Skip to content
BLACKMESA.CA Brief

Thursday, October 8, 2026 · generated · about 5 min read

Morning Brief

Patch today vendors with the most new CVEs today

Ranked by CVE count. Each vendor opens the CVE Feed filtered to that vendor and these dates.

Top developments ranked by cross-source trending

  1. Image: Cisco Talos

    UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing

    Threat Intel Cisco Talos2h ago9 sources

    Cisco Talos identified an advanced persistent threat (APT) spear-phishing campaign against individuals affiliated with Taiwan research organizations. The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions to establish credibility. The phishing emails exhibited highly consistent structure, rhetoric, and personalization patterns, suggesting the threat actor likely used AI-assisted content generation to rapidly customize invitation lures for different targets while maintaining a common social engineering framework. Beyond traditional…

    Also in Bleeping Computer The Register Security The Hacker News +3

    View on Security Feed

  2. U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks

    News The Hacker News5h ago7 sources

    The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM. The reward is for information leading to his identification or location, the news outlet NTD reported this week, citing a notice

    Also in Bleeping Computer Graham Cluley Bleeping Computer +3

    View on Security Feed

  3. Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws

    News The Hacker News7 Oct5 sources

    Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional

    Also in Cisco Security Advisories Dark Reading Rapid7 Blog +2

    View on Security Feed

  4. Hackers Use GitHub-Hosted Poem to Control PoeLLM Malware Targeting AI Infrastructure

    News Cyber Security News3h ago4 sources

    Hackers are using a poem hosted on GitHub to guide PoeLLM malware toward its command-and-control servers, turning exposed AI infrastructure into a growing cryptocurrency-mining botnet. The campaign targets internet-facing services, including LiteLLM and Ollama, while also affecting Gotenberg PDF converters and Gitea development servers. Active since at least April 2026, PoeLLM uses selected words in the poem to calculate its next control server address. Changing those words lets the attacker redirect infected machines without replacing the malware. Compromised servers also become scanners and…

    Also in CCCS Alerts & Advisories The Register Security Palo Alto Unit 42

    View on Security Feed

  5. FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials

    News The Hacker News7 Oct5 sources

    The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat

    Also in SecurityWeek Bleeping Computer The Register Security +1

    View on Security Feed

  6. Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

    News The Hacker News7 Oct4 sources

    Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software

    Also in Infosecurity Magazine CCCS Alerts & Advisories The Hacker News +1

    View on Security Feed

  7. MALFEX npm Malware Hides Executables in PNG Files to Infect Windows Developers

    News Cyber Security News5h ago3 sources

    A long-running npm malware campaign called MALFEX is targeting Windows developers with remote access tools, data stealers, and hidden downloaders. The attack uses eight malicious packages and three separate delivery paths, including a Windows executable disguised as a PNG and an encrypted program hidden after real image data. The operator has published packages since August 2023. Across the eight malicious packages, npm recorded 40,767 downloads by October 1, 2026, including 3,017 during the previous week. Those numbers show package reach, not confirmed infections: downloads can include…

    Also in Microsoft Security Microsoft Security Microsoft Security +1

    CVE-2026-69436 ↗CVE-2026-69582 ↗CVE-2026-71343 ↗View on Security Feed

  8. CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian products

    Research Rapid7 Blog7 Oct4 sources

    Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589 , a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian assigned the vulnerability a CVSSv4 score of 9.3 . An unauthenticated remote attacker who knows a target file's exact name and path can access it within the application's web root; the vulnerability does not provide directory listing or enumeration…

    Also in SANS Internet Storm Center Bleeping Computer watchTowr Labs

    CVE-2026-21589 ↗View on Security Feed

  9. Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

    News The Hacker News5 Oct2 sources

    Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a

    Also in Tenable Blog

    View on Security Feed

  10. Amazon has an uncomfortably personal profile on you

    Threat Intel Malwarebytes Labs27m ago2 sources

    Amazon’s “About You” page reveals what it thinks it knows about you—and you can’t simply switch it off. Dexerto reports that one shopper discovered her profile included the observation: “has flat buttocks” She suggested this might relate to a previous purchase of “butt scrunch leggings.” Whatever the connection, buying clothes doesn’t mean you expect the retailer to start describing your body. What is Amazon’s About You? About You is a page where customers can review and edit the personal details Amazon uses to shape their shopping recommendations. Amazon introduced it in May as a way to make…

    Also in Bleeping Computer

    View on Security Feed

Vulnerability watch what to look at, most urgent first

Details CVEProductSeverity CVSSEPSS KEVFixIn the news
Highest scoring today 10new CVEs, highest CVSS first
CVE-2026-102255 SMA1000SonicWall Critical 10.0 — — None linked — CVSS 10.0No fix linked
CVE-2025-70518 Google Critical 10.0 — — None linked — CVSS 10.0No fix linked
CVE-2026-76482 Cisco License On-PremCisco Critical 10.0 — — None linked — CVSS 10.0No fix linked
CVE-2026-105192 LMCacheLMCache Critical 9.8 0.7% — None linked — EPSS 0.7%CVSS 9.8No fix linked
CVE-2025-70521 Google Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-107204 LMCacheLMCache Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-62252 homersipcapture Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-62253 homersipcapture Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-76455 Cisco NX-OS SoftwareCisco Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-76465 Cisco NX-OS SoftwareCisco Critical 9.8 — — None linked — CVSS 9.8No fix linked

Click a row, or press +, to expand it.EPSS is FIRST's estimated chance of exploitation in the next 30 days.Full CVE Feed

Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score. No AI writes any of this, and every number traces back to something already published on those two tools.

Top developments come from the Security Feed's cross-source trending detection. Vulnerability watch comes from the CVE Feed's daily NVD and CISA KEV sync.