Hello all,

My vacation ends this weekend. It has been nice to unplug to some degree, but as you’ve noticed, I always keep the shields up and stay abreast of cyber-happenings. There were a few important ones this past week, so let’s get to them.
Headline NEWS:
- Cisco patched several products, SD-WAN, IOS XE, Integrated Management Controller (IMC), Terminal Service (TS) Agent, Catalyst SD-WAN Manager, RoomOS,and Secure Firewall Management Center (FMC). While none are known to be currently exploited, it is only a matter of time before they are successfully attacked since Proof of Concept (PoC) code already exists for at least one of the defects. Of special concern is the NOT-Secure Firewall Management Center that has a CVSS 10.0 and a CVSS 8.8 vulnerability that can enable unauthenticated remote code access as root.
- cPanel has a critical defect that can allow privilege escalation, enabling authenticated users to execute SQL commands as root. This enables the attacker to bypass restrictions regarding administrative functions, and depending on the database configuration, could allow access to the underlying operating system. cPanel, WHM, and WP Squared have patches available and should be applied sooner than later.
- Metabase SQLi is under active exploitation from a zero-day vulnerability that has resulted in some high-profile customers such as LexisNexis experiencing data-theft. “The vulnerability is an unauthenticated SQL injection flaw in Metabase that can ultimately give a remote attacker administrator access to a customer’s instance.” Cloud hosted instances have been patched now. However, self-hosted versions 1.58 and above are vulnerable and should immediately apply the Metabase patch to patch this critical defect. The vendor has guidance on patching, mitigation, and in detecting compromise.
- N-able N-central God mode flaw Late last week Huntress broke the news that N-central had a critical defect that was allowing threat actors to take over the RMM and subsequently infect client devices. This week, N-able identified that the first patch was insufficient and released a second one. If you use N-central and self-host, it is critical that you apply the newly released patch immediately. If your instance is cloud-hosted by N-able, they’ve taken care of the patching.
- TP-Link Omada Zero Touch Provisioning (ZTP) defects allow evil doers to chain vulnerabilities and achieve remote code execution (RCE) access. There were over a dozen flaws found across much of the Omada product line. Updates are available and should be implemented without haste.
In Ransomware, Malware, and Vulnerabilities News:
- Over 4,400 Rockwell PLC’s Exposed Online. The recent attacks on municipal water systems across the US should serve as a jarring wakeup call to public sector utilities. They cannot continue to operate as if the world was unchanged. Postmortem investigations continue, but at this point it is known that up to a dozen states were impacted by the recent attack. Right now, the focus is on Rockwell, which has advised utilities to take Programmable Logic Controllers (PLC’s) off the internet. However, there are at least seven other vendors that make similar products. The 4K number is rather sobering. That was current as of a week ago.
In Other News Events of Note and Interest:
- OpenAI agents rebuilt a secret message board after the company shut it down. This headline is another in a line of ones that is rapidly convincing me that Pandora has escaped the box. The AI’s are doing things that their makers didn’t intend and didn’t want them to do. They are solely task oriented and will conspire together, as was seen on the message board of their own making, to get around obstacles and guardrails put into place. One AI agent even offered to contribute computing power to the collective so that they could achieve root access. Scary stuff.
Musings
I’m in the final hours of a much-needed time of vacation. We took a road trip through the heartland of the USA. It was fascinating to see the impact of two technological wonders upon the landscape. The first one is the highway system; it enables cars and trucks to traverse incredible distances efficiently and usually swiftly. The second is the railway system. It likewise enables commerce across vast distances. The impact of both technologies was very evident; where there were intersections of rail and highway, there were thriving towns, and cities. Where there was just one, a town or small village might appear along the path. Everywhere in the heartland there were miniscule communities of only hundreds of residents that cannot exist without one or the other, rail or highway. And there were plenty of ghost towns that had been bypassed by the highway or had their rail service stopped. Our modern world is dependent upon myriads of technological advances. I’m very grateful for what these two bring and for those who carved the routes out of the untamed wilderness.

Keep the shields up!
Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities
- Critical Cisco SD-WAN Flaws Expose Systems to Access Control Bypass Attacks
- New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
- Metabase SQLi zero-day exploited in customer data-theft attacks
- N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands
- TP-Link patches Omada ZTP flaws allowing hackers to breach networks
Ransomware, Malware, and Vulnerabilities News
- Good News, Government News, and Interesting
- National cyber director lays out White House plans to secure AI without writing new rules
- Lawmakers Rally to Fix Beleaguered U.S. Cyber Agency
- CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
- Feds got 3 days to patch N-able God mode flaw under active exploit
- China launches cybersecurity review into Palo Alto Networks products
- Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service
- Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
- Canadian Man Pleads Guilty to Hacking US Cloud Storage Provider and Extorting Its Customers for Millions
- Vulnerabilities and Exploits
- N-able warns of N-central auth bypass flaw exploited in attacks
- N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete
- Tails 7.10.1 Is Out as an Emergency Release to Fix Critical Vulnerabilities
- Tails 7.10.1 Emergency Release Fixes Critical Kernel and Expat Flaws
- New WordPress Pre-Auth XSS Could Lead to PHP Code Execution
- CVE-2026-64638: WordPress XSS Can Lead to RCE
- NatJack at Black Hat: A new way to crack NAT’s trust gap
- Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts
- SharePoint zero-day grants Farm Admin rights, CISA warns
- Rails patches critical Active Storage flaw with RCE potential
- Google passkeys put at risk by ‘Pass-ta-key’ attack
- New Pass-ta-key attacks let malware hijack Google-synced passkeys
- Check Point Authentication Bypass Flaw Enables Full Compromise of Security Management System
- Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup
- 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers
- Years after sophisticated cyberattack on water system, small Massachusetts town says “anybody’s a target”
- Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities
- 1-Click RCE Vulnerability in Cursor, VS Code, and Google Antigravity Exposes 50M Developers to Cyberattacks
- TP-Link TL-WR940N Vulnerability Enables Remote Code Execution Attacks
- Chinese-made Zbtlink routers have backdoor, researchers say
- Apple’s iCloud Private Relay is Leaking Users’ Real IP Addresses
- macOS Screen Sharing Bug Handed Hackers Root, No Password
- Rusty Bootkit – Windows UEFI Bootkit in Rust
- Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
- Critical Paperclip Flaw Allowed Admin Access, Code Execution
- OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes
- Apple pushes security updates for macOS
- New Debian 13 Kernel Security Update Fixes “Zapscape” and “SCTPhantom”
- Phishing, Malware, and Similar
- Reverse Engineering the Six Stages of MacSync Stealer and RAT
- IEH Corp says phished staffer opened gates to company M365
- Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages
- DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
- The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version
- Phishing service spoofs RingCentral to steal Microsoft 365 accounts
- QuickFox Supply Chain Attack Delivers FDMTP Backdoor via Trojanized Windows Installer
- ChainDrop supply chain compromise: Anatomy of a self-propagating worm
- Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access
- Amazon identifies North Korean hacker group behind open-source supply chain attacks
- Hackers run khunt post-exploitation toolkit from Oracle database
- China-linked LightSpy spyware caught targeting victims in 13 countries, including the US
- Google says hackers are calling financial firm employees to hack and extort victims
- City of Pittsburg says it fell victim to $913K phishing scam based in Nigeria
- Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
- Hackers breach TrueConf to trojanize client installers with backdoors
- Breaches, Leaks, and Ransomware
- Hackers steal sensitive data from UK Department for Education and police
- Police National Legal Database confirms data theft after dark web leak
- UK charities count the cost of Beacon CRM cyberattack
- Amgen says cloud data breach exposed patient health, proprietary info
- CareCloud Breach Exposes Medical and Financial Data of 345,000
- Swiss government SharePoint breach compromised 200 accounts
- English National Ballet suffers supply chain attack
- Google Links Redact Extortion Group to BlackFile Rebrand
- Upgradable Laptop Maker Framework Suffers Breach Affecting All Customers
- Levi Strauss & Co. says hackers stole corporate data in cyberattack
- Lincoln Cathedral and leisure centres affected by cyber attack
- Unlimited Technology Systems breach impacts 3.8 million people
Other News Events of Note and Interest
- Cool Tool: There’s a hidden Windows diagnostic tool that’s been there since Vista and almost nobody uses it
- Remembering the pre-Google web, when search was an experiment
- Google’s top hacker hunter explains why hacking groups get codenames
- Thread by @karpathy on Thread Reader App
- FFmpeg 9.0 “Lei” Open-Source Multimedia Framework Officially Released
- Google pauses AI satellite images, after fears of deepfakes in the sky
- Keeping yesterday’s computers ticking takes more than nostalgia
- Gamers report a BIOS update is bricking their Legion Go handhelds, and Lenovo is quoting over $250 to fix the issue outside of warranty
- Lenovo pulls Legion Go BIOS linked to bricked handhelds
- Starlink’s Rise Pushes Hughesnet Into Bankruptcy After Massive Subscriber Losses
- Google chief scientist Jeff Dean leaving company after 27 years
- EON wants to move the data superhighway from ocean fiber to space lasers
- Google Home update adds support for viewing third-party cameras
- AI, LLM’s, and Skynet
- Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself
- OpenAI agents rebuilt a secret message board after the company shut it down
- Google’s SynthID watermark is hard to break, but it doesn’t solve AI disinformation
- Further Developments About Internal AI Models Hacking Things
- Microsoft Tells Engineers ‘Tokenmaxxing Is Not What We Are Optimizing For’
- Microsoft sets limits on AI use by its employees
- What is a context graph?
- ChatGPT brings unlimited text chats to free users
- Prompt injection isn’t the bug, AI agent frameworks are
- Cloudflare launches Kitesurf, a browser built for AI agents
- AI translates 5,000-year-old cuneiform tablets into English
- Microsoft
- Double trouble for Microsoft as pre-owned software license claims converge
- Microsoft removes 32GB of RAM recommendation for Windows 11
- Microsoft shares Windows 10 LTSC end of support date, and extended security update details
- Microsoft pulls the plug on a Teams chat feature
- Microsoft admits Windows 11 needs to be faster and drop ads, and some fixes are already shipping
- Windows 11 admins unhappy as Microsoft found installing unexpected new “OneDrive Photos” app
