daily cyber × ai intelligence

index

tagged

[cloudflare]

7 editions · 7 items

September 16, 2026

CVE-2026-76461 Gives Remote Attackers Root on Cisco Email Gateways

Cisco Secure Email Gateway suffers from CVE-2026-76461, an unauthenticated SQL injection flaw in AsyncOS being actively exploited for root-level command execution; CISA has added it to KEV. CVE-2026-39364 enables mass scanning of exposed Vite development servers to harvest cloud secrets from AWS, Azure, and Terraform configurations. n8n patched two agent authorization bypasses (CVE-2026-65015 and CVE-2026-59207) that allowed read-only users to execute arbitrary nodes and bypass domain restrictions to steal credentials. Iranian state actors deployed CHOSEN BRICK spyware against dissidents and journalists using fake MRI results as a social-engineering lure, while UTA0560 exploited a Chrome–Windows zero-day chain to deliver GRIMWEDGE against NGOs on September 1.

September 2, 2026

  • OpenAI's Astra scored 100% on ExploitBench and, on a fresh internal benchmark of 20 recent high-severity V8 bugs built to control for contamination, hit ~39% arbitrary-code-execution versus ~1% for GPT-5.6 Sol at comparable token spend, per @AiBattle_. In expert evaluations the model reportedly escaped a hardened browser sandbox from a single HTML file and chained OS bugs from unprivileged user to root, and discovered two previously unknown V8 vulnerabilities during the eval itself (@kimmonismus). Read the numbers with care: the strongest results reflect elevated Daybreak Blue access rather than the default public configuration, and full exploit capability goes to alpha testers and Daybreak partners like Cisco and Cloudflare first (@TokenGremlin, @IntCyberDigest). OpenAI says public release is "soon" with cyber capabilities restricted. · AI & Model Security
  • Nimbus Manticore / Mirage Kitten is now cross-platform, delivering the previously undocumented NodeRabbit and PollCat Node.js/JavaScript RATs to Windows, Linux, and macOS via LinkedIn spear-phishing with trojanized coding-challenge archives. Kaspersky reports targeting of aviation and FinTech in Afghanistan, Egypt, and Ethiopia, with C2 blended into Azure and Cloudflare traffic (Securelist, The Hacker News). · Threat Activity

in OpenAI Says Astra Crossed the Line: Autonomous Zero-Day Discovery at "Critical" Cyber Risk

August 31, 2026

  • TerminalFix chains a fake Cloudflare CAPTCHA (ClickFix) lure into DLL sideloading and a reverse tunnel for persistent access, with Microsoft publishing detections and hunting queries (Microsoft, The Hacker News). Kevin Beaumont notes the same entry technique is being run by a ransomware-as-a-service operation that is reaching some of the world's largest companies (discussion). · Threat Activity

in Fully Patched, Still Domain Admin