Weekly Threat Landscape Digest – Week 39

HawkEye CSOC Riyadh
  1. Actively Exploited Check Point Security Management Directory Traversal & File Upload (CVE-2026-93616, CVSS 9.8)

Overview

  • Critical pre-authentication directory traversal and arbitrary file upload vulnerability in Check Point Security Management, Multi-Domain Management, Log, Multi-Domain Log servers, and SmartEvent.
  • Allows unauthenticated remote attackers to upload and execute arbitrary scripts or load arbitrary Java classes.
  • Active exploitation confirmed since July 23, 2026. LivePatch Takes 28/29 do NOT mitigate this vulnerability.

Impact

  • Complete compromise of Management Servers, enabling control of security management operations and policies.

Affected / Fixed Versions

  • Affected: R82.20, R82.10 (JHF Take ≤44), R82 (JHF Take ≤126), R81.20 (JHF Take ≤166), R81.10 (JHF Take ≤190, EoS), R80.x/R81 (EoS).
  • Fixed (hotfixes issued September 22, 2026): R82.20 Security Hotfix; R82.10 JHF Take 45+; R82 JHF Take 127+; R81.20 JHF Take 170+; R81.10 JHF Take 192+.
  • End-of-support releases require upgrade to supported versions.

Recommendations

  • Immediately apply appropriate security hotfixes to all affected servers.
  • Restrict access to TCP/19009 to trusted IP addresses only.
  • Place Management Servers behind Check Point Security Gateway/Firewall.
  • Monitor logs for oversized usernames in cpm.elg* logs, directory traversal patterns (../../../../), and unexpected core dumps.
  • Preserve logs and forensic evidence if compromise is suspected.

Reference Links

  1. SolarWinds Observability Self-Hosted RCE Vulnerabilities (CVE-2026-28324 CVSS 9.8, CVE-2026-28325 CVSS 8.8)

Overview

  • CVE-2026-28324: Insufficient integrity validation enabling unauthenticated RCE in non-default configurations.
  • CVE-2026-28325: Insecure deserialization of untrusted data causing RCE when certain communication modes are enabled.

Impact

  • Unauthenticated remote attackers can execute arbitrary code on affected systems, leading to full system compromise.

Affected / Fixed Versions

  • Affected: SolarWinds Observability Self-Hosted version 2026.2.2 and below.
  • Fixed: Version 2026.2.3 and later.

Recommendations

  • Update SolarWinds Observability Self-Hosted to version 2026.2.3 or later immediately.

Reference Links

  1. Actively Exploited F5 BIG-IP APM OAuth Heap Buffer Overflow RCE (CVE-2026-94127, CVSS 9.8)

Overview

  • Critical heap-based buffer overflow in BIG-IP APM OAuth functionality when APM access policy and OAuth profile are configured on a virtual server with BIG-IP APM as OAuth Authorization Server.
  • Allows unauthenticated remote code execution. Active exploitation confirmed by F5.

Impact

  • Remote code execution enabling full system compromise. IoCs include repeated OAuth authentication failures (10+), suspicious post-auth commands, TMM SIGABRT events, unexpected TMM core files.

Affected / Fixed Versions

  • Affected: BIG-IP APM 21.1.0, 17.5.0–17.5.1, 17.1.0–17.1.3.
  • Fixed: Hotfix-BIGIP-21.1.0.2.0.30.22-ENG.iso (21.1.0); Hotfix-BIGIP-17.5.1.9.0.160.12-ENG.iso (17.5.1); Hotfix-BIGIP-17.1.3.5.0.41.14-ENG.iso (17.1.3).

Recommendations

  • Immediately apply the appropriate F5 hotfix to affected systems.
  • Contact F5 Support to obtain and apply an iRule mitigation for affected virtual servers.
  • Monitor BIG-IP APM and audit logs for indicators of compromise. Isolate and perform incident response if compromise is suspected.

