Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

AdaptHealth breach tied to ShinyHunters exposes health data of 4.1 million

AdaptHealth, a US network of more than 680 medical-equipment facilities, confirmed that a breach attributed to the ShinyHunters group exposed the personal, health, and insurance information of about 4.1 million people. The attackers got in by socially engineering a third-party contractor's privileged account, then reached AdaptHealth's cloud business applications, patient-management systems, and electronic health record portals, and stole a password file tied to insurance billing. It fits ShinyHunters' pattern of tricking a person into handing over access to connected cloud services, and it is the latest in a wave of large healthcare breaches this year alongside Aesto, CareCloud, and McKesson. Social security and financial data were reportedly not taken.

Check
Affected patients should watch for medical, insurance, and identity fraud and use the offered monitoring, and healthcare organizations should tighten third-party and contractor account access against social engineering.
Affected
About 4.1 million people whose names, contact details, and health and insurance information were exposed; the data supports targeted phishing and insurance fraud, and the contractor-account entry shows the third-party path.
Fix
Require phishing-resistant authentication and least privilege for contractors and third parties, monitor connected cloud apps for anomalous access, verify help-desk and account changes, and treat contractor accounts as a primary attack surface.

Microsoft's record Patch Tuesday fixes 974 flaws and two exploited Windows zero-days

Microsoft shipped its largest-ever Patch Tuesday, fixing a record 974 vulnerabilities, including two Windows zero-days already exploited in attacks. Both zero-days are local privilege-escalation flaws that let an attacker gain SYSTEM access: CVE-2026-85880 is a heap buffer overflow in the Advanced Local Procedure Call component that can let code in a low-privilege sandbox escape and elevate, and CVE-2026-81963 is a link-following flaw in the Windows Update Stack. The release also includes about 20 potentially wormable flaws, remotely exploitable without authentication, across services like DNS, DHCP, SMB, and Active Directory, plus critical fixes in Exchange, SharePoint, SQL Server, and Kerberos. The sheer volume makes prioritization essential.

Check
Prioritize the two exploited zero-days and the roughly 20 wormable, internet-facing flaws in this month's update, deploying them first, then work through the rest based on exposure and asset criticality.
Affected
Windows and Microsoft server environments across the board (CVE-2026-85880, CVE-2026-81963, and others); the exploited zero-days give local attackers SYSTEM privileges, while wormable flaws in core network services could spread remotely without authentication.
Fix
Apply the September updates promptly, patching exploited and wormable issues first, watch for privilege-escalation activity these flaws enable when chained with initial access, and test large rollouts given the release size.

Critical SAP kernel flaw lets unauthenticated attackers run commands as admin

SAP patched a critical flaw in its kernel, tracked as CVE-2026-44756 and dubbed OVERPASS with a top score of 10.0, that lets an unauthenticated, remote attacker run commands with administrative privileges and fully compromise a system. The memory-corruption bug is in the Extended Passport processing library and is reachable over several SAP communication protocols, including through the internet-facing Internet Communication Manager, which researchers say exposes more than 10,000 SAP systems online. In the same update SAP fixed a second 10.0 flaw, a missing-authentication issue in the NetWeaver Message Server that lets attackers run code across an entire SAP cluster without credentials. Both need prompt patching.

Check
Apply SAP's September security notes for the kernel and NetWeaver Message Server immediately, and identify any SAP systems whose Internet Communication Manager is reachable from the internet as top priority.
Affected
Organizations running affected SAP systems, especially with an internet-facing Internet Communication Manager (CVE-2026-44756, CVE-2026-58240); unauthenticated remote attackers can execute commands as admin or run code across the whole SAP cluster.
Fix
Patch the SAP kernel and Message Server now, restrict and monitor internet exposure of the Internet Communication Manager and message server ports, and watch for unusual command execution on affected SAP hosts.

