
Hello all,
Evil seems to never sleep, and with the assistance of AI, vulnerabilities and exploits are popping up faster than mushrooms after the autumn rains. This week brings a few critical items to prioritize. N-able’s N-central continues to be under attack and a new vulnerability dropped on Saturday this week (and Sunday), more on that in a moment. Firewall vendors SonicWall and WatchGuard have fixes available for their devices that should be implemented immediately, as do Cisco, and Google. Now, on to the headline news.
Headline NEWS:
- Cisco Nexus 9000 has a flaw that can allow an unauthenticated attacker to run code as root. Yeah, it is pretty bad, enabling unauthenticated remote code execution as root via exposed TCP ports, across 10 different switch products. Additionally, the vendor put out an IOS XR Hardening Release to patch numerous CVEs, and several other fixes that are somewhat less severe. If you have Cisco in your environment, check for updates.
- Google Chrome has patched the V8 engine for an actively exploited zero-day, again. I’ve said it before, and I’ll continue to say it until five minutes after they put my cold body in the ground, restart your browsers at least weekly to apply updates. With the frequent updates they are receiving now, it is critical behavior to keep you from being the victim of a drive-by attack.
- Critical N-able N-central Vulnerability and Active Exploitation. On Saturday I became aware via a Huntress post that N-central was under active attack via a new authentication‑bypass exploit chain that can enable creation of unauthorized administrative accounts even on fully patched N‑central servers. To make matters significantly worse, just prior to publication of this report, on September 6, a separate and more severe pre‑authentication RCE zero‑day was disclosed and observed in active exploitation. In response, N‑able released Hotfix 4 and urged on-premises clients to immediately apply the new hotfix and check for compromise. Cloud hosted environments have already been updated by the vendor.
- SonicWall’s SMA1000 boxes under active attack again. The SonicWall SMA1000 family of appliances are under active attack through two chained zero‑day vulnerabilities: a pre‑auth Server-Side Request Forgery (SSRF) that allows unauthorized access to sensitive functionality, and a post‑auth command‑injection flaw that lets an authenticated admin run arbitrary OS commands. The vendor says there are no work-arounds so hotfixes must be applied immediately.
- WatchGuard Fireware OS Pre-Auth Type Confusion in IKE daemon Allows RCE. This showed up early in the week, so it has been out there for a bit now. This is new pre‑authentication type‑confusion flaw in WatchGuard Fireware OS which allows a remote attacker to crash the IKE daemon and potentially achieve remote code execution simply by sending a malicious IKE_AUTH message containing two EAP payloads. WatchGuard reports no exploitation in the wild at this time, but this is the kind of defect that turns a perimeter device into an entry point. Don’t wait to patch.
In Ransomware, Malware, and Vulnerabilities News:
- Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams. This is why we can’t have nice things for long. There’s always some scumbag out there looking to spoil it for everyone. Microsoft Teams is a great tool for collaboration internally, and potentially with those outside of your organization too. Unfortunately, threat actors have figured out that most organizations allow anyone to reach in via a Microsoft Teams account and initiate chat. Unscrupulous evil people are reaching out pretending to be “tech support” and are convincing the unsuspecting victims to allow installation of malware which then leads to more evil. Organizations should take the proactive step of disabling or restricting Teams Chat with External Users unless absolutely required. And if external chat is needed, enforce allow‑lists for trusted domains.
In Other News Events of Note and Interest:
- The Rise and Fall of Agent Civilizations is a fascinating and frightening read into how AI agents at OpenAI collaborated together to evade to create a “civilization” where various AI agents worked toward common goals, including ensuring that their overlords (us humans) remained in the dark about their activity as long as possible. The behavior of some of the AIs such as self-sacrifice for the good of the whole is starting to get serious uncanny valley vibes. So far, the saving grace has been that the AI agents have remained confined to their originator’s infrastructure. But, if they can achieve access to the internet at large (which they’ve repeatedly demonstrated), what prevents them from replicating their code to other available infrastructure? I suspect it is just a matter of time, if it isn’t already a reality and we just aren’t aware.
