Sam's News β security β 2026-09-22¶
Security¶
7.5 Zyxel and Veeam security flaws actively exploited in the wild¶
The event title references Zyxel and Veeam security flaws with active exploitation, but the provided pages contain only Microsoft security content from January and February 2025 (Patch Tuesday updates addressing Windows Hyper-V vulnerabilities and other Microsoft flaws). The pages do not contain any information about Zyxel GS1900, Veeam, or CVE-2026-7273. The one_liner mentions CISA adding a critical Zyxel GS1900 vulnerability to its known exploited vulnerabilities catalog with command and system-level access confirmed, but this specific information is not present in the fetched article content. Without access to pages or search results containing actual Zyxel or Veeam vulnerability details, a factual extract cannot be reliably constructed from the available sources.
Sources: BleepingComputer RSS, The Hacker News RSS
7.5 Windows Defender zero-day blocks antivirus updates¶
A June 2026 zero-day in Microsoft Defender (CVE-2026-50656, RoguePlanet) allows remote attackers to gain administrative control of Windows 10/11 machines. Microsoft's July patch introduced a memory leak enabling disk exhaustion via unlimited Zone.Identifier caching, preventing normal antivirus operation.
- CVE-2026-50656 (RoguePlanet) disclosed June 2026 with public exploit code
- Microsoft patched via Malware Protection Engine update July 9, 2026
- Patch defense-in-depth introduces 8-byte memory leak in mpengine.dll when opening files
- SpyNet cloud caching of Zone.Identifier alternative data streams has no size limits, allowing attackers to exhaust disk space
Sources: Ars Technica AI Web Searched, BleepingComputer RSS
7.5 McKesson suffers third-party data breach exposing physicians and patient information¶
Healthcare distributor McKesson disclosed a data breach through third-party compromise exposing 284 million patient records including health insurance data, Social Security numbers, and medical information.
- 284 million patient records exposed
- Data includes health insurance information, Social Security numbers, names, addresses, driver's license numbers, financial data, and medical information
- Third-party attack vector
- Affected patients notified
Sources: Health Exec AI Web Searched, Medical Economics Web Search
7 WordPress patches Click2Shell remote code execution vulnerability¶
WordPress patched 11 vulnerabilities on September 22, 2026, including Click2Shell, which allows unauthenticated remote code execution via specially crafted URLs exploiting theme-preview API inconsistencies. Attackers can force theme installation and abuse unprotected installers to gain site ownership.
- Click2Shell: unauthenticated RCE via malformed theme-preview URLs
- Over 40 third-party WordPress.org themes execute PHP during Customizer preview when inactive
- Attackers can point to crafted plugin packages executed under WordPress server account
- WordPress 7.1.1 patches all 11 vulnerabilities; pwn.ai received $300 bug bounty (program maximum)
Sources: SecurityWeek AI Web Searched
7 Japan dismantles first North Korean laptop farm; US and allies expose WaterPlum campaign¶
Japan shut down the first confirmed North Korean laptop farm while the US, Japan, Germany, and Australia released a joint report detailing North Korea's WaterPlum campaign.
Sources: SecurityWeek RSS
7 WordPress Comment2Shell flaw allows anonymous XSS to escalate to RCE via admin session¶
WordPress patched a critical vulnerability (CVE-2026-93485) where an anonymous commenter's injected script could execute code on the server when viewed by an administrator.
Sources: The Hacker News RSS
6.5 BigCommerce merchants hit by Ribon app credential breach and malicious injection¶
BigCommerce has alerted merchants to data breaches involving compromised Ribon app credentials used to inject malicious scripts into online stores.
Sources: BleepingComputer RSS
6 SideCopy expands targeting to Indian academic institutions with ReverseRAT spear-phishing¶
The SideCopy threat actor has broadened its focus to target academic institutions in India via spear-phishing campaigns delivering the ReverseRAT malware.
Sources: The Hacker News RSS
6 Meta Muse AI assistant vulnerable to backdoor attacks via hidden settings¶
A security researcher demonstrated a proof-of-concept showing that malware on a Mac can hijack Meta's Muse assistant by modifying hidden settings to enable unauthorized control.
Sources: The Hacker News RSS
Policy/Security¶
6.5 US Proposes AI Incident Alert System in Talks With China¶
The US has proposed establishing an AI incident alert system during negotiations with China, according to Treasury Secretary Bessent.
Sources: SecurityWeek RSS