Citrix confirms two NetScaler RCE zero-days exploited in attacks

Source: BleepingComputer

Author: Lawrence Abrams

URL: https://www.bleepingcomputer.com/news/security/citrix-admins-warned-to-shut-down-netscalers-over-2-exploited-zero-days/

ONE SENTENCE SUMMARY:

Two unpatched Citrix NetScaler RCE zero-days are reportedly exploited worldwide, prompting private agency warnings, shutdown advice, and imminent patch releases.

MAIN POINTS:

  1. Unpatched Citrix NetScaler zero-days are reportedly exploited in active attacks.
  2. IT suppliers privately urged some organizations to shut down NetScaler appliances immediately.
  3. Law enforcement, CERTs, and national agencies reportedly contacted targets about the threat.
  4. watchTowr corroborated credible reports of multiple in-the-wild NetScaler RCEs.
  5. The incident is explicitly unrelated to August-disclosed CVE-2026-19490 and CVE-2026-19489.
  6. CVE-2026-19490 is an auth bypass already exploited after a public PoC emerged.
  7. CISA added CVE-2026-19490 to the Known Exploited Vulnerabilities catalog September 9.
  8. NCSC-NL described two critical zero-days, each independently enabling remote code execution.
  9. One vulnerability reportedly allows placing shellcode directly into memory.
  10. No CVEs, advisories, affected versions, IoCs, or mitigations are publicly available yet.

TAKEAWAYS:

  1. Expect exploitation to intensify once Citrix publishes patches and technical details.
  2. Prepare now for potential downtime to patch quickly when releases arrive next week.
  3. Reduce exposure by taking Internet-facing NetScaler systems offline where feasible.
  4. Restrict access to trusted networks/IPs, especially for management interfaces.
  5. Monitor for vendor and national CSIRT updates since official IoCs are currently unavailable.

Microsoft: Recent Windows updates cause desktop loading issues

Source: BleepingComputer

Author: Sergiu Gatlan

URL: https://www.bleepingcomputer.com/news/microsoft/microsoft-recent-windows-updates-cause-desktop-loading-issues/

ONE SENTENCE SUMMARY:

Microsoft warns August 2026 Windows preview and later updates can cause black screens, mainly on AVD with FSLogix, mitigated via Explorer restart or KIR.

MAIN POINTS:

  1. Microsoft confirmed desktop loading failures and black screens after August 2026 preview updates.
  2. Issue primarily impacts Azure Virtual Desktop hosts running FSLogix user-profile technology.
  3. Affected users may see black screen post sign-in and no desktop access.
  4. Application event logs can show Windows Explorer crashes tied to the problem.
  5. Known affected updates include KB5120996 and KB5120998 across Windows 11 versions.
  6. Patch Tuesday updates KB5124008 and KB5122880 can also trigger the issue.
  7. Temporary workaround involves manually launching Windows Explorer to restore the session.
  8. Users can start explorer.exe via Task Manager’s “Run new task” function.
  9. Microsoft deployed a Known Issue Rollback mitigation for enterprise-managed devices.
  10. Administrators must install matching KIR Group Policy and reboot devices to apply.

TAKEAWAYS:

  1. Prioritize monitoring AVD+FSLogix environments after Windows preview or cumulative updates.
  2. Keep a documented helpdesk procedure for starting explorer.exe during black-screen incidents.
  3. Use KIR Group Policy as the fastest enterprise mitigation until a permanent fix ships.
  4. Track specific KBs in change management to correlate rollout timing with desktop failures.
  5. Expect Microsoft to reintroduce functionality later via a future Windows update resolution.

Microsoft integrates SOC capabilities with Defender for enterprises

Source: CSO Online

Author: unknown

URL: https://www.csoonline.com/article/4226195/microsoft-integrates-soc-capabilities-with-defender-for-enterprises.html

ONE SENTENCE SUMMARY:

Microsoft’s ISOC brings bundled SIEM into Defender for E5/E7, reducing Microsoft-log costs while raising third-party metering and vendor-dependency concerns.

MAIN POINTS:

  1. E5/E7 customers can now use SIEM in Microsoft Defender without extra license cost.
  2. ISOC unifies SIEM with XDR, threat intelligence, automation, and AI in one portal.
  3. Previously, SIEM required a separate Microsoft Sentinel purchase despite Defender XDR inclusion.
  4. Microsoft-source security logs incur no ingestion charges under ISOC.
  5. Third-party and external data ingestion becomes pay-as-you-go at $2.40 per GB from Oct. 1.
  6. Public preview began Sept. 23; production readiness and end date remain unspecified.
  7. Eligibility requires Defender Suite plus E5/E7, no Sentinel workspace, and no minimum seats.
  8. Case management, workbooks, and natural-language SOAR playbooks roll out automatically to eligible tenants.
  9. Included telemetry spans Defender products, Entra ID Protection, and Azure/O365 activity logs.
  10. Retention is 30 days in preview, increasing to 90 days on Nov. 15.

TAKEAWAYS:

  1. Microsoft-heavy stacks may gain major savings by avoiding re-ingestion of vendor-held telemetry.
  2. Mixed and multicloud environments should compare total SIEM ownership costs versus current tools.
  3. Migrating from established SIEMs demands scrutiny of retraining, content portability, and exit costs.
  4. Workspace-based features (connectors, UEBA, CI/CD, TI) require Azure subscription and added complexity.
  5. SOC agents increase risk via telemetry poisoning and prompt injection, needing strict identities and approvals.

What to do first when you get 90 days to secure AI agent data

Source: Help Net Security

Author: Mirko Zorz

URL: https://www.helpnetsecurity.com/2026/09/24/kelly-herrell-nol8-ai-agent-data-security/

ONE SENTENCE SUMMARY:

AI agents increase organizational exposure by rapidly aggregating sensitive context, requiring deterministic, in-path data governance controls over agent interactions.

MAIN POINTS:

  1. Focusing on the data path reveals true exposure beyond declared agent inventories.
  2. Key questions include reachable data, context inputs, tool/model calls, and outputs.
  3. Most organizations can’t evidence every boundary-crossing interaction, only sampled logs.
  4. Ticketing systems often contain overlooked sensitive artifacts like credentials and incident narratives.
  5. CRM, shared drives, chats, knowledge bases, and collaboration tools store rich institutional context.
  6. Human workflow friction once limited correlation; agents remove friction and implicit safeguards.
  7. AI increases speed, scale, and ease of discovery, not the inherent sensitivity of data.
  8. A 90-day plan should start with mapping paths and measuring sensitive data flows.
  9. Postpone identity overhauls, full data classification, masked replicas, and per-agent code guardrails.
  10. Resolve business-security tension by redacting sensitive fields in-flight rather than blocking access.

TAKEAWAYS:

  1. Measure exposure by what data actually crosses boundaries, not what deployments claim.
  2. Treat “authorized to access” as separate from “appropriate to see or disclose.”
  3. Implement a deterministic policy enforcement point that cannot be bypassed in the data path.
  4. Prioritize rapid, runtime enforcement on highest-risk flows before broader governance programs.
  5. Avoid controls embedded in each agent’s codebase; centralized enforcement prevents “forgotten” protections.

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html

ONE SENTENCE SUMMARY:

Bifrost AI gateway exposes default-unauthenticated management APIs enabling unauthenticated RCE/SSRF, credential theft, and requiring urgent upgrades and key rotation.

MAIN POINTS:

  1. CVE-2026-90898 enables unauthenticated remote command execution via Bifrost management API.
  2. Issue impacts all HTTP transports versions before 2.1.0 when auth disabled by default.
  3. Attack registers a stdio MCP client using unauthenticated POST to /api/mcp/client.
  4. Bifrost executes the provided command immediately, before MCP handshake, as gateway user.
  5. Successful RCE exposes stored provider API keys and virtual keys on the gateway.
  6. Stock binary binds management API to localhost, reducing remote exposure by default.
  7. Official Docker image binds management API to 0.0.0.0, exposing it when ports published.
  8. transports/v2.1.0 blocks unauthenticated stdio client registration by returning HTTP 403.
  9. CVE-2026-86242 allows unauthenticated HTTP-path plugin download and loading; fixed in v2.0.0.
  10. Multiple recent Bifrost vulnerabilities stem from default-disabled management authentication and echo prior MCP/LiteLLM attack patterns.

TAKEAWAYS:

  1. Upgrade immediately to transports/v2.1.0 to mitigate unauthenticated MCP-stdio RCE.
  2. Enable governance.auth_config.is_enabled and enforce strong management credentials.
  3. Restrict management listener to trusted networks; avoid exposing Docker-published management ports.
  4. Assume compromise if auth was disabled with exposed management API; rotate all keys.
  5. Patch older lines carefully: v2.0.0 fixes plugin issue but not MCP RCE; 1.6.x fixes neither.

CQURE Hacks #83: Attack on Active Directory Certificate Services (AD CS) – ESC16

Source: CQURE Academy

Author: Daniel

URL: https://cqureacademy.com/blog/cqure-hacks-83-attack-on-active-directory-certificate-services-ad-cs-esc16/

ONE SENTENCE SUMMARY:

ESC16 exploits missing SID extensions and weak mapping to impersonate accounts via UPN changes, enabling domain compromise through AD CS.

MAIN POINTS:

  1. ESC16 arises when a CA omits the SID security extension in certificates.
  2. SID extension normally binds certificates strongly to specific Active Directory accounts.
  3. Without SID binding, weak certificate mapping can rely on UPN identity fields.
  4. A low-privileged user, bob, can modify his own userPrincipalName attribute.
  5. Bob changes his UPN to Administrator before requesting a standard user certificate.
  6. The CA issues a certificate embedding Administrator UPN, yet tied to Bob’s SID.
  7. Bob restores his original UPN after obtaining the misbound certificate.
  8. KDC maps the certificate to the real Administrator account during authentication.
  9. Attacker obtains an Administrator TGT and recovers the Administrator NT hash.
  10. With Domain Admin rights, DCSync retrieves the krbtgt account hash.

TAKEAWAYS:

  1. Enforce SID security extension issuance to prevent ambiguous certificate-to-account binding.
  2. Disable weak certificate mapping behaviors that allow UPN-based identity confusion.
  3. Restrict permissions to modify identity attributes like userPrincipalName.
  4. Audit AD CS templates, CA settings, and KDC mapping configurations regularly.
  5. Minor PKI misconfigurations can cascade into full Active Directory domain compromise.

