Why Should I Care? โ 2026-09-30 | ๐ด 6 HIGH ยท ๐ก 2 MEDIUM ยท ๐ต 23 RADAR ยท โช 100 FILTERED
๐ Briefing โ 2026-09-30
31 vendor intel items scanned | ๐ด 6 HIGH | ๐ก 2 MEDIUM | ๐ต 23 RADAR | โช 100 FILTERED
๐ด Critical โ action required:
- CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-86950) โ Yes, if you run Apple products affected by this vulnerability: immediate action is required to prevent unauthorized access and control.
- Toptech TMS7 and TopHAT (CVE-2026-71379) โ Yes, if you run TMS7 7.6.3 or TopHAT 7.6.3: these vulnerabilities could allow an attacker to access critical data or execute arbitrary code.
- Viidure Dashcam Android Application (CVE-2026-94204, CVE-2026-96587) โ Yes, if you run Viidure Dashcam Android Application <=3.3.1.260403: attackers can access, modify, or delete sensitive data and critical system files, potentially compromising the entire platform.
- Anjvision YSSD-RTMP-H5 (CVE-2026-100291, CVE-2026-100292, CVE-2026-100293, CVE-2026-100294, CVE-2026-100295, CVE-2026-100296, CVE-2026-100297, CVE-2026-100298, CVE-2026-100299) โ Yes, if you run Anjvision YSSD-RTMP-H5 firmware 3.3.2.4_build_2024-12-26: An attacker could access sensitive information, user accounts, and execute OS-level commands, taking full control over the device.
- VIVOTEK Camera Firmware (CVE-2026-22755) โ Yes, if you run any of the affected VIVOTEK Camera Firmware versions listed: attackers could remotely execute commands with root privileges, fully compromising your camera system.
- MikroTik RouterOS (CVE-2026-84411) โ Yes, if you run MikroTik RouterOS versions less than 7.24: this vulnerability allows unauthenticated attackers to execute arbitrary code or cause a denial of service.
Everything else can wait.
๐ก Medium โ review when time permits:
- Lantronix G520 Series Cellular Gateway โ Yes, if you run Lantronix G520 Series 2.6.0.4R6_stable: An attacker could replace software and execute arbitrary code with root privileges.
- Baicells Nova 430H โ Yes, if you run Baicells Nova 430H eNodeB (model pBS3101SH) <= BaiBLQ_3.0.12: An attacker can cause a denial-of-service condition by sending malformed messages.
๐ต 15 items on the radar โ see below โ
Why Should I Care? ๐ด HIGH โ Handle Now
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Advisories [CISA KEV] | CVE-2026-86950
โ Why Should I Care?
Yes, if you run Apple products affected by this vulnerability: immediate action is required to prevent unauthorized access and control.
๐ฏ Affected versions: All versions of Apple products listed in the advisory
๐ญ In plain English:
This vulnerability allows attackers to write data outside the intended memory boundaries, potentially leading to arbitrary code execution. For example, an attacker could exploit this to install malware on your device, take control of it, and steal sensitive information.
๐ง Prerequisites:
- Running an affected version of Apple software
- No recent security updates applied
โฑ Urgency: High urgency due to active exploitation and the risk of total control over affected assets.
๐ก Context: The root cause is improper bounds checking when handling data, allowing for out-of-bounds writes.
Toptech TMS7 and TopHAT
CISA Advisories | CVSS 10 | CVE-2026-71379
โ Why Should I Care?
Yes, if you run TMS7 7.6.3 or TopHAT 7.6.3: these vulnerabilities could allow an attacker to access critical data or execute arbitrary code.
๐ฏ Affected versions: TMS7 7.6.3, TopHAT 7.6.3
๐ญ In plain English:
These vulnerabilities mean an attacker could steal sensitive data or run malicious code on your system. For example, an attacker could upload a harmful file that takes control of your web server.
๐ง Prerequisites:
- Running TMS7 7.6.3 or TopHAT 7.6.3
โฑ Urgency: High urgency due to the critical nature of the vulnerabilities and the potential for data theft and code execution.
โ Fixed in: 7.8
๐ก Context: The root cause includes issues like unrestricted file uploads and SQL injection vulnerabilities.
Viidure Dashcam Android Application
CISA Advisories | CVSS 10 | CVE-2026-94204, CVE-2026-96587
โ Why Should I Care?
Yes, if you run Viidure Dashcam Android Application <=3.3.1.260403: attackers can access, modify, or delete sensitive data and critical system files, potentially compromising the entire platform.
๐ฏ Affected versions: Viidure Dashcam Android Application <=3.3.1.260403
๐ญ In plain English:
This vulnerability means that anyone on the internet can access your dashcam footage and sensitive data because the app's cloud storage is misconfigured and uses hard-coded credentials. An attacker could view your live footage, steal your data, or even tamper with your firmware.
