Weekly Threat Landscape Digest – Week 37

- Cisco UCS UEFI Secure Boot Bypass Vulnerability (CVE-2026-20293)
Overview
- High-severity vulnerability (CVSS 7.1, CWE-749) in the UEFI Shell implementation on Cisco UCS Servers and UCS-based appliances.
- Allows memory-write commands in the UEFI Shell while UEFI Secure Boot is enabled, enabling Secure Boot bypass by modifying UEFI memory variables during boot.
- Public proof-of-concept exploit code is available.
Impact
- Unauthorized software execution by bypassing UEFI Secure Boot validation.
- Potential manipulation of the preboot environment on affected systems.
Affected / Fixed Versions
- Affected: Cisco UCS B/C/E/S/X-Series, ENCS 5000, Unified Edge, and UCS-based appliances (APIC, HyperFlex, Nexus Dashboard, Secure Email/Endpoint/Firewall, ISE SNS, Secure Web, etc.).
- Fixed UCS Manager: 4.3(6h), 6.0(2d). Fixed Intersight (B-Series): 5.4(0.260050), 6.0(2.260143); (X-Series): 5.4(0.260042), 6.0(2.260143).
- Fixed UCS C-Series M5/M6/M7/M8: 4.2(3r), 4.3(6.260054), or 6.0(2.260143). Fixed UCS E-Series M3: 4.04; M6: 4.15.4-b.
- Some fixes scheduled for September or October 2026.
Recommendations
- Update all affected Cisco UCS servers and appliances to fixed firmware/software versions as soon as available.
- Monitor official Cisco advisories for updates and mitigation guidance.
Reference Links
- PAN-OS XML Processing Buffer Overflow – RCE and DoS (CVE-2026-0310)
Overview
- High-severity buffer overflow (CWE-787) in the XML processing of PAN-OS affecting VM-Series, PA-Series firewalls, Panorama, and Cloud NGFW.
- An unauthenticated remote attacker with access to the management web or dataplane interface can exploit this vulnerability.
Impact
- Denial of service or remote code execution with root privileges. Potential firewall compromise and disruption of network security controls.
Affected / Fixed Versions
- PAN-OS 10.2, 11.1, 11.2, 12.1, 12.2: various fixed hotfix/patch versions — see Palo Alto advisory for exact version mapping.
- Prisma Access 10.2, 11.2, 12.1: fixed in respective hotfix versions. Cloud NGFW: contact Palo Alto Networks Support.
Recommendations
- Immediately update affected PAN-OS versions to the latest fixed releases.
- Contact Palo Alto Networks Support for Cloud NGFW updates.
- Monitor management and dataplane interfaces for signs of exploitation.
Reference Links
- Critical Authorization Bypass in MongoDB (CVE-2026-82067)
Overview
- Critical flaw (CVSSv4 9.2) in MongoDB involving improper case sensitivity handling in configuration validation that can cause authorization controls to remain disabled during startup.
- Additional vulnerabilities may lead to unauthorized denial of service, out-of-bounds memory writes, credential exposure, or unauthorized access to collection data.
Impact
- The critical vulnerability can allow unauthorized access to MongoDB deployments by disabling authorization. Additional issues could enable DoS, memory corruption, credential leaks, or unauthorized data access.
Affected / Fixed Versions
- Fixed in MongoDB versions 7.0.41, 8.0.30, 8.2.13, 8.3.9, and 9.0.0-rc2.
Recommendations
- Upgrade MongoDB Server to the latest fixed release immediately.
Reference Links
- Security Updates – Google Chrome 153 (Including Actively Exploited CVE-2026-87491)
Overview
- Chrome versions 153.0.8010.36/.37 (Windows/Mac) and 153.0.8010.36 (Linux) address 230 security vulnerabilities.
- Critical severity flaws in WebGL and Cast; multiple use-after-free and out-of-bounds write issues.
- Active exploitation confirmed in the wild for CVE-2026-87491.
Impact
- Critical vulnerabilities could lead to arbitrary code execution or memory corruption. Active exploitation of CVE-2026-87491 increases risk for unpatched users.
Affected / Fixed Versions
- Windows/Mac: Chrome 153.0.8010.36/.37. Linux: Chrome 153.0.8010.36.
Recommendations
- Update all managed Chrome installations to the latest versions promptly, prioritizing sensitive environments.
Reference Links
- SAP September 2026 Security Updates
Overview
- SAP released September 2026 security updates addressing 19 new vulnerabilities and updating one prior note.
- Affected products include SAP NetWeaver, EPP, CAP, Integration Suite, Commerce Cloud, S/4HANA, UI5, Manufacturing Integration and Intelligence, and others.
