{"date_iso":"2026-09-25","date_human":"Friday, September 25, 2026","generated_utc":"2026-09-25 17:54 UTC","read_minutes":6,"patch_tuesday":false,"top_stories":[{"title":"Podcast: OpenAI Admits AI is Killing the Internet","link":"https://www.404media.co/podcast-openai-admits-ai-is-killing-the-internet/","reason":"Microsoft","category":"News","sources":["404 Media","Bleeping Computer","CCCS Alerts & Advisories","Cyber Security News","Dark Reading","Huntress","Infosecurity Magazine","The Hacker News"],"coverage":8,"cve_ids":[],"summary":"We start this week with Jason\u2019s story about OpenAI and Microsoft\u2019s big admissions from court records that they are destroying the internet in all sorts of ways, and stealing intellectual property on an unprecedented\u2026","source":"404 Media","date_rel":"2h ago","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/09/maxresdefault-5.jpg","description":"We start this week with Jason\u2019s story about OpenAI and Microsoft\u2019s big admissions from court records that they are destroying the internet in all sorts of ways, and stealing intellectual property on an unprecedented scale. He admit it. After the break, Emanuel explains how he hijacked a real band\u2019s Spotify page with AI-generated slop. In the subscribers-only section, we hear all about iLands, the AI agent platform that is basically just spam. Listen to the weekly podcast on Apple Podcasts , Spotify , or YouTube . Become a paid subscriber for access to this episode's bonus content and to power\u2026","related":[{"title":"Microsoft security advisory \u2013 August 2026 monthly rollup (AV26-804) \u2013 Update 4","link":"https://cyber.gc.ca/en/alerts-advisories/microsoft-security-advisory-august-2026-monthly-rollup-av26-804","source":"CCCS Alerts & Advisories","date_rel":"1h ago"},{"title":"Microsoft plans to deprecate Windows Deployment Services","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-to-deprecate-windows-deployment-services-after-windows-server-2025/","source":"Bleeping Computer","date_rel":"5h ago"},{"title":"Microsoft: Recent Windows updates cause desktop loading issues","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-recent-windows-updates-cause-desktop-loading-issues/","source":"Bleeping Computer","date_rel":"7h ago"},{"title":"Managed or Modified: Choose How Huntress Hardens Microsoft 365","link":"https://www.huntress.com/blog/managed-or-modified-choose-how-huntress-hardens-microsoft-365","source":"Huntress","date_rel":"24 Sep"},{"title":"Windows 11 KB5124010 update released with 46 changes and fixes","link":"https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5124010-update-released-with-46-changes-and-fixes/","source":"Bleeping Computer","date_rel":"24 Sep"},{"title":"Microsoft Rebuilds the SOC with AI Agents, SIEM Integration and Machine-Speed Defense","link":"https://cybersecuritynews.com/microsoft-rebuilds-the-soc/","source":"Cyber Security News","date_rel":"24 Sep"}]},{"title":"Crooks use fake desktop apps to fool HR staff into giving them remote access","link":"https://www.theregister.com/security/2026/09/25/crooks-use-fake-desktop-apps-to-fool-hr-staff-into-giving-them-remote-access/5299226","reason":"Windows","category":"News","sources":["Cyber Security News","Dark Reading","Infosecurity Magazine","Malwarebytes Labs","Microsoft Security","The Hacker News","The Register Security"],"coverage":7,"cve_ids":["CVE-2026-69732","CVE-2026-71337","CVE-2026-85921"],"summary":"You work in your company's human resources department and use HR software to check employee information, benefits, and payroll. So, when you see a downloadable Windows version promising a faster alternative to the usual\u2026","source":"The Register Security","date_rel":"23m ago","thumbnail":"https://image.theregister.com/?imageId=262302&width=800","description":"You work in your company's human resources department and use HR software to check employee information, benefits, and payroll. So, when you see a downloadable Windows version promising a faster alternative to the usual web interface, you grab it. Unfortunately, the app isn't what it claims to be. Instead, it silently installs ConnectWise's legitimate ScreenConnect software, giving the operator persistent remote access to your PC. Cybersecurity outfit Allure Security reported the discovery of the campaign Thursday, describing it as the latest evolution in a trend of abusing