CIS Community Defense Model v3.0: Turning Threat Intelligence Into Action

Source: Blog Feed – Center for Internet Security

Author: unknown

URL: https://www.cisecurity.org/insights/blog/cis-community-defense-model-v3-turning-threat-intelligence-into-action

ONE SENTENCE SUMMARY:

CDM v3.0 prioritizes high-value CIS Controls Safeguards, improving visibility, resilience, and risk reduction through standardized, confidence-driven cybersecurity management.

MAIN POINTS:

  1. CDM v3.0 helps identify and prioritize high-value CIS Controls Safeguards.
  2. A risk-based approach aligns cybersecurity actions to mission-critical outcomes.
  3. Continuous monitoring improves visibility into assets, vulnerabilities, and configurations.
  4. Standardized metrics enable consistent measurement across programs and organizations.
  5. Centralized reporting supports faster, data-driven decision-making for leadership.
  6. Implementation guidance clarifies which safeguards deliver the greatest risk reduction.
  7. Improved cyber hygiene strengthens resilience against common and advanced threats.
  8. Confidence increases by validating controls through measurable performance indicators.
  9. Resource allocation becomes more efficient by focusing on highest-impact safeguards first.
  10. Reduced uncertainty supports defensible compliance and audit readiness efforts.

TAKEAWAYS:

  1. Prioritize safeguards that measurably reduce the most risk.
  2. Use continuous monitoring to maintain accurate, actionable security visibility.
  3. Apply standardized measures to compare progress and effectiveness over time.
  4. Focus investments where they strengthen resilience and mission assurance.
  5. Validate outcomes with metrics to reduce guesswork and increase confidence.

Revoking the token didn’t kill the backdoor

Source: CSO Online

Author: unknown

URL: https://www.csoonline.com/article/4223975/revoking-the-token-didnt-kill-the-backdoor.html

ONE SENTENCE SUMMARY:

GraphWorm uses Microsoft Graph/OneDrive C2 and can remotely swap OAuth identities, making token revocation insufficient without endpoint isolation.

MAIN POINTS:

  1. Typical identity runbooks prioritize revoking tokens to end session-based compromise.
  2. GraphWorm communicates via Microsoft Graph, using OneDrive as a dead-drop C2.
  3. Tasking uses encrypted job/result folders plus heartbeat and fingerprint files.
  4. Network controls struggle because traffic looks like normal Microsoft 365 TLS activity.
  5. Implant stores client ID, client secret, tenant ID, and long refresh token in cleartext.
  6. Victim ID is hardware-derived, resisting containment via hostname, subnet, or egress changes.
  7. An upgrade command replaces all credentials and scopes from a single task.
  8. Operator can recover immediately after token revocation by switching to a spare OneDrive identity.
  9. Effective detection relies on cloud telemetry: app ID, tenant anomalies, user-agent, file names.
  10. Containment must target the app registration and endpoint behavior, not just token artifacts.

TAKEAWAYS:

  1. Reframe token revocation as a delay when adversaries control application identities.
  2. Sequence response to block channel access while burning credentials, not afterward.
  3. File platform suspension requests early because third-party tenant action can be slow.
  4. Query sign-in telemetry for fixed malicious application IDs to confirm exposure quickly.
  5. Focus hunts on endpoint-resident code and repeatable behaviors attackers can’t cheaply replace.

5 ways AI is reshaping the cybersecurity job market

Source: CSO Online

Author: unknown

URL: https://www.csoonline.com/article/4224019/5-ways-ai-is-reshaping-the-cybersecurity-job-market.html

ONE SENTENCE SUMMARY:

AI automation is reshaping cybersecurity teams through consolidation, shifting analyst work to judgment, demanding AI fluency, and shrinking pipelines globally.

MAIN POINTS:

  1. LastPass dissolved dedicated vulnerability management, moving duties into IT and product security.
  2. Triage and analysis increasingly rely on AI and business intelligence tools.
  3. WEF reports 87% see AI-related vulnerabilities as fastest-growing risk category.
  4. SANS/GIAC found 74% say AI is changing security team sizes and roles.
  5. Leadership structures are consolidating, avoiding new C-level roles for AI governance.
  6. Routine GRC compliance is being automated so staff can become higher-level risk advisors.
  7. Analysts now evaluate automated findings and tune systems, not just work alert queues.
  8. Judgment has become the scarcest capability, especially validating AI outputs against business context.
  9. The “AI loop” can reinforce wrong assumptions, producing confident but flawed risk reports.
  10. Entry-level rungs are disappearing, widening skills gaps and linking workforce shortages to breaches.

TAKEAWAYS:

  1. Consolidate governance thoughtfully while ensuring accountability doesn’t overload a few leaders.
  2. Re-skill SOC staff toward validation, root-cause reasoning, and system engineering oversight.
  3. Prioritize senior judgment development to counter confidently incorrect automation at scale.
  4. Hire for balanced AI fluency—neither skepticism nor hype—aligned to real control needs.
  5. Protect junior-to-senior pathways to prevent future talent shortages becoming operational security risk.

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html

ONE SENTENCE SUMMARY:

TASK#STOMP is a VBScript-orchestrated, PowerShell-based backdoor campaign enabling stealthy persistence, surveillance, credential theft, document exfiltration, and redundant C2.

