Skip to content

Morning Brief

Thursday, September 24, 2026 · generated · ~5 min read

Top developments

Managed or Modified: Choose How Huntress Hardens Microsoft 365

Managed ISPM now offers two deployment modes. Choose fully automated hardening or full control over which Microsoft 365 controls roll out, and when. See how it works.

Google to critical infra orgs: Our AI scanners won't be evil, promise

Google has jumped on the AI-defense-for-critical-systems train with its Scan for Good initiative, and says that its threat-hunting models have already autonomously uncovered critical security issues at hospitals, a…

Decades-old file security flaws found in Android, Linux, macOS, and Windows

Security researchers affiliated with Austria's Graz University of Technology have found flaws in the implementation of file notification systems on Android, Linux, macOS, and Windows that leak potentially compromising…

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. "third-party[.]com has been a…

Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)

Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry. We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas…

How dynamic application security testing validates risk at runtime

Security teams already have long queues of potential application vulnerabilities. The useful question is what happens next: can they see how a weakness behaves in a running application, reproduce the attack, and give…

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start…

Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates

A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster…

Hackers Exploit Critical Check Point VPN Flaws to Gain Remote Access Without Login

Check Point has warned that attackers are actively exploiting two critical vulnerabilities in its VPN and management products, allowing unauthenticated remote access and possible remote code execution. Both flaws carry…

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an…

Vulnerability watch

CVE-2026-59167 JiHong88 · suneditor CWE-79 CRITICAL 10.0

SunEditor is a lightweight and powerful WYSIWYG editor in vanilla JavaScript with no dependencies. Prior to 2.47.11, the sanitizer in src/lib/core.js does not consistently reject namespaced or custom HTML elements, allowing event-handler at…

CVE-2026-86708 ManageEngine · ManageEngine Applications Manager CWE-321 CRITICAL 10.0

ZohoCorp ManageEngine Applications Manager versions 182200 and below were vulnerable to exposure of a Google Cloud service-account private key in the Applications Manager installer, which could allow an unauthenticated attacker to impersona…

CVE-2026-19599 ManageEngine · ManageEngine OpManager CWE-78 CRITICAL 9.9

ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were vulnerable to a Remote Code Execution vulnerability in the Notification Profile module.

CVE-2026-77602 OpenC3 · cosmos CWE-94 CRITICAL 9.9

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From 5.1.0 until 7.3.0, authenticated non-administrator users can write content under targets_modified/ that is later ex…

CVE-2026-84474 Red Hat · Red Hat Ansible Automation Platform 2.4 for RHEL 8 CWE-807 CRITICAL 9.9

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template API…

CVE-2026-84502 Red Hat · Red Hat Ansible Automation Platform 2.4 for RHEL 8 CWE-88 CRITICAL 9.9

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the module r…

CVE-2026-84719 Red Hat · Red Hat Ansible Automation Platform 2.4 for RHEL 8 CWE-862 CRITICAL 9.9

A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and …

CVE-2026-89078 GitLab · GitLab CWE-415 CRITICAL 9.9

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on th…

CVE-2026-93577 GitLab · GitLab CWE-190 CRITICAL 9.9

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on th…

CVE-2026-76183 Apache · Apache Tomcat CWE-289 CRITICAL 9.8

Authentication Bypass by Alternate Name vulnerability in Apache Tomcat allowed the security constraints for any WebSocket endpoint to be bypassed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 1…

Full CVE Feed →

About this brief Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score — no AI writes any of this. Every number and link traces back to something already published on those two tools.

Data sources Top developments from Security Feed's cross-source trending detection. Vulnerability watch from CVE Feed's daily NVD + CISA KEV sync.

More Browse past briefs → · Patch Tuesday specials →