ScreenConnect and\u2026","related":[{"title":"Kothamine malware uses Tailscale\u2019s tailcat to evade network detection","link":"https://www.malwarebytes.com/blog/threat-intel/2026/09/kothamine-malware-uses-tailscales-tailcat-to-evade-network-detection","source":"Malwarebytes Labs","date_rel":"2h ago"},{"title":"CVE-2026-85921 Windows Secure Kernel Mode Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-85921","source":"Microsoft Security","date_rel":"3h ago"},{"title":"Criminals turn placeholder domain into ClickFix trap","link":"https://www.malwarebytes.com/blog/news/2026/09/criminals-turn-placeholder-domain-into-clickfix-trap","source":"Malwarebytes Labs","date_rel":"5h ago"},{"title":"Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content","link":"https://thehackernews.com/2026/09/placeholder-third-partycom-referenced.html","source":"The Hacker News","date_rel":"24 Sep"},{"title":"CVE-2026-69732 Windows Link Layer Topology Discovery Protocol Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69732","source":"Microsoft Security","date_rel":"24 Sep"},{"title":"CVE-2026-71337 Windows Storage Management Provider Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71337","source":"Microsoft Security","date_rel":"24 Sep"}]},{"title":"Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions","link":"https://thehackernews.com/2026/09/unpatched-oneplus-flaws-let-installed.html","reason":"Android","category":"News","sources":["Infosecurity Magazine","Malwarebytes Labs","SecurityWeek","The Hacker News","The Register Security"],"coverage":5,"cve_ids":[],"summary":"A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain\u2026","source":"The Hacker News","date_rel":"23h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjiGu2guziH88Cs_LnFsPkCJ4zuxqgSX7q3SRrBXdSAEeJPhmYnpNp-c0WCNCqoOoyCv6NcnmCKm20rhqSb2rjw7KZ6Kh6UssR2fZG5SZX9Pjhb_fjONdBfgpxqpWNABPDvSmD9Hp913nErgH4PQm1ehlyspJt5RXASYckP6jHE3G0V2ou5fwkG7JOZyBY/s1600/oneplus.jpg","description":"A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone. OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not","related":[{"title":"Windows, Linux, Android File Notification Systems Leak User Activity","link":"https://www.securityweek.com/windows-linux-android-file-notification-systems-leak-user-activity/","source":"SecurityWeek","date_rel":"7h ago"},{"title":"RemControl Banking Trojan Gives Attackers Remote Control of Android Devices","link":"https://www.infosecurity-magazine.com/news/banking-trojan-remote-control/","source":"Infosecurity Magazine","date_rel":"8h ago"},{"title":"Decades-old file security flaws found in Android, Linux, macOS, and Windows","link":"https://www.theregister.com/security/2026/09/24/decades-old-file-security-flaws-found-in-android-linux-macos-and-windows/5298672","source":"The Register Security","date_rel":"24 Sep"},{"title":"Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls","link":"https://thehackernews.com/2026/09/corp-mdm-spyware-targets-logistics.html","source":"The Hacker News","date_rel":"24 Sep"},{"title":"Update Chrome: 108 security fixes for desktop, new release for Android","link":"https://www.malwarebytes.com/blog/bugs/2026/09/update-chrome-108-security-fixes-for-desktop-new-release-for-android","source":"Malwarebytes Labs","date_rel":"24 Sep"}]},{"title":"A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You","link":"https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html","reason":"Gitlab","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Dark Reading","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start\u2026","source":"The Hacker News","date_rel":"23 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjaHKzSxkk0R4wjlziQHsR5vS1s1mTJovZkES9XL9nn5VLYiM55XuJoiGP9cugwNUOBMEMG3NrW3iBL9cVOqfp0F-9roYS7K7R5w8t3_NJr61_2_XgRNltvjXBFoGLfQPQFhUk0ju_mMCRCqJHjr76BrbngafAtElKkD-LZWZ7uUcY82i8PAMKh0ljHJQI/s1600/gitlab-email.jpg","description":"The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button labeled \"Email work item to this project.