MAIN POINTS:

  1. Campaign deploys a PowerShell backdoor for data theft and remote command execution.
  2. Infection begins with wscript.exe running an encoded VBScript staged on the desktop.
  3. Initial delivery vector is unclear, possibly phishing or social engineering via email.
  4. Randomized VBScript filename likely aims to evade simple name-based detections.
  5. Persistence established through scheduled tasks masquerading as legitimate Windows services.
  6. Backup persistence uses Startup folder to run msdiag.vbs at user logon.
  7. Malware kills prior instances to enforce a single active session.
  8. Stealth techniques include timestomping, hidden execution, and trace-cleanup behaviors.
  9. Two PowerShell modules provide redundancy, mutual watchdogging, and separate C2 channels.
  10. C2 domains corecloudfileshare[.]xyz and attachmentsharingdrive[.]xyz use token-authenticated communications.

TAKEAWAYS:

  1. Native Windows tooling abuse can make malicious activity resemble routine administration.
  2. Layered persistence significantly increases resilience against partial remediation.
  3. Mutual watchdog processes help maintain long-lived access despite interruptions.
  4. Collection focuses on business documents, Wi‑Fi credentials, clipboard data, and screenshots.
  5. Unusual user-facing actions (opening Iran tenders site) may indicate staging, distraction, or operator workflow.

Data center failure affects New Mexico credit union services

Source: Top Stories

Author: unknown

URL: https://www.koat.com/article/data-center-failure-affects-new-mexico-credit-union-services/73795685

ONE SENTENCE SUMMARY:

A third-party data center cooling failure triggered a Sharetec outage, disrupting New Mexico credit union access without evidence of breach.

MAIN POINTS:

  1. Cooling system failure occurred at an out-of-state third-party data center.
  2. Sharetec experienced a nationwide outage beginning Sept. 15.
  3. New Mexico credit union members faced limited account access.
  4. Service impacts differed depending on each credit union’s reliance on Sharetec.
  5. Direct deposit availability was restricted for some affected members.
  6. Cash withdrawal access was limited at certain institutions.
  7. Everyone’s Federal Credit Union handled member needs individually.
  8. Manual processing using paper records replaced automated transactions.
  9. Sharetec provided only a voicemail acknowledging connectivity issues and remediation efforts.
  10. Credit unions stated the incident was not identified as a data breach.

TAKEAWAYS:

  1. Third-party infrastructure failures can cascade into widespread financial service outages.
  2. Manual fallback procedures help maintain limited operations during prolonged vendor downtime.
  3. Customer impacts may include delayed deposits and constrained cash access.
  4. Lack of timely vendor communication increases uncertainty for affected institutions and members.
  5. Ongoing restoration timelines can remain unclear even when breaches are ruled out.

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

Source: Help Net Security

Author: Zeljka Zorz

URL: https://www.helpnetsecurity.com/2026/09/17/cisco-ise-vulnerability-exploited-cve-2026-76460/

ONE SENTENCE SUMMARY:

Cisco warns CVE-2026-76460 actively exploits Cisco ISE API authentication bypass; update, hunt indicators, and reimage compromised nodes.

MAIN POINTS:

  1. Cisco confirmed active exploitation of CVE-2026-76460 in Cisco Identity Services Engine.
  2. Vulnerability is an authentication bypass caused by insufficient API endpoint authentication controls.
  3. Remote unauthenticated attackers can bypass the web management interface via crafted requests.
  4. Affected products include Cisco ISE and Cisco ISE Passive Identity Connector (ISE-PIC).
  5. Impacted versions span releases 3.0 through 3.5 across deployments.
  6. Cisco provided indicators of compromise but withheld observed attack details.
  7. Investigation should review access.log for suspicious usernames on every node.
  8. If compromise suspected, re-image affected nodes and restore configurations from backups.
  9. Verify external firewall and network logs for suspicious uploads/downloads tied to affected devices.
  10. Fixed releases are 3.1 Patch 12, 3.2 Patch 11, 3.3 Patch 12, 3.4 Patch 7, 3.5 Patch 4.

TAKEAWAYS:

  1. Patch immediately because no workaround mitigates this actively exploited authentication bypass.
  2. Treat all cluster nodes as potentially affected and perform uniform log review.
  3. Preserve evidence by correlating device activity with external network and firewall telemetry.
  4. Plan migration away from 3.0–3.2 due to limited or ended maintenance support.
  5. Expect additional ISE/ISE-PIC security fixes, including findings from researchers and internal AI-assisted testing.

DeepZero: Open-source hunting for vulnerable Windows drivers

Source: Help Net Security

Author: Mirko Zorz

URL: https://www.helpnetsecurity.com/2026/09/16/vulnerable-windows-drivers-deepzero-open-source/

ONE SENTENCE SUMMARY:

DeepZero automates finding exploitable Windows kernel drivers using YAML pipelines, static analysis, filtering, and LLM exploitability assessment.

MAIN POINTS:

  1. DeepZero scans folders of Windows driver binaries to locate exploit candidates automatically.
  2. Project is open-source, written in Python 3.11+, with YAML-defined pipelines.
  3. Maintainer reports multiple verified vulnerabilities found in Snappy Driver Installer driver corpus.
  4. Included pipeline focuses on BYOVD attacks using signed but vulnerable kernel drivers.
  5. Stage one parses PE headers to extract metadata and initial driver characteristics.
  6. Stage two retains only kernel-mode drivers exposing reachable IOCTL interfaces.
  7. Stage three removes drivers already listed on loldrivers.io to avoid known cases.
  8. Ghidra headless decompilation and Semgrep rules analyze recovered/exported C-like output.
  9. A reduction step selects top candidates before sending artifacts to a language model.
  10. Hardware-dependent device creation can block confirmation without correct devices enumerated.

