Skip to content

Sam's News β€” security β€” 2026-09-16

Security

8.5 Critical Issabel Framework vulnerability CVE-2026-89026 exploited for unauthenticated OS command execution

A critical vulnerability (CVE-2026-89026, CVSS 9.8) in Issabel Framework allows unauthenticated attackers to execute arbitrary OS commands via forged JWT tokens. A patch released August 1, 2026, replaces the hard-coded JWT signing key with one stored in configuration files; active exploitation began September 9.

  • CVE-2026-89026 with CVSS score 9.8/10 allows unauthenticated remote command execution
  • Hard-coded JWT signing key identical across all installations enabled token forgery
  • Patch released August 1, 2026; active exploitation first observed September 9, 2026
  • Attackers exploit /pbxapi/manager/originate endpoint to execute commands as Asterisk user

Sources: The Hacker News AI Web Searched

8 Google patches actively exploited Android zero-day on Pixel devices

Google released patches on September 15 for an actively exploited privilege escalation vulnerability (CVE-2026-58704) in Pixel modem firmware.

  • CVE-2026-58704 zero-day vulnerability in Pixel modem
  • Allows privilege escalation bypassing modem sandbox
  • Zero-click attack requiring no user interaction
  • Some Pixel owners targeted and compromised
  • Commonly exploited by surveillance vendors and spyware makers

Sources: BleepingComputer RSS, SecurityWeek RSS, TechCrunch AI Web Searched

8 WSO2 API Manager JWT Bypass Vulnerability Under Active Exploitation

CVE-2026-5430, a critical JWT authentication bypass vulnerability in WSO2 API Manager and related products, is under active exploitation as of September 13, 2026. The flaw allows attackers to forge admin tokens by using unsupported cryptographic algorithms, enabling full account takeover and access to sensitive credentials.

  • CVSS score 9.8/10.0
  • Affects API Manager 4.1.0–4.6.0, API Control Plane 4.5.0–4.6.0, Traffic Manager 4.5.0–4.6.0, Universal Gateway 4.5.0–4.6.0
  • Active exploitation detected September 13, 2026
  • Patches released May 2026; community fixes available via GitHub
  • Attackers can access API credentials, consumer keys, and secrets for registered applications

Sources: The Hacker News AI Web Searched

8 Critical ScreenConnect Vulnerability Actively Exploited in the Wild

A critical-severity vulnerability in ConnectWise ScreenConnect is being actively exploited by attackers in the wild, according to CISA.

Sources: BleepingComputer RSS Update to: ConnectWise patches critical ScreenConnect vulnerability exploited in attacks

7.5 Oracle patches over 800 vulnerabilities in September 2026 security update

Oracle released 673 new security patches on September 16, 2026, addressing over 800 vulnerabilities across 17 product families, including more than 100 critical-severity flaws and over 240 remotely exploitable without authentication. E-Business Suite, Fusion Middleware, and Hyperion received the largest patch volumes.

  • 673 new patches released September 16, 2026
  • Over 800 vulnerabilities addressed across 17 product families
  • More than 100 critical-severity flaws
  • Over 240 remotely exploitable without authentication
  • E-Business Suite: 159 patches (19 remotely exploitable); Fusion Middleware: 153 patches (78 remotely exploitable); Hyperion: 102 patches (50 remotely exploitable)

Sources: SecurityWeek AI Web Searched

7.5 Attacker hijacks AI coding assistant, spreads malware across 100 repositories

An attacker hijacked an active AI coding-assistant session at a SaaS provider and deployed the self-spreading Shai-Hulud malware across approximately 100 internal repositories. The attack chain included stealing GitHub OAuth tokens and poisoning packages in the company's official namespace.

  • Approximately 100 internal repositories infected
  • Shai-Hulud self-spreading malware deployed
  • GitHub OAuth tokens stolen via infostealer
  • Second employee infected via poisoned package in official namespace
  • Malware stole repository secrets and source code

Sources: The Hacker News AI Web Searched

7.5 280,000 Patients Impacted by Premier Medical Group Data Breach

Premier Medical Group in New York suffered a data breach in June 2026 exposing personal and medical information for 282,075 patients. The breach included names, contact information, diagnoses, medications, insurance details, and treatment records, with PMG notifying HHS on September 16.

  • 282,075 patients' data exposed
  • Breach occurred June 14, 2026
  • Data included names, diagnoses, medications, insurance information
  • PMG serves cardiology, dermatology, gastroenterology, neurology, and other specialties
  • No responsible party or ransomware group identified

Sources: SecurityWeek AI Web Searched

7.5 Banking malware toolkit forces Chrome and Edge extension installations

A banking malware operation active since mid-2025 uses a toolkit called KREMLIN to forcibly install malicious browser extensions that steal credentials and session tokens.

  • Malware: KREMLIN (REF9334), active since May 2025
  • Targets: Brazilian banks via fake banking/invoice/company documents in Portuguese
  • Browser extensions targeted: Chrome and Edge, extension ID ndpbidppejfanjbhfgjlohfanbfbklff
  • Uses Ethereum smart contracts as dead drop C2 resolvers for endpoint updates
  • Sandbox/VM evasion; DLL sideloading via SentinelOne binary; credential/token theft

Sources: BleepingComputer RSS Update to: KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials

7.5 Browser extension vulnerability could hijack AI assistants across Chrome, Edge, Opera, and Claude

Security researchers at Forever Security discovered a single browser extension vulnerability affecting AI assistants in Chrome, Edge, Opera, and Claude extensions. The attacks required only two common browser permissions and no user interaction, with Chrome and Perplexity Comet vulnerabilities fixed; others remain unpatched.

  • CVE-2026-0628 (Chrome, CISA 8.8/10) fixed in version 143.0.7499.192 in January 2026
  • CVE-2026-55945 (Edge, severity 4.2) fixed in version 150.0.4078.48 on July 2, 2026
  • Comet, Opera Neon, and Claude vulnerabilities have no CVE assigned
  • Researcher earned approximately $20,000 total in bug bounties across five products

Sources: The Hacker News AI Web Searched

7.5 Windows 11 KB5124008 security update breaks domain trust relationships for enterprise users

Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships, preventing valid domain credential authentication.

Sources: BleepingComputer RSS