\" Mail sent to it opens an issue in that project, authored","related":[{"title":"GitLab security advisory (AV26-962)","link":"https://cyber.gc.ca/en/alerts-advisories/gitlab-security-advisory-av26-962","source":"CCCS Alerts & Advisories","date_rel":"5h ago"},{"title":"Exposed GitLab project email addresses let attackers push code","link":"https://www.bleepingcomputer.com/news/security/exposed-gitlab-project-email-addresses-let-attackers-push-code/","source":"Bleeping Computer","date_rel":"24 Sep"},{"title":"GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks","link":"https://www.darkreading.com/application-security/gitlab-email-addresses-supply-chain-attacks","source":"Dark Reading","date_rel":"23 Sep"}]},{"title":"Bitget blames North Korea for $387.5M crypto wallet raid","link":"https://www.theregister.com/cyber-crime/2026/09/25/bitget-blames-north-korea-for-3875m-crypto-wallet-raid/5299218","reason":"Exchange","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News","The Register Security"],"coverage":4,"cve_ids":[],"summary":"The CEO of crypto exchange Bitget has confirmed that a cyberattack with all the hallmarks of a North Korean operation resulted in approximately $387.5 million worth of digital assets being stolen from the exchange\u2019s\u2026","source":"The Register Security","date_rel":"49m ago","thumbnail":"https://image.theregister.com/?imageId=239887&width=800","description":"The CEO of crypto exchange Bitget has confirmed that a cyberattack with all the hallmarks of a North Korean operation resulted in approximately $387.5 million worth of digital assets being stolen from the exchange\u2019s wallets. Bitget initially estimated the loss at $351.6 million, but later revised the figure to $387.5 million after identifying additional affected assets on Zcash and TRON that were not included in the initial estimate. Blockchain intelligence company Arkham published its preliminary observations of the attack, estimating at the time that roughly $350 million was stolen and that\u2026","related":[{"title":"Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise","link":"https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html","source":"The Hacker News","date_rel":"7h ago"},{"title":"Hackers steal $351.6 million in Bitget crypto exchange hack","link":"https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/","source":"Bleeping Computer","date_rel":"9h ago"},{"title":"Bitget Hot Wallet Hacked \u2013 Attackers Stole $351.6 Million From Hot Wallets","link":"https://cybersecuritynews.com/bitget-hot-wallet-hacked/","source":"Cyber Security News","date_rel":"14h ago"}]},{"title":"Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing","link":"https://www.theregister.com/security/2026/09/24/salesforce-agentforce-vulns-allowed-0-click-crm-data-theft-anonymous-phishing/5298958","reason":"Salesforce","category":"News","sources":["Dark Reading","Infosecurity Magazine","SecurityWeek","The Register Security"],"coverage":4,"cve_ids":[],"summary":"Security flaws in Salesforce Agentforce allowed poisoned leads to hijack its AI agents, silently steal CRM data without requiring a click, and send phishing messages under the agents\u2019 identities. Zenity Labs uncovered\u2026","source":"The Register Security","date_rel":"22h ago","thumbnail":"https://image.theregister.com/?imageId=5223048&width=800","description":"Security flaws in Salesforce Agentforce allowed poisoned leads to hijack its AI agents, silently steal CRM data without requiring a click, and send phishing messages under the agents\u2019 identities. Zenity Labs uncovered the three vulnerabilities, collectively called SalesBleed, and reported them to Salesforce, which worked with the AI agent security provider to fix the issues. While these attack chains no longer work, Zenity co-founder and CTO Michael Bargury told The Register that the vulnerabilities highlight the difficulties in controlling what agents can access - and what happens if and\u2026","related":[{"title":"Zero-Click Vulnerabilities in Salesforce Agentforce Expose Wider AI Agent Risk","link":"https://www.infosecurity-magazine.com/news/vulnerabilities-salesforce-ai/","source":"Infosecurity Magazine","date_rel":"4h ago"},{"title":"\u2018SalesBleed\u2019 Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration","link":"https://www.securityweek.com/salesbleed-flaws-in-salesforce-agentforce-enabled-zero-click-data-exfiltration/","source":"SecurityWeek","date_rel":"8h ago"},{"title":"'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing","link":"https://www.darkreading.com/application-security/salesbleed-exploits-salesforce-agents-slack-phishing","source":"Dark Reading","date_rel":"20h ago"}]},{"title":"Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware","link":"https://thehackernews.com/2026/09/compromised-github-actions-came-back.html","reason":"Github","category":"News","sources":["CCCS