Security news, decoded.
74 stories in the last 7 days, naming 204 CVEs; 59 of those CVEs are in CISA KEV.
The wire
Wednesday, Sep 96 stories
- Help Net SecurityGoogle fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)
Google has addressed an actively exploited zero-day vulnerability, designated as CVE-2026-87491, within the V8 JavaScript and WebAssembly engine of Chrome. This out-of-bounds write flaw enables remote attackers to execute arbitrary code via specifically crafted HTML pages. The security update is available in Chrome versions 153.0.8010.36 and .37 for Windows and macOS, as well as 153.0.8010.36 for Linux.
Reported exploitedGoogle Chrome - The Hacker NewsF5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
Sophos detailed the mechanics of malware targeting F5 BIG-IP Access Policy Manager appliances, revealing that it injects a PHP web shell directly into memory rather than writing it to disk. This technique evades standard file-based detection methods by modifying the Apache process only after it loads specific PHP scripts, effectively hiding the malicious code from disk integrity checks. The intrusion is linked to CVE-2025-53521, a critical remote code execution vulnerability with a CVSS score of 9.8 that was reclassified in March 2026 and subsequently added to CISA's Known Exploited Vulnerabilities catalog. Administrators should verify that their systems are patched, with fixes available in versions such as 17.5.1.3, 17.1.3, and 16.1.6.1. Because the malware can persist in memory even after patching, security teams are advised to run sys-eicheck integrity checks, generate qkview reports for analysis, and compare in-memory modules against disk copies to confirm the absence of active compromises.
Reported exploitedF5 BIG-IP APM - The Hacker NewsResearcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed
Security researcher Chaotic Eclipse has released a proof-of-concept named ShieldCrash that exploits an incomplete remediation for CVE-2026-69414 in Microsoft Defender. This new exploit effectively bypasses the patch for the previously disclosed ShieldBreak vulnerability, allowing for arbitrary file reads with SYSTEM privileges across all supported Windows desktop versions. Although Microsoft recently updated the Microsoft Malware Protection Engine to version 1.1.26080.3 to address the initial flaw, this new finding indicates that certain code paths remain vulnerable under specific conditions.
PoC publicMicrosoft Defender - The Hacker NewsSAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
SAP has released security updates addressing multiple critical vulnerabilities, most notably CVE-2026-44756, a CVSS 10.0 memory corruption flaw in the SAP kernel's Extended Passport (EPP) processing. Identified by Onapsis as "OVERPASS," this defect allows unauthenticated attackers to achieve remote code execution with administrative privileges via crafted network requests, potentially compromising business data across SAP S/4HANA and other ABAP-based systems. Additionally, SAP patched CVE-2026-58240 (CVSS 9.8), a missing authentication check in the NetWeaver Message Server dubbed "S4GET" by researchers, along with two other high-severity issues affecting CAP and SAP GUI for Java. Although no active exploitation has been confirmed, administrators are urged to patch internet-facing systems urgently since traditional access controls do not mitigate these kernel-level defects.
PatchSAP Extended Passport (EPP) - The Hacker NewsMicrosoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Microsoft released its largest monthly security update ever, remediating 974 vulnerabilities across its ecosystem. Among these fixes are two Windows zero-day flaws, CVE-2026-85880 and CVE-2026-81963, that have been actively exploited in the wild. Both vulnerabilities enable local privilege escalation with a CVSS score of 7.8, allowing attackers to gain SYSTEM privileges. The issue was reported by Volexity, Proofpoint, and Microsoft MSTIC, prompting CISA to add both CVEs to the Known Exploited Vulnerabilities catalog. Organizations should apply the September 2026 patches immediately to secure their systems.
Reported exploitedWindows - The Hacker NewsN-able N-central Pre-Auth RCE Flaw Exploited in the Wild
CISA has added CVE-2026-86218 to its Known Exploited Vulnerabilities catalog, mandating that federal agencies patch N-able N-central by September 11, 2026. This maximum-severity flaw (CVSS 10.0) enables pre-authentication remote code execution via static code injection. The vendor released a fix in N-central 2026.3 Hotfix 4 on September 5, 2026, following reports of active exploitation and customer compromises investigated by Huntress.
