{"date_iso":"2026-10-08","date_human":"Thursday, October 8, 2026","generated_utc":"2026-10-08 12:57 UTC","read_minutes":5,"patch_tuesday":false,"top_stories":[{"title":"UAT-11985: AI-assisted event lures delivering real-time Google AitM phishing","link":"https://blog.talosintelligence.com/uat-11985/","reason":"Google","category":"Threat Intel","sources":["Ars Technica Security","Bleeping Computer","CCCS Alerts & Advisories","Cisco Talos","Dark Reading","ESET WeLiveSecurity","Malwarebytes Labs","The Hacker News","The Register Security"],"coverage":9,"cve_ids":[],"summary":"Cisco Talos identified an advanced persistent threat (APT) spear-phishing campaign against individuals affiliated with Taiwan research organizations. The operation leveraged legitimate public event themes and\u2026","source":"Cisco Talos","date_rel":"2h ago","thumbnail":"https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/images/2026/10/threat_spotlight.jpg","description":"Cisco Talos identified an advanced persistent threat (APT) spear-phishing campaign against individuals affiliated with Taiwan research organizations. The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions to establish credibility. The phishing emails exhibited highly consistent structure, rhetoric, and personalization patterns, suggesting the threat actor likely used AI-assisted content generation to rapidly customize invitation lures for different targets while maintaining a common social engineering framework. Beyond traditional\u2026","related":[{"title":"Hackers hijack Google domains after breaching ccTLD registries","link":"https://www.bleepingcomputer.com/news/security/hackers-hijack-google-domains-after-breaching-cctld-registries/","source":"Bleeping Computer","date_rel":"16h ago"},{"title":"Attackers hijacked top-level domains, minted fake security certs for Google and other orgs","link":"https://www.theregister.com/security/2026/10/07/attackers-hijacked-top-level-domains-minted-fake-security-certs-for-google-and-other-orgs/5301718","source":"The Register Security","date_rel":"17h ago"},{"title":"Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains","link":"https://thehackernews.com/2026/10/attackers-hijack-gh-sl-and-as.html","source":"The Hacker News","date_rel":"18h ago"},{"title":"Google security advisory (AV26-1006)","link":"https://cyber.gc.ca/en/alerts-advisories/google-security-advisory-av26-1006","source":"CCCS Alerts & Advisories","date_rel":"23h ago"},{"title":"Update Chrome and ChromeOS to fix critical security issues","link":"https://www.malwarebytes.com/blog/bugs/2026/10/update-chrome-and-chromeos-to-fix-critical-security-issues","source":"Malwarebytes Labs","date_rel":"7 Oct"},{"title":"Inside a brand deal scam targeting YouTube creators","link":"https://www.welivesecurity.com/en/social-media/brand-deal-scam-targeting-youtube-creators/","source":"ESET WeLiveSecurity","date_rel":"7 Oct"}]},{"title":"U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks","link":"https://thehackernews.com/2026/10/us-offers-up-to-10-million-for-tips-on.html","reason":"Microsoft","category":"News","sources":["Bleeping Computer","CCCS Alerts & Advisories","Dark Reading","Graham Cluley","Huntress","The Hacker News","The Register Security"],"coverage":7,"cve_ids":[],"summary":"The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft\u2026","source":"The Hacker News","date_rel":"5h ago","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgFF6VpR3wVqISJUhvijTLl00h_uH1hImVFzJiqEyaGpgFqwRMQxT1VEbay1QbGWehkEmZXIa5rAvkjA5K326ZRtVY7OKq9luzZo1gRXX6jUPX3ajFp6gLfpFf6tQg6D5wBgsctILhw7Ma_dpUgswrwXUYTphyphenhyphenj2rT9nfz3zURxMwvma9EZvKYEzkqlIk/s1600/reward.jpg","description":"The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM. The reward is for information leading to his identification or location, the news outlet NTD reported this week, citing a notice","related":[{"title":"Microsoft Teams to get support for third-party deepfake detection tools","link":"https://www.bleepingcomputer.com/news/security/microsoft-teams-to-add-third-party-deepfake-detection-impersonation-protection/","source":"Bleeping Computer","date_rel":"48m ago"},{"title":"Smashing Security podcast #487: Clippy\u2019s crypto comeback","link":"https://grahamcluley.com/smashing-security-podcast-487/","source":"Graham Cluley","date_rel":"13h ago"},{"title":"Microsoft Outlook to block MSIX attachments starting