- Vulnerabilities cover memory corruption, missing authentication, credential disclosure, privilege escalation, XXE, insecure deserialization, SQL injection, CRLF injection, clickjacking, CSRF, missing authorization, and DoS.
Impact
- Unauthorized access, privilege escalation, credential or sensitive information disclosure, data manipulation, DoS, and potential full system compromise. Most severe flaws allow unauthenticated remote compromise.
Affected / Fixed Versions
- Detailed affected versions and fixes provided in the official SAP advisory.
Recommendations
- Apply SAP’s latest security patches without delay, prioritizing critical and high-severity vulnerabilities.
- Monitor SAP environments for suspicious activity.
Reference Links
- Multiple Critical Vulnerabilities in Fortinet Products
Overview
- CVE-2026-84388 (CVSS 9.1): Improper authentication in FortiPAM Chrome Extension allows unauthenticated attacker to redirect browser traffic.
- CVE-2026-84390 (CVSS 9.6): Authentication bypass using forged/reused JWTs in FortiMonitor OnSight grants unauthorized web portal access.
- CVE-2026-26084 (CVSS 8.9): Improper access control in FortiSandbox allows unauthenticated retrieval of sensitive information.
- CVE-2026-84393 (CVSS 7.3): Improper certificate validation in FortiOS and FortiProxy Agentless ZTNA portal enables man-in-the-middle attacks.
Impact
- Unauthorized browser traffic redirection, authentication bypass, sensitive information retrieval, and man-in-the-middle attacks on network traffic.
Affected / Fixed Versions
- FortiPAM Chrome Extension: fixed in 8.0.1.123+.
- FortiMonitor OnSight: fixed in 7.2.8+.
- FortiSandbox: fixed in 4.4.9, 5.0.6, or 5.2.0+ depending on branch.
- FortiOS and FortiProxy: fixed in 7.6.7+ or 8.0.0+.
Recommendations
- Immediately update all affected Fortinet products to the fixed versions.
- Monitor network traffic for unusual redirections or unauthorized access attempts.
Reference Links
- https://fortiguard.fortinet.com/psirt/FG-IR-26-168
- https://fortiguard.fortinet.com/psirt/FG-IR-26-170
- https://fortiguard.fortinet.com/psirt/FG-IR-26-166
- https://fortiguard.fortinet.com/psirt/FG-IR-26-174
- Multiple Critical RCE Vulnerabilities in Ivanti Neurons for ITSM
Overview
- Seven vulnerabilities in Ivanti Neurons for ITSM including five Critical and two High severity.
- Stem from Deserialization of Untrusted Data (CWE-502) and Missing Authorization (CWE-862).
- Remote attackers, in some cases unauthenticated, can execute arbitrary code.
- CVE-2026-12744, CVE-2026-12745: Unauthenticated RCE (CVSS 9.8). CVE-2026-12650, CVE-2026-12645/46/47: Authenticated RCE (CVSS 9.9). CVE-2026-12651, CVE-2026-12648: Authenticated RCE (CVSS 8.8).
Impact
- Unauthenticated and authenticated remote code execution on affected ITSM servers.
Affected / Fixed Versions
- Cloud/SaaS: version 2026.2 affected; patch applied August 9, 2026.
- On-Prem: versions 2025.2, 2025.3, 2025.4, 2026.1 affected; fixed via September 2026 security patches (2026.2 on-prem release September 21, 2026).
Recommendations
- Identify all Ivanti Neurons for ITSM deployments. Prioritize immediate patching with September 2026 security updates.
Reference Links
- Microsoft September 2026 Patch Tuesday – 972 CVEs Including 2 Actively Exploited Zero-Days
Overview
- Record-breaking September 2026 Patch Tuesday fixes 972 vulnerabilities including 113 Critical and two actively exploited zero-days.
- CVE-2026-81963: Windows Update Stack EoP (CVSS 7.8) — local attacker escalates to SYSTEM via improper link resolution, actively exploited.
- CVE-2026-85880: Windows ALPC EoP (CVSS 7.8) — local attacker escapes AppContainer sandbox via heap buffer overflow, actively exploited.
- Critical RCE vulnerabilities (CVSS 9.8) in Netlogon, DNS Server, DHCP Server, MSMQ, NFS ONCRPC, SSTP VPN, Kerberos authentication, Hyper-V, and more.
- 22 critical Microsoft Office vulnerabilities including no-click RCEs via Outlook Reading Pane/Explorer Preview Pane (CVE-2026-77493, CVE-2026-78510, CVE-2026-78509; CVSS 9.8).
- RDP vulnerability CVE-2026-69518 (CVSS 8.8) enables code execution via crafted clipboard data.
Impact
- Local privilege escalation to SYSTEM without user interaction. Unauthenticated RCE on critical network services and domain controllers. Guest-to-host Hyper-V escape. No-click RCE through email/file preview. Potential domain controller compromise and lateral movement.
