{"date_iso":"2026-10-01","date_human":"Thursday, October 1, 2026","generated_utc":"2026-10-01 15:38 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"Microsoft catches hackers exploiting Zimbra bug before disclosure","link":"https://www.theregister.com/security/2026/10/01/microsoft-catches-hackers-exploiting-zimbra-bug-before-disclosure/5300543","reason":"Microsoft","category":"News","sources":["Ars Technica Security","Bleeping Computer","Cyber Security News","Dark Reading","ESET WeLiveSecurity","Infosecurity Magazine","The Hacker News","The Register Security"],"coverage":8,"cve_ids":[],"summary":"Attackers were poking at a critical Zimbra mail server bug weeks before it was publicly disclosed, and then moved on to steal credentials, raid mailboxes, and take deeper control of compromised systems. Microsoft Threat\u2026","source":"The Register Security","date_rel":"53m ago","thumbnail":"https://image.theregister.com/?imageId=5279434&width=800","description":"Attackers were poking at a critical Zimbra mail server bug weeks before it was publicly disclosed, and then moved on to steal credentials, raid mailboxes, and take deeper control of compromised systems. Microsoft Threat Intelligence said it tracked exploitation of CVE-2026-73570, an unauthenticated command injection vulnerability in Zimbra Collaboration Suite that gives attackers a potentially easy route into exposed mail servers. No stolen password or unfortunate employee clicking a dodgy link is required. An attacker can send a specially crafted email to a vulnerable internet-facing server\u2026","related":[{"title":"Warlock Ransomware Exploiting SharePoint Flaws to Attack Water and Telecom Operators","link":"https://cybersecuritynews.com/warlock-ransomware-exploiting-sharepoint-flaws/","source":"Cyber Security News","date_rel":"1h ago"},{"title":"China-Linked Hackers Impersonate AI Experts to Target US Policy Insiders","link":"https://www.infosecurity-magazine.com/news/ta419-impersonates-ai-experts-us/","source":"Infosecurity Magazine","date_rel":"1h ago"},{"title":"Microsoft Enables Windows 11 Backup Setting by Default for Organizations","link":"https://cybersecuritynews.com/windows-11-backup-setting-by-default/","source":"Cyber Security News","date_rel":"2h ago"},{"title":"Hackers Abuse Microsoft Defender Exclusions to Hide Malware From Antivirus Scans","link":"https://cybersecuritynews.com/hackers-abuse-microsoft-defender/","source":"Cyber Security News","date_rel":"2h ago"},{"title":"Microsoft enables Windows settings backup by default for orgs","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-enables-windows-settings-backup-by-default-for-orgs/","source":"Bleeping Computer","date_rel":"4h ago"},{"title":"Attackers have been exploiting critical Zimbra flaw to steal emails","link":"https://arstechnica.com/security/2026/09/attackers-have-been-exploiting-critical-zimbra-flaw-to-steal-emails/","source":"Ars Technica Security","date_rel":"18h ago"}]},{"title":"Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path","link":"https://thehackernews.com/2026/10/apple-coregraphics-poc-emerges-as.html","reason":"CVE-2026-86950","category":"News","sources":["CISA Alerts & Advisories","Dark Reading","Infosecurity Magazine","SANS Internet Storm Center","The Hacker News","The Register Security"],"coverage":6,"cve_ids":["CVE-2026-86950"],"summary":"Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a\u2026","source":"The Hacker News","date_rel":"9h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj5u07cHr0A83x9aQdJE-_Emw6K1GzjR2eybdv9Rq_qi43Oi-M2U4eWqCkjvH5fUhw5wKSa-rvQ81gePKLYCqJXyrZpWHXOehEFq_QaTdYpy0O3LLUQGGYn1pxlUGUXwplloAHT3ZP7oMcF6al9A7q9XfnYNUhtBD0qw-GOWuKiyZl8zbrudyjWtEzHXC0/s1600/apple-whatsapp.jpg","description":"Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working","related":[{"title":"Apple Patches CoreGraphics Zero Day Exploited in Attacks","link":"https://www.infosecurity-magazine.com/news/apple-patches-coregraphics-zero/","source":"Infosecurity Magazine","date_rel":"30 Sep"},{"title":"Apple Zero-Day Vulnerability Weaponized in Targeted Attacks","link":"https://www.darkreading.com/cyberattacks-data-breaches/apple-zero-day-vulnerability-weaponized-targeted-attacks","source":"Dark