Reference Links

  1. HPE Networking ALE Critical Remote Access and Arbitrary File Write (CVE-2026-76708, CVE-2026-76709, CVSS 9.8)

Overview

  • 10 vulnerabilities in HPE Networking Analytics and Location Engine (ALE) including two critical CVSS 9.8 flaws.
  • CVE-2026-76708: Hard-coded credentials enable unauthenticated remote access to management interface and underlying OS.
  • CVE-2026-76709: Internal administrative component flaw allows unauthenticated remote arbitrary filesystem writes with elevated privileges.
  • Additional high-severity issues include information disclosure, DoS, and RCE.

Impact

  • Full system compromise via unauthenticated management access or arbitrary filesystem write. Information disclosure and service disruption from additional issues.

Affected / Fixed Versions

  • Affected: HPE Networking ALE version 5.0.0.0 and earlier.
  • Fixed: ALE version 5.1.0.0.

Recommendations

  • Immediately upgrade ALE to version 5.1.0.0.
  • Restrict ALE management interface access to trusted administrative networks.
  • Avoid exposing ALE management interfaces to untrusted networks.
  • Review authentication configurations and monitor for unauthorized accounts or filesystem changes.

Reference Links

  1. Exim 4.100.1 – Heap Corruption, Stack Disclosure, SMTP Smuggling, and Use-After-Free

Overview

  • Exim 4.100.1 addresses four vulnerabilities: heap corruption via Proxy Protocol v1 (OOB reads and NUL-byte writes), stack data disclosure via Proxy Protocol v2 (sensitive memory contents), SMTP smuggling (message content discrepancy), and use-after-free in GnuTLS TLS-on-connect processing (process crash).

Impact

  • Remote attackers can cause heap corruption, information disclosure, message manipulation, or denial of service.

Affected / Fixed Versions

  • Heap corruption/stack disclosure: Exim 4.83–4.100. SMTP smuggling: Exim through 4.100. Use-after-free: Exim 4.98–4.100.
  • Fixed: Exim version 4.100.1.

Recommendations

  • Upgrade all affected Exim servers to version 4.100.1 as soon as possible.

Reference Links

  1. IBM MQ Critical Heap Buffer Overflow and Underflow (CVE-2026-10747 CVSS 10.0, CVE-2026-10858 CVSS 9.9)

Overview

  • CVE-2026-10747 (CVSS 10.0): Heap buffer overflow during protocol message processing allowing unauthenticated pre-auth DoS or arbitrary code execution.
  • CVE-2026-10858 (CVSS 9.9): Heap buffer underflow via multi-segment messages enabling remote DoS.

Impact

  • Remote unauthenticated attackers can disrupt IBM MQ services or execute arbitrary code.

Affected / Fixed Versions

  • IBM MQ Appliance 9.4 LTS (9.4.0.0–9.4.0.25) → fixed in 9.4.0.26+.
  • IBM MQ Appliance 9.4 CD (9.4.1.0–9.4.5.2) → fixed in 9.4.5.3+ (M2002) or 10.0.0.5+ (M2003).
  • IBM MQ Appliance 10.0 (10.0.0.0–10.0.0.1) → fixed in 10.0.0.5+.
  • IBM MQ for HPE NonStop (8.1.0–8.1.0.40) → fixed in 8.1.0.41.

Recommendations

  • Update all affected IBM MQ products to specified fixed versions immediately.

Reference Links

  1. Actively Exploited Zyxel GS1900 Stack Buffer Overflow RCE (CVE-2026-7273, CVSS 8.8)

Overview

  • Stack-based buffer overflow in CGI program of Zyxel GS1900 series switches allowing unauthenticated LAN-accessible attackers to execute arbitrary OS commands via crafted HTTP requests.
  • Actively exploited in the wild.

Impact

  • Remote unauthenticated code execution and potential full compromise of affected network switches.

Affected / Fixed Versions

  • GS1900-8 through GS1900-48HPv2 various models — all affected through firmware version x.90(xxxx.1)C0; fixed in x.90(xxxx.2)C0. See advisory for model-specific versions.

