🔘 Vulnerability(cybersecuritynews.com): Hackers Actively Exploiting Critical Langflow RCE and Rails Vulnerability
✉ 01.09.2026 16:52:27 Abinaya
💻 Two critical vulnerabilities affecting Langflow and Ruby on Rails deployments are being actively exploited, with attackers quickly moving from public disclosure to reconnaissance, secret harvesting, and potential remote code execution, according to VulnCheck telemetry.
The first issue, tracked as CVE-2026-0768, affects Langflow, a low-code platform for building AI-powered applications, agents, and workflow automations.
VulnCheck observed exploitation attempts against its internet-facing Canary systems shortly after the vulnerability was added to its Known Exploited Vulnerabilities catalog.
CVE-2026-0768 is an unauthenticated remote code execution flaw in the code validator used by Langflow’s custom component editor. An attacker may be able to execute code on a vulnerable server without first authenticating.
The flaw was disclosed through Trend Micro’s Zero Day Initiative in January, and VulnCheck said no public proof-of-concept exploit was known at the time of the observed attacks.
The company initially recorded more than 50 detections, but the volume later increased to around 360 exploitation events. The malicious requests appeared to be designed to identify valuable credentials and access paths rather than immediately deploy ransomware or other destructive payloads.
Langflow RCE and Rails Vulnerability Exploited
Observed commands attempted to retrieve environment variables associated with Langflow administration, OpenAI APIs, and AWS cloud access.
Observed first-time exploitation of CVE-2026-0768 in Langflow (source: VulnCheck )
Attackers also tried to read Langflow’s local secret key file at /root/.cache/langflow/secret_key, inspect SSH access, and determine the size of .bash_history files. These checks could help an intruder identify administrator activity, stolen credentials, cloud resources, and possible routes for lateral movement.
VulnCheck said the Langflow traffic primarily originated from Russia and, at the time of reporting, targeted Canary systems located in the United Kingdom.
The activity adds to a growing pattern of exploitation targeting Langflow. Several other Langflow vulnerabilities have reportedly been added to VulnCheck’s KEV catalog during 2026.
Separately, researchers observed exploitation of CVE-2026-66066, a critical Ruby on Rails vulnerability described as an Active Storage file-read-to-RCE issue.
Active exploitation of CVE-2026-66066 (source: VulnCheck)
The attacks hit Canary systems in Singapore, Israel, and the United Kingdom. VulnCheck linked the activity to a single source IP address in France. At ...
#Cyber_Security_News #Vulnerability #Vulnerability_News #cyber_security #cyber_security_news
https://cybersecuritynews.com/langflow-rce-and-rails-vulnerability-exploited/
read it on CSN:
https://csn.net4me.net/cyber_security_27904.html
✉ 01.09.2026 16:52:27 Abinaya
💻 Two critical vulnerabilities affecting Langflow and Ruby on Rails deployments are being actively exploited, with attackers quickly moving from public disclosure to reconnaissance, secret harvesting, and potential remote code execution, according to VulnCheck telemetry.
The first issue, tracked as CVE-2026-0768, affects Langflow, a low-code platform for building AI-powered applications, agents, and workflow automations.
VulnCheck observed exploitation attempts against its internet-facing Canary systems shortly after the vulnerability was added to its Known Exploited Vulnerabilities catalog.
CVE-2026-0768 is an unauthenticated remote code execution flaw in the code validator used by Langflow’s custom component editor. An attacker may be able to execute code on a vulnerable server without first authenticating.
The flaw was disclosed through Trend Micro’s Zero Day Initiative in January, and VulnCheck said no public proof-of-concept exploit was known at the time of the observed attacks.
The company initially recorded more than 50 detections, but the volume later increased to around 360 exploitation events. The malicious requests appeared to be designed to identify valuable credentials and access paths rather than immediately deploy ransomware or other destructive payloads.
Langflow RCE and Rails Vulnerability Exploited
Observed commands attempted to retrieve environment variables associated with Langflow administration, OpenAI APIs, and AWS cloud access.
Observed first-time exploitation of CVE-2026-0768 in Langflow (source: VulnCheck )
Attackers also tried to read Langflow’s local secret key file at /root/.cache/langflow/secret_key, inspect SSH access, and determine the size of .bash_history files. These checks could help an intruder identify administrator activity, stolen credentials, cloud resources, and possible routes for lateral movement.
VulnCheck said the Langflow traffic primarily originated from Russia and, at the time of reporting, targeted Canary systems located in the United Kingdom.
The activity adds to a growing pattern of exploitation targeting Langflow. Several other Langflow vulnerabilities have reportedly been added to VulnCheck’s KEV catalog during 2026.
Separately, researchers observed exploitation of CVE-2026-66066, a critical Ruby on Rails vulnerability described as an Active Storage file-read-to-RCE issue.
Active exploitation of CVE-2026-66066 (source: VulnCheck)
The attacks hit Canary systems in Singapore, Israel, and the United Kingdom. VulnCheck linked the activity to a single source IP address in France. At ...
#Cyber_Security_News #Vulnerability #Vulnerability_News #cyber_security #cyber_security_news
https://cybersecuritynews.com/langflow-rce-and-rails-vulnerability-exploited/
read it on CSN:
https://csn.net4me.net/cyber_security_27904.html
Cyber Security News
Hackers Actively Exploiting Critical Langflow RCE and Rails Vulnerability
Two critical Langflow and Ruby on Rails flaws are being actively exploited for reconnaissance, secret harvesting, and potential remote code execution.
🔘 OpenNet: Релиз Firefox 155
✉ 01.09.2026 21:40:04
💻 Состоялся релиз web-браузера Firefox 155 и сформированы обновления прошлых веток с длительным сроком поддержки - 153.2.0, 140.15.0 и 115.40.0. Firefox 155 стал первым выпусков, сформированным в рамках нового двухнедельного цикла формирования релизов, который позволит чаще доводить новые возможности до пользователей, обеспечит более предсказуемый процесс формирования релизов и снизит нагрузку на разработчиков перед релизами. На стадию бета-тестирования переведена ветка Firefox 156, релиз которой намечен на 15 сентября.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66187
read it on CSN:
https://csn.net4me.net/cyber_security_27905.html
✉ 01.09.2026 21:40:04
💻 Состоялся релиз web-браузера Firefox 155 и сформированы обновления прошлых веток с длительным сроком поддержки - 153.2.0, 140.15.0 и 115.40.0. Firefox 155 стал первым выпусков, сформированным в рамках нового двухнедельного цикла формирования релизов, который позволит чаще доводить новые возможности до пользователей, обеспечит более предсказуемый процесс формирования релизов и снизит нагрузку на разработчиков перед релизами. На стадию бета-тестирования переведена ветка Firefox 156, релиз которой намечен на 15 сентября.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66187
read it on CSN:
https://csn.net4me.net/cyber_security_27905.html
🔘 OpenNet: Опубликован Linux From Scratch 13.1
✉ 02.09.2026 07:52:22
💻 Доступно руководство Linux From Scratch 13.1 (LFS), начиная с ветки 13.x формируемое только в виде редакции с системным менеджером systemd. В Linux From Scratch приведены инструкции по созданию с нуля базовой Linux-системы, используя исходные тексты необходимого программного обеспечения. Отдельно развивает редакция Beyond Linux From Scratch, которая дополняет инструкции LFS информацией о сборке и настройке около 1000 программных пакетов, охватывающих различные области применения, от СУБД и серверных систем, до графических оболочек и медиапроигрывателей. Выпуск BLFS 13.1 намерены опубликовать в ближайшие дни.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66195
read it on CSN:
https://csn.net4me.net/cyber_security_27906.html
✉ 02.09.2026 07:52:22
💻 Доступно руководство Linux From Scratch 13.1 (LFS), начиная с ветки 13.x формируемое только в виде редакции с системным менеджером systemd. В Linux From Scratch приведены инструкции по созданию с нуля базовой Linux-системы, используя исходные тексты необходимого программного обеспечения. Отдельно развивает редакция Beyond Linux From Scratch, которая дополняет инструкции LFS информацией о сборке и настройке около 1000 программных пакетов, охватывающих различные области применения, от СУБД и серверных систем, до графических оболочек и медиапроигрывателей. Выпуск BLFS 13.1 намерены опубликовать в ближайшие дни.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66195
read it on CSN:
https://csn.net4me.net/cyber_security_27906.html
👍1
🔘 OpenNet: Выпуск WinBtrfs 1.10, реализации файловой системы Btrfs для Windows
✉ 02.09.2026 08:23:33
💻 После более двух лет разработки опубликован выпуск проекта WinBtrfs 1.10, развивающего драйвер для использования файловой системой Btrfs на платформе Windows. WinBtrfs не основан на коде Btrfs из ядра Linux, а является созданной с нуля альтернативной реализацией. Поддерживается работа с Windows XP и более новыми выпусками. Драйвер включён в состав операционной системы ReactOS и может применяться для загрузки Windows из раздела с Btrfs. Код написан на языках C/C++ и распространяется под лицензией LGPLv3.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66197
read it on CSN:
https://csn.net4me.net/cyber_security_27907.html
✉ 02.09.2026 08:23:33
💻 После более двух лет разработки опубликован выпуск проекта WinBtrfs 1.10, развивающего драйвер для использования файловой системой Btrfs на платформе Windows. WinBtrfs не основан на коде Btrfs из ядра Linux, а является созданной с нуля альтернативной реализацией. Поддерживается работа с Windows XP и более новыми выпусками. Драйвер включён в состав операционной системы ReactOS и может применяться для загрузки Windows из раздела с Btrfs. Код написан на языках C/C++ и распространяется под лицензией LGPLv3.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66197
read it on CSN:
https://csn.net4me.net/cyber_security_27907.html
🔘 OpenNet: Атакующие использовали BGP для подмены сервера обновлений Virtualizor и сайта Softaculous
✉ 02.09.2026 08:27:44
💻 Атакующие смогли подменить элементы инфраструктуры компании Softaculous, осуществив подстановку фиктивного маршрута через BGP, благодаря которой удалось перенаправить трафик подсети с серверами Softaculous на подконтрольный атакующим сервер. В результате атаки, среди прочего, удалось перенаправить обращения к клиентскому web-сайту компании, биллингу и серверам распространения обновлений для ПО Virtualizor, после чего использовать их для распространения вредоносного ПО и атаки на клиентов компании. Атакующие смогли получить через сервис Let's Encrypt корректные TLS-сертификаты для доменов Softaculous, так как автоматическая проверка владения доменами прошла через подменённые хосты.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66196
