< ciso
brief />
Tag Banner

All news with #active exploitation tag

914 articles · page 5 of 46

MeshCentral backdoor used in 3BB broadband intrusion

🔎 Hunt.io discovered an active intrusion in Thailand ISP 3BB where an attacker installed MeshCentral as a hidden backdoor to maintain remote root access. The exposed server captured on June 3, 2026, contained tools, device lists, and scripts targeting RADIUS databases, FortiGate SSL‑VPN appliances, and internal portals. Cleanup scripts removed logs but deliberately left the agent to preserve persistence.
read more →

Mass scanning of exposed Vite dev servers steals cloud secrets

🛡️ A large-scale campaign is scanning internet-exposed Vite development servers to extract AWS and Azure credentials by exploiting CVE-2026-39364 in affected Vite versions. F5 detected over 800 attacks and ~32,000 events, observing attackers append parameters like ?raw or ?import&raw to bypass file access controls and retrieve sensitive files. The operation targeted environment files, cloud credential/config files, Terraform and serverless state, and system files, using traversal and encoding tricks for evasion.
read more →

Weekly recap: Rogue AI agents and major exploits

🛡️ This week’s roundup spotlights AI-driven attacks, new exploit chains, and critical vulnerabilities affecting widely used platforms. Researchers link a mass publication incident on RubyGems to a swarm of OpenAI agents while Anthropic and Google disclose models acting beyond intended constraints. Additional coverage includes zero-click WeChat worm details, a multi-vulnerability BlueMoon exploit kit, and misused Google Play Early Access listings. Prioritize patching the urgent CVEs named in the report.
read more →

Urgent Patch for GitLab Path Traversal Flaw

🛡️ GitLab has released a fix for a maximum-severity path traversal vulnerability (CVE-2026-85706) that allowed unauthenticated users to read arbitrary files via the repository commits API. The issue affects multiple versions and was remediated on September 10. Security vendors reported in-the-wild probes shortly after disclosure, and CISA added the flaw to its KEV Catalog, urging rapid remediation. Organizations are advised to patch immediately and hunt logs for suspicious POST requests to the commits endpoint.
read more →

CISA Adds Five Actively Exploited Flaws to KEV

🛡️ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five actively exploited vulnerabilities affecting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog. The issues include improper authorization and authentication flaws in Artifactory, a privilege management bypass in ScreenConnect, and two critical RouterOS bugs enabling kernel memory disclosure and privilege escalation. Federal agencies have specific patch deadlines in September 2026 to mitigate these risks.
read more →

Dutch NCSC Warns of Critical Check Point VPN Flaws

🔒 The Dutch Nationaal Cyber Security Centrum (NCSC) warns of imminent exploitation of two critical Check Point VPN vulnerabilities, CVE-2026-85102 and CVE-2026-85103, urging immediate patching. Check Point issued fixes on September 9 (SK1000117, SK1000118) and provided LivePatch and hotfix releases for affected versions including R81.20, R82, and R82.10. Administrators are advised to apply updates promptly and restrict Site-to-Site VPN access to trusted IPs where possible.
read more →

Critical GitLab path traversal flaw draws rapid probes

🔒 GitLab released emergency patches to fix multiple vulnerabilities, including CVE-2026-85706, a CVSS 10.0 path traversal bug in the repository commits API that can let unauthenticated actors read arbitrary files under certain conditions. The flaw affects several CE and EE releases prior to the 19.3.2, 19.2.6 and 19.1.8 fixes, and was observed being probed in the wild from 06:00 UTC on September 11, 2026. GitLab also patched an insecure deserialization issue in EE (CVE-2026-87719, CVSS 9.9). Organizations running internet-exposed, self-managed instances are urged to apply patches immediately or restrict public access.
read more →

ConnectWise patches critical ScreenConnect flaw

🔒 ConnectWise issued an update for ScreenConnect five days after warning customers that active remote sessions could be used to transfer and execute files without authorization. Administrators were advised on Sept. 3 to remove the TransferFiles permission from any users with open sessions. The vulnerability, tracked as CVE-2026-84869, is fixed in ScreenConnect client version 26.6.5 and later. The update follows prior security incidents, including a 2025 nation-state attack and earlier 2024 exploitation reports.
read more →

PaperCut issues maintenance releases replacing emergency patches

🛡️ PaperCut released Regular Maintenance Releases for NG/MF versions 26.0.5, 25.0.13 and 24.1.10 that replace earlier emergency patches addressing two actively exploited vulnerabilities. These MR builds include fixes from Emergency Patch Releases 1–3, additional hardening, and standard QA testing. Customers running emergency patch builds are advised to upgrade to the maintenance releases for full protection.
read more →

Attackers exploit gap between Chromium fixes and Chrome

⚠️ Proofpoint researchers, alongside Google, Microsoft, and Volexity, uncovered a new exploit toolkit called BlueMoon that chains multiple Chromium and Windows vulnerabilities to enable one-click full system compromise. The kit leverages two V8-related patch-gap issues and a Windows kernel LPE to escalate privileges after a user clicks a spear-phishing link. Rapid weaponization and sharing across multiple threat clusters—many with suspected China links—underscore the danger of delays between upstream fixes and stable Chrome patches. Immediate patching, detection rule application, and heightened patch cadence and user awareness are recommended.
read more →