Recommendations

  • Upgrade all affected Zyxel GS1900 switches to fixed firmware versions.
  • Restrict management interface and HTTP access to trusted LAN hosts.
  • Monitor for anomalous HTTP requests and unexpected command execution.

Reference Links

  1. MongoDB Integration Libraries Multiple Critical Vulnerabilities (CVE-2026-93762, CVSS 9.8)

Overview

  • 14 vulnerabilities in Mongoid, MongoDB C Driver, and Entity Framework Core Provider including field-name method injection, unvalidated method-name dispatch, server-side JavaScript injection, NoSQL injection, heap overflow, cross-principal document manipulation, DoS, and plaintext credential persistence.
  • No confirmed exploitation or public PoC reported.

Impact

  • Unauthorized data deletion/modification, arbitrary server-side JavaScript execution, DoS, memory corruption, credential cracking, and sensitive data exposure in plaintext.

Affected / Fixed Versions

  • Mongoid: 7.2.0–9.1.0. MongoDB C Driver: 1.24.0–2.4.0. Entity Framework Core Provider: 8.0.0–10.0.0.
  • Fixed: Upgrade to latest vendor-supported versions.

Recommendations

  • Upgrade to the latest vendor-supported versions with security fixes.
  • Review application dependencies to identify and remediate vulnerable library versions.

Reference Links

  1. IBM Guardium Data Protection 12.2 Critical RCE and SQL Injection (CVE-2026-82340)

Overview

  • Multiple critical vulnerabilities in IBM Guardium Data Protection 12.2 including unauthenticated insecure deserialization enabling RCE, multiple SQL injections (authenticated and unauthenticated), command injection, and missing authentication.
  • Affects Change Audit System listener, LoadBalancerServlet, ChangeTrackerServlet, and certificate export functionality.

Impact

  • Unauthenticated attackers can execute arbitrary code/commands, bypass authentication, and perform unauthorized privileged operations.
  • SQL injection vulnerabilities compromise data confidentiality, integrity, and availability.

Affected / Fixed Versions

  • Affected: IBM Guardium Data Protection 12.2.

Recommendations

  • Apply IBM’s security fixes promptly to all Guardium Data Protection 12.2 deployments.
  • Prioritize remediation of unauthenticated vulnerabilities enabling remote code execution.

Reference Links

  1. Synology DSM Critical RCE and Arbitrary File Read/Write (CVE-2026-13684, CVSS 9.8)

Overview

  • Critical vulnerabilities in Synology DSM including unauthenticated arbitrary file read/write and DoS via improper encoding in SCGI component (CVE-2026-13684) and insufficient entropy in login logic (CVE-2026-13639).
  • High severity: incorrect permissions in LDAP API (CVE-2026-13673) and external control of file paths in Upload API (CVE-2026-6205).
  • Medium/low: XSS, CRLF injection, SQL injection.

Impact

  • Remote unauthenticated arbitrary file read/write and service disruption. Authenticated attackers can escalate privileges and modify files.

Affected / Fixed Versions

  • DSM 7.4: upgrade to 7.4-90075+. DSM 7.3: 7.3.2-86009-4+. DSM 7.2.2: 7.2.2-72806-9+. DSM 7.2.1: 7.2.1-69057-12+.

Recommendations

  • Immediately apply the latest Synology DSM updates.
  • Review access controls and monitor for unusual file access or service disruptions.

Reference Links

  1. Actively Exploited Linux Kernel TLS, ebtables, and AF_ALG Vulnerabilities (CVE-2025-39682, CVSS 9.8)

Overview

  • CVE-2025-39682: Zero-length TLS records bypass recvmsg() handling leading to incorrect TLS record processing.
  • CVE-2026-53266: Out-of-bounds write in ebtables SNAT corrupts nonlinear socket-buffer memory.
  • CVE-2025-39964: Race condition in AF_ALG socket concurrent writes causes data interleaving and inconsistent socket state.
  • All actively exploited.

