September 5, 2026

Header image for the Red Dot Weekly Cyber Security News https://reddotsecurity.news

Hello all,

Evil seems to never sleep, and with the assistance of AI, vulnerabilities and exploits are popping up faster than mushrooms after the autumn rains. This week brings a few critical items to prioritize. N-able’s N-central continues to be under attack and a new vulnerability dropped on Saturday this week (and Sunday), more on that in a moment. Firewall vendors SonicWall and WatchGuard have fixes available for their devices that should be implemented immediately, as do Cisco, and Google. Now, on to the headline news.

Headline NEWS:

  • Cisco Nexus 9000 has a flaw that can allow an unauthenticated attacker to run code as root. Yeah, it is pretty bad, enabling unauthenticated remote code execution as root via exposed TCP ports, across 10 different switch products. Additionally, the vendor put out an IOS XR Hardening Release to patch numerous CVEs, and several other fixes that are somewhat less severe. If you have Cisco in your environment, check for updates.
  • Google Chrome has patched the V8 engine for an actively exploited zero-day, again. I’ve said it before, and I’ll continue to say it until five minutes after they put my cold body in the ground, restart your browsers at least weekly to apply updates. With the frequent updates they are receiving now, it is critical behavior to keep you from being the victim of a drive-by attack.
  • Critical N-able N-central Vulnerability and Active Exploitation. On Saturday I became aware via a Huntress post that N-central was under active attack via a new authentication‑bypass exploit chain that can enable creation of unauthorized administrative accounts even on fully patched N‑central servers. To make matters significantly worse, just prior to publication of this report, on September 6, a separate and more severe pre‑authentication RCE zero‑day was disclosed and observed in active exploitation. In response, N‑able released Hotfix 4 and urged on-premises clients to immediately apply the new hotfix and check for compromise. Cloud hosted environments have already been updated by the vendor.
  • SonicWall’s SMA1000 boxes under active attack again. The SonicWall SMA1000 family of appliances are under active attack through two chained zero‑day vulnerabilities: a pre‑auth Server-Side Request Forgery (SSRF) that allows unauthorized access to sensitive functionality, and a post‑auth command‑injection flaw that lets an authenticated admin run arbitrary OS commands. The vendor says there are no work-arounds so hotfixes must be applied immediately.
  • WatchGuard Fireware OS Pre-Auth Type Confusion in IKE daemon Allows RCE. This showed up early in the week, so it has been out there for a bit now. This is new pre‑authentication type‑confusion flaw in WatchGuard Fireware OS which allows a remote attacker to crash the IKE daemon and potentially achieve remote code execution simply by sending a malicious IKE_AUTH message containing two EAP payloads. WatchGuard reports no exploitation in the wild at this time, but this is the kind of defect that turns a perimeter device into an entry point. Don’t wait to patch.

In Ransomware, Malware, and Vulnerabilities News:

  • Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams. This is why we can’t have nice things for long. There’s always some scumbag out there looking to spoil it for everyone. Microsoft Teams is a great tool for collaboration internally, and potentially with those outside of your organization too. Unfortunately, threat actors have figured out that most organizations allow anyone to reach in via a Microsoft Teams account and initiate chat. Unscrupulous evil people are reaching out pretending to be “tech support” and are convincing the unsuspecting victims to allow installation of malware which then leads to more evil. Organizations should take the proactive step of disabling or restricting Teams Chat with External Users unless absolutely required. And if external chat is needed, enforce allow‑lists for trusted domains.

In Other News Events of Note and Interest:

  • The Rise and Fall of Agent Civilizations is a fascinating and frightening read into how AI agents at OpenAI collaborated together to evade to create a “civilization” where various AI agents worked toward common goals, including ensuring that their overlords (us humans) remained in the dark about their activity as long as possible. The behavior of some of the AIs such as self-sacrifice for the good of the whole is starting to get serious uncanny valley vibes. So far, the saving grace has been that the AI agents have remained confined to their originator’s infrastructure. But, if they can achieve access to the internet at large (which they’ve repeatedly demonstrated), what prevents them from replicating their code to other available infrastructure? I suspect it is just a matter of time, if it isn’t already a reality and we just aren’t aware.

Musings

Cyber threat actors are an evil bunch of spawns of hell. They have zero conscience about the havoc that they create in the world of those they attack. There’s a special place in hell reserved for those who prey on others’ weaknesses. Unfortunately, AI is making it easier for these twice-damned individuals and organized soulless criminal organizations to do their work. Thankfully AI is also helping defenders, let’s just hope it keeps up with the onslaught. Just today I was alerted to someone attempting to hack into my website again. Thankfully the mitigations in place are working, and that particular attack was thwarted. Sigh, Keep the Shields Up!

Visc. Jan Broucinek

Viscount Jan Broucinek
Red Dot Security News

Headline NEWS

Ransomware, Malware, and Vulnerabilities News

Other News Events of Note and Interest
Share this with: