Daily briefing: Wednesday, September 30, 2026
Cisco has warned of active exploitation of a critical zero-day vulnerability, CVE-2026-76504, in its Catalyst SD-WAN Manager.
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Attackers exploited CVE-2026-73570 in Zimbra to deploy web shells and access mailbox data on servers with SNMP notifications enabled. A simple email gives attackers the ability to remotely inject OS commands. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on August 21, 2026.
- Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets The Hacker News
- Attackers have been exploiting critical Zimbra flaw to steal emails Ars Technica
- Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 Microsoft Threat Intelligence
Cisco warns of new SD-WAN zero-day exploited in attacks
Cisco released security updates to address a critical zero-day in Catalyst SD-WAN Manager, tracked as CVE-2026-76504, that attackers are actively exploiting. Attackers are exploiting the vulnerability to access Cisco SD-WAN Manager APIs as administrator without credentials. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog on September 30, 2026.
Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
Citrix NetScaler CVE-2026-88772 is exploited in the wild and can enable remote code execution through a DTLS buffer overflow. Mandiant CTO Charles Carmakal stated that suspected state-sponsored threat actors are likely behind targeted intrusions using the vulnerability. Dozens of impacted organizations across North America and Europe include government, financial, and educational sectors.
- Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution The Hacker News
- Suspected state-sponsored hackers exploited NetScaler zero-day since early September (CVE-2026-88772) Help Net Security
- Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks SecurityWeek
Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
The Russian state-sponsored actor Star Blizzard has launched phishing campaigns to deploy its signature CosmicPulse backdoor. The group is using a new tactic, dubbed RedFlick, against Ukrainian-linked targets to limit victim interaction.
Google: AI Is Changing the Pace and Profile of Vulnerability Discovery
Google Threat Intelligence Group found that AI is measurably changing the pace of vulnerability discovery and exploitation. Google's analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution.
- Google: AI Is Changing the Pace and Profile of Vulnerability Discovery SecurityWeek
- Vulnerability Discovery and Exploitation Trends in the AI Era Google Threat Intelligence
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Threat actors abuse legitimate domains from OpenAI and Google in these campaigns to fool unsuspecting users.
Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development
Trump says top tech firms have signed a voluntary accord to self-police artificial intelligence development. The accord calls on companies to implement greater controls and oversight over AI safety.
AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
Glow Labs found that AI coding agents leaked more than 13,000 internal company screenshots to public GitHub repositories. The images, spread over more than 900 repositories from over 300 organizations, include customer billing records.
Written by a language model from the linked articles only. Each sentence cites its sources and was checked against them, mechanically and by a model; sentences that failed either check were removed.