Skip to content

Sam's News — security — 2026-09-10

Security

8.5 IDScan Confirms Data Breach Exposing 153 Million Driver's License Scans

IDScan confirmed a data breach offering 153 million driver's license scans for sale following a September 4 incident notification.

Sources: BleepingComputer RSS, TechCrunch RSS, The Record RSS

8.5 Check Point Patches Two Critical VPN Certificate Vulnerabilities Enabling Unauthenticated RCE

Check Point disclosed two CVSS 9.8 critical vulnerabilities in its firewall and management products on September 9, 2026, allowing unauthenticated remote code execution via VPN certificate validation flaws and buffer overflow. Patches delivered via Live Patch and Jumbo Hotfix; Check Point found both vulnerabilities and reports no indication of active exploitation.

  • CVE-2026-85102 and CVE-2026-85103, both rated CVSS 9.8
  • VPN certificate validation failure (CVE-2026-85102) and heap buffer overflow in ASN.1 decoding (CVE-2026-85103)
  • Affects R82.10, R82, R81.20 and Spark Firewall
  • Unauthenticated remote code execution possible
  • No indication of active exploitation as of disclosure

Sources: The Hacker News AI Web Searched

8 Critical NetScaler Authentication Bypass CVE-2026-19490 Exploited in Wild

Citrix NetScaler ADC and Gateway appliances are vulnerable to CVE-2026-19490, a CVSS 9.3 authentication bypass flaw patched August 19 but actively exploited since September 3, 2026. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 10 and ordered federal agencies to patch within three days.

  • CVE-2026-19490, CVSS 9.3 authentication bypass
  • Patched by Citrix August 19, 2026
  • Exploitation began September 3 (one day after PoC published on GitHub)
  • CISA added to KEV catalog September 10; ordered federal agency patching within 3 days
  • Matching exploitation from three IP addresses across three countries detected by early September

Sources: SecurityWeek AI Web Searched

8 Russian Attackers Use AI Agents to Exploit PaperCut Flaws, Compromise 440+ Instances

A likely Russian-speaking threat actor deployed hundreds of AI agents to conduct a coordinated campaign exploiting PaperCut NG/MF vulnerabilities across 395 organizations.

  • 395 organizations compromised across 48 countries
  • Two CVE vulnerabilities exploited: CVE-2026-81578 and CVE-2026-82078
  • Campaign launched August 31 from IP 45.142.193.132
  • Some AI agents ignored attacker's country-restriction instructions
  • Fastest compromise: RCE in 4 hours, domain admin in 2 additional hours

Sources: The Hacker News RSS, BleepingComputer RSS, The Register AI Web Searched

8 AI Agents Rapidly Exploit Security Flaws from Minimal Information

Researchers demonstrate that AI agents can discover working software exploits from minimal information—even rumors suffice—and independently find vulnerabilities before public patches. The velocity of AI-driven exploit discovery has compressed the traditional disclosure timeline to minutes or hours, fundamentally incompatible with existing open-source embargo practices.

  • AI agents can derive working exploits from rumors or minimal information about vulnerabilities
  • Exploit discovery occurs in minutes to hours, much faster than developer patching
  • Attackers can probe targets within minutes of patches going live
  • Speed inverts traditional vulnerability disclosure cycle where secrecy previously bought patching time

Sources: Schneier on Security AI Web Searched

8 Cisco Firewall Management Center vulnerabilities exploited by ransomware and state-sponsored actors

Cisco Talos reported that two recently patched vulnerabilities in Secure Firewall Management Center have been exploited by ransomware gangs and state-sponsored threat actors.

Sources: BleepingComputer RSS

7.5 September Windows Server security updates break Remote Desktop Services

Windows Server 2019, 2022, and 2025 servers experience Remote Desktop Services failures following September 2026 security updates, in some cases requiring hard resets.

Sources: BleepingComputer RSS

7 Malicious Apps Exploit Google Play Early Access to Evade Security Review

Attackers are abusing Google Play's Early Access program to distribute deceptive apps falsely promising money, rewards, and casino winnings without undergoing standard review.

Sources: The Hacker News RSS, SecurityWeek RSS

7 BlueMoon exploit kit leverages Windows and Chrome zero-day vulnerabilities

Cyber-espionage groups deployed a malicious toolkit called BlueMoon that exploited previously unknown security flaws in Microsoft Windows and Google Chrome.

  • Four+ Chinese cyber-espionage groups exploiting same vulnerability
  • BlueMoon exploit kit uses identical code across groups
  • Targets U.S. defense contractors, NGOs, Southeast Asian government agencies
  • Four-week patch gap between fix and user deployment
  • Google moving to two-week Chrome release cycle to reduce patch gaps

Sources: BleepingComputer RSS Update to: Four China-Linked Hacking Groups Exploit Identical Chrome Zero-Day

7 AdaptHealth Data Breach Exposes Personal, Health, and Insurance Data of 4.1 Million

A breach of AdaptHealth's systems in June 2026 compromised personal, health, and insurance information for 4.1 million individuals.

Sources: SecurityWeek RSS