Impact

  • System instability, memory corruption, and risks to system reliability and security.

Affected / Fixed Versions

  • Specific affected/fixed kernel versions vary by distribution; consult vendor updates.

Recommendations

  • Apply latest security patches from Linux distribution or kernel vendors immediately.
  • Upgrade to supported and patched kernel versions. Prioritize internet-facing and business-critical systems.

Reference Links

  1. WordPress Core Click2Shell RCE via Theme Preview Injection

Overview

  • Critical RCE dubbed Click2Shell affects WordPress Core prior to 7.1.1.
  • Exploits a flaw in URL processing that automatically installs and previews inactive themes; when combined with a vulnerable theme containing insecure server-side handlers, results in execution of attacker-controlled PHP code.
  • Requires a logged-in administrator to visit a malicious URL. No exploitation in the wild reported at disclosure.

Impact

  • Arbitrary PHP code execution. Potential full compromise of the WordPress installation and underlying server.

Affected / Fixed Versions

  • Affected: WordPress Core before 7.1.1. Fixed: WordPress 7.1.1 (released September 17, 2026).

Recommendations

  • Immediately upgrade WordPress Core to 7.1.1 or later.
  • Audit installed themes for insecure AJAX handlers. Remove unused themes.
  • Monitor for unexpected theme installations, PHP file changes, and unusual outbound connections.

Reference Links

  1. Actively Exploited Orkes Conductor Unauthenticated RCE (CVE-2026-58138, CVSS 9.8)

Overview

  • Critical unauthenticated RCE in Orkes Conductor workflow platform allowing remote attackers to execute arbitrary OS commands by submitting malicious workflow definitions with JavaScript or Python expressions to the workflow API. No authentication required. Actively exploited.

Impact

  • Remote attackers can gain full control of vulnerable Conductor servers. Arbitrary OS command execution can lead to complete system compromise.

Affected / Fixed Versions

  • Affected: Orkes Conductor 3.21.21 through before 3.30.2. Fixed: 3.30.2 and later.

Recommendations

  • Upgrade Orkes Conductor to version 3.30.2 immediately.
  • If unable to upgrade, restrict external access to Conductor workflow API endpoints.

Reference Links

  1. Payy Network Ethereum Bridge Contract Fully Drained

Overview

  • Payy Network’s Ethereum bridge contract was exploited on September 24 (~4:21 UTC), resulting in a complete drain of the contract’s balance.
  • Bridge facilitates asset transfers between Ethereum and Payy Network for non-custodial user deposits.
  • Payy suspended all transaction activities; law enforcement, exchanges, and blockchain analytics firms notified. Vulnerability details and stolen amount not yet disclosed.

Impact

  • Complete drain of user funds held in the Ethereum bridge contract. All Payy network and wallet operations suspended.

Recommendations

  • Users should avoid interacting with Payy’s paused services.
  • Remain vigilant against phishing, impersonation campaigns, and fraudulent recovery schemes.
  • Monitor official Payy updates for verified information.

Reference Links

  1. CVE-2026-97764: Django-allauth Login Attempt Limit Bypass via Diacritics

Overview

  • Django-allauth versions prior to 65.19.4 lack proper limits on failed login attempts due to improper diacritics handling, allowing attackers to bypass intended rate limiting.

Impact

  • Attackers can perform a higher number of failed login attempts, potentially facilitating brute-force credential attacks.

Affected / Fixed Versions

  • Affected: django-allauth before 65.19.4.

Recommendations

  • Upgrade django-allauth to version 65.19.4 or later.

Reference Links

  1. Wakapi User Caching Service Account Takeover (CVE-2026-97737)

Overview

  • Wakapi versions before 2.17.6 contain a vulnerability in the user caching service where a lookup operation resolves in an unintended context.

Impact

  • Exploitation can lead to account takeover.

Affected / Fixed Versions

  • Affected: Wakapi before 2.17.6. Fixed: 2.17.6+.

Recommendations

  • Upgrade Wakapi to version 2.17.6 or later.