Reading","date_rel":"29 Sep"},{"title":"Apple patches CoreGraphics zero-day already exploited in targeted attacks","link":"https://www.theregister.com/security/2026/09/29/apple-patches-coregraphics-zero-day-already-exploited-in-targeted-attacks/5299721","source":"The Register Security","date_rel":"29 Sep"},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/29/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"29 Sep"},{"title":"Apple Emergency Patch for iOS 26, macOS26, macOS15 (CVE-2026-86950), (Mon, Sep 28th)","link":"https://isc.sans.edu/diary/rss/33376","source":"SANS Internet Storm Center","date_rel":"28 Sep"},{"title":"Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks","link":"https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html","source":"The Hacker News","date_rel":"28 Sep"}]},{"title":"CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV","link":"https://thehackernews.com/2026/10/cisa-adds-exploited-cisco-catalyst-sd.html","reason":"Cisco","category":"News","sources":["CCCS Alerts & Advisories","Infosecurity Magazine","SecurityWeek","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following\u2026","source":"The Hacker News","date_rel":"5h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8jgm3LMY2zr1S1DmXnvVEPDiTKYR5FXHW7q_6duG1lVPhzbW2ZfJwRM9glqAJrQhBX3HAAiksz-tUpRN4pfT9VWHUksa-1SgHZmKcNUd1tJfsyFiwhtezZN_zBM_cEmqjkECI_2gfWhnqZ1ry2hgDou-qQCB21zbl1RzYN9JB0bRjqzhB2m6gBomg-ow9/s1600/cisa-wan.jpg","description":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as CVE-2026-76504 (CVSS score: 9.8), could allow an unauthenticated, remote attacker to access an affected system with","related":[{"title":"Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation","link":"https://www.infosecurity-magazine.com/news/critical-cisco-catalyst-sdwan/","source":"Infosecurity Magazine","date_rel":"1h ago"},{"title":"Cisco security advisory (AV26-978)","link":"https://cyber.gc.ca/en/alerts-advisories/cisco-security-advisory-av26-978","source":"CCCS Alerts & Advisories","date_rel":"4h ago"},{"title":"Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability","link":"https://www.securityweek.com/cisco-patches-exploited-catalyst-sd-wan-zero-day-vulnerability/","source":"SecurityWeek","date_rel":"7h ago"},{"title":"Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager","link":"https://thehackernews.com/2026/09/cisco-warns-of-attackers-exploiting.html","source":"The Hacker News","date_rel":"30 Sep"}]},{"title":"Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution","link":"https://thehackernews.com/2026/09/citrix-netscaler-cve-2026-88772-exploit.html","reason":"CVE-2026-88772","category":"News","sources":["CyberScoop","Palo Alto Unit 42","The Hacker News","The Register Security","watchTowr Labs"],"coverage":5,"cve_ids":["CVE-2026-88771","CVE-2026-88772"],"summary":"Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked\u2026","source":"The Hacker News","date_rel":"30 Sep","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcFl1djJdJQkamdMtV0xibSpzc4ahUKNoVKtVoDSeKFJAYUkH2SnmxalYIJpaVZ9cywBJqyUflBrXWbhTIzpwL51iIyfINyH7z7YUHqDl3IbAJJmpCANlw8YvFFtmLa3T2es4rdE70Jd9tEUYAbuWFuXVBsx6Ar2radG2ZhgkqjBA5ZErCm0xVhNPv6d3F/s1600/watch-exploit.jpg","description":"Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler","related":[{"title":"Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)","link":"https://unit42.paloaltonetworks.com/netscaler-zero-days-exploited/","source":"Palo Alto Unit 42","date_rel":"19h ago"},{"title":"Attackers exploited Citrix NetScaler zero-day for at least three weeks undetected","link":"https://cyberscoop.com/citrix-netscaler-zero-day-attacks-three-weeks-undetected/","source":"CyberScoop","date_rel":"29 Sep"},{"title":"Custom malware used in Citrix 0-day attacks targeting govt, banks, professional services","link":"https://www.theregister.com/security/2026/09/29/custom-malware-used-in-citrix-0-day-attacks-targeting-govt-banks-professional-services/5299867","source":"The Register Security","date_rel":"29 Sep"},{"title":"Here We Go Again (Citrix NetScaler DTLS Preauth Memory Overflow