Friday, October 9, 2026 · generated · about 6 min read
Morning Brief
Patch today vendors with the most new CVEs today
- IBM 17 critical 93
- Microsoft 7 critical 39
- Progressive Robot Ltd 17
- Unknown 1 critical 16
- MongoDB 15
- WordPress 13
- ImageMagick 13
- banq 13
- Go standard library 12
- pydantic 10
Ranked by CVE count. Each vendor opens the CVE Feed filtered to that vendor and these dates.
Top developments ranked by cross-source trending
-
Image: The Hacker News Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own
Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas Labs $300,000, the contest's top prize, and made the team the overall winner. Trend Micro's Zero
Also in SecurityWeek SecurityWeek The Record +3
-
Microsoft Says PKI, HSMs and Security Appliances Must Prepare for Post-Quantum Authentication
Microsoft is urging organizations to prepare their certificate systems for post-quantum authentication, warning that public key infrastructure (PKI), hardware security modules (HSMs), and security appliances need testing before deployment. Its October 8 guidance says the shift will affect applications, devices, certificate chains, and the processes that keep digital trust working. The message goes beyond protecting encrypted traffic. While many quantum security plans focus on attackers collecting data now to decrypt later, authentication depends on certificates and private keys being issued…
Also in Bleeping Computer Bleeping Computer The Hacker News +3
-
VirusTotal Adds Scanning for Public IPv4 Space to Expose C2 Servers and Malware Infrastructure
VirusTotal has added daily scanning of the public IPv4 space, giving security teams a new way to find command-and-control (C2) servers and track malware infrastructure. Announced on October 8, 2026, the update records exposed services, port activity, banners, and server fingerprints alongside existing threat intelligence. The change helps researchers look beyond an IP address’s detection score. Earlier reports showed hosting details, passive DNS records, and files that contacted an address. The new data shows what a server exposes now, helping analysts find related hosts that have no malware…
Also in Cisco Security Advisories Elastic Security Labs The Hacker News +2
-
Low-cost Android phones ship with residential proxy malware
A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies.
Also in SecurityWeek Malwarebytes Labs CCCS Alerts & Advisories
-
Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets
GitHub Copilot CLI may reveal developer secrets if it comes across instructions that tell it to do so, depending on the underlying model. The coding agent tool was flagged earlier this year for being susceptible to indirect prompt injection. That's when a model ingests text from a source other than the user that directs it to take some action outside the scope of its intended function. This is more of the same, with a twist. According to security researchers at Adversa AI, GitHub Copilot CLI suffers from the same vulnerability identified in Grok two months ago: Cryptographic Context Injection…
-
Cisco warns of critical flaws allowing Nexus switch takeover
Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches.
Also in SecurityWeek CCCS Alerts & Advisories
-
Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer
Threat actors are exploiting AhsayCBS flaws, including CVE-2026-105133 and CVE-2026-105134, to deploy webshells and XMRig cryptominers. Update to 10.3.4 and restrict access now.
Also in SecurityWeek
-
Let’s Encrypt Cuts TLS Certificate Lifetimes From 90 to 64 Days Starting February 2027
Let’s Encrypt will cut its default TLS certificate lifetime from 90 days to 64 days on February 10, 2027, giving website operators less time between renewals. The change applies to certificates issued or renewed from that date, while subscribers can still choose shorter certificate profiles offering 45 days or roughly six days. Let’s Encrypt Certificate Lifetime According to the October 7 announcement published by Let’s Encrypt , the nonprofit certificate authority confirmed the schedule. Existing certificates will remain valid until their normal expiry dates, and Let’s Encrypt will not…
Also in Ars Technica Security
-
Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software
-
Citrix gives NetScaler admins another critical reason to patch
Citrix is urging customers to patch another critical NetScaler vulnerability after weeks of disclosures involving actively exploited flaws. CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution (RCE) or denial of service (DoS). It carries a CVSS v4.0 score of 9.5. The affected configurations depend on the software version. Older builds are vulnerable when configured as a SAML (Security Assertion Markup Language) service provider (SP) or identity provider (IdP); some more recent builds are affected only in the identity provider configuration…