read it on CSN:
https://csn.net4me.net/cyber_security_27908.html
✉ 02.09.2026 08:27:44
💻 Атакующие смогли подменить элементы инфраструктуры компании Softaculous, осуществив подстановку фиктивного маршрута через BGP, благодаря которой удалось перенаправить трафик подсети с серверами Softaculous на подконтрольный атакующим сервер. В результате атаки, среди прочего, удалось перенаправить обращения к клиентскому web-сайту компании, биллингу и серверам распространения обновлений для ПО Virtualizor, после чего использовать их для распространения вредоносного ПО и атаки на клиентов компании. Атакующие смогли получить через сервис Let's Encrypt корректные TLS-сертификаты для доменов Softaculous, так как автоматическая проверка владения доменами прошла через подменённые хосты.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66196
read it on CSN:
https://csn.net4me.net/cyber_security_27908.html
🔘 OpenNet: Выпуск nginx 1.31.5 и njs 1.0.1
✉ 02.09.2026 23:01:17
💻 Опубликован выпуск основной ветки nginx 1.31.5, в которой продолжается развитие новых возможностей. В параллельно поддерживаемую стабильную ветку 1.30.x вносятся только изменения, связанные с устранением серьёзных ошибок и уязвимостей. В дальнейшем на базе основной ветки 1.31.x будет сформирована стабильная ветка 1.32. Код проекта написан на языке Си и распространяется под лицензией BSD.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66201
read it on CSN:
https://csn.net4me.net/cyber_security_27909.html
✉ 02.09.2026 23:01:17
💻 Опубликован выпуск основной ветки nginx 1.31.5, в которой продолжается развитие новых возможностей. В параллельно поддерживаемую стабильную ветку 1.30.x вносятся только изменения, связанные с устранением серьёзных ошибок и уязвимостей. В дальнейшем на базе основной ветки 1.31.x будет сформирована стабильная ветка 1.32. Код проекта написан на языке Си и распространяется под лицензией BSD.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66201
read it on CSN:
https://csn.net4me.net/cyber_security_27909.html
🔥1
🔘 OpenNet: За неделю после релиза загружено более миллиона копий LibreOffice 26.8
✉ 03.09.2026 09:50:42
💻 Организация The Document Foundation опубликовала статистику загрузок релиза LibreOffice 26.8. Сообщается, что за первую неделю LibreOffice 26.8 был загружен через официальную страницу загрузки на сайте проекта 1.031 млн раз (в статистике не учтены пользователи дистрибутивов, использующие LibreOffice из штатных репозиториев).
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66204
read it on CSN:
https://csn.net4me.net/cyber_security_27910.html
✉ 03.09.2026 09:50:42
💻 Организация The Document Foundation опубликовала статистику загрузок релиза LibreOffice 26.8. Сообщается, что за первую неделю LibreOffice 26.8 был загружен через официальную страницу загрузки на сайте проекта 1.031 млн раз (в статистике не учтены пользователи дистрибутивов, использующие LibreOffice из штатных репозиториев).
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66204
read it on CSN:
https://csn.net4me.net/cyber_security_27910.html
🔘 Vulnerability(cybersecuritynews.com): Researcher Claims CrowdStrike Falcon 0-Day Privilege Escalation Vulnerability
✉ 03.09.2026 08:35:43 Abinaya
💻 A security researcher known as Nightmare-Eclipse, who also goes by the names Chaotic Eclipse and MSNightmare, has released a project that claims to take advantage of a security flaw in the CrowdStrike Falcon Sensor. This flaw allows for local privilege escalation, which means it could give unauthorized users higher access rights.
The project, named FalconFlank, alleges that the issue abuses CrowdStrike’s remediation workflow for malicious Microsoft Office macros on Windows systems.
According to the repository’s README, the claimed flaw affects devices where the “Microsoft Office file malicious macro removal” capability is enabled.
The researcher stated that the proof of concept worked against fully updated Windows 11 25H2 and Windows Server 2025 environments protected by CrowdStrike Falcon with Phase 3 Optimal Protection enabled.
The public repository was created recently and includes C source code, a Visual Studio solution, project files, headers, and a compiled x64 release directory.
CrowdStrike Falcon 0-Day Privilege Escalation
Its README describes the project as a “Crowdstrike Falcon 0day Privilege Escalation Vulnerability,” but the claim has not been independently verified.
CrowdStrike had not issued a public advisory, CVE identifier, patch notice, or confirmation for the alleged vulnerability at the time of writing. The researcher claims the technique abuses the security product’s handling of Office documents identified as containing malicious macros.
PoC Demonstrates Local Privilege Escalation to SYSTEM Access (source: MSNightmare)
In endpoint protection platforms, remediation features often operate with elevated permissions because they may need to quarantine, delete, modify, or restore files in protected locations.
A local attacker could obtain higher privileges if they can manipulate a remediation process to load an attacker-controlled file, follow a malicious path, or handle unsafe file metadata. The FalconFlank README suggests that CrowdStrike detections may already identify the released proof of concept.
It also claims that testing may require Falcon exclusions or changes to the payload’s DLL loading method. Those statements should be treated with caution: they are assertions by the researcher and do not establish that a vulnerability exists or that exploitation is reliable across customer environments.
If validated, a privilege escalation flaw in an endpoint security agent could have significant security implications. Falcon runs with extensive operating system privileges to monitor activity and prevent threats.
...
#Cyber_Security_News #Vulnerability #Vulnerability_News #cyber_security #cyber_security_news
https://cybersecuritynews.com/crowdstrike-falcon-0-day/
read it on CSN:
https://csn.net4me.net/cyber_security_27911.html
✉ 03.09.2026 08:35:43 Abinaya
💻 A security researcher known as Nightmare-Eclipse, who also goes by the names Chaotic Eclipse and MSNightmare, has released a project that claims to take advantage of a security flaw in the CrowdStrike Falcon Sensor. This flaw allows for local privilege escalation, which means it could give unauthorized users higher access rights.
The project, named FalconFlank, alleges that the issue abuses CrowdStrike’s remediation workflow for malicious Microsoft Office macros on Windows systems.
According to the repository’s README, the claimed flaw affects devices where the “Microsoft Office file malicious macro removal” capability is enabled.
The researcher stated that the proof of concept worked against fully updated Windows 11 25H2 and Windows Server 2025 environments protected by CrowdStrike Falcon with Phase 3 Optimal Protection enabled.
The public repository was created recently and includes C source code, a Visual Studio solution, project files, headers, and a compiled x64 release directory.
CrowdStrike Falcon 0-Day Privilege Escalation
Its README describes the project as a “Crowdstrike Falcon 0day Privilege Escalation Vulnerability,” but the claim has not been independently verified.
CrowdStrike had not issued a public advisory, CVE identifier, patch notice, or confirmation for the alleged vulnerability at the time of writing. The researcher claims the technique abuses the security product’s handling of Office documents identified as containing malicious macros.
PoC Demonstrates Local Privilege Escalation to SYSTEM Access (source: MSNightmare)
In endpoint protection platforms, remediation features often operate with elevated permissions because they may need to quarantine, delete, modify, or restore files in protected locations.
A local attacker could obtain higher privileges if they can manipulate a remediation process to load an attacker-controlled file, follow a malicious path, or handle unsafe file metadata. The FalconFlank README suggests that CrowdStrike detections may already identify the released proof of concept.
It also claims that testing may require Falcon exclusions or changes to the payload’s DLL loading method. Those statements should be treated with caution: they are assertions by the researcher and do not establish that a vulnerability exists or that exploitation is reliable across customer environments.
If validated, a privilege escalation flaw in an endpoint security agent could have significant security implications. Falcon runs with extensive operating system privileges to monitor activity and prevent threats.
...
#Cyber_Security_News #Vulnerability #Vulnerability_News #cyber_security #cyber_security_news
https://cybersecuritynews.com/crowdstrike-falcon-0-day/
read it on CSN:
https://csn.net4me.net/cyber_security_27911.html
Cyber Security News
Researcher Claims CrowdStrike Falcon 0-Day Privilege Escalation Vulnerability
A security researcher known as Nightmare-Eclipse, who also goes by the names Chaotic Eclipse and MSNightmare, has released a project that claims to take advantage of a security flaw in the CrowdStrike Falcon Sensor.
🔘 Vulnerability(cybersecuritynews.com): Cisco Nexus 9000 Series Switches Flaw Allows Remote Attackers to Execute Malicious Code
✉ 03.09.2026 10:08:41 Abinaya
💻 Cisco has disclosed a critical vulnerability in Cisco Nexus 9000 Series Switches that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.
Tracked as CVE-2026-20212, the flaw has received a CVSS score of 9.8 out of 10 and affects Nexus 9000 models that use a Silicon One ASIC. The security issue, identified as CWE-1327, is detailed in Cisco advisory cisco-sa-n9k-s1-rce-EH8dEtr, published on September 2, 2026.
Cisco said the vulnerability was discovered while resolving a Technical Assistance Center support case. At the time of publication, Cisco PSIRT said it was not aware of public exploitation or malicious activity involving the flaw.
The vulnerability exists because TCP ports 43210 and 43211 are reachable through the default Layer 3 virtual routing and forwarding configuration on affected devices. An attacker does not need valid credentials to target the vulnerable service.
By connecting to an exposed switch and sending specially crafted input, an attacker could cause that input to be executed as code with root-level privileges.
Cisco Nexus 9000 Series Switches Vulnerability
Root access would give an attacker broad control over the targeted switch. This could enable changes to network configuration, traffic monitoring, service disruption, data interception, or movement to other systems connected to the network.
Successful exploitation can also crash the S1HAL process, Cisco warned, potentially forcing the affected device to reload and causing a network outage. The issue affects Cisco Nexus 9000 Series Switches that include a Silicon One ASIC.
Cisco listed several affected product identifiers, including N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804, and N9K-C9808.
Administrators can identify the installed module and product identifier by running the show module command on the switch. Organizations should compare the returned model number against Cisco’s affected-product list and then verify whether their current NX-OS release is vulnerable through the Cisco Software Checker.