November","link":"https://www.bleepingcomputer.com/news/microsoft/microsoft-outlook-to-block-msix-attachments-used-in-attacks/","source":"Bleeping Computer","date_rel":"21h ago"},{"title":"Phishing Campaign Abuses Microsoft Power BI to Deploy Rogue RMMs","link":"https://www.huntress.com/blog/screenconnect-power-bi","source":"Huntress","date_rel":"23h ago"},{"title":"'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates","link":"https://www.darkreading.com/application-security/bigdiskbuster-microsoft-defender-running-blocking-updates","source":"Dark Reading","date_rel":"6 Oct"},{"title":"Microsoft extends the Outlook naughty step with two more file types","link":"https://www.theregister.com/software/2026/10/06/microsoft-extends-the-outlook-naughty-step-with-two-more-file-types/5301350","source":"The Register Security","date_rel":"6 Oct"}]},{"title":"Anthropic Expands Claude Access for Vetted Cyber Teams as Glasswing Finds 129,000 Flaws","link":"https://thehackernews.com/2026/10/anthropic-expands-claude-access-for.html","reason":"Teams","category":"News","sources":["Cisco Security Advisories","Dark Reading","Rapid7 Blog","The Hacker News","Wiz Research"],"coverage":5,"cve_ids":[],"summary":"Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company\u2026","source":"The Hacker News","date_rel":"7 Oct","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimg1tAvNh5aMWuNTZXjb4kKfxIQ0iWkuo2bCznozA8oz2Fm36WzbPnBI1bBDX5Mc3hpyOMIcjS_fcdYzzpQnrtUkex17u0_fn7r3bgcRYEN4o2hoGf4vlw5hQKEgcDd2VoVT2P9unKzsVOlly1QFlu6WfySqGPZ4Pf7xrZXaL4pEy1vrhWQBHR7SiqHHvf/s1600/claude-flaws.jpg","description":"Anthropic on Tuesday said it's expanding a program that allows vetted cybersecurity professionals to test its advanced artificial intelligence (AI) models with reduced safeguards and blocking classifiers, as the company claimed its Project Glasswing initiative uncovered at least 129,000 verified software vulnerabilities between April and July 2026. The company said it also found an additional","related":[{"title":"Cisco Meraki Security Hardening Release: October 2026","link":"https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-meraki-os-drbEX9GH?vs_f=Cisco%20Security%20Advisory%26vs_cat=Security%20Intelligence%26vs_type=RSS%26vs_p=Cisco%20Meraki%20Security%20Hardening%20Release:%20October%202026%26vs_k=1","source":"Cisco Security Advisories","date_rel":"12h ago"},{"title":"IANS' Kakolowski: How AI Is Reshaping CISO Budgets & Security Teams","link":"https://www.darkreading.com/cybersecurity-operations/ai-reshaping-ciso-budgets-security-teams","source":"Dark Reading","date_rel":"6 Oct"},{"title":"Securing Agent-to-Agent Communication: The Next Identity Frontier","link":"https://www.rapid7.com/blog/post/ai-securing-agent-to-agent-communication-next-identity-frontier","source":"Rapid7 Blog","date_rel":"6 Oct"},{"title":"What\u2019s New in Wiz Service Catalog: Smarter Discovery, Governance, and Service-Level Context","link":"https://www.wiz.io/blog/wiz-service-catalog-updates","source":"Wiz Research","date_rel":"5 Oct"},{"title":"Need for Speed: AI-Driven Attacks Are Changing Security Strategies","link":"https://www.darkreading.com/cyber-risk/ai-attacks-security-strategies","source":"Dark Reading","date_rel":"5 Oct"}]},{"title":"Hackers Use GitHub-Hosted Poem to Control PoeLLM Malware Targeting AI Infrastructure","link":"https://cybersecuritynews.com/hackers-use-github-hosted-poem/","reason":"Github","category":"News","sources":["CCCS Alerts & Advisories","Cyber Security News","Palo Alto Unit 42","The Register Security"],"coverage":4,"cve_ids":[],"summary":"Hackers are using a poem hosted on GitHub to guide PoeLLM malware toward its command-and-control servers, turning exposed AI infrastructure into a growing cryptocurrency-mining botnet. The campaign targets\u2026","source":"Cyber Security News","date_rel":"3h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/Hackers-Use-GitHub-Hosted-Poem-to-Control-PoeLLM-Malware-Targeting-AI-Infrastructure.webp","description":"Hackers are using a poem hosted on GitHub to guide PoeLLM malware toward its command-and-control servers, turning exposed AI infrastructure into a growing cryptocurrency-mining botnet. The campaign targets internet-facing services, including LiteLLM and Ollama, while also affecting Gotenberg PDF converters and Gitea development servers. Active since at least April 2026, PoeLLM uses