Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

First car head unit malware spreads through built-in Android updaters

Kaspersky documented what it calls the first malware found on a car head unit with an infection chain built specifically for that kind of device. The malware spreads through the built-in software updaters of certain Android-based automotive head unit firmware, then pulls a multi-stage downloader that runs ad fraud and enrolls the unit into a reverse-proxy botnet. Researchers attribute it with high confidence to a group tied to the BADBOX ad-fraud and residential-proxy operation. A head unit is the central console that handles media and, on many vehicles, some vehicle functions, so malware delivered through its own update mechanism is a notable expansion of automotive supply-chain risk.

Check
For fleets and connected-vehicle programs, ask head unit and firmware suppliers about the integrity of their built-in updaters, and monitor automotive and IoT devices for proxy or ad-fraud traffic.
Affected
Vehicles using affected Android automotive head unit firmware whose built-in updater delivered the malware; infected units run ad fraud and act as reverse-proxy nodes, and the head unit has partial vehicle-function access.
Fix
Treat the firmware update channel as a supply-chain trust boundary, source head units from vendors with signed verified updates, monitor connected vehicles for anomalous outbound traffic, and track this actor's proxy infrastructure.

Fake npm calendar tools drop an AI-assisted Linux backdoor on import

Trend Micro found 14 malicious npm packages that pose as working calendar and streak utilities while secretly installing a Linux backdoor from the commercial RedC2 4.0 toolkit. The packages function as advertised, but on load they locate a bundled binary disguised as a math accelerator, mark it executable, and run it as a detached background process. No install script is needed, so a single import anywhere in the dependency graph, even a transitive one, triggers execution. RedC2 is sold on criminal forums as an evasion-focused command-and-control framework with surveillance, credential theft, tunneling, in-memory payload execution, and AI-assisted command features. It shows how import-time execution keeps making package registries an easy delivery route.

Check
Audit npm dependencies, including transitive ones, for the malicious calendar packages and any bundled binaries, and remove them, since simply importing one runs the backdoor without an install script.
Affected
Developers and systems that installed the trojanized npm calendar packages; importing one anywhere in the dependency tree drops and runs a RedC2 Linux backdoor with surveillance, credential theft, and remote-control capabilities.
Fix
Pin and vet dependencies, watch for packages that bundle binaries or spawn detached processes on import, use lockfiles and isolated builds, and monitor developer and CI hosts for unexpected outbound connections.

Truffle Security finds hundreds of leaked AWS keys still fully controlling accounts

Researchers at Truffle Security reported that after four years of collecting leaked Amazon Web Services keys, they found 768 that still grant full control over a company's cloud account, with a median age of about five years. The keys were exposed in places like public code and configuration and were never rotated, so they remain live long after the people who created them have likely forgotten them. A single valid key with broad permissions can let an attacker read data, spin up resources, and move through a cloud environment. The finding is a reminder that leaked long-lived credentials remain one of the most durable and overlooked paths into cloud accounts.

Check
Scan code, configuration, and logs for exposed AWS keys, revoke and rotate any long-lived keys you find, and move toward short-lived credentials and roles instead of static access keys.
Affected
Organizations with old, long-lived AWS access keys exposed in code or configuration and never rotated; an attacker who finds a still-valid key can gain full control of the account it belongs to.
Fix
Replace static keys with temporary credentials and roles, enforce rotation and least privilege, add automated secret scanning across repositories and history, and monitor for use of old or unexpected keys.

US Bank ties ransomware leak claim to a fourth-party vendor incident

US Bank said that data-theft claims made by the LockBit ransomware group stem from a fourth-party incident that happened outside its own environment, at a contractor working for one of its third-party vendors. The bank stated there is no evidence its own systems, networks, or data repositories were compromised, while LockBit set a deadline to leak the data unless paid. The "fourth-party" framing is the notable part: exposure reached the bank's customers through a vendor's vendor, two steps removed from its own controls. It follows earlier third-party incidents affecting US Bank customer data and underscores how far organizations' real attack surface extends beyond their direct suppliers.

