About this episode
A busy week of active exploitation against management and developer infrastructure, attacks on sessions and trusted delivery paths, major personal-data exposure, and the expanding role of AI as both target and tool.
This episode brings together the week’s most relevant cybersecurity stories and their operational context for defenders.
Play the episode, then review the stories and chapter list for the reporting and topics covered.
Stories covered this week
Critical MikroTik SSH Authentication Bypass Vulnerability Exploited
MikroTik has released a patch for a critical SSH authentication bypass vulnerability that is actively being exploited. Attackers are adding new accounts to maintain access even after patching.
Source: SANS ISC
N-able patches critical RCE flaw in N-central amid active exploitation
N-able has issued an emergency hotfix for a maximum-severity remote code execution vulnerability in its N-central RMM platform, which is currently under active attack. The flaw allows attackers to execute arbitrary code remotely, posing significant security risks to managed environments.
Source: BleepingComputer
Microsoft September 2026 Patch Tuesday fixes 966 flaws and 2 zero-days
Microsoft's September 2026 Patch Tuesday updates address a record 966 vulnerabilities, including two zero-day exploits actively targeted in the wild. This update is critical for all organizations using Microsoft products to apply promptly.
Source: BleepingComputer
Cisco confirms active exploitation of critical FMC authentication bypass flaw
Cisco has confirmed active exploitation of a critical authentication bypass vulnerability (CVE-2026-20079) in its Secure Firewall Management Center software. This flaw allows attackers to bypass authentication, posing significant risks to enterprise defenses.
Source: BleepingComputer
Cisco FMC Flaws Exploited by Ransomware and State Hackers
Cisco Talos reports that two patched vulnerabilities in Secure Firewall Management Center have been actively exploited by ransomware gangs and state-sponsored threat actors. These exploits impact critical network security infrastructure used by many enterprises.
Source: BleepingComputer
GitLab CVSS 10 File-Read Flaw Faces In-the-Wild Probes
GitLab released patches for multiple flaws including a critical CVSS 10.0 path traversal vulnerability in its repository commits API, exploited within hours. This flaw allows unauthenticated users to read arbitrary files on GitLab servers.
Source: The Hacker News
Critical Artifactory Flaws Exploited to Deploy Rust Backdoor Malware
Attackers are chaining critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain admin access, and install a Rust-based backdoor on self-hosted servers. These exploits target vulnerable deployments, posing a significant risk to enterprise environments.
Source: BleepingComputer
Passkey-themed Social Engineering Enables Identity and Cloud Compromise
Attackers use passkey-themed social engineering to bypass MFA, abusing Microsoft Graph for reconnaissance and accessing SharePoint, OneDrive, and email data. Key detection and mitigation strategies are provided to protect against these advanced identity and cloud attacks.
Source: Microsoft
Attackers Use Invisible Unicode Characters to Bypass Email Filters
Threat actors are employing the ASCII smuggling technique by inserting invisible Unicode characters into phishing emails to evade detection by security filters. This new tactic complicates the identification of phishing lures and poses a significant risk to email security.
Source: BleepingComputer
Four Spy Groups Deploy BlueMoon Exploit Kit Targeting Chrome and Windows
Four espionage-linked threat groups have been found using a new BlueMoon exploit kit chaining multiple Chrome and Windows vulnerabilities. The first in-the-wild use is linked to the China-aligned APT31 group.
Source: The Hacker News
AI-driven attack exploits PaperCut flaws to breach 395 organizations
A Russian-speaking threat actor used hundreds of AI agents to launch a global campaign exploiting vulnerabilities in PaperCut NG/MF servers, compromising 395 organizations. This highlights the evolving use of AI in orchestrating complex cyberattacks on enterprise infrastructure.
Source: BleepingComputer
China-Linked UNC3569 Exploits Sogou Input Method Flaw for GRAYRABBIT Backdoor
China-linked threat group UNC3569 exploited a vulnerability in the widely used Sogou Input Method on Windows to deploy the GRAYRABBIT backdoor. The attack begins with a crafted link and grants attackers full control of the logged-in user's machine.
Source: The Hacker News
Cloud Security Risks Vary Significantly Across Providers, New Data Shows
A 2026 Cloud Security Index analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud, revealing that each cloud provider exhibits unique risk profiles. This challenges conventional multi-cloud security approaches and checklists.
Source: The Hacker News
REVSTEALER Modules Disable Windows Defender to Run Crypto Miner
Elastic Security Labs uncovered four programs linked to the REVSTEALER information stealer that disable Windows Update and Defender before deploying a cryptocurrency miner. These modules persist on infected machines even after the main stealer deletes itself.
Source: The Hacker News
5,400+ hacked sites deliver ClickFix malware via blockchain storage
Over 5,400 small-business websites have been compromised to distribute ClickFix malware payloads stored in smart contracts on the BNB Smart Chain. This innovative technique leverages blockchain to evade detection and complicate takedowns.
Source: BleepingComputer
JSCeal Malware Can Bypass Google Auth Using Stolen Session Cookies
JSCeal is a sophisticated compiled V8 JavaScript malware that can harvest credentials, perform surveillance, and intercept traffic, bypassing Google authentication via stolen session cookies. It uses advanced obfuscation techniques like RC4 encryption and control-flow flattening to evade detection.