selected words in the poem to calculate its next control server address. Changing those words lets the attacker redirect infected machines without replacing the malware. Compromised servers also become scanners and\u2026","related":[{"title":"GitHub security advisory (AV26-1007)","link":"https://cyber.gc.ca/en/alerts-advisories/github-security-advisory-av26-1007","source":"CCCS Alerts & Advisories","date_rel":"22h ago"},{"title":"Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets","link":"https://www.theregister.com/ai-and-ml/2026/10/06/zombie-instructions-on-carefully-constructed-web-pages-could-trick-github-copilot-cli-into-sharing-secrets/5301206","source":"The Register Security","date_rel":"6 Oct"},{"title":"Blinder Tunnel Campaign Targets Iraqi Infrastructure","link":"https://unit42.paloaltonetworks.com/blinder-tunnel-targets-critical-infrastructure/","source":"Palo Alto Unit 42","date_rel":"6 Oct"}]},{"title":"FBI Warns FortiBleed Remains Active After Amassing 86,644 Fortinet Device Credentials","link":"https://thehackernews.com/2026/10/fbi-warns-fortibleed-remains-active.html","reason":"Fortinet","category":"News","sources":["Bleeping Computer","CyberScoop","SecurityWeek","The Hacker News","The Register Security"],"coverage":5,"cve_ids":[],"summary":"The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate\u2026","source":"The Hacker News","date_rel":"7 Oct","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQZeKQIcHTVLgqnHpZYN73YclFawl51QxpykrKEb97sAJjA8qtN7FaUJaS0jLMeSS29cTB0nR_yFzsITX_e5SI8Xa8BfM1LDOGsEEEpDmVC8YNqOcEYEuep1UbHovyLlxrwRmYZ3FrbaaKq9eKwICiUTkkPleIibOHdWnbV5cpwYPCrHQasrTxVFA9seQ-/s1600/forti-admin.jpg","description":"The U.S. Federal Bureau of Investigation (FBI) and Secret Service (USSS) on Tuesday warned that the FortiBleed credential harvesting campaign remains an active threat aimed at internet-facing Fortinet FortiGate firewalls and secure socket layer (SSL) virtual private network (VPN) gateways. \"The campaign exploits reused or leaked credentials and legacy SHA-256 password storage, enabling threat","related":[{"title":"FortiBleed Attackers Locking Victims Out of Fortinet Devices","link":"https://www.securityweek.com/fortibleed-attackers-locking-victims-out-of-fortinet-devices/","source":"SecurityWeek","date_rel":"5h ago"},{"title":"FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins","link":"https://www.bleepingcomputer.com/news/security/fbi-ongoing-fortibleed-attacks-lock-out-fortigate-vpn-admins/","source":"Bleeping Computer","date_rel":"15h ago"},{"title":"FortiBleed still a bleeding nuisance as FBI confirms ongoing attacks","link":"https://www.theregister.com/security/2026/10/07/fortibleed-still-a-bleeding-nuisance-as-fbi-confirms-ongoing-attacks/5301585","source":"The Register Security","date_rel":"7 Oct"},{"title":"Alert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacks","link":"https://cyberscoop.com/fortibleed-fortinet-vpn-ransomware-fbi-warning/","source":"CyberScoop","date_rel":"6 Oct"}]},{"title":"Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details","link":"https://thehackernews.com/2026/10/atlassian-data-center-flaw-draws.html","reason":"Atlassian","category":"News","sources":["CCCS Alerts & Advisories","Infosecurity Magazine","The Hacker News","The Register Security"],"coverage":4,"cve_ids":[],"summary":"Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw\u2026","source":"The Hacker News","date_rel":"7 Oct","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEityRbZfy1N9Y0SuqWl7yeWTYMjeirrTbDx719fM65Be6yXOt2Zl0YweAi0hAfswNzV_LrHa4eFCpcCemC3FNwxZve4bPkSelQiRnCdXpZofAnI7Si96nULBV6i25jgFaZkEY1T3LuPRhj6QzTSsWHZtLuoH1zXlLKZN3WwSiKS7QoY_Zug0CtaaCGozT6N/s1600/jira-attack.jpg","description":"Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software","related":[{"title":"Critical Flaw in Multiple Atlassian Products Exploited in the Wild","link":"https://www.infosecurity-magazine.com/news/critical-vulnerability-atlassian/","source":"Infosecurity Magazine","date_rel":"2h ago"},{"title":"Atlassian security advisory (AV26-1002) - Update 1","link":"https://cyber.gc.ca/en/alerts-advisories/atlassian-security-advisory-av26-1002","source":"CCCS Alerts & Advisories","date_rel":"23h ago"},{"title":"Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products","link":"https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html","source":"The Hacker News","date_rel":"6 