Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

Attackers abuse the trusted Node.js runtime to run malware past defenses

Symantec reported that threat actors are abusing the legitimate, digitally signed Node.js runtime to run malicious JavaScript while slipping past security tools, in attacks on government, technology, and hospitality targets since February. Because the Node.js executable is a trusted developer tool, defenses rarely flag it, so instead of dropping a malicious program the attackers stage the genuine runtime and keep their harmful logic in interpreted scripts. They gain persistence through a Windows registry startup key and, in one case, pulled command-and-control instructions from the blockchain using a technique called EtherHiding. The activity has been tied to a ClickFix social-engineering entry point and an initial-access broker.

Check
Hunt for unexpected Node.js installations on machines that should not run developer tools, suspicious registry startup entries invoking the runtime, and outbound traffic to blockchain endpoints used for command and control.
Affected
Windows environments where a signed Node.js runtime can be introduced and run scripts unnoticed; attackers use it to execute malicious JavaScript, persist through registry keys, and evade tools that trust the binary.
Fix
Apply application control to restrict where the Node.js runtime may run, alert on its use outside development, monitor script execution and registry run-key changes, and block known blockchain command-and-control and ClickFix infrastructure.

Global phishing campaign tricks victims into installing legitimate remote-control software

Researchers at ANY.RUN documented a phishing campaign spanning 46 countries, with about 45 percent of activity aimed at the United States, that tricks victims into installing legitimate remote monitoring and management software to give attackers persistent access. The lures pose as tax documents, invoices, shipping notices, and government messages, and the operation leans on disposable infrastructure hosted on trusted platforms like Vercel, GitHub Pages, and Netlify, with most hosts appearing for only a single day. Because the specific domains and remote-access tools are interchangeable while the delivery chain stays stable, defenders cannot rely on individual indicators or malware verdicts alone. Remote-management governance is the more durable control.

Check
Maintain an inventory and allowlist of approved remote-management tools, block or alert on any others, and warn staff that finance and government-themed messages may push legitimate remote-access software.
Affected
Organizations and users targeted by business-themed phishing that delivers legitimate remote monitoring and management tools; once installed, attackers gain hands-on remote access that looks like ordinary IT activity and evades reputation-based defenses.
Fix
Allowlist approved remote-access software and disable the rest, require remote access through controlled paths like VPNs, monitor for unexpected remote-management execution, and detect on the stable delivery chain rather than disposable domains.

AI-enhanced malware turns hacked Windows machines into marketplace inventory

Group-IB detailed BraZetsu, a modular malware framework that turns compromised Windows machines into products sold to other criminals. It uses generative AI to triage stolen data and flag high-value victims for initial-access brokers, and it collects digital certificates, browser histories from several browsers, and financial files while watching users through screenshots. Compromised hosts feed an underground access-as-a-service marketplace where buyers can pay a small deposit to purchase entry into a victim's system and then run their own follow-on payloads. Some samples were fully undetected by antivirus at the time of analysis. It shows attackers using AI to scale the triage and resale of stolen access.

Check
Treat any infostealer infection as a potential gateway that could be resold, respond by fully rebuilding and rotating credentials, and hunt for stealthy data collection, browser theft, and unauthorized remote access.
Affected
Windows users infected by this framework; it harvests certificates, browser data, and financial files, uses AI to rank victims for brokers, and enrolls the machine into a resale marketplace.
Fix
Strengthen endpoint detection and application control, enforce phishing-resistant authentication so stolen credentials are less useful, monitor for stealthy collection and remote access, and rebuild rather than clean machines suspected of infostealer compromise.

Thomson Reuters court software breach exposed personal and sealed case records

Thomson Reuters disclosed that attackers obtained files from C-Track, a court case-management platform sold by its West Publishing unit, affecting courts across eleven US states, the US Virgin Islands, and Ontario, Canada. The intrusion happened in March and was not discovered until the end of June. Exposed records may include names, Social Security numbers, driver's license numbers, dates of birth, and medical and insurance information, and at some courts confidential, redacted, or sealed court information may also have been taken. The stolen data came from database backups that courts had supplied to the vendor for troubleshooting. How the attackers got in, and why they went unnoticed for months, remains unanswered.