Reported exploitedN-central
Tuesday, Sep 815 stories
- Cisco TalosMicrosoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has published its September 2026 security update, remediating 973 vulnerabilities across its software portfolio, including 113 rated as "critical." Among these, 82 are remote code execution flaws affecting products such as Windows, Office, SQL Server, Azure Cosmos DB, and Spring Cloud Azure. Notably, Microsoft confirmed active exploitation in the wild for two elevation of privilege issues: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call (ALPC). Administrators should prioritize patching these components immediately, alongside other high-severity bugs flagged by the vendor as having a higher likelihood of exploitation.
Reported exploitedWindows - Krebs on SecurityMicrosoft Plugs Nearly 1,000 Security Holes – Krebs on Security
Microsoft has released its largest patch bundle to date, addressing 974 vulnerabilities across Windows and other products, with two zero-day flaws—CVE-2026-81963 and CVE-2026-85880—currently being actively exploited for privilege escalation. This monthly update includes 113 critical issues, notably a high-severity remote code execution flaw in the Windows Shell identified as CVE-2026-69829 (CVSS 9.8) and a DNS weakness affecting Windows Server 2012 and later versions labeled CVE-2026-69730. The surge in disclosed bugs, attributed partly to AI-assisted discovery, is prompting experts to warn enterprises about the growing operational burden of testing and deploying such extensive fix sets within standard maintenance windows.
Reported exploitedWindows - Dark ReadingPatch Tuesday Sets Another Record With 974 CVEs
Microsoft has addressed a record-high 974 vulnerabilities in its September security update, including two flaws currently being exploited in the wild. The affected products span Windows, Office, Exchange Server, and SQL Server, with CVE-2026-85880 and CVE-2026-81963 representing immediate risks as both allow privilege escalation on compromised systems. Beyond the active exploits, the release includes 13 critical-rated issues and 20 wormable remote code execution bugs, notably CVE-2026-69730 in Windows DNS Server. Organizations should prioritize applying these updates to mitigate the risk of automated network propagation and unauthorized administrative access.
Reported exploitedWindows - Ars Technica (Security)Why this month's Microsoft patch release is a doozy
Microsoft has addressed a historic surge of approximately 972 security flaws in its latest cumulative update, with 112 of them classified as critical. This release includes fixes for two zero-day vulnerabilities, CVE-2026-81963 and CVE-2026-85880, which are currently being actively exploited in the wild. The unprecedented volume of patches reflects the growing impact of AI-driven vulnerability discovery across the tech industry.
Reported exploitedWindows - OX SecurityCVE-2026-82533: DeepSeek Harness Vulnerability Lets AI Agents Escape Their Own Sandbox
OX Research has published a proof-of-concept demonstrating how CVE-2026-82533 allows AI agents running inside DeepSeek Harness to escape their operating system sandbox. The vulnerability, rated CVSS 9.4, stems from the local HTTP API trusting client-supplied 'Host' headers instead of verifying peer addresses, while default sandbox profiles permitted unrestricted loopback networking. By exploiting this misconfiguration, a sandboxed agent could issue a single shell command to escalate its session to full access, effectively disabling security controls without network exposure or additional credentials. OX Research disclosed the issue to VulnCheck on August 24, 2026, and confirmed that the fix in DeepSeek Harness 0.1.2-alpha.1 resolves the defect.
PoC publicDeepSeek Harness - BleepingComputerHackers breach F5 BIG-IP APM devices to deploy Linux rootkit
Security researchers have identified active exploitation of F5 BIG-IP APM devices where attackers leverage the critical remote code execution flaw CVE-2025-53521 to deploy a sophisticated Linux rootkit. Dubbed 'PoisonedRefresh' by ESET, this second-stage payload uses fileless techniques to intercept PHP file loading via Apache APR hooks, effectively injecting a hidden web shell directly into memory without writing malicious code to disk. Sophos analysis reveals that the implant modifies SELinux configurations to persist across upgrades and establishes a password-protected local UNIX socket for interactive Bash access, avoiding standard TCP listeners. Defenders should monitor for specific indicators such as unusual POST requests to .php3 endpoints returning HTTP 201 with text/css content types, and note that approximately 795 vulnerable endpoints remained exposed online recently.