Oct"},{"title":"Atlassian warns of critical file access flaw in its datacenter products","link":"https://www.theregister.com/security/2026/10/06/atlassian-warns-of-critical-file-access-flaw-in-its-datacenter-products/5301284","source":"The Register Security","date_rel":"6 Oct"}]},{"title":"MALFEX npm Malware Hides Executables in PNG Files to Infect Windows Developers","link":"https://cybersecuritynews.com/malfex-npm-malware/","reason":"Windows","category":"News","sources":["Cyber Security News","Microsoft Security","The Hacker News"],"coverage":3,"cve_ids":["CVE-2026-69436","CVE-2026-69582","CVE-2026-71343"],"summary":"A long-running npm malware campaign called MALFEX is targeting Windows developers with remote access tools, data stealers, and hidden downloaders. The attack uses eight malicious packages and three separate delivery\u2026","source":"Cyber Security News","date_rel":"5h ago","thumbnail":"https://cybersecuritynews.com/wp-content/uploads/2026/10/MALFEX-npm-Malware-Hides-Executables-in-PNG-Files-to-Infect-Windows-Developers.webp","description":"A long-running npm malware campaign called MALFEX is targeting Windows developers with remote access tools, data stealers, and hidden downloaders. The attack uses eight malicious packages and three separate delivery paths, including a Windows executable disguised as a PNG and an encrypted program hidden after real image data. The operator has published packages since August 2023. Across the eight malicious packages, npm recorded 40,767 downloads by October 1, 2026, including 3,017 during the previous week. Those numbers show package reach, not confirmed infections: downloads can include\u2026","related":[{"title":"CVE-2026-69436 Windows State Repository Service Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69436","source":"Microsoft Security","date_rel":"22h ago"},{"title":"CVE-2026-69582 Windows Volume Manager Extension Driver Elevation of Privilege Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69582","source":"Microsoft Security","date_rel":"6 Oct"},{"title":"CVE-2026-71343 Windows Remote Access Connection Manager Remote Code Execution Vulnerability","link":"https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-71343","source":"Microsoft Security","date_rel":"6 Oct"},{"title":"ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits","link":"https://thehackernews.com/2026/10/clickfix-smuggles-payloads-through.html","source":"The Hacker News","date_rel":"6 Oct"}]},{"title":"CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian products","link":"https://www.rapid7.com/blog/post/etr-cve-2026-21589-critical-unauthenticated-arbitrary-file-access-in-atlassian-products","reason":"CVE-2026-21589","category":"Research","sources":["Bleeping Computer","Rapid7 Blog","SANS Internet Storm Center","watchTowr Labs"],"coverage":4,"cve_ids":["CVE-2026-21589"],"summary":"Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589 , a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira\u2026","source":"Rapid7 Blog","date_rel":"7 Oct","thumbnail":"https://images.contentstack.io/v3/assets/blte4f029e766e6b253/blt65a432ba319f4043/6846abddaf18306debe6cf4d/ETR.webp","description":"Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589 , a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian assigned the vulnerability a CVSSv4 score of 9.3 . An unauthenticated remote attacker who knows a target file's exact name and path can access it within the application's web root; the vulnerability does not provide directory listing or enumeration\u2026","related":[{"title":"Scans for Atlassian vulnerablity (CVE-2026-21589), (Wed, Oct 7th)","link":"https://isc.sans.edu/diary/rss/33406","source":"SANS Internet Storm Center","date_rel":"21h ago"},{"title":"Hackers exploit critical Atlassian flaw after public PoC release","link":"https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-atlassian-flaw-after-public-poc-release/","source":"Bleeping Computer","date_rel":"7 Oct"},{"title":"You Won\u2019t Hear About These, Even In Myths (Atlassian Jira, Confluence (and more) Pre-Auth Arbitrary File Read CVE-2026-21589)","link":"https://labs.watchtowr.com/you-wont-hear-about-these-even-in-myths-atlassian-jira-confluence-and-more-pre-auth-arbitrary-file-read-cve-2026-21589/","source":"watchTowr Labs","date_rel":"6 Oct"}]},{"title":"Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes","link":"https://thehackernews.com/2026/10/microsoft-exchange-flaw-lets.html","reason":"Exchange","category":"News","sources":["Tenable Blog","The Hacker News"],"coverage":2,"cve_ids":[],"summary":"Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked\u2026","source":"The Hacker News","date_rel":"5 Oct","thumbnail":"https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBNa12GUjRngANug2kbws6i9X_HPN2PRVbOcxr7GtaXMKq9PloaCTD7DuYC8zZIcrg5Wa-F5pDv9y-00EMX4QWvovMz-ZWK5vNZ-gkIdEA7UiZQ1SqBCZof411VOQt6nQrvZCYxZpmzPA3hUeFia9KVP45Q1J1OPkiIH_Fhy5hoiOo9z6eYw1H16RgvKs5/s1600/ms-emails.jpg","description":"Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. \"Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a","related":[{"title":"Inside the Exchange Inspector: How Tenable uses OpenAI GPT cyber models to review open-source AI agents","link":"https://www.tenable.com/blog/tenable-openai-security-vetting-open-source-ai-agents-exchange-inspector","source":"Tenable Blog","date_rel":"6m ago"}]},{"title":"Amazon has an uncomfortably personal profile on you","link":"https://www.malwarebytes.com/blog/news/2026/10/amazon-has-an-uncomfortably-personal-profile-on-you-check-yours-now","reason":"Amazon","category":"Threat Intel","sources":["Bleeping Computer","Malwarebytes Labs"],"coverage":2,"cve_ids":[],"summary":"Amazon\u2019s \u201cAbout You\u201d page reveals what it thinks it knows about you\u2014and you can\u2019t simply switch it off. Dexerto reports that one shopper discovered her profile included the observation: \u201chas flat buttocks\u201d She suggested\u2026","source":"Malwarebytes Labs","date_rel":"27m ago","thumbnail":"","description":"Amazon\u2019s \u201cAbout You\u201d page reveals what it thinks it knows about you\u2014and you can\u2019t simply switch it off. Dexerto reports that one shopper discovered her profile included the observation: \u201chas flat buttocks\u201d She suggested this might relate to a previous purchase of \u201cbutt scrunch leggings.\u201d Whatever the connection, buying clothes doesn\u2019t mean you expect the retailer to start describing your body. What is Amazon\u2019s About You? About You is a page where customers can review and edit the personal details Amazon uses to shape their shopping recommendations. Amazon introduced it in May as a way to make\u2026","related":[{"title":"Musician sent to prison for $10 million streaming fraud using AI bots","link":"https://www.bleepingcomputer.com/news/security/musician-gets-18-months-in-prison-for-10-million-streaming-fraud-using-ai-bots/","source":"Bleeping Computer","date_rel":"7 Oct"}]}],"worth_reading":[],"kev_watch":[],"vuln_watch":[{"id":"CVE-2026-102255","vendor":"SonicWall","product":"SMA1000","severity":"CRITICAL","score":10.0,"description":"A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to\u2026","cwe":"CWE-441","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0017"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-102255"},{"id":"CVE-2025-70518","vendor":"Google","product":"","severity":"CRITICAL","score":10.0,"description":"The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code \u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["http://download.fanvil.com/Firmware/Release/X7A/","https://www.darkpoint.ca/blog/2026/02/27/Fanvil-x7a-PA2S-Vulnerability-Disclosure","https://www.fanvil.com/products/p1/x/20210921/5043.html"],"url":"https://cve.blackmesa.ca/?q=CVE-2025-70518"},{"id":"CVE-2026-76482","vendor":"Cisco","product":"Cisco License On-Prem","severity":"CRITICAL","score":10.0,"description":"As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security re\u2026","cwe":"CWE-347","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-ssm-Ph77wdhf"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-76482"},{"id":"CVE-2026-105192","vendor":"LMCache","product":"LMCache","severity":"CRITICAL","score":9.8,"description":"LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack. Extension code 1 is passed to DeviceIPCWrapper.