Check
Map not just your direct vendors but their subcontractors, and require contractual security and breach-notification obligations that flow down to fourth parties handling your data.
Affected
Organizations whose data is handled by vendors' subcontractors; a breach at a fourth party can expose customer data even when your own and your direct vendor's systems are untouched.
Fix
Extend third-party risk management to fourth parties, inventory where data flows downstream, require flow-down security terms and prompt breach notification, and remember that paying extortion does not guarantee stolen data is deleted.

Exploited Entra ID flaw scored a perfect ten but was fixed in Microsoft's cloud

Microsoft disclosed that a critical flaw in Entra ID, its cloud identity and access service formerly known as Azure Active Directory, was exploited in the wild, though it says the issue is fully mitigated on its side and customers need take no action. Tracked as CVE-2026-69836 and scored 10.0, it is an unsafe-deserialization bug that let an unauthenticated attacker run code over the network in the identity service. Because Entra ID underpins sign-in to Microsoft 365, Azure, and many third-party apps, a code execution flaw there is unusually serious. Microsoft has not shared how it was exploited, so the practical step is reviewing identity logs for suspicious activity before the disclosure.

Check
No patching is required since Microsoft fixed this in its cloud, but review Entra ID sign-in and audit logs for suspicious service-principal changes, role assignments, and unusual token or admin activity.
Affected
Organizations relying on Microsoft Entra ID for identity (CVE-2026-69836); the flaw allowed unauthenticated remote code execution in the identity service itself, though Microsoft states it is now fully mitigated.
Fix
Treat this as a prompt to hunt for identity compromise, not to patch: review privileged accounts, tokens, and app registrations for anomalies, tighten conditional access, and monitor Entra logs.

Attackers exploit unauthenticated Zimbra SNMP flaw for remote code execution

Poland's national CERT warned that attackers are exploiting a now-patched flaw in Zimbra Collaboration to run commands on mail servers without authentication. Tracked as CVE-2026-73570 and scored 8.9, it is an OS command injection bug in Zimbra's SNMP monitoring feature: when the optional SNMP package is installed and notification traps are enabled, improper input handling lets an unauthenticated attacker send crafted requests that execute commands as the Zimbra user. The monitoring service involved is on by default where SNMP is used, widening exposure. Zimbra fixed it in version 10.1.20 in July, and Zimbra servers are a long-standing target, so unpatched instances should be treated as urgent.

Check
Update Zimbra Collaboration to 10.1.20 or later now, and check whether the SNMP package is installed with notifications enabled, which is the exposed configuration under active attack.
Affected
Organizations running Zimbra Collaboration before 10.1.20 with the SNMP package installed and notifications enabled (CVE-2026-73570); an unauthenticated attacker can execute operating-system commands as the Zimbra user, and exploitation is underway.
Fix
Patch to 10.1.20, and if you ran an exposed version, inspect the Zimbra log for suspicious service restarts and recently created files, since patching alone will not evict a foothold.

Critical Citrix NetScaler flaw lets attackers bypass authentication on gateways

Citrix patched a critical flaw in NetScaler ADC and Gateway that lets a remote, unauthenticated attacker bypass authentication on appliances used for remote access. Tracked as CVE-2026-19490 and scored 9.3, it is an authentication-bypass issue affecting devices configured as a gateway for SSL VPN, ICA proxy, clientless VPN, or RDP proxy, or as an AAA authentication server. On newer builds it requires a SAML configuration, but on older builds any gateway or AAA configuration is exposed. There is no confirmed exploitation yet, but NetScaler appliances sit at the network edge and have repeatedly been attacked soon after disclosure, so patching is urgent.

