Cybersecurity topic

Ransomware

Operational reporting on ransomware crews, extortion campaigns, initial-access paths, victim disclosures, and defensive lessons for enterprise responders.

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

Cisco confirmed active exploitation of CVE-2026-76460, an authentication bypass in an ISE API endpoint that lets a remote unauthenticated attacker bypass the web management interface; the fix requires upgrading to 3.3 Patch 12, 3.4 Patch 7, or 3.5 Patch 4, and no workarounds exist. The Shadowserver Foundation separately observed active exploitation of CVE-2026-89026 in Issabel Framework, where a hard-coded HS256 JWT signing key in pbxapi/index.php lets an unauthenticated attacker forge bearer tokens and execute arbitrary OS commands as the Asterisk user; a patch shipped August 1, 2026, replaces the key with one stored in /etc/issabel.conf.

Read this edition

Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited

Cisco confirmed that state-sponsored and ransomware actors are actively exploiting CVE-2026-20079, an authentication bypass in Secure Firewall Management Center, and N-able shipped an emergency hotfix for CVE-2026-86218, a pre-auth RCE in N-central already exploited in the wild. Sophos separately reported a Linux rootkit on compromised F5 BIG-IP APM appliances that keeps its web shell in memory to evade disk-based detection, while the Dutch NCSC issued an imminent-exploitation warning for two Check Point VPN flaws (CVE-2026-85102, CVE-2026-85103) for which no public proof-of-concept exists yet.

Read this edition

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

PaperCut released maintenance builds 26.0.5, 25.0.13, and 24.1.10 to replace emergency patches for CVE-2026-81578 and CVE-2026-82078, which GreyNoise and Blackpoint Cyber confirmed a suspected Russian-speaking actor used to breach at least 395 organizations via AI-agent-driven attacks. Cisco confirmed three threat clusters are exploiting CVE-2026-20079 and CVE-2026-20316 in Secure FMC to deploy Qilin ransomware and a Sandworm-linked Cyclops Blink variant, with hotfixes available and CISA mandating federal patching by September 12.

Read this edition

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco confirmed on Wednesday that CVE-2026-20079, a CVSS 10.0 authentication bypass in Secure FMC that lets an unauthenticated remote attacker execute root-level commands via crafted HTTP requests, is under active exploitation, with no workarounds available and CISA ordering federal civilian agencies to patch by September 12. Proofpoint separately documented four espionage clusters deploying the BlueMoon kit—chaining two V8 Chrome flaws with a Windows ALPC heap overflow—within a single week, and CISA has set KEV patch deadlines of September 18 through 23 for the three CVEs while publishing process-tree, file, and scheduled-task IOCs for organizations to hunt after applying browser and OS updates.

Read this edition

SonicWall warns of actively exploited SMA1000 zero-day flaws

SonicWall confirmed active exploitation of a zero-day chain—CVE-2026-83548, an SSRF-to-command-injection flaw in the WorkPlace interface, and CVE-2026-83549, a command injection in the Management Console—against SMA1000 6210, 7210, and 8200v appliances; the vendor shipped a hotfix and advises re-imaging, credential rotation, and TOTP reset where IOCs are detected, though it has not yet published those IOCs. In parallel, Horizon3.ai and SRA Labs observed in-the-wild exploitation of CVE-2026-9586, an unauthenticated SQL injection in Sangoma Switchvox 8.3 yielding PostgreSQL superuser code execution; the patch shipped July 14, six weeks before the first observed attacks on August 30, and roughly 4,000 instances remain internet-exposed.

Read this edition

Unknown PaperCut NG/MF vulnerability is under active attack

PaperCut confirmed active exploitation of an unspecified NG/MF vulnerability and issued specific remediation—restrict Application Server web access to trusted IPs and hunt for truncated server.log files or suspicious pc-app.exe post-exploitation activity—while CISA added Citrix NetScaler CVE-2026-8452 to its KEV Catalog after watchTowr demonstrated root-level RCE beyond Citrix's initial DoS-only assessment, setting an August 29 federal patch deadline. Separately, the FBI and DOJ seized domains that rendered QTFY's QScan and QTRouter tools inoperable, dismantling the obfuscation network behind intrusions targeting NASA, the Federal Reserve, and the U.S. Senate.

Read this edition

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Prioritize immediate patching of Check Point Management Servers and JFrog Artifactory instances due to active exploitation and public PoCs. We are seeing a dangerous convergence of AI agents autonomously exploiting zero-days and supply-chain compromises in npm, requiring tighter secrets management and dependency auditing. Additionally, critical RCEs in Gitea and vBulletin, alongside VMware VM escape flaws, necessitate an urgent update cycle across developer and virtualization stacks.

Read this edition

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

Immediate priority is patching the CVSS 10.0 Arista VeloCloud Orchestrator flaw and auditing for FastJson RCE, both of which are seeing active exploitation. We are also seeing a surge in high-impact identity risks via AD CS PoCs and cloud 'Confused Deputy' flaws. Additionally, the emergence of autonomous AI agents in real-world espionage underscores an urgent need to evaluate agentic browser security.

Read this edition