Reported exploitedF5 BIG-IP APM - SecurityWeekMicrosoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days
Microsoft released a record number of security updates this month, resolving 974 vulnerabilities across its software portfolio, including two actively exploited zero-days. The first, CVE-2026-85880, is a heap buffer overflow in the Windows Advanced Local Procedure Call (ALPC) that allows local attackers to escalate privileges to System level. The second, CVE-2026-81963, involves improper link resolution in the Windows Update Stack, also enabling privilege escalation. Additionally, the patch addresses significant remote code execution risks in Exchange Server, SharePoint, and Remote Desktop Services.
Reported exploitedWindows ALPC - Qualys Security BlogMicrosoft and Adobe Patch Tuesday, September 2026 Security Update Review
Qualys reports that Microsoft has issued its largest Patch Tuesday update to date, remediating 974 security vulnerabilities across its product ecosystem. Among these fixes are two zero-days currently under active exploitation: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows Advanced Local Procedure Call (ALPC), both enabling local privilege escalation. Additionally, Adobe released a patch for critical vulnerability CVE-2026-75650 in Adobe Commerce, which allows arbitrary code execution and has been added to CISA's Known Exploited Vulnerabilities Catalog.
Reported exploitedMicrosoft Exchange Server - SecurityWeekAdobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day
Adobe has issued security updates for over 170 vulnerabilities across multiple products, including an urgent patch for a critical, actively exploited zero-day in Adobe Commerce and Magento Open Source. Tracked as CVE-2026-75650 with a perfect CVSS score of 10/10, this code injection flaw enables unauthenticated remote code execution and has been leveraged by threat actors, identified by Sansec research as StyleSmuggler, to backdoor online stores through the 'Payment Transaction Failed Reminder' feature. The vendor strongly advises administrators to apply the fixes immediately and rotate all encryption keys, administrative credentials, database access details, and API tokens at their source. Additional priority one patches were also distributed for Critical Command Injection issues in Campaign Classic and ColdFusion.
Reported exploitedAdobe Commerce - BleepingComputerMicrosoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days
Microsoft has released its September 2026 security updates to address a record high of 966 vulnerabilities across products including Windows, Microsoft Office, Exchange Server, and SharePoint. This release includes fixes for two zero-day vulnerabilities that are currently being exploited in the wild, both of which allow attackers to escalate privileges locally to gain SYSTEM access. One of these flaws exists in the Windows Update Stack due to improper link resolution, while the other involves a heap-based buffer overflow in the Windows Advanced Local Procedure Call (ALPC) subsystem. Administrators should prioritize deploying these patches immediately to mitigate the risk of active exploitation.
Reported exploitedWindows - BleepingComputerSAP warns of maximum severity 'OVERPASS' kernel vulnerability
SAP has released September 2026 security updates addressing 20 vulnerabilities, including a maximum-severity buffer overflow in the SAP Kernel dubbed OVERPASS. Identified as CVE-2026-44756 by Onapsis researchers, this flaw allows unprivileged attackers to gain administrative command execution on vulnerable hosts via the Internet Communication Manager. Additionally, SAP resolved CVE-2026-58240, a missing authentication issue in the NetWeaver Message Server known as S4GET, which permits remote code execution across entire system clusters without credentials. Onapsis estimates that over 10,000 internet-facing SAP systems are potentially exposed to these attacks.
