Skip to content
BLACKMESA.CA Brief

Friday, October 9, 2026 · generated · about 6 min read

Morning Brief

Patch today vendors with the most new CVEs today

Ranked by CVE count. Each vendor opens the CVE Feed filtered to that vendor and these dates.

Top developments ranked by cross-source trending

  1. Image: The Hacker News

    Three Teams Demonstrate Remote Hacks of Fully Patched Google Pixel 10 at Pwn2Own

    News The Hacker News4h ago11 sources

    Three research teams broke into Google's Pixel 10 on October 8 at Pwn2Own Ireland, a hacking contest in Cork whose rules require every target to be fully patched. The contest pays researchers to show working exploits and passes the flaws to the vendors. One of the three Pixel exploits earned Ikotas Labs $300,000, the contest's top prize, and made the team the overall winner. Trend Micro's Zero

    Also in SecurityWeek SecurityWeek The Record +3

    View on Security Feed

  2. Microsoft Says PKI, HSMs and Security Appliances Must Prepare for Post-Quantum Authentication

    News Cyber Security News4h ago8 sources

    Microsoft is urging organizations to prepare their certificate systems for post-quantum authentication, warning that public key infrastructure (PKI), hardware security modules (HSMs), and security appliances need testing before deployment. Its October 8 guidance says the shift will affect applications, devices, certificate chains, and the processes that keep digital trust working. The message goes beyond protecting encrypted traffic. While many quantum security plans focus on attackers collecting data now to decrypt later, authentication depends on certificates and private keys being issued…

    Also in Bleeping Computer Bleeping Computer The Hacker News +3

    View on Security Feed

  3. VirusTotal Adds Scanning for Public IPv4 Space to Expose C2 Servers and Malware Infrastructure

    News Cyber Security News5h ago6 sources

    VirusTotal has added daily scanning of the public IPv4 space, giving security teams a new way to find command-and-control (C2) servers and track malware infrastructure. Announced on October 8, 2026, the update records exposed services, port activity, banners, and server fingerprints alongside existing threat intelligence. The change helps researchers look beyond an IP address’s detection score. Earlier reports showed hosting details, passive DNS records, and files that contacted an address. The new data shows what a server exposes now, helping analysts find related hosts that have no malware…

    Also in Cisco Security Advisories Elastic Security Labs The Hacker News +2

    View on Security Feed

  4. Low-cost Android phones ship with residential proxy malware

    News Bleeping Computer17h ago4 sources

    A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices into residential proxies.

    Also in SecurityWeek Malwarebytes Labs CCCS Alerts & Advisories

    View on Security Feed

  5. Zombie instructions on carefully constructed web pages could trick GitHub Copilot CLI into sharing secrets

    News The Register Security6 Oct3 sources

    GitHub Copilot CLI may reveal developer secrets if it comes across instructions that tell it to do so, depending on the underlying model. The coding agent tool was flagged earlier this year for being susceptible to indirect prompt injection. That's when a model ingests text from a source other than the user that directs it to take some action outside the scope of its intended function. This is more of the same, with a twist. According to security researchers at Adversa AI, GitHub Copilot CLI suffers from the same vulnerability identified in Grok two months ago: Cryptographic Context Injection…

    Also in Bleeping Computer CCCS Alerts & Advisories

    View on Security Feed

  6. Cisco warns of critical flaws allowing Nexus switch takeover

    News Bleeping Computer21h ago3 sources

    Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches.

    Also in SecurityWeek CCCS Alerts & Advisories

    View on Security Feed

  7. Threat Actors Exploit Critical AhsayCBS Flaws to Drop Webshells and XMRig Cryptominer

    Threat Intel Huntress16h ago2 sources

    Threat actors are exploiting AhsayCBS flaws, including CVE-2026-105133 and CVE-2026-105134, to deploy webshells and XMRig cryptominers. Update to 10.3.4 and restrict access now.