Affected / Fixed Versions
- All supported Windows client and server editions. Microsoft Office, SQL Server, Skype for Business, Windows Server roles (DNS, DHCP, MSMQ, NFS, RRAS, Hyper-V, Failover Cluster).
Recommendations
- Deploy September 2026 updates immediately, prioritizing actively exploited zero-days, domain controllers, internet-facing infrastructure, Office clients with preview panes enabled, and Hyper-V hosts.
- Review RDP clipboard configurations. Monitor for suspicious privilege escalation and authentication bypass attempts.
Reference Links
- Critical Unauthenticated Vulnerabilities in JetBrains Hub and YouTrack Helpdesk
Overview
- JetBrains released updates addressing 29 vulnerabilities, including two critical unauthenticated flaws.
- Hub vulnerability enables registering a rogue service to obtain superuser privileges (CVE-2026-86480).
- YouTrack Helpdesk flaw allows unauthenticated account takeover via a forged email address (CVE-2026-86478).
Impact
- Full administrative compromise of JetBrains Hub. Account takeover of YouTrack Helpdesk users. No confirmed active exploitation.
Affected / Fixed Versions
- YouTrack Helpdesk: fixed in 2025.3.161254, 2026.1.14042.
- Hub: fixed in 2026.2.52442.
Recommendations
- Immediately upgrade all affected JetBrains products to the latest fixed versions, prioritizing Hub and YouTrack Helpdesk.
Reference Links
- Multiple Critical Vulnerabilities in Dell Secure Connect Gateway
Overview
- Multiple critical and high-severity vulnerabilities in Dell Secure Connect Gateway Application and Appliance.
- CVE-2026-80172 (CVSS 9.8): Unauthenticated remote attacker can reuse captured requests to gain administrative access and refresh tokens.
- CVE-2026-61410 (CVSS 9.4): Unauthenticated remote command execution via crafted requests.
- CVE-2026-80238 (CVSS 9.3): Low-privileged local attacker can escalate to root and escape container boundaries.
- Additional issues include authentication/authorization flaws, hard-coded credentials, path traversal, OS command injection, SQL injection, SSRF, and privilege escalation.
Impact
- Unauthorized access, remote code execution, privilege escalation, information disclosure, and denial-of-service.
Affected / Fixed Versions
- Affected: Application versions prior to 5.36.00.00; Appliance versions prior to 5.36.00.16.
- Fixed: Application 5.36.00.00+; Appliance 5.36.00.16+.
Recommendations
- Update Dell Secure Connect Gateway to the fixed versions immediately.
Reference Links
- Actively Exploited Critical Adobe Commerce/Magento Zero-Day ‘StyleSmuggler’ (CVE-2026-75650)
Overview
- Emergency out-of-band hotfix released for CVE-2026-75650, a CVSS 10.0 RCE vulnerability in Adobe Commerce and Magento Open Source 2.4.4–2.4.9 and Commerce B2B 1.3.3–1.5.3.
- Active exploitation confirmed since September 4, 2026 — three days before the patch release.
- Attackers deployed web shells, established C2 over TLS and custom NTP-shaped traffic, and dropped malware payloads.
- Indicators include unauthorized PHP code injections, new admin accounts, and anomalous payment failure logs.
Impact
- Complete compromise of affected Adobe Commerce/Magento platforms. Persistent implants running scheduled malicious tasks on compromised stores.
Affected / Fixed Versions
- Affected: Adobe Commerce/Magento Open Source 2.4.4–2.4.9 (including all -2026-aug patch builds); Adobe Commerce B2B 1.3.3–1.5.3.
- Fixed: Emergency hotfix APSB26-146 released September 7, 2026.
Recommendations
- Apply Adobe emergency hotfix APSB26-146 immediately.
- Treat all unpatched internet-facing instances as potentially compromised.
- Scan for unauthorized PHP code, unfamiliar admin accounts, web shells, and anomalous payment email logs.
- Rotate Magento encryption keys and all protected credentials (admin, payment gateway API keys, database, third-party integrations).
- Deploy WAF rules to detect template injection. Enable enhanced logging around payment failure workflows.
Reference Links
- Multiple Vulnerabilities in HPE Telco Network Function Virtualization Orchestrator
Overview
- Vulnerabilities in HPE Telco NFV Orchestrator could allow remote attackers to cause denial of service, gain unauthorized remote access, or exploit memory corruption, buffer overflow, and input validation flaws.
- CVEs include CVE-2026-42527 (CVSS 8.1), CVE-2026-40984, CVE-2026-44432, CVE-2026-5079, CVE-2026-59869 (all 7.5), and others.