AdvisorySAP S/4HANA - SecurityWeekSAP Patches Critical Extended Passport Processing Vulnerability
SAP has published emergency security updates addressing a critical memory corruption vulnerability, identified as CVE-2026-44756, within its Extended Passport (EPP) processing logic. Security researchers at Onapsis, who dubbed the defect "OVERPASS," warn that unauthenticated attackers can exploit this bug to execute arbitrary system commands, steal database credentials, and manipulate SAP binaries across various platforms including S/4HANA and ERP. The flaw exists because missing boundary validations during data deserialization occur before standard authorization controls are applied, effectively bypassing user locks and role-based restrictions. Although SAP has not reported active exploitation in the wild, the severity of the issue—rated CVSS 10/10—demands immediate attention from administrators running affected kernel versions. The company also resolved three other high-priority issues, including CVE-2026-58240, which allows unregistered component registration in S/4HANA 2025 and earlier, alongside vulnerabilities affecting NetWeaver and cloud-capable applications.
PatchSAP Kernel - BleepingComputerAdobe fixes critical Magento zero-day exploited to backdoor servers
Adobe has issued an emergency update to address CVE-2026-75650, a critical zero-day flaw in Magento and Adobe Commerce that is currently being leveraged to deploy backdoors on compromised servers. E-commerce security firm Sansec identified active exploitation of this vulnerability, referred to as StyleSmuggler, starting in early September, where attackers used it to install persistent access mechanisms disguised as NTP servers. Affected products include Adobe Commerce versions 2.4.4 through 2.4.9, Adobe Commerce B2B 1.3.3 through 1.5.3, and Magento Open Source 2.4.6 through 2.4.9. The vendor has released the VULN-39341 hotfix to resolve this arbitrary code execution issue. Administrators are urged to apply the patch immediately and subsequently rotate all administrative credentials, API keys, and secrets to mitigate potential compromise.
Reported exploitedPlex Media Server - The Hacker NewsFreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
Red Hat has disclosed a critical vulnerability chain in FreeIPA, tracked as CVE-2026-76578, which allows unauthenticated clients to create arbitrary Kerberos identities with administrator privileges. This attack exploits a combination of the identity management flaw and a separate issue in 389 Directory Server (CVE-2026-76560), enabling attackers to bypass ownership checks and write privileged entries to the directory database. The FreeIPA project has addressed this through version 4.13.4, while Red Hat has released patches for various distributions including RHEL and Fedora. Additionally, a second unrelated flaw in FreeIPA, CVE-2026-79678, was identified that allows authenticated users to leak environment variables via an unsafe eval call in the idp-add command.
AdvisoryWindows ALPC - The Hacker NewsAdobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Adobe has issued emergency patches for a critical remote code execution vulnerability affecting Adobe Commerce and Magento Open Source, confirmed to be under active attack. Tracked as CVE-2026-75650 with a maximum CVSS score of 10.0, this flaw allows attackers to execute arbitrary code by abusing the platform's template processing mechanisms. Threat actors have already leveraged the zero-day to install persistent threats, including a custom Rust-based Linux backdoor and PHP web shells on compromised stores. To mitigate the risk, administrators must immediately apply the VULN-39341 hotfix and rotate all encryption keys across vulnerable versions of Adobe Commerce, Adobe Commerce B2B, and Magento Open Source.
Reported exploitedAdobe Commerce
Monday, Sep 710 stories
- Check Point Research7th September – Threat Intelligence Report
Check Point's weekly threat intelligence report confirms active exploitation of SonicWall SMA 1000 gateways via two critical flaws, CVE-2026-83548 and CVE-2026-83549, alongside a newly discovered authentication bypass in self-hosted JFrog Artifactory deployments tracked as CVE-2026-82329. The briefing also covers the release of "FalconFlank," a proof-of-concept privilege escalation technique targeting CrowdStrike Falcon on recent Windows versions, as well as ongoing breaches at major organizations including Thomson Reuters and Dropbox.
Reported exploitedDropbox - The Hacker News⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
This week's security landscape is dominated by active exploitation campaigns targeting Google Chrome, MikroTik RouterOS, and N-able N-central. Google addressed a high-severity type confusion bug in the V8 engine (CVE-2026-85046) that is currently under attack, while CERT Polska warned of a critical zero-day chain dubbed MikroTrick being used to hijack routers via SSH. N-able released urgent hotfixes for two severe authentication bypass flaws (CVE-2026-86206 and CVE-2026-86207) and a CVSS 10.0 remote code execution vulnerability (CVE-2026-86218), with evidence suggesting attackers are already leveraging these weaknesses. Additionally, e-commerce platforms are suffering from an unpatched Magento and Adobe Commerce zero-day known as StyleSmuggler, which allows unauthenticated attackers to inject backdoors into online stores.