CVE-2026-88772)","link":"https://labs.watchtowr.com/here-we-go-again-citrix-netscaler-dtls-preauth-memory-overflow-cve-2026-88772/","source":"watchTowr Labs","date_rel":"29 Sep"}]},{"title":"Someone \u2018Torturing\u2019 LLMs in a Robot Prison Has Triggered the Dumbest Debate in AI Yet","link":"https://www.404media.co/someone-torturing-llms-in-a-robot-prison-has-triggered-the-dumbest-debate-in-ai-yet/","reason":"Github","category":"News","sources":["404 Media","Bleeping Computer","SecurityWeek","The Hacker News"],"coverage":4,"cve_ids":[],"summary":"One of the most heated discussions occurring on X at the moment is about the ethics of a GitHub project in which a person is running Saw-like \u201ctorture\u201d and \u201cpain\u201d experiments on a series of locally hosted large language\u2026","source":"404 Media","date_rel":"18h ago","thumbnail":"https://storage.ghost.io/c/0f/76/0f76b548-bc58-4f25-abc3-3f5ebca07da4/content/images/2026/09/CleanShot-2026-09-30-at-2.15.47-PM@2x.png","description":"One of the most heated discussions occurring on X at the moment is about the ethics of a GitHub project in which a person is running Saw-like \u201ctorture\u201d and \u201cpain\u201d experiments on a series of locally hosted large language models, causing a series of effective altruists and people who believe LLMs are sentient to beg GitHub to delete the project on the grounds that the AI is suffering and that this glorified text adventure game is somehow cruel. The saga is an outgrowth of several recent viral papers and blog posts that have sparked a wildly tiresome conversation about AI consciousness and the\u2026","related":[{"title":"500,000 Active Credentials Left Exposed on GitHub","link":"https://www.securityweek.com/500000-active-credentials-left-exposed-on-github/","source":"SecurityWeek","date_rel":"5h ago"},{"title":"Over 543,000 valid credentials exposed in public GitHub repositories","link":"https://www.bleepingcomputer.com/news/security/over-543-000-valid-credentials-exposed-in-public-github-repositories/","source":"Bleeping Computer","date_rel":"21h ago"},{"title":"AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub","link":"https://thehackernews.com/2026/09/ai-coding-agents-exposed-13000-internal.html","source":"The Hacker News","date_rel":"30 Sep"}]},{"title":"Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version","link":"https://thehackernews.com/2026/10/google-rolls-out-gemini-4-argon-to.html","reason":"Google","category":"News","sources":["Dark Reading","Infosecurity Magazine","The Hacker News","The Record"],"coverage":4,"cve_ids":[],"summary":"Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. \"It delivers\u2026","source":"The Hacker News","date_rel":"7h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhYk4zu5KwFghyphenhyphenGNFmUKfmtScZfRpYSwO3huCn6VYY6EiFZH7t7zWwr6Agn-AqOHA19-uc6wQMnoOHXGY3V8F2ZWfxoTNiTp8VV1ePAvDGYlW3ocD8tXLN-tPuqvzwf7YRX9CXl1_Zj2b0ZcMqbZAo_5Ut3uG3gTTEXTCVxJyyTtcUlbfwXkdqCu8PpY4l6/s1600/gemini-4.jpg","description":"Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. \"It delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense,\" Koray Kavukcuoglu,","related":[{"title":"Malicious Custom GPTs Turn ChatGPT Into RAT Delivery Lure","link":"https://www.darkreading.com/cyberattacks-data-breaches/malicious-custom-gpts-chatgpt-rat-delivery-lure","source":"Dark Reading","date_rel":"18h ago"},{"title":"Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation","link":"https://therecord.media/google-vulnerabilities-cyberattacks-ai","source":"The Record","date_rel":"20h ago"},{"title":"AI-Found Vulnerabilities More Likely to Enable RCE, Google Says","link":"https://www.infosecurity-magazine.com/news/ai-found-vulnerabilities-rce/","source":"Infosecurity Magazine","date_rel":"30 Sep"},{"title":"Attackers Combine ChatGPT Feature Abuse With ClickFix to Deliver Trojan Malware","link":"https://www.infosecurity-magazine.com/news/chatgpt-feature-abuse-to-deliver/","source":"Infosecurity Magazine","date_rel":"30 Sep"},{"title":"Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions","link":"https://www.darkreading.com/application-security/chrome-store-poper-blocker-spyware-downloaded-millions","source":"Dark Reading","date_rel":"28 