{"date_iso":"2026-09-18","date_human":"Friday, September 18, 2026","generated_utc":"2026-09-18 17:02 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"Android Apps Can Now Check If Your Phone Is Missing Critical Security Patches","link":"https://cybersecuritynews.com/android-apps-check-security-patches/","reason":"Android","category":"News","sources":["404 Media","Bleeping Computer","CCCS Alerts & Advisories","Cyber Security News","Hak5","Infosecurity Magazine","Malwarebytes Labs","The Hacker News"],"coverage":8,"cve_ids":[],"summary":"Android has released new Security State libraries that allow apps and enterprise tools to check whether a device is missing important security patches. The update gives developers a more detailed view of Android\u2026","source":"Cyber Security News","date_rel":"6h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Android-Apps-Can-Now-Check-If-Your-Phone-Is-Missing-Critical-Security-Patches.webp","description":"Android has released new Security State libraries that allow apps and enterprise tools to check whether a device is missing important security patches. The update gives developers a more detailed view of Android security than the traditional monthly Security Patch Level , helping apps identify unpatched system components, pending updates, and specific vulnerability fixes. The stable release includes AndroidX Security State version 1.1.0 and Security State Provider version 1.0.0. These libraries are designed for security-sensitive Android apps, including banking, fintech, healthcare\u2026","related":[{"title":"New Android malware uses AI to steal bank logins and PINs","link":"https://www.malwarebytes.com/blog/news/2026/09/new-android-malware-uses-ai-to-steal-bank-logins-and-pins","source":"Malwarebytes Labs","date_rel":"1h ago"},{"title":"RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall","link":"https://thehackernews.com/2026/09/rathat-android-malware-abuses-adb-to.html","source":"The Hacker News","date_rel":"10h ago"},{"title":"New RatHat Android malware uses AI to automate device control","link":"https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/","source":"Bleeping Computer","date_rel":"19h ago"},{"title":"A Phone Call Can Now Spread a Zero-Click Worm | Threat Wire","link":"https://www.youtube.com/watch?v=fp959e8GFT4","source":"Hak5","date_rel":"17 Sep"},{"title":"University Rescinds Job Offer to Activist Who Allegedly Wiped Phone Before DHS Could Search It","link":"https://www.404media.co/university-rescinds-job-offer-to-activist-who-allegedly-wiped-phone-before-dhs-could-search-it/","source":"404 Media","date_rel":"17 Sep"},{"title":"New Chinese-Made \u2018RatHat\u2019 Android Malware Leverages AI to Steal Financial Data","link":"https://www.infosecurity-magazine.com/news/rathat-android-malware-ai-steal/","source":"Infosecurity Magazine","date_rel":"17 Sep"}]},{"title":"An Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking Gang","link":"https://www.wired.com/story/an-undercover-google-analyst-infiltrated-a-notorious-supply-chain-hacking-gang/","reason":"Google","category":"Media","sources":["CCCS Alerts & Advisories","Malwarebytes Labs","The Hacker News","The Register Security","Wired Security"],"coverage":5,"cve_ids":[],"summary":"TeamPCP pulled off the worst-ever software supply chain hacking spree and breached thousands of companies. Now Google\u2019s threat intelligence group says it had a mole inside the hackers\u2019 inner circle.","source":"Wired Security","date_rel":"1h ago","thumbnail":"https://media.wired.com/photos/6aac35420820a9282b5f1721/master/pass/Security_An%20Undercover%20Google%20Researcher%20Infiltrated%20the%20Gang%20Behind%20the%20Worst-Ever%20Supply%20Chain%20Hacking%20Spree_v1.jpg","description":"","related":[{"title":"Google security advisory (AV26-939)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-939","source":"CCCS Alerts & Advisories","date_rel":"1h ago"},{"title":"CISO's Expert Guide to Agentic Pentesting for Websites","link":"https://thehackernews.com/2026/09/cisos-expert-guide-to-agentic.html","source":"The Hacker News","date_rel":"17 Sep"},{"title":"Google Pixel phones pwned in zero-click attacks","link":"https://www.theregister.com/security/2026/09/16/google-pixel-phones-pwned-in-zero-click-attacks/5296936","source":"The Register Security","date_rel":"16 Sep"},{"title":"Google security advisory (AV26-926)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-926","source":"CCCS Alerts & Advisories","date_rel":"16 Sep"},{"title":"Google Pixel owners urged to patch actively exploited modem