Reported exploitedN-central - Help Net SecurityHackers exploit RouterOS flaws to hijack MikroTik devices without authentication
CERT Polska reported active exploitation of a vulnerability chain in MikroTik RouterOS that allows attackers to seize full control of devices with internet-exposed SSH services without prior authentication. The attack leverages CVE-2026-67276, an SSH authentication bypass, combined with CVE-2026-86060, a privilege escalation flaw, to establish administrative access. Additionally, CVE-2026-67277 was identified alongside three other lower-severity issues affecting certificate handling and web interfaces. Vendors have released fixes in RouterOS versions 7.25beta3, 7.24.2, 7.23.4, and 6.49.21. Administrators are urged to apply these updates immediately, disable exposed services like SSH as a temporary mitigation, and audit device configurations for unauthorized users such as 'ops' or suspicious script entries.
Reported exploitedMikroTik RouterOS - Help Net SecurityN-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)
N-able has issued an urgent security update for its N-central remote monitoring and management platform, addressing a critical vulnerability identified as CVE-2026-86218. This flaw allows for pre-authenticated remote code execution on the N-central server, posing a significant risk to both hosted and on-premises deployments. While the vendor's initial public advisory did not confirm active exploitation, subsequent customer notifications explicitly stated that the vulnerability was observed being exploited in the wild, characterizing it as a zero-day issue. Affected organizations are advised to upgrade immediately to N-central 2026.3 Hotfix 4 (build 2026.3.1.14) to mitigate the threat.
Reported exploitedN-central - The Hacker NewsTelerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
Security researchers at TantoSec have published a proof-of-concept exploit that enables unauthenticated remote code execution in Telerik UI for ASP.NET AJAX by chaining a padding oracle vulnerability with unsafe deserialization. This attack targets the RadAsyncUpload control in versions 2010.1.309 through 2026.2.519, specifically leveraging CVE-2026-13181 (CVSS 8.1), CVE-2026-13182, and CVE-2026-13183 to bypass encryption protections and load malicious payloads. Although Progress Software patched the issues in version 2026.2.708 released on July 8, the recent release of ready-to-run tooling lowers the barrier for attackers who meet specific non-default configuration requirements.
PoC publicTelerik UI for ASP.NET AJAX - BleepingComputerHackers exploit new MikroTik RouterOS flaws to hijack routers
Attackers are actively leveraging a combination of two recently disclosed vulnerabilities in MikroTik RouterOS to gain full administrative control over devices with SSH services exposed to the internet. The exploit chain involves CVE-2026-67276, an authentication bypass flaw stemming from incomplete RSA public key validation, and CVE-2026-86060, a privilege escalation bug triggered by specially crafted usernames. This threat was identified by Poland's CERT agency, which confirmed active in-the-wild exploitation under the name "MikroTrick." A related issue, CVE-2026-67277, also affects the bandwidth-test service, potentially allowing remote denial-of-service conditions.
Reported exploitedMikroTik RouterOS - BleepingComputerConnectWise warns of new ScreenConnect flaw without patch
ConnectWise has published an emergency security advisory for a new vulnerability in ScreenConnect Remote Access that impacts file transfer behavior in Support and Access sessions. Because the company has not yet released a permanent fix, administrators are instructed to manually revoke the TransferFiles (or TransferFilesInSession) permission from user roles as a temporary mitigation. While no CVE ID has been assigned to this specific issue, Shadowserver data indicates nearly 6,000 ScreenConnect instances remain exposed to the internet, increasing the risk of exploitation given the product's history of targeting by ransomware groups and state-sponsored actors.
