FlagThis — Daily Cybersecurity Intelligence Briefing

FILTERING BY: CLEAR FILTER

CVE-2026-93616: Critical Unauthenticated RCE in Check Point Management Server

In September 2026, Check Point disclosed CVE-2026-93616, a critical unauthenticated remote code execution flaw affecting Security Management Server and Log Server versions R80.30 through R80.40 prior to hotfix CP‑HF‑2026‑09‑15. The vulnerability, scored CVSS v3.1 9.8, stems from insufficient input validation in the web‑based management interface’s file upload endpoint (/msa/upload.php), allowing an attacker to embed directory‑traversal sequences (e.g., \"../\") in the filename parameter, write arbitrary scripts outside the intended directory, and execute them with root privileges. Active exploitation has been observed in targeted attacks against high‑value enterprises, prompting emergency patches via LivePatch and advisories from Check Point, CISA, and multiple threat‑intel feeds.

MI5 Designates CGTRI as MSS Front Organization in Academic Influence Campaign

MI5 has formally designated the China Global Talent Recruitment Initiative (CGTRI) as a front organization for the Chinese Ministry of State Security (MSS). The campaign exploits academic openness within the UK higher education sector to facilitate intelligence collection through research grants, joint AI projects, and talent recruitment programs. By embedding MSS interests within legitimate scientific collaborations, the actor aims to exfiltrate dual-use technological data, including proprietary algorithms and machine learning research. Over 100 UK academics have been identified as unwitting participants in these efforts, necessitating immediate institutional reviews and the severance of all CGTRI-affiliated research ties to protect UK national security and technological sovereignty.

Graphalgo Campaign Targets HashiCorp Terraform Registry via Malicious Go-Based Providers

The Graphalgo campaign involves the distribution of malicious Go modules and Terraform providers via the HashiCorp Terraform Registry. Threat actors, attributed to a DPRK-linked group, utilize fake job application lures to induce the initialization of compromised providers such as gocommunity-io/dockerd and kreuzwenker/terraform-provider-vault. These modules execute obfuscated init routines and goroutines to deploy a Go-compiled Remote Access Trojan (RAT) and establish reverse TCP shells. The campaign has affected over 120 organizations through 379 observed downloads, facilitating credential theft, persistence via cron, and lateral movement within CI/CD pipelines.

Linux Kernel ARM64 KVM VHE Flaw Enables Guest Host Memory Read/Write

A race condition in the ARM64 KVM virtualization host extensions (VHE) path allows a guest VM to retain access to freed host memory when nested virtualization is enabled, leading to arbitrary host kernel memory read/write. The flaw, tracked as CVE-2026-89775 (CVSS 9.8), can be chained via the ITScape exploit to achieve full guest‑to‑host escape and root‑level code execution on the host. Affected systems include any Linux kernel on ARM64 with KVM VHE and nested virt enabled, notably RHEL 8.4 EUS and its derivatives. Immediate mitigation requires applying the upstream kernel patch or disabling nested virtualization.

ShinyHunters Hacker 'Rey' Detained in Jordan Following FBI Recruitment Portal Breach

Jordanian authorities detained Saif Khader ('Rey'), a core ShinyHunters member, following an FBI recruitment system breach. Attackers leveraged phishing lures via fbi-recruit.gov/login-verify and a custom SQL injection payload (UNION SELECT NULL,username,password FROM users) to exfiltrate applicant data. Post-exploitation utilized Cobalt Strike beacons (updateservice.cloud, statsapi.net) and Mimikatz for credential harvesting. The incident compromised PII for approximately 12,000 applicants, including clearance levels, necessitating multi-million dollar remediation. Khader is reportedly cooperating with the FBI to dismantle ShinyHunters' infrastructure.

