Today's report Older
Source: Security Rabbits
The Rabbit's Foot (TLDR)
Check Point Quantum VPN Flaws Enable Unauthenticated RCE
Two 9.8-rated certificate validation flaws in Check Point Quantum Security Gateway allow unauthenticated remote code execution. Patch immediately and restrict VPN access.
MikroTik RouterOS Vulnerabilities Exploited (CISA KEV)
CISA flags actively exploited RouterOS flaws enabling kernel memory disclosure, DoS, and privilege escalation. Apply vendor mitigations and follow BOD 26-04 patching guidance.
WordPress Elementor Forms Plugin RCE Under Attack
Unauthenticated attackers can upload executable PHP files and achieve remote code execution on sites running Drag and Drop File Upload for Elementor Forms up to 1.6.0. Update immediately or disable the plugin.
Apache ActiveMQ Artemis Critical Authentication Bypass
Unauthenticated attackers can steal authenticated sessions or delete arbitrary queues via crafted packets, leading to full broker compromise. Upgrade to 2.57.0.
CISA Adds Cisco, Citrix, Fortinet Flaws to KEV with Sept 12 Deadline
Federal agencies must patch three actively exploited vulnerabilities by September 12. All organizations should prioritize these updates to prevent ransomware and state-sponsored attacks.
Source: CVE Trend
Trending vulnerability
CVE-2026-85102
Check Point Quantum Security Gateway
    Published:
    Updated:




🥕 🥕 🥕
(29%)
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
Source: CISA
CISA exploits

MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.(2026-09-10)

MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.(2026-09-10)
Source: NIST
NIST CVE
Unauthenticated attackers can upload executable PHP files and achieve remote code execution on any site running this plugin up to 1.6.0. Update immediately or disable the plugin until patched.
An unauthenticated remote attacker can steal an existing authenticated session via a crafted CORE protocol SESSION_REATTACH packet, leading to full broker compromise. Upgrade to 2.57.0.
Unauthenticated remote attackers can delete arbitrary queues via a crafted Openwire RemoveSubscriptionInfo command before authentication. Upgrade to 2.57.0.
Unauthenticated network attackers can trigger a buffer overflow in XML processing, causing DoS on VM-Series or root code execution on PA-Series firewalls. Restrict management interface access and apply vendor patches.
Path traversal in template loading allows attackers to read arbitrary files when localized lookup is enabled (default). Upgrade to 2.3.35 or disable localized lookup.
The Kubernetes ingress-nginx provider mishandles Ingresses with both auth and from-to-www-redirect annotations, allowing unauthenticated requests to bypass authentication and IP allowlisting. Upgrade to v3.7.12.
With HTTP/3 enabled and backend NTLM/Negotiate auth, an unrelated client can reuse an authenticated backend connection and act as the victim. Upgrade to 2.11.57 or 3.7.13.
Other software at risk
\\   Advanced Product Fields Extended for WooCommerce \\   Anchor CMS \\   Angular \\   Armiya Access Control System \\   Autodesk Fusion Desktop \\   AVideo \\   Bosch Sensortec BHI360 SensorAPI \\   Bosch Sensortec BHI385 SensorAPI \\   Bosch Sensortec COINES_SDK \\   Bulk Password Reset (WordPress plugin) \\   Capgo \\   ConfigServer Security & Firewall \\   Consul \\   consul-template \\   Countly Server \\   Craft CMS \\   crun \\   CyberPanel \\   Dell ThinOS 10 \\   Direct Download for WooCommerce \\   ESP32-audioI2S \\   FileRun \\   Flowise \\   Forgejo \\   Gemini CLI \\   GeoVision GV-LPC2211 \\   GisLab Laboratory Management System \\   gvfs \\   HikCentral Access Control \\   IBM App Connect Enterprise \\   IBM Aspera Enterprise WebApps \\   IBM Common Licensing Agent \\   IBM ContextForge MCP Gateway \\   IBM DataStage on Cloud Pak for Data \\   IBM Db2 \\   IBM Langflow OSS \\   IBM webMethods Integration Server \\   ICEcoder \\   ION-DTN \\   isomorphic-git \\   jose (OCaml) \\   knowns \\   Lenovo Filez Client \\   Lenovo File Manager Android Application \\   Lenovo Health Android Application \\   Lenovo Software Fix \\   libXfont2 \\   LIBRID/LIBREF \\   MailMunch \\   MISP \\   miniOrange 2FA \\   MongoDB integration for Laravel \\   MongoDB PHP Library \\   MongoDB Rust Driver \\   MongoDB C# Driver \\   MongoDB Python Driver \\   MongoDB Ruby Driver \\   MongoDB Go Driver \\   MongoDB Java Driver \\   MongoDB C++ Driver \\   MongoDB C Driver \\   Netskope Endpoint DLP \\   NI SystemLink \\   Nintendo Switch \\   OpenNMS Horizon \\   OpenPanel \\   OmniRoute \\   Page Visits Counter – Lite \\   passport-saml-encrypted \\   Pavlok Behavioral Conditioning Wearable \\   Plesk \\   rclone \\   Registration Form for WooCommerce \\   Renovate \\   RepairBuddy \\   Return Refund and Exchange For WooCommerce \\   Rizwan17 inventory-management-system \\   Shirt Product Designer for WooCommerce \\   Sidebar Manager Light \\   Site Reviews \\   SiteSkite \\   SP Property \\   Suricata \\   t-digest \\   Tesseract \\   Thank You Page Customizer for WooCommerce \\   Tianxi AI Agent PC Application \\   Traefik \\   Ultimate Gift Cards for WooCommerce
News
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars
Here's a tip for any budding cybercriminals out there. If you're going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don't broadcast on a group chat every time you buy a Lamborghini, or blow half a million dollars on a [...] (GRAHAM CLULEY)
AI-powered attack exploited PaperCut flaws to hack 395 organizations
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. [...] (BleepingComputer)
Conti ransomware gang member sentenced to 4 years in prison
A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...] (BleepingComputer)
New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. [...] (BleepingComputer)
CISA Updates Insider Threat Guide With New Mitigation Advice
CISA has updated its insider threat guide with new advice on remote work, AI and risk detection (Unsourced)
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
The new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actors (Unsourced)
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that [...] (The Hacker News)
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) [...] (The Hacker News)
CISA: WatchGuard RCE flaw now exploited in ransomware attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. [...] (BleepingComputer)
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [...] (BleepingComputer)
Source: Ransomware.live
Ransomware attacks
🛡️ Wallstreet
On Demand Occupational Medicine  \\ NcbChurch  \\ Goldston Oil Corporation
⚔️ Vexy Ransomware
i2k2 Networks
🕳️ ShadowByt3$
John Engel Team
🐛 rhysida
Professional Retail Services  \\ General Santos Doctors Hospital
💀 play
Sys-kool  \\ Grunthal Welding & Supplies
🦨 lockbit5
alphaomega-eng.com
⚠️ incransom
jms building corporation
🧠 Global Secret Group
CO-OP URBAN BANK LTD
👿 emperador
EASY JOB S.A.S.
🐛 clop
HARLEY-DAVIDSON.COM  \\ HENRYPRATT.COM
🧟 chaos
mankatoclinic.com  \\ artiflexmfg.com
💻 AuditTeam
ki***jp  \\ my***ru
🔒 akira
George Cameron Nash  \\ Eagle Construction  \\ AK Stamping
Source: Hybrid Analysis
Top malicious URL
Source: Hybrid Analysis
Top malicious files