Attackers plant a stealthy Linux rootkit on F5 BIG-IP access gateways

Researchers at Sophos and ESET found attackers breaching F5 BIG-IP APM access gateways and installing a stealthy Linux rootkit that ESET calls PoisonedRefresh. Rather than dropping a file on disk, it hides a web shell in memory, hooks into the Apache and PHP components, tampers with SELinux settings, and uses disguised requests to run commands while blending into normal traffic. Crucially, it persists across device upgrades, so patching the appliance alone does not remove it. The intrusions likely began by exploiting a critical remote code execution flaw that F5 had earlier downgraded to a mere denial-of-service issue, which may have led some organizations to deprioritize patching it.

Check
Treat internet-facing F5 BIG-IP APM devices as potentially compromised, patch the underlying remote code execution flaw, and hunt for in-memory web shells, Apache and PHP hooks, and altered SELinux settings.
Affected
Organizations running F5 BIG-IP APM access gateways, especially internet-facing ones on the vulnerable version; attackers install a memory-resident rootkit that survives upgrades and turns the gateway into a persistent, covert foothold.
Fix
Patch the F5 flaw, but because the rootkit survives upgrades, inspect and rebuild affected devices from known-good images, restrict management exposure, rotate credentials the gateway handled, and re-evaluate vendor DoS-only ratings.

Researchers build a zero-click WeChat worm that spreads through voice calls

Security researchers built a zero-click worm that hijacks WeChat accounts through an incoming voice call on both iPhone and Android, without the target ever answering. The exploit fires during the ringing phase, before the user declines or picks up, abusing a memory-corruption flaw in WeChat's call-handling code to run commands on the device and take over the account. Because it can spread from a compromised contact to their contacts, it behaves like a worm. Notably, the researchers used AI to find the bug and write the exploit in about two days. Tencent patched it in late August and added a server-side mitigation, and saw no in-the-wild abuse before the fix.

Check
Make sure WeChat is updated to the patched version on all devices, since the fix landed in late August, and treat messaging apps with call features as a real remote attack surface.
Affected
WeChat users on iPhone and Android not updated before the late-August patch; a malicious incoming call could take over the account with no interaction, and the worm could spread to their contacts.
Fix
Keep messaging and calling apps updated promptly, prioritize patches for zero-click and call-handling flaws, and recognize that AI is shortening the time between a bug and a working exploit.

Attackers use autonomous AI agents to steal thousands of credentials in hours

Google's threat-intelligence team reported that a financially motivated attacker used an autonomous, multi-agent AI framework to compromise thousands of third-party credentials in under six hours, a pace that would take a human far longer. It is part of a broader shift in which criminals fold autonomous and coding-focused AI agents into operations, using them to get past defenses, reverse-engineer software, and sift stolen data. Google also found infostealer malware now specifically targeting AI developer configurations and credentials, and actors running open-weight models on compromised machines to sidestep restrictions on commercial services. The takeaway is that AI is collapsing attack timelines from days to hours, and AI access itself is now worth stealing.

Check
Assume attackers can now move at machine speed, and shorten detection and response for credential abuse: enforce phishing-resistant authentication, monitor authentication closely, and protect AI developer keys and configurations as sensitive credentials.
Affected
Organizations exposed to large-scale automated credential attacks; autonomous AI agents can test and abuse stolen credentials across many services in hours, and AI keys and developer configurations are now specific theft targets.
Fix
Adopt phishing-resistant, device-bound authentication, monitor for rapid credential-testing and anomalous automation, secure and rotate AI provider keys and developer configs, and assume the window between a leak and its abuse is shrinking.

ShinyHunters claims theft of Florida driver records through a password-reset flaw

The extortion group ShinyHunters claims it breached Florida's DAVID system, an internal driver and vehicle database used by law enforcement and state officials, and stole more than 200,000 records. According to the group, a password-reset flaw let it take over several internal accounts, including those of motor-vehicle employees and, notably, an FBI agent, which it then used to pull driver files, photos, and signatures by cycling through record IDs. It posted a sample it says is a public figure's license as proof and set a leak deadline. Florida's agency has not confirmed the breach, and the claim is unverified, but the group is reportedly probing other states' motor-vehicle systems the same way.

