Skip to content
BLACKMESA.CA Brief

Wednesday, September 30, 2026 · generated · about 5 min read

Morning Brief

Patch today vendors with the most new CVEs today

Ranked by CVE count. Each vendor opens the CVE Feed filtered to that vendor and these dates.

Top developments ranked by cross-source trending

  1. Image: Cyber Security News

    RATHat Android Malware Uses Gemini AI to Control Phones Outside Normal App Permissions

    News Cyber Security News5h ago7 sources

    RATHat Android malware uses Gemini AI to help take control of infected phones beyond normal app permissions. The banking trojan abuses a developer feature to establish a separate command channel that can survive removal of the malicious application until the phone reboots. Attackers distribute it through malicious adverts and phishing text messages targeting Europe, Latin America and Southeast Asia. Fake apps lure victims into granting Accessibility access, extending the risks described in earlier RatHat banking attacks with deeper control over the device. Cleafy researchers identified three…

    Also in The Record Bleeping Computer CISA Alerts & Advisories +3

    View on Security Feed

  2. Oh Look, The Foot Gun Went Off Again (Citrix NetScaler PreAuth Command Injection CVE-2026-88771)

    Research watchTowr Labs28 Sep6 sources

    God damn it, we're back in the room again. Yes, that sound in your ears is screaming. The footgun has gone off again, shockingly, and we are yet again dealing with a situation where the entire world apparently knew about Citrix NetScaler CVEs before Citrix had woken up or bothered to acknowledge them. https://www.citrix.com/blogs/2026-01/security-by-design-proven-by-action-with-citrix-netscaler On Saturday, we took our role in the industry seriously - by rapidly adding credibility to the rumors via the (inter)national authorities that we've historically worked with, and then broadcasting that…

    Also in SecurityWeek Palo Alto Unit 42 Rapid7 Blog +2

    CVE-2026-88771 ↗CVE-2026-88772 ↗View on Security Feed

  3. Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

    News The Hacker News6h ago7 sources

    Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional

    Also in Dark Reading CyberScoop The Hacker News +3

    View on Security Feed

  4. Apple patches CoreGraphics zero-day already exploited in targeted attacks

    News The Register Security29 Sep6 sources

    Apple has patched a CoreGraphics zero-day after warning that attackers may already have used the bug to compromise a small number of carefully chosen targets. The vulnerability, tracked as CVE-2026-86950, is an out-of-bounds write flaw in CoreGraphics, Apple's framework for handling graphics across its operating systems. According to Apple's advisory, processing a maliciously crafted file could allow an attacker to execute arbitrary code on a vulnerable device. The fruity vendor said it addressed the problem with improved bounds checking, though the bug appears to have made it out into the…

    Also in Infosecurity Magazine Dark Reading CISA Alerts & Advisories +2

    CVE-2026-86950 ↗View on Security Feed

  5. AI Agent Finds Linux Kernel Bug That Turns a Tiny Memory Write Into Root Access

    News Cyber Security News6h ago5 sources

    Autonomous security research platform XBOW has disclosed CVE-2026-72018, a high-severity Linux kernel vulnerability that converts a tightly constrained out-of-bounds memory write into local root access. The flaw affects the DIBS loopback implementation used by the SMC-D shared-memory communication path, where a missing bounds check allows attacker-controlled data to be copied beyond an allocated kernel buffer. The vulnerability is notable not only for its impact, but for the weakness of the available exploit primitive. XBOW’s research showed that the bug could reliably produce only 16 zero…

    Also in Bleeping Computer The Hacker News Bleeping Computer +3

    CVE-2026-72018 ↗View on Security Feed

  6. US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

    News The Hacker News4h ago5 sources

    ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud

    Also in Bleeping Computer Bleeping Computer The Hacker News +3

    View on Security Feed

  7. Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

    News The Hacker News9h ago5 sources

    Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler

    Also in CyberScoop Bleeping Computer The Register Security +1

    CVE-2026-88772 ↗View on Security Feed

  8. Custom ChatGPTs push ClickFix attacks to deploy RAT malware

    News Bleeping Computer18h ago3 sources

    Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware.

    Also in SecurityWeek Infosecurity Magazine Infosecurity Magazine

    View on Security Feed

  9. OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

    News The Hacker News7h ago3 sources

    A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way

    Also in SecurityWeek Cyber Security News

    CVE-2026-84782 ↗View on Security Feed

  10. Fortinet Uncovers SectopRAT Variant Hidden Inside Tampered Legitimate Windows Software

    News Cyber Security News6h ago2 sources

    A SectopRAT variant has been found hidden inside tampered Windows software, allowing attackers to control an infected computer and steal sensitive information. The intrusion used legitimate application components as cover, with encrypted files concealing the malware until it was loaded into memory. The affected program came from an Italian developer known for a long-running digital audio workstation. Attackers modified its supporting files and arranged automatic execution through a scheduled task. The investigation did not establish how the altered software first reached the victim’s…

    Also in Microsoft Security Microsoft Security Microsoft Security

    CVE-2026-69288 ↗CVE-2026-69504 ↗CVE-2026-69712 ↗View on Security Feed

Vulnerability watch what to look at, most urgent first

Details CVEProductSeverity CVSSEPSS KEVFixIn the news
Highest scoring today 10new CVEs, highest CVSS first
CVE-2026-53988 dockhandFinsys Critical 10.0 — — None linked — CVSS 10.0No fix linked
CVE-2026-96587 Dashcam Android ApplicationGoogle Critical 10.0 — — None linked — CVSS 10.0No fix linked
CVE-2026-71379 TMS7Toptech Systems Critical 10.0 — — None linked — CVSS 10.0No fix linked
CVE-2026-84154 GEOVIA Geospatial Data ManagerDassault Systèmes Critical 9.9 0.4% — None linked — EPSS 0.4%CVSS 9.9No fix linked
CVE-2026-102911 pi-llm-wikizosmaai Critical 9.9 — — None linked — CVSS 9.9No fix linked
CVE-2023-54400 Fumeng CloudMicrosoft Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-77177 Unknown Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-100291 YSSD-RTMP-H5Anjvision Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-39117 Unknown Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-76721 Instant ONHP Critical 9.8 — — None linked — CVSS 9.8No fix linked

Click a row, or press +, to expand it.EPSS is FIRST's estimated chance of exploitation in the next 30 days.Full CVE Feed

Worth reading quieter, still worth your time

  1. The Blue Agent POV: Investigating Multi-Platform Data Exfiltration Across AWS and GitHub

    Research Wiz Research29 Sep2 sources

    See how the Blue Agent investigated a multi-platform attack in minutes, following evidence across AWS and GitHub to uncover compromised credentials, stolen source code, and custom data exfiltration tooling

    Also in Infosecurity Magazine

    View on Security Feed

Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score. No AI writes any of this, and every number traces back to something already published on those two tools.

Top developments come from the Security Feed's cross-source trending detection. Vulnerability watch comes from the CVE Feed's daily NVD and CISA KEV sync.