Check
People in affected court cases should watch for identity theft and use the offered credit monitoring, and organizations should limit the sensitive and backup data they hand to software vendors for support.
Affected
Individuals whose details appear in affected court records, including some sealed cases; exposed names, Social Security numbers, and health data enable identity theft and fraud, with added risk from sealed-case exposure.
Fix
Affected people should monitor credit and court accounts; organizations should minimize data shared with vendors, avoid supplying sensitive backups for troubleshooting, encrypt vendor-held data, and hold third parties to strong security terms.

Attackers chain two SonicWall VPN zero-days for unauthenticated remote code execution

SonicWall warned that attackers are actively exploiting two zero-day flaws in its SMA 1000 series remote-access VPN appliances, which can be chained for unauthenticated remote code execution. The first, CVE-2026-83548, scored 10.0, is a pre-authentication server-side request forgery flaw in the user-facing portal that lets an unauthenticated attacker abuse the appliance as a proxy and reach sensitive functions. The second, CVE-2026-83549, is a command-injection flaw in the admin console. SonicWall confirmed active exploitation and shipped hotfixes with no workarounds. Because these gateways aggregate remote users' credentials and tie into directory services, compromising one means compromising the authentication system itself. It is the third SMA 1000 zero-day campaign in under a year.

Check
Apply the SonicWall SMA 1000 hotfixes immediately since there are no workarounds and exploitation is active, then hunt the appliance for compromise, including rogue sessions, credential theft, and unexpected outbound requests.
Affected
Organizations running SonicWall SMA 1000 models 6210, 7210, or 8200v on affected versions (CVE-2026-83548, CVE-2026-83549); the flaws chain to unauthenticated remote code execution on an appliance that holds credentials and session state.
Fix
Patch to the fixed hotfix releases now, treat any exposed unpatched appliance as compromised, rotate credentials and session secrets it handled, review logs for exploitation, and limit portal exposure to the internet.

Exploited Sangoma Switchvox flaw gives unauthenticated attackers reverse shells

Attackers are exploiting a critical flaw in Sangoma Switchvox, a widely used enterprise VoIP phone-system platform, to run code on servers without any credentials. Tracked as CVE-2026-9586 and scored 9.3, it is an unauthenticated SQL injection in an internet-facing endpoint that concatenates user-controlled input directly into database queries, letting an attacker execute commands as the database superuser and drop a reverse shell. Researchers at Horizon3 saw exploitation begin on August 30 and warn that most of the roughly 4,000 internet-exposed Switchvox systems may already have been targeted. Sangoma patched the flaw in version 8.4.0.2 back in July, but many systems remain unpatched and reachable.

Check
Update Sangoma Switchvox to 8.4.0.2 or later immediately, and because exploitation is active, review logs for the published indicators, reverse-shell activity, and process-enumeration commands on exposed systems.
Affected
Organizations running internet-exposed Sangoma Switchvox before 8.4.0.2 (CVE-2026-9586); an unauthenticated attacker can inject SQL, execute commands as the database superuser, gain a reverse shell, and take over the phone system.
Fix
Patch to 8.4.0.2, take the management interface off the public internet, hunt for reverse shells and unauthorized database changes, rotate credentials, and treat any exposed unpatched instance as potentially already compromised.

WordPress backup plugin flaw lets attackers hijack sites through a poisoned import

A flaw in All-in-One WP Migration and Backup, a WordPress plugin installed on millions of sites, can let an unauthenticated attacker take over a site. Tracked as CVE-2026-19949, it is a second-order SQL injection caused by incorrect handling of escaped characters when the plugin rewrites database content during a restore. An attacker plants crafted data through WordPress trackbacks, which triggers when an administrator exports and imports the site, both routine plugin operations. The injection can leak the plugin's secret import key through a public comment, letting the attacker import a malicious backup archive containing executable code and seize full control. ServMask fixed it in version 7.110, but many sites remain unpatched.