    Also in SecurityWeek

    CVE-2026-105133 ↗CVE-2026-105134 ↗View on Security Feed

  8. Let’s Encrypt Cuts TLS Certificate Lifetimes From 90 to 64 Days Starting February 2027

    News Cyber Security News4h ago2 sources

    Let’s Encrypt will cut its default TLS certificate lifetime from 90 days to 64 days on February 10, 2027, giving website operators less time between renewals. The change applies to certificates issued or renewed from that date, while subscribers can still choose shorter certificate profiles offering 45 days or roughly six days. Let’s Encrypt Certificate Lifetime According to the October 7 announcement published by Let’s Encrypt , the nonprofit certificate authority confirmed the schedule. Existing certificates will remain valid until their normal expiry dates, and Let’s Encrypt will not…

    Also in Ars Technica Security

    View on Security Feed

  9. Atlassian Data Center Flaw Draws Exploitation Attempts Within Two Hours of Public Details

    News The Hacker News7 Oct3 sources

    Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software

    Also in Infosecurity Magazine CCCS Alerts & Advisories

    View on Security Feed

  10. Citrix gives NetScaler admins another critical reason to patch

    News The Register Security1h ago2 sources

    Citrix is urging customers to patch another critical NetScaler vulnerability after weeks of disclosures involving actively exploited flaws. CVE-2026-107406 affects NetScaler ADC and NetScaler Gateway and can lead to remote code execution (RCE) or denial of service (DoS). It carries a CVSS v4.0 score of 9.5. The affected configurations depend on the software version. Older builds are vulnerable when configured as a SAML (Security Assertion Markup Language) service provider (SP) or identity provider (IdP); some more recent builds are affected only in the identity provider configuration…

    Also in SecurityWeek

    CVE-2026-107406 ↗View on Security Feed

Vulnerability watch what to look at, most urgent first

Details CVEProductSeverity CVSSEPSS KEVFixIn the news
Highest scoring today 10new CVEs, highest CVSS first
CVE-2026-96207 Microsoft Partner CenterMicrosoft Critical 10.0 — — None linked — CVSS 10.0No fix linked
CVE-2026-106126 Tenable Identity Exposure (SaaS)Microsoft Critical 9.9 — — None linked — CVSS 9.9No fix linked
CVE-2026-94510 Microsoft BookingsMicrosoft Critical 9.9 — — None linked — CVSS 9.9No fix linked
CVE-2026-105110 InnboxIskratel Critical 9.8 3% — None linked — EPSS 3%CVSS 9.8No fix linked
CVE-2026-92555 AKINSOFT WOLVOX Control PanelAKIN Software Computer Import-Export Industry and Trade Co. Ltd. Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-16340 DataPower Gateway 10.6CDIBM Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-14991 DataPower Gateway 10.6CDIBM Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-15762 DataPower Gateway 10.6CDIBM Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-14269 DataPower Gateway 10.6CDIBM Critical 9.8 — — None linked — CVSS 9.8No fix linked
CVE-2026-14502 DataPower Gateway 10.6CDIBM Critical 9.8 — — None linked — CVSS 9.8No fix linked

Click a row, or press +, to expand it.EPSS is FIRST's estimated chance of exploitation in the next 30 days.Full CVE Feed

Worth reading quieter, still worth your time

  1. Inside the Exchange Inspector: How Tenable uses OpenAI GPT cyber models to review open-source AI agents

    Research Tenable Blog8 Oct2 sources

    Community-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here’s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange. Three tools have already passed. Key takeaways Every Inspector-vetted listing clears three gates: an automated check, a frontier model assessment, and human verification. Tenable uses Tenable One AI Exposure to screen for prompt injection and exposed secrets, and OpenAI GPT Cyber models to assess the code and threat model. Tenable security researchers then verify runtime behavior in a clean…

    Also in Bleeping Computer

    View on Security Feed

  2. CVE-2026-21589: Critical unauthenticated arbitrary file access in Atlassian products

    Research Rapid7 Blog7 Oct3 sources

    Overview On October 5, 2026, Atlassian published a security advisory for CVE-2026-21589 , a critical arbitrary file access vulnerability affecting eight products: Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software Data Center, Bamboo Data Center, Crowd Data Center, Crucible, and Fisheye. Atlassian assigned the vulnerability a CVSSv4 score of 9.3 . An unauthenticated remote attacker who knows a target file's exact name and path can access it within the application's web root; the vulnerability does not provide directory listing or enumeration…

    Also in SANS Internet Storm Center watchTowr Labs

    CVE-2026-21589 ↗View on Security Feed

Assembled automatically, once a day, from data the Security Feed and CVE Feed already collect and score. No AI writes any of this, and every number traces back to something already published on those two tools.

Top developments come from the Security Feed's cross-source trending detection. Vulnerability watch comes from the CVE Feed's daily NVD and CISA KEV sync.