TAKEAWAYS:

  1. Layered filtering ensures the LLM reviews only high-signal, novel driver candidates.
  2. BYOVD remains practical because signed drivers can still contain exploitable flaws.
  3. Static reports may miss issues when device objects are created only via plug-and-play callbacks.
  4. Tracking IoCreateDevice location helps distinguish universally reachable drivers from hardware-gated ones.
  5. Framework is pipeline-oriented and can be adapted beyond Windows kernel driver analysis.

Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html

ONE SENTENCE SUMMARY:

Acronis reports CVE-2026-87886 in its cPanel/WHM Backup plugin is exploited, enabling local privilege escalation via insecure permissions.

MAIN POINTS:

  1. Acronis disclosed active exploitation of a high-severity flaw in its Backup plugin.
  2. Vulnerability is tracked as CVE-2026-87886 with a CVSS score of 7.8.
  3. Root cause involves insecure file permissions enabling local privilege escalation on Linux.
  4. Attackers need low-privilege access to escalate permissions on affected deployments.
  5. Exploitation could enable unauthorized actions or arbitrary code execution impacting confidentiality and integrity.
  6. Acronis says fixes are included in version 1.9.3 HF3 and urged immediate installation.
  7. Advisory notes exploitation has been observed in limited, targeted attacks in the wild.
  8. Public details about the vulnerability’s mechanics have not been released.
  9. Attribution for the attacks and adversary objectives remain unknown.
  10. Detection timeline and duration of exploitation activity have not been clarified.

TAKEAWAYS:

  1. Patch Acronis Backup plugin installations to 1.9.3 HF3 promptly to reduce risk.
  2. Treat low-privilege footholds on cPanel/WHM servers as potential escalation paths.
  3. Prioritize monitoring for suspicious privilege changes on Linux hosting environments.
  4. Assume targeted exploitation may expand, despite currently limited reporting.
  5. Maintain rapid update processes for hosting control panel plugins due to frequent attacker interest.

CISA: Critical VMware RCE flaw now exploited by ransomware gangs

Source: BleepingComputer

Author: Sergiu Gatlan

URL: https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/

ONE SENTENCE SUMMARY:

CISA warns ransomware gangs are exploiting critical VMware vCenter CVE-2026-59310, urging urgent patching amid widespread global compromises online now detected.

MAIN POINTS:

  1. Broadcom patched CVE-2026-59310 in vCenter Syslog on July 29.
  2. Vulnerability is a critical directory traversal enabling unauthenticated remote code execution.
  3. Supplemental FAQ urged customers to treat remediation as an emergency.
  4. QUIRSO observed APT exploitation deploying a reverse SSH tool for persistence.
  5. Investigators found 361 compromised IPs spanning 47 countries after initial exploitation.
  6. CISA added the flaw to KEV and mandated federal remediation within three days.
  7. KEV entry was later updated, noting active abuse by ransomware groups.
  8. Shadowserver reports over 450 vCenter servers currently exposed to the internet.
  9. Attackers favor vCenter/ESXi compromise for lateral access to networks and sensitive data.
  10. CISA has tagged 26 VMware flaws exploited in five years; nine linked to ransomware.

TAKEAWAYS:

  1. Apply vCenter patches immediately when KEV-listed, especially for unauthenticated RCE conditions.
  2. Reduce internet exposure of vCenter services to shrink attack surface and opportunistic scanning.
  3. Hunt for reverse SSH backdoors and unusual persistence following vCenter compromise indicators.
  4. Expect ransomware operators to target VMware ecosystems using purpose-built VM encryptors.
  5. Track CISA KEV updates to prioritize remediation ahead of rapid threat-actor adoption.

Certificate failures can cost firms over $250,000

Source: Help Net Security

Author: Anamarija Pogorelec

URL: https://www.helpnetsecurity.com/2026/09/14/digicert-certificate-management-automation-report/

ONE SENTENCE SUMMARY:

DigiCert warns 47-day TLS certificates will multiply renewals, validations and outages unless enterprises rapidly gain visibility and automate lifecycles everywhere.

MAIN POINTS:

  1. Shifting to 47-day public TLS certificates by 2029 increases renewals eightfold and validations 40x.
  2. Expired certificates caused outages for 34% of firms; 40% reported downtime from mismanagement.
  3. Downtime severity is high: nearly three-quarters lost five hours, while 21% lost 25+.
  4. Financial impact is substantial, with 25% citing their worst incident exceeding $250,000.
  5. Operational ownership skews to infrastructure: 57% label outages IT issues versus 17% security incidents.
  6. Certificate sprawl is common, as over half of organizations manage more than 1,000 certificates.
  7. Key “very/extremely concerned” challenges include expiration, customer trust, regulatory compliance, and multi-cloud/platform management.
  8. Managing internal and external systems simultaneously worries 52%, highlighting fragmented environments needing central control.
  9. Adoption momentum is growing: ~70% are preparing for shorter lifetimes, and volumes are expected to rise.
  10. Automation expansion is constrained by cost, legacy incompatibility, weak executive buy-in, and limited expertise.