flaw","link":"https://www.malwarebytes.com/blog/mobile/2026/09/google-pixel-owners-urged-to-patch-actively-exploited-modem-flaw","source":"Malwarebytes Labs","date_rel":"16 Sep"}]},{"title":"\u2018Doom Loop\u2019: OpenAI and Microsoft Admits LLMs Are Destroying the Web and Built on Theft","link":"https://www.404media.co/doom-loop-openai-and-microsoft-admits-llms-are-destroying-the-web-and-built-on-theft/","reason":"Microsoft","category":"News","sources":["404 Media","Bleeping Computer","Dark Reading","The Register Security","Zero Day Initiative"],"coverage":5,"cve_ids":[],"summary":"Executives working on AI at Microsoft and OpenAI admitted what its critics have been saying all along: Large language models are predatory pieces of technology that have been built on what a Microsoft executive called\u2026","source":"404 Media","date_rel":"19h ago","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/09/CleanShot-2026-09-17-at-2.48.18-PM@2x-1.png","description":"Executives working on AI at Microsoft and OpenAI admitted what its critics have been saying all along: Large language models are predatory pieces of technology that have been built on what a Microsoft executive called \u201can astonishing theft of unprecedented proportions,\u201d and the \u201clargest theft of labor in human history.\u201d An internal Microsoft document said generative AI products have created a \u201cdoom loop\u201d that is killing \u201cthe entire web.\u201d Those statements and a series of other mask-off moments feature heavily in an unredacted court filing that was unsealed Thursday in the behemoth New York\u2026","related":[{"title":"Secure enterprise sharing with access reviews for Microsoft 365","link":"https://www.bleepingcomputer.com/news/security/secure-enterprise-sharing-with-access-reviews-for-microsoft-365/","source":"Bleeping Computer","date_rel":"3h ago"},{"title":"Microsoft Teams will let admins block custom file extensions","link":"https://www.bleepingcomputer.com/news/security/microsoft-teams-will-let-admins-block-custom-file-extensions/","source":"Bleeping Computer","date_rel":"3h ago"},{"title":"Microsoft fixes bug behind \u2018Defender Antivirus is turned off\u2019 alerts","link":"https://www.bleepingcomputer.com/news/security/microsoft-fixes-bug-behind-defender-antivirus-is-turned-off-alerts/","source":"Bleeping Computer","date_rel":"4h ago"},{"title":"Mythos has made 2026 patching hell. It might make 2027 a breeze","link":"https://www.theregister.com/security/2026/09/16/mythos-has-made-2026-patching-hell-it-might-make-2027-a-breeze/5296747","source":"The Register Security","date_rel":"16 Sep"},{"title":"ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-708/","source":"Zero Day Initiative","date_rel":"16 Sep"},{"title":"Microsoft Issues Emergency Fixes After Massive Patch Tuesday","link":"https://www.darkreading.com/application-security/microsoft-emergency-fixes-patch-tuesday","source":"Dark Reading","date_rel":"15 Sep"}]},{"title":"Linux Kernel Hit by Four Privilege Escalation Flaws Enabling Root Access","link":"https://cybersecuritynews.com/linux-kernel-privilege-escalation-flaws/","reason":"Linux","category":"News","sources":["CISA Alerts & Advisories","Cyber Security News","Dark Reading","Zero Day Initiative"],"coverage":4,"cve_ids":["CVE-2025-39964","CVE-2026-53266"],"summary":"Four newly disclosed Linux kernel vulnerabilities could allow local attackers to corrupt kernel memory and escalate privileges to root on affected systems. The flaws, named DirtyAH6, TUNderflow, PPPoEject, and\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Linux-Kernel-Hit-by-Four-Privilege-Escalation-Flaws-Enabling-Root-Access.webp","description":"Four newly disclosed Linux kernel vulnerabilities could allow local attackers to corrupt kernel memory and escalate privileges to root on affected systems. The flaws, named DirtyAH6, TUNderflow, PPPoEject, and DiagSpill, affect long-standing networking code and have now received upstream fixes. The vulnerabilities are tracked as CVE-2026-80844, CVE-2026-81000, CVE-2026-68121, and CVE-2026-74469. DirtyAH6, tracked as CVE-2026-80844, affects IPv6 Authentication Header processing in Linux IPsec/XFRM code. The issue occurs when the kernel handles malformed IPv6 routing-header values without\u2026","related":[{"title":"CISA Adds Two Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/18/cisa-adds-two-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"5h ago"},{"title":"ZDI-26-715: Linux Mint Xreader PDF File Parsing Type Confusion Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-715/","source":"Zero Day Initiative","date_rel":"12h ago"},{"title":"Cyber Op Targets South Korean Media & Automotive