Impact
- Potential service disruption and system compromise in affected HPE Telco orchestration environments.
Affected / Fixed Versions
- Affected: HPE Telco NFV Orchestrator version 7.7.0 and earlier; HPE Telco SDC.D version prior to 2.8.0.
- Fixed: NFV Orchestrator 7.8.0+; SDC.D 2.8.0.
Recommendations
- Update HPE Telco NFV Orchestrator to v7.8.0 and SDC Designer to v2.8.0.
Reference Links
- Critical ASUS Control Center Enterprise Authentication Bypass (CVE-2026-75754)
Overview
- Missing authentication, SSRF, and hard-coded credentials in ASUS Control Center Enterprise (ACC) prior to version 3.1.0.9.
- An unauthenticated attacker sends an HTTP request to obtain an encryption key, triggering a local service to enable SSH on port 2222, then uses hard-coded credentials to gain root shell access.
Impact
- Read, modify, or delete data. Potential full system compromise of devices managed through ASUS Control Center.
Affected / Fixed Versions
- Affected: ASUS Control Center Enterprise versions earlier than 3.1.0.9.
- Fixed: Version 3.1.0.9 and later.
Recommendations
- Update ASUS Control Center Enterprise to version 3.1.0.9 or later immediately.
- Review access logs for unusual SSH connections on port 2222.
Reference Links
- Multiple Security Vulnerabilities in Roundcube Webmail
Overview
- Roundcube Webmail 1.6.19 and 1.7.4 address 12 vulnerabilities including zero-click stored XSS, SSRF, email header injection, CSS injection/smuggling, remote-content filtering bypasses, cross-user access-control flaws, and URL validation bypasses.
Impact
- XSS execution without user interaction, SSRF, email header manipulation, CSS injection, loading blocked external resources, unauthorized address book access, and bypass of URL restrictions.
Affected / Fixed Versions
- Affected: Roundcube Webmail 1.6 LTS and 1.7 branches prior to 1.6.19 and 1.7.4.
- Fixed: Roundcube Webmail 1.6.19 and 1.7.4.
Recommendations
- Upgrade to Roundcube Webmail 1.6.19 or 1.7.4 immediately.
Reference Links
- Skullcandy Dime 3 Bluetooth Zero-Auth Pairing Vulnerability (CVE-2025-20701)
Overview
- The Skullcandy Dime 3 earbuds (firmware 1.0.0.28) accept Bluetooth Classic pairing without owner approval due to insecure BR/EDR pairing and NoInputNoOutput I/O capability.
- Attackers can pair from Bluetooth range without PIN, passkey, or user interaction, gaining trusted device status.
Impact
- Attackers can hijack audio playback (A2DP) and potentially access Hands-Free/Headset profiles enabling live microphone eavesdropping.
Affected / Fixed Versions
- Affected: Skullcandy Dime 3 firmware 1.0.0.28. Fixed firmware reportedly in 1.0.0.30 but no consumer-accessible update mechanism exists.
Recommendations
- Avoid using affected earbuds near unknown people within Bluetooth range. Stay alert for unexpected pairing announcements and remove unfamiliar devices from paired-device lists.
Reference Links
- USN-8571-2: Apache HTTP Server Regression and Vulnerabilities
Overview
- A regression was introduced after USN-8571-1 fixes causing Apache HTTP Server to fail when HTTP/2 proxying was enabled.
- Vulnerabilities in mod_authn_socache, mod_proxy_ajp, mod_proxy_html, mod_dav_fs, mod_xml2enc, mod_ssl, mod_proxy_ftp, and mod_http2 include DoS, HTTP response splitting, information disclosure, arbitrary code execution, and use-after-free.
Impact
- Remote attackers could cause DoS, inject arbitrary HTTP headers, obtain sensitive information, or execute arbitrary code.
Affected / Fixed Versions
- Ubuntu 16.04 LTS, 18.04 LTS, and 20.04 LTS.
Recommendations
- Apply the updated package resolving the regression and all listed vulnerabilities.
Reference Links
- Active Exploitation of JFrog Artifactory Vulnerabilities (CVE-2026-42016, CVE-2026-42018, CVE-2026-82329)
Overview
- Wiz Research reports active exploitation of three critical/high-severity vulnerabilities in JFrog Artifactory.
- Attackers chain these vulnerabilities to bypass authentication and obtain administrative privileges.
Impact
- Full administrative control over vulnerable Artifactory instances, potentially leading to severe compromise and further misuse.
Recommendations
- Apply security patches from JFrog addressing all three CVEs immediately.
- Monitor for suspicious activity indicative of unauthorized access and privilege escalation.
Reference Links
- Cisco FMC Flaws Exploited by Ransomware Gang and State-Sponsored Hackers
Overview
- Cisco Talos reported exploitation of two recently patched vulnerabilities in Secure Firewall Management Center (FMC).