Alerts & Advisories","Infosecurity Magazine","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected\u2026","source":"The Hacker News","date_rel":"3h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJFMIQ6v0uJDRoxyIhqsoqsYoXN00dcDH4IvkdQAkRBRj6ha5LIu2-2yzzvQk1OZTc-7tK1fjeqyIh8xvRNvz_CotOtGNsYnejlbHED7cI-bmZFP80JIdxk_0D9I6Zo10-6b4x4euCTaRtz8c6ncYKykDsW7Bt4oFEVYWTe3AHJdiUxM32R6hGP9C0Y0Xf/s1600/github-shai.jpg","description":"Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHub Actions are listed below - actions-cool/issues-helper actions-cool/maintain-one-comment Visiting either of the repositories now shows the message: \"Access to this","related":[{"title":"GitHub security advisory (AV26-956)","link":"https://cyber.gc.ca/en/alerts-advisories/github-security-advisory-av26-956","source":"CCCS Alerts & Advisories","date_rel":"23 Sep"},{"title":"Hundreds of Leaked GitHub App Keys Still Authenticate","link":"https://www.infosecurity-magazine.com/news/hundreds-leaked-github-app-keys/","source":"Infosecurity Magazine","date_rel":"23 Sep"}]},{"title":"Google to critical infra orgs: Our AI scanners won't be evil, promise","link":"https://www.theregister.com/security/2026/09/24/google-to-critical-infra-orgs-our-ai-scanners-wont-be-evil-promise/5298685","reason":"Google","category":"News","sources":["Dark Reading","Malwarebytes Labs","Risky Business","The Register Security"],"coverage":4,"cve_ids":[],"summary":"Google has jumped on the AI-defense-for-critical-systems train with its Scan for Good initiative, and says that its threat-hunting models have already autonomously uncovered critical security issues at hospitals, a\u2026","source":"The Register Security","date_rel":"24 Sep","thumbnail":"https://image.theregister.com/?imageId=5298699&width=800","description":"Google has jumped on the AI-defense-for-critical-systems train with its Scan for Good initiative, and says that its threat-hunting models have already autonomously uncovered critical security issues at hospitals, a municipality, a public rail operator, and major technology providers. So don't fear these bots. The initiative, announced on Thursday, uses Google\u2019s Gemini 3.8 Flash Cyber, a version of the model tuned for software bug hunting and remediation, and Wiz\u2019s Red Agent - this is the Google-owned cloud security shop\u2019s pentesting AI agent. The AI systems will uncover public exposures and\u2026","related":[{"title":"Google\u2019s location data privacy failures draw a \u20ac403 million fine","link":"https://www.malwarebytes.com/blog/news/2026/09/googles-location-data-privacy-failures-draw-a-e403-million-fine","source":"Malwarebytes Labs","date_rel":"24 Sep"},{"title":"Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign","link":"https://www.darkreading.com/threat-intelligence/attackers-manipulate-ai-chatbots-mass-disinformation-phishing-campaign","source":"Dark Reading","date_rel":"23 Sep"},{"title":"Fake Claude Max giveaway hides a Google account phishing trap","link":"https://www.malwarebytes.com/blog/threat-intel/2026/09/fake-claude-max-giveaway-hides-a-google-account-phishing-trap","source":"Malwarebytes Labs","date_rel":"23 Sep"},{"title":"Risky Business #854 -- We're Jevpilled","link":"https://risky.biz/RB854/","source":"Risky Business","date_rel":"23 Sep"},{"title":"Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions","link":"https://www.theregister.com/security/2026/09/22/windows-closedquorum-malware-uses-ai-models-to-autonomously-select-post-compromise-actions/5298435","source":"The Register Security","date_rel":"22 Sep"}]},{"title":"PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence","link":"https://thehackernews.com/2026/09/pamstealer-macos-malware-adds-live-c2.html","reason":"Macos","category":"News","sources":["Bleeping Computer","Cyber Security News","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to\u2026","source":"The Hacker News","date_rel":"4h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRZ3gQjU3cKnH6bHzlz8PjeaUqGcrVWnRx-bT-mgDBYv-G4CM2Iix8afTJe8sAXEghuPTiD5KszOYzA0peRhyoGKNW9YE1QtwLubBFuv9YZjXnANEGyMGwi7-oEdIqmtRBWPzUZV7S91WiUX4cI2YVMHVSQbByCmIwAX9oZxvzjb2ScVJmpmMCzpDKaKtN/s1600/macos.jpg","description":"Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. \"Where earlier variants embedded their payload key