Cisco confirmed that other Nexus 9000 models not listed in the advisory are not affected. Nexus 9000 Fabric Switches operating in ACI mode are also not vulnerable.
Other confirmed unaffected products include Nexus 3000 and Nexus 7000 Series Switches, MDS 9000 Series Multilayer Switches, Cisco Firepower appliances, Secure Firewall products, and several UCS Fabric Interconnect platforms.
Cisco has released software updates to address CVE-2026-20212 a...
#Cisco #Cyber_Security_News #Vulnerability #cyber_security #cyber_security_news
https://cybersecuritynews.com/cisco-nexus-9000-series-switches-vulnerability/
read it on CSN:
https://csn.net4me.net/cyber_security_27912.html
✉ 03.09.2026 10:08:41 Abinaya
💻 Cisco has disclosed a critical vulnerability in Cisco Nexus 9000 Series Switches that could allow an unauthenticated remote attacker to execute arbitrary code with root privileges.
Tracked as CVE-2026-20212, the flaw has received a CVSS score of 9.8 out of 10 and affects Nexus 9000 models that use a Silicon One ASIC. The security issue, identified as CWE-1327, is detailed in Cisco advisory cisco-sa-n9k-s1-rce-EH8dEtr, published on September 2, 2026.
Cisco said the vulnerability was discovered while resolving a Technical Assistance Center support case. At the time of publication, Cisco PSIRT said it was not aware of public exploitation or malicious activity involving the flaw.
The vulnerability exists because TCP ports 43210 and 43211 are reachable through the default Layer 3 virtual routing and forwarding configuration on affected devices. An attacker does not need valid credentials to target the vulnerable service.
By connecting to an exposed switch and sending specially crafted input, an attacker could cause that input to be executed as code with root-level privileges.
Cisco Nexus 9000 Series Switches Vulnerability
Root access would give an attacker broad control over the targeted switch. This could enable changes to network configuration, traffic monitoring, service disruption, data interception, or movement to other systems connected to the network.
Successful exploitation can also crash the S1HAL process, Cisco warned, potentially forcing the affected device to reload and causing a network outage. The issue affects Cisco Nexus 9000 Series Switches that include a Silicon One ASIC.
Cisco listed several affected product identifiers, including N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804, and N9K-C9808.
Administrators can identify the installed module and product identifier by running the show module command on the switch. Organizations should compare the returned model number against Cisco’s affected-product list and then verify whether their current NX-OS release is vulnerable through the Cisco Software Checker.
Cisco confirmed that other Nexus 9000 models not listed in the advisory are not affected. Nexus 9000 Fabric Switches operating in ACI mode are also not vulnerable.
Other confirmed unaffected products include Nexus 3000 and Nexus 7000 Series Switches, MDS 9000 Series Multilayer Switches, Cisco Firepower appliances, Secure Firewall products, and several UCS Fabric Interconnect platforms.
Cisco has released software updates to address CVE-2026-20212 a...
#Cisco #Cyber_Security_News #Vulnerability #cyber_security #cyber_security_news
https://cybersecuritynews.com/cisco-nexus-9000-series-switches-vulnerability/
read it on CSN:
https://csn.net4me.net/cyber_security_27912.html
Cyber Security News
Cisco Nexus 9000 Series Switches Flaw Allows Remote Attackers to Execute Malicious Code
Cisco disclosed a critical Nexus 9000 flaw enabling unauthenticated remote code execution with root privileges.
🔘 OpenNet: CERN переведёт систему управления ускорителем на Debian, но оставит RHEL/AlmaLinux в датацентрах
✉ 03.09.2026 11:55:26
💻 Представители Европейской организации по ядерным исследованиям (CERN) упомянули в своём выступлении на конференции MiniDebConf о планах до конца 2026 года перевести с RHEL на Debian 13 более 2200 промышленных и встраиваемых компьютеров, применяемых для управления ускорительным комплексом, в который входит Большой адронный коллайдер и ряд независимых экспериментальных установок. Отдельно уточняется, что миграция не затронет датацентры и экспериментальные системы, на которых будет продолжено использование RHEL/AlmaLinux.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66202
read it on CSN:
https://csn.net4me.net/cyber_security_27913.html
✉ 03.09.2026 11:55:26
💻 Представители Европейской организации по ядерным исследованиям (CERN) упомянули в своём выступлении на конференции MiniDebConf о планах до конца 2026 года перевести с RHEL на Debian 13 более 2200 промышленных и встраиваемых компьютеров, применяемых для управления ускорительным комплексом, в который входит Большой адронный коллайдер и ряд независимых экспериментальных установок. Отдельно уточняется, что миграция не затронет датацентры и экспериментальные системы, на которых будет продолжено использование RHEL/AlmaLinux.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66202
read it on CSN:
https://csn.net4me.net/cyber_security_27913.html
🔘 OpenNet: Выпуск системы глубокого инспектирования пакетов nDPI 6.0
✉ 03.09.2026 12:46:11
💻 Проект ntop, развивающий инструменты для захвата и анализа трафика, опубликовал инструментарий для глубокого инспектирования пакетов nDPI 6.0, продолжающий развитие библиотеки OpenDPI. Проект nDPI основан после безуспешной попытки передачи изменений в репозиторий OpenDPI, который остался без сопровождения. Код nDPI написан на языке Си и распространяется под лицензией LGPLv3.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66198
read it on CSN:
https://csn.net4me.net/cyber_security_27915.html
✉ 03.09.2026 12:46:11
💻 Проект ntop, развивающий инструменты для захвата и анализа трафика, опубликовал инструментарий для глубокого инспектирования пакетов nDPI 6.0, продолжающий развитие библиотеки OpenDPI. Проект nDPI основан после безуспешной попытки передачи изменений в репозиторий OpenDPI, который остался без сопровождения. Код nDPI написан на языке Си и распространяется под лицензией LGPLv3.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66198
read it on CSN:
https://csn.net4me.net/cyber_security_27915.html
🔘 Vulnerability(cybersecuritynews.com): Hackers Actively Exploiting Sangoma Switchvox VoIP Platform RCE Flaw in Attacks
✉ 03.09.2026 13:59:24 Abinaya
💻 A critical vulnerability in Sangoma Switchvox is being actively exploited, affecting the enterprise VoIP platform used to manage business phone systems, voicemail, call forwarding, monitoring, and analytics.
The flaw, tracked as CVE-2026-9586, enables unauthenticated attackers to execute commands remotely on vulnerable systems without needing valid credentials.
Horizon3.ai researchers observed valid exploitation attempts against internet-exposed Switchvox devices on August 30, 2026, with attackers attempting to deploy reverse shells for remote command-line access to compromised VoIP servers.
CVE-2026-9586 is an unauthenticated SQL injection vulnerability affecting Sangoma Switchvox SMB Edition 8.3, build 104997, and earlier releases. The issue has a CVSS severity score of 9.3 and can lead to remote code execution.
The vulnerable component is an unauthenticated HTTP endpoint, /pa, that processes XML messages for supported IP phones. These messages can be used to notify phone systems about events such as incoming and outgoing calls.
Hackers Exploiting Sangoma Switchvox VoIP RCE Flaw
Horizon3 researchers found that Switchvox extracts the PhoneIP value from an XML request and directly adds it to a PostgreSQL database query.
The application does not properly sanitize or parameterize the user-controlled input. This allows a remote attacker to inject malicious SQL commands through a specially crafted request.
Because the database query is executed with elevated PostgreSQL permissions, an attacker could run operating system commands on the Switchvox server.
This could allow them to access database contents, alter user data, create or elevate administrator accounts, steal authentication material, and establish persistent remote access.
Same attacker IP hits multiple honeypots. (Source: Horizon)
Horizon3 and Defused Cyber deployed internet-facing honeypots to monitor for exploitation attempts. On August 30, researchers detected attacks from the IP address 176.65.148.184 across multiple honeypots in quick succession.
The observed activity included an attempt to launch a reverse shell using Netcat. Attackers then used a Base64-encoded command to collect information on active processes running on the vulnerable Switchvox appliance.
The results were prepared for transmission to an attacker-controlled server, suggesting that the attackers were conducting post-exploitation reconnaissance after gaining access.
Horizon3 warned that the speed and scale of the attempts indicate that internet-exposed Switchvox systems are likely being broadly scanned and ...
#Cyber_Security_News #Vulnerability #cyber_security #cyber_security_news
https://cybersecuritynews.com/hackers-exploiting-sangoma-switchvox-voip-rce-flaw/
read it on CSN:
https://csn.net4me.net/cyber_security_27916.html
✉ 03.09.2026 13:59:24 Abinaya
💻 A critical vulnerability in Sangoma Switchvox is being actively exploited, affecting the enterprise VoIP platform used to manage business phone systems, voicemail, call forwarding, monitoring, and analytics.
The flaw, tracked as CVE-2026-9586, enables unauthenticated attackers to execute commands remotely on vulnerable systems without needing valid credentials.
Horizon3.ai researchers observed valid exploitation attempts against internet-exposed Switchvox devices on August 30, 2026, with attackers attempting to deploy reverse shells for remote command-line access to compromised VoIP servers.
CVE-2026-9586 is an unauthenticated SQL injection vulnerability affecting Sangoma Switchvox SMB Edition 8.3, build 104997, and earlier releases. The issue has a CVSS severity score of 9.3 and can lead to remote code execution.
The vulnerable component is an unauthenticated HTTP endpoint, /pa, that processes XML messages for supported IP phones. These messages can be used to notify phone systems about events such as incoming and outgoing calls.
Hackers Exploiting Sangoma Switchvox VoIP RCE Flaw
Horizon3 researchers found that Switchvox extracts the PhoneIP value from an XML request and directly adds it to a PostgreSQL database query.
The application does not properly sanitize or parameterize the user-controlled input. This allows a remote attacker to inject malicious SQL commands through a specially crafted request.
Because the database query is executed with elevated PostgreSQL permissions, an attacker could run operating system commands on the Switchvox server.
This could allow them to access database contents, alter user data, create or elevate administrator accounts, steal authentication material, and establish persistent remote access.
Same attacker IP hits multiple honeypots. (Source: Horizon)
Horizon3 and Defused Cyber deployed internet-facing honeypots to monitor for exploitation attempts. On August 30, researchers detected attacks from the IP address 176.65.148.184 across multiple honeypots in quick succession.
