rootpwn

Threat intel

Cybersecurity news & threat intelligence

Daily cybersecurity news, vulnerability advisories, and threat briefings on cloud credential theft, ransomware, zero-days, and the attack patterns we track in the field.

273 articles

News Advisories

Apple Unveils iOS 27.2 Beta – What Developers Need to Know

Apple has rolled out iOS 27.2 beta (build 24B5084k) to the developer community, offering early access to the next generation of iOS. While the release notes are sparse, the beta is expected to include security enhancements, performance tweaks, and new developer APIs. Teams should download the build, run TestFlight, and start testing their apps for compatibility and any emerging security implications.

Read briefing

News Release Notes

Xcode 27.2 Beta Drops Swift, SwiftUI, and Security Tweaks for 2026

Apple’s Xcode 27.2 beta, released on September 16, 2026, brings the latest Swift language enhancements, fresh SwiftUI APIs, and broader support for visionOS, tvOS, and macOS. The beta also tightens compiler security checks, improves sandboxing, and fixes a handful of build‑time bugs. Developers can grab the installer from the Apple Developer portal and start testing the new features today.

Read briefing

News Advisories

Cisco BroadWorks CommPilot: Auth Bypass Lets Low‑Privilege Users Flip Configs

Cisco has disclosed a medium‑impact vulnerability in its BroadWorks CommPilot web‑management interface that allows authenticated users with minimal privileges to modify device configurations by sending crafted HTTP requests. The flaw stems from missing authorization checks and can be exploited remotely. Cisco has released patches; no workarounds exist.

Read briefing

News Advisories

Critical Cisco Hardening Release: ASA, FTD, FMC Patch Internal Exploits

Cisco’s security team has rolled out a hardening update for its Secure Firewall Adaptive Security Appliance, Threat Defense, and Management Center software, addressing a suite of internally discovered flaws. Eight CVEs (CVE‑2026‑20329 through CVE‑2026‑20336) cover issues ranging from static credential exposure to authentication bypass, with two vulnerabilities already being actively exploited. No workarounds exist; customers must install the patches promptly to mitigate the critical risk.

Read briefing

News Advisories

Cisco ISE 802.1X Session Hijack & Info Leak Vulnerabilities – Unauthenticated Local Attackers Can Bypass Auth

Cisco’s Identity Services Engine (ISE) now contains two medium‑risk flaws that let a local, unauthenticated user hijack an 802.1X session or pull sensitive data. The bugs, tracked as CVE‑2026‑20071 and CVE‑2026‑20072, expose attackers to authentication bypass and information disclosure. Cisco has issued patches; no workarounds exist. Systems must be updated promptly.

Read briefing

News Vulnerabilities

Cisco FMC Java Deserialization Flaw Lets Remote Attacker Gain Root

Cisco’s Secure Firewall Management Center (FMC) suffers a critical insecure Java deserialization bug that permits unauthenticated remote actors to execute arbitrary code as root. By sending a crafted Java byte stream to a specific TCP port from a host listed in the external database access list, an attacker can elevate privileges and run any command. No workaround exists; Cisco has released patches for the affected releases. The flaw is catalogued as CVE‑2026‑20242 and rated Critical.

Read briefing

News Vulnerabilities

Cisco ASA/FTD DTLS DoS Vulnerability (CVE‑2026‑20250) – Immediate Patch Required

Cisco’s Adaptive Security Appliance (ASA) and Threat Defense (FTD) software for the 3100 and 4200 series can be forced into a denial‑of‑service state by an unauthenticated attacker sending crafted DTLS traffic. The flaw stems from improper resource handling during DTLS message processing, causing a device reload. Cisco has issued patches and workarounds; applying the update is essential to keep firewalls online.