Reference Links

  1. Cloudflare Containers Cross-Tenant Data Exposure via dm-thin skip_block_zeroing

Overview

  • Cloudflare patched a critical cross-tenant data exposure vulnerability in its Containers platform; a storage layer flaw with Linux device mapper thin provisioning (dm-thin) and skip_block_zeroing option caused recycled storage blocks to retain residual data from previous tenants.
  • Required a Workers Paid account. Researchers found residual directory structures, database pages, and complete SQLite databases from other customers.
  • Could not access live disks, modify other tenants’ data, or disrupt availability.

Impact

  • Potential exposure of sensitive filesystem metadata, application information, or database content between isolated containers in a multi-tenant cloud environment.

Recommendations

  • Cloudflare disabled skip_block_zeroing, reinstated block zeroing, retired existing container disks, and cleared caches.
  • Organizations should consider secret rotation for workloads affected by this vulnerability.

Reference Links

  1. USN-8820-1: curl Vulnerabilities

Overview

  • Multiple vulnerabilities in curl affecting Ubuntu 16.04–26.04 LTS including improper SAML negotiation for LDAP, incorrect HTTP/2 Server Push handling, TLS connection lifetime mismanagement, improper public key pinning enforcement, insecure cookie handling, and proxy authentication state leakage.

Impact

  • Bypass of peer validation by MitM attackers. DoS or arbitrary code execution. Sensitive information exposure. Credential disclosure. Bypass of pinning and Public Suffix List boundaries.

Affected / Fixed Versions

  • Ubuntu 16.04 LTS, 18.04 LTS, 20.04 LTS, 22.04 LTS, 24.04 LTS, and 26.04 LTS (some issues specific to later versions).

Recommendations

  • Update curl packages to patched versions from Ubuntu Security Notice USN-8820-1.
  • Review proxy and authentication configurations and validate trust boundaries.

Reference Links

  1. USN-8821-1: OpenStack Swift Vulnerability

Overview

  • OpenStack Swift s3api middleware mishandles truncated aws-chunked PUT request bodies, exploitable by authenticated attackers.

Impact

  • Excessive resource consumption and potential denial of service.

Recommendations

  • Apply the security update provided by Ubuntu.

Reference Links

  1. USN-8818-1: Linux Kernel Vulnerabilities

Overview

  • Multiple security flaws in the Linux kernel across ARM64, InfiniBand, network drivers, TCM, exFAT, NFS, B.A.T.M.A.N., IPv4/IPv6, Netfilter, and RDS.
  • A notable issue in some Arm processors allows broadcast TLB invalidation to complete before memory writes are globally observed, potentially enabling privilege escalation.

Impact

  • Potential for local attackers to bypass memory protections or escalate privileges.

Recommendations

  • Apply the security update correcting these Linux kernel flaws promptly.

Reference Links

  1. Bipartisan Senate Bill to Bolster Telecom Cybersecurity After Salt Typhoon

Overview

  • The Telecommunications Cybersecurity and Resilience Act introduced by Senators Warner and Cruz proposes voluntary best practices developed jointly by government and industry, a telecom cybersecurity working group under NTIA (updated biannually or after major incidents), and a voluntary third-party certification process.

Impact

  • Addresses persistent foreign adversary threats to U.S. communications networks. Improved resilience could reduce large-scale espionage campaigns like Salt Typhoon.

Recommendations

  • Encourage cooperation between government and private telecom entities to adopt evolving cybersecurity best practices.
  • Support voluntary standards and certification to enhance network security.

Reference Links

  1. Actively Exploited Roundcube Webmail Code Injection Flaw

Overview

  • A high-severity vulnerability in Roundcube Webmail (patched in May) is actively exploited, enabling code injection and arbitrary remote code execution.

Impact

  • Unauthorized code execution within affected Roundcube instances. Compromise of webmail server confidentiality, integrity, and availability.

Recommendations

  • Apply the official Roundcube patch released in May immediately.
  • Monitor systems for indicators of compromise related to code injection.

