LIVE · cybersecurity feed
Live wire
malware

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter REVSTEALER ramps up Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode GuardBreaker: Derailing AI-assisted malware analysis with a code comment DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive […]

zeroday.news ·

Attackers are actively exploiting a critical vulnerability in Cisco Secure Firewall Management Center (FMC) to deploy Qilin ransomware, according to recent reports. The flaw, which has not yet been assigned a CVE identifier in the provided information, allows for the deployment of ransomware, indicating a significant risk to affected systems.

In a related development, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added several vulnerabilities to its Known Exploited Vulnerabilities catalog. These include flaws affecting Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler. CISA also updated its catalog with actively exploited vulnerabilities in Microsoft Windows, N-able N-central, and Adobe products.

Google has addressed the seventh actively exploited Chrome zero-day of 2026, highlighting ongoing threats to web browsers. This particular zero-day was reportedly exploited by four distinct nation-state actors within a 12-day period using the same exploit kit.

Another significant vulnerability, CVE-2026-85706 in GitLab, is being actively exploited. This flaw allows for a full file read with a single unauthenticated HTTP request and was reportedly exploited within 24 hours of its discovery.

Microsoft's recent Patch Tuesday was substantial, addressing 974 CVEs. Among these were two zero-day vulnerabilities and 20 wormable bugs, emphasizing the breadth of security issues being patched.

Beyond these specific vulnerabilities, a new fileless Linux rootkit named PoisonedRefresh has been identified. This rootkit injects PHP web shells directly into the memory of F5 BIG-IP APM servers, making detection more challenging.

In other attack news, a UK Council attack has been linked to the mass exploitation of a SonicWall flaw. Additionally, a WeChat worm has been reported that can hijack user accounts without requiring the victim to answer a call.

Researchers have also released ShieldCrash, a proof-of-concept exploit for a Microsoft Defender zero-day vulnerability, under the name Chaotic Eclipse. This indicates potential future threats to Microsoft Defender users.

Finally, a separate incident saw hackers drain $320 million from the Liquid Network, though most of the stolen funds were subsequently returned.

malwarenation-stateai
ShareXLinkedInWhatsAppFacebook

More News

view all →
malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s