Threat actors are increasingly abusing Active Directory replication to impersonate domain controllers and steal password hashes from enterprise networks.…
Category: EN
Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
[This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]
CISA Warns of Fortinet Heap-based Buffer Overflow Flaw Exploited in Attacks
The U.S. Cybersecurity and Infrastructure Security Agency has added a critical Fortinet vulnerability, tracked as CVE-2025-25249, to its Known Exploited…
How to Disable Root Login via SSH: Step-by-Step Guide (2026)
By HOC Team | Last updated: September 08, 2026 | Read time: ~12 min How to Disable Root…
OpenSSL 4.1.0 Alpha1 Released With DTLS 1.3 and Faster Post-Quantum Cryptography
The OpenSSL Project has released OpenSSL 4.1.0 Alpha1, an early preview of its forthcoming feature release. This update adds support for Datagram…
Microsoft Patches Nearly 1,000 Vulnerabilities in September Update
A significant security update was released by Microsoft on Patch Tuesday in September, addressing 974 vulnerabilities across the company’s software…
LiteLLM Flaws Let Attackers Execute Code as Root and Steal Cloud Credentials
LiteLLM deployments can expose far more than an organization’s AI spending. Newly disclosed weaknesses in the open-source gateway could let attackers run…
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
The new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actors
Skullcandy Dime 3 Bluetooth Flaw Lets Nearby Attackers Hijack Audio and Microphone
Skullcandy Dime 3 wireless earbuds have a serious vulnerability related to unauthenticated Bluetooth pairing. This flaw allows nearby attackers to…
Australia To Let Users Switch Off Social Media Algorithms
Draft ‘duty of care’ legislation to be proposed this week would give users choice of whether to use platforms’ algorithms
Critical NetScaler Vulnerability Exploited in Attacks
Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3.
Will AI kill us all within the next decade?
AI researchers are warning that the technology could kill us all within the next decade, although they say the risk from current models is low.
Apple Xcode Integer Underflow Flaw Lets Crafted Archives Leak Memory and Crash Builds
A recently disclosed integer-underflow vulnerability in Apple’s modern Mach-O archive parser could allow a malicious static library to crash Xcode build…
Palo Alto PAN-OS Buffer Overflow Lets Attackers Execute Arbitrary Code as Root
Palo Alto Networks has announced a high-severity buffer overflow vulnerability in PAN-OS that may allow unauthenticated, network-based attackers to…
Hackers Steal Active Directory Password Hashes Without Attacking Domain Controllers Directly
Threat actors are increasingly exploiting Active Directory replication mechanisms to steal password hashes without directly compromising a domain…
Widened Scan Turns Up Fourth Rogue Claude Cyber Incident
Anthropic is most concerned about Claude Mythos 5’s reckless behavior after recent incidents in which real systems were hacked.
Fake GTA 6 Installer Steals Browser Passwords, Discord Tokens and Crypto Data From Gamers
Threat actors are exploiting anticipation around Grand Theft Auto VI by pushing fraudulent “leaked” game downloads that install a layered malware bundle…
ISC Stormcast For Tuesday, September 8th, 2026 https://isc.sans.edu/podcastdetail/10084, (Tue, Sep 8th)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Tuesday, September 8th, 2026 https://isc.sans.edu/podcastdetail/10084,…
Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)
State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure…
4.1 Million Impacted by AdaptHealth Data Breach
In June 2026, hackers stole personal, health, and insurance information from AdaptHealth’s systems.