Sep"}]},{"title":"WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory","link":"https://thehackernews.com/2026/10/wordpress-backdoor-rebuilds-itself.html","reason":"Wordpress","category":"News","sources":["Cyber Security News","SANS Internet Storm Center","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site\u2026","source":"The Hacker News","date_rel":"59m ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgbdAzWwJ7WC6PL7vtBZDUWfVyYu9iIBlT3X5gZn-Yl9aRuZAEeW3RjEU81RQWsvH_7og6v7-somVgG-fR35drKy6bxLMcHdpJQAi6ydXw-m3oMxZ1hlDC7kr8Wsu0dOfRt6ZLEasAsYNGq-pzmQiBNWMbEBzqa9zYdAu16NtgIfDe3PpOvCVzGj6yFqmet/s1600/wordpress-exploit.jpg","description":"Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the \"SC_\" markers present in the injected content. Sucuri has described the malware as a \"self-healing mesh\" that's","related":[{"title":"WordPress Malware Comes Back After Removal Using a Self-Healing Backdoor","link":"https://cybersecuritynews.com/wordpress-malware-2/","source":"Cyber Security News","date_rel":"1h ago"},{"title":"Scans for Wordfence Protected Websites, (Tue, Sep 29th)","link":"https://isc.sans.edu/diary/rss/33382","source":"SANS Internet Storm Center","date_rel":"29 Sep"}]},{"title":"Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs","link":"https://thehackernews.com/2026/10/citrix-netscaler-post-exploitation.html","reason":"Citrix","category":"News","sources":["CyberScoop","Dark Reading","The Hacker News"],"coverage":3,"cve_ids":[],"summary":"Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data\u2026","source":"The Hacker News","date_rel":"11h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjAuODp7WTARNyJa6hiyuveQ1LUgYlaYQXGDDfRAYUA7Zkwwb7vMriA7VIh5HmBJwWWR0kALhQkijvT43ke2ajjOQHk6YxQb2rAgsB0PYcbMKPdm-JezjILBH8j3kY29iATKhZLQhVIyAjwNj9XFBTeenqPCHM1AzKMKRCVlMME3jQs5yIYSoVtrbRnVSY7/s1600/citrix-css-shell.jpg","description":"Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler","related":[{"title":"Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT","link":"https://thehackernews.com/2026/09/attackers-exploit-netscaler-flaw-for.html","source":"The Hacker News","date_rel":"30 Sep"},{"title":"Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers","link":"https://www.darkreading.com/vulnerabilities-threats/netscaler-zero-days-chaos-citrix","source":"Dark Reading","date_rel":"29 Sep"},{"title":"Citrix patches actively exploited NetScaler zero-days after a weekend of unofficial warnings","link":"https://cyberscoop.com/citrix-zero-days-delayed-disclosure/","source":"CyberScoop","date_rel":"29 Sep"}]},{"title":"Critical Cisco Catalyst SD-WAN Manager API authentication bypass exploited in the wild (CVE-2026-76504)","link":"https://www.rapid7.com/blog/post/etr-critical-cisco-catalyst-sd-wan-manager-api-authentication-bypass-exploited-in-the-wild-cve-2026-76504","reason":"CVE-2026-76504","category":"Research","sources":["Bleeping Computer","CISA Alerts & Advisories","Rapid7 Blog"],"coverage":3,"cve_ids":["CVE-2026-76504"],"summary":"Overview On September 30, 2026, Cisco published a security advisory for CVE-2026-76504 , a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has a CVSSv3.1 score\u2026","source":"Rapid7 Blog","date_rel":"30 Sep","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp","description":"Overview On September 30, 2026, Cisco published a security advisory for CVE-2026-76504 , a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has a CVSSv3.1 score of 9.8 and results from improper handling of URL encoding ( CWE-177 ). An unauthenticated, remote attacker can send a crafted HTTP request that bypasses an authentication rule for a specific API endpoint, gaining access to the API with the privileges of the admin user. According to Cisco, CVE-2026-76504 is being actively exploited in the wild; Cisco PSIRT became aware of the\u2026","related":[{"title":"Cisco warns of new SD-WAN zero-day exploited in attacks","link":"https://www.bleepingcomputer.com/news/security/cisco-warns-of-new-sd-wan-authentication-bypass-zero-day-exploited-in-attacks/","source":"Bleeping Computer","date_rel":"30 Sep"},{"title":"CISA Adds One Known Exploited Vulnerability to