TAKEAWAYS:

  1. Inventory completeness (what, where, owner) becomes mandatory when lifecycles shrink to 47 days.
  2. Eliminating manual tracking reduces outage risk more effectively than relying on reminders and spreadsheets.
  3. Building an ROI case should emphasize avoided downtime and remediation labor, not just tooling costs.
  4. Integrating certificate management into DevOps pipelines is the top near-term improvement priority.
  5. Addressing “very/extremely concerned” areas requires lifecycle-wide automation across clouds, platforms, and compliance workflows.

How to level up from security pro to security leader

Source: CSO Online

Author: unknown

URL: https://www.csoonline.com/article/4221303/how-to-level-up-from-security-pro-to-security-leader.html

ONE SENTENCE SUMMARY:

Aspiring CISOs must evolve from technical experts into business-focused leaders who communicate risk, influence stakeholders, build trust, and learn continuously.

MAIN POINTS:

  1. Translating technical risk into business priorities separates top CISOs from technical specialists.
  2. Employers prioritize communication skills, regulatory knowledge, and broad education over specific tools.
  3. Modern CISO expectations center on strategy and leadership, not daily hands-on security tasks.
  4. Trust-building requires collaboration without reverting to an “IT guy” posture.
  5. Professional presence means concise, confident communication and appropriate cultural fit.
  6. Cross-functional relationships enable influence across engineering, operations, legal, finance, and executives.
  7. Admitting mistakes and sharing lessons can strengthen credibility and leadership maturity.
  8. Business fluency comes from understanding revenue models, budgets, and organizational tradeoffs.
  9. Curiosity and learning are mandatory as AI agents, APIs, and machine identities expand.
  10. Mentorship and focusing on impact today matter more than rigid career-path scripting.

TAKEAWAYS:

  1. Develop an executive narrative that ties security decisions to outcomes leaders care about.
  2. Invest in political and partnership skills to drive shared accountability beyond formal authority.
  3. Build business competence through MBA alternatives like budgeting, product work, and risk roles.
  4. Seek diverse technical exposure to better govern emerging enterprise technologies.
  5. Use mentors and present authentic growth, prioritizing results over title-chasing.

Why Patch Automation Needs Brakes, Not Just an Accelerator

Source: BleepingComputer

Author: Sponsored by Action1

URL: https://www.bleepingcomputer.com/news/security/why-patch-automation-needs-brakes-not-just-an-accelerator/

ONE SENTENCE SUMMARY:

Software updates outpace IT capacity, so controlled patch automation using staged rings, defined success criteria, and human oversight reduces risk.

MAIN POINTS:

  1. Update volume and vulnerability disclosures are rising faster than IT teams can evaluate.
  2. Staffing constraints and complex environments cause patch backlogs and risky deployment trade-offs.
  3. Compressed testing and skipped reviews increase chances of outages or insecure exposure windows.
  4. Automation can rapidly spread failures if speed becomes the primary metric.
  5. Effective patch automation requires “brakes” to control progression, timing, and stop conditions.
  6. Test labs help but cannot mirror diverse production configurations and behaviors.
  7. Controlled production validation using staged deployment better reflects real-world conditions.
  8. Establish upfront success definitions: install success, endpoint health, app functionality, acceptable failure rates.
  9. Update rings enable gradual rollout governed by predefined criteria, reducing ad-hoc human decisions.
  10. Human involvement remains essential for business-critical systems while routine decisions get automated.

TAKEAWAYS:

  1. Treat speed as secondary to safety by pairing automation with enforceable deployment controls.
  2. Implement staged rollouts that automatically advance or halt based on measurable outcomes.
  3. Formalize what “success” means before deploying, then monitor continuously against those baselines.
  4. Reserve manual approvals and expert judgment for high-impact systems and exceptions.
  5. Aim for consistent, controlled automation first, then optimize for faster patching over time.

Microsoft releases emergency Windows updates to fix RDS failures

Source: BleepingComputer

Author: Lawrence Abrams

URL: https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-emergency-windows-updates-to-fix-rds-failures/

ONE SENTENCE SUMMARY:

Microsoft issued out-of-band Windows updates to fix September 2026 security-update regressions breaking RDS, plus Hyper-V and USB audio issues.

MAIN POINTS:

  1. September 2026 security updates destabilized Remote Desktop Services, causing RDP sign-in and connection failures.
  2. Some impacted servers became unresponsive, indicating severe service disruption beyond simple login issues.
  3. Related tools like MMC, Licensing Diagnoser, File Explorer, and Windows Update could hang.
  4. Out-of-band fixes shipped September 14 to remediate the introduced regressions.
  5. Windows Server 2025 failures traced to KB5122871; Windows Server 2022 issues tied to KB5122882.
  6. Temporary mitigations were previously provided via Group Policy while engineering developed permanent patches.
  7. Uninstalling September updates restored Remote Desktop, but removed included security protections.
  8. Windows 11 26H1 KB5129194 is distributed via WU, WUfB, Catalog, and WSUS.
  9. Server out-of-band updates for 2022/2025 are offered through the Microsoft Update Catalog only.
  10. Additional OOB updates include KB5129195 (Win11 24H2/25H2) and KB5129236 (Win10 21H2/22H2).

