Terminal

root@news:~/news$ ls -lah news/

Cisco Exploit critical Cisco confirms active exploitation of FMC auth bypass granting root access

Cisco updated its Secure Firewall Management Center advisory after confirming active exploitation of CVE-2026-20079, a CVSS 10 authentication bypass that lets unauthenticated remote attackers run scripts and commands as root. CISA added the flaw to KEV on September 9. On-premises FMC operators should apply Cisco hot fixes or fixed releases immediately, check the published license.tmp log indicator, and treat positive indicators as an incident because preventive hot fixes do not remove an existing compromise.

Microsoft Security Phishing high Passkey-themed social engineering drives Entra identity and cloud compromise

Microsoft is investigating passkey- and SSO-themed social engineering in which attackers call or text employees, then steer them into adversary-in-the-middle phishing or legitimate device-code authorization flows. Successful attacks capture or obtain session tokens, bypass normal MFA value, add attacker-controlled authentication methods, enumerate Microsoft Graph and collect cloud data. Entra defenders should correlate user reports with device-code sign-ins and authentication-method changes, revoke compromised sessions, enforce phishing-resistant credentials, and restrict unmanaged-device access.

CISA Exploit critical CISA confirms active exploitation of critical N-able N-central RCE

CISA added CVE-2026-86218 to the Known Exploited Vulnerabilities catalog on September 8, materially escalating the earlier N-central advisory from uncertain exploitation to confirmed in-the-wild risk. The CVSS 10 pre-authentication RCE affects self-hosted N-central before 2026.3.1.14. MSPs should install Hotfix 4 immediately, restrict management exposure, audit unexpected accounts and privileged remote sessions, and rotate downstream credentials if compromise indicators are found.

BleepingComputer Malware high PoisonedRefresh rootkit gives attackers fileless persistence on F5 BIG-IP APM

Sophos analysis of compromised F5 BIG-IP APM environments identified PoisonedRefresh, a Linux rootkit that infects Apache, survives BIG-IP upgrades and injects a PHP web shell only in memory while leaving on-disk scripts unchanged. The implant was likely deployed after exploitation of CVE-2025-53521, but the initial vector is not definitively established. Defenders should investigate Apache workers accessing /proc/self/maps, /run/bigtlog.pipe, unexpected Bash execution and suspicious HTTP 201 text/css responses, and rebuild confirmed-compromised appliances.

SOCRadar Exploit critical FortiGate exploitation deploys PivotC2 RAT through CVE-2025-25249

SOCRadar reports ongoing exploitation of CVE-2025-25249 against FortiGate appliances, with more than 30,000 IPs targeted and 178 devices infected with the custom Node.js PivotC2 RAT. The unauthenticated heap overflow reaches the CAPWAP control service and can yield arbitrary code execution; CISA added the flaw to KEV on September 9. Operators should patch affected FortiOS and FortiSwitchManager versions, restrict UDP/5246 exposure, hunt for PivotC2 activity, and triage exposed appliances for compromise rather than relying on patching alone.

Last content update GitHub / main