Post

Cybersecurity Newsfeed - 10/09/26

Daily cybersecurity news covering vulnerabilities, adversaries, trends, breaches, and other notable security developments.

Cybersecurity Newsfeed - 10/09/26

Cybersecurity Newsfeed

📅 10/09/26

🛡️ Vulnerabilities

  • Maximum-Severity Cisco FMC Authentication Bypass (CVE-2026-20079): Cisco confirmed active exploitation of a CVSS 10.0 authentication bypass flaw in Secure Firewall Management Center (FMC) software. Unauthenticated remote attackers can send crafted HTTP requests to execute arbitrary commands with root privileges across on-premises and Security Cloud Control services. More info

  • CISA Adds Four Vulnerabilities to KEV Catalog: CISA added CVE-2025-25249 (Fortinet buffer overflow), CVE-2026-19490 (Citrix NetScaler authentication bypass), CVE-2026-87491 (Google Chromium V8 write flaw), and CVE-2026-20079 (Cisco FMC root access flaw) to its KEV catalog, ordering federal agencies to patch immediately. More info

  • Microsoft Defender “ShieldCrash” Zero-Day Disclosed: A zero-day flaw in Microsoft Defender permits local privilege escalation to SYSTEM level and denial-of-service conditions by abusing real-time scanning engine file parsing routines. More infoMore info
  • Critical Pre-Auth RCE in N-able N-central: A critical vulnerability in N-able N-central remote monitoring software allows unauthenticated remote attackers to send crafted requests and execute arbitrary commands with SYSTEM rights on central management servers. More info

  • Chrome 153 Patches Seventh Zero-Day of 2026 (CVE-2026-87491): Google addressed an actively exploited out-of-bounds write flaw in the Chrome V8 JavaScript engine that allows attackers to crash processes or execute arbitrary code. More info

  • Critical Input Validation Flaw in Alby Hub: Open-source Lightning Network management software Alby Hub fixed an API endpoint input validation flaw that could allow unauthenticated remote code execution and wallet draining. More info

  • Ivanti Issues Emergency Patches Across Enterprise Products: Security updates addressed multiple critical remote code execution, SQL injection, and privilege escalation vulnerabilities affecting Endpoint Manager and Connect Secure appliances. More info

  • cPanel Shared Hosting Local Privilege Escalation: A vulnerability in cPanel system management scripts allows web hosting users to bypass permission checks and elevate privileges to root across multi-tenant shared hosting environments. More info

  • Bluetooth Hijacking Flaw in Skullcandy Dime 3 Earbuds: Improper pairing authentication procedures in Skullcandy Dime 3 wireless earbuds allow nearby unauthenticated attackers to force connections, inject audio, or intercept microphone input. More info

  • Android September 2026 Security Updates Patch 180 Flaws: Google released fixes for 180 vulnerabilities across system components, frameworks, and vendor hardware drivers, addressing high-severity remote code execution and privilege escalation flaws. More info

🎯 Adversaries

  • Four Espionage Groups Exploit Identical Chrome and Windows Zero-Days: Four distinct state-sponsored APT groups independently deployed identical commercial exploit chains targeting browser parsing engines and Windows kernel privilege escalation flaws. More info

  • AI-Powered “Blue Moon” Exploitation Framework Disclosed: Threat actors are using the “Blue Moon” framework targeting Chrome and Windows environments, leveraging integrated AI code generation to automate exploit chain development and dynamic payload obfuscation. More info

  • Fileless Memory Rootkit Targets F5 BIG-IP APM: Threat actors are deploying a rootkit hiding a web shell entirely within volatile RAM on F5 BIG-IP Access Policy Manager appliances to evade file integrity checks and intercept authentication traffic. More info

  • US Accuses Chinese Firms of Extensively Scraping US AI Models: US officials and agencies warned that foreign entities are using proxy networks to extract billions of tokens and model outputs from frontier American AI models via knowledge distillation techniques. More infoMore infoMore info
  • Passkey-Themed Social Engineering Attacks Cloud Identity: Attackers are bypassing traditional MFA by tricking corporate employees into registering attacker-controlled passkeys during fake account recovery workflows. More info
  • Account Recovery Flow Becomes Primary MFA Bypass Vector: Threat actors are shifting away from direct protocol attacks to target self-service password resets, help desk social engineering, and SIM swaps to reset parameters and gain access. More info

  • Infostealer Logs Expose Replayable AI Session Tokens: Leaked session cookies captured by infostealers allow unauthorized actors to replay active sessions and gain persistent access to corporate AI platform logs, prompt histories, and code snippets. More info

  • Over 100,000 Fraudulent Online Stores Harvesting Payment Cards: Threat researchers uncovered a network of over 100,000 fake retail storefronts that mimic legitimate brands to harvest consumer credit card details and personal identity data. More info

  • Microsoft Releases Cloud and Web Application Threat Matrix: Microsoft published a comprehensive security framework detailing threat patterns across enterprise identity boundaries, cross-cloud tenant exposures, and web service API vulnerabilities. More info

💥 Breaches & Leaks

  • AdaptHealth Discloses Healthcare Data Breach Impacting 4.1M People: Medical supplier AdaptHealth confirmed a major breach following a July cyberattack that compromised personal identifiers, contact details, medical records, and health insurance information. More info

  • Veradigm Patient Data Breach Claimed by “Gentlemen” Group: Healthcare software provider Veradigm confirmed a network intrusion resulting in the extraction of patient names, clinical details, and demographic indicators by extortion actors. More info

⚖️ Law Enforcement & Defense

  • US Authorities Disrupt “Xinbi Guarantee” Escrow Scam Network: The US Department of Justice seized server infrastructure, web domains, and cryptocurrency assets belonging to Xinbi Guarantee, an illicit escrow platform that laundered hundreds of millions from ransomware and BEC scams. More info

📚 Others

  • Zscaler Launches Agentic SOC Solution: Zscaler introduced an autonomous SOC solution leveraging dynamic AI agents to automate threat triage, context enrichment, and incident containment across enterprise telemetry. More info

  • Securin Updates Exposure Management Platform: Securin released an updated attack surface monitoring platform combining vulnerability management, asset inventory tracking, and real-time threat intelligence. More info

  • Microsoft Unveils Age Awareness APIs for Developers: Microsoft introduced privacy-preserving APIs that analyze account telemetry to indicate whether users are children, teens, or adults to aid global child safety compliance. More info


⬅ Back to Archive

This post is licensed under CC BY 4.0 by the author.