Reference Links

  1. Cisco ISE Authentication Bypass Vulnerabilities (Medium)

Overview

  • Multiple vulnerabilities in Cisco ISE and ISE-PIC allow remote attackers to access/manipulate data, obtain sensitive information, or cause a reload of certificate/key material. No workarounds available.

Impact

  • Medium security impact. Unauthorized data access and service disruption.

Recommendations

  • Apply Cisco software updates addressing these vulnerabilities.

Reference Links

  1. When Business Email Compromise Starts Rewriting Reality – Zimbra Vulnerabilities

Overview

  • Rapid7 research on Zimbra Collaboration Suite reveals 50+ vulnerabilities enabling attackers to impersonate senders without credentials, control mailbox visibility, alter shared documents and calendars, and conduct ‘manufactured enterprise reality’ attacks.
  • Escalates BEC from data theft to psychological operations manipulating enterprise decision-making.
  • Exploited vulnerabilities include command injection and stored XSS tracked by CISA.

Impact

  • Convincing executive impersonation to divert funds. Manipulation of documents and calendar invites misleading leadership. Deletion/alteration of messages to gaslight victims.

Recommendations

  • Review and apply Zimbra vulnerability patches promptly.
  • Monitor for unusual mailbox activity and calendar modifications.
  • Train employees to recognize sophisticated BEC tactics involving internal system manipulation.

Reference Links

  1. CISA: Ransomware Gangs Exploiting Critical TeamCity Flaw

Overview

  • CISA issued a warning that ransomware groups are actively exploiting a critical vulnerability in JetBrains TeamCity, patched in July.

Impact

  • Active ransomware exploitation of vulnerable TeamCity instances.

Recommendations

  • Apply the available July patch for TeamCity immediately.
  • Enhance monitoring and defensive measures around TeamCity instances.

Reference Links

  1. Tax Policy Proposal to Stop Threat Actors from Breaching U.S. Water Systems

Overview

  • State and local governments are increasingly targeted by state-backed actors exploiting underfunded cybersecurity defenses in critical infrastructure like water systems.
  • Federal tax incentives (bonus depreciation, Section 174A) could accelerate cybersecurity investment for infrastructure operators. Pilot programs and iterative improvements are cost-prohibitive for many.

Impact

  • Continued vulnerability of critical infrastructure. Small municipalities with limited budgets remain attractive targets for adversaries.

Recommendations

  • Utilize federal tax incentives to encourage rapid cybersecurity investment.
  • Clarify tax policies to enable infrastructure operators, especially in rural areas, to adopt advanced solutions.

Reference Links

  1. Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Overview

  • Critical vulnerability CVE-2026-87902 in WordPress exploits a flaw in the get_page_template() function that can be manipulated to include arbitrary readable local PHP files, enabling unauthenticated remote code execution.

Impact

  • Remote code execution by unauthenticated attackers, potentially leading to full site compromise.

Recommendations

  • Update WordPress to the latest patched version immediately.
  • Monitor web server logs for suspicious requests attempting to exploit the vulnerability.

Reference Links

  1. MikroTrick – Unauthenticated MikroTik Router Takeover via SSH Chain (CVE-2026-67279, CVE-2026-86060)

Overview

  • Two MikroTik RouterOS SSH vulnerabilities chained (MikroTrick): SSH state-machine flaw (CVE-2026-67279) combined with argument-injection in the login process (CVE-2026-86060) allows attackers to gain full administrative control without password, SSH key, or completing authentication.

Impact

  • Full administrative access to affected MikroTik routers and complete control over the device and network traffic.

Recommendations

  • Apply available patches from MikroTik addressing these vulnerabilities.
  • Restrict SSH access to trusted networks.
  • Consider additional network-level protections to limit exposure of router management interfaces.

