Why Should I Care? โ 2026-09-22 | ๐ด 1 HIGH ยท ๐ก 0 MEDIUM ยท ๐ต 17 RADAR ยท โช 66 FILTERED
๐ Briefing โ 2026-09-22
18 vendor intel items scanned | ๐ด 1 HIGH | ๐ก 0 MEDIUM | ๐ต 17 RADAR | โช 66 FILTERED
๐ด Critical โ action required:
- CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-7273) โ Yes, if you run Zyxel GS1900 Series Switches: This vulnerability can allow attackers to take full control of your switch.
Everything else can wait.
๐ต 15 items on the radar โ see below โ
Why Should I Care? ๐ด HIGH โ Handle Now
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Advisories [CISA KEV] | CVE-2026-7273
โ Why Should I Care?
Yes, if you run Zyxel GS1900 Series Switches: This vulnerability can allow attackers to take full control of your switch.
๐ฏ Affected versions: All versions of Zyxel GS1900 Series Switches
๐ญ In plain English:
This vulnerability means that an attacker can overflow a buffer in the switch's software, potentially allowing them to execute arbitrary code and take control of the switch. For example, an attacker could redirect network traffic or shut down the switch entirely.
๐ง Prerequisites:
- Access to the switch's network
- No patches applied
โฑ Urgency: High urgency due to active exploitation and the risk of total control over the switch.
๐ก Context: The root cause is a lack of proper input validation in the switch's software, leading to a stack-based buffer overflow.
Why Should I Care? ๐ก MEDIUM (0)
None.
Why Should I Care? ๐ต On the Radar (17)
- CISA alerts of active exploitation of three Linux kernel flaws (BleepingComputer) โ CISA has warned that hackers are actively exploiting three Linux kernel vulnerabilities, one of which is critical and has existed for 14 years. These flaws can lead to system crashes, privilege escalation, and data corruption.
- BigCommerce alerts merchants of data breach linked to Ribon apps (BleepingComputer) โ BigCommerce merchants were affected by a data breach due to compromised credentials of third-party Ribon apps, leading to the injection of malicious scripts into online stores. This impacts customer data like names, email addresses, phone numbers, and shipping addresses.
- Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto (The Hacker News) โ North Korean hackers have compromised 30,000 devices and stolen $10.71M in cryptocurrency by posing as recruiters on social media. They target web designers, engineers, and cryptocurrency specialists.
- Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR (The Hacker News) โ A fake LastPass Authenticator installer uses a Microsoft-signed driver to disable antivirus and EDR, then steals passwords and other sensitive data. This impacts any user or organization that relies on LastPass or has security software.
- WordPress Click2Shell flaw lets hackers execute PHP on the server (BleepingComputer) โ A new WordPress vulnerability, Click2Shell, allows attackers to execute PHP code on your server if an admin visits a malicious link. This can lead to unauthorized access and control of your site.
- ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure (The Hacker News) โ A new RAT called ChainScript is being spread through ClickFix-like lures, disguised as legitimate software updates for popular applications like Spotify, Zoom, and Microsoft Teams. This malware can steal data and control your system.
- Microsoft to retire Microsoft 365 Companion apps in December (BleepingComputer) โ Microsoft is retiring the Calendar, People, and Files companion apps on December 16, 2026. Admins need to remove these apps from managed devices to avoid disruptions.
- TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data (The Hacker News) โ A new malware campaign, TASK#STOMP, uses PowerShell to steal documents, Wi-Fi passwords, and clipboard data from Windows systems. It establishes multiple persistence mechanisms to ensure continued access and data exfiltration.
- Google Fined โฌ403 Million Over GDPR Violations Tied to Location Data (The Hacker News) โ Google fined for GDPR violations related to location data handling.
- โก Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks (The Hacker News) โ Weekly recap of various security issues.
- Microsoft reminds admins to migrate Entra ID users to passkeys (BleepingComputer) โ Microsoft advises migrating Entra ID users to phishing-resistant authentication methods.
- FBI's CJIS v6.1: What Security Teams Need to Know. (BleepingComputer) โ Explains changes in FBI's CJIS Security Policy v6.1.
- Microsoft fixes broken Excel copy and paste for all Office users (BleepingComputer) โ Microsoft has fixed an issue causing Excel copy-and-paste failures.
- Google fined โฌ403 million over location data privacy violations (BleepingComputer) โ Reports on GDPR violations and resulting fine for Google.
- Transforming Bedrock Guardrails events into OCSF with CloudWatch (AWS Security Blog) โ Provides guidance on transforming Bedrock Guardrails events into OCSF with CloudWatch.
โช 66 low-priority items filtered.
๐ฆ Aggregated and triaged by Donna AI | Sources: 8 vendor feeds | CISA KEV