This website uses cookies

Read our Privacy policy and Terms of use for more information.

Summary: The U.S. Cybersecurity and Infrastructure Security Agency warned that threat actors are actively exploiting CVE-2026-85706, a maximum-severity (CVSS 10.0) path-traversal vulnerability in GitLab CE/EE. The flaw stems from missing authentication enforcement and improper path confinement in the repository commits API, allowing unauthenticated attackers to read arbitrary files, including credentials and secrets, from vulnerable servers. GitLab released fixes in versions 19.3.2, 19.2.6 and 19.1.8; CISA added the CVE to its Known Exploited Vulnerabilities catalog with a federal remediation deadline of September 14 under BOD 26-04. watchTowr observed in-the-wild probes shortly after disclosure.

Key takeaway / Actionable note: Immediately upgrade self-managed GitLab instances and hunt logs for POST requests to /api/v4/projects/{id}/repository/commits/ containing file.path parameters.

Summary: Revolut disclosed that an unauthorized third party used a legitimate government agency email domain to submit fraudulent information requests, obtaining sensitive customer data. Impacted data included identity and contact details, dates of birth, addresses, phone numbers, copies of identity documents (passports and driver’s licenses), and potentially verification selfies, account statements and transaction histories. A limited number of customers were affected; Revolut blocked the address, notified the agency, law enforcement and regulators, and stated that systems and customer funds remain unaffected.

Key takeaway / Actionable note: Treat any government-domain data request as potentially fraudulent until independently verified through official channels.

Summary: China-aligned threat group UNC3569 is exploiting CVE-2026-51990, a critical one-click remote-code-execution vulnerability in Tencent’s Sogou Input Method for Windows, to deploy the GrayRabbit backdoor. The exploit chains unvalidated command-line argument injection in the sgbiz: protocol handler, unrestricted URL navigation in a CEF webview, and an outdated unsandboxed Chromium 80 engine. Gen Threat Labs observed the activity in the wild; Tencent fixed the issue in version 16.3.0.3498 via automatic update, though the underlying browser remains outdated.

Key takeaway / Actionable note: Ensure Sogou Input Method is updated to 16.3.0.3498 or later and monitor for GrayRabbit indicators on systems used by Chinese-language users.

Summary: ConnectWise released ScreenConnect 26.6.5 to address CVE-2026-84869 (CVSS 9.9), a missing-authorization and improper-privilege-management flaw in the client that allows unauthorized file transfer and execution through an active remote session. Huntress reported worm-like exploitation since August 20 that uses modified clients and VBScript payloads for persistence and propagation. CISA added the vulnerability to the KEV catalog with a September 14 remediation deadline.

Key takeaway / Actionable note: Upgrade all ScreenConnect servers and reinstall/refresh every host client and access agent to 26.6.5 or later.

Summary: Multiple threat actors are chaining and exploiting three patched JFrog Artifactory vulnerabilities—CVE-2026-42016, CVE-2026-42018 and CVE-2026-82329—to obtain administrative privileges, deploy custom Rust backdoors, Groovy plugins and web shells, and exfiltrate configuration and keys. Wiz observed chaining of the authentication and privilege-escalation flaws from mid-August through early September, with independent exploitation of the critical authentication-bypass starting in the first week of September. Large percentages of internet-facing instances remained unpatched weeks after fixes were available.

Key takeaway / Actionable note: Apply the latest Artifactory patches immediately and audit for unauthorized admin accounts, SSH keys and plugins.

Summary: Microsoft confirmed that the September 2026 security updates cause Remote Desktop Services instability on Windows Server 2012 and later as well as Windows 10/11. Symptoms include RDP connections failing after several minutes, sign-in issues, servers hanging at “Please wait for the Remote Desktop Configuration,” and unresponsive related tools. Known Issue Rollback Group Policy packages are available for affected builds; temporary recovery is possible by restarting affected VMs or rolling back the updates (which removes the security fixes).

Key takeaway / Actionable note: Deploy the appropriate Known Issue Rollback GPOs or plan controlled restarts while monitoring for a permanent fix.

Summary: Gen Threat Labs detailed active exploitation of the Sogou Input Method RCE by UNC3569, a China-linked group previously associated with both cybercrime and contractor activity. The one-click chain delivers system-level code execution and deploys the long-running GrayRabbit modular backdoor, which supports reverse shells, process execution, file transfer and in-memory plugin loading. The patch was deployed rapidly via auto-update, but residual risk remains from the outdated Chromium component.

Key takeaway / Actionable note: Prioritize detection of sgbiz: URI activity and GrayRabbit C2 on endpoints running Chinese-language input software.

Summary: Anthropic’s latest threat-intelligence report describes a ShinyHunters-linked operator who used Claude to orchestrate a pipeline that downloaded, decompiled and scanned 1.8 million Android APKs for hardcoded secrets with TruffleHog, routing verified findings to Telegram channels. The same actor harvested GitHub organization emails and Personal Access Tokens; the credentials supported multiple confirmed breaches, including a SaaS provider whose data affected roughly 200 downstream customers. AI assistance compressed one Azure AD token-harvesting operation to approximately 34 hours across more than 40 tenants.

Key takeaway / Actionable note: Scan mobile apps and repositories for hardcoded secrets and treat AI-assisted credential mining as a high-velocity initial-access vector.

Also Noted:

Bottom line: The last 24 hours delivered multiple actively exploited critical flaws (GitLab, ScreenConnect, Artifactory, Sogou) plus a high-profile social-engineering data disclosure at Revolut. Prioritize KEV-driven patching, verify government-domain requests, and assume AI-assisted credential harvesting is already scaling.

Reply

Avatar

or to participate