Check
Upgrade NetScaler ADC and Gateway to the fixed builds immediately, and check your configuration for SAML action, gateway, and AAA virtual server entries to gauge exposure, treating edge appliances as priority targets.
Affected
Organizations running affected Citrix NetScaler ADC or Gateway as a gateway or AAA server (CVE-2026-19490); a remote, unauthenticated attacker can bypass authentication and reach internal services normally protected by it.
Fix
Patch to the fixed NetScaler versions, review configurations against Citrix's exposure criteria, monitor these appliances closely for compromise given their history as targets, and restrict management and gateway exposure where possible.

Critical Elementor Pro flaw lets unauthenticated visitors upload PHP and run code

Researchers disclosed a critical flaw in Elementor Pro, the widely used WordPress page builder, that lets an unauthenticated visitor upload a PHP file through a public form and run code on the server. Tracked as CVE-2026-32475 and scored 9.0, it is a desynchronization bug in the Forms module's file-upload field: the code that validates an upload and the code that saves it disagree about how to handle an empty file entry. By sending a crafted upload with an empty first part followed by a PHP payload, an attacker slips the file past validation into a public directory. It affects versions up to 4.2.1 and is fixed in 4.2.2.

Check
Update Elementor Pro to 4.2.2 across all WordPress sites, and because updating does not remove files already uploaded, inspect the Elementor forms upload directory for unexpected PHP files.
Affected
WordPress sites running Elementor Pro up to 4.2.1 with a published form containing a file-upload field (CVE-2026-32475); an unauthenticated visitor can upload a PHP file and execute code as the web server.
Fix
Patch to 4.2.2, scan for web shells and unexpected files in upload directories, put a web application firewall in front of the site, and restrict public upload forms until confirmed clean.

Poisoned Rust crate ran malware at build time inside a 245-million-download library

Attackers briefly poisoned arrayref, a foundational Rust crate with about 245 million downloads that sits underneath widely used graphics and blockchain libraries, along with two sibling crates from the same maintainer account. The crate code itself was clean; each added a dependency on a typosquat of a popular package whose build script ran during compilation, pulling and executing an infostealer that grabbed host data and browser credentials. Because the malicious code lived in a build script, simply compiling a project that resolved the crate ran it, with nothing from the library needing to be called. The bad versions were pulled within about ninety minutes, but any build during that window was exposed.

Check
If you build Rust projects, check whether arrayref, internment, or append-only-vec resolved during the exposure window, search the Cargo cache for the malicious files, and pin arrayref to 0.3.9 or earlier.
Affected
Rust developers and CI systems that resolved the poisoned crate versions during the window; the malicious build script ran an infostealer at compile time, taking host information and browser credentials.
Fix
Build with committed lockfiles and the locked flag to avoid pulling fresh malicious versions, enable two-factor authentication on registry accounts, and treat any machine that built during the window as potentially compromised.

Forty fake Firefox wallet extensions steal seed phrases and private keys

Researchers at Socket found 40 malicious Firefox extensions, part of a wider set of 77, that impersonate cryptocurrency wallets like OKX, Rabby, and TronLink to steal users' funds. Dubbed the Offside Wallet Theft Factory and active since March, the campaign uses lookalike names with subtle character swaps, cloned wallet code, and reused extension identities. Some variants capture recovery phrases as a user sets up or imports a wallet; others copy the wallet's keyring before it is encrypted locally, so on-device encryption offers no protection. Stolen data goes out through Cloudflare Workers, attacker databases, and hardcoded servers. Removing an extension after theft does not secure the wallet, so victims must move funds.

Check
Warn users to install wallet extensions only from verified publishers and to check for lookalike names, and if a fake wallet extension was installed, move funds to a new wallet immediately.
Affected
Firefox users who installed a fake wallet extension impersonating brands like OKX, Rabby, or TronLink; the extensions steal recovery phrases and private keys, in some cases capturing keyrings before local encryption applies.
Fix
Vet browser extensions and publishers carefully, since a stated purpose and modest permissions do not prove safety, and treat any wallet touched by a malicious extension as compromised.