< ciso
brief />
Astra Rollout Stumbles; Critical Fixes and Major Breaches

Astra Rollout Stumbles; Critical Fixes and Major Breaches

Coverage: 07 Sept 2026 (UTC)

< view all daily briefs >

Security teams faced a mixed slate of vendor rollouts, emergency fixes, active exploitation, and expanding breach fallout. OpenAI’s newest model launch drew governance questions as enterprises waited for access, while administrators of RMM tools, routers, and remote access software confronted critical vulnerabilities and public exploit releases. At the same time, lawsuits and disclosures highlighted how identity integrations and third‑party platforms can broaden blast radius, and threat actors continued to refine social engineering and token‑theft techniques that evade endpoint defenses.

AI Rollouts Meet Enterprise Reality

CSO Online reports that OpenAI’s introduction of GPT‑6 Astra ran into access gaps for many paid subscribers and API users, prompting CEO Sam Altman to apologize for a “messy” rollout and outline a staged expansion from Pro and enterprise customers to Plus and other tiers. Analysts framed the episode as an operational signal rather than a product failure, urging organizations to verify entitlements, adjust identity and governance controls, and scrutinize how contracts and SLAs account for availability that varies by subscription, surface, or phase; they also advised focusing on concrete use‑case outcomes and strengthening observability and accountability as agentic capabilities scale.

Critical Fixes and Active Exploits

Infosecurity reports that N‑able released an urgent hotfix for CVE‑2026‑86218, a CVSS 10 pre‑auth remote code execution flaw in the N‑central RMM platform; the issue is remediated in N‑central 2026.3 Hotfix 4 (build 2026.3.1.14). The vendor has not shared technical details and says it has no evidence of in‑production exploitation; the fix follows earlier hotfixes for related authentication and access‑control issues, some of which were previously exploited and added to CISA’s KEV list, underscoring the need for customers to update promptly.

BleepingComputer details an exploit chain (“MikroTrick”) disclosed by Poland’s CERT that combines an SSH authentication bypass (CVE‑2026‑67276) with an SSH privilege escalation (CVE‑2026‑86060) to seize full control of internet‑exposed MikroTik routers; a separate bandwidth‑test issue (CVE‑2026‑67277) can leak kernel memory or crash devices. MikroTik has issued fixes in RouterOS 7.25beta3, 7.24.2, 7.23.4, and 6.49.21 and added startup compromise‑detection measures; administrators are advised to patch, restrict or disable externally accessible SSH/WWW services, and, for suspected compromise, isolate, factory‑reset, rebuild from trusted configs, and rotate secrets, with Shadowserver observing over 122,500 devices exposing SSH.

BleepingComputer also relays that ConnectWise warned of a new ScreenConnect vulnerability affecting cloud‑hosted and on‑prem deployments, with a patch pending; as an interim mitigation, administrators should edit roles to deselect TransferFiles (or legacy TransferFilesInSession) permissions across session groups. With nearly 6,000 ScreenConnect instances exposed online per Shadowserver and a track record of exploitation by ransomware and state‑backed actors, swift mitigation and heightened monitoring are recommended until a permanent fix is available.

The Hacker News reports that TantoSec published a full exploit chain and tooling that weaponize an AES‑CBC padding‑oracle (CVE‑2026‑13182) in Telerik UI for ASP.NET AJAX’s RadAsyncUpload into unauthenticated RCE by abusing type resolution (CVE‑2026‑13181) and a timing‑variant oracle (CVE‑2026‑13183). Progress fixed the issues in version 2026.2.708, which moves to authenticated encryption; while exploitation requires non‑default preconditions, defenders are urged to upgrade, enable customErrors, disable the async upload handler if unused, or revert to machine‑key encryption, and to hunt for behavioral signs such as unexpected .aspx files or mixed‑mode DLLs in upload/temp paths.

Infosecurity highlights a researcher‑published proof of concept (“FalconFlank”) for a zero‑day local privilege escalation targeting CrowdStrike Falcon Sensor’s Microsoft Office malicious macro remediation feature; CrowdStrike advised customers to disable the Windows policy setting for Microsoft Office File Suspicious Macro Removal while it investigates. The PoC reportedly works on fully updated Windows 11 25H2 and Windows Server 2025 when Phase 3 Optimal Protection and the macro‑removal feature are enabled; no CVE has been issued at report time.

Breaches Expose Identity and Vendor Risk

Infosecurity reports multiple class‑action lawsuits in U.S. federal court alleging a massive leak of driver’s licenses and other identity documents tied to IDScan.net, a B2B ID‑verification provider used by major firms and cannabis dispensaries. The FBI has opened an investigation following reporting that linked a Russian forum seller’s trove to IDScan.net; plaintiffs seek damages and stronger controls, while legal advisers urge affected individuals to document where their IDs were scanned and to avoid sending sensitive details unsolicited.

BleepingComputer writes that Mathspace disclosed a breach impacting 1,079,819 individuals after attackers exploited a vulnerability in a self‑hosted Metabase reporting system to gain admin access and download data from an Australian database. Exposed records include personal information for students, staff, and parents/guardians in Australia and New Zealand; while no passwords or tokens were disclosed, Mathspace warned of targeted social‑engineering risks and noted the broader campaign against Metabase instances linked to the ShinyHunters group in other cases.

BleepingComputer also reports that Trezor expanded its disclosure to 81,000 customers after a third‑party logistics provider (ShipMonk) breach exposed names, shipping addresses, emails, phone numbers, and order numbers; the scope grew due to data retention beyond contractual commitments. Trezor emphasized that its infrastructure and devices were not compromised but warned of elevated phishing and potential physical‑targeting attempts leveraging leaked data, urging vigilance.

Bitdefender describes how a flawed Lenovo ID email verification process allowed attackers to create Lenovo accounts with victims’ email addresses and, because Dropbox still accepted Lenovo ID authentication, access ~5,000 Dropbox accounts without the Dropbox password. Dropbox terminated Lenovo ID sessions, now requires entry of the Dropbox password even when using Lenovo ID, and advised resets and 2FA, illustrating how identity verification lapses at one vendor can cascade through trusted SSO links.

Social Engineering and Token Theft

The Hacker News details a data‑theft and extortion cluster (tracked by Arctic Wolf as PREY‑0058) that targets executives with help‑desk vishing, lures them to authentication‑themed domains, and uses adversary‑in‑the‑middle Microsoft 365 flows to harvest credentials and MFA approvals. The actors replay session tokens via residential proxies to bypass protections, then enumerate and exfiltrate content from SharePoint, OneDrive, Exchange, and Box; recommended countermeasures include Conditional Access, phishing‑resistant MFA, tighter SharePoint scoping, and vishing‑aware training.

The Hacker News also documents JSCeal, a compiled V8 JavaScript malware delivered via malvertising and lookalike trading sites that steals credentials, cookies, and OAuth tokens from multiple Chromium‑based browsers and can reconstruct sessions to bypass Google authentication. Strong obfuscation, proxy capabilities, and version‑specific artifacts complicate analysis and detection, while targets include retail traders and crypto investors across languages and regions.

Astra Rollout Stumbles; Critical Fixes and Major Breaches · CISO Brief