๐ง Prerequisites:
- Internet access
- No authentication required
โฑ Urgency: High urgency because the vulnerability allows unrestricted access to sensitive data and critical system files, which can be exploited immediately.
๐ก Context: The root cause is the misconfiguration of cloud storage permissions and the use of hard-coded credentials in the application code.
Anjvision YSSD-RTMP-H5
CISA Advisories | CVSS 9.8 | CVE-2026-100291, CVE-2026-100292, CVE-2026-100293, CVE-2026-100294, CVE-2026-100295, CVE-2026-100296, CVE-2026-100297, CVE-2026-100298, CVE-2026-100299
โ Why Should I Care?
Yes, if you run Anjvision YSSD-RTMP-H5 firmware 3.3.2.4_build_2024-12-26: An attacker could access sensitive information, user accounts, and execute OS-level commands, taking full control over the device.
๐ฏ Affected versions: Anjvision YSSD-RTMP-H5 firmware 3.3.2.4_build_2024-12-26
๐ญ In plain English:
This vulnerability means an attacker could access your device's sensitive information, user accounts, and even take full control of the device. For example, an attacker could remotely execute commands on your device, potentially stealing data or causing it to malfunction.
๐ง Prerequisites:
- Access to the device's network
- No authentication required for certain operations
โฑ Urgency: High urgency due to the critical nature of the vulnerabilities and the potential for full device control.
๐ก Context: The root cause includes insecure default settings, lack of proper authentication, and insufficient cryptographic verification of firmware updates.
VIVOTEK Camera Firmware
CISA Advisories | CVE-2026-22755
โ Why Should I Care?
Yes, if you run any of the affected VIVOTEK Camera Firmware versions listed: attackers could remotely execute commands with root privileges, fully compromising your camera system.
๐ฏ Affected versions: V Series model_FD9187, V Series model_FD9189, V Series model_FD9365, V Series model_FD9387, V Series model_FD9389, V Series model_FD9391, C Series model_FE9180, V Series model_FE9191, V Series model_FE9382, V Series model_FE9391, V Series model_IB9365, V Series model_IB9387, V Series model_IB9389, V Series model_IB939, V Series model_IP9165, V Series model_IP9171, S Series model_IP9172, V Series model_IP9181, V Series model_IP9191, V Series model_IT9389, V Series model_MA9321, V Series model_MA9322, S Series model_MS9321, V Series model_MS9390, S Series model_TB9330, Dome model_FD8365, Dome model_FD8365v2, Dome model_FD9165, Dome model_FD9171, Dome model_FD9371, Dome model_FD9381, Panoramic model_FE9181, Panoramic model_FE9381, VIVOTEK Camera model_FE9582, VIVOTEK Camera model_IB93587LPR, Bullet model_IB9371, Bullet model_IB9381
๐ญ In plain English:
This vulnerability means an attacker could take full control of your camera, like a hacker taking over your computer. They could watch you, record you, or even use the camera to attack other devices on your network.
๐ง Prerequisites:
- The camera must be accessible from the internet or a network the attacker can reach.
โฑ Urgency: High urgency because an attacker could fully compromise your camera system, leading to privacy breaches and potential network infiltration.
๐ก Context: The root cause is a command injection vulnerability in the firmware modules used by the affected camera models.
MikroTik RouterOS
CISA Advisories | CVSS 9.8 | CVE-2026-84411
โ Why Should I Care?
Yes, if you run MikroTik RouterOS versions less than 7.24: this vulnerability allows unauthenticated attackers to execute arbitrary code or cause a denial of service.
๐ฏ Affected versions: RouterOS <7.24
Not affected: RouterOS 7.24 and later
๐ญ In plain English:
This vulnerability means that an attacker can send a specially crafted request to your router and take full control of it or crash it, without needing any login credentials. For example, an attacker could remotely shut down your network or install malicious software.
๐ง Prerequisites:
- RouterOS version <7.24
- Access to the web management service
โฑ Urgency: High urgency due to the critical nature of the vulnerability and the potential for unauthenticated remote code execution.
โ Fixed in: 7.24
๐ก Context: The root cause is an integer underflow in the HTTP request body handling of the web management service.
Why Should I Care? ๐ก MEDIUM (2)
Lantronix G520 Series Cellular Gateway
CISA Advisories | CVSS 7.5 | CVE-2026-84409, CVE-2026-91191
โ Why Should I Care?
Yes, if you run Lantronix G520 Series 2.6.0.4R6_stable: An attacker could replace software and execute arbitrary code with root privileges.
๐ฏ Affected versions: Lantronix G520 Series 2.6.0.4R6_stable
๐ญ In plain English:
An attacker could inject malicious code into your device's software updates, allowing them to take full control of the device. For example, they could install a backdoor that lets them access your device at any time.
