Press "Enter" to skip to content

OSINT / CyberSec report 11.09.2026 00:06

1. Cisco confirmed that a maximum severity authentication bypass vulnerability CVE 2026 20079 in its Secure Firewall Management Center is being actively exploited in the wild (https://www.reddit.com/r/cybersecurity/comments/1wbzdsv/cisco_confirms_maxseverity_fmc_bug_cve202620079/).

2. CISA reported that ransomware gangs are actively exploiting a critical WatchGuard Firebox firewall vulnerability (https://www.bleepingcomputer.com/news/security/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/).

3. Google issued a warning regarding a new Chrome zero day vulnerability that is currently being exploited in attacks (https://www.reddit.com/r/cybersecurity/comments/1wbprfh/google_warns_of_new_chrome_zeroday_bug_exploited/).

4. Multiple espionage groups are using a new exploit kit called BlueMoon to chain vulnerabilities in Windows and Chrome, with initial activity linked to APT31 (https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html).

5. Hackers have deployed a Linux rootkit on F5 BIG IP APM devices to hide web shells within system memory (https://www.reddit.com/r/cybersecurity/comments/1wbw95s/hackers_deploy_linux_rootkit_on_f5_bigip_apm/).

6. AdaptHealth confirmed a data breach involving the exposure of personal information for 4.1 million individuals, attributed to the ShinyHunters group (https://www.bleepingcomputer.com/news/security/adapthealth-confirms-41-million-people-exposed-in-july-cyberattack/).

7. Veradigm disclosed a patient data breach resulting from a cybersecurity incident at a third party vendor (https://www.bleepingcomputer.com/news/security/veradigm-discloses-patient-data-breach-after-gentlemen-gang-claims-attack/).

8. A database containing 153 million drivers licenses is currently being offered for sale on the dark web (https://www.schneier.com/blog/archives/2026/09/drivers-license-data-for-sale.html).

9. Trezor users are receiving malicious QR codes via postal mail following a breach at a third party email provider (https://www.reddit.com/r/cybersecurity/comments/1wbp4qk/trezor_breach_victims_are_now_getting_malicious/).

10. Skullcandy Dime 3 earbuds are vulnerable to Bluetooth hijacking because they automatically pair with unauthorized devices without user interaction (https://www.bleepingcomputer.com/news/security/skullcandy-dime-3-earbuds-expose-users-to-bluetooth-hijacking/).

11. US intelligence agencies accused Chinese AI firms of conducting industrial scale distillation attacks to extract proprietary capabilities from American frontier models (https://thehackernews.com/2026/09/us-agencies-accuse-china-ai-firms-of.html).

12. Nearly 10 percent of exposed LiteLLM gateways were found to be using the default admin key sk 1234, allowing unauthorized access (https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html).

13. The US Department of Justice disrupted the Xinbi Guarantee scam marketplace and froze 52.8 million dollars in cryptocurrency assets (https://thehackernews.com/2026/09/us-disrupts-xinbi-guarantee-scam.html).

14. A critical flaw in Alby Hub potentially allowed attackers to take over internet exposed Bitcoin wallets and misappropriate funds (https://thehackernews.com/2026/09/alby-hub-critical-flaw-could-let.html).

Be First to Comment

    Leave a Reply

    Your email address will not be published. Required fields are marked *