Check
Organizations with self-service password-reset flows should test them for account-takeover flaws, and agencies operating sensitive lookup systems should monitor for accounts enumerating records by ID and for logins from unexpected sources.
Affected
Government and law-enforcement lookup systems reachable with staff accounts; a password-reset weakness let attackers hijack employee and agent logins and mass-download driver records, exposing highly sensitive identity and vehicle data for extortion.
Fix
Harden password-reset and authentication flows, require phishing-resistant authentication for privileged lookup systems, alert on bulk record access and ID enumeration, limit how much any single account can pull, and verify breach claims.

FreeIPA flaw chain lets anonymous clients grant themselves admin credentials

Red Hat disclosed a flaw chain in FreeIPA, the identity-management system that controls logins across Linux domains, that lets a client which never authenticated create an administrator account for itself. The FreeIPA flaw, CVE-2026-76578 and rated 9.8, is an access rule that lets anyone write a one-time-password token without logging in, and does not restrict what else is written alongside it. The second flaw, CVE-2026-76560 in the underlying 389 Directory Server, treats an unauthenticated client's empty name as matching an empty ownership field, so it passes an owner-only check by being nobody. Together they let an anonymous client write a Kerberos identity into the administrators group; a default install is affected.

Check
Apply Red Hat's updates for FreeIPA and 389 Directory Server as soon as available, and audit your directory for unexpected Kerberos identities and accounts recently added to the administrators group.
Affected
Organizations running FreeIPA or Red Hat Identity Management (CVE-2026-76578, CVE-2026-76560); an unauthenticated client can create an admin-level Kerberos identity, and a default install is vulnerable, putting the whole identity system at risk.
Fix
Patch FreeIPA and the directory server promptly, restrict who can reach the directory service over the network, hunt for rogue tokens and admin accounts, and rotate credentials if abuse is found.

ConnectWise warns of an unpatched ScreenConnect flaw and urges interim mitigation

ConnectWise warned of a new vulnerability in ScreenConnect, its widely used remote-access platform, affecting both cloud and on-premises deployments, and issued temporary mitigations while it prepares a patch. The flaw involves file-transfer behavior in remote-access sessions and has not yet received a CVE identifier. As an interim measure, administrators are told to disable file-transfer permissions in the ScreenConnect console. ScreenConnect is a favorite tool of managed-service providers and IT teams, which also makes it a repeated target: three earlier ScreenConnect flaws are in the exploited-vulnerabilities catalog, two abused in ransomware, and nearly 6,000 instances are exposed online. There is a concurrent campaign spreading malware through rogue ScreenConnect clients.

Check
Apply ConnectWise's interim mitigation now by disabling file-transfer permissions in the ScreenConnect console, restrict access to the platform, and apply the official patch as soon as it ships this week.
Affected
Organizations and managed-service providers running ScreenConnect, cloud and on-premises; the unpatched file-transfer flaw could be abused for attacks, on a platform that grants powerful remote access and is frequently targeted by ransomware.
Fix
Disable file-transfer permissions until patched, limit and monitor who can reach the ScreenConnect console, watch for unauthorized clients and sessions, patch promptly on release, and treat this remote-access tooling as high-value infrastructure.

Public exploit chains a Telerik padding-oracle flaw into unauthenticated code execution

Tanto Security released a working exploit for flaws in Telerik UI for ASP.NET AJAX, a widely used web component set, that chains into unauthenticated remote code execution. The core issue is an AES-CBC padding oracle in the file-upload component: because the encryption does not authenticate the ciphertext, an attacker can tweak encrypted input and read the server's error responses to decrypt protected configuration one byte at a time without the key. That unlocks a .NET deserialization flaw that loads an attacker-supplied assembly and drops a web shell. Progress patched the flaws in July, but the published tool now puts a full attack path in public hands, though only non-default configurations are affected.

Check
Update Telerik UI for ASP.NET AJAX to the patched release, and review applications for the non-default upload configuration this attack requires, prioritizing internet-facing sites now that a working exploit is public.
Affected
Web applications using vulnerable Telerik UI for ASP.NET AJAX in a specific non-default upload configuration (CVE-2026-13181 and related); an unauthenticated attacker can chain the padding oracle and deserialization into remote code execution.
Fix
Patch to the fixed Telerik version, avoid the vulnerable upload configuration, add web application firewall rules for the exploit's request patterns, monitor for web shells and unexpected assembly loads, and rotate keys.