{"date_iso":"2026-09-16","date_human":"Wednesday, September 16, 2026","generated_utc":"2026-09-16 17:36 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds","link":"https://cybersecuritynews.com/ghostcode-phishing-kit/","reason":"Microsoft","category":"News","sources":["Bleeping Computer","Cyber Security News","Dark Reading","Infosecurity Magazine","Schneier on Security","The Register Security","Zero Day Initiative"],"coverage":7,"cve_ids":[],"summary":"GhostCode is a newly identified phishing kit that turns a normal Microsoft 365 sign-in into an account takeover. It does not need to steal a password. Instead, it persuades people to approve a login that gives criminals\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/GhostCode-Phishing-Kit-Bypasses-Microsoft-365-MFA-to-Hijack-Accounts-in-78-Seconds.webp","description":"GhostCode is a newly identified phishing kit that turns a normal Microsoft 365 sign-in into an account takeover. It does not need to steal a password. Instead, it persuades people to approve a login that gives criminals access to their work account. The campaign began with ordinary-looking messages submitted through business contact forms. Attackers posed as procurement staff, followed up with a request to sign a non-disclosure agreement, then sent a WeTransfer link holding a password-protected HTML attachment. The file presented a document-sharing lure and directed the recipient to a\u2026","related":[{"title":"Microsoft 365 Hit by New Outage as Users Report Widespread 502 and 503 Errors","link":"https://cybersecuritynews.com/microsoft-365-hit-by-new-outage/","source":"Cyber Security News","date_rel":"2h ago"},{"title":"Microsoft says Copilot buttons still missing in classic Outlook","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-workaround-for-missing-outlook-copilot-buttons/","source":"Bleeping Computer","date_rel":"5h ago"},{"title":"Windows Server 2022 reaches end of mainstream support next month","link":"https://www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches-end-of-mainstream-support-next-month/","source":"Bleeping Computer","date_rel":"8h ago"},{"title":"Mythos has made 2026 patching hell. It might make 2027 a breeze","link":"https://www.theregister.com/security/2026/09/16/mythos-has-made-2026-patching-hell-it-might-make-2027-a-breeze/5296747","source":"The Register Security","date_rel":"11h ago"},{"title":"ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-708/","source":"Zero Day Initiative","date_rel":"12h ago"},{"title":"Microsoft Issues Emergency Fixes After Massive Patch Tuesday","link":"https://www.darkreading.com/application-security/microsoft-emergency-fixes-patch-tuesday","source":"Dark Reading","date_rel":"21h ago"}]},{"title":"Hackers Can Rent VectraRAT for $250 a Month to Take Control of Windows PCs","link":"https://cybersecuritynews.com/hackers-can-rent-vectrarat/","reason":"Windows","category":"News","sources":["Cyber Security News","Dark Reading","Microsoft Security","The Hacker News","The Register Security"],"coverage":5,"cve_ids":["CVE-2026-68841","CVE-2026-69406","CVE-2026-69608"],"summary":"Hackers can now rent a Windows-focused remote access tool called VectraRAT for $250 a month, lowering the barrier to deep and persistent compromise. The malware gives paying operators a way to watch victims, steal data\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Hackers-Can-Rent-VectraRAT-for-250-a-Month-to-Take-Control-of-Windows-PCs.webp","description":"Hackers can now rent a Windows-focused remote access tool called VectraRAT for $250 a month, lowering the barrier to deep and persistent compromise. The malware gives paying operators a way to watch victims, steal data, run commands, and move traffic through an infected computer. VectraRAT has surfaced as a rental-only malware service rather than a one-off tool used by a single group. Investigators linked it to campaigns that use the Amadey loader and ClickFix pages, where fake verification prompts persuade people to run copied commands on their own devices. SOCRadar said in a report shared\u2026","related":[{"title":"Iranian spies hit Windows machines with Chosen Brick data-stealing malware","link":"https://www.theregister.com/security/2026/09/15/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/5296646","source":"The Register Security","date_rel":"23h ago"},{"title":"VectraRAT Can Hack Windows Enterprises for $250 per Month","link":"https://www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises","source":"Dark Reading","date_rel":"15 Sep"},{"title":"Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists","link":"https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html","source":"The Hacker News","date_rel":"15 Sep"},{"title":"CVE-2026-68841 Windows NTFS Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68841","source":"Microsoft Security","date_rel":"15 Sep"},{"title":"CVE-2026-69406 Windows Kernel Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69406","source":"Microsoft Security","date_rel":"15 Sep"},{"title":"CVE-2026-69608 Microsoft Windows Search Component Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69608","source":"Microsoft Security","date_rel":"15 Sep"}]},{"title":"Hackers Use Cross-Platform Noodle RAT to Secretly Control Windows and Linux Systems","link":"https://cybersecuritynews.com/cross-platform-noodle-rat/","reason":"Linux","category":"News","sources":["Bleeping Computer","Cyber Security News","Dark Reading","The Hacker News","Zero Day Initiative"],"coverage":5,"cve_ids":[],"summary":"Noodle RAT is a remote-access trojan that gives attackers control of compromised computers and servers. Its renewed visibility matters because it runs on both Windows and Linux, allowing one malware family to follow\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Hackers-Use-Cross-Platform-Noodle-RAT-to-Secretly-Control-Windows-and-Linux-Systems.webp","description":"Noodle RAT is a remote-access trojan that gives attackers control of compromised computers and servers. Its renewed visibility matters because it runs on both Windows and Linux, allowing one malware family to follow victims across corporate networks. The tool has appeared in operations against organisations across Asia-Pacific, including Thailand, India, Japan, Malaysia and Taiwan. Operators can steal files, run commands and route traffic through a victim system, expanding an initial breach into a wider network risk. Check Point analysts identified the malware as a distinct family, rather\u2026","related":[{"title":"Cyber Op Targets South Korean Media & Automotive Sectors","link":"https://www.darkreading.com/cyberattacks-data-breaches/cyber-south-korean-media-automotive","source":"Dark Reading","date_rel":"16h ago"},{"title":"Acronis warns of actively exploited flaw in its cPanel backup plugin","link":"https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/","source":"Bleeping Computer","date_rel":"19h ago"},{"title":"BambooToken Malware Uses MQTT to Control Windows and Linux Systems","link":"https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html","source":"The Hacker News","date_rel":"15 Sep"},{"title":"BambooToken malware controls Windows and Linux systems via MQTT","link":"https://www.bleepingcomputer.com/news/security/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt/","source":"Bleeping Computer","date_rel":"15 Sep"},{"title":"ZDI-26-702: Linux Kernel usbnet Driver Race Condition Privilege Escalation Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-702/","source":"Zero Day Initiative","date_rel":"14 Sep"},{"title":"ZDI-26-701: Linux Kernel TLS Protocol Out-Of-Bounds Read Information Disclosure Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-701/","source":"Zero Day Initiative","date_rel":"14 Sep"}]},{"title":"Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware","link":"https://www.huntress.com/blog/google-doc-sidebar-malware-mac-windows","reason":"Google","category":"Threat Intel","sources":["CCCS Alerts & Advisories","Huntress","Malwarebytes Labs","Wiz Research"],"coverage":4,"cve_ids":[],"summary":"A single X DM split into two malware chains: AMOS stealer on Mac, NetSupport Manager on Windows, see the Huntress SOC analyst breakdown.","source":"Huntress","date_rel":"15 Sep","thumbnail":"https://cdn.builder.io/api/v1/image/assets%2F3eb6f92aedf74f109c7b4b0897ec39a8%2Fdca76d702afd4b8fb78824a5b8651986","description":"","related":[{"title":"Google security advisory (AV26-926)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-926","source":"CCCS Alerts & Advisories","date_rel":"21m ago"},{"title":"Google Pixel owners urged to patch actively exploited modem flaw","link":"https://www.malwarebytes.com/blog/mobile/2026/09/google-pixel-owners-urged-to-patch-actively-exploited-modem-flaw","source":"Malwarebytes Labs","date_rel":"6h ago"},{"title":"Investing Together: Wiz Defend and Google Security Operations","link":"https://www.wiz.io/blog/wiz-defend-and-google-security-operations","source":"Wiz Research","date_rel":"15 Sep"},{"title":"Google\u2019s new search redirects make links harder to check before you click","link":"https://www.malwarebytes.com/blog/news/2026/09/googles-new-search-redirects-make-links-harder-to-check-before-you-click","source":"Malwarebytes Labs","date_rel":"14 Sep"}]},{"title":"Google fixes actively exploited Android zero-day on Pixel devices","link":"https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-zero-day-on-pixel-devices/","reason":"Android","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Malwarebytes Labs","Microsoft Security"],"coverage":4,"cve_ids":["CVE-2026-65812","CVE-2026-69559"],"summary":"Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks.","source":"Bleeping Computer","date_rel":"10h ago","thumbnail":"","description":"","related":[{"title":"Android security advisory \u2013 September 2026 monthly rollup (AV26-920) \u2013 Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/android-security-advisory-september-2026-monthly-rollup-av26-920","source":"CCCS Alerts & Advisories","date_rel":"25m ago"},{"title":"CVE-2026-69559 Microsoft Teams for Android Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69559","source":"Microsoft Security","date_rel":"15 Sep"},{"title":"CVE-2026-65812 Microsoft Teams for Android Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-65812","source":"Microsoft Security","date_rel":"15 Sep"},{"title":"A week in security (September 7 \u2013 September 13)","link":"https://www.malwarebytes.com/blog/news/2026/09/a-week-in-security-september-7-september-13","source":"Malwarebytes Labs","date_rel":"14 Sep"}]},{"title":"Cisco email security boxes can be rooted by... an email","link":"https://www.theregister.com/security/2026/09/15/cisco-email-security-boxes-can-be-rooted-by-an-email/5296604","reason":"CVE-2026-76461","category":"News","sources":["CISA Alerts & Advisories","CyberScoop","Rapid7 Blog","Sophos Threat Research","The Hacker News","The Register Security"],"coverage":6,"cve_ids":["CVE-2026-76461"],"summary":"Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and\u2026","source":"The Register Security","date_rel":"15 Sep","thumbnail":"https://image.theregister.com/?imageId=260832&width=800","description":"Criminals are exploiting a critical Cisco Secure Email Gateway flaw that can turn a malicious email into root access. The vulnerability, tracked as CVE-2026-76461, carries a 9.8 CVSS score and affects physical and virtual Secure Email Gateway appliances regardless of their configuration. Cisco says there are no workarounds, so patching is the only fix. The bug lies in how Cisco's AsyncOS software handles incoming email. An attacker doesn't need to log in: they can send a booby-trapped message through a vulnerable gateway and, if the exploit works, run commands as root. Which is not exactly\u2026","related":[{"title":"Cisco warns customers of actively exploited zero-day in email gateways","link":"https://cyberscoop.com/cisco-secure-email-gateway-zero-day-exploited/","source":"CyberScoop","date_rel":"15 Sep"},{"title":"CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild","link":"https://www.rapid7.com/blog/post/etr-cve-2026-76461-critical-cisco-secure-email-gateway-vulnerability-exploited-in-the-wild","source":"Rapid7 Blog","date_rel":"15 Sep"},{"title":"Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution","link":"https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html","source":"The Hacker News","date_rel":"15 Sep"},{"title":"Cisco Secure Email Gateway vulnerability (CVE-2026-76461) in active exploitation","link":"https://www.sophos.com/en-us/blog/cisco-secure-email-gateway-vulnerability-cve-2026-76461-in-active-exploitation","source":"Sophos Threat Research","date_rel":"15 Sep"},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/14/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"14 Sep"}]},{"title":"Threat Intelligence Alone Won't Close the Exploitation Gap","link":"https://thehackernews.com/2026/09/threat-intelligence-alone-wont-close.html","reason":"Teams","category":"News","sources":["Bleeping Computer","CISA Alerts & Advisories","Cisco Security Advisories","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers\u2026","source":"The Hacker News","date_rel":"6h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiNTaZ2mJpwks9AMkwh4I_Q5sK5sgj01Fd4eW4c47_ZsHN_8hKPjptnlJ_P0RboejQy7PB6Ad4UXLFggJXAGlVsBigp46txL8LoSlpMuwQ0sXkAPQZ4TYtg89jNIa6SLPxuv-YC-_LlNZq2FZdNHRnrP_iQUYPSj2-MzugjnlL_CrIJw80lMzbVCZEf0x8/s1600/pentera.jpg","description":"A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most security programs are built to react.","related":[{"title":"Cisco Identity Services Engine Hardening Release: September 2026","link":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Hardening%20Release:%20September%202026%26vs_k=1","source":"Cisco Security Advisories","date_rel":"1h ago"},{"title":"Using Cyber Decoys to Strengthen Detection and Response","link":"https://www.cisa.gov/resources-tools/resources/using-cyber-decoys-strengthen-detection-and-response","source":"CISA Alerts & Advisories","date_rel":"5h ago"},{"title":"CISA: Critical VMware RCE flaw now exploited by ransomware gangs","link":"https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/","source":"Bleeping Computer","date_rel":"15 Sep"},{"title":"Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point","link":"https://thehackernews.com/2026/09/attack-chains-not-just-attack-surfaces.html","source":"The Hacker News","date_rel":"15 Sep"}]},{"title":"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells","link":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html","reason":"Wordpress","category":"News","sources":["Bleeping Computer","Infosecurity Magazine","SecurityWeek","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. \"This vulnerability can be leveraged by unauthenticated\u2026","source":"The Hacker News","date_rel":"11h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhaDJy8WPrkf8CE0D66EluNlAxZjtSyl-SeLt9BmCzqINPxm9H08ACj6o1nZWYQxcR5FYK-RrzDRXe014EEAMDH1wBa-SSXV1HNXJyLZsOWzNxU533Err9iI0Z_PQwy2Z6pY3LkGMSB2xKwQPIJe5mXgCJFeeUGj8qDKSmA9I9RS0MNl7jtlUhqkVPOkIfL/s1600/wordpress-shell.jpg","description":"Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. \"This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution,\" Wordfence said. The WordPress security company said it has blocked over","related":[{"title":"PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug","link":"https://www.infosecurity-magazine.com/news/woocommerce-wholesale-lead-capture/","source":"Infosecurity Magazine","date_rel":"2h ago"},{"title":"Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover","link":"https://www.securityweek.com/unauthenticated-rce-flaws-could-expose-200000-wordpress-sites-to-takeover/","source":"SecurityWeek","date_rel":"6h ago"},{"title":"Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites","link":"https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites/","source":"Bleeping Computer","date_rel":"21h ago"},{"title":"Hackers target WordPress sites via third-party WooCommerce plugin","link":"https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/","source":"Bleeping Computer","date_rel":"15 Sep"},{"title":"WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution","link":"https://thehackernews.com/2026/09/wordpress-adds-automated-plugin-reviews.html","source":"The Hacker News","date_rel":"14 Sep"}]},{"title":"HBO Max Reddit account compromised to serve ClickFix attacks","link":"https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408","reason":"Macos","category":"News","sources":["Palo Alto Unit 42","SANS Internet Storm Center","The Register Security"],"coverage":3,"cve_ids":[],"summary":"Someone compromised the official HBO Max Reddit account and used it to push more than 100 malicious ads serving up ClickFix attacks targeting both Windows and macOS devices with information-stealing malware. A Reddit\u2026","source":"The Register Security","date_rel":"14 Sep","thumbnail":"https://image.theregister.com/?imageId=5296419&width=800","description":"Someone compromised the official HBO Max Reddit account and used it to push more than 100 malicious ads serving up ClickFix attacks targeting both Windows and macOS devices with information-stealing malware. A Reddit user uncovered the infostealer ads on September 6, noting that the ad showed u/hbomax as the author \u2014 this is the verified HBO Max account \u2014 and advertised a macOS app for HBO Max. The streaming service does not offer a native client for the Mac. Anyone who clicked on the malicious ad would then be taken to a \u201csomewhat-legitimate\u201d looking landing page (hbomaxx[.]us) that includes\u2026","related":[{"title":"Atomic macOS (AMOS) Stealer Activity","link":"https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/","source":"Palo Alto Unit 42","date_rel":"7h ago"},{"title":"MacOS 27 - First Boot, (Tue, Sep 15th)","link":"https://isc.sans.edu/diary/rss/33340","source":"SANS Internet Storm Center","date_rel":"15 Sep"}]},{"title":"One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude","link":"https://thehackernews.com/2026/09/one-extension-could-hijack-ai.html","reason":"Chrome","category":"News","sources":["Elastic Security Labs","SecurityWeek","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft\u2026","source":"The Hacker News","date_rel":"2h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjnDFTLauyvgkyhmqrKcQ3QI3yCM1vbu_L8iwQK997zJz25tL7Gkm50y5S_wiSVF7hSJ7sLUMJEwXzxaubfjQc9JTdwttimIg5POxADfGNPLZEWbplFqzlKn2SZPvPuAyN0BhFtsc8PCzV2bZdBtx3z6qnRdRfw9tj-zk3aWL3t4TufGwksVdAjBuhVdO0/s1600/jack.jpg","description":"Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension. Once the extension was installed, it could access each product's built-in AI with a single click. On Comet, Edge,","related":[{"title":"Chrome, Firefox Updates Patch 115 Vulnerabilities","link":"https://www.securityweek.com/chrome-firefox-updates-patch-115-vulnerabilities/","source":"SecurityWeek","date_rel":"7h ago"},{"title":"KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens","link":"https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html","source":"The Hacker News","date_rel":"22h ago"},{"title":"China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE","link":"https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html","source":"The Hacker News","date_rel":"15 Sep"},{"title":"The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions","link":"https://www.elastic.co/security-labs/threat-command/malicious-browser-extension-kremlin-banking-malware","source":"Elastic Security Labs","date_rel":"14 Sep"}]}],"worth_reading":[{"title":"On the NSA\u2019s Supercomputer from the 1960s","link":"https://www.schneier.com/blog/archives/2026/09/on-the-nsas-supercomputer-from-the-1960s.html","reason":"Ibm","category":"Media","sources":["CCCS