Sectors","link":"https://www.darkreading.com/cyberattacks-data-breaches/cyber-south-korean-media-automotive","source":"Dark Reading","date_rel":"16 Sep"}]},{"title":"Critical Microsoft Azure AI Foundry Vulnerability Allows Attackers to Escalate Privileges","link":"https://cybersecuritynews.com/microsoft-azure-ai-foundry-vulnerability/","reason":"Azure","category":"News","sources":["Cyber Security News","Microsoft Security","SecurityWeek","The Hacker News"],"coverage":4,"cve_ids":["CVE-2026-68791","CVE-2026-69399","CVE-2026-70009"],"summary":"Microsoft has patched a maximum-severity security flaw in Azure AI Foundry, its enterprise platform for building and managing generative AI applications and agents, that could have allowed an unauthenticated attacker to\u2026","source":"Cyber Security News","date_rel":"2h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Microsoft-Azure-AI-Foundry-Vulnerability.webp","description":"Microsoft has patched a maximum-severity security flaw in Azure AI Foundry, its enterprise platform for building and managing generative AI applications and agents, that could have allowed an unauthenticated attacker to escalate privileges over the network without any user interaction. Tracked as CVE-2026-85889 , the vulnerability carries the highest possible CVSS score of 10.0, placing it among the most severe cloud security issues disclosed this year. According to Microsoft\u2019s advisory, published on September 17, 2026, the root cause is a missing authentication check for a critical function\u2026","related":[{"title":"Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation","link":"https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html","source":"The Hacker News","date_rel":"4h ago"},{"title":"Microsoft Patches 18 Vulnerabilities in AI, Cloud Products","link":"https://www.securityweek.com/microsoft-patches-18-vulnerabilities-in-ai-cloud-products/","source":"SecurityWeek","date_rel":"6h ago"},{"title":"CVE-2026-70009 Azure Arc Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-70009","source":"Microsoft Security","date_rel":"17 Sep"},{"title":"CVE-2026-69399 Azure Arc Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69399","source":"Microsoft Security","date_rel":"17 Sep"},{"title":"CVE-2026-68791 Azure Machine Learning Information Disclosure Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-68791","source":"Microsoft Security","date_rel":"17 Sep"}]},{"title":"Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root","link":"https://thehackernews.com/2026/09/critical-check-point-management-server.html","reason":"Check Point","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","SecurityWeek","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is\u2026","source":"The Hacker News","date_rel":"22h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiuFSb4LQQ7e_Iz1RS0JfQEDY9G9LcQZ23RM0h6ladr56GJ6nN3kPwVoZPpNVJUyJEBmLVEyMaIxytF2XqyQs8fGjIdd_ymPjwaZA8Q8R7JiXC-srMFj0_YBd-a94juv46HZm4ie72j7PTj45veyTgOBaeuN53HvktSH3JTgasvV_Mo-RwjsTPnRLlHFVk/s1600/cp-main.jpg","description":"A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw","related":[{"title":"New Check Point flaw lets hackers execute code with root privileges","link":"https://www.bleepingcomputer.com/news/security/check-point-warns-critical-flaw-lets-hackers-execute-code-as-root/","source":"Bleeping Computer","date_rel":"7h ago"},{"title":"Check Point, Kaspersky, Tanium Patch Product Vulnerabilities","link":"https://www.securityweek.com/check-point-kaspersky-tanium-patch-product-vulnerabilities/","source":"SecurityWeek","date_rel":"9h ago"},{"title":"Check Point security advisory (AV26-933)","link":"https://cyber.gc.ca/en/alerts-advisories/check-point-security-advisory-av26-933","source":"CCCS Alerts & Advisories","date_rel":"22h ago"}]},{"title":"Cisco drops another exploited zero-day, this time a perfect 10","link":"https://www.theregister.com/security/2026/09/17/cisco-drops-another-exploited-zero-day-this-time-a-perfect-10/5297180","reason":"CVE-2026-76460","category":"News","sources":["CCCS Alerts & Advisories","CISA Alerts & Advisories","CyberScoop","The Hacker News","The Register Security"],"coverage":5,"cve_ids":["CVE-2026-20192","CVE-2026-76423","CVE-2026-76460"],"summary":"Cisco admins who have spent their week patching email gateways now face a perfect-10 Identity Services Engine flaw under active attack. Cisco disclosed CVE-2026-76460 on Wednesday, describing it as an authentication\u2026","source":"The Register Security","date_rel":"17 Sep","thumbnail":"https://image.theregister.com/?imageId=5249134&width=800","description":"Cisco admins who have spent their week patching email gateways now face a perfect-10 Identity Services Engine flaw under active attack. Cisco disclosed CVE-2026-76460 on Wednesday, describing it as an authentication bypass affecting Identity Services Engine (ISE) and ISE Passive Identity Connector (ISE-PIC). Successful exploitation can give an unauthenticated remote attacker command execution with root privileges. Product Security Incident Response Team said it was aware of active exploitation and urged customers to install the fixes immediately. CISA has also added the vulnerability to its\u2026","related":[{"title":"Cisco alerts customers to second actively exploited zero-day in as many days","link":"https://cyberscoop.com/cisco-ise-zero-day-cve-2026-76460/","source":"CyberScoop","date_rel":"19h ago"},{"title":"AL26-021 - Vulnerabilities Impacting Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) - CVE-2026-20192, CVE-2026-76423 and CVE-2026-76460","link":"https://cyber.gc.ca/en/alerts-advisories/al26-021-vulnerabilities-impacting-cisco-identity-services-engine-ise-cisco-ise-passive-identity-connector-ise-pic-cve-2026-20192-cve-2026-76423-cve-2026-76460","source":"CCCS Alerts & Advisories","date_rel":"23h ago"},{"title":"Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks","link":"https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html","source":"The Hacker News","date_rel":"17 Sep"},{"title":"CISA Adds Two Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/16/cisa-adds-two-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"16 Sep"}]},{"title":"Tutor LMS Flaw Exposes 100,000+ WordPress Sites to Remote Code Execution","link":"https://cybersecuritynews.com/tutor-lms-flaw/","reason":"Wordpress","category":"News","sources":["Cyber Security News","Infosecurity Magazine","SecurityWeek","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"A high-severity flaw in the Tutor LMS WordPress plugin could let a low-privileged user take control of an affected server. The issue affects more than 100,000 sites that use the e-learning plugin, particularly\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/Tutor-LMS-Flaw-Exposes-100000-WordPress-Sites-to-Remote-Code-Execution.webp","description":"A high-severity flaw in the Tutor LMS WordPress plugin could let a low-privileged user take control of an affected server. The issue affects more than 100,000 sites that use the e-learning plugin, particularly installations that allow visitors to register as students. Tracked as CVE-2026-78175, the vulnerability is rated 8.8 out of 10 and affects Tutor LMS versions 4.0.7 and earlier. An attacker needs a subscriber-level account, but on sites with open registration, creating that account may be as simple as completing a student sign-up form. Researchers noted that the bug can lead to remote\u2026","related":[{"title":"In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw","link":"https://www.securityweek.com/in-other-news-ransomware-developer-sentenced-plugin4shell-ai-attack-critical-sap-flaw/","source":"SecurityWeek","date_rel":"2h ago"},{"title":"PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug","link":"https://www.infosecurity-magazine.com/news/woocommerce-wholesale-lead-capture/","source":"Infosecurity Magazine","date_rel":"16 Sep"},{"title":"Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells","link":"https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html","source":"The Hacker News","date_rel":"16 Sep"}]},{"title":"Inside the Modern SOC: Defending the Cross-Environment Pivot","link":"https://unit42.paloaltonetworks.com/soc-cross-environment-pivot/","reason":"Teams","category":"Threat Intel","sources":["CISA Alerts & Advisories","Cisco Security Advisories","Palo Alto Unit 42","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths.","source":"Palo Alto Unit 42","date_rel":"19h ago","thumbnail":"https://unit42.paloaltonetworks.com/wp-content/uploads/2026/09/01_Myth-Busting_Overview_1920x900_Resized.jpg","description":"","related":[{"title":"Cisco Identity Services Engine Hardening Release: September 2026","link":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ise-XU5EwX5T?