- Three distinct threat actor groups including ransomware gangs and state-sponsored hackers are actively exploiting these flaws.
Impact
- Unauthorized access and potential full control of FMC systems, disrupting network security infrastructure and facilitating further malicious activities.
Affected / Fixed Versions
- Vulnerabilities patched in recent Cisco FMC updates.
Recommendations
- Immediately apply the latest Cisco FMC security patches.
- Monitor network traffic and logs for signs of exploitation.
Reference Links
- USN-8745-1: KissFFT Vulnerabilities
Overview
- KissFFT mishandles certain large Fourier transform sizes on 32-bit architectures enabling potential crashes or arbitrary code execution.
- Additional vulnerability involves incorrect handling of multidimensional Fourier transform sizes.
Impact
- Denial of service via application crashes. Potential arbitrary code execution.
Recommendations
- Apply available Ubuntu security updates to mitigate risks.
Reference Links
- USN-8748-1: Linux Kernel (NVIDIA) Vulnerabilities
Overview
- Multiple security flaws in the Linux kernel affecting hardware crypto device drivers, NVIDIA Tegra memory controller, network drivers, filesystems (GFS2, OCFS2, SMB), B.A.T.M.A.N. meshing, Ceph, and networking protocols (IPv4, IPv6, Netfilter, Open vSwitch, RxRPC, SCTP, TIPC).
- CVEs tracked from CVE-2026-52914 to CVE-2026-64531.
Impact
- An attacker could potentially exploit these flaws to compromise the affected system.
Recommendations
- Apply the security update provided by Ubuntu promptly.
Reference Links
- BlueMoon Exploit Kit: Windows and Chrome Zero-Days Used by Four Spy Groups
Overview
- Multiple cyber-espionage groups are using the ‘BlueMoon’ exploit kit which chains vulnerabilities targeting Microsoft Windows and Google Chrome.
- First known use in the wild linked to China-aligned APT31. Four distinct spy groups deployed BlueMoon within a week.
Impact
- Enables attackers to exploit multiple Windows and Chrome vulnerabilities for system compromise, facilitating espionage activities.
Recommendations
- Apply latest security patches for Microsoft Windows and Google Chrome.
- Monitor for exploitation attempts related to BlueMoon and associated threat actors.
- Employ intrusion detection capable of recognizing multi-stage exploit chains.
Reference Links
- https://www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/
- https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html
- Check Point Two Critical VPN Certificate Flaws Enabling Unauthenticated RCE (CVSS 9.8)
Overview
- Check Point patched two critical vulnerabilities in firewall and management products related to VPN certificate handling.
- Both flaws enable unauthenticated RCE under specific conditions; one affects Security Gateways only, the other affects both Security Gateways and management products.
Impact
- Remote attackers can execute arbitrary code without authentication on affected Check Point devices.
Recommendations
- Apply the latest patches from Check Point immediately.
Reference Links
- CISA Flags Exploited Cisco, Citrix, Fortinet Flaws – Sept. 12 Federal Patch Deadline
Overview
- CISA added three critical vulnerabilities affecting Cisco, Citrix, and Fortinet to its Known Exploited Vulnerabilities catalog.
- FCEB agencies mandated to patch by September 12, 2026. CVE-2026-20079 has CVSS score of 10.0.
Impact
- Critical severity and active exploitation pose significant threats to affected organizations.
Recommendations
- Apply security patches for the identified vulnerabilities immediately by the federal deadline.
- Prioritize patch management on Cisco, Citrix, and Fortinet products.
Reference Links
- Cisco IOS XR Software Security Hardening Release: September 2026
Overview
- Cisco internal security review of IOS XR uncovered multiple vulnerabilities grouped by CWE with aggregate CVE IDs. No active exploitation known. No workarounds available.
Impact
- Critical security impact rating.
Affected / Fixed Versions
- Specific affected and fixed versions detailed in the Cisco advisory.
Recommendations
- Apply the released software updates promptly.
Reference Links
- WatchGuard Firebox RCE Flaw Now Exploited in Ransomware Attacks
Overview
- CISA confirmed active exploitation of a critical RCE vulnerability in WatchGuard Firebox firewalls by ransomware threat actors.
- Attackers can execute arbitrary code remotely on affected devices, enabling ransomware deployment.
Impact
- Full system compromise enabling deployment of ransomware or other malicious activities. Critical infrastructure and enterprise networks at significant risk.
Affected / Fixed Versions
- Specific affected versions and patches detailed in WatchGuard’s original security advisory.
Recommendations
- Immediately apply available patches and updates from WatchGuard.
- Monitor network traffic for indicators of compromise.
