Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    InfoSec News Nuggets – 09/22/2026

    September 22, 2026

    New Windows Defender zero-day blocks Microsoft antivirus updates

    September 22, 2026

    CISA orders feds to patch Zyxel flaw exploited for data theft

    September 22, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»InfoSec News Nuggets – 09/22/2026
    News

    InfoSec News Nuggets – 09/22/2026

    adminBy adminSeptember 22, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

    SolarWinds has shipped security updates for Access Rights Manager after discovering a hard-coded static cryptographic key that could let an attacker execute code on a managed host without authentication. Tracked as CVE-2026-28326 with a CVSS score of 8.8, the flaw affects all ARM versions 2026.2 and earlier and was privately reported by a security researcher rather than found through active exploitation. Administrators are urged to upgrade to ARM 2026.2.1, which also resolves a batch of other recently disclosed flaws in the company’s Web Help Desk and Serv-U products.

     

    CISA Warns of Linux Kernel Vulnerabilities Actively Exploited in Attacks

    CISA added three actively exploited Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, spanning a critical flaw in the kernel’s TLS receive path, an out-of-bounds write in the netfilter bridge ebtables SNAT target, and a race condition in the AF_ALG cryptographic interface. Federal civilian agencies faced a September 21 remediation deadline, and the agency additionally required forensic triage of potentially exposed systems rather than treating patching alone as sufficient. CISA has not disclosed who is behind the exploitation or which organizations have been targeted.

     

    TanStack NPM Supply Chain Attack Exposes 170 Private CrowdSec GitHub Repositories

    CrowdSec disclosed that attackers used a stolen GitHub OAuth token belonging to a recently departed employee to clone roughly 170 of its private repositories during May’s broader TanStack npm supply-chain compromise, with the theft only discovered after the stolen code surfaced on a cybercrime forum in September. The exposed archive contained internal source code along with email addresses for 83 users and contact details for 51 potential investors from 2020, though the company says its production infrastructure and databases were never touched. CrowdSec has since deployed endpoint detection on developer workstations and is tightening offboarding procedures to prevent similar lingering access.

     

    Cisco drops another exploited zero-day, this time a perfect 10

    Cisco disclosed a maximum-severity authentication bypass in Identity Services Engine and ISE Passive Identity Connector that is already under active exploitation, letting an unauthenticated remote attacker send a crafted request to an API and ultimately gain root-level command execution. No workaround exists beyond restricting management traffic with access control lists, and admins are being urged to check logs for suspicious activity and, where compromise is suspected, reimage affected nodes entirely. The advisory landed just days after a separate actively exploited flaw was patched in the company’s Secure Email Gateway products, making for an unusually heavy patching month.

     

    Revolut phishing texts appear days after data breach

    Days after Revolut acknowledged that fraudsters posing as a government agency tricked it into handing over sensitive customer records, including IDs, selfies, and financial histories, affected customers began receiving convincing phishing texts that appeared in the same message thread as legitimate bank alerts. One reported scam page requests camera access to mimic Revolut’s identity-verification flow before harvesting a password, a tactic that could make follow-on account takeover attempts far more convincing. It remains unconfirmed whether the phishing wave is directly tied to the leaked data or is opportunistic exploitation of the breach’s publicity.

    The post InfoSec News Nuggets – 09/22/2026 appeared first on AboutDFIR – The Definitive Compendium Project.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleNew Windows Defender zero-day blocks Microsoft antivirus updates
    admin
    • Website

    Related Posts

    News

    New Windows Defender zero-day blocks Microsoft antivirus updates

    September 22, 2026
    News

    CISA orders feds to patch Zyxel flaw exploited for data theft

    September 22, 2026
    News

    Microsoft to retire Microsoft 365 Companion apps in December

    September 22, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202679 Views

    How fraudsters target credit unions

    May 4, 202644 Views

    IP Address Investigations and Local OSINT

    March 20, 202641 Views
    Our Picks

    InfoSec News Nuggets – 09/22/2026

    September 22, 2026

    New Windows Defender zero-day blocks Microsoft antivirus updates

    September 22, 2026

    CISA orders feds to patch Zyxel flaw exploited for data theft

    September 22, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.