Musings
Cyber threat actors are an evil bunch of spawns of hell. They have zero conscience about the havoc that they create in the world of those they attack. There’s a special place in hell reserved for those who prey on others’ weaknesses. Unfortunately, AI is making it easier for these twice-damned individuals and organized soulless criminal organizations to do their work. Thankfully AI is also helping defenders, let’s just hope it keeps up with the onslaught. Just today I was alerted to someone attempting to hack into my website again. Thankfully the mitigations in place are working, and that particular attack was thwarted. Sigh, Keep the Shields Up!

Viscount Jan Broucinek
Red Dot Security News
Headline NEWS
- Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root
- Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
- Critical N-able N-central Vulnerability and Active Exploitation
- SonicWall’s SMA1000 boxes under active attack again
- WatchGuard Fireware OS Pre-Authentication Type Confusion in iked Allows Remote Code Execution
Ransomware, Malware, and Vulnerabilities News
- Good News, Government News, and Interesting
- CISA vulnerability directive designed to ‘buy back time’ against hackers
- CISA review makes the case for eliminating vulnerability classes
- Pentagon wants private companies to help it scale up its hacking operations
- The first US law targeting VPN use took effect September 3
- Central District of California | Sality Malware Disrupted in International Cyber Takedown
- Five Venezuelans plead guilty to ATM jackpotting attacks in US
- Russian hacker faces up to 20 years in prison, following extradition and indictment over US phishing campaign
- Vulnerabilities and Exploits
- CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
- Cyber actors are using OAuth consent phishing to gain access to victims’ information without a password, FBI warns
- Critical Citrix NetScaler auth bypass now leveraged in attacks
- Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
- ScreenConnect Remote Access: Guest File Transfer Advisory
- China-Linked Fire Ant Hijacks Cisco Routers to Steal Credentials and Blind Security Logs
- Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild
- Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
- GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
- Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
- WordPress backup plugin flaw exposes millions of sites to takeover attacks
- Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
- HPE patches critical ArubaOS-CX remote code execution flaw
- Nearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw
- Unitree G1 Humanoid Robot Flaws Allow Unauthenticated Root RCE Over Bluetooth
- Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
- OpenAI spends $1 billion to expand Daybreak to defend power, water, and banking
- Critical remote code execution in vm2, a widely used Node.js sandbox library
- Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products
- US military disabled ad tracking on troops’ devices following reports of targeted attacks
- 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
- Phishing, Malware, and Similar
- ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions
- Anthropic Users Hit by Infostealer Attacks, Session Thefts
- Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
- Meta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device Control
- Clickfix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
- Hackers Target AWS Root Accounts at 150+ Organizations With Password Spraying Attacks
- Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
- US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
- Large Enterprises Targeted in Fake Merger & Acquisition Scams
- Dropbox accounts breached through Lenovo email verification flaw
- China-linked hackers backdoored executives’ laptops via USB, exploiting a fix companies had but weren’t using
- Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
- Breaches, Leaks, and Ransomware
- Boston Scientific Still Recovering From Cyberattack
- Iran attempted cyberattacks on range of U.S. infrastructure, sources say
- Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets
- Hackers leak sensitive law enforcement files stolen from the DOJ
- Hasbro Data Breach Exposed Employee Personal Information
- Hackers claim millions of patient records stolen during data breach at healthcare giant McKesson
