> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> InfoSec News Nuggets – 09/22/2026

[SOURCE] AboutDFIR [AUTHOR: Mary] [DATE: 22/09/2026 10:08] [LANGUAGE: EN]
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE SolarWinds has shipped security updates for Access Rights Manager after discovering a hard-coded static cryptographic key that could let an attacker execute code on a managed host without authentication. Tracked as CVE-2026-28326 with a CVSS score of 8.8, the flaw affects all ARM versions 2026.2 and earlier and was privately reported by a security researcher rather than found through active exploitation. Administrators are urged to upgrade to ARM 2026.2.1, which also resolves a batch of other recently disclosed flaws in the company’s Web Help Desk and Serv-U products.   CISA Warns of Linux Kernel Vulnerabilities Actively Exploited in Attacks CISA added three actively exploited Linux kernel vulnerabilities to its Known Exploited Vulnerabilities catalog, spanning a critical flaw in the kernel’s TLS receive path, an out-of-bounds write in the netfilter bridge ebtables SNAT target, and a race condition in the AF_ALG cryptographic interface. Federal civilian agencies faced a September 21 remediation deadline, and the agency additionally required forensic triage of potentially exposed systems rather than treating patching alone as sufficient. CISA has not disclosed who is behind the exploitation or which organizations have been targeted.   TanStack NPM Supply Chain Attack Exposes 170 Private CrowdSec GitHub Repositories CrowdSec disclosed that attackers used a stolen GitHub OAuth token belonging to a recently departed employee to clone roughly 170 of its private repositories during May’s broader TanStack npm supply-chain compromise, with the theft only discovered after the stolen code surfaced on a cybercrime forum in September. The exposed archive contained internal source code along with email addresses for 83 users and contact details for 51 potential investors from 2020, though the company says its production infrastructure and databases were never touched. CrowdSec has since deployed endpoint detection on developer workstations and is tightening offboarding procedures to prevent similar lingering access.   Cisco drops another exploited zero-day, this time a perfect 10 Cisco disclosed a maximum-severity authentication bypass in Identity Services Engine and ISE Passive Identity Connector that is already under active exploitation, letting an unauthenticated remote attacker send a crafted request to an API and ultimately gain root-level command execution. No workaround exists beyond restricting management traffic with access control lists, and admins are being urged to check logs for suspicious activity and, where compromise is suspected, reimage affected nodes entirely. The advisory landed just days after a separate actively exploited flaw was patched in the company’s Secure Email Gateway products, making for an unusually heavy patching month.   Revolut phishing texts appear days after data breach Days after Revolut acknowledged that fraudsters posing as a government agency tricked it into handing over sensitive customer records, including IDs, selfies, and financial histories, affected customers began receiving convincing phishing texts that appeared in the same message thread as legitimate bank alerts. One reported scam page requests camera access to mimic Revolut’s identity-verification flow before harvesting a password, a tactic that could make follow-on account takeover attempts far more convincing. It remains unconfirmed whether the phishing wave is directly tied to the leaked data or is opportunistic exploitation of the breach’s publicity. The post InfoSec News Nuggets – 09/22/2026 appeared first on AboutDFIR - The Definitive Compendium Project.
[messages.read_original_source] →