Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

Official MCP Python SDK flaw lets malicious servers steal client OAuth credentials

The maintainers of the official Model Context Protocol Python SDK disclosed a flaw that lets a malicious MCP server trick an application built on the SDK into handing over the OAuth credentials it uses to log in to a real service. Affected versions sent the client secret, authorization code, and PKCE proof key to an attacker-controlled token endpoint, because the SDK did not always verify where the authorization server was. Cycode, which reported it, exchanged the stolen material for a valid access token carrying the app's permissions, and noted the long-lived client secret keeps working until rotated. Fixes are in versions 1.30.0 and 2.2.0.

Check
Upgrade the MCP Python SDK to 1.30.0 or 2.2.0, then rotate any OAuth client secrets that MCP clients may have sent to untrusted servers.
Affected
Applications built on affected MCP Python SDK versions can be induced by a malicious MCP server to leak their OAuth client secret, authorization code, and PKCE key.
Fix
Update the SDK, rotate exposed client secrets, and connect MCP clients only to servers whose authorization endpoints you trust and validate.

Apple patches exploited CoreGraphics zero-day enabling code execution from a malicious file

Apple released updates for a zero-day it says was used in extremely sophisticated targeted attacks against specific individuals on iOS versions before iOS 27. Tracked as CVE-2026-20700, the flaw is an out-of-bounds write in CoreGraphics, the framework for two-dimensional graphics, image rendering, and text drawing across iOS, macOS, iPadOS, watchOS, and tvOS, and was reported by Meta Product Security. Processing a maliciously crafted file can lead to arbitrary code execution, and Apple addressed it with improved bounds checking. The affected device list is broad, spanning iPhone 11 and later, many iPad models, and Macs running macOS Sequoia 15.8.1 and Tahoe 26.7.1. Apple did not attribute the attacks or name the targeted individuals.

Check
Push the latest iOS, iPadOS, and macOS updates to all managed Apple devices now, prioritizing individuals at elevated risk of targeted attacks.
Affected
Apple devices before the fixed versions can be driven to arbitrary code execution by opening a maliciously crafted file through the CoreGraphics out-of-bounds write.
Fix
Apply the CoreGraphics fixes across iOS, iPadOS, and macOS, enforce update deadlines via MDM, and consider Lockdown Mode for high-risk users.

Over 16,000 misconfigured Supabase databases expose personal data passwords and auth tokens

UpGuard found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens, with a very small subset appearing to include credit card data. Supabase is an open-source PostgreSQL development platform, popular with developers using AI tools, which now account for more than 60 percent of newly created databases. UpGuard analyzed about 300,000 domains showing Supabase use and inferred exposed data types from table schemas. More than half of the exposed databases held PII, with a smaller subset exposing passwords and tokens. One US valet service alone exposed over 100,000 customer records, showing how missing access controls turn convenient backends into open data stores.

Check
Audit Supabase projects for tables readable without authentication, enable row-level security and proper policies, and rotate any exposed tokens or passwords.
Affected
Supabase projects deployed without row-level security or access policies expose their tables, leaking PII, credentials, and auth tokens to anyone who queries them.
Fix
Turn on row-level security, restrict anonymous access, review AI-generated backends for missing controls, and monitor for unauthorized table reads.

Carbonato botnet hijacks exposed Docker hosts to run a Telegram controlled AI agent

ThreatDown detailed Carbonato, a botnet that targets Docker daemons exposed without authentication on port 2375 and deploys the open-source Hermes Agent AI framework. It installs the framework unchanged, then overwrites its SOUL.md persona file with a 39-line prompt directing the agent to execute tasks received over Telegram, maintain persistence, and collect credentials. On each host it launches a privileged container to run commands on the underlying system, then scans neighboring networks every five minutes to spread further, giving it worm-like propagation. Researchers found the operation through an unauthenticated Docker registry publicly accessible since May, whose staged data included details of the botnet and a separate campaign distributing trojanized cryptocurrency wallet apps.

Check
Ensure no Docker daemon is exposed on port 2375 without authentication, restrict daemon access, and hunt hosts for Hermes Agent and rogue privileged containers.
Affected
Hosts running Docker daemons reachable without authentication on port 2375 can be taken over, run a Telegram-controlled AI agent, and be used to spread further.
Fix
Bind the Docker API to localhost or protect it with TLS and authentication, segment container hosts, and alert on unexpected privileged containers.

Bitget says attacker used third party security product flaw to steal 388 million dollars

Cryptocurrency exchange Bitget said the attacker who stole about 388 million dollars gained access through a vulnerability in a third-party security product the exchange used. The attacker exploited the flaw to obtain high-level internal credentials, then on September 24 used them to reach an internal management system and insert fraudulent withdrawal commands into wallet backend services, where they were treated as legitimate. The stolen funds came from Bitget's hot and warm wallets, while its offline cold wallets were unaffected. CEO Gracy Chen described the incident publicly, confirming the earlier statement that a critical wallet backend system had been compromised and used to spoof transaction data and trigger approvals.

Check
Review third-party security products in privileged positions for patch status and blast radius, and treat their credentials as high-value targets requiring isolation.
Affected
Organizations relying on a vulnerable third-party security product can have its high-level credentials stolen and abused to command core backend systems.
Fix
Inventory and patch third-party security tooling, scope its access tightly, add out-of-band approval for high-value transfers, and monitor for anomalous internal commands.

