Thursday, October 8, 2026 · generated · about 5 min read
Morning Brief
Patch today vendors with the most new CVEs today
- Brocade 59
- Cisco 15 critical 36
- WordPress 2 critical 27
- Splunk 1 critical 23
- Microsoft 1 critical 20
- ImageMagick 20
- Red Hat 15
- Unknown 1 critical 14
- AsyncHttpClient 13
- Apache 1 critical 9
Ranked by CVE count. Each vendor opens the CVE Feed filtered to that vendor and these dates.
Top developments ranked by cross-source trending
-
Image: Cisco Talos UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing
Cisco Talos identified an advanced persistent threat (APT) spear-phishing campaign against individuals affiliated with Taiwan research organizations. The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions to establish credibility. The phishing emails exhibited highly consistent structure, rhetoric, and personalization patterns, suggesting the threat actor likely used AI-assisted content generation to rapidly customize invitation lures for different targets while maintaining a common social engineering framework. Beyond traditional…
Also in Bleeping Computer The Register Security The Hacker News +3
-
U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks
The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM. The reward is for information leading to his identification or location, the news outlet NTD reported this week, citing a notice
Also in Bleeping Computer Graham Cluley Bleeping Computer +3
-
Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws
Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional
Also in Cisco Security Advisories Dark Reading Rapid7 Blog +2
-
Hackers Use GitHub-Hosted Poem to Control PoeLLM Malware Targeting AI Infrastructure
Hackers are using a poem hosted on GitHub to guide PoeLLM malware toward its command-and-control servers, turning exposed AI infrastructure into a growing cryptocurrency-mining botnet. The campaign targets internet-facing services, including LiteLLM and Ollama, while also affecting Gotenberg PDF converters and Gitea development servers. Active since at least April 2026, PoeLLM uses selected words in the poem to calculate its next control server address. Changing those words lets the attacker redirect infected machines without replacing the malware. Compromised servers also become scanners and…
Also in CCCS Alerts & Advisories The Register Security Palo Alto Unit 42
-
FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials
The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. "The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat
Also in SecurityWeek Bleeping Computer The Register Security +1
-
Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software
Also in Infosecurity Magazine CCCS Alerts & Advisories The Hacker News +1
-
MALFEX npm Malware Hides Executables in PNG Files to Infect Windows Developers
A long-running npm malware campaign called MALFEX is targeting Windows developers with remote access tools, data stealers, and hidden downloaders. The attack uses eight malicious packages and three separate delivery paths, including a Windows executable disguised as a PNG and an encrypted program hidden after real image data. The operator has published packages since August 2023. Across the eight malicious packages, npm recorded 40,767 downloads by October 1, 2026, including 3,017 during the previous week. Those numbers show package reach, not confirmed infections: downloads can include…
Also in Microsoft Security Microsoft Security Microsoft Security +1
CVE-2026-69436 ↗CVE-2026-69582 ↗CVE-2026-71343 ↗View on Security Feed
-
CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian products
Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589 , a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian assigned the vulnerability a CVSSv4 score of 9.3 . An unauthenticated remote attacker who knows a target file's exact name and path can access it within the application's web root; the vulnerability does not provide directory listing or enumeration…
Also in SANS Internet Storm Center Bleeping Computer watchTowr Labs
-
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a
Also in Tenable Blog
-
Amazon has an uncomfortably personal profile on you
Amazon’s “About You” page reveals what it thinks it knows about you—and you can’t simply switch it off. Dexerto reports that one shopper discovered her profile included the observation: “has flat buttocks” She suggested this might relate to a previous purchase of “butt scrunch leggings.” Whatever the connection, buying clothes doesn’t mean you expect the retailer to start describing your body. What is Amazon’s About You? About You is a page where customers can review and edit the personal details Amazon uses to shape their shopping recommendations. Amazon introduced it in May as a way to make…
Also in Bleeping Computer
Vulnerability watch what to look at, most urgent first
| Details | CVE | Product | Severity | CVSS | EPSS | KEV | Fix | In the news | |
|---|---|---|---|---|---|---|---|---|---|
| Highest scoring today 10new CVEs, highest CVSS first | |||||||||
| CVE-2026-102255 | SMA1000SonicWall | Critical | 10.0 | — | — | None linked | — | CVSS 10.0No fix linked | |
What it isA Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to… Attack
Exploitation
|
|||||||||
| CVE-2025-70518 | Critical | 10.0 | — | — | None linked | — | CVSS 10.0No fix linked | ||
What it isThe management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code … Attack
Exploitation
|
|||||||||
| CVE-2026-76482 | Cisco License On-PremCisco | Critical | 10.0 | — | — | None linked | — | CVSS 10.0No fix linked | |
What it isAs part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security re… Attack
Exploitation
|
|||||||||
| CVE-2026-105192 | LMCacheLMCache | Critical | 9.8 | 0.7% | — | None linked | — | EPSS 0.7%CVSS 9.8No fix linked | |
What it isLMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.… Attack
Exploitation
|
|||||||||
| CVE-2025-70521 | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | ||
What it isThe management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code … Attack
Exploitation
|
|||||||||
| CVE-2026-107204 | LMCacheLMCache | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isLMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the inject… Attack
Exploitation
|
|||||||||
| CVE-2026-62252 | homersipcapture | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isHomer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (st… Attack
Exploitation
|
|||||||||
| CVE-2026-62253 | homersipcapture | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isHomer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == ""`. The JWT secret defaults to an empty s… Attack
Exploitation
|
|||||||||
| CVE-2026-76455 | Cisco NX-OS SoftwareCisco | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isAs part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mu… Attack
Exploitation
|
|||||||||
| CVE-2026-76465 | Cisco NX-OS SoftwareCisco | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isA vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execut… Attack
Exploitation
|
|||||||||
Click a row, or press +, to expand it.EPSS is FIRST's estimated chance of exploitation in the next 30 days.Full CVE Feed
Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score. No AI writes any of this, and every number traces back to something already published on those two tools.
Top developments come from the Security Feed's cross-source trending detection. Vulnerability watch comes from the CVE Feed's daily NVD and CISA KEV sync.