Source: The Hacker News
BigBear Phishing Service Bypasses MFA at 258 Organizations
The BigBear 2.0 phishing-as-a-service framework has bypassed multi-factor authentication at 258 organizations, stealing over 5,000 Microsoft 365 credentials. This campaign highlights ongoing risks to MFA security in enterprise environments.
Source: BleepingComputer
Hackers Deploy Linux Rootkit on F5 BIG-IP APM Devices
A Linux rootkit is actively exploited to breach F5 BIG-IP APM devices, injecting fileless web shells directly into memory by intercepting PHP file loading. This technique avoids disk writes, complicating detection and response efforts.
Source: BleepingComputer
JetBrains Cadence Breached via Unpatched TeamCity, AWS Credentials Exposed
Attackers exploited a critical unpatched vulnerability in JetBrains TeamCity to breach the Cadence environment and extract AWS credentials. JetBrains urges immediate revocation and rotation of all related credentials to mitigate impact.
Source: The Hacker News
AdaptHealth Confirms Data Exposure of 4.1 Million in July Cyberattack
Healthcare provider AdaptHealth confirmed that 4.1 million people's data was exposed in a July cyberattack linked to the ShinyHunters threat group. The breach highlights ongoing risks targeting healthcare organizations.
Source: BleepingComputer
IDScan Confirms Breach Affecting 153 Million Driver’s License Records
IDScan verified that hackers accessed customer data on its cloud platform following reports of a massive leak containing over 153 million driver’s license scans. This compromise exposes highly sensitive personal identity information.
Source: BleepingComputer
Securing Edge AI in Customer-Owned Environments
As AI deployment expands into customer-owned environments, organizations face new challenges in verifying trusted systems and software before exposing sensitive data and AI models. Microsoft outlines key strategies to secure edge AI assets against potential threats.
Source: Microsoft
U.S. Agencies Accuse China AI Firms of Distilling Major AI Models
U.S. cybersecurity and intelligence agencies accuse China-based AI firms of conducting industrial-scale distillation attacks on proprietary models like Claude, GPT, Gemini, and Grok. This extraction forms the core of their AI development strategy.
Source: The Hacker News
Microsoft Flags AI-Driven Executive Impersonation and Invoice Fraud
Microsoft reveals an AI-assisted business email compromise campaign that targets finance teams using executive impersonation and fake invoices to commit ACH fraud. The attack highlights the evolving threat landscape combining AI and social engineering.
Source: Microsoft
AI Agent Exploits and Aggregates Stolen LLM Access via Insecure Gateways
An attacker uses a semi-autonomous AI coding agent to identify and exploit vulnerable LLM resale APIs, harvesting inference capacity and consolidating it behind their own gateway. This operation leverages common web flaws and account farming to monetize stolen AI access.
Source: SANS ISC
Hackers Exploited Claude AI to Extract Secrets from 1.8M Android Apps
Threat actors, including Russian and Chinese state-sponsored groups, abused Anthropic's Claude AI model to extract sensitive data from 1.8 million Android apps. This abuse highlights increasing risks in AI model misuse by advanced adversaries.
Source: BleepingComputer
Chapters
- Opening
- Cisco confirms active exploitation of critical FMC authentication bypass flaw
- Cisco FMC Flaws Exploited by Ransomware and State Hackers
- N-able patches critical RCE flaw in N-central amid active exploitation
- Critical MikroTik SSH Authentication Bypass Vulnerability Exploited
- Hackers Deploy Linux Rootkit on F5 BIG-IP APM Devices
- Microsoft September 2026 Patch Tuesday fixes 966 flaws and 2 zero-days
- AI-driven attack exploits PaperCut flaws to breach 395 organizations
- GitLab CVSS 10 File-Read Flaw Faces In-the-Wild Probes
- Critical Artifactory Flaws Exploited to Deploy Rust Backdoor Malware
- JetBrains Cadence Breached via Unpatched TeamCity, AWS Credentials Exposed
- Four Spy Groups Deploy BlueMoon Exploit Kit Targeting Chrome and Windows
- China-Linked UNC3569 Exploits Sogou Input Method Flaw for GRAYRABBIT Backdoor
- 5,400+ hacked sites deliver ClickFix malware via blockchain storage
- Attackers Use Invisible Unicode Characters to Bypass Email Filters
- Passkey-themed Social Engineering Enables Identity and Cloud Compromise
- BigBear Phishing Service Bypasses MFA at 258 Organizations
- JSCeal Malware Can Bypass Google Auth Using Stolen Session Cookies
- REVSTEALER Modules Disable Windows Defender to Run Crypto Miner
- Microsoft Flags AI-Driven Executive Impersonation and Invoice Fraud
- IDScan Confirms Breach Affecting 153 Million Driver’s License Records
- AdaptHealth Confirms Data Exposure of 4.1 Million in July Cyberattack
- Hackers Exploited Claude AI to Extract Secrets from 1.8M Android Apps
- AI Agent Exploits and Aggregates Stolen LLM Access via Insecure Gateways
- Securing Edge AI in Customer-Owned Environments
- Cloud Security Risks Vary Significantly Across Providers, New Data Shows
- U.S. Agencies Accuse China AI Firms of Distilling Major AI Models
- Closing