The observed activity included an attempt to launch a reverse shell using Netcat. Attackers then used a Base64-encoded command to collect information on active processes running on the vulnerable Switchvox appliance.
The results were prepared for transmission to an attacker-controlled server, suggesting that the attackers were conducting post-exploitation reconnaissance after gaining access.
Horizon3 warned that the speed and scale of the attempts indicate that internet-exposed Switchvox systems are likely being broadly scanned and ...
#Cyber_Security_News #Vulnerability #cyber_security #cyber_security_news
https://cybersecuritynews.com/hackers-exploiting-sangoma-switchvox-voip-rce-flaw/
read it on CSN:
https://csn.net4me.net/cyber_security_27916.html
Cyber Security News
Hackers Actively Exploiting Sangoma Switchvox VoIP Platform RCE Flaw in Attacks
Sangoma Switchvox faces an actively exploited critical flaw enabling unauthenticated remote command execution.
🔘 Vulnerability(cybersecuritynews.com): Critical Chrome 0-Day Vulnerability Actively Exploited in the Wild
✉ 04.09.2026 09:17:13 Abinaya
💻 Google has released an emergency Chrome security update that fixes a critical zero-day vulnerability already being exploited in real-world attacks.
The flaw, tracked as CVE-2026-85046, affects the V8 JavaScript and WebAssembly engine used by Chrome to process web content. The company confirmed that it is aware of an exploit for the vulnerability existing in the wild.
While Google did not disclose details about the attacks, affected targets, or the threat actors behind the activity, the active exploitation notice makes immediate patching important for all Chrome desktop users.
The security update moves Chrome Stable to version 152.0.7977.82/.83 for Windows and macOS. Linux users receive version 152.0.7977.82. Google said the update will roll out gradually over the coming days and weeks.
Chrome 0-Day Vulnerability Exploited
CVE-2026-85046 is described as a high-severity type confusion vulnerability in V8. Type confusion bugs occur when software incorrectly treats a piece of data as one type when it is actually another type.
In a browser engine, this kind of memory-handling error can be dangerous. An attacker may be able to create specially crafted JavaScript or web content that causes Chrome to handle memory unexpectedly.
Depending on the exploit chain, this could lead to browser crashes, data exposure, or the execution of attacker-controlled code within the browser process.
A victim may only need to visit a malicious or compromised website for an exploit attempt to begin. Attackers can also deliver exploit links via phishing emails, malicious advertisements, social media messages, or compromised legitimate sites.
The vulnerability was reported by security researcher Salvatore Gulizia, also known as Serotav, on August 4, 2026. Google awarded a $1,000 bug bounty for the report.
The Chrome update contains 12 security fixes in total. Several of the patched issues are rated high severity and affect important browser components, including V8, WebGL, Network, DevTools, Skia, CacheStorage, Compositing, and CrashReporting.
Among the notable fixes are a race condition in V8, an out-of-bounds write vulnerability in WebGL, use-after-free flaws in Compositing, DevTools, and Skia, and a type confusion issue in Compositing.
Google is restricting access to some vulnerability details until most users have installed the update. This approach is intended to reduce the chance that attackers can quickly reverse-engineer the fixes and build additional exploit code before organizations and individuals patch their browsers.
Chrome users should update immediately by ...
#Chrome #Cyber_Security_News #Vulnerability #cyber_security #cyber_security_news
https://cybersecuritynews.com/chrome-0-day-flaw-exploited-wild/
read it on CSN:
https://csn.net4me.net/cyber_security_27917.html
✉ 04.09.2026 09:17:13 Abinaya
💻 Google has released an emergency Chrome security update that fixes a critical zero-day vulnerability already being exploited in real-world attacks.
The flaw, tracked as CVE-2026-85046, affects the V8 JavaScript and WebAssembly engine used by Chrome to process web content. The company confirmed that it is aware of an exploit for the vulnerability existing in the wild.
While Google did not disclose details about the attacks, affected targets, or the threat actors behind the activity, the active exploitation notice makes immediate patching important for all Chrome desktop users.
The security update moves Chrome Stable to version 152.0.7977.82/.83 for Windows and macOS. Linux users receive version 152.0.7977.82. Google said the update will roll out gradually over the coming days and weeks.
Chrome 0-Day Vulnerability Exploited
CVE-2026-85046 is described as a high-severity type confusion vulnerability in V8. Type confusion bugs occur when software incorrectly treats a piece of data as one type when it is actually another type.
In a browser engine, this kind of memory-handling error can be dangerous. An attacker may be able to create specially crafted JavaScript or web content that causes Chrome to handle memory unexpectedly.
Depending on the exploit chain, this could lead to browser crashes, data exposure, or the execution of attacker-controlled code within the browser process.
A victim may only need to visit a malicious or compromised website for an exploit attempt to begin. Attackers can also deliver exploit links via phishing emails, malicious advertisements, social media messages, or compromised legitimate sites.
The vulnerability was reported by security researcher Salvatore Gulizia, also known as Serotav, on August 4, 2026. Google awarded a $1,000 bug bounty for the report.
The Chrome update contains 12 security fixes in total. Several of the patched issues are rated high severity and affect important browser components, including V8, WebGL, Network, DevTools, Skia, CacheStorage, Compositing, and CrashReporting.