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Identity%20Services%20Engine%20Hardening%20Release:%20September%202026%26vs_k=1","source":"Cisco Security Advisories","date_rel":"16 Sep"},{"title":"Using Cyber Decoys to Strengthen Detection and Response","link":"https://www.cisa.gov/resources-tools/resources/using-cyber-decoys-strengthen-detection-and-response","source":"CISA Alerts & Advisories","date_rel":"16 Sep"},{"title":"Threat Intelligence Alone Won't Close the Exploitation Gap","link":"https://thehackernews.com/2026/09/threat-intelligence-alone-wont-close.html","source":"The Hacker News","date_rel":"16 Sep"}]},{"title":"New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems","link":"https://cybersecuritynews.com/new-settra-ransomware/","reason":"Windows","category":"News","sources":["Cyber Security News","Sophos Threat Research","The Register Security"],"coverage":3,"cve_ids":[],"summary":"Settra ransomware is emerging as a serious threat to Windows networks after investigators linked it to two recent intrusions involving remote-management software and recovery-blocking actions. The operation encrypts\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/09/New-SETTRA-Ransomware-Uses-MeshAgent-RMM-and-BYOVD-to-Encrypt-Windows-Systems.webp","description":"Settra ransomware is emerging as a serious threat to Windows networks after investigators linked it to two recent intrusions involving remote-management software and recovery-blocking actions. The operation encrypts files, leaves victims with ransom notes, and tries to make both investigation and restoration more difficult. Public reporting indicates that the people behind Settra have gained entry through virtual private networks or previously stolen credentials. That makes exposed remote access and weak account controls a central concern, while the use of legitimate administration software\u2026","related":[{"title":"September Patch Tuesday haul includes 973 CVEs","link":"https://www.sophos.com/en-us/blog/september-2026-patch-tuesday","source":"Sophos Threat Research","date_rel":"16 Sep"},{"title":"Iranian spies hit Windows machines with Chosen Brick data-stealing malware","link":"https://www.theregister.com/security/2026/09/15/iranian-spies-hit-windows-machines-with-chosen-brick-data-stealing-malware/5296646","source":"The Register Security","date_rel":"15 Sep"}]}],"worth_reading":[{"title":"ZDI-26-718: Cisco Identity Services Engine MnTRESTLivelogService XML External Entity Processing Information Disclosure Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-718/","reason":"Cisco","category":"Research","sources":["CCCS Alerts & Advisories","Infosecurity Magazine","Zero Day Initiative"],"coverage":3,"cve_ids":[],"summary":"This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a\u2026","source":"Zero Day Initiative","date_rel":"12h ago","thumbnail":"","description":"This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2026-20235.","related":[{"title":"ZDI-26-717: Cisco Identity Services Engine AlarmMessageDiskQueue Deserialization of Untrusted Data Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-717/","source":"Zero Day Initiative","date_rel":"12h ago"},{"title":"ZDI-26-716: Cisco Identity Services Engine createDBLink Command Injection Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-716/","source":"Zero Day Initiative","date_rel":"12h ago"},{"title":"Cisco security advisory (AV26-932)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-932","source":"CCCS Alerts & Advisories","date_rel":"17 Sep"},{"title":"Cisco Warns of Active Exploitation of Critical ISE Flaw","link":"https://www.infosecurity-magazine.com/news/cisco-active-exploitation-critical/","source":"Infosecurity Magazine","date_rel":"17 Sep"}]},{"title":"Exploring the new AWS Sign Up experience","link":"https://www.wiz.io/blog/exploring-the-new-aws-sign-up-experience","reason":"Aws","category":"Research","sources":["Palo Alto Unit 42","Wiz Research"],"coverage":2,"cve_ids":[],"summary":"This post will explore what this new concept does, how it works with the new Account Access capability, and why a strong security posture still requires upgrading out of the sandbox.","source":"Wiz Research","date_rel":"17 Sep","thumbnail":"https://www.datocms-assets.com/75231/1789596868-starter-home-2x.png","description":"","related":[{"title":"A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity","link":"https://unit42.paloaltonetworks.com/securing-aws-agentcore-harness-credentials/","source":"Palo Alto Unit 42","date_rel":"7h ago"}]},{"title":"ZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-703/","reason":"Sharepoint","category":"Research","sources":["Microsoft Security","Zero Day Initiative"],"coverage":2,"cve_ids":["CVE-2026-69724"],"summary":"This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of\u2026","source":"Zero Day Initiative","date_rel":"16 Sep","thumbnail":"","description":"This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92203.","related":[{"title":"CVE-2026-69724 Microsoft Office SharePoint Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69724","source":"Microsoft Security","date_rel":"17 