material","related":[{"title":"New MacSync Malware Turns macOS Apps Into Tools for Crypto and Password Theft","link":"https://cybersecuritynews.com/new-macsync-malware/","source":"Cyber Security News","date_rel":"9h ago"},{"title":"MacSync malware uses public iCloud calendars to deliver new payloads","link":"https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/","source":"Bleeping Computer","date_rel":"20h ago"}]},{"title":"CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks","link":"https://www.bleepingcomputer.com/news/security/cisa-warns-of-sharepoint-wso2-adobe-commerce-flaws-exploited-in-attacks/","reason":"CVE-2026-5430","category":"News","sources":["Bleeping Computer","CISA Alerts & Advisories"],"coverage":2,"cve_ids":["CVE-2026-5430","CVE-2026-71362"],"summary":"The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider\u2026","source":"Bleeping Computer","date_rel":"29m ago","thumbnail":"","description":"","related":[{"title":"CISA Adds Two Known Exploited Vulnerabilities to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/24/cisa-adds-two-known-exploited-vulnerabilities-catalog","source":"CISA Alerts & Advisories","date_rel":"24 Sep"}]}],"worth_reading":[{"title":"Is This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)","link":"https://labs.watchtowr.com/is-this-a-joke-in-the-auth-header-f5-big-ip-unauth-heap-overflow-to-rce-cve-2026-94127/","reason":"CVE-2026-94127","category":"Research","sources":["CCCS Alerts & Advisories","Rapid7 Blog","The Hacker News","watchTowr Labs"],"coverage":4,"cve_ids":["CVE-2026-94127"],"summary":"Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry. We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas\u2026","source":"watchTowr Labs","date_rel":"23 Sep","thumbnail":"https://storage.ghost.io/c/a0/dc/a0dcbbe4-0ae7-4d7e-90f7-ebbc3a0f5a84/content/images/2026/09/1.png","description":"Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry. We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas (apparently?) are now using LLMs to find and reproduce vulnerabilities - it\u2019s a free-for-all (unless you\u2019re trying to buy RAM). Unfortunately, while we're all finding more vulnerabilities and flexing obfuscated stack traces\u2026 (or emoji-ridden HTTP requests that are actually complete slop and not real, and please, for the love of god, no, those slop-ridden payloads appearing in\u2026","related":[{"title":"CVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APM","link":"https://www.rapid7.com/blog/post/etr-cve-2026-94127-critical-unauthenticated-rce-in-f5-big-ip-apm","source":"Rapid7 Blog","date_rel":"23 Sep"},{"title":"F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers","link":"https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html","source":"The Hacker News","date_rel":"23 Sep"},{"title":"AL26-022 - Vulnerability impacting F5 BIG-IP Access Policy Manager (APM) \u2013 CVE-2026-94127","link":"https://cyber.gc.ca/en/alerts-advisories/al26-022-vulnerability-impacting-f5-big-ip-access-policy-manager-apm-cve-2026-94127","source":"CCCS Alerts & Advisories","date_rel":"22 Sep"}]},{"title":"Wiz Named a Leader in The Forrester Wave\u2122: Proactive Security Platforms, Q3 2026","link":"https://www.wiz.io/blog/forrester-wave-for-proactive-security-2026","reason":"Forrester Proactive Platforms","category":"Research","sources":["CrowdStrike Blog","Wiz Research"],"coverage":2,"cve_ids":[],"summary":"Forrester\u2019s Proactive Security Platforms evaluation rated Wiz with top scores across eight areas, reflecting our commitment to securing the AI era","source":"Wiz Research","date_rel":"24 Sep","thumbnail":"https://www.datocms-assets.com/75231/1790266246-blog-banner-image.png","description":"","related":[{"title":"CrowdStrike Named a Leader in The Forrester Wave\u2122: Proactive Security Platforms, Q3 2026","link":"https://www.crowdstrike.com/en-us/blog/crowdstrike-named-leader-forrester-wave-proactive-security-platforms-q3-2026/","source":"CrowdStrike Blog","date_rel":"24 Sep"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-97359","vendor":"rejetto","product":"hfs2","severity":"CRITICAL","score":10.0,"description":"HFS2 version 2.4.0 and earlier contains a template injection vulnerability in the multipart upload handler that allows unauthenticated attackers to achieve remote code execution by embedding malicious template syntax in a