2026-09-09 08:50 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-09 09:30 UTC
PoisonedRefresh rootkit injects PHP web shells into F5 BIG-IP APM Apache memory, leaving no disk artifacts. SophosLabs published a detailed technical analysis on September 8, 2026, of a Linux implant, dubbed PoisonedRefresh by ESET, they found in compromised F5 BIG-IP Access Policy Manager environments. Sophos tracks it as Linux/Agnt-IC. F5 has confirmed exploitation of the […]
P0
2026-09-09 08:44 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-09 08:45 UTC
An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content. [...]
P0
2026-09-09 08:19 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 09:30 UTC
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.
P0
2026-09-09 07:53 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-09 08:30 UTC
The researcher Chaotic Eclipse released ShieldCrash, a PoC exploit for a Microsoft Defender Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit ShieldCrash, it triggers an arbitrary file read as SYSTEM. The researcher claims that Microsoft has not fully […]
P25
2026-09-09 07:36 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 09:30 UTC
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are
P0
2026-09-09 07:30 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-09 07:50 UTC
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]
P30
2026-09-09 07:06 UTC
Other
Group-IB · indexed 2026-09-09 07:35 UTC
How the Gigabud Android banking trojan abuses Shelter, an open-source app cloner, and what that means for banks, users, and defenders.
P0
2026-09-09 07:03 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-09 07:10 UTC
September 2026 Patch Tuesday fixes a record 974 CVEs including 2 exploited zero-days, 20 wormable bugs, and a critical Exchange RCE via Visio email. Microsoft’s September 2026 Patch Tuesday set a new record. Depending on how researchers count external and Chromium bugs, Microsoft fixed between 966 and 997 CVEs in this update. The company also […]
P40
2026-09-09 06:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 09:30 UTC
The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic
P30
2026-09-09 06:25 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-09 06:35 UTC
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...]
P45
2026-09-09 06:25 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 09:30 UTC
SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP
P20
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of VMware Workstation. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-59346.
P15
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-8037.
P20
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiSandbox. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-84387.
P20
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-60155.
P15
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-60162.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-60159.
P15
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.1. The following CVEs are assigned: CVE-2026-71114.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows local attackers to disclose sensitive information on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3. The following CVEs are assigned: CVE-2026-71132.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle VirtualBox. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-71116.
P15
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60414.
P20
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60413.
P20
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:50 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60412.
P20
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:30 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Oracle Outside In Technology. User interaction is required to exploit this vulnerability in that the target must open a malicious file or visit a malicious page. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-60392.
P20
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:30 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Flowise. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 9.8. The following CVEs are assigned: CVE-2026-70477.
P20
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:30 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-4153.
P20
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:30 UTC
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-13086.
P20
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:30 UTC
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-18444.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:30 UTC
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NI LabVIEW. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-18445.
P5
2026-09-09 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-09 22:30 UTC
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Microsoft Azure. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.8.
P0