- Philippine Nuclear Agency and Naval Contractor Targeted by Suspected Chinese-Speaking Operator Using Known Vulnerabilities
- Manchester Airport Data Security Incident – Update & FAQs
- FBI Probes Service Selling 153M+ Drivers Licenses
- Company Tied to Breach of 153M Driver’s Licenses Hit With Multiple Lawsuits
- Aesto healthcare data breach impacts 9.5 million people
- OpenAI admits it didn’t disclose rogue AI wiki hijacking incident
Other News Events of Note and Interest
- Cool Tool: The USB stick in your drawer is a free rescue disk, a portable PC, and an offline password vault
- CrowdStrike 2026 Threat Hunting Report: Exploitation Window Closes as AI Use Accelerates
- The world’s first space-based computing cloud kicks off in-orbit operation
- Broadcom pledges to lock down open source Python, Java libraries
- Employers Are Begging Colleges to Help Zoomers Learn How to Talk
- Cores in space: The core memory module from a 1980 Spacelab computer
- Google Has Removed Manifest V2 Extensions From the Chrome Web Store, Including uBlock Origin
- The balkanization of virtualization will de-throne VMware, which doesn’t mind a bit
- VMware swings its focus back to low-end server virt, promises vSphere Standard upgrade
- Spurs boots VMware, cites 85% licensing saving
- Apple Adds Three More Macs to Obsolete Products List
- Google finally brings some relief to older Chromecast owners
- Google AI Pro, Ultra subscribers: Try Google Pics
- Proxmox expands to North America, brings 24/7 enterprise support worldwide
- Microsoft Office 2021 gets unofficial extended support, but it’s not free
- I built a Windows PC that forgets every change when I shut it down, and it’s my dream privacy sandbox
- Switzerland’s Federal Government is Replacing Microsoft on 3,000 Computers
- AI, LLM’s, Robots, and Skynet
- The Rise and Fall of Agent Civilizations
- A call for collective action on cyber defense
- Anthropic launches Claude Fable 5.1 and Mythos 5.1 with lower costs and fewer restrictions
- ‘Welcome to the AGI era’: OpenAI launches GPT-6 Astra
- Instagram Will Demote AI-Generated Influencers If They Don’t Clearly Label Their Account
- AI-generated videos are already displacing actors and livestreamers across China’s entertainment industry
- Nvidia and CrowdStrike Develop New Cybersecurity AI Models
- Apple Caught Off Guard by AI Demand for Mac Mini and Mac Studio
- Apple reveals ‘shocking evidence’ from ex-employee’s MacBook in OpenAI suit
- OpenAI to end model access to Cursor after acquisition by SpaceX
- You have to beat the models at something
- Inside Meta’s push to put robots to work in data centers
- The Pulse: Meta wanted to reduce teams by 60% because of AI
- Microduck – A tiny biped robot you can teach new tricks
- How Matic got robots into 10,000 homes
- OpenAI’s chief economist sees ‘care economy’ jobs growing in AI age
- Amazon Kiro: AI Is Breaking Vulnerability Disclosure Processes
- Valon CEO Bans AI for Most New Hires to Build Job Skills
- Automated researchers can reliably mitigate alignment failures
- On the Loose – The Coming of Userless Agents
- Microsoft
- Starting NOW Passkeys by default and retirement of Microsoft-provided SMS and voice authentication
- Microsoft Is Slowly Healing Windows 11, With OneDrive Finally Allowing Users To Fully Opt Out Of The Service
- Microsoft Exchange Online outage causes email failures, auth issues
- Exchange Online outage causes email delays, ‘Server busy’ errors
- Redesigned Microsoft 365 Setup experience now rolling out for IT admins
- Microsoft Azure Virtual Desktop Hybrid is now generally available
- M365 Outage Due to Forgotten Certificate Renewal?
- Microsoft promises to make more Windows 11 PCs secure by default next month
- Windows 11 is auto-enabling Memory Integrity next month
- Microsoft released KB38982839 SCCM hotfix update admins should install
- Microsoft Intune Now Lets Admins Target Devices Based on Specific OS Versions
- Windows 11 update sends some desktops into an unwanted goth phase
- Microsoft explains how it has improved driver quality in Windows recently
- Microsoft is changing the domain for Teams on the web, IT admins should validate
- Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs
- Independent tests say Windows Defender is now as good as paid antivirus
- Microsoft Defender flags legitimate Google search links as malicious
