Sam's News β security β 2026-09-09¶
Security¶
9 SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution¶
SAP patched CVE-2026-44756, a CVSS 10.0 maximum-severity vulnerability in SAP Extended Passport Processing that allows unauthenticated remote code execution. A second critical flaw (CVE-2026-58240, CVSS 9.8) was also patched, both enabling attackers to execute arbitrary commands and extract sensitive data without credentials.
- CVE-2026-44756: CVSS 10.0, unauthenticated remote code execution via malformed EPP headers
- CVE-2026-58240: CVSS 9.8, missing authentication in NetWeaver Message Server
- Attackers can read SAP secure store, extract database credentials, and access session data
- Flaws reachable through internet-facing protocols without pre-existing authentication
Sources: The Hacker News AI Web Searched
8.5 Microsoft Patch Tuesday Addresses Record 974 Vulnerabilities Including Two Exploited Windows Zero-Days¶
Microsoft released an unprecedented 973 security patches in a single Patch Tuesday cycle, with at least two vulnerabilities already being exploited in the wild.
Sources: The Hacker News RSS, The Record RSS Update to: Microsoft September 2026 Patch Tuesday addresses record 966 vulnerabilities including two zero-days
8 F5 BIG-IP APM Malware Deploys In-Memory PHP Web Shell to Evade Disk Scans¶
Sophos identified malware targeting F5 BIG-IP APM that injects a PHP web shell into memory, bypassing disk-based threat detection. The attack exploits CVE-2025-53521 (RCE, CVSS 9.8), which was reclassified from DoS to remote code execution in March 2026 despite patches being available since October 2025.
- Malware injects PHP web shell into Apache memory while keeping disk version clean
- CVE-2025-53521: CVSS 9.8/9.3, active exploitation since March 2026 reclassification
- Affects BIG-IP APM versions 15.1.0β17.5.1; patches available since October 2025
- Attack begins with installer that modifies /usr/sbin/httpd and disables SELinux
Sources: The Hacker News AI Web Searched
8 Google Patches Seventh Chrome Zero-Day Exploited in Active Attacks This Year¶
Google released patches for 230 vulnerabilities including a seventh actively exploited Chrome zero-day in 2024.
Sources: BleepingComputer RSS
8 US Agencies Report Chinese Firms Conducted Industrial-Scale Distillation Attacks on American Frontier AI Models¶
U.S. cybersecurity and intelligence agencies disclosed that six Chinese AI companies executed large-scale model distillation attacks against American cutting-edge AI models since late 2024.
Sources: BleepingComputer RSS, The Register RSS
8 Four China-Linked Hacking Groups Exploit Identical Chrome Zero-Day¶
A previously undocumented exploit kit called BlueMoon, which chains Windows and Chrome vulnerabilities, has been deployed by four espionage-motivated threat groups in a single week.
- Four+ Chinese cyber-espionage groups exploiting same vulnerability
- BlueMoon exploit kit uses identical code across groups
- Targets U.S. defense contractors, NGOs, Southeast Asian government agencies
- Four-week patch gap between fix and user deployment
- Google moving to two-week Chrome release cycle to reduce patch gaps
Sources: The Record AI Web Searched, The Hacker News RSS
7.5 Chrome V8 Zero-Day Vulnerability Patched After Active Exploitation¶
Google patched CVE-2026-87491, a medium-severity out-of-bounds write vulnerability in Chrome's V8 engine that was actively exploited in the wild. The flaw allowed arbitrary code execution within the Chrome sandbox via crafted HTML.
- CVE-2026-87491: out-of-bounds write in V8 JavaScript/WebAssembly engine
- Patched in Chrome 153.0.8010.36/.37; actively exploited before patch release
- Researcher Jihyeon Jeong discovered flaw August 6, 2026; received $2,500 bounty
- Seventh actively exploited Chrome zero-day addressed in 2026
Sources: The Hacker News AI Web Searched
7.5 cPanel Root Code Execution Flaw via EmailTrack Mail Privilege Escalation¶
cPanel patched a vulnerability allowing authenticated mail-account holders to execute code as root through the EmailTrack feature.
Sources: The Hacker News RSS
7.5 N-able N-central Critical Pre-Auth RCE Vulnerability Exploited in Active Attacks¶
CISA added a critical remote code execution flaw in N-able N-central to its known exploited vulnerabilities catalog, with a September 11 federal remediation deadline.
- CVE-2026-86218: unauthenticated remote code execution, CVSS 10.0
- Static code injection flaw (CWE-96) affecting all N-central builds before 2026.3.1.14
- Fourth hotfix in five weeks; Hotfix 3 released eight hours before Hotfix 4
- Hosted N-central instances already patched; on-premises customers must upgrade immediately
- Huntress recommends IP allowlisting, VPN restriction, or taking servers offline until patching
Sources: The Hacker News RSS Update to: N-able releases fourth hotfix in five weeks for critical N-central RCE vulnerability
7.5 Google Security Alert: AI Enables Lesser-Resourced Attackers to Reach Nation-State Threat Levels¶
Google's Threat Intelligence Group warned that AI is enabling lesser-resourced criminal and state-sponsored attackers to automate attacks at nation-state sophistication. Threat actor TeamPCP (UNC6780) used AI coding tools to execute a mass credential harvesting campaign in under six hours, conducting supply chain compromises across PyPI, npm, and Docker Hub.
- Evolution from prompt injection to adversaries deploying own AI systems
- TeamPCP conducted campaign in less than six hours using AI chatbots
- Supply chain compromises targeting PyPI, npm, Docker Hub since March 2026
- Developed publicly available malware Shai-Hulud and Miasma
- Public malware release likely to spur emulation by other adversaries
Sources: SecurityWeek AI Web Searched