|
|
Your daily, AI-assisted cybersecurity intelligence brief.
|
|
|
|
Today's report
|
|
Source: Security Rabbits
|
The Rabbit's Foot (TLDR)
|
|
Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-XXXXX)
Unauthenticated remote attackers can bypass authentication via URI encoding manipulation and gain admin access to the SD-WAN Manager API. Patch immediately; this is a critical network infrastructure component.
|
|
|
WatchGuard Fireware OS Remote Code Execution
An attacker controlling a remote VPN server can execute arbitrary commands as root on the connecting Firebox via BOVPN Over TLS client configuration handling. Update Fireware OS immediately.
|
|
|
Apache MINA SSHD Authentication Bypass
Authentication bypass in sshd-core allows skipping signature checks in public-key or hostbased authentication for servers using asynchronous authentication. Upgrade to 2.20.0 or 3.0.0-M6.
|
|
|
Apache WSS4J Authentication Bypass
Unauthenticated remote attackers can forge authenticated SOAP messages via crafted unsigned SAML assertions. Upgrade to 4.0.2, 3.0.6, or 2.4.4.
|
|
|
Zammad Session Hijack Leading to RCE
Session hijack vulnerability leads to remote code execution as the zammad user in versions 6.3.0 to 6.5.4. Update to the latest patched version immediately.
|
|
| Source: CVE Trend
|
Trending vulnerability
|
|
|
I don't have enough information to determine the impacted software. The text "Unauthenticated remote code execution" is a generic vulnerability description that could apply to countless software products. Without a CVE ID, vendor name, product name, or additional context, there's no way to identify the specific software.
|
Published:
Updated:
|
Unauthenticated remote code execution
|
|
| Source: Have I been pwned?
|
Have I been pwnd
|
Medela (medela.com)
|
Count: 423,947
|
Published: 2026-09-07
Updated: 2026-09-30
|
In September 2026, Swiss medical device company Medela was the target of a ShinyHunters "pay or leak" extortion campaign. The data allegedly obtained in the breach was later published publicly and included 424k unique email addresses belonging predominantly to healthcare professionals, Medela staff and leads. The exposed data consisted primarily of corporate contact information, including names, physical addresses and phone numbers, with some records also containing associated support tickets.
|
|
| Source: CISA
|
CISA exploits
|
|
|
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.(2026-09-30)
|
|
| Source: NIST
|
NIST CVE
|
|
|
Unauthenticated remote attackers can bypass authentication via URI encoding manipulation and gain admin access to the SD-WAN Manager API. Patch immediately; this is a critical network infrastructure component.
|
|
|
|
An attacker controlling a remote VPN server can execute arbitrary commands as root on the connecting Firebox via BOVPN Over TLS client configuration handling. Update Fireware OS immediately.
|
|
|
|
Authentication bypass in sshd-core allows skipping signature checks in public-key or hostbased authentication for servers using asynchronous authentication. Upgrade to 2.20.0 or 3.0.0-M6.
|
|
|
|
LDAP injection in sshd-ldap allows authentication bypass with username and password '*'. Upgrade to 2.20.0 or 3.0.0-M6 if using the LDAP component.
|
|
|
|
Authentication bypass allows unauthenticated remote attackers to forge authenticated SOAP messages via crafted unsigned SAML assertions. Upgrade to 4.0.2, 3.0.6, or 2.4.4.
|
|
|
|
Improper signature verification and certificate validation in the OPC UA driver allow man-in-the-middle attackers to impersonate servers and read/modify secure-channel traffic. Upgrade to 1.0.0.
|
|
|
|
Session hijack vulnerability leads to remote code execution as the zammad user in versions 6.3.0 to 6.5.4. Update to the latest patched version immediately.
|
|
|
|
News
|
| Source: Ransomware.live
|
Ransomware attacks
|
|
|
Drinks Wines Spirits \\ LegalWise \\ Edcon \\ Europrim \\ Groupe APROSEP \\ Josee Bendaaa-Guerrero Asociados \\ Agospap \\ Northern NJ Eye Institute \\ Pulmonary Services Group \\ QUALITY SPORT Topsport Italia \\ Samwumed \\ Solaria \\ Telrad Networks \\ Tommy Garner Air Conditioning Heating \\ VUS - The English Center \\ Webb Electric Company of Florida \\ Williamson Dacar Associates \\ Corswarem Group \\ Defencebit \\ DBU Construction \\ Don Hierro \\ Auren \\ Auto Holler \\ Datacomm Services \\ Custom Rx Shoppe
|
|
|
|
Olnick Rentals \\ Century Management Services \\ Poca Valley Bank \\ Silvercup Studios \\ Stockham Construction \\ UC Components \\ Vintners Distributors \\ West County Health Centers \\ Agra Industries \\ North Hills Facility Services \\ Gardeners' Guild
|
|
|
|
econ-tec.com \\ wolfusofsky.de \\ assist2enjoy.be
|
|
|
|
clicks digital GmbH Information \\ Law Offices of R. David Williams, P.A.
|
|
|
|
Titus \\ Orth Automobile \\ Airtech Mechanical Services
|
|
|
|
Software Answers, a Banyan Software Company
|
|
|
|
Houston Thyroid & Endocrine Specialists \\ MCAP — MortgageHub commercial lending platform
|
|
|
|
Altmannshofer Sicherheits-Videotechnik \\ Wilhelm Kühne \\ Virtual Ideas \\ Dr Damiel Pugliese \\ Vinco Energy \\ FIDUCIAL \\ Astidental di Sabbione \\ GERLON \\ Becker Logistik \\ PROJAHN
|
|
|
|
Le Centre National de l'Expertise Hospitalière (CNEH)
|
|
|
|
Buford-Thompson Company, LTD
|
|
|
|