๐ง Prerequisites:
- Unencrypted HTTP connection for software updates
- Authenticated access to the management interface
โฑ Urgency: High urgency due to the potential for full device compromise and the critical infrastructure sectors affected.
โ Fixed in: 2.6.0.7R6
๐ก Context: The root cause is the lack of proper input validation and cryptographic signature verification in the software update process.
Baicells Nova 430H
CISA Advisories | CVSS 7.4 | CVE-2026-96274
โ Why Should I Care?
Yes, if you run Baicells Nova 430H eNodeB (model pBS3101SH) <= BaiBLQ_3.0.12: An attacker can cause a denial-of-service condition by sending malformed messages.
๐ฏ Affected versions: Baicells Nova 430H eNodeB (model pBS3101SH) <= BaiBLQ_3.0.12
๐ญ In plain English:
An attacker can send bad messages to your device, causing it to stop working temporarily. For example, if you're using this device for communication, an attacker could disrupt service, making it hard for you to send or receive messages.
๐ง Prerequisites:
- An unauthenticated device within radio range
โฑ Urgency: High urgency due to the potential for service disruption and the lack of a fix from the vendor.
๐ก Context: The root cause is the device's failure to properly validate the payload of uplink messages during connection setup.
Why Should I Care? ๐ต On the Radar (23)
- Hackers exploit Citrix NetScaler zero-day to deploy web shells (BleepingComputer) โ Hackers are exploiting two unpatched vulnerabilities in Citrix NetScaler to deploy web shells and gain root access, potentially leading to credential theft and network infiltration. For example, if your organization uses NetScaler for load balancing or as a gateway, your systems could be at risk of unauthorized access and data breaches.
- Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor (The Hacker News) โ Russian hackers, known as Star Blizzard, are tricking people into installing a backdoor on their Windows computers by sending fake event invitations. This has affected over 100 organizations, mostly in the U.S. and U.K., and targets those involved with Ukraine.
- Automated AI agent used to breach cybersecurity nonprofit DIVD (BleepingComputer) โ A cybersecurity nonprofit was hacked using an automated AI agent, indicating a new and sophisticated threat vector. This attack shows that AI can be weaponized to autonomously exploit vulnerabilities, leaving messy but traceable evidence.
- Apple patches CoreGraphics zero-day flaw exploited in attacks (BleepingComputer) โ Apple has fixed a serious security flaw that could let attackers take control of your device. This affects iPhones, iPads, and Macs. If you haven't updated your device, you're at risk.
- Custom ChatGPTs push ClickFix attacks to deploy RAT malware (BleepingComputer) โ Hackers are using custom versions of ChatGPT to trick users into visiting malicious sites that deploy RAT malware. This can lead to remote access, data theft, and system compromise.
- New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses (The Hacker News) โ A new Spectre variant, BTR, has been discovered that can leak sensitive data from Linux systems and JIT engines used in web browsers and language runtimes, even with existing defenses in place. This means that attackers could potentially access sensitive information like root passwords.
- New Spectre v2 attack variant leaks Linux root password hash in minutes (BleepingComputer) โ A new Spectre v2 variant, called BTR, can steal root password hashes from Intel-based Linux systems in just 3-5 minutes. This means attackers can potentially access sensitive data and systems if they have access to the machine.
- 101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent (The Hacker News) โ A cluster of 101 malicious npm packages has been identified that can add developers' WhatsApp accounts to groups without their consent, potentially exposing them to unwanted marketing or spam.
- Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown (The Hacker News) โ Kiteworks found and fixed a critical security flaw during a precautionary shutdown. The flaw affects less than 1% of customers using a specific capability. No evidence of malicious exploitation was found.
- Kiteworks patches critical flaw, brings customer systems online (BleepingComputer) โ Kiteworks patched a critical vulnerability that could have led to cyberattacks on their platform. They asked customers to shut down systems temporarily, but now it's safe to go back online.
- Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials (The Hacker News) โ A flaw in the MCP Python SDK allows malicious servers to steal OAuth credentials from applications, potentially giving attackers access to your services. This affects applications that use the SDK to connect to untrusted servers.
- Microsoft is rolling out Linux container support to WSL (BleepingComputer) โ New feature release
- FBI tells ShinyHunters members to turn themselves in after recent arrest (BleepingComputer) โ FBI urging ShinyHunters members to surrender after an arrest.
- Signal adds encypted local backup support to iOS, desktop apps (BleepingComputer) โ Signal's secure backups feature now available on all supported platforms.
- French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks (The Hacker News) โ French tax data theft using stolen staff passwords went undetected for seven weeks.
โช 100 low-priority items filtered.
๐ฆ Aggregated and triaged by Donna AI | Sources: 8 vendor feeds | CISA KEV