\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":0.0067,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/LMCache/LMCache","https://github.com/LMCache/LMCache/blob/v0.3.9/lmcache/v1/multiprocess/custom_types.py","https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/platform/base/ipc_wrapper.py"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-105192"},{"id":"CVE-2025-70521","vendor":"Google","product":"","severity":"CRITICAL","score":9.8,"description":"The management portal's diagnostic ping tool of Fanvil x7a firmware version 2.6.0.1182 does not handle user supplied input securely. The lack of secure user input handling allows any unauthenticated attacker to inject commands and run code \u2026","cwe":"CWE-77","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["http://download.fanvil.com/Firmware/Release/PA2S/","https://www.darkpoint.ca/blog/2026/02/27/Fanvil-x7a-PA2S-Vulnerability-Disclosure","https://www.fanvil.com/products/p5/wulianwangwangguan_1/20210921/5035.html"],"url":"https://cve.blackmesa.ca/?q=CVE-2025-70521"},{"id":"CVE-2026-107204","vendor":"LMCache","product":"LMCache","severity":"CRITICAL","score":9.8,"description":"LMCache through 0.5.5 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute Python code by posting scripts to the /run_script endpoint. Attackers can recover real builtins through the inject\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/LMCache/LMCache","https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/internal_api_server/common/run_script_api.py#L54-L76","https://github.com/LMCache/LMCache/blob/v0.5.5/lmcache/v1/multiprocess/http_apis/common_api.py#L41-L46"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-107204"},{"id":"CVE-2026-62252","vendor":"sipcapture","product":"homer","severity":"CRITICAL","score":9.8,"description":"Homer is open source telecom observability software. Prior to version 11.0.283, on every fresh Homer deployment using internal authentication, the bootstrap process automatically creates an `admin` account with the password `sipcapture` (st\u2026","cwe":"CWE-798","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/sipcapture/homer/commit/b2e942031ff8cd7435a244ebef306ee97d16b809","https://github.com/sipcapture/homer/pull/838","https://github.com/sipcapture/homer/releases/tag/11.0.283"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-62252"},{"id":"CVE-2026-62253","vendor":"sipcapture","product":"homer","severity":"CRITICAL","score":9.8,"description":"Homer is open source telecom observability software. Prior to version 11.0.283, both JWT middleware functions (`JWTMiddleware` and `JWTMiddlewareV4`) immediately return `next(c)` when `jwtSecret == \"\"`. The JWT secret defaults to an empty s\u2026","cwe":"CWE-306","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://github.com/sipcapture/homer/commit/5e90809657c9df321db191a69c6050f873f5646b","https://github.com/sipcapture/homer/pull/839","https://github.com/sipcapture/homer/releases/tag/11.0.283"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-62253"},{"id":"CVE-2026-76455","vendor":"Cisco","product":"Cisco NX-OS Software","severity":"CRITICAL","score":9.8,"description":"As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses mu\u2026","cwe":"CWE-284","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hardening-nxosw1-cWzSbtR"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-76455"},{"id":"CVE-2026-76465","vendor":"Cisco","product":"Cisco NX-OS Software","severity":"CRITICAL","score":9.8,"description":"A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execut\u2026","cwe":"CWE-590","kev":false,"kev_action":"","kev_due":"","kev_added":"","epss":null,"cvss_vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","fix":false,"fix_url":"","refs":["https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-moam-rce-uBTzYV7"],"url":"https://cve.blackmesa.ca/?q=CVE-2026-76465"}],"vendor_spikes":[{"vendor":"Brocade","count":59,"critical_count":0},{"vendor":"Cisco","count":36,"critical_count":15},{"vendor":"WordPress","count":27,"critical_count":2},{"vendor":"Splunk","count":23,"critical_count":1},{"vendor":"Microsoft","count":20,"critical_count":1},{"vendor":"ImageMagick","count":20,"critical_count":0},{"vendor":"Red Hat","count":15,"critical_count":0},{"vendor":"Unknown","count":14,"critical_count":1},{"vendor":"AsyncHttpClient","count":13,"critical_count":0},{"vendor":"Apache","count":9,"critical_count":1}],"epss_risers":[],"developing_map":{},"trending_count":19,"new_cve_count":373,"has_news_data":true,"has_cve_data":true,"news_for_cve":{"CVE-2026-69436":{"anchor":"#dev-7","rank":7,"coverage":3},"CVE-2026-69582":{"anchor":"#dev-7","rank":7,"coverage":3},"CVE-2026-71343":{"anchor":"#dev-7","rank":7,"coverage":3},"CVE-2026-21589":{"anchor":"#dev-8","rank":8,"coverage":4}}}