Among the notable fixes are a race condition in V8, an out-of-bounds write vulnerability in WebGL, use-after-free flaws in Compositing, DevTools, and Skia, and a type confusion issue in Compositing.
Google is restricting access to some vulnerability details until most users have installed the update. This approach is intended to reduce the chance that attackers can quickly reverse-engineer the fixes and build additional exploit code before organizations and individuals patch their browsers.
Chrome users should update immediately by ...
#Chrome #Cyber_Security_News #Vulnerability #cyber_security #cyber_security_news
https://cybersecuritynews.com/chrome-0-day-flaw-exploited-wild/
read it on CSN:
https://csn.net4me.net/cyber_security_27917.html
Cyber Security News
Critical Chrome 0-Day Vulnerability Actively Exploited in the Wild
Google released an emergency Chrome update fixing a zero-day exploited in attacks, affecting the V8 JavaScript and WebAssembly engine.
🔘 OpenNet: Выпуск звукового редактора Audacity 4.0 с новым интерфейсом на Qt
✉ 04.09.2026 08:43:00
💻 Опубликован релиз свободного редактора звука Audacity 4.0, предоставляющего средства для редактирования звуковых файлов (Ogg Vorbis, FLAC, MP3 и WAV), записи и оцифровки звука, изменения параметров звукового файла, наложения треков и применения эффектов (например, подавление шума, изменение темпа и тона). Код Audacity распространяется под лицензией GPLv3, бинарные сборки доступны для Linux, Windows и macOS.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66209
read it on CSN:
https://csn.net4me.net/cyber_security_27918.html
✉ 04.09.2026 08:43:00
💻 Опубликован релиз свободного редактора звука Audacity 4.0, предоставляющего средства для редактирования звуковых файлов (Ogg Vorbis, FLAC, MP3 и WAV), записи и оцифровки звука, изменения параметров звукового файла, наложения треков и применения эффектов (например, подавление шума, изменение темпа и тона). Код Audacity распространяется под лицензией GPLv3, бинарные сборки доступны для Linux, Windows и macOS.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66209
read it on CSN:
https://csn.net4me.net/cyber_security_27918.html
🔘 OpenNet: Представлен дистрибутив Amazon Linux 2027
✉ 04.09.2026 13:10:11
💻 Компания Amazon начала тестирование дистрибутива Amazon Linux 2027 (AL2027), оптимизированного для облачных окружений и поддерживающего интеграцию с инструментами и расширенными возможностями сервиса Amazon EC2. В качестве основы задействована пакетная база Fedora Linux. Сборки формируются для архитектур x86_64 и ARM64 (Aarch64). Несмотря на первостепенную ориентацию на использование в AWS (Amazon Web Services), дистрибутив также поставляется в форме универсального образа виртуальной машины, который можно запустить на локальной системе или в других облачных окружениях.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66210
read it on CSN:
https://csn.net4me.net/cyber_security_27919.html
✉ 04.09.2026 13:10:11
💻 Компания Amazon начала тестирование дистрибутива Amazon Linux 2027 (AL2027), оптимизированного для облачных окружений и поддерживающего интеграцию с инструментами и расширенными возможностями сервиса Amazon EC2. В качестве основы задействована пакетная база Fedora Linux. Сборки формируются для архитектур x86_64 и ARM64 (Aarch64). Несмотря на первостепенную ориентацию на использование в AWS (Amazon Web Services), дистрибутив также поставляется в форме универсального образа виртуальной машины, который можно запустить на локальной системе или в других облачных окружениях.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66210
read it on CSN:
https://csn.net4me.net/cyber_security_27919.html
🔘 OpenNet: Выпуск Grml 2026.09, Live-дистрибутива для системных администраторов
✉ 04.09.2026 22:13:00
💻 Представлен выпуск Live-дистрибутива grml 2026.09, предлагающего подборку программ для выполнения работ, возникающих в практике системных администраторов, таких как восстановление данных после сбоя и разбор инцидентов. Дистрибутив основан на пакетной базе Debian GNU/Linux и в прошлом году отметил своё двадцатилетие. Графическое окружение построено с использованием оконного менеджера Fluxbox. По умолчанию предлагается командная оболочка Zsh. Размер полного iso-образа 1.1 ГБ, сокращённого - 643 МБ. Сборки доступны для архитектур x86_64 и ARM64.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66211
read it on CSN:
https://csn.net4me.net/cyber_security_27920.html
✉ 04.09.2026 22:13:00
💻 Представлен выпуск Live-дистрибутива grml 2026.09, предлагающего подборку программ для выполнения работ, возникающих в практике системных администраторов, таких как восстановление данных после сбоя и разбор инцидентов. Дистрибутив основан на пакетной базе Debian GNU/Linux и в прошлом году отметил своё двадцатилетие. Графическое окружение построено с использованием оконного менеджера Fluxbox. По умолчанию предлагается командная оболочка Zsh. Размер полного iso-образа 1.1 ГБ, сокращённого - 643 МБ. Сборки доступны для архитектур x86_64 и ARM64.
#csn #cyber_news
https://www.opennet.ru/opennews/art.shtml?num=66211
read it on CSN:
https://csn.net4me.net/cyber_security_27920.html