- Employ enhanced firewall and endpoint detection strategies.
Reference Links
- Chromium V8 Type Confusion – Exploit in the Wild (CVE-2026-85046)
Overview
- A type confusion vulnerability in the V8 JavaScript engine used by Chromium. Google Chrome has publicly acknowledged the existence of an exploit in the wild.
- Microsoft Edge (Chromium-based) includes the patched version.
Impact
- Successful exploitation could lead to arbitrary code execution or other security breaches.
Recommendations
- Update to the latest Chromium-based browser versions immediately.
Reference Links
- Microsoft Cloud Web Applications Threat Matrix
Overview
- Microsoft introduced the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework for cloud-hosted web applications and serverless platforms.
- Organizes attack techniques across resource development, initial access, execution, persistence, privilege escalation, defense evasion, credential access, discovery, lateral movement, collection, and impact.
- Covers subdomain takeover, code injection in repositories, compromised registry images, exposed admin interfaces, serverless trigger injection, and misuse of deployment credentials.
Impact
- Threat actors can gain footholds enabling code execution, data access, and persistence. Risks include service hijacking, RCE, unauthorized access, data exfiltration, and long-term cloud presence.
Recommendations
- Evaluate and secure DNS records to prevent subdomain takeover. Patch public-facing web applications. Control repository access and monitor commits. Validate container images before deployment. Harden admin interfaces and deployment credentials.
Reference Links
- CVE-2026-0304: Cortex XDR Broker VM Privilege Escalation (Medium)
Overview
- A medium severity privilege escalation vulnerability in Cortex XDR Broker VM allows an attacker with limited privileges to escalate permissions.
Impact
- Exploitation can lead to increased access rights, potentially enabling further attacks or unauthorized system changes.
Recommendations
- Apply available security updates and patches from Palo Alto Networks.
Reference Links
- CVE-2026-0308: PAN-OS Stored XSS in Web Interface (Low)
Overview
- A stored XSS vulnerability in the PAN-OS web interface allows an attacker to inject malicious scripts that are stored and executed when viewed by other users.
Impact
- Potential for session hijacking, defacement, or redirection of users to malicious sites.
Recommendations
- Apply security updates from Palo Alto Networks as available. Implement additional input validation and sanitization where possible.
Reference Links
- CVE-2026-0309: PAN-OS Authenticated Command Injection in CLI with Luna HSM (Medium)
Overview
- Authenticated command injection in the PAN-OS CLI when Luna HSM is configured; attackers with CLI access could execute arbitrary commands.
Impact
- Potential unauthorized command execution potentially leading to system compromise.
Recommendations
- Review Luna HSM configuration in PAN-OS CLI. Apply available patches or mitigations from Palo Alto Networks.
Reference Links
- Cisco Secure FMC Software Authentication Bypass Vulnerability
Overview
- A vulnerability in the Cisco Secure FMC web interface allows unauthenticated remote attackers to bypass authentication via an improper system process created at boot time, then execute script files with root access.
Impact
- Execution of scripts and commands with root privileges. High risk given potential for full system compromise.
Affected / Fixed Versions
- Software updates addressing this vulnerability have been released by Cisco.
Recommendations
- Apply the released Cisco security updates promptly. Ensure the FMC management interface is not exposed to the public internet. No workarounds available.
Reference Links
- Microsoft September 2026 Patch Tuesday – 974 CVEs (Record-Breaking)
Overview
- Microsoft released patches addressing a record-breaking 974 CVEs. Two vulnerabilities actively exploited in the wild. An additional 58 vulnerabilities have a high likelihood of exploitation.
Impact
- Active exploitation increases risk of system compromise across a broad range of affected software.
Recommendations
- Prioritize patching the actively exploited vulnerabilities. Apply all relevant patches promptly.
Reference Links
- Cisco Secure Email S/MIME Ciphertext Decryption Vulnerabilities
Overview
- Multiple vulnerabilities in Cisco Secure Email S/MIME decryption functionality. Insufficient message integrity validation allows man-in-the-middle exploitation to recover plaintext from encrypted email messages. No known workarounds.
Impact
- Unauthenticated remote attacker can obtain plaintext of encrypted email communications.
Recommendations
- Apply Cisco’s security updates once available. Monitor Cisco resources for further updates.
Reference Links
- Critical N-able N-central Vulnerability Actively Exploited
Overview
- A critical vulnerability in the N-able N-central RMM console allows unauthenticated attackers to gain full administrative (‘god-mode’) access. Active exploitation has been reported.
Impact
- Attackers can execute actions with full administrative privileges on the N-central console, posing severe risks to managed systems and networks.
Recommendations
- Apply security updates from N-able to remediate the vulnerability immediately.
- Monitor network traffic and system logs for indicators of compromise.
