π° Microsoft Patches 398 Flaws Including a Windows Driver Zero-Day Under Active Attack
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-68820
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-68820
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-94127
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-94127
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-85880 CVE-2026-87491 CVE-2026-85046
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-85880 CVE-2026-87491 CVE-2026-85046
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° EDR Evasion Stack Helps Process Injection Slip Past Defenses
A process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.
π Source
#RSS #CyberSecurity #Security #Tool
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.
π Source
#RSS #CyberSecurity #Security #Tool
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Dark Reading
EDR Evasion Stack Helps Process Injection Slip Past Defenses
The process parameter poisoning EDR evasion technique bypasses security tools by hiding payloads in Windows process initialization structures.
π° Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution. The post Critical F5 BIG-IP Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution. The post Critical F5 BIG-IP Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution.
π° MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-67279 CVE-2026-86060
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-67279 CVE-2026-86060
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Adobe Patches Critical Flaws in Connect, AEM Forms
The nine critical security defects could be exploited for arbitrary code execution and privilege escalation. The post Adobe Patches Critical Flaws in Connect, AEM Forms appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
The nine critical security defects could be exploited for arbitrary code execution and privilege escalation. The post Adobe Patches Critical Flaws in Connect, AEM Forms appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
Adobe Patches Critical Flaws in Connect, AEM Forms
The nine critical security defects could be exploited for arbitrary code execution and privilege escalation.
π° Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below - gocommunity-io/dockerd (222 downloads) kreuzwenker/.
π Source
#RSS #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below - gocommunity-io/dockerd (222 downloads) kreuzwenker/.
π Source
#RSS #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Dark Reading
GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.
π° Arista Urges Immediate Patching of Exploited VCO Zero-Day
Remote attackers could trigger the critical-severity flaw to access privileged internal functionality. The post Arista Urges Immediate Patching of Exploited VCO Zero-Day appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Remote attackers could trigger the critical-severity flaw to access privileged internal functionality. The post Arista Urges Immediate Patching of Exploited VCO Zero-Day appeared first on SecurityWeek.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
Arista Urges Immediate Patching of Exploited VCO Zero-Day
Remote attackers could trigger the critical-severity flaw to access privileged internal functionality.
π° Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
A new security vulnerability in Next. js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A new security vulnerability in Next. js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image.
π Source
#RSS #CVE #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° **Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape**
A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7. 8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.
π [Source](https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html)
#RSS #CVE #CyberSecurity #Security #Tool #Report CVE-2026-80521
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7. 8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.
π [Source](https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html)
#RSS #CVE #CyberSecurity #Security #Tool #Report CVE-2026-80521
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9. 8), affects all versions of the Bifrost HTTP transport before 2.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-90898
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9. 8), affects all versions of the Bifrost HTTP transport before 2.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-90898
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin
IonQ's new single processor quantum error decoder minimizes the classical computing overhead in quantum error correction. The post IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
IonQ's new single processor quantum error decoder minimizes the classical computing overhead in quantum error correction. The post IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU Decoder
IonQβs new single processor quantum error decoder minimizes the classical computing overhead in quantum error correction.
π° This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios
The idea that AI could break away and work toward its own agenda is looking increasingly plausible to researchers and experts. The post Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
The idea that AI could break away and work toward its own agenda is looking increasingly plausible to researchers and experts. The post Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios
The idea that AI could break away and work toward its own agenda is looking increasingly plausible to researchers and experts.
π° Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-93616
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point.
π Source
#RSS #CVE #CyberSecurity #Security #Tool CVE-2026-93616
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below - CVE-2026-48362 (CVSS score: 10. 0) - An operating system command injection vulnerability in ColdFusion that could.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-48362
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below - CVE-2026-48362 (CVSS score: 10. 0) - An operating system command injection vulnerability in ColdFusion that could.
π Source
#RSS #CVE #CyberSecurity #Security CVE-2026-48362
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in.
π Source
#RSS #CVE #CyberSecurity #Security #Tool #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in.
π Source
#RSS #CVE #CyberSecurity #Security #Tool #Report
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button labeled "Email work item to this project.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this address behind a button labeled "Email work item to this project.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
π° Chrome 154 Patches 108 Vulnerabilities
The browser update resolves several critical-severity memory safety and memory corruption flaws. The post Chrome 154 Patches 108 Vulnerabilities appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
The browser update resolves several critical-severity memory safety and memory corruption flaws. The post Chrome 154 Patches 108 Vulnerabilities appeared first on SecurityWeek.
π Source
#RSS #CyberSecurity #Security
βββββββββββββββ
πΉ Admin
@ZenithGhost
πΈ Channel
@PandoraCoreLab
SecurityWeek
Chrome 154 Patches 108 Vulnerabilities
The browser update resolves several critical-severity memory safety and memory corruption flaws.