Microsoft Azure AI Foundry CVSS 10.0 Authentication Bypass CVE-2026-85889 and Windows Zero-Day Exploitation

During Microsoft's September 2026 Patch Tuesday, a critical CVSS 10.0 authentication bypass (CVE-2026-85889) was disclosed in the Azure AI Foundry internal management API. This vulnerability allowed unauthenticated network attackers to invoke privileged functions, enabling immediate administrator role escalation. A subsequent chain of five vulnerabilities (CVE-2026-85890 through CVE-2026-85894) facilitated cross-tenant access, session hijacking, and arbitrary code execution within the Foundry sandbox. Concurrently, two Windows zero-day vulnerabilities in win32k.sys (CWE-416) and spoolsv.exe (CWE-120) were observed being actively exploited in the wild for approximately 72 hours before out-of-band patches were released. While the Azure vulnerability was mitigated server-side, immediate client-side patching is required for all Windows systems to prevent kernel-mode exploitation.

Warlock Ransomware Exploits Microsoft SharePoint Vulnerabilities

The Warlock ransomware group is conducting targeted campaigns against critical infrastructure sectors, including energy, water, and healthcare, by exploiting unpatched Microsoft SharePoint vulnerabilities. Attackers utilize CVE-2023-29357 for unauthenticated remote code execution (RCE) and CVE-2022-24521 for privilege escalation. Following initial access, the threat actor deploys webshells for persistence and utilizes living-off-the-land binaries like certutil and bitsadmin for lateral movement. The campaign employs AES-256 and RSA-4096 hybrid encryption coupled with double extortion via data exfiltration to leak sites. Immediate application of SharePoint Cumulative Updates is required to mitigate these high-impact exploitation vectors.

Chainalysis Reactor: AI-Driven Tracing of the $387M Bitget Bridge Exploit

On September 28, 2024, attackers exploited smart contract vulnerabilities within Bitget's cross-chain bridge validator sets, enabling unauthorized minting and burning of wrapped assets. The exploit resulted in the theft of approximately $387 million, comprising ~120,000 ETH and various ERC20, BEP20, and SPL tokens. Attackers utilized Wormhole, Multichain, and Synapse bridges alongside mixers to obfuscate fund movements. Utilizing the Chainalysis Reactor platform and graph-based machine learning models, investigators reduced the manual reconciliation time from over 20 hours to under 10 minutes, successfully clustering 1,400 associated addresses and identifying over 15% of the stolen assets moving toward exchange hot wallets for potential recovery.

Google Gemini 4 Argon Enters Post-Training and Enhances Agentic Cyber Defense

Google DeepMind has transitioned the Gemini 4 Argon model into the early post-training phase, significantly expanding its operational capacity for autonomous security tasks. By increasing the output token ceiling from 64k to 1M tokens, Argon enables sustained agentic workflows, specifically for automated vulnerability discovery, validation, and patching. While Argon demonstrates benchmark leadership over OpenAI’s GPT6 Astra and Anthropic’s Claude Opus 5.5, Google Threat Intelligence Group (GTIG) data highlights an escalating risk: AI-identified vulnerabilities are being exploited by threat actors within days of disclosure. This advancement accelerates the dual-use nature of frontier LLMs in the cyber domain.

Cisco Catalyst SD-WAN Manager Authentication Bypass CVE-2026-76504

Cisco PSIRT has disclosed CVE-2026-76504, a critical authentication bypass vulnerability in Cisco Catalyst SD-WAN Manager (vManage) affecting multiple release branches. The flaw arises from improper handling of URL-encoded characters within the j_security_check API endpoint, allowing unauthenticated remote attackers to bypass security controls using crafted requests, such as POST /%6a_security_check. Active exploitation has been confirmed in the wild, prompting immediate inclusion in the CISA Known Exploited Vulnerabilities catalog. Successful exploitation grants full administrative control over the SD-WAN control plane, enabling lateral movement and potential compromise of the entire managed network infrastructure. Immediate patching is required as no software workarounds are available.


LINK COPIED TO CLIPBOARD