Why Should I Care? β 2026-10-01 | π΄ 1 HIGH Β· π‘ 0 MEDIUM Β· π΅ 19 RADAR Β· βͺ 100 FILTERED
π Briefing β 2026-10-01
20 vendor intel items scanned | π΄ 1 HIGH | π‘ 0 MEDIUM | π΅ 19 RADAR | βͺ 100 FILTERED
π΄ Critical β action required:
- CISA Adds One Known Exploited Vulnerability to Catalog (CVE-2026-76504) β Yes, if you run Cisco Catalyst SD-WAN Manager versions 2.0.0 to 2.4.5: this vulnerability allows attackers to gain total control of your system.
Everything else can wait.
π΅ 15 items on the radar β see below β
Why Should I Care? π΄ HIGH β Handle Now
CISA Adds One Known Exploited Vulnerability to Catalog
CISA Advisories [CISA KEV] | CVSS 9.8 | CVE-2026-76504
β Why Should I Care?
Yes, if you run Cisco Catalyst SD-WAN Manager versions 2.0.0 to 2.4.5: this vulnerability allows attackers to gain total control of your system.
π― Affected versions: 2.0.0 to 2.4.5
Not affected: 2.4.6 and later
π In plain English:
This vulnerability means that attackers can exploit a flaw in the way your system handles certain data, allowing them to take full control of your network management system. For example, an attacker could remotely access your network, change configurations, and disrupt services.
π§ Prerequisites:
- Running affected versions of Cisco Catalyst SD-WAN Manager
- Network access to the SD-WAN Manager
β± Urgency: High urgency due to active exploitation and the risk of total system compromise.
β Fixed in: 2.4.6, 2.5.0
π‘ Context: The root cause is a flaw in the hex encoding process used by the SD-WAN Manager, which allows for injection of malicious data.
Why Should I Care? π‘ MEDIUM (0)
None.
Why Should I Care? π΅ On the Radar (19)
- Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets (The Hacker News) β A security flaw in Zimbra Collaboration Suite allowed attackers to deploy web shells and steal authentication secrets. This flaw was patched, but it's critical to ensure your Zimbra version is up to date to avoid exploitation.
- Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution (The Hacker News) β A critical flaw in Citrix NetScaler ADC and Gateway allows attackers to execute arbitrary code without authentication due to a memory overflow bug. This can lead to full server compromise.
- Russian state hackers use new RedFlick technique to push malware (BleepingComputer) β Russian state hackers are using a new method called RedFlick to spread malware through phishing emails. This method is more automated and harder to detect than previous methods, making it a significant threat to organizations that might be targeted.
- Over 543,000 valid credentials exposed in public GitHub repositories (BleepingComputer) β Over 543,000 valid credentials were found in public GitHub repositories, with some exposed for over 6 years. This highlights the ongoing risk of sensitive data exposure in public code repositories.
- DIVD says Zammad zero-days enabled AI-driven network breach (BleepingComputer) β DIVD was breached due to two zero-day vulnerabilities in Zammad, an open-source ticketing system. These vulnerabilities allowed attackers to hijack sessions, execute remote code, and escalate privileges, leading to data exfiltration. This is a significant security risk for any organization using Zammad.
- Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager (The Hacker News) β A critical flaw in Cisco's SD-WAN Manager lets attackers log in as admin without needing credentials, potentially giving them full control over your network. This is urgent if you use Cisco SD-WAN.
- Cisco warns of new SD-WAN zero-day exploited in attacks (BleepingComputer) β Cisco has identified a critical zero-day vulnerability in their Catalyst SD-WAN Manager software that allows attackers to bypass authentication and gain admin access. This can lead to unauthorized control over your network infrastructure.
- CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS (BleepingComputer) β CISA has identified a critical vulnerability in MikroTik RouterOS that allows unauthenticated attackers to execute code remotely or cause a denial-of-service. This affects versions below 7.24, and the impact could be severe for networks using these routers.
- Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT (The Hacker News) β A critical security flaw in Citrix NetScaler ADC and Gateway appliances has been exploited by attackers to gain root access and deploy malicious tools like WHIPSHOT and SLAPSHOT. This affects government, financial services, technology, education, and legal sectors.
- Bitget hacked via zero-day in third-party security products (BleepingComputer) β Bitget, a cryptocurrency exchange, was hacked due to a zero-day flaw in third-party security products, leading to a theft of $387.5 million. This shows that even with security products, vulnerabilities can be exploited, potentially leading to massive financial losses.
- Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks (The Hacker News) β Hackers are using phishing emails to trick users into installing MSP360, which then allows them to install ScreenConnect and gain full remote access to your systems. This can lead to data theft and further system compromise.
- Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures (The Hacker News) β Hackers are using fake AI chatbots to trick users into downloading malware. This can lead to remote access to your systems and data theft. For example, a user might click on a seemingly legitimate link and end up installing a RAT (Remote Access Trojan) that gives attackers control over their machine.
- TeamViewer urges users to patch severe flaws βas soon as possibleβ (BleepingComputer) β TeamViewer has identified and patched several high-severity vulnerabilities that could allow unauthorized access and remote code execution. If you use TeamViewer, you need to update immediately to protect your systems from potential attacks.
- OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted (The Hacker News) β A critical flaw in OpenSSL's DTLS implementation can leak unencrypted heap memory and cause crashes. This affects software using OpenSSL for DTLS, impacting confidentiality and availability.
- US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access (The Hacker News) β A phishing campaign is targeting US-based executives, stealing Microsoft 365 sessions and deploying remote access tools, potentially giving attackers both account and endpoint control. This can lead to broader account compromise, fraud, and persistent access to business systems.
βͺ 100 low-priority items filtered.
π¦ Aggregated and triaged by Donna AI | Sources: 8 vendor feeds | CISA KEV