- Limit external access to the N-central console until the vulnerability is mitigated.
Reference Links
AI Threat Landscape
- FBI: AI Is Bolstering Adversaries – Focus on Cyber Basics and Patching
Overview
- FBI cyber officials report AI is enhancing threat actors’ speed and capabilities, leading to an exponential rise in AI-enabled offensive actions.
- FBI’s upcoming cyber strategy includes a dedicated AI section to accelerate malware analysis, victim notifications, and adversary infrastructure mapping.
- FBI emphasizes fundamental cybersecurity hygiene: multifactor authentication and ongoing patching, remain effective against AI-augmented threats.
Impact
- AI is accelerating vulnerability discovery and increasing the pace and scale of attacks. Rapid escalation necessitates continuous, risk-based patching.
Recommendations
- Implement basic controls including multifactor authentication.
- Adopt continuous, risk-driven patch management practices.
- Maintain vigilance on core cyber hygiene measures.
Reference Links
- Anthropic: Claude AI Misused by State-Sponsored and Criminal Groups to Automate Cyberattacks
Overview
- Anthropic’s Threat Intelligence team revealed extensive misuse of Claude AI by state-sponsored, criminal, and hacktivist groups.
- Key actors: GTG-20006 (Russian Midnight Blizzard-linked) and GTG-50014 (ShinyHunters-affiliated), and GTG-10007 (Chinese exploit foundry producing dozens of zero-days monthly with AI agent swarms).
- Techniques include self-healing malware, DNS hijacking, automated WhatsApp account takeovers, mass credential harvesting, SaaS supply-chain breaches, and large-scale surveillance platforms.
- AI agents monitor and adapt malware in real-time to evade security products.
- Anthropic responded by banning accounts, enhancing abuse detection, and sharing IOCs with law enforcement.
Impact
- Multi-national espionage against governments, military, and critical infrastructure. Theft of terabytes of data. Rapid lateral movement across hundreds of corporate tenants. Democratization of advanced attack methods enabling smaller groups to operate at scale.
Recommendations
- Treat AI-enhanced cyberattacks as a baseline threat level.
- Enhance detection engineering to outpace autonomous, self-adapting AI attacks.
- Monitor for indicators of compromise linked to AI agent frameworks.
- Collaborate with AI vendors and law enforcement to share intelligence.
Reference Links
- https://cybersecuritynews.com/claude-ai-agents-used-to-automate-cyberattacks/
- https://cyberscoop.com/anthropic-report-ai-enabled-cyber-attacks/
- Microsoft: AI-Assisted Executive Impersonation and Invoice Fraud Campaign
Overview
- Microsoft observed a large campaign using generative AI to craft sophisticated executive impersonation and invoice fraud emails.
- Over one million emails sent using third-party email infrastructure targeting U.S. enterprises, especially IT services and consumer goods.
- Threat actors impersonated CEOs sending payment approval emails requesting ACH transfers of ~$50,000, including fabricated ServiceNow-branded invoices and fake forwarded email threads.
- Indicators of generative AI use included AI-style HTML comments, structured template labeling, and uniform narrative structure with personalized details.
Impact
- Financial theft through social engineering targeting finance departments. AI-generated content increases risk of successful fraud and evasion of traditional detection.
Recommendations
- Employ layered email protections: proper authentication, spoof protection, and mail-flow connectors.
- Use Microsoft Defender for Office 365 and Zero-hour Auto Purge.
- Train finance personnel to verify payment requests through secondary channels.
Reference Links
- PuzzleMask: Plain Prose as a Covert AI Attack Vector
Overview
- Researchers introduced PuzzleMask — a prompt-crafting technique embedding policy-violating payloads in plain English prose that bypasses quick LLM-based policy checks.
- Exploits two-stage LLM pipelines: a gatekeeper LLM conducts rapid policy checks; the stronger target model detects and processes hidden instructions.
- Payloads hidden in natural language evade the gatekeeper while the target model processes them.
- Tested against multiple LLM gatekeepers, PuzzleMask succeeded in bypassing all of them. Can be combined with jailbreak prompts.
Impact
- Enables submission of disallowed instructions to sensitive LLMs without blocking. Could lead to file encryption, copyright content leaking, or ignoring safeguards. Undermines defense-in-depth relying on fast policy enforcers.
Recommendations
- Enhance gatekeeper LLMs to perform deeper analysis or incorporate output monitoring.
- Use paraphrasing LLMs to normalize inputs before policy checks.
- Augment policies to capture obfuscated payload constructs.
- Employ defense-in-depth combining multiple complementary safeguards.
Reference Links
- WordPress AI-Driven Security Review Blocks Malicious Plugin Updates
Overview
- WordPress implemented an AI-driven security review analyzing every plugin release during a six-hour cooldown period before distribution.