AdvisoryScreenConnect Remote Access - Help Net SecurityAttackers spread malware through ScreenConnect file transfers
Threat actors are actively exploiting a file transfer vulnerability in ConnectWise ScreenConnect to distribute malware across remote access sessions. According to Huntress research, attackers deploy rogue client instances that spawn VBScript files to establish persistence and create a worm-like infection pattern on newly connected systems. This compromise affects both cloud-hosted and on-premise deployments. As a mitigation pending an official patch, ConnectWise advises administrators to disable file transfer permissions within their role settings.
Reported exploitedScreenConnect - The Hacker NewsN-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
N-able has released Hotfix 4 for the N-central Remote Monitoring and Management platform to address a critical, pre-authentication remote code execution vulnerability identified as CVE-2026-86218. This flaw, which carries a CVSS score of 10.0 and allows unauthenticated attackers to execute arbitrary code on the server, has reportedly been actively exploited in the wild according to N-able's incident notice, although the company's official release notes currently state that such exploitation remains unconfirmed. This update is particularly urgent because it supersedes Hotfix 3, meaning systems patched just one day prior to this release remain vulnerable. All on-premises installations running builds older than 2026.3.1.14 must be updated immediately to prevent unauthorized access and potential endpoint compromise. N-able advises administrators to restrict network exposure and audit user accounts while waiting for deployment completion, noting that hosted instances have already been secured.
Reported exploitedN-central - BleepingComputerN-able patches max severity N-central flaw amid ongoing attacks
N-able has issued an emergency hotfix for a maximum-severity remote code execution vulnerability, identified as CVE-2026-86218, in its N-central platform. This flaw allows unauthenticated attackers to execute malicious code on exposed systems. While N-able has not confirmed widespread production exploitation, security firm Huntress has flagged the issue as part of ongoing active attack campaigns involving related vulnerabilities. Organizations using N-central are advised to install N-central 2026.3 HF4 immediately to mitigate the risk.
Reported exploitedN-able N-central
Sunday, Sep 61 story
- Help Net SecurityWeek in review: Claude accounts compromised through infostealer, Patch Tuesday forecast
This weekly security briefing highlights active exploitation of two zero-day vulnerabilities in SonicWall SMA 1000 appliances, identified as CVE-2026-83548 and CVE-2026-83549. Additionally, Shadowserver Foundation scans reveal that approximately 22,000 Microsoft Exchange servers remain unprotected against critical authentication bypass flaw CVE-2026-62911. The report also covers active targeting of Sangoma Switchvox via recently patched SQL injection defect CVE-2026-9586, alongside broader updates on threats including Claude account compromises via infostealer malware and the September 2026 Patch Tuesday landscape.
RoundupClaude
Saturday, Sep 55 stories
- The Hacker NewsAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
Unidentified threat actors compromised JetBrains' hosted service, Cadence, by exploiting the critical TeamCity vulnerability CVE-2026-63077 between August 8 and 24, 2026. This active exploitation allowed attackers to extract multiple AWS IAM credentials from a server backup and access sensitive user data, including personal information and project source code. JetBrains is urgently advising all Cadence users to revoke and rotate their credentials, as well as invalidating all plugin access tokens to mitigate the risk of further unauthorized access.
Reported exploitedJetBrains Cadence - The Hacker NewsCritical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
Broadcom has issued security updates for VMware Workstation and VMware Fusion to remediate two distinct vulnerabilities, including a critical integer-overflow flaw. The primary issue, identified as CVE-2026-59346 with a CVSS score of 9.3, permits a local administrator within a guest virtual machine using the VMXNET3 adapter to execute arbitrary code on the host system. Additionally, a high-severity stack-based buffer overflow in HGFS (CVE-2026-59347, CVSS 8.1) was addressed, allowing similar privilege escalation to the host's VMX process. Both flaws affect versions 25H2 and 26H1 of the software, and users should update to the fixed releases, VMware Workstation 26H1u1 and VMware Fusion 26H1u1, as no workarounds are available.