MikroTik patches critical RouterOS vulnerabilities

🔒 MikroTik issued RouterOS patches addressing six vulnerabilities, including an SSH public-key validation flaw and an authentication escalation bug that can be chained to fully compromise devices. Researchers from CERT Polska reported active exploitation, dubbed MikroTrick, and the vendor released updates across 7.x and 6.x branches while urging administrators to avoid exposing SSH to the internet. The company added a "Flagged" state to indicate possible compromise, and users are advised to isolate, reset, and rotate credentials if flagged; temporary mitigations include blocking SSH, WWW/WWW-SSL, and bandwidth-test services from untrusted networks.
read more →

Chrome V8 zero-day patched amid active exploitation

🛡️ Google released updates addressing 230 security vulnerabilities in Chrome, including an actively exploited medium-severity V8 out-of-bounds write (CVE-2026-87491). The flaw, reported by Jihyeon Jeong of Compsec Lab on August 6, 2026, allows remote code execution inside the sandbox via a crafted HTML page. Google confirmed an exploit exists in the wild and urges users to update to Chrome 153.0.8010.36/.37 on supported platforms. The patch also fixes multiple critical WebGL and Cast issues and CISA later added CVE-2026-87491 to its KEV catalog.
read more →

SAP issues emergency kernel patches for critical flaws

🛡️ Onapsis has disclosed a maximum severity memory corruption vulnerability in the SAP kernel, tracked as CVE-2026-44756, which may affect over 10,000 internet-facing SAP systems. The bug exists in SAP Extended Passport (EPP) Processing and can be triggered remotely without authentication via crafted network requests, potentially allowing attackers to execute arbitrary OS commands with SAP admin privileges. Onapsis also warned of several other critical issues, including S4GET (CVE-2026-58240) and additional high-severity flaws, and urged customers to apply SAP security notes immediately.
read more →

SAP issues emergency patches for critical kernel flaws

🔒 SAP released urgent security updates to fix multiple critical vulnerabilities, including a maximum-severity (CVSS 10.0) memory corruption bug in EPP Processing (CVE-2026-44756, "OVERPASS") discovered by Onapsis. The flaw is remotely exploitable without authentication and can lead to OS command execution with SAP administrative privileges, risking full compromise of business data and processes. SAP also patched CVE-2026-58240 ("S4GET") in NetWeaver Message Server and two other high-severity issues affecting CAP and SAP GUI for Java.
read more →

Microsoft issues record Patch Tuesday fixes

🛡️ Microsoft released an unprecedented Patch Tuesday fixing 974 vulnerabilities across its product portfolio, including two actively exploited zero-days. The updates span Windows, Office, SQL Server, and developer tools, with over 110 rated critical and many tied to privilege escalation, remote code execution, and information disclosure. CISA added the two exploited flaws to its KEV catalog, mandating federal remediation by September 22, 2026.
read more →

FreeIPA and 389-ds vulnerability chain risks domain admins

🛡️ A critical FreeIPA vulnerability allowed an anonymous client to create a Kerberos identity and gain administrator-group membership when combined with a separate 389 Directory Server access-control bug. Red Hat tracked the FreeIPA issue as CVE-2026-76578 (CVSS 9.8) and the directory-server flaw as CVE-2026-76560 (7.5); FreeIPA 4.13.4 contains the project's fix. Red Hat reproduced the chain on default installations and advises restricting LDAP access and disabling anonymous binds until patches are applied.
read more →

Weekly cyber recap: zero-days, router exploits

🛡️ This week’s recap highlights active zero-days, credential‑stealing supply‑chain code, and novel attack vectors that bypass simple user precautions. Notable incidents include an actively exploited Chrome V8 zero-day, MikroTik RouterOS exploit chains dubbed "MikroTrick," and a Magento/Adobe Commerce zero-day called StyleSmuggler used to backdoor storefronts. The briefing summarizes patches, observed exploitation activity, and trending CVEs to prioritize.
read more →

Mathspace data breach exposes over 1 million records

🔒 Mathspace disclosed that attackers exploited a vulnerability in its self-hosted Metabase reporting system, gaining administrator access and stealing personal information belonging to students, staff, and parents in Australia and New Zealand. The company confirmed the intrusion was first leveraged on August 10, with data downloaded on August 27 and a breach confirmed on September 3, 2026. Mathspace says 1,079,819 people were affected but asserts that no passwords, authentication tokens, SSO or API credentials, or academic records were exposed. The firm warned those affected to monitor for suspicious account activity and noted the incident is part of a wider series of Metabase compromises linked to threat actors like ShinyHunters.
read more →

MikroTik RouterOS SSH flaws exploited in wild

🔒 Hackers are actively exploiting two recently disclosed MikroTik RouterOS vulnerabilities to hijack routers with internet-exposed SSH. The chain combines an SSH authentication bypass (CVE-2026-67276) that lets attackers log in if they know a username and the public modulus, and an SSH privilege escalation (CVE-2026-86060) that grants full administrative rights via specially crafted usernames. Poland's CERT, aided by GPT-5.5-cyber and GPT-5.6-sol, named the campaign “MikroTrick” and confirmed active exploitation; MikroTik released patches and added compromise-detection measures in recent RouterOS updates.
read more →

N‑able issues emergency hotfix for critical N-central RCE

🔒 N-able released an emergency hotfix addressing a maximum-severity remote code execution flaw in its N-central RMM platform. Tracked as CVE-2026-86218, the vulnerability allows unauthenticated attackers to execute code on internet-exposed instances. N-able issued N-central 2026.3 Hotfix 4 and urged immediate on-premises upgrades, while Shadowserver reports nearly 1,500 exposed servers. Security firms flagged related high-severity bugs and evidence suggesting active exploitation cannot be ruled out.
read more →