Cybersecurity

The 5-Minute Cyber Brief: September 11, 2026

The 5-Minute Cyber Brief: September 11, 2026

Published: 09/11/26 Today’s pattern is management-plane root: when the systems that configure firewalls, terminate VPN, and run ERP kernels become…

SAP OVERPASS CVE-2026-44756: unauth OS command exec on NetWeaver/Web Dispatcher

SAP OVERPASS CVE-2026-44756: unauth OS command exec on NetWeaver/Web Dispatcher

What Changed SAP’s September 2026 Patch Day, with Onapsis Research Labs, shipped Security Note 3747649 for OVERPASS (CVE-2026-44756): a memory-corruption…

Check Point twin CVSS 9.8s in VPN certificate path (CVE-2026-85102 / 85103)

Check Point twin CVSS 9.8s in VPN certificate path (CVE-2026-85102 / 85103)

What Changed Check Point disclosed on September 9, 2026 two critical flaws in VPN certificate handling on Quantum Security Gateway…

Fortinet CVE-2025-25249: PivotC2 Node.js RAT on FortiGate after cw_acd RCE

Fortinet CVE-2025-25249: PivotC2 Node.js RAT on FortiGate after cw_acd RCE

What Changed SOCRadar reports that Russian-speaking cybercrime actors have been exploiting CVE-2025-25249—an unauthenticated heap-based buffer overflow in the FortiOS and…

Cisco FMC CVE-2026-20079: Sandworm-linked and Qilin clusters hit firewall management for root

Cisco FMC CVE-2026-20079: Sandworm-linked and Qilin clusters hit firewall management for root

What Changed Cisco Talos confirmed on September 9–10 that three intrusion clusters are actively abusing Cisco Secure Firewall Management Center…

The 5-Minute Cyber Brief: September 10, 2026

The 5-Minute Cyber Brief: September 10, 2026

BlueMoon’s shared Chrome kit, Kestra’s suffix-match RCE, LiteLLM’s empty MCP session, and Windows Update Stack’s SYSTEM zero-day....

Windows Update Stack CVE-2026-81963: The Link-Following Zero-Day That Finishes the Job

Windows Update Stack CVE-2026-81963: The Link-Following Zero-Day That Finishes the Job

September Patch Tuesday’s exploited Update Stack EoP turns a low-privilege foothold into SYSTEM—and it is already in KEV....

LiteLLM CVE-2026-59822: Failed Auth Fell Through to an Empty MCP Session

LiteLLM CVE-2026-59822: Failed Auth Fell Through to an Empty MCP Session

Before 1.84.0, LiteLLM’s MCP path could replace a failed Bearer check with an empty UserAPIKeyAuth()—and CISA put it in KEV....

Kestra CVE-2026-49869: The Suffix Match That Turned Workflows Into Root Shells

Kestra CVE-2026-49869: The Suffix Match That Turned Workflows Into Root Shells

CVE-2026-49869 (CVSS 10.0) lets unauthenticated attackers bypass Kestra Basic Auth with any path ending in /configs and run root workflows....

BlueMoon: Four Espionage Groups Share One Chrome-to-SYSTEM Exploit Kit

BlueMoon: Four Espionage Groups Share One Chrome-to-SYSTEM Exploit Kit

Proofpoint’s BlueMoon kit chains Chromium patch-gap RCE with a Windows ALPC LPE—and four espionage clusters adopted it in days....

How to Stay Secure Managing End-of-Life Software

How to Stay Secure Managing End-of-Life Software

Legacy software often operates under the “if it isn’t broken, don’t fix it” mentality until a security crisis forces action.…

Best 6 Tools to Eliminate CVEs in Container Images

Best 6 Tools to Eliminate CVEs in Container Images

Key Takeaways Container image vulnerabilities have become one of the most frustrating problems in modern software delivery. A team can…

8 Best Virtual CISO Companies of 2026

8 Best Virtual CISO Companies of 2026

The virtual CISO market has changed. A few years ago, many companies hired a vCISO mainly to prepare for SOC…