Eclypsium's September InfraTrust Pulse report logged 158 new security advisories across 17 vendors between August 25 and September 17, covering 1,699 vulnerabilities. Of these, 42 were rated critical, eight scored a maximum 10.0 severity, 71 could be exploited remotely without authentication, and five advisories included flaws later added to CISA's Known Exploited Vulnerabilities catalog. The report singles out a maximum-severity Cisco Secure Firewall Management Center authentication bypass, CVE-2026-20079, which Cisco confirmed on September 9 was being actively exploited, allowing attackers to run commands as root without credentials.
bleepingcomputer.com
· 2026-09-23
CISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 series switches, to its Known Exploited Vulnerabilities catalog after confirming active attacks. The flaw allows unauthenticated LAN attackers to run OS commands via crafted HTTP requests, and federal agencies must secure affected devices by Thursday under Binding Operational Directive 26-04. Zyxel issued firmware fixes on June 16 but has not yet updated its advisory to acknowledge exploitation.
bleepingcomputer.com
· 2026-09-22
Celeste Amadon, founder of AI dating app Known, launched a public nomination campaign called 'San Francisco's Hot List,' inviting people to nominate attractive, accomplished singles in the city. The X post drew mixed reactions—mockery alongside genuine engagement—but generated over 15,000 submissions within a day, according to Amadon. The campaign taps into a growing narrative pushing back on San Francisco's reputation as an undateable, style-deficient tech hub.
wired.com
· 2026-09-04