Why Should I Care? โ 2026-09-24 | ๐ด 0 HIGH ยท ๐ก 0 MEDIUM ยท ๐ต 27 RADAR ยท โช 69 FILTERED
๐ Briefing โ 2026-09-24
27 vendor intel items scanned | ๐ด 0 HIGH | ๐ก 0 MEDIUM | ๐ต 27 RADAR | โช 69 FILTERED
โ No critical items today.
Everything else can wait.
๐ต 15 items on the radar โ see below โ
Why Should I Care? ๐ด HIGH โ Handle Now
No HIGH priority items in the last 24h.
Why Should I Care? ๐ก MEDIUM (0)
None.
Why Should I Care? ๐ต On the Radar (27)
- MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key (The Hacker News) โ Two vulnerabilities in MikroTik RouterOS allow attackers to take over routers without authentication. This means anyone with access to the Internet can potentially control your router if it's exposed.
- Check Point warns of hackers exploiting Security Gateway VPN RCE flaw (BleepingComputer) โ Hackers are actively exploiting vulnerabilities in Check Point's Security Gateway product, allowing them to execute code remotely and potentially take control of the system. This affects the certificate-handling functionality and the Management web service.
- Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware (The Hacker News) โ Chinese hackers are using a combination of previously unknown vulnerabilities in Chrome and Windows to spread malware. This attack can affect anyone using these technologies, potentially leading to unauthorized access and control of your system.
- F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers (The Hacker News) โ A critical flaw in F5's BIG-IP APM allows attackers to execute code on your system without needing to log in, specifically if your system uses APM as an OAuth authorization server. This could lead to unauthorized access and control over your infrastructure.
- Placeholder domain used in dev docs now serves ClickFix attacks (BleepingComputer) โ The domain third-party.com, often used as a placeholder in developer documentation and code examples, is now being used to serve a ClickFix attack that tricks Windows users into running malicious PowerShell commands. This could lead to malware installation.
- A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You (The Hacker News) โ A leaked GitLab email address can allow attackers to push code and run CI/CD jobs as you. This impacts anyone using GitLab for project management, especially those with higher permissions like Maintainers.
- Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers (BleepingComputer) โ A financially motivated attacker used AI tools to compromise hundreds of online retailers, stealing over 600,000 credit card records and infecting over 100 sites with skimmers. This shows how AI can be weaponized to automate and scale cyberattacks.
- Hackers start exploiting critical WordPress flaw for code execution (BleepingComputer) โ Hackers are exploiting a critical flaw in WordPress that allows them to run commands on your server. If your site is not updated, it could be compromised.
- New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control (The Hacker News) โ A critical security flaw in cPanel's services allows any hosting account to run code as root and take full control of the server. This affects both the CalDAV/CardDAV service and the WP Toolkit plugin, impacting server security and data integrity.
- Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI (The Hacker News) โ Malicious actors have compromised MemTensor packages on npm and PyPI, pushing a credential-stealing malware called sckit. This affects developers and CI/CD pipelines that use these packages.
- Arista patches actively exploited VeloCloud Orchestrator zero-day (BleepingComputer) โ A critical flaw in VeloCloud Orchestrator (VCO) On-Prem deployments is being actively exploited by threat actors. This flaw allows unauthorized access to privileged internal VCO host functionality without requiring user interaction or system privileges.
- ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants (The Hacker News) โ A cybercrime group, ShinyHunters, claims to have breached the FBI and stolen sensitive data from agents and job applicants. They exploited a zero-day vulnerability in Oracle PeopleSoft, which could affect other organizations using the same software.
- F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks (BleepingComputer) โ F5 has patched a critical vulnerability in BIG-IP APM that allows attackers to execute code remotely. This flaw is being actively exploited, and if you use BIG-IP APM, you need to apply the patch immediately to avoid potential breaches.
- New RemControl Android banking malware targets users in Europe and Canada (BleepingComputer) โ A new Android malware called RemControl is targeting users in Europe, Canada, and the Middle East through fake apps that steal banking credentials. It uses AI to create phishing overlays and can bypass Google Play's security checks.
- Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry (The Hacker News) โ Cybercriminals are now using the HashiCorp Registry to distribute malware through malicious Terraform providers and Go Modules. This means that if you use these tools, your infrastructure could be at risk of being compromised.
โช 69 low-priority items filtered.
๐ฆ Aggregated and triaged by Donna AI | Sources: 8 vendor feeds | CISA KEV