Catalog","link":"https://www.cisa.gov/news-events/alerts/2026/09/30/cisa-adds-one-known-exploited-vulnerability-catalog","source":"CISA Alerts & Advisories","date_rel":"30 Sep"}]},{"title":"ZDI-26-750: WatchGuard FireWare OS spamd statushdlr Stack-based Buffer Overflow Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-750/","reason":"Watchguard","category":"Research","sources":["CCCS Alerts & Advisories","Zero Day Initiative"],"coverage":2,"cve_ids":[],"summary":"This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of\u2026","source":"Zero Day Initiative","date_rel":"30 Sep","thumbnail":"","description":"This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-18145.","related":[{"title":"WatchGuard security advisory (AV26-981)","link":"https://cyber.gc.ca/en/alerts-advisories/watchguard-security-advisory-av26-981","source":"CCCS Alerts & Advisories","date_rel":"1h ago"},{"title":"ZDI-26-749: WatchGuard FireWare OS samld SAMLSession Deserialization of Untrusted Data Remote Code Execution Vulnerability","link":"http://www.zerodayinitiative.com/advisories/ZDI-26-749/","source":"Zero Day Initiative","date_rel":"30 Sep"},{"title":"WatchGuard security advisory (AV26-972)","link":"https://cyber.gc.ca/en/alerts-advisories/watchguard-security-advisory-av26-972","source":"CCCS Alerts & Advisories","date_rel":"29 Sep"}]}],"worth_reading":[{"title":"The Blue Agent POV: Investigating Multi-Platform Data Exfiltration Across AWS and GitHub","link":"https://www.wiz.io/blog/blue-agent-data-exfiltration-investigation","reason":"Aws","category":"Research","sources":["Infosecurity Magazine","Wiz Research"],"coverage":2,"cve_ids":[],"summary":"See how the Blue Agent investigated a multi-platform attack in minutes, following evidence across AWS and GitHub to uncover compromised credentials, stolen source code, and custom data exfiltration tooling","source":"Wiz Research","date_rel":"29 Sep","thumbnail":"https://www.datocms-assets.com/75231/1790604308-artboard-2-copy-3-2x.png","description":"","related":[{"title":"Amazon Bedrock AgentCore Flaws Could Expose AWS Credentials","link":"https://www.infosecurity-magazine.com/news/aws-agentcore-sdk-flaws-ai/","source":"Infosecurity Magazine","date_rel":"29 Sep"}]}],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-96349","vendor":"SiteSkite","product":"SiteSkite","severity":"CRITICAL","score":10.0,"description":"Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/plugin/siteskite/vulnerability/wordpress-siteskite-plugin-2-1-8-remote-code-execution-rce-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-96349"},{"id":"CVE-2026-55107","vendor":"elct9620","product":"kobako","severity":"CRITICAL","score":10.0,"description":"Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts (LLM-generated code, user formulas, student submissions, third-party plugins) in-process without giving the\u2026","cwe":"CWE-94","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/elct9620/kobako/commit/64f84700c81f44902bed9211318d5362f44987b3","https://github.com/elct9620/kobako/releases/tag/v0.9.1","https://github.com/elct9620/kobako/security/advisories/GHSA-7pwq-q9jf-539h"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-55107"},{"id":"CVE-2026-102455","vendor":"DigiWin","product":"EasyFlow .NET","severity":"CRITICAL","score":9.8,"description":"EasyFlow .NET developed by Digiwin has a Insecure Deserialization vulnerability. Unauthenticated remote attackers can execute arbitrary code on the server by sending maliciously crafted serialized content.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://www.twcert.org.tw/en/cp-139-11242-13f37-2.html","https://www.twcert.org.tw/tw/cp-132-11237-c9189-1.html"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-102455"},{"id":"CVE-2026-102458","vendor":"DigiWin","product":"EasyFlow .NET","severity":"CRITICAL","score":9.8,"description":"EasyFlow .NET developed by Digiwin has a Missing Authentication vulnerability. Unauthenticated remote attackers can obtain other users' plaintext passwords through a specific API.","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://www.twcert.org.tw/en/cp-139-11242-13f37-2.html","https://www.twcert.org.tw/tw/cp-132-11237-c9189-1.html"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-102458"},{"id":"CVE-2026-88920","vendor":"Apache","product":"Apache WSS4J","severity":"CRITICAL","score":9.8,"description":"An authentication bypass in the DOM security processor in Apache WSS4J allows unauthenticated remote attackers to forge authenticated SOAP messages via a crafted unsigned SAML sender-vouches assertion containing an attacker-controlled key.