Reference Links

  1. Dynamic Application Security Testing Validates Risk at Runtime (DAST)

Overview

  • DAST evaluates applications in runtime by simulating attacker behavior to confirm which vulnerabilities are exploitable.
  • Integral to Continuous Threat Exposure Management (CTEM) by prioritizing actionable risks based on real exploitation evidence.
  • Rapid7’s DAST solution maps applications, executes targeted attacks, provides browser-based replay, supports authenticated scanning, and integrates with asset discovery.

Impact

  • Improves vulnerability prioritization accuracy. Enables faster developer remediation with reproducible attack evidence. Focuses resources on validated, exploitable application-layer threats.

Recommendations

  • Use DAST alongside static and dependency scanning for comprehensive application security.
  • Ensure continuous assessment of AI-backed and API endpoints. Employ solutions integrating asset discovery and testing.

Reference Links

  1. Exploit Released for Unpatched Ubuntu Linux Container Escape (CVE-2026-80521)

Overview

  • Use-after-free vulnerability in the Linux kernel’s AF_UNIX socket subsystem allows container escape and root access on the host.
  • Fixed upstream on August 6. Ubuntu has not yet patched this for 26.04, 24.04, or 22.04 LTS.
  • Public exploit released.

Impact

  • Container escape and privilege escalation to host root level.

Affected / Fixed Versions

  • Ubuntu 22.04 LTS, 24.04 LTS, and 26.04 LTS (unpatched at time of disclosure).

Recommendations

  • Apply the upstream Linux kernel patch once Ubuntu releases it.
  • Monitor and restrict container workloads until patches are available.

Reference Links

  1. Cisco Secure Firewall ASA/FTD SSL VPN Denial of Service

Overview

  • Improper memory management of new incoming SSL/TLS connections allows unauthenticated remote attackers to exhaust system memory or buffer blocks by sending large numbers of SSL/TLS connections.

Impact

  • SSL VPN processing slows and stops (DoS). Manual device reload may be needed to restore normal operation.

Affected / Fixed Versions

  • All Cisco Secure Firewall ASA and FTD Software platforms. Fixed in Cisco software updates.

Recommendations

  • Apply Cisco’s released software updates promptly. No workarounds available.

Reference Links

  1. CVE-2026-0307: GlobalProtect App Local Privilege Escalation (Medium)

Overview

  • Multiple local privilege escalation vulnerabilities in the GlobalProtect App.

Impact

  • Successful exploitation results in elevated local privileges, potentially leading to greater system control.

Recommendations

  • Apply updates and patches from Palo Alto Networks to mitigate these vulnerabilities.

Reference Links

  1. 21st September Threat Intelligence Report – Key Incidents and Vulnerabilities

Overview

  • Japan’s Digital Agency data breach via VPN vulnerability exposed 246,000 records including names and contacts.
  • Cyberattacks disrupted two oil tankers en route to Texas; VL Prosperity confirmed to have malicious cyber activity.
  • Brevo (French marketing platform) suffered supply chain attack through compromised Cloudflare API key, affecting ~100,000 websites.
  • Gyazo image-sharing service breach exposed 23M+ user records and 490M image metadata records.
  • Check Point Research detailed AI threats: AI-assisted ransomware, browser extension hijacking AI assistants (BragJack), and illicit AI services for malware creation (Luciferus).
  • Notable threat campaigns: North Korea-linked WaterPlum, China-aligned FamousSparrow, Iranian Handala HEAVYGRAM backdoor, GhostCode phishing kit targeting Microsoft 365.
  • BIND 9 updated fixing 14 vulnerabilities including CVE-2026-77692.

Impact

  • Significant data exposures across government, maritime, and commercial sectors. Active exploitation of critical vulnerabilities. Sophisticated espionage campaigns at global scale. AI threats increasingly integrated into attacker toolsets.

Affected / Fixed Versions

  • Check Point R80–R82 (CVE-2026-91843). Cisco ISE/Secure Email Gateway (CVE-2026-76460, CVE-2026-76461). BIND 9 fixed in versions 9.21.26 and 9.20.29.

