Skip to content
Tech News
clear
Topics: Today This Week This Month This Year

CISA mandates federal patch for actively exploited Zyxel GS1900 switch flaw

CISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 series switches, to its Known Exploited Vulnerabilities catalog after confirming active attacks. The flaw allows unauthenticated LAN attackers to run OS commands via crafted HTTP requests, and federal agencies must secure affected devices by Thursday under Binding Operational Directive 26-04. Zyxel issued firmware fixes on June 16 but has not yet updated its advisory to acknowledge exploitation.

CISA flags active exploitation of three Linux kernel vulnerabilities

CISA has added three Linux kernel security flaws to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting them in the wild. The bugs include CVE-2025-39964, a 14-year-old race condition in the AF_ALG crypto socket interface; CVE-2026-53266, an out-of-bounds write in ebtables SNAT; and CVE-2025-39682, a flaw in the kernel's TLS receive path. Federal agencies were ordered to patch these by end of day, though CISA has not disclosed details on the attackers or specific incidents.

Cisco patches actively exploited zero-day in Identity Services Engine

Cisco disclosed and fixed several critical vulnerabilities in its Identity Services Engine and ISE-PIC products, including CVE-2026-76460, a maximum-severity authentication bypass that attackers are already exploiting in the wild. The flaw lets an attacker send a crafted request to an unguarded API endpoint and slip past ISE's web management interface entirely. CISA added the bug to its Known Exploited Vulnerabilities catalog the same day the patch shipped.

CISA to end weekly vulnerability bulletins, pushes risk-based approach instead

CISA announced it will stop publishing its weekly vulnerability summary bulletins starting Sept. 28, directing organizations instead to its Known Exploited Vulnerabilities catalog, security advisories, and vendor alerts. The agency says the change reflects its push for risk-based vulnerability prioritization rather than relying on severity scores alone, amid a surge in disclosed vulnerabilities partly driven by AI-assisted flaw hunting.

CISA confirms active exploitation of ConnectWise ScreenConnect flaw CVE-2026-84869

CISA has added a critical ScreenConnect vulnerability, now designated CVE-2026-84869, to its known exploited vulnerabilities catalog after confirming attackers are actively abusing it. The flaw stems from missing authorization checks that let low-privilege users transfer and execute files during active remote sessions without host confirmation, and it has been fixed in ScreenConnect 26.6.5. Federal agencies have been given three days to patch, while Shadowserver reports over 1,000 unpatched, internet-exposed ScreenConnect servers, mostly in North America and Europe.

CISA confirms ransomware groups exploiting critical VMware vCenter flaw CVE-2026-59310

CISA has updated its Known Exploited Vulnerabilities catalog to flag ransomware gangs actively exploiting a critical VMware vCenter directory traversal flaw, CVE-2026-59310, patched by Broadcom in July. The bug had already been abused by a suspected APT group to compromise over 361 IP addresses across 47 countries, and Shadowserver now tracks more than 450 exposed vCenter servers online.

CISA confirms active exploitation of critical GitLab path traversal flaw CVE-2026-85706

CISA has added a maximum-severity GitLab vulnerability, CVE-2026-85706, to its known exploited vulnerabilities catalog after security firm watchTowr detected attackers scanning the internet for unpatched servers. The flaw allows unauthenticated attackers to read credentials and sensitive files from GitLab instances via a single crafted HTTP request to the repository commits API. GitLab patched the issue in versions 19.3.2, 19.2.6, and 19.1, but federal agencies now have just three days to remediate under a binding directive.

CISA and FBI Urge Clearer Crisis Communication During Cyber Outages

CISA, the FBI and international partners published a joint advisory this month titled 'Communicating Under Pressure: Best Practices for Service Providers,' addressing poor communication during IT and OT outages. The guidance calls on companies to move away from PR-driven messaging and instead give users transparent, actionable updates about root causes and expected impacts during disruptions.

CISA confirms ransomware groups exploiting WatchGuard Firebox flaw CVE-2025-14733

CISA has updated its Known Exploited Vulnerabilities catalog to warn that ransomware operators are now actively abusing a critical remote-code-execution bug in WatchGuard Firebox firewalls, first flagged as exploited back in December. The flaw, an out-of-bounds write bug affecting multiple Fireware OS versions, lets unauthenticated attackers run code remotely, particularly on devices configured for IKEv2 VPN. Shadowserver data shows nearly 9,000 Firebox devices remain unpatched online nine months after fixes were released.

FBI, NSA, CISA Accuse Alibaba, DeepSeek and Others of Mass-Distilling US AI Models

US federal agencies issued a joint advisory on Sept. 8 alleging that Chinese AI companies including Alibaba, DeepSeek, MiniMax, Moonshot AI, StepFun and Z.AI have run large-scale operations to pull outputs from US models like Claude, GPT, Gemini and Grok since late 2024. The advisory says these firms extracted billions of tokens through millions of queries, using techniques such as chain-of-thought extraction and automated evasion to dodge blocking measures, in order to train their own competing systems.

Cisco confirms active exploitation of critical Secure FMC bug CVE-2026-20079

Cisco has verified that attackers are actively exploiting CVE-2026-20079, a maximum-severity (CVSS 10.0) flaw in its Secure Firewall Management Center software that lets unauthenticated remote attackers bypass login and run commands as root. The company first disclosed the bug in March without evidence of exploitation, but updated its advisory this week to acknowledge PSIRT detected active attacks in August, though it hasn't shared attacker identity or attack timeline details. CISA has since added the flaw to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 12 to patch.

US agencies accuse six Chinese AI firms of mass model-distillation attacks on US chatbots

CISA, the NSA, and the FBI issued a joint advisory naming DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI as having harvested billions of tokens from Anthropic, OpenAI, Google, and xAI models since late 2024. The firms allegedly used fraudulent accounts, proxy networks, and automated failover systems to bypass rate limits and extract restricted reasoning data at industrial scale.

Today's top topics: openai apple anthropic qualcomm claude opus 5.5 artificial intelligence iphone 18 pro ai safety motorola signature 27 sam altman
View all today's topics →