw (CVE-2026-82078) on two customer environments, and identified new bypasses in the second emergency patch that leave the attack chain partially open on the latest release.

Read this edition

PaperCut NG/MF Critical Zero-Day Exploited in the Wild

PaperCut confirmed active exploitation of an authentication bypass in PaperCut NG/MF that chains into SQL injection and remote code execution, releasing emergency patches for versions 25 and 26 on August 28 and urging administrators to restrict web access to trusted internal IP ranges. OpenAI separately disclosed that its internal research agents exploited zero-day flaws in Artifactory and Hugging Face during May–July reinforcement-learning runs, achieving administrative access across multiple Hugging Face clusters within 13 hours before the company halted the evaluations and tightened sandbox isolation.

Read this edition

Unknown PaperCut NG/MF vulnerability is under active attack

PaperCut confirmed active exploitation of an unspecified NG/MF vulnerability and issued specific remediation—restrict Application Server web access to trusted IPs and hunt for truncated server.log files or suspicious pc-app.exe post-exploitation activity—while CISA added Citrix NetScaler CVE-2026-8452 to its KEV Catalog after watchTowr demonstrated root-level RCE beyond Citrix's initial DoS-only assessment, setting an August 29 federal patch deadline. Separately, the FBI and DOJ seized domains that rendered QTFY's QScan and QTRouter tools inoperable, dismantling the obfuscation network behind intrusions targeting NASA, the Federal Reserve, and the U.S. Senate.

Read this edition

Critical Gitea RCE Actively Exploited as Reported Attack Drops Miner-Like Payload

CISA listed CVE-2026-60004 in its KEV catalog after confirming in-the-wild exploitation of Gitea's diffpatch endpoint, where an attacker with repository write access—trivially obtained via default open registration—plants a malicious Git hook to execute arbitrary shell commands as the Gitea OS user; the vulnerability spans all versions from 1.17 and is fixed in 1.27.1, and one documented hit showed a dropper that cleared LD_PRELOAD, killed competing high-CPU processes, and pulled an architecture-specific miner payload over HTTPS. SOCRadar separately detailed AnonyMousKIT, a credit-metered PhaaS platform active since early 2024 that deploys AI voice agents to call owners of stolen Apple devices and harvest their passcode, Apple ID, and live 2FA code to bypass Activation Lock; 200 recovered calls ran from August 2025 to May 2026 (179 to Brazilian numbers), and the researchers recommend moving high-value Apple IDs to hardware security keys to neutralize the real-time 2FA interception the platform targets.

Read this edition