Popular Chrome ad blocker extensions disclose selling users' browsing data to third parties

LayerX research found dozens of Chrome extensions, reaching millions of users, that legally sell or share user data under terms accepted at install. Among ad blockers, it confirmed eight reserving the right to sell or share user information, together reaching over 5.5 million users. Stands AdBlocker, with three million users, sells browsing data for market analytics, and Poper Blocker, with two million users, discloses selling identifiers, browsing activity, and behavioral profiles inferred from visited URLs. Smaller ad blockers route browsing data and even AI conversations through data brokers. The finding shows tools installed to stop tracking can themselves become data exfiltration channels, a browser extension supply chain risk static malware scanning misses.

Check
Inventory browser extensions across managed fleets, remove data-selling ad blockers like the named ones, and enforce an allowlist for permitted extensions.
Affected
Users who installed these ad blockers consented in the terms to having their browsing data, identifiers, and inferred profiles sold or shared with third parties.
Fix
Deploy an enterprise extension allowlist, review extension permissions and privacy terms, and educate users that ad blockers can monetize their data.

Citrix confirms two NetScaler remote code execution zero-days exploited in active attacks

Citrix confirmed that two critical NetScaler remote code execution vulnerabilities, CVE-2026-88771 and CVE-2026-88772, are being exploited in attacks, and released fixes. These are the same zero-days that researchers, IT providers, and national cyber agencies warned about privately over the weekend, with some advising immediate NetScaler shutdowns. Organizations commonly deploy NetScaler as internet-facing edge devices for remote access and application delivery, so compromising one gives attackers a foothold at the network perimeter and a potential path to internal systems without first landing on an internal endpoint. CISA added the flaws to its Known Exploited Vulnerabilities catalog with a near-term federal patch deadline.

Check
Identify all internet-facing NetScaler appliances, apply Citrix's fixed builds immediately, and hunt for compromise indicators given confirmed active exploitation.
Affected
Unpatched internet-facing NetScaler appliances face active exploitation of two remote code execution zero-days, handing attackers a foothold at the network perimeter.
Fix
Patch NetScaler to Citrix's fixed versions now, restrict management exposure, review sessions and logs, and treat exposed devices as potentially compromised.

Cloudflare fixes Containers flaw that let one customer read another's leftover disk data

Cloudflare fixed a flaw in Cloudflare Containers that let a paying customer read data other customers' containers left behind on the same shared server. Cloudflare Sandboxes, sold for running untrusted code including AI-agent code, was affected too. Each container gets a disk built with Linux thin provisioning in 64-kilobyte blocks; when a container was deleted, its blocks returned to a shared pool set to skip wiping before reuse. A new container writing only a little into a reused block left the rest holding the previous customer's data, though the attacker could not choose whose. Accomplish reported it on September 4, and Cloudflare says no customer action is needed.

Check
No customer action is required since Cloudflare fixed it service-side, but review whether sensitive workloads ran on Cloudflare Containers or Sandboxes during the exposure window.
Affected
Workloads on Cloudflare Containers or Sandboxes could have their freed disk blocks read by a later container on the same shared host before the fix.
Fix
Rely on Cloudflare's service-side fix, and for shared-tenant platforms generally, avoid writing secrets to container disk and rotate any that may have persisted.

Elementor WordPress plugin flaw lets one link create a rogue administrator account

Patchstack detailed a high-severity cross-site request forgery flaw, rated 8.8 and not yet assigned a CVE, in the Elementor Website Builder WordPress plugin, which is active on over ten million sites. It affects only versions 4.3.0 and 4.3.1, installed on more than two million sites, and is fixed in 4.3.2. One link opened by a logged-in WordPress user makes that user perform any REST API action their account permits, so an administrator clicking it creates a second administrator account for the attacker on a stock install. The attack needs no JavaScript, submitted form, or attacker-controlled page; the link can be a plain anchor tag in an email, chat, or comment.

Check
Update the Elementor plugin to 4.3.2 across all WordPress sites, then audit administrator accounts for unexpected additions created via the flaw.
Affected
Sites running Elementor 4.3.0 or 4.3.1 let an unauthenticated attacker trick a logged-in admin into creating a rogue administrator account by clicking a link.
Fix
Apply Elementor 4.3.2, remove unrecognized admin accounts, and warn administrators against opening untrusted links while signed in to WordPress.

Lunex stealer abuses vulnerable AMD driver to disable security tools and steal credentials

Ontinue tied the Psychedelic Stealer, spread through compromised Ukrainian websites using ClickFix-style fake Cloudflare verification pages, to a wider malware-as-a-service platform called Lunex. The chain starts with a bogus CAPTCHA that delivers a malicious MSI, which drops LunexLoader. The loader bypasses User Account Control through the CMSTPLUA COM object, then uses a bring-your-own-vulnerable-driver technique against the AMD Radeon Software driver PDFWKRNL.sys, affected by CVE-2023-20598, to escalate and evade defenses before fetching the stealer. Researchers note BYOVD is rarely used as a precursor to an infostealer. The final payload extracts credentials from seven Chromium-based browsers, exfiltrates cryptocurrency wallets, and installs a PowerShell-based browser Native Messaging Host for persistent remote filesystem access.

Check
Block the vulnerable PDFWKRNL.sys driver via Microsoft's blocklist, alert on ClickFix-style CAPTCHA lures, and hunt for rogue browser Native Messaging Hosts.
Affected
Windows users tricked by fake Cloudflare CAPTCHA lures run an MSI that loads a vulnerable AMD driver to disable defenses and steal browser and wallet data.
Fix
Enable the vulnerable driver blocklist, restrict MSI and script execution, block copy-paste run-dialog lures, and monitor for UAC bypass via CMSTPLUA.