Read briefing

News Threat Intel

Ransomware Costs Reveal: Ransom Is Just the Tip of the Iceberg – Downtime, Recovery and Compliance Add Millions

While the headline ransom payment often steals the spotlight, the real financial damage from a ransomware hit runs into the millions. New data shows an average total cost of $5.08 million per incident, compared to a median ransom of roughly $140 k. Prolonged downtime, complex recovery, and regulatory fallout drive the bulk of the bill. Only 35 % of firms actually restore critical systems in under a day, despite 60 % claiming they can. A mature Business Continuity & Disaster Recovery (BCDR) plan can slash downtime, streamline backups and ease compliance, dramatically reducing the overall hit.

Read briefing

News Advisories

Copilot Buttons Vanish in Classic Outlook – Microsoft Issues Workaround

Microsoft is still probing a glitch that makes the Copilot and Copilot Chat buttons disappear from Classic Outlook on Windows for users with certain M365 Copilot licenses. The problem surfaces after updating to build 20026.20182 or newer, and is tied to Outlook’s inability to find a specific MAPI property in a null profile section. While a permanent fix is pending, users can enable the "Show Apps in Outlook" setting or switch to a new profile, the new Outlook client, or OWA. The company also flagged unrelated crashes linked to Kaspersky’s Mail Checker, urging those customers to contact Kaspers

Read briefing

News Threat Intel

Inside the First Hours of a Google Workspace Breach: Live Webinar Reveals What Works and What Doesn’t

BleepingComputer partners with Material Security to host a live deep‑dive on how fast‑growing firms handle Google Workspace intrusions. The session dissects real breaches where attackers used social engineering and rogue OAuth apps, highlighting the critical early decisions that can either curb damage or amplify it. Attendees learn which controls deliver the most bang for lean security teams and hear the speakers’ take on building a resilient Workspace strategy from scratch.

Read briefing

News Advisories

CISA Unveils Updated Cyber Defense Playbook for Critical Infrastructure

The Cybersecurity and Infrastructure Security Agency (CISA) has released a refreshed guidance package designed to help critical infrastructure operators spot, track, and neutralize malicious cyber activity. Building on NIST standards, the playbook adds new threat‑intelligence sharing protocols, recommends automated monitoring solutions, and outlines coordinated incident‑response workflows. The goal is to cut detection lag, shorten dwell times, and strengthen resilience across energy, water, transportation, and other essential sectors.

Read briefing

News Advisories

Windows Server 2022 Slips Into Extended Support Next Month—Plan Your Upgrade to 2025 Before 2031

Microsoft announced that Windows Server 2022 will exit mainstream support on Oct 13 2026, sliding into a five‑year extended phase that ends Oct 14 2031. Hotpatching for the Datacenter: Azure Edition stays active until Oct 2027, while the free Windows 10 ESU program now runs until Oct 12 2027. Admins are urged to begin testing Windows Server 2025, which launched in 2024 and will stay mainstream until Nov 13 2029 with extended support until 2034. A free 180‑day trial is available via the Microsoft Evaluation Center. Early migration is key to keep your environment secure and compliant.

Read briefing

News Vulnerabilities

Google Patches Exploited Zero‑Day on Pixel Phones – 110 Bugs Fixed

Google released its September 2026 security patch for Pixel devices, addressing 110 vulnerabilities, including CVE‑2026‑58704 – a zero‑day that was actively exploited in targeted attacks. The flaw lives in the modem stack and lets attackers on an adjacent network elevate privileges without user interaction. All supported Pixel models now receive the 2026‑09‑05 update, and users are urged to install immediately.

Read briefing

News Threat Intel

North Korean APT Breaches South Korean Media and Auto Firms via New Linux Toolkit on HAProxy Load Balancers

A suspected North Korean APT deployed a previously undocumented Linux espionage toolkit, dubbed "TED," to compromise HAProxy load balancers in South Korean media and automotive companies. The attackers leveraged the compromised appliances to harvest credentials, redirect traffic, and execute drive‑by downloads, fitting the DPRK pattern of long‑term espionage via trusted software. Rapid7 links the activity to APT37 with medium confidence, highlighting the dual focus on information control and manufacturing IP.

Read briefing

News Vulnerabilities

Oracle Database Server Hit by Multi‑Vulnerability Storm: Remote Code Execution & DoS

A wave of critical flaws in Oracle Database Server—spanning 19.3 through 23.26.3—enables attackers to launch remote code execution and denial‑of‑service attacks. The vulnerabilities, catalogued under CVE‑2026‑83088 to CVE‑2026‑83351, affect all major releases from 19.3 to 23.26.3. Oracle has released patches in the 15 September 2026 security bulletin. Immediate patching is mandatory for any exposed database instances. CERT‑FR has issued an alert urging rapid remediation.

Read briefing

News Vulnerabilities

Mozilla Products Hit by 20+ Critical Vulnerabilities

The French CERT released an alert on September 16, 2026, detailing a suite of 22 CVEs affecting older releases of Firefox, Firefox ESR, Thunderbird, and Thunderbird ESR. The flaws enable attackers to elevate privileges, launch remote denial‑of‑service attacks, and exfiltrate sensitive data. Patches are available through Mozilla’s MFSA 2026‑90 to 2026‑95 advisories. All affected users should update immediately.

Read briefing

News Advisories

F5 NGINX Remote DoS & Data Integrity Flaw (CVE-2026-90439) – Patch Now

A critical flaw in F5’s NGINX Open Source has been exposed, letting attackers trigger a remote denial‑of‑service and corrupt data integrity. The vulnerability, identified as CVE‑2026‑90439, affects NGINX 1.31.x prior to 1.31.6 and 1.30.5. Immediate patching is essential. F5 has released a security bulletin detailing the fix; administrators should update or apply the vendor’s mitigation steps without delay.

Read briefing

News Advisories

Netgate pfSense Remote Code Execution Vulnerability (Sept 16 2026)

A critical flaw in Netgate’s pfSense firewall software allows attackers to run arbitrary code remotely. The issue affects all pfSense CE releases older than 2.9.0 and all pfSense Plus builds before 26.07. The vulnerability was disclosed by the French CERT (CERT‑FR) and a patch is available in the Netgate Security Advisory SA‑26_22. Administrators should update immediately to mitigate the risk of compromise.

Read briefing

News Vulnerabilities

StrongSwan Remote DoS Vulnerability (CVE‑2026‑78123) – Immediate Patching Required

A critical remote denial‑of‑service flaw has been discovered in StrongSwan VPN software, identified as CVE‑2026‑78123. The vulnerability allows attackers to crash the daemon on any system running a version older than 6.1.0, potentially taking networks offline. It is triggered by malformed IKE packets and can be mitigated by applying the vendor‑released patch. All affected deployments should update immediately.

Read briefing

News Vulnerabilities

HPE Aruba SD‑WAN Products Hit by Multiple Remote Code Execution and Privilege‑Escalation Flaws

HPE Aruba Networking has disclosed a set of critical flaws in its EdgeConnect SD‑WAN Gateways and Orchestrator that can be exploited for remote code execution, privilege escalation, and denial‑of‑service. Affected releases include Gateway 9.4.x‑9.7.x (pre‑9.4.9.0, 9.5.9.0, 9.6.4.0, 9.7.1.0) and Orchestrator 9.4.x‑9.7.x (pre‑9.4.11, 9.5.9, 9.6.4, 9.7.1.0). The CVE list ranges from CVE‑2024‑32664 to CVE‑2026‑76696. Patch the firmware immediately and follow HPE’s advisory for configuration hardening.

Read briefing

News Advisories

Google Chrome Faces 20+ CVEs – Update Now to Patch Critical Vulnerabilities

The French CERT has issued an urgent alert after discovering a bundle of 20+ CVEs in Google Chrome that can be exploited to trigger unspecified security failures. Affected are all Chrome releases older than 153.0.8010.47 on Linux and Windows, and 153.0.8010.48 on macOS. The vulnerabilities were disclosed in a Google release on 15 September 2026. Immediate upgrade to the latest stable channel is mandatory to close the gaps.

Read briefing