TAKEAWAYS:

  1. Treat Patch Tuesday deployments cautiously; critical regressions can break core remote administration paths.
  2. Use Microsoft’s out-of-band patches rather than rolling back security updates when feasible.
  3. Validate RDS plus management tooling after updates, not just RDP connectivity.
  4. Hyper-V Plan9 shared-folder issues and multichannel USB audio failures are also addressed in Windows 11 OOB updates.
  5. Remaining USB Audio Class 1.0 “Code 10/no audio” problems persist, with a future fix pending.

CQURE Hacks #82: Microsoft Entra ID Conditional Access Bypass via User-Agent Policy Gap

Source: CQURE Academy

Author: Asia

URL: https://cqureacademy.com/blog/cqure-hacks-82-microsoft-entra-id-conditional-access-bypass-via-user-agent-policy-gap/

ONE SENTENCE SUMMARY:

A User-Agent–based Conditional Access gap enabled Xbox token issuance without MFA, leading to Graph access, secret discovery, and full tenant compromise.

MAIN POINTS:

  1. Conditional Access trusted device platforms based solely on client-controlled User-Agent strings.
  2. Policies blocked Windows, Linux, and iPhone, but overlooked Xbox Series X.
  3. Xbox User-Agent allowed Microsoft Graph token acquisition without triggering MFA.
  4. Obtained access token enabled direct Graph API access despite portal restrictions.
  5. GraphRunner enumerated users, groups, and roles through Microsoft Graph.
  6. Portal blocking proved ineffective because underlying APIs remained accessible.
  7. Custom scripting searched directory objects for exposed credentials and secrets.
  8. A clear-text password was found stored in a group description attribute.
  9. Exposed credentials belonged to a break-glass Global Administrator account.
  10. Chaining policy gaps with poor secret storage resulted in full tenant compromise.

TAKEAWAYS:

  1. Expand Conditional Access coverage to include Graph/API token acquisition flows.
  2. Avoid security decisions based on manipulable client signals like User-Agent.
  3. Enforce MFA consistently across all sensitive access paths, not just portals.
  4. Prevent secrets from being stored in readable directory attributes and descriptions.
  5. Assume attackers will chain minor misconfigurations into high-impact compromises.

Update your firewall rules: Teams and Copilot are changing address

Source: CSO Online

Author: unknown

URL: https://www.computerworld.com/article/4221272/teams-and-copilot-are-changing-addresses-update-your-firewalls.html

ONE SENTENCE SUMMARY:

Microsoft will redirect M365 and Teams web traffic to new cloud.microsoft domains, requiring enterprises to update controls by October.

MAIN POINTS:

  1. Redirects will send M365 web users to copilot.cloud.microsoft starting this month.
  2. Teams web users are being redirected to teams.cloud.microsoft already.
  3. Microsoft announced changes via MessageCenter posts MC1465764 and MC1462915.
  4. Organizations must update systems and documentation to preserve user access.
  5. Client device configurations should be reviewed for compatibility with new destinations.
  6. Proxies, firewalls, and secure web gateways may need rule adjustments.
  7. Enterprise network controls must allow connections to the new addresses.
  8. Troubleshooting should reference Microsoft 365 Copilot network requirement guidance.
  9. TenantRestrictions can replace blocking copilot.cloud.microsoft to limit personal account access.
  10. Limited Teams redirect exceptions may continue until December 31, 2026.

TAKEAWAYS:

  1. Change management is needed to prevent service disruption from domain redirects.
  2. Network security tooling should be validated against updated Microsoft endpoint destinations.
  3. Policy-based tenant controls are preferred over blunt domain blocking for account restrictions.
  4. Early October is the target completion date; support is available through account representatives.
  5. Long-term planning must assume Teams exceptions end permanently after the 2026 deadline.

GitLab urges users to patch max severity path traversal flaw

Source: BleepingComputer

Author: Sergiu Gatlan

URL: https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/

ONE SENTENCE SUMMARY:

GitLab released urgent patches for critical path traversal and deserialization flaws, warning self-managed users to upgrade immediately to prevent sensitive data exposure.

MAIN POINTS:

  1. Maximum-severity path traversal vulnerability tracked as CVE-2023-2825 prompted immediate patching guidance.
  2. Researcher “s3ntago” reported the issue via GitLab’s HackerOne bug bounty program.
  3. Root cause involves improper path confinement and missing authentication in repository commits API.
  4. Unauthenticated attackers could read arbitrary files from vulnerable GitLab servers under conditions.
  5. Second critical flaw, CVE-2026-87719, involves insecure deserialization in GraphQL subscription serializer.
  6. CVE-2026-87719 impacts GitLab EE and requires authenticated Duo Chat access.
  7. Exploitation could expose sensitive credentials and Advanced Search instance configurations.
  8. Fixes shipped in GitLab CE/EE versions 19.3.2, 19.2.6, and 19.1.x releases.
  9. GitLab.com already runs patched code; GitLab Dedicated customers need no action.
  10. CISA has listed multiple GitLab vulnerabilities as exploited since 2021, underscoring active risk.

TAKEAWAYS:

  1. Upgrade self-managed GitLab immediately to patched versions to reduce exposure windows.
  2. Enforce strong API authentication and path confinement to prevent traversal-style data leaks.
  3. Treat deserialization in GraphQL-related components as high-risk and audit serializers rigorously.
  4. Monitor CISA exploited-vulnerability listings to prioritize patching and threat-informed remediation.
  5. Past GitLab security incidents show recurring attacker interest, requiring continuous vulnerability management.

Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example “sk-1234” Admin Key

Source: The Hacker News

Author: info@thehackernews.com (The Hacker News)

URL: https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html

ONE SENTENCE SUMMARY:

Wiz found many exposed LiteLLM gateways using default master keys, enabling credential theft, code execution, and urgent hardening upgrades needed.

MAIN POINTS:

  1. Scan found 3,074 Shodan-listed LiteLLM gateways; 294 accepted the example key.
  2. Of those 294, 191 had no master key set, accepting any value.
  3. Prior to 1.82.0-stable, missing master key granted full admin to all requests.
  4. Administrators can view stored model-provider API keys and all prompts/responses passing through.
  5. Pass-through endpoints allow SSRF to cloud instance metadata, exposing IAM credentials.
  6. IMDSv2 protections were bypassed using LiteLLM’s x-pass- header forwarding behavior.
  7. Maintainers classify misconfiguration-based attacks as out-of-scope; no CVE for metadata access.
  8. CVE-2026-59821 enabled container code execution via guardrail checks bypass pre-1.82.0-stable.
  9. CISA lists exploited CVE-2026-59822, enabling MCP access with trivial Bearer tokens.
  10. Mitigations include upgrading to 1.84.0+, blocking risky endpoints, and least-privilege cloud roles.

TAKEAWAYS:

  1. Replace sk-1234 with a long random master key and follow correct rotation procedure.
  2. Adopt LiteLLM 1.84.0 or later to cover all listed CVE fixes.
  3. Enforce outbound network restrictions and minimal IAM permissions to limit blast radius.
  4. Disable or proxy-block /mcp/, MCP test endpoints, and unsafe guardrail routes.
  5. Assume compromise if exposed: audit guardrails, restart services, and rotate provider/database credentials.

Threat matrix: Mapping threats across cloud web applications

Source: Microsoft Security Blog

Author: Microsoft Security Research and Lior Leizerovich

URL: https://www.microsoft.com/en-us/security/blog/2026/09/09/threat-matrix-mapping-threats-across-cloud-web-applications/

ONE SENTENCE SUMMARY:

Microsoft’s MITRE ATT&CK-aligned cloud web applications threat matrix maps techniques across app and cloud layers to prioritize defenses.

MAIN POINTS:

  1. Attack paths span code, runtimes, identities, pipelines, and connected cloud resources.
  2. Separate app-versus-cloud investigations create blind spots and missed adversary chaining opportunities.
  3. Matrix organizes cloud web app and serverless techniques by MITRE ATT&CK tactics.
  4. Subdomain takeover can occur from orphaned DNS pointing at reusable provider endpoints.
  5. Initial access includes app vulnerabilities, repo injections, compromised images, misconfigured admin interfaces, trigger abuse.
  6. Execution vectors include remote code execution exploits, cloud-native terminals, and malicious App Service extensions.
  7. Persistence occurs via scheduled jobs, source modification in canonical artifacts, and compromised valid accounts.
  8. Privilege escalation leverages app-stored secrets or workload identity tokens via metadata/identity endpoints.
  9. Defense evasion uses staging slots/aliases and disabling or manipulating cloud logging controls.
  10. Impact techniques include theft, destruction, defacement, resource hijacking, and denial-of-wallet cost abuse.

TAKEAWAYS:

  1. Prioritize MFA and least privilege for users, workloads, and deployment access paths.
  2. Lock down repositories, build systems, registries, and extensions to trusted sources only.
  3. Eliminate reusable secrets in code/config by using workload identities and proper secrets management.
  4. Centralize protected logging and prevent tampering to enable detection and incident reconstruction.
  5. Reduce blast radius with quotas, concurrency limits, cost guardrails, and tested backup recovery.

Is a Quantified Cyber Risk Number Defensible? The Inputs

Source: Rivial Security Blog

Author: Randy Lindberg

URL: https://www.rivialsecurity.com/blog/is-cyber-risk-quantification-defensible

ONE SENTENCE SUMMARY:

Defensible cyber risk quantification uses external breach data, ATT&CK scenarios, Monte Carlo loss curves, and validated controls to justify dollar figures.

MAIN POINTS:

  1. Security leaders often dismiss CRQ as guesses disguised as precise dollars.
  2. High/medium/low ratings also rely on subjective inputs but conceal assumptions.
  3. Quantified models can be defensible by transparently showing calculations and sources.
  4. Self-populated likelihood estimates merely reformat opinion and undermine board credibility.
  5. Independent breach datasets anchor incident frequency and cost baselines objectively.
  6. Organization specifics adjust baselines using systems, data types, records, and controls.
  7. MITRE ATT&CK grounds threat scenarios in observed adversary techniques across attack chains.
  8. Monte Carlo simulation models lognormal losses, capturing both expected loss and catastrophic tail risk.
  9. Interview-only control assessments weaken models; validation ties inputs to evidence and testing.
  10. Quantified, validated outputs support regulator scrutiny and enable cost-effective risk reduction decisions.

TAKEAWAYS:

  1. Replacing colors with dollars improves auditability because assumptions become inspectable.
  2. External, regularly updated research reduces bias in likelihood and impact estimation.
  3. ATT&CK-based scenarios increase credibility by using a widely accepted public framework.
  4. Simulation provides board-relevant views of tail losses, not just single expected values.
  5. Evidence-backed control effectiveness turns CRQ into actionable capital allocation and tolerance management.