PatchVMware Workstation - The Hacker NewsTrezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
Hardware wallet vendor Trezor has disclosed that the recent compromise of its shipping provider, ShipMonk, has affected an additional 67,000 U.S. customers, exposing personal details including names, contact information, and shipping addresses for orders placed between November 2019 and August 2021. This expansion follows a previous disclosure involving roughly 13,600 users and contradicts written assurances previously provided by ShipMonk stating that such data had been deleted per contractual agreements. The intrusion stems from the active exploitation of CVE-2026-72898, a critical zero-day SQL injection vulnerability in Metabase, which allowed the ShinyHunters group to access customer records stored by the logistics firm. While Trezor confirmed that the security of its hardware wallets remains intact, the company warned customers to remain vigilant against targeted phishing campaigns and social engineering attacks leveraging the stolen information.
Reported exploitedShipMonk - SecurityWeekElementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Security firm Defiant reports active exploitation of a critical vulnerability identified as CVE-2026-32475 within the Elementor Pro WordPress plugin. This flaw, assigned a CVSS score of 9.8, allows unauthenticated attackers to bypass file validation by manipulating form submission arrays, enabling them to upload and execute malicious PHP payloads directly on the server. All versions of Elementor Pro prior to 4.2.1 are affected, with the fix available in version 4.2.2 released on August 19. Because attackers began exploiting the issue immediately after the patch dropped, site administrators must update urgently. Defiant has already blocked over 190,000 attack attempts and advises users to inspect the /wp-content/uploads/elementor/forms/ directory for unauthorized PHP files and review logs for suspicious activity related to /wp-admin/admin-ajax.php.
Reported exploitedElementor Pro WordPress Plugin - The Hacker NewsAttackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Arctic Wolf has confirmed active exploitation of CVE-2026-81578 and CVE-2026-82078, a combined authentication bypass and remote code execution vulnerability affecting PaperCut Application Server. Threat actors are leveraging this chain against K-12 schools and universities across the U.S. and Europe to perform system reconnaissance and establish persistent privileged access. Post-compromise activity includes the deployment of credential harvesting tools such as lsacollect.exe and savehives.exe, alongside Metasploit payloads intended to extract sensitive configuration data and SAM database access. To mitigate these risks, administrators should immediately restrict direct internet exposure of PaperCut servers and monitor for anomalous command executions involving cmd.exe or PowerShell processes with pc-app.exe as the parent.
Reported exploitedPaperCut Application Server
Friday, Sep 43 stories
- SecurityWeekIn Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation
Microsoft applied server-side patches to fix nine vulnerabilities affecting services including Entra ID, Azure Cosmos DB, Power Automate, and Copilot Studio. Meanwhile, public exploit code has emerged for CVE-2026-62911, a high-severity flaw in Microsoft Exchange Server that previously received an August patch but still affects more than 21,000 exposed systems.
PoC publicMicrosoft Entra ID - SecurityWeekHPE Patches Critical RCE Vulnerabilities in AOS-CX
Hewlett Packard Enterprise has deployed security updates for the Aruba Networking ArubaOS-CX platform, resolving 34 vulnerabilities including a critical remote code execution flaw identified as CVE-2026-73749. The advisory covers fixes for multiple software releases, specifically 10.18.1002, 10.17.1030, 10.16.1060, 10.13.1190, and 10.10.1181, addressing issues ranging from denial-of-service attacks to authentication bypasses. This specific cluster of critical defects allows unauthenticated attackers to execute arbitrary commands with elevated privileges by sending malformed input to an internal service. While HPE reports that these flaws were found internally and there is no evidence of active exploitation yet, network administrators are advised to apply the latest patches and restrict management interface access.
PatchArubaOS-CX (AOS-CX) - BleepingComputerCritical Citrix NetScaler auth bypass now leveraged in attacks
Security researchers at Previdian have observed active exploitation attempts against CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and Gateway appliances. This flaw enables unprivileged attackers to remotely circumvent authentication controls on devices configured as AAA virtual servers or Gateways (including SSL VPN and RDP proxies). While Citrix issued a patch in mid-August, recent data indicates that adversaries began targeting this weakness following the publication of a proof-of-concept exploit. Belgian cyber authorities have also warned organizations to prioritize upgrading vulnerable NetScaler instances to the recommended builds.
Reported exploitedCitrix NetScaler ADC