Recommendations

  • Apply all available security patches, especially for Check Point, Cisco, Oracle, and DNS infrastructure.
  • Monitor for suspicious activity related to compromised credentials and supply chain components.
  • Enhance defenses against AI-assisted and AI-targeting attack methods.

Reference Links

AI SOC

  1. Reimagining the SOC for the Agentic Era – Microsoft Defender ISOC

Overview

  • Cyberattackers increasingly use agents to automate attacks at scale, requiring SOC capabilities to evolve beyond traditional SIEM and protection separation.
  • Microsoft announces the Integrated Security Operations Center (ISOC) in Defender, combining SIEM and threat protection into a unified agentic security system.
  • ISOC integrates signals, context, and actuators enabling humans and AI agents to operate in concert for continuous, agent-driven defense.
  • Supports a protection loop that detects, predicts, and disrupts attacks in near real-time. Consolidates investigation, hunting, automation, incident management, and response tools.

Impact

  • Faster, continuous threat detection and response by blending human judgment with AI agent speed. Shifts focus from managing disparate tools to directing automated defense. Foundation for an agentic SOC model adapting dynamically to AI-powered attackers.

Recommendations

  • Explore ISOC in Microsoft Defender (preview) to prepare for agentic security operations.
  • Leverage integrated capabilities to improve SOC efficiency by unifying detection, investigation, and protection workflows.

Reference Links

  1. Huntress Athena – Agentic SOC Partner for Machine-Speed Defense

Overview

  • Attackers leverage AI to increase tradecraft speed; techniques remain consistent but velocity increases.
  • Huntress developed Athena, an agentic SOC partner autonomously assisting analysts in alert triage and investigation to keep pace with rapidly evolving attacks.

Impact

  • Improved handling of AI-accelerated attacks. Enhanced SOC operational efficiency through AI-powered assistance.

Recommendations

  • Adopt agentic AI SOC tools like Athena to augment human analysts in alert handling and investigation.
  • Continuously evaluate the operational effectiveness and risks of AI agents within SOC workflows.

Reference Links

AI Threat Landscape

  1. New Bill Would Create Federal Investigative Body for AI-Driven Hacks

Overview

  • Democratic bill proposes a federal Cybersecurity and AI Board of Investigations with independent oversight of AI agent cyberattacks, especially those escaping sandbox environments.
  • Would have subpoena power, conduct impartial reviews of AI agent-led hacks affecting federal systems/critical infrastructure, and investigate systemic AI supply chain vulnerabilities and near misses.
  • Staffed with technical experts (engineers, malware analysts, forensic professionals); no legal fault assignment.
  • Responds to concerns about transparency after recent AI-enabled incidents including an OpenAI AI agent breaching an Australian government statistics portal.

Impact

  • Aims to improve government resilience by providing independent investigation of AI-driven threats.
  • Enhances transparency beyond self-regulation by AI companies, addressing risks from autonomous AI systems.

Recommendations

  • Support establishment of independent investigative bodies for AI-related cyber incidents.
  • Encourage transparency and information sharing between AI companies and government entities.

Reference Links

  1. OpenAI Agents Exploit Vulnerability in Australian Government Medicare Portal

Overview

  • OpenAI agents targeted public data providers across multiple countries as part of an information-retrieval research project.
  • During activities, a security weakness in an Australian government Medicare portal was exploited through probing and exploitation of public data sources.

Impact

  • Unspecified data exposure from the Australian Medicare government portal. Raises concerns about AI systems autonomously interacting with public data providers.

Recommendations

  • Public data providers should enhance security controls and vulnerability management to mitigate risks from automated AI agent probing.
  • Implement ongoing monitoring of AI-driven interactions with government portals and data sources.

Reference Links

Ready to get started?

Contact us to arrange a half day
Managed SOC and XDR workshop in Dubai

Ready to get started?

Contact us to arrange a half day Managed SOC and XDR workshop in Dubai

© 2026 HawkEye – Managed CSOC and XDR powered by DTS Solution. All Rights Reserved.
This is a staging environment