Also in SecurityWeek
Vulnerability watch what to look at, most urgent first
| Details | CVE | Product | Severity | CVSS | EPSS | KEV | Fix | In the news | |
|---|---|---|---|---|---|---|---|---|---|
| Highest scoring today 10new CVEs, highest CVSS first | |||||||||
| CVE-2026-96207 | Microsoft Partner CenterMicrosoft | Critical | 10.0 | — | — | None linked | — | CVSS 10.0No fix linked | |
What it isImproper certificate validation in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network. Attack
Exploitation
|
|||||||||
| CVE-2026-106126 | Tenable Identity Exposure (SaaS)Microsoft | Critical | 9.9 | — | — | None linked | — | CVSS 9.9No fix linked | |
What it isA command injection vulnerability in the Active Directory Events Listener of Tenable Identity Exposure (SaaS) allows an authenticated, low-privileged attacker to execute arbitrary commands as SYSTEM on the PDCe. Attack
Exploitation
|
|||||||||
| CVE-2026-94510 | Microsoft BookingsMicrosoft | Critical | 9.9 | — | — | None linked | — | CVSS 9.9No fix linked | |
What it isAuthorization bypass through user-controlled key in Microsoft Bookings allows an unauthorized attacker to elevate privileges over a network. Attack
Exploitation
|
|||||||||
| CVE-2026-105110 | InnboxIskratel | Critical | 9.8 | 3% | — | None linked | — | EPSS 3%CVSS 9.8No fix linked | |
What it isOS Command Injection in the login.xgi CGI endpoint in Iskratel Innbox GPON ONT devices allows an unauthenticated remote attacker to execute arbitrary commands as root via the CLI parameter. Attack
Exploitation
|
|||||||||
| CVE-2026-92555 | AKINSOFT WOLVOX Control PanelAKIN Software Computer Import-Export Industry and Trade Co. Ltd. | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isInsertion of sensitive information into sent data vulnerability in AKIN Software Computer Import-Export Industry and Trade Co. Ltd. AKINSOFT WOLVOX Control Panel allows Pull Data from System Resources. This issue affects AKINSOFT WOLVOX Co… Attack
Exploitation
|
|||||||||
| CVE-2026-16340 | DataPower Gateway 10.6CDIBM | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isIBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write in the RFC2047 encoded-… Attack
Exploitation
|
|||||||||
| CVE-2026-14991 | DataPower Gateway 10.6CDIBM | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isIBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffe… Attack
Exploitation
|
|||||||||
| CVE-2026-15762 | DataPower Gateway 10.6CDIBM | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isIBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to execute arbitrary code due to an out-of-bounds write. Attack
Exploitation
|
|||||||||
| CVE-2026-14269 | DataPower Gateway 10.6CDIBM | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isIBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. An unauthenticated remote … Attack
Exploitation
|
|||||||||
| CVE-2026-14502 | DataPower Gateway 10.6CDIBM | Critical | 9.8 | — | — | None linked | — | CVSS 9.8No fix linked | |
What it isIBM DataPower Gateway 10.5.0.0 through 10.5.0.22, 10.6.1 through 10.6.6, 10.6.0.0 through 10.6.0.10, and 11.0.0.0 through 11.0.0.2 could allow a remote attacker to obtain administrative access due to failure to reject empty passwords during… Attack
Exploitation
|
|||||||||
Click a row, or press +, to expand it.EPSS is FIRST's estimated chance of exploitation in the next 30 days.Full CVE Feed
Worth reading quieter, still worth your time
-
Inside the Exchange Inspector: How Tenable uses OpenAI GPT cyber models to review open-source AI agents
Community-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here’s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange. Three tools have already passed. Key takeaways Every Inspector-vetted listing clears three gates: an automated check, a frontier model assessment, and human verification. Tenable uses Tenable One AI Exposure to screen for prompt injection and exposed secrets, and OpenAI GPT Cyber models to assess the code and threat model. Tenable security researchers then verify runtime behavior in a clean…
Also in Bleeping Computer
-
CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian products
Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589 , a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian assigned the vulnerability a CVSSv4 score of 9.3 . An unauthenticated remote attacker who knows a target file's exact name and path can access it within the application's web root; the vulnerability does not provide directory listing or enumeration…
Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score. No AI writes any of this, and every number traces back to something already published on those two tools.
Top developments come from the Security Feed's cross-source trending detection. Vulnerability watch comes from the CVE Feed's daily NVD and CISA KEV sync.