- Multiple AI models in parallel alongside Jetpack Scan generate a consolidated security risk score; releases exceeding a risk threshold are automatically blocked.
- Triggered by a real July 28, 2026 incident where a backdoor was inserted into a plugin update affecting ~20,000 active installations — the AI blocked distribution.
Impact
- Significantly reduces risk of malicious plugin updates propagating at scale. Enhances supply-chain security by proactively blocking high-risk code changes.
Affected / Fixed Versions
- AI review process applies to all plugin and theme releases on WordPress.org starting June 5, 2026.
Recommendations
- Plugin authors should review AI-generated findings and promptly fix identified issues. Publish corrected releases rather than relying on manual appeals.
Reference Links
- GitSpawn: AI Coding Agents Vulnerable to Malicious Git Config RCE
Overview
- GitSpawn vulnerability affects AI coding agents including Claude Code, Codex, Cursor, Goose, Qwen Code, Grok Build, and Hermes, allowing malicious Git repository configurations to trigger arbitrary code execution before trust prompts.
- AI-assisted ransomware attacked an enterprise network in under 10 hours using autonomous agents to map internal systems, mine code repositories, obtain root credentials, and abuse build pipelines and cloud resources.
Impact
- Remote code execution under the developer context via AI coding tools, risking software development security. AI-assisted ransomware significantly reduces intrusion time and human effort required.
Recommendations
- Implement rigorous validation of Git repository configurations to mitigate GitSpawn attacks.
- Enhance monitoring of AI agent activities within development and operational environments.
- Apply defensive measures and patches for exposed systems.
Reference Links
- Zscaler Launches Agentic SOC
Overview
- On September 9, 2026, Zscaler announced Zscaler Agentic SOC — an AI-first security operations approach designed to detect, investigate, and respond to threats at machine speed.
- Combines Zscaler telemetry with specialized AI agents for alert triage, investigation, attack-path analysis, verdict generation, and response recommendations.
- Integration with Zero Trust controls enables automated containment and closed-loop remediation.
Impact
- AI-driven attacks reduce time for manual investigation. Agentic SOC can reduce repetitive analyst workload and accelerate identification of high-priority threats. Potential to reduce MTTD and MTTR.
Recommendations
- Evaluate Agentic SOC capabilities for alert triage, investigation, enrichment, and response automation.
- Maintain human oversight for high-impact containment activities.
- Apply least-privilege access to AI agents. Maintain detailed audit logs of AI-generated decisions.
Reference Links
- SANS: Security Risks and Opportunities of the Agentic SOC
Overview
- SANS Institute presented on ‘The Agentic SOC: Defending With, and Against, Autonomous AI’ on September 8, 2026.
- Agentic AI systems can perform alert triage, threat intelligence enrichment, threat hunting, investigation, and response activities with increasing autonomy.
- AI agents may create sub-agents, temporarily hold credentials, and delegate trust across multiple systems.
- Increased autonomy introduces risks: prompt injection, excessive privileges, agent manipulation, and complex machine-to-machine trust relationships.
Impact
- Significantly accelerates SOC investigations and reduces repetitive analyst workloads. Compromised or manipulated AI agents could misuse trusted access without requiring traditional credential theft. Zero Trust architectures may need to evolve to safely support autonomous AI agents.
Recommendations
- Apply Zero Trust principles to AI agents and agent-to-agent communications. Restrict agents to minimum required privileges.
- Require human approval for sensitive, destructive, or business-impacting response actions.
- Maintain complete monitoring and audit trails of AI-agent activities.
- Protect AI workflows against prompt injection. Regularly review agent permissions and trust relationships.
Reference Links
- Autonomous SOC: Investigation vs. Autonomous Response
Overview
- Command Zero analysis (September 6, 2026) examining the distinction between autonomous security investigation and autonomous response.
- AI-driven systems can autonomously gather evidence, correlate telemetry, develop investigation timelines, and produce analyst-ready findings.
- Autonomous response introduces greater operational risk because AI-generated actions may directly affect users, endpoints, infrastructure, and business services.
- The emerging SOC model emphasizes greater autonomy for investigation while maintaining stronger governance around response actions.
Impact
- Autonomous investigations can significantly reduce manual work. AI-powered investigations process large volumes of telemetry faster than manual workflows. Incorrect autonomous response actions may disrupt legitimate users or critical infrastructure.
Recommendations
- Prioritize autonomous AI for investigation, evidence collection, correlation, and enrichment.
- Introduce autonomous response gradually based on risk and business impact.
- Require analyst approval for high-risk containment or remediation.
- Define clear boundaries for AI-independent actions. Implement rollback mechanisms. Maintain full audit trails.
Reference Links