This isn&#;x26;#;39;t a new attack, but something I saw "pop-up" in our logs this week:

A recent observation in network logs has highlighted an interaction between Rondo and Geoserver, which, while not a novel attack vector, was noted as a recurring event. The report indicates that this activity was specifically observed "popping up" in logs during the week of July 22nd. The nature of the interaction suggests an ongoing or recently re-emergent pattern of activity rather than a newly discovered vulnerability or exploit.
Geoserver is an open-source server for sharing geospatial data, widely used in web mapping applications and geographic information systems (GIS). It allows users to publish data from various sources using open standards. Its broad adoption in government, academic, and commercial sectors makes it a frequent target for reconnaissance and potential exploitation attempts, as compromise could lead to data exfiltration or disruption of critical mapping services.
Rondo, in this context, likely refers to a tool or framework used for network scanning, vulnerability assessment, or potentially exploitation. While specific details about the Rondo component are not provided, such tools are commonly employed by both legitimate security researchers and malicious actors to identify accessible services and potential weaknesses in internet-facing infrastructure. The "pop-up" in logs suggests an automated or semi-automated process interacting with Geoserver instances.
The observed interaction could manifest in several ways, such as Rondo attempting to enumerate Geoserver versions, probe for known vulnerabilities in its API endpoints, or even attempt default credential attacks. This class of activity typically involves sending specially crafted requests to a target server and analyzing the responses for tell-tale signs of a particular software version, configuration, or exploitable flaw.
For organizations operating Geoserver instances, typical mitigation strategies involve ensuring all software is kept up to date with the latest security patches. This is crucial as many public exploits target known vulnerabilities that have already been addressed by vendors. Additionally, implementing robust access controls, placing Geoserver behind a web application firewall (WAF), and regularly reviewing server logs for unusual activity are standard best practices. Network segmentation can also limit the blast radius if an external-facing Geoserver is compromised.
The re-emergence of this specific interaction in logs underscores the continuous nature of cyber threats and the importance of vigilant monitoring. Even if an attack vector is not new, its renewed appearance can indicate a shift in attacker focus, the availability of new tooling, or a broader scanning campaign targeting widely deployed software. This highlights the need for ongoing security assessments and adaptive defense strategies to protect critical infrastructure.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed