Check Point disclosed that hackers are actively exploiting CVE-2026-85102, a pre-authentication remote code execution flaw in its Security Gateway VPN certificate handling, and CVE-2026-93616, a path traversal bug in its Management web service. The company says the path traversal flaw has been exploited as a zero-day since July 23, while exploitation of the gateway flaw began September 12 using VPNs and proxies to mask attacker origin. CISA has added both vulnerabilities to its Known Exploited Vulnerabilities catalog, giving federal agencies until September 25, 2026 to patch.
bleepingcomputer.com
· 2026-09-23
CISA released new guidance last week outlining how organizations can deploy deception techniques—such as decoy files, honeypots, and tripwires—to detect intruders inside their networks. The introductory resource explains how to design and implement these traps to shorten detection time and reveal attacker behavior, framing deception as a complement to zero-trust security models.
darkreading.com
· 2026-09-22
CISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 series switches, to its Known Exploited Vulnerabilities catalog after confirming active attacks. The flaw allows unauthenticated LAN attackers to run OS commands via crafted HTTP requests, and federal agencies must secure affected devices by Thursday under Binding Operational Directive 26-04. Zyxel issued firmware fixes on June 16 but has not yet updated its advisory to acknowledge exploitation.
bleepingcomputer.com
· 2026-09-22
CISA has added three Linux kernel security flaws to its Known Exploited Vulnerabilities catalog, warning that attackers are actively exploiting them in the wild. The bugs include CVE-2025-39964, a 14-year-old race condition in the AF_ALG crypto socket interface; CVE-2026-53266, an out-of-bounds write in ebtables SNAT; and CVE-2025-39682, a flaw in the kernel's TLS receive path. Federal agencies were ordered to patch these by end of day, though CISA has not disclosed details on the attackers or specific incidents.
bleepingcomputer.com
· 2026-09-21
Cisco disclosed and fixed several critical vulnerabilities in its Identity Services Engine and ISE-PIC products, including CVE-2026-76460, a maximum-severity authentication bypass that attackers are already exploiting in the wild. The flaw lets an attacker send a crafted request to an unguarded API endpoint and slip past ISE's web management interface entirely. CISA added the bug to its Known Exploited Vulnerabilities catalog the same day the patch shipped.
darkreading.com
· 2026-09-18
CISA announced it will stop publishing its weekly vulnerability summary bulletins starting Sept. 28, directing organizations instead to its Known Exploited Vulnerabilities catalog, security advisories, and vendor alerts. The agency says the change reflects its push for risk-based vulnerability prioritization rather than relying on severity scores alone, amid a surge in disclosed vulnerabilities partly driven by AI-assisted flaw hunting.
darkreading.com
· 2026-09-17
CISA has added a critical ScreenConnect vulnerability, now designated CVE-2026-84869, to its known exploited vulnerabilities catalog after confirming attackers are actively abusing it. The flaw stems from missing authorization checks that let low-privilege users transfer and execute files during active remote sessions without host confirmation, and it has been fixed in ScreenConnect 26.6.5. Federal agencies have been given three days to patch, while Shadowserver reports over 1,000 unpatched, internet-exposed ScreenConnect servers, mostly in North America and Europe.
bleepingcomputer.com
· 2026-09-16
CISA has updated its Known Exploited Vulnerabilities catalog to flag ransomware gangs actively exploiting a critical VMware vCenter directory traversal flaw, CVE-2026-59310, patched by Broadcom in July. The bug had already been abused by a suspected APT group to compromise over 361 IP addresses across 47 countries, and Shadowserver now tracks more than 450 exposed vCenter servers online.
bleepingcomputer.com
· 2026-09-15
CISA has added a maximum-severity GitLab vulnerability, CVE-2026-85706, to its known exploited vulnerabilities catalog after security firm watchTowr detected attackers scanning the internet for unpatched servers. The flaw allows unauthenticated attackers to read credentials and sensitive files from GitLab instances via a single crafted HTTP request to the repository commits API. GitLab patched the issue in versions 19.3.2, 19.2.6, and 19.1, but federal agencies now have just three days to remediate under a binding directive.
bleepingcomputer.com
· 2026-09-14
CISA, the FBI and international partners published a joint advisory this month titled 'Communicating Under Pressure: Best Practices for Service Providers,' addressing poor communication during IT and OT outages. The guidance calls on companies to move away from PR-driven messaging and instead give users transparent, actionable updates about root causes and expected impacts during disruptions.
darkreading.com
· 2026-09-11
CISA has updated its Known Exploited Vulnerabilities catalog to warn that ransomware operators are now actively abusing a critical remote-code-execution bug in WatchGuard Firebox firewalls, first flagged as exploited back in December. The flaw, an out-of-bounds write bug affecting multiple Fireware OS versions, lets unauthenticated attackers run code remotely, particularly on devices configured for IKEv2 VPN. Shadowserver data shows nearly 9,000 Firebox devices remain unpatched online nine months after fixes were released.
bleepingcomputer.com
· 2026-09-10
US federal agencies issued a joint advisory on Sept. 8 alleging that Chinese AI companies including Alibaba, DeepSeek, MiniMax, Moonshot AI, StepFun and Z.AI have run large-scale operations to pull outputs from US models like Claude, GPT, Gemini and Grok since late 2024. The advisory says these firms extracted billions of tokens through millions of queries, using techniques such as chain-of-thought extraction and automated evasion to dodge blocking measures, in order to train their own competing systems.
darkreading.com
· 2026-09-09