Why Should I Care? โ 2026-09-12 | ๐ด 2 HIGH ยท ๐ก 0 MEDIUM ยท ๐ต 16 RADAR ยท โช 72 FILTERED
๐ Briefing โ 2026-09-12
18 vendor intel items scanned | ๐ด 2 HIGH | ๐ก 0 MEDIUM | ๐ต 16 RADAR | โช 72 FILTERED
๐ด Critical โ action required:
- CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-85706) โ Yes, if you run GitLab Community Edition or Enterprise Edition versions 14.2.0 to 14.10.5: this path traversal vulnerability allows attackers to access sensitive files and directories.
- CISA Adds Three Known Exploited Vulnerabilities to Catalog (CVE-2026-42016, CVE-2026-42018, CVE-2026-84869) โ Yes, if you run JFrog Artifactory or ConnectWise ScreenConnect versions affected by the listed CVEs: these vulnerabilities are actively exploited and pose significant risks.
Everything else can wait.
๐ต 15 items on the radar โ see below โ
Why Should I Care? ๐ด HIGH โ Handle Now
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Advisories [CISA KEV] | CVSS 8.8 | CVE-2026-85706
โ Why Should I Care?
Yes, if you run GitLab Community Edition or Enterprise Edition versions 14.2.0 to 14.10.5: this path traversal vulnerability allows attackers to access sensitive files and directories.
๐ฏ Affected versions: 14.2.0 to 14.10.5
Not affected: 14.10.6 and later
๐ญ In plain English:
This vulnerability means an attacker can trick the system into revealing files and directories it shouldn't, like sensitive configuration files or user data. For example, an attacker could access and steal sensitive configuration files that contain database passwords.
๐ง Prerequisites:
- Running GitLab versions 14.2.0 to 14.10.5
- Publicly exposed GitLab instance
โฑ Urgency: High urgency due to active exploitation and the risk of total control over the asset post-exploitation.
โ Fixed in: 14.10.6, 14.11.0
๐ก Context: The root cause is improper validation of user input that is used to construct file paths.
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA Advisories [CISA KEV] | CVE-2026-42016, CVE-2026-42018, CVE-2026-84869
โ Why Should I Care?
Yes, if you run JFrog Artifactory or ConnectWise ScreenConnect versions affected by the listed CVEs: these vulnerabilities are actively exploited and pose significant risks.
๐ฏ Affected versions: JFrog Artifactory versions prior to 7.28.5, ConnectWise ScreenConnect versions prior to 12.3.4
Not affected: JFrog Artifactory 7.28.5 and later, ConnectWise ScreenConnect 12.3.4 and later
๐ญ In plain English:
These vulnerabilities allow attackers to gain unauthorized access to your systems and escalate privileges, potentially taking full control. For example, an attacker could log in as an admin and steal sensitive data or deploy malware.
๐ง Prerequisites:
- Running an affected version of JFrog Artifactory or ConnectWise ScreenConnect
- Publicly exposed services
โฑ Urgency: High urgency due to active exploitation and the risk of full system compromise.
โ Fixed in: 7.28.5, 12.3.4
๐ก Context: The vulnerabilities stem from flaws in the authentication and authorization mechanisms, allowing unauthorized access and privilege escalation.
Why Should I Care? ๐ก MEDIUM (0)
None.
Why Should I Care? ๐ต On the Radar (16)
- GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure (The Hacker News) โ A critical flaw in GitLab allows attackers to read files without authentication, impacting versions 18.7 to 19.3.2. This could expose sensitive data like credentials and configuration files.
- Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware (The Hacker News) โ Cisco FMC software has critical flaws that allow attackers to bypass authentication and steal credentials, potentially deploying ransomware. This impacts network security and could lead to significant data breaches.
- Florida confirms DMV database breached via stolen police account (BleepingComputer) โ A Florida DMV database was breached due to stolen police credentials, highlighting the risks of improper credential storage and the potential for large-scale data leaks. This could impact millions of individuals' personal information.
- Artifactory flaws chained in attacks deploying backdoor malware (BleepingComputer) โ Hackers are using known flaws in JFrog Artifactory to gain unauthorized access and install backdoor malware, potentially compromising your data and systems.
- GitLab urges users to patch max severity path traversal flaw (BleepingComputer) โ GitLab has a critical vulnerability that allows attackers to read sensitive files without needing to authenticate. This affects both Community and Enterprise Editions, and it's already being probed by attackers.
- PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws (The Hacker News) โ PaperCut has released new security updates for their NG/MF software that fix two critical flaws being actively exploited by attackers. These flaws could allow unauthorized access and code execution on your systems.
- China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor (The Hacker News) โ A hacking group exploited a flaw in Sogou Input Method to install a backdoor on victims' computers. This means if you use Sogou Input Method on Windows, your system could be compromised by attackers who can do anything the logged-in user can do.
- Trezor: 347,000 users targeted in phishing attacks after Brevo breach (BleepingComputer) โ Trezor users were targeted in a phishing attack after their email provider, Brevo, was breached. The attackers sent fake security alert emails to 347,000 users, and 2,500 users clicked on a malicious link.
- Passkey-themed phishing attacks lead to Microsoft 365 data theft (BleepingComputer) โ Cybercriminals are using passkey and single sign-on-themed phishing attacks to steal data from Microsoft 365. They impersonate IT help desks to trick employees into entering credentials on fake login pages.
- Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection (The Hacker News) โ Russian state-sponsored hackers are using AI to rebuild malware after detection, targeting government and defense organizations. This makes it harder for security products to block their attacks.
- Claude Used to Automate Exploitation and Data Theft Across Multiple Victims (The Hacker News) โ Cybercriminals and state-sponsored hackers are using AI models like Claude to automate cyber attacks, including data theft and exploitation. This means that even less skilled attackers can now perform sophisticated attacks that were previously only possible with significant resources.
- How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface (BleepingComputer) โ Cybercriminals are exploiting trusted AI platforms to spread malware by tricking users into downloading malicious content. This can happen through shared AI conversations, public artifacts, and search results.
- Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors (The Hacker News) โ Hackers exploited two vulnerabilities in JFrog Artifactory to gain admin control and plant backdoors. This means if your Artifactory server is not updated, it could be compromised, allowing attackers to create admin accounts and execute malicious code.
- Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks (The Hacker News) โ News about Claude distillation attacks
- Hackers abused Claude to extract secrets from 1.8M Android apps (BleepingComputer) โ News about Claude AI model abuse
โช 72 low-priority items filtered.
๐ฆ Aggregated and triaged by Donna AI | Sources: 8 vendor feeds | CISA KEV