Today's report Older
Source: Security Rabbits
The Rabbit's Foot (TLDR)
Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-XXXXX)
Unauthenticated remote attackers can bypass authentication via URI encoding manipulation and gain admin access to the SD-WAN Manager API. Patch immediately; this is a critical network infrastructure component.
WatchGuard Fireware OS Remote Code Execution
An attacker controlling a remote VPN server can execute arbitrary commands as root on the connecting Firebox via BOVPN Over TLS client configuration handling. Update Fireware OS immediately.
Apache MINA SSHD Authentication Bypass
Authentication bypass in sshd-core allows skipping signature checks in public-key or hostbased authentication for servers using asynchronous authentication. Upgrade to 2.20.0 or 3.0.0-M6.
Apache WSS4J Authentication Bypass
Unauthenticated remote attackers can forge authenticated SOAP messages via crafted unsigned SAML assertions. Upgrade to 4.0.2, 3.0.6, or 2.4.4.
Zammad Session Hijack Leading to RCE
Session hijack vulnerability leads to remote code execution as the zammad user in versions 6.3.0 to 6.5.4. Update to the latest patched version immediately.
Source: CVE Trend
Trending vulnerability
CVE-2023-3519
I don't have enough information to determine the impacted software. The text "Unauthenticated remote code execution" is a generic vulnerability description that could apply to countless software products. Without a CVE ID, vendor name, product name, or additional context, there's no way to identify the specific software.
    Published:
    Updated:

🥕 ⚪ ⚪ ⚪ ⚪ ⚪ ⚪ ⚪ ⚪ ⚪
(14%)
Unauthenticated remote code execution
Source: Have I been pwned?
Have I been pwnd
Medela
(medela.com)
    Count: 423,947
    Published: 2026-09-07
    Updated: 2026-09-30




In September 2026, Swiss medical device company Medela was the target of a ShinyHunters "pay or leak" extortion campaign. The data allegedly obtained in the breach was later published publicly and included 424k unique email addresses belonging predominantly to healthcare professionals, Medela staff and leads. The exposed data consisted primarily of corporate contact information, including names, physical addresses and phone numbers, with some records also containing associated support tickets.
Source: CISA
CISA exploits

Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.(2026-09-30)
Source: NIST
NIST CVE
Unauthenticated remote attackers can bypass authentication via URI encoding manipulation and gain admin access to the SD-WAN Manager API. Patch immediately; this is a critical network infrastructure component.
An attacker controlling a remote VPN server can execute arbitrary commands as root on the connecting Firebox via BOVPN Over TLS client configuration handling. Update Fireware OS immediately.
Authentication bypass in sshd-core allows skipping signature checks in public-key or hostbased authentication for servers using asynchronous authentication. Upgrade to 2.20.0 or 3.0.0-M6.
LDAP injection in sshd-ldap allows authentication bypass with username and password '*'. Upgrade to 2.20.0 or 3.0.0-M6 if using the LDAP component.
Authentication bypass allows unauthenticated remote attackers to forge authenticated SOAP messages via crafted unsigned SAML assertions. Upgrade to 4.0.2, 3.0.6, or 2.4.4.
Improper signature verification and certificate validation in the OPC UA driver allow man-in-the-middle attackers to impersonate servers and read/modify secure-channel traffic. Upgrade to 1.0.0.
Session hijack vulnerability leads to remote code execution as the zammad user in versions 6.3.0 to 6.5.4. Update to the latest patched version immediately.
Other software at risk
\\   AiSOC \\   AJA HELO Plus \\   Apache PLC4X \\   Apache WSS4J \\   apcupsd \\   Astro \\   baserCMS \\   basic-ftp \\   BVMS \\   Cato Networks SDP Client \\   CODESYS Gateway Client \\   CRI-O \\   Deno \\   EasyFlow .NET \\   Gosub browser engine \\   Grouper \\   Handlebars.java \\   iDocView \\   iperf3 \\   JetBrains Hub \\   JetBrains IntelliJ IDEA \\   JetBrains TeamCity \\   JetBrains YouTrack \\   Joomla JCTables \\   Joomla OrdaSoft CCK \\   Kiteworks \\   Kiteworks Core \\   Kiteworks Email Protection Gateway \\   Kiteworks Secure Data Forms \\   Kobako \\   LightLLM \\   LiteSpeed Web Server \\   MediaWiki CentralAuth extension \\   MediaWiki Wikibase extension \\   MediaWiki WikiLambda extension \\   MineAdmin \\   MISP \\   modelscope Agentscope \\   MQTT WebSocket \\   NVIDIA GPU Display Driver \\   NVIDIA Linux GPU Display Driver \\   NVIDIA NVAPI \\   NVIDIA vGPU Manager \\   NVIDIA vGPU software \\   NVIDIA vGPU Virtual GPU Manager \\   NVIDIA Virtual GPU Manager \\   oc-mirror \\   OpenBSD ldapd \\   OpenClaw Windows Node \\   OpenSave \\   PCRE2 \\   Pexip Infinity \\   Pgpool-II \\   piscina \\   PTZOptics cameras \\   pypdf
News
Attacker signs up as a member to plant webshells on parks and recreation platform, hunts for card data
Security researchers at Huntress have detailed a multi-stage intrusion in which a threat actor compromised three web servers belonging to a popular recreation management platform used by local municipalities and parks organisations, planting [...] (IT Security Guru)
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September [...] (The Hacker News)
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google [...] (The Hacker News)
Trump, Six AI Giants Sign 'Super Intelligence' Safety Accord
Trump and six AI firms sign a voluntary accord on internal controls, audits and board oversight (Unsourced)
Trump, Tech Giants Strike Voluntary AI Safety Accord
The new White House Accord on so-called "Super Intelligence" calls on companies to implement greater controls and oversight over AI safety. (darkreading)
A Vulnerability in Cisco Catalyst SD-WAN Manager Could Allow for Authentication Bypass
A vulnerability has been discovered in Cisco Catalyst SD-WAN Manager (formerly SD-WAN vManage) that could allow for authentication bypass. Cisco Catalyst SD-WAN Manager is the centralized dashboard used to monitor and manage SD-WAN fabric devices, [...] (Cyber Security Advisories - MS-ISAC)
AI-Found Vulnerabilities More Likely to Enable RCE, Google Says
AI-discovered vulnerabilities are more likely to enable RCE, as disclosures and exploitation rise (Unsourced)
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted [...] (The Hacker News)
AI Boosts SOC Analyst Capacity but Limits Skill Development
Swimlane finds that AI is reducing repetitive work for SOC teams but some feel their careers may suffer (Unsourced)
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 [...] (The Hacker News)
Source: Ransomware.live
Ransomware attacks
⚔️ Vexy Ransomware
Summit Electric Supply
🐀 ULose
www.newyjh.com
🛑 thegentlemen
Drinks Wines Spirits  \\ LegalWise  \\ Edcon  \\ Europrim  \\ Groupe APROSEP  \\ Josee Bendaaa-Guerrero Asociados  \\ Agospap  \\ Northern NJ Eye Institute  \\ Pulmonary Services Group  \\ QUALITY SPORT Topsport Italia  \\ Samwumed  \\ Solaria  \\ Telrad Networks  \\ Tommy Garner Air Conditioning Heating  \\ VUS - The English Center  \\ Webb Electric Company of Florida  \\ Williamson Dacar Associates  \\ Corswarem Group  \\ Defencebit  \\ DBU Construction  \\ Don Hierro  \\ Auren  \\ Auto Holler  \\ Datacomm Services  \\ Custom Rx Shoppe
🧠 Storm
Olnick Rentals  \\ Century Management Services  \\ Poca Valley Bank  \\ Silvercup Studios  \\ Stockham Construction  \\ UC Components  \\ Vintners Distributors  \\ West County Health Centers  \\ Agra Industries  \\ North Hills Facility Services  \\ Gardeners' Guild
🧱 settra
dfiretailgroup.com
🤖 safepay
econ-tec.com  \\ wolfusofsky.de  \\ assist2enjoy.be
🐛 rhysida
clicks digital GmbH Information  \\ Law Offices of R. David Williams, P.A.
💀 play
Titus  \\ Orth Automobile  \\ Airtech Mechanical Services
🧨 pear
Software Answers, a Banyan Software Company
⚠️ netrunner
P***** M***** I**
🛑 N0n
Houston Thyroid & Endocrine Specialists  \\ MCAP — MortgageHub commercial lending platform
🧱 lamashtu
Altmannshofer Sicherheits-Videotechnik  \\ Wilhelm Kühne  \\ Virtual Ideas  \\ Dr Damiel Pugliese  \\ Vinco Energy  \\ FIDUCIAL  \\ Astidental di Sabbione  \\ GERLON  \\ Becker Logistik  \\ PROJAHN
🧬 kairos
Le Centre National de l'Expertise Hospitalière (CNEH)
🐉 interlock
Blaise C. Bender, PC
👿 emperador
SitePro Rentals
💀 Eclipse
The Japan Times
🫥 aurora
Buford-Thompson Company, LTD