Sep"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-62104","vendor":"superweby","product":"Migratico Lite","severity":"CRITICAL","score":10.0,"description":"Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-62104"},{"id":"CVE-2026-92937","vendor":"patriksimek","product":"vm2","severity":"CRITICAL","score":10.0,"description":"vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v is incomplete: the bridge gate at lib/bridge.js:1624 identity-checks only the direct call target when\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-92937"},{"id":"CVE-2026-92940","vendor":"patriksimek","product":"vm2","severity":"CRITICAL","score":10.0,"description":"vm2 versions 3.11.3 through 3.11.6 expose the host process's real https.globalAgent to sandboxed code when a NodeVM is explicitly configured to allow require('https'). The builtin loader wraps host modules in a read-only proxy, but method c\u2026","cwe":"CWE-668","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-92940"},{"id":"CVE-2026-92941","vendor":"patriksimek","product":"vm2","severity":"CRITICAL","score":10.0,"description":"vm2 versions from 3.11.3 before 3.11.7 expose the host tls module to NodeVM sandbox code, allowing attackers to call tls.setDefaultCACertificates() and replace process-wide certificate authorities. Attackers with access to allowed tls and u\u2026","cwe":"CWE-732","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-92941"},{"id":"CVE-2026-92946","vendor":"patriksimek","product":"vm2","severity":"CRITICAL","score":10.0,"description":"vm2 before 3.11.7 contains a remote code execution vulnerability when require.external is enabled without an explicit require.root that excludes node_modules. Sandboxed code can require vm2's own package, instantiate an unrestricted NodeVM \u2026","cwe":"CWE-913","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-92946"},{"id":"CVE-2026-92947","vendor":"patriksimek","product":"vm2","severity":"CRITICAL","score":10.0,"description":"vm2 before 3.11.7 exposes Node's shared Buffer pool to sandboxed code, allowing disclosure of host memory used by Buffer.from, Buffer.concat, and related allocations. Sandboxed code can read and write to host-realm buffers by acquiring Arra\u2026","cwe":"CWE-200","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-92947"},{"id":"CVE-2026-92953","vendor":"patriksimek","product":"vm2","severity":"CRITICAL","score":10.0,"description":"vm2 versions from 3.11.0 before 3.11.8 fail to protect host TypedArray and ArrayBuffer prototypes from sandbox mutation. Attackers can use prototype-walking primitives to reach and modify host Uint8Array.prototype, %TypedArray%.prototype, a\u2026","cwe":"CWE-913","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-92953"},{"id":"CVE-2026-92955","vendor":"patriksimek","product":"vm2","severity":"CRITICAL","score":10.0,"description":"vm2 before 3.11.8 contains a sandbox escape vulnerability in NodeVM that allows attackers to access the host __proto__ getter/setter through console._stdout and console._stderr. Attackers can overwrite EventEmitter.prototype.emit and trigge\u2026","cwe":"CWE-913","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-92955"},{"id":"CVE-2026-92956","vendor":"patriksimek","product":"vm2","severity":"CRITICAL","score":10.0,"description":"vm2 versions 3.10.1 through 3.11.6 contain a sandbox escape reachable from a default `new VM()` sandbox when running on Node.js 26. WebAssembly.compileStreaming and WebAssembly.instantiateStreaming can produce a raw host-realm Promise that \u2026","cwe":"CWE-693","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-92956"},{"id":"CVE-2026-92960","vendor":"patriksimek","product":"vm2","severity":"CRITICAL","score":10.0,"description":"vm2 before 3.11.6 fails to restrict access to os and dns builtins under the builtin: ['*'] configuration, allowing sandbox code to read host process identity and network topology. Attackers can invoke dns.setServers() to hijack the host pro\u2026","cwe":"CWE-200","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-92960"}],"vendor_spikes":[{"vendor":"Linux","count":551,"critical_count":0},{"vendor":"WordPress","count":81,"critical_count":0},{"vendor":"Apple","count":40,"critical_count":1},{"vendor":"Microsoft","count":39,"critical_count":13},{"vendor":"Dell","count":24,"critical_count":0},{"vendor":"patriksimek","count":24,"critical_count":14},{"vendor":"Google","count":19,"critical_count":0},{"vendor":"Synology","count":19,"critical_count":2},{"vendor":"Unknown","count":17,"critical_count":0},{"vendor":"Red Hat","count":15,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":1118,"has_news_data":true,"has_cve_data":true}