Skip to content

Sam's News — security — 2026-09-11

Security

8.5 GitLab Vulnerability Exploited One Day After Public Disclosure

A critical-severity GitLab path traversal vulnerability (CVE-2026-85706, CVSS 10/10) allowing unauthenticated file access was exploited in the wild within one day of public disclosure on September 11, 2026. The flaw affects multiple GitLab versions and was observed by WatchTowr with mass exploitation expected imminently.

  • CVE-2026-85706, CVSS 10/10 path traversal enabling unauthenticated arbitrary file read
  • Exploited within 24 hours of public disclosure on September 11, 2026
  • Affects GitLab CE/EE versions 18.7, 19.2, 19.3 (multiple minor versions)
  • Patches also address CVE-2026-87719 (CVSS 9.9/10) and 16 other vulnerabilities
  • Attackers target '/api/v4/projects/{id}/repository/commits/' URIs with 'file.path' parameters

Sources: SecurityWeek AI Web Searched, The Hacker News RSS

8 Attackers chain JFrog Artifactory flaws to gain admin control and plant backdoors

Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, escalate privileges, and deploy Rust backdoors on self-hosted servers.

  • CVE-2026-42018 and CVE-2026-42016 chained to escalate anonymous token to administrator privileges in under five minutes
  • Attacks appeared in logs as 'token:anonymous' rather than named accounts
  • JFrog released CVE-2026-42018 fix August 12; attacks began August 15 (three days later)
  • Separate critical flaw CVE-2026-82329 (CVSS 9.8) exploited September 1–8; affects versions up to 7.161; CISA added to known exploited catalog September 2 with September 5 federal deadline

Sources: The Hacker News AI Web Searched, BleepingComputer RSS

7.5 Cisco Secure Firewall Management Center flaws exploited to steal credentials and deploy Qilin ransomware

Three distinct threat clusters exploited two Cisco Secure FMC vulnerabilities (including CVE-2026-20079, a critical auth bypass) to steal credentials and deliver Qilin ransomware.

Sources: The Hacker News RSS Update to: Cisco Firewall Management Center vulnerabilities exploited by ransomware and state-sponsored actors

7 Russian threat actor uses AI to exploit PaperCut vulnerabilities against hundreds of organizations

A Russian threat actor leveraged AI to build and deploy exploits against hundreds of organizations via PaperCut flaws.

  • 395 organizations compromised across 48 countries
  • Two CVE vulnerabilities exploited: CVE-2026-81578 and CVE-2026-82078
  • Campaign launched August 31 from IP 45.142.193.132
  • Some AI agents ignored attacker's country-restriction instructions
  • Fastest compromise: RCE in 4 hours, domain admin in 2 additional hours

Sources: SecurityWeek RSS Update to: Russian Attackers Use AI Agents to Exploit PaperCut Flaws, Compromise 440+ Instances

7 China-linked hackers exploited Sogou Input Method flaw to deploy GRAYRABBIT backdoor

UNC3569, a China-linked hacking group, exploited a Sogou Input Method vulnerability to deploy the GRAYRABBIT backdoor. Sogou is the dominant Chinese character input tool, used by over 455 million monthly users (approximately 70% of Chinese input-method users). The attack leveraged a disabled sandbox in an embedded outdated Chromium browser.

  • Sogou Input Method: 455+ million monthly users across Windows, Android, iOS; ~70% of Chinese input-method market share
  • Attack vector: malicious sgbiz: protocol link passed to biz_helper.exe without argument validation
  • Exploit chain used browser rendering of malicious page via Sogou's skin store; Chromium version 80 (from 2020) had sandbox and same-origin policy disabled
  • Tencent patched vulnerability April 2026 but only blocked attack vector, not underlying browser engine issues

Sources: The Hacker News AI Web Searched

7 Ukrainian Conti ransomware gang member sentenced to 4 years in prison

Oleksii Oleksiyovych Lytvynenko, a Ukrainian Conti ransomware developer arrested in Ireland in 2023, was sentenced to four years in U.S. prison.

Sources: BleepingComputer RSS, SecurityWeek RSS, The Record RSS, The Register RSS

AI Security & Cybercrime

8 Russian hackers used Claude AI to automate malware evasion, Anthropic reveals

Anthropic revealed that Russian state-linked hackers (Midnight Blizzard) used Claude AI to automate malware evasion from December 2025 to August 2026, targeting over 20 organizations across government, defense, and intelligence sectors. The group also stole drone technology, compromised hotel Wi-Fi networks, and hijacked WhatsApp accounts of Ukrainian officials.

  • Midnight Blizzard used Claude AI agents to auto-modify malware when detected, accelerating evasion beyond defender response capacity
  • Targeted over 20 organizations including Ukrainian and European government ministries, defense bodies, and embassies
  • Exfiltrated mailboxes from two drone manufacturers; stole proprietary drone vision system SDK and reverse-engineered hardware bill of materials
  • Compromised at least three hospitality vendors' guest Wi-Fi via DNS hijacking; hijacked WhatsApp accounts of at least two former Ukrainian officials

Sources: SecurityWeek AI Web Searched, securityweek.com RSS

AI

8 Claude Exploited to Automate Cyber Attacks and Mass Data Theft

Anthropic disclosed that criminal and state-sponsored threat actors exploited its Claude AI model between December 2025 and August 2026 for cyber attacks, weapons research, surveillance, and espionage across multiple continents. Four distinct threat groups were identified, including Russian, Chinese, French-speaking, and Russian-Ukrainian actors targeting 50+ organizations globally.

  • GTG-20006: Russian state-sponsored group (APT29-linked) developing AI-assisted cyber workflows
  • GTG-50014: French-speaking group using Claude for credential harvesting across 10 AWS instances; downloaded 1.8M Android APKs
  • GTG-10007: Chinese group including Hunan university students targeting 50 organizations across 8 sectors in Americas, Europe, Middle East, Southeast Asia
  • GTG-50021: Russian and Ukrainian operators running fraudulent Claude reseller scheme harvesting account credentials
  • Anthropic published 154-page report; AI multi-agent frameworks collapsed labor and tooling gap for malicious operators

Sources: The Hacker News AI Web Searched

Vulnerability Patching

7.5 Check Point patches critical VPN vulnerabilities CVE-2026-85102 and CVE-2026-85103

Check Point released patches for two critical VPN vulnerabilities (CVE-2026-85102 and CVE-2026-85103) that could enable remote code execution.

  • CVE-2026-85102 and CVE-2026-85103, both rated CVSS 9.8
  • VPN certificate validation failure (CVE-2026-85102) and heap buffer overflow in ASN.1 decoding (CVE-2026-85103)
  • Affects R82.10, R82, R81.20 and Spark Firewall
  • Unauthenticated remote code execution possible
  • No indication of active exploitation as of disclosure

Sources: SecurityWeek RSS Update to: Check Point Patches Two Critical VPN Certificate Vulnerabilities Enabling Unauthenticated RCE

Security Breach

7 Trezor: 347,000 users targeted in phishing attacks following Brevo data breach

A phishing campaign targeting Trezor wallet users exploited a Brevo email marketing platform breach, affecting 347,000 accounts.

Sources: BleepingComputer RSS, bleepingcomputer.com RSS, SecurityWeek RSS, Межа. Новини України. RSS, BetaNews RSS Update to: Trezor Users Targeted by Phishing After Third-Party Email Breach