Alerts & Advisories","Schneier on Security"],"coverage":2,"cve_ids":[],"summary":"Really interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.","source":"Schneier on Security","date_rel":"15 Sep","thumbnail":"","description":"","related":[{"title":"IBM security advisory (AV26-922)","link":"https://cyber.gc.ca/en/alerts-advisories/ibm-security-advisory-av26-922","source":"CCCS Alerts & Advisories","date_rel":"15 Sep"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-59971","vendor":"Oracle","product":"mysql_mcp_server","severity":"CRITICAL","score":10.0,"description":"MySQL MCP Server is a Model Context Protocol server that enables secure interaction with MySQL databases. Prior to 0.4.2, setting MCP_TRANSPORT=sse causes src/mysql_mcp_server/server.py to construct SseServerTransport without security_setti\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-59971"},{"id":"CVE-2026-53710","vendor":"IBM","product":"mcp-context-forge","severity":"CRITICAL","score":10.0,"description":"MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in mcp-servers/python/python_sandbox_server/src/python_sandbox_server/server_fastmcp.py exposes raw getattr\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-53710"},{"id":"CVE-2026-71133","vendor":"Oracle","product":"Oracle Access Manager","severity":"CRITICAL","score":10.0,"description":"Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-71133"},{"id":"CVE-2026-83020","vendor":"Oracle","product":"Oracle Platform Security for Java","severity":"CRITICAL","score":10.0,"description":"Vulnerability in the Oracle Platform Security for Java product of Oracle Fusion Middleware (component: Centralized Thirdparty Jars).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.0.0. Easily exploitable vulnerability allo\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-83020"},{"id":"CVE-2026-83021","vendor":"Oracle","product":"Oracle WebLogic Server","severity":"CRITICAL","score":10.0,"description":"Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container).  Supported versions that are affected are 12.2.1.4.0, 14.1.1.0.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenti\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-83021"},{"id":"CVE-2026-83059","vendor":"Oracle","product":"Oracle Internet Directory","severity":"CRITICAL","score":10.0,"description":"Vulnerability in the Oracle Internet Directory product of Oracle Fusion Middleware (component: OID LDAP Server).  Supported versions that are affected are 12.2.1.4.0 and  14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated a\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-83059"},{"id":"CVE-2026-83099","vendor":"Oracle","product":"Oracle Forms","severity":"CRITICAL","score":10.0,"description":"Vulnerability in the Oracle Forms product of Oracle Fusion Middleware (component: Forms Services, C/S, Charmode).  Supported versions that are affected are 12.2.1.19.0 and  14.1.2.0.0. Easily exploitable vulnerability allows unauthenticated\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-83099"},{"id":"CVE-2026-87230","vendor":"Oracle","product":"Oracle Hyperion Financial Management","severity":"CRITICAL","score":10.0,"description":"Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security).   The supported version that is affected is 11.2.26.0.000. Easily exploitable vulnerability allows unauthenticated attacker with net\u2026","cwe":"","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-87230"},{"id":"CVE-2026-73453","vendor":"Arista Networks","product":"EOS","severity":"CRITICAL","score":10.0,"description":"An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under certain conditions on affected platforms running Arista EOS configured with P4Runtime. P4Runtime is \u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-73453"},{"id":"CVE-2026-57138","vendor":"Microsoft","product":"PraisonAI","severity":"CRITICAL","score":9.9,"description":"PraisonAI is a multi-agent teams system. From 1.4.0 until 1.7.2, codeMode in src/praisonai-ts/src/tools/builtins/code-mode.ts executes untrusted JavaScript with new Function() inside with(sandbox) and relies on a small source-code blocklist\u2026","cwe":"CWE-184","kev":false,"kev_action":"","kev_due":"","epss":0.0065,"url":"https://cve.blackmesa.ca/?q=CVE-2026-57138"}],"vendor_spikes":[{"vendor":"Oracle","count":637,"critical_count":98},{"vendor":"Google","count":140,"critical_count":4},{"vendor":"Mozilla","count":78,"critical_count":0},{"vendor":"WordPress","count":62,"critical_count":2},{"vendor":"HP","count":38,"critical_count":6},{"vendor":"Microsoft","count":37,"critical_count":7},{"vendor":"Unknown","count":34,"critical_count":0},{"vendor":"Arista Networks","count":31,"critical_count":3},{"vendor":"Concrete CMS","count":30,"critical_count":0},{"vendor":"IBM","count":25,"critical_count":2}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":1514,"has_news_data":true,"has_cve_data":true}