\n\u2026","cwe":"CWE-287","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://lists.apache.org/thread.html/grt43m3bgbzz0mk0cnho3rcybb1j01z9","http://www.openwall.com/lists/oss-security/2026/09/30/10"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-88920"},{"id":"CVE-2026-76504","vendor":"Cisco","product":"Catalyst Sd-Wan Manager","severity":"CRITICAL","score":9.8,"description":"A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.\r\n\r\nThis vulnerability is due\u2026","cwe":"CWE-177","kev":true,"kev_action":"Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA\u2019s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA\u2019s \u201cForensics Triage Requirements\u201d (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.","kev_due":"2026-10-03","kev_added":"2026-09-30","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-sdwan-webauth-xr8beuuU","https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-76504"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-76504"},{"id":"CVE-2026-96350","vendor":"Estatik","product":"Estatik","severity":"CRITICAL","score":9.8,"description":"Subscriber Privilege Escalation in Estatik <= 4.3.5 versions.","cwe":"CWE-266","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/plugin/estatik/vulnerability/wordpress-estatik-plugin-4-3-5-privilege-escalation-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-96350"},{"id":"CVE-2026-97248","vendor":"Booking Activities Team","product":"Booking Activities","severity":"CRITICAL","score":9.8,"description":"Unauthenticated PHP Object Injection in Booking Activities <= 1.18.7.1 versions.","cwe":"CWE-502","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/plugin/booking-activities/vulnerability/wordpress-booking-activities-plugin-1-18-7-1-php-object-injection-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-97248"},{"id":"CVE-2026-97274","vendor":"miniOrange","product":"OAuth Single Sign On \u2013 SSO (OAuth Client)","severity":"CRITICAL","score":9.8,"description":"Unauthenticated Bypass Vulnerability in OAuth Single Sign On \u2013 SSO (OAuth Client) <= 7.1.2 versions.","cwe":"CWE-290","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://patchstack.com/database/wordpress/plugin/miniorange-login-with-eve-online-google-facebook/vulnerability/wordpress-oauth-single-sign-on-sso-oauth-client-plugin-7-1-2-bypass-vulnerability-vulnerability?_s_id=cve"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-97274"},{"id":"CVE-2026-82307","vendor":"Dolusoft Software Technologies","product":"SOPLOG","severity":"CRITICAL","score":9.8,"description":"Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Dolusoft Software Technologies SOPLOG allows SQL Injection.\n\nThis issue affects SOPLOG: before Soplog 2026.9.4.1.","cwe":"CWE-89","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1224"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-82307"}],"vendor_spikes":[{"vendor":"NVIDIA","count":114,"critical_count":0},{"vendor":"Kiteworks","count":61,"critical_count":9},{"vendor":"WordPress","count":58,"critical_count":1},{"vendor":"Unknown","count":29,"critical_count":0},{"vendor":"JetBrains","count":28,"critical_count":0},{"vendor":"Apache","count":19,"critical_count":6},{"vendor":"Microsoft","count":18,"critical_count":1},{"vendor":"The Wikimedia Foundation","count":12,"critical_count":0},{"vendor":"py-pdf","count":8,"critical_count":0},{"vendor":"Pgpool Global Development Group","count":7,"critical_count":0}],"epss_risers":[],"developing_map":{},"trending_count":20,"new_cve_count":624,"has_news_data":true,"has_cve_data":true,"news_for_cve":{"CVE-2026-86950":{"anchor":"#dev-2","rank":2,"coverage":6},"CVE-2026-88771":{"anchor":"#dev-4","rank":4,"coverage":5},"CVE-2026-88772":{"anchor":"#dev-4","rank":4,"coverage":5},"CVE-2026-76504":{"anchor":"#dev-9","rank":9,"coverage":3}}}