filename. Attacker\u2026","cwe":"CWE-1336","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-97359"},{"id":"CVE-2026-97360","vendor":"rejetto","product":"hfs2","severity":"CRITICAL","score":10.0,"description":"HFS2 version 2.4.0 and earlier contains an unauthenticated arbitrary file access vulnerability that allows unauthenticated attackers to read, write, append, and delete files anywhere the HFS service account has filesystem access outside the\u2026","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-97360"},{"id":"CVE-2026-19072","vendor":"Rapid7","product":"Velociraptor","severity":"CRITICAL","score":9.9,"description":"Velociraptor stores the compiled VQL in the hunt object internally to avoid having to recompile the artifacts for each endpoint in the hunt. Although the field \"compiled_collector_args\" is an internal field, Velociraptor allowed the field t\u2026","cwe":"CWE-164","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-19072"},{"id":"CVE-2026-93207","vendor":"Linux","product":"Linux","severity":"CRITICAL","score":9.8,"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nSUNRPC: Zero rpc_gss_wire_cred at svcauth_gss_decode_credbody() entry\n\nsvcauth_gss_decode_credbody() writes the caller's\nrpc_gss_wire_cred field by field and assigns gc_ct\u2026","cwe":"","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93207"},{"id":"CVE-2026-97413","vendor":"Linux","product":"Linux","severity":"CRITICAL","score":9.8,"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nRDMA/rtrs-srv: Fix integer underflow in process_read and process_write\n\nusr_len is read from a network-supplied message field (le16_to_cpu)\nand used to compute data_len = \u2026","cwe":"","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-97413"},{"id":"CVE-2026-14281","vendor":"WordPress","product":"Automation Web Platform \u2013 Notifications and OTP for WooCommerce, Advanced Country Code","severity":"CRITICAL","score":9.8,"description":"The Automation Web Platform \u2013 Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 4.8.6. This is due to missing permission enforcement\u2026","cwe":"CWE-269","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-14281"},{"id":"CVE-2026-81549","vendor":"IBM","product":"DataStage on Cloud Pak for Data","severity":"CRITICAL","score":9.6,"description":"IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of the X-Forwarded-Proto header.","cwe":"CWE-918","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-81549"},{"id":"CVE-2026-93228","vendor":"HashiCorp","product":"Linux","severity":"CRITICAL","score":9.1,"description":"In the Linux kernel, the following vulnerability has been resolved:\n\nsvcrdma: Reject Write/Reply chunks with segcount 0\n\nA peer can send a Write or Reply chunk whose segcount field is zero.\nxdr_check_write_chunk() only rejects segcount > rc\u2026","cwe":"","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93228"},{"id":"CVE-2026-89055","vendor":"WordPress","product":"Customer Reviews for WooCommerce","severity":"CRITICAL","score":9.1,"description":"The Customer Reviews for WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.120.0. This is due to the plugin not properly verifying that a user is authorized to perform an action. \u2026","cwe":"CWE-862","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-89055"},{"id":"CVE-2026-93399","vendor":"WordPress","product":"Online Scheduling and Appointment Booking System \u2013 Bookly","severity":"CRITICAL","score":9.1,"description":"The Bookly plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 28.2 via the 'bookly_get_form_id', 'bookly_render_complete', 'bookly_add_to_calendar' and 'bookly_rollback_order' AJAX actio\u2026","cwe":"CWE-639","kev":false,"kev_action":"","kev_due":"","epss":null,"url":"https://cve.blackmesa.ca/?q=CVE-2026-93399"}],"vendor_spikes":[{"vendor":"Linux","count":100,"critical_count":2},{"vendor":"WordPress","count":44,"critical_count":3},{"vendor":"Unknown","count":19,"critical_count":0},{"vendor":"IBM","count":19,"critical_count":1},{"vendor":"HashiCorp","count":10,"critical_count":1},{"vendor":"Microsoft","count":8,"critical_count":0},{"vendor":"Altera","count":8,"critical_count":0},{"vendor":"Red Hat","count":7,"critical_count":0},{"vendor":"Novadigits technologies","count":7,"critical_count":0},{"vendor":"Apple","count":6,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":287,"has_news_data":true,"has_cve_data":true}