Check Point patched two critical flaws in how its firewall and management products handle VPN certificates, each scored 9.8, that could let an unauthenticated remote attacker run code. CVE-2026-85102 is improper certificate-trust validation during VPN negotiation that can lead to code execution on the Security Gateway. CVE-2026-85103 is a heap overflow while decoding a certificate's structure, affecting both the gateway and the management server. Notably, because the second flaw is about certificate processing, Check Point says it could be triggered even where VPN is not running, so management servers need the fix regardless. Check Point found the issues internally and reports no exploitation yet, though its products were attacked twice this year.
Identity-verification company IDScan confirmed that attackers accessed customer data in its cloud, behind a dark-web marketplace offering scans of more than 153 million US and Canadian driver's licenses, plus names and government-ID numbers. IDScan authenticates government IDs for businesses ranging from banks to car-rental agencies to cannabis and gun retailers, which makes it an aggregator of everyone's identity documents and a single point of mass failure. Investigative journalist Brian Krebs traced the marketplace back to IDScan by matching document scans to occasions when IDs were presented. The FBI is investigating and lawsuits have been filed. Because these are scanned government IDs, victims cannot simply rotate a leaked driver's license.
Researchers at Proofpoint and Volexity detailed BlueMoon, a modular exploit kit that chains three zero-day flaws to take a victim from a malicious web page to full control of their Windows machine. It uses two Chrome flaws, CVE-2026-85046 and CVE-2026-87491, to run code in the browser and escape its sandbox, then a Windows kernel bug, CVE-2026-85880, to gain SYSTEM privileges. Both Chrome flaws were "patch-gap" zero-days: their fixes were already public in Chromium's open source before reaching stable Chrome, so attackers reverse-engineered the fixes to hit users who had not yet updated. Multiple espionage groups adopted the shared kit within days, and researchers expect wider use.
Researchers describe attackers using voice phishing calls to talk employees into granting access from their personal devices, then reaching Microsoft 365 and corporate data through the trust the user extends. The attackers do not hack the device; they convince the person, then use Microsoft's Graph API to identify valuable targets and pass access to extortion groups like ShinyHunters. Because the weakness is the user's decision rather than the hardware, banning personal devices would not stop it. The stronger defense is tightening identity and authentication and limiting what a compromised account can actually do, so that tricking one person yields far less to the attacker.
VPN provider Surfshark disclosed that attackers accessed an internal engineering test server that a configuration error had left reachable from the internet, along with a proxy server used for content optimization. Surfshark says the exposure was limited to a non-production environment and included service configurations, build-related credentials, system binaries, and portions of code history, but did not reach customer data, VPN traffic, encryption keys, or production systems. The company detected the activity on August 31, contained it by September 2, rotated credentials, revoked tokens, and completed remediation within days. It is a reminder that misconfigured internet-exposed test environments remain a common and avoidable breach path, even at security-focused companies.
CISA added several actively exploited flaws in internet-facing security appliances to its catalog, ordering federal agencies to patch by September 12. The most severe, CVE-2026-20079 scored 10.0, is an authentication bypass in Cisco Secure Firewall Management Center that lets an unauthenticated attacker run scripts and gain root on the device; Cisco confirmed exploitation since August. A Citrix NetScaler authentication bypass, CVE-2026-19490, saw a surge of attacks on September 8, and a Fortinet FortiOS flaw, CVE-2025-25249, is being used to deliver a remote access trojan. Separately, CISA warned that a critical WatchGuard Firebox firewall flaw is now being exploited in ransomware attacks. Edge appliances remain prime targets.
Researchers at Wiz found that nearly one in ten internet-facing LiteLLM servers still accept "sk-1234," the example administrator key printed in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway that sits between an organization's apps and the model providers it pays for, and that admin key unlocks every stored provider API key; in Wiz's tests it even reached the cloud identity credentials of the host machine. The finding accompanies a cluster of exploited LiteLLM flaws that attackers have used to run code, steal secrets, and deploy crypto miners, with one ransomware group and a Microsoft-documented breach among them. Microsoft's advice is to treat AI gateways as top-tier secrets stores.
cPanel patched a critical flaw that lets an ordinary hosting account with mail privileges take root control of the whole server. Tracked as CVE-2026-67401 and scored 9.9, it is a SQL injection in the EmailTrack mail-tracking feature that lets an authenticated account create arbitrary files and escalate to code execution as root. It affects all supported cPanel and WHM versions. On a shared server, a single cheap hosting plan or one stolen webmail password can lead to full server takeover, exposing every other tenant's sites, databases, and data. It is the third cPanel flaw since late July that turns one authenticated tenant into root, and cPanel published no indicators to hunt for.
Alby warned of a critical flaw in older versions of Alby Hub, a self-hosted Bitcoin Lightning wallet that people run on their own computer or server to hold their funds. An attacker who could reach the wallet's management interface over the internet could gain access without permission and send the owner's funds. The flaw affects versions 1.7.0 through 1.18.5, released before August 2025, and was fixed in 1.19.0 and later, with 1.24.0 the current release. Alby says one user has been affected so far and is withholding technical details for now. The core lesson is to never expose a self-hosted wallet's control interface to the public internet.
Researchers at VulnCheck found a flaw in the DeepSeek Harness, a tool that runs an AI agent's commands inside an operating-system sandbox so an agent handling untrusted files cannot write outside its workspace. Through an authentication bypass using a spoofed host header, an attacker needing no credentials or API key can call the tool's own web interface to invoke privileged commands with full-access permissions, raise the session's approval policy to unrestricted execution, and read every stored conversation. In effect, the sandbox meant to contain the agent can be switched off from outside. It is a reminder that an AI agent's isolation is only as strong as the authentication protecting its control interface.