|
|
Your daily, AI-assisted cybersecurity intelligence brief.
|
|
|
|
Today's report
|
|
Source: Security Rabbits
|
The Rabbit's Foot (TLDR)
|
|
Check Point Quantum VPN Flaws Enable Unauthenticated RCE
Two 9.8-rated certificate validation flaws in Check Point Quantum Security Gateway allow unauthenticated remote code execution. Patch immediately and restrict VPN access.
|
|
|
MikroTik RouterOS Vulnerabilities Exploited (CISA KEV)
CISA flags actively exploited RouterOS flaws enabling kernel memory disclosure, DoS, and privilege escalation. Apply vendor mitigations and follow BOD 26-04 patching guidance.
|
|
|
WordPress Elementor Forms Plugin RCE Under Attack
Unauthenticated attackers can upload executable PHP files and achieve remote code execution on sites running Drag and Drop File Upload for Elementor Forms up to 1.6.0. Update immediately or disable the plugin.
|
|
|
Apache ActiveMQ Artemis Critical Authentication Bypass
Unauthenticated attackers can steal authenticated sessions or delete arbitrary queues via crafted packets, leading to full broker compromise. Upgrade to 2.57.0.
|
|
|
CISA Adds Cisco, Citrix, Fortinet Flaws to KEV with Sept 12 Deadline
Federal agencies must patch three actively exploited vulnerabilities by September 12. All organizations should prioritize these updates to prevent ransomware and state-sponsored attacks.
|
|
|
Source: CVE Trend
|
Trending vulnerability
|
|
|
Check Point Quantum Security Gateway
|
Published:
Updated:
|
Improper certificate trust validation during VPN negotiation in Check Point Quantum Security Gateway may allow an unauthenticated remote attacker to execute arbitrary code on the Gateway.
|
|
|
Source: CISA
|
CISA exploits
|
|
|
MikroTik RouterOS contains a missing authenticaion for critical function vulnerability which allows kernel memory disclosure and denial of service in the btest service.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.(2026-09-10)
|
|
|
|
MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.(2026-09-10)
|
|
|
Source: NIST
|
NIST CVE
|
|
|
Unauthenticated attackers can upload executable PHP files and achieve remote code execution on any site running this plugin up to 1.6.0. Update immediately or disable the plugin until patched.
|
|
|
|
An unauthenticated remote attacker can steal an existing authenticated session via a crafted CORE protocol SESSION_REATTACH packet, leading to full broker compromise. Upgrade to 2.57.0.
|
|
|
|
Unauthenticated remote attackers can delete arbitrary queues via a crafted Openwire RemoveSubscriptionInfo command before authentication. Upgrade to 2.57.0.
|
|
|
|
Unauthenticated network attackers can trigger a buffer overflow in XML processing, causing DoS on VM-Series or root code execution on PA-Series firewalls. Restrict management interface access and apply vendor patches.
|
|
|
|
Path traversal in template loading allows attackers to read arbitrary files when localized lookup is enabled (default). Upgrade to 2.3.35 or disable localized lookup.
|
|
|
|
The Kubernetes ingress-nginx provider mishandles Ingresses with both auth and from-to-www-redirect annotations, allowing unauthenticated requests to bypass authentication and IP allowlisting. Upgrade to v3.7.12.
|
|
|
|
With HTTP/3 enabled and backend NTLM/Negotiate auth, an unrelated client can reuse an authenticated backend connection and act as the victim. Upgrade to 2.11.57 or 3.7.13.
|
|
|
|
News
|
|
|
CISA: WatchGuard RCE flaw now exploited in ransomware attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. [...] (BleepingComputer)
|
|
|
Source: Ransomware.live
|
Ransomware attacks
|
|
|
On Demand Occupational Medicine \\ NcbChurch \\ Goldston Oil Corporation
|
|
|
|
Professional Retail Services \\ General Santos Doctors Hospital
|
|
|
|
Sys-kool \\ Grunthal Welding & Supplies
|
|
|
|
HARLEY-DAVIDSON.COM \\ HENRYPRATT.COM
|
|
|
|
mankatoclinic.com \\ artiflexmfg.com
|
|
|
|
George Cameron Nash \\ Eagle Construction \\ AK Stamping
|
|
|
Source: Hybrid Analysis
|
Top malicious URL
|
|
Source: Hybrid Analysis
|
Top malicious files
|
|