Check
Update All-in-One WP Migration and Backup to 7.110 or later across all WordPress sites, and review sites for suspicious trackback comments, unexpected admin accounts, and unfamiliar files.
Affected
WordPress sites running All-in-One WP Migration and Backup through 7.109 (CVE-2026-19949); an unauthenticated attacker can plant SQL injection that leaks the plugin's secret key, enabling a malicious archive import and site takeover.
Fix
Patch the plugin, scan for web shells and unexpected files, audit administrator accounts, rotate WordPress secrets, disable trackbacks if not needed, and put a web application firewall in front of the site.

Attackers probe LiteLLM AI gateways to steal cloud and model provider secrets

Attackers are actively probing LiteLLM deployments for an authorization flaw that turns a low-privilege account into full control of the AI gateway. Tracked as CVE-2026-35029 and affecting versions before 1.83.0, the flaw is a missing permission check on the configuration-update endpoint, so a read-only user can change settings reserved for administrators. LiteLLM sits between applications and model providers and stores provider API keys, database details, and admin credentials, making it a rich target. By abusing configuration writes, an attacker can extract secrets from server environment files and even reset the dashboard login to seize admin access. Researchers recorded thousands of probing requests, some directly attempting to read known secret files.

Check
Upgrade LiteLLM to 1.83.0 or later, restrict access to its control plane and configuration endpoints, and rotate any provider, cloud, or database secrets the gateway could expose.
Affected
Organizations running LiteLLM before 1.83.0 as an AI gateway (CVE-2026-35029); a low-privilege authenticated user can modify configuration, read environment secrets, and escalate to administrator, exposing stored model provider and cloud credentials.
Fix
Patch, segment and firewall the LiteLLM control plane away from untrusted users, enforce least privilege, store secrets outside reachable environment files, rotate exposed keys, and monitor configuration endpoints for unauthorized changes.

Malicious repository settings can make AI coding agents run attacker commands

Researchers at Manifold Security disclosed a class of flaws across several command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs automatically on the developer's machine. The command executes outside the agent's sandbox, with the user's privileges, and without any approval prompt, often before the agent even contacts the model. Simply reviewing or opening a malicious project can run attacker code. It triggers when a repository arrives as files with its hidden Git directory intact, such as through a shared drive, archive, or USB stick, rather than a normal clone. Several tools shipped fixes, but some remained vulnerable at disclosure.

Check
Update command-line AI coding agents to patched versions, treat opening or reviewing an untrusted repository in an agentic tool as running its code, and prefer plain clones over copied repositories.
Affected
Developers using command-line AI coding agents who open untrusted repositories delivered as files with their Git directory intact; repository settings can execute attacker commands outside the sandbox, without approval.
Fix
Keep agent tools updated, run them against untrusted code in isolated environments, restrict what the agent can reach, avoid opening repositories from shared drives or archives without inspection, and watch startup commands.

BGP hijack poisons a server-panel update to plant persistent root access

Attackers used a BGP hijack, a manipulation of internet routing, to divert update traffic for Virtualizor, a widely used server and hypervisor management panel, to a server they controlled. During the diversion, which began August 28, they obtained a valid TLS certificate so the connection looked legitimate, then delivered a malicious update that installed persistent root access on affected hosts. One hosting provider found root-level compromise on five of thirty-four hypervisors it checked. Because the software's updates were not cryptographically signed, transport encryption alone did not stop the tampering once routing was hijacked. The vendor released a scanner and patch, but package signing remains unfinished, leaving update integrity dependent on routing security.

Check
Run the vendor's scanner on Virtualizor hosts, check for the published indicators like the malicious service and payload file, rotate and IP-restrict API keys, and audit for unknown SSH keys and users.
Affected
Hosting providers and organizations running Virtualizor that pulled updates during the hijack window; a malicious signed-looking update could install persistent root access on hypervisors, exposing every virtual machine they host.
Fix
Scan and remediate affected hosts preserving evidence, rotate credentials and API keys, verify update integrity independently of transport encryption, monitor routing for hijacks of critical vendors, and prefer vendors that sign updates.