Cybersecurity Newsfeed - 10/09/26
Daily cybersecurity news covering vulnerabilities, adversaries, trends, breaches, and other notable security developments.
Cybersecurity Newsfeed
📅 10/09/26
🛡️ Vulnerabilities
Maximum-Severity Cisco FMC Authentication Bypass (CVE-2026-20079): Cisco confirmed active exploitation of a CVSS 10.0 authentication bypass flaw in Secure Firewall Management Center (FMC) software. Unauthenticated remote attackers can send crafted HTTP requests to execute arbitrary commands with root privileges across on-premises and Security Cloud Control services. More info
CISA Adds Four Vulnerabilities to KEV Catalog: CISA added CVE-2025-25249 (Fortinet buffer overflow), CVE-2026-19490 (Citrix NetScaler authentication bypass), CVE-2026-87491 (Google Chromium V8 write flaw), and CVE-2026-20079 (Cisco FMC root access flaw) to its KEV catalog, ordering federal agencies to patch immediately. More info
Critical Pre-Auth RCE in N-able N-central: A critical vulnerability in N-able N-central remote monitoring software allows unauthenticated remote attackers to send crafted requests and execute arbitrary commands with SYSTEM rights on central management servers. More info
Chrome 153 Patches Seventh Zero-Day of 2026 (CVE-2026-87491): Google addressed an actively exploited out-of-bounds write flaw in the Chrome V8 JavaScript engine that allows attackers to crash processes or execute arbitrary code. More info
Critical Input Validation Flaw in Alby Hub: Open-source Lightning Network management software Alby Hub fixed an API endpoint input validation flaw that could allow unauthenticated remote code execution and wallet draining. More info
Ivanti Issues Emergency Patches Across Enterprise Products: Security updates addressed multiple critical remote code execution, SQL injection, and privilege escalation vulnerabilities affecting Endpoint Manager and Connect Secure appliances. More info
cPanel Shared Hosting Local Privilege Escalation: A vulnerability in cPanel system management scripts allows web hosting users to bypass permission checks and elevate privileges to root across multi-tenant shared hosting environments. More info
Bluetooth Hijacking Flaw in Skullcandy Dime 3 Earbuds: Improper pairing authentication procedures in Skullcandy Dime 3 wireless earbuds allow nearby unauthenticated attackers to force connections, inject audio, or intercept microphone input. More info
- Android September 2026 Security Updates Patch 180 Flaws: Google released fixes for 180 vulnerabilities across system components, frameworks, and vendor hardware drivers, addressing high-severity remote code execution and privilege escalation flaws. More info
🎯 Adversaries
Four Espionage Groups Exploit Identical Chrome and Windows Zero-Days: Four distinct state-sponsored APT groups independently deployed identical commercial exploit chains targeting browser parsing engines and Windows kernel privilege escalation flaws. More info
AI-Powered “Blue Moon” Exploitation Framework Disclosed: Threat actors are using the “Blue Moon” framework targeting Chrome and Windows environments, leveraging integrated AI code generation to automate exploit chain development and dynamic payload obfuscation. More info
Fileless Memory Rootkit Targets F5 BIG-IP APM: Threat actors are deploying a rootkit hiding a web shell entirely within volatile RAM on F5 BIG-IP Access Policy Manager appliances to evade file integrity checks and intercept authentication traffic. More info
- Passkey-Themed Social Engineering Attacks Cloud Identity: Attackers are bypassing traditional MFA by tricking corporate employees into registering attacker-controlled passkeys during fake account recovery workflows. More info
📈 Trends
Account Recovery Flow Becomes Primary MFA Bypass Vector: Threat actors are shifting away from direct protocol attacks to target self-service password resets, help desk social engineering, and SIM swaps to reset parameters and gain access. More info
Infostealer Logs Expose Replayable AI Session Tokens: Leaked session cookies captured by infostealers allow unauthorized actors to replay active sessions and gain persistent access to corporate AI platform logs, prompt histories, and code snippets. More info
Over 100,000 Fraudulent Online Stores Harvesting Payment Cards: Threat researchers uncovered a network of over 100,000 fake retail storefronts that mimic legitimate brands to harvest consumer credit card details and personal identity data. More info
Microsoft Releases Cloud and Web Application Threat Matrix: Microsoft published a comprehensive security framework detailing threat patterns across enterprise identity boundaries, cross-cloud tenant exposures, and web service API vulnerabilities. More info
💥 Breaches & Leaks
AdaptHealth Discloses Healthcare Data Breach Impacting 4.1M People: Medical supplier AdaptHealth confirmed a major breach following a July cyberattack that compromised personal identifiers, contact details, medical records, and health insurance information. More info
Veradigm Patient Data Breach Claimed by “Gentlemen” Group: Healthcare software provider Veradigm confirmed a network intrusion resulting in the extraction of patient names, clinical details, and demographic indicators by extortion actors. More info
⚖️ Law Enforcement & Defense
- US Authorities Disrupt “Xinbi Guarantee” Escrow Scam Network: The US Department of Justice seized server infrastructure, web domains, and cryptocurrency assets belonging to Xinbi Guarantee, an illicit escrow platform that laundered hundreds of millions from ransomware and BEC scams. More info
📚 Others
Zscaler Launches Agentic SOC Solution: Zscaler introduced an autonomous SOC solution leveraging dynamic AI agents to automate threat triage, context enrichment, and incident containment across enterprise telemetry. More info
Securin Updates Exposure Management Platform: Securin released an updated attack surface monitoring platform combining vulnerability management, asset inventory tracking, and real-time threat intelligence. More info
Microsoft Unveils Age Awareness APIs for Developers: Microsoft introduced privacy-preserving APIs that analyze account telemetry to indicate whether users are children, teens, or adults to aid global child safety compliance. More info
