Skip to content

Morning Brief

Tuesday, September 22, 2026 · generated · ~5 min read

Top developments

NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past

Serial Microsoft zero-day leaker NightmareEclipse has found another way to mess with Windows Defender, this time by stopping the antivirus from updating itself. The security researcher, also known as Abdelhamid Naceri…

EU data regulator fines Google more than $460 million for location data violations

Ireland’s Data Protection Commission will fine Google more than €403 million ($462 million) over the tech giant’s processing of location data, concluding an inquiry into the company that began in early 2020.

CAIRN – A New Tool to Track AI Malware That Operates Without Human Control

Cisco Talos has released CAIRN, an open-source toolkit designed to hunt, classify, and track AI-integrated malware by examining the digital markers developers leave behind. The Cognitive Artifact Intelligence Research…

AI Agents Are Rewriting the Rules of Lateral Movement

Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has? A…

Linux KVM/arm64 Vulnerability Lets Attackers Escape Virtual Machines and Gain Host Access

A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-89775, could let attackers escape an ARM64 virtual machine and access the underlying host system. The issue affects KVM/arm64 environments where nested…

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server…

Check Point warns of Management Server zero-day exploited in attacks

Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts.

New TASK#STOMP Backdoor Uses PowerShell to Steal Documents and Wi-Fi Passwords

TASK#STOMP is a newly analyzed Windows backdoor that turns ordinary built-in tools into a durable spying operation. It uses a Visual Basic Script installer, hidden PowerShell, scheduled tasks, and runtime code…

Hackers Clone Legitimate Websites to Silently Trigger Chrome and Windows Zero-Day Exploits

Hackers are using convincing copies of trusted websites to turn an ordinary browser visit into a full Windows compromise. The campaign pairs targeted phishing emails with a chained set of previously unknown flaws in…

Siemens Industrial Edge Management

View CSAF Summary Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without…

Vulnerability watch

CVE-2026-77521 1Panel-dev · MaxKB CWE-78 CRITICAL 10.0

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits execut…

CVE-2026-94493 Gigatech · PDV5701 CWE-287 CRITICAL 10.0

A vulnerability was detected in Gigatech PDV5701 1.0.31_240305_112640. This issue affects some unknown processing of the file /index.html of the component WebSocket Service. The manipulation results in missing authentication. The attack can…

CVE-2026-93952 Arista Networks · VeloCloud Orchestrator (VCO) On-Prem CWE-20 CRITICAL 10.0

VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality and impact the VCO host. Successful exploitation may compromise the confidentiality, integrit…

CVE-2026-79920 ajenti · ajenti CWE-862 CRITICAL 9.9

Ajenti is a Linux & BSD modular server admin panel. Prior to version 2.2.16, any authenticated user can call /api/core/tasks/start to enqueue InstallPlugin, UnInstallPlugin, or UpgradeAll from plugins/plugins/tasks.py without plugin-managem…

CVE-2026-94301 Apache · Apache MINA CWE-502 CRITICAL 9.8

The fix for CVE-2026-47065/ZDRES-232 ("resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy"), released on 2026-06-02 and announced as "Fully addressed" in MINA 2.2.8, 2.1.13 and 2.0.29, was committed …

CVE-2026-85751 F5 · Mailu CWE-290 CRITICAL 9.8

Mailu is a mail server distributed as a set of Docker images. From Mailu 2.0 until 2024.06.55 and prior to Mailu helm-charts 2.7.3, deployments with PROXY_AUTH_WHITELIST configured but REAL_IP_HEADER unset trusted a client-controlled X-Forw…

CVE-2026-13355 WordPress · Meta Box Frontend Submission CWE-269 CRITICAL 9.8

The Meta Box AIO plugin for WordPress is vulnerable to Privilege Escalation to Administrator in versions up to, and including, 3.11.0. This is due to a chained flaw: the populate_via_query_string() function in the mb-frontend-submission com…

CVE-2026-19658 WordPress · Give Tributes CWE-502 CRITICAL 9.8

The Give Tributes plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 2.3.1 via deserialization of untrusted input . This makes it possible for unauthenticated attackers to inject a PHP Object. N…

CVE-2026-25254 Qualcomm · Snapdragon CWE-285 CRITICAL 9.8

Improper authorization leads to Remote Code Execution via SocketIO interface.

CVE-2026-58491 Oracle · warpgate CWE-79 CRITICAL 9.3

Warpgate is an open source SSH, HTTPS and MySQL bastion host for Linux. Prior to 0.25.5, the /@warpgate/api/sso/providers/:name/start endpoint stores an attacker-controlled next parameter that the POST /@warpgate/api/sso/return handler inse…

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →