Eurojust says a 16-year-old is the suspected main operator of KillSec, a group it blames for almost 1,000 data-theft extortion attacks since 2024. Both published accounts say its favoured way in was poorly secured access to victims' cloud storage.
Perspective Coverage
14 publishers
- Builder
- Builder 16%
- Operator
- Operator 75%
- Investor
- Investor 9%
Reality
- Evidence78
- Adoption
- Insufficient
- Hype gap+25
- Incentives45
- Confidence76
Cisco says attackers are exploiting CVE-2026-76504, a 9.8-rated flaw that gives unauthenticated requests admin access to the Catalyst SD-WAN Manager API. Every configuration is affected, leaving exposed on-premises Managers needing an out-of-cycle upgrade and a check for earlier intrusion.
Perspective Coverage
12 publishers
- Builder
- Builder 14%
- Operator
- Operator 76%
- Investor
- Investor 10%
Reality
- Evidence85
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence80
Rapid7 tracked Linux implants on South Korean and Taiwanese edge appliances that erase their files ten seconds after launch but keep running. File scans miss them, so defenders have to hunt processes with no image on disk.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence58
Investigators say KillSec, tied to about 1,000 suspected attacks, got in through software flaws, weak cloud storage and logins bought on the dark web. Those gaps sit in victims' own systems, beyond the reach of any server seizure.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+5
- Incentives
- Insufficient
- Confidence40
Disclosures doubled year over year while actually-exploited vulnerabilities rose 8%. The arithmetic retires patch-everything SLAs and leaves exploitability triage as the defensible option.
Perspective Coverage
3 publishers
- Builder
- Builder 12%
- Operator
- Operator 76%
- Investor
- Investor 12%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+30
- Incentives70
- Confidence60
CVE-2026-19490 lets an unauthenticated attacker past NetScaler gateway and AAA virtual servers. Rapid7 has seen no exploitation yet and expects it shortly.
Perspective Coverage
5 publishers
- Builder
- Builder 14%
- Operator
- Operator 73%
- Investor
- Investor 13%
Reality
- Evidence78
- Adoption62
- Hype gap+10
- Incentives38
- Confidence75
A third party published CVE-2026-63520 before the planned date, and two public gadget chains now reach the same flaw by different routes. One signature will not cover both.
Reality
- Evidence72
- Adoption40
- Hype gap+5
- Incentives45
- Confidence70
Rapid7 scored it 9.9 and Gogs shipped 0.14.3 on June 7, 2026. The reason it rates that high is configuration: open registration and unlimited repository creation let a stranger own the repo they attack from.
Publishers:rapid7.com · runzero.com
Reality
- Evidence86
- Adoption50
- Hype gap+8
- Incentives72
- Confidence70
Huntress has seen exploitation in two customer environments. One flaw hands over PaperCut's configuration without a login, the second turns that configuration into a class loader, so patching and config review are one job.
Perspective Coverage
10 publishers
- Builder
- Builder 27%
- Operator
- Operator 60%
- Investor
- Investor 13%
Reality
- Evidence85
- Adoption70
- Hype gap−10
- Incentives40
- Confidence78
SonicWall's CVSS 10.0 SSRF chains into command execution on remote access appliances, and JFrog Artifactory hands unauthenticated attackers admin under default configuration. Reverse shells and miners are already landing.
Perspective Coverage
13 publishers
- Builder
- Builder 24%
- Operator
- Operator 63%
- Investor
- Investor 13%
Reality
- Evidence72
- Adoption30
- Hype gap+15
- Incentives55
- Confidence68
Rapid7 says the ted backdoor is built into the victim's existing HAProxy 2.8.12 and hooks its filter API, so the load balancer keeps balancing normally while it logs cookies and injects scripts for selected clients.
Perspective Coverage
5 publishers
- Builder
- Builder 42%
- Operator
- Operator 53%
- Investor
- Investor 5%
Reality
- Evidence70
- Adoption10
- Hype gap+20
- Incentives35
- Confidence66
N-able shipped N-central 2026.3 HF4 on Saturday and says nothing confirms production exploitation, while Huntress calls the bug a possible zero-day and has one compromised customer console whose logs had already rotated.
Perspective Coverage
7 publishers
- Builder
- Builder 17%
- Operator
- Operator 75%
- Investor
- Investor 8%
Reality
- Evidence72
- Adoption40
- Hype gap+10
- Incentives55
- Confidence70
CISA says all four are under active exploitation, and three of them are unauthenticated flaws in edge and management appliances. Its own alert cites BOD 26-04 and prints no due date for any of them.
Perspective Coverage
4 publishers
- Builder
- Builder 14%
- Operator
- Operator 80%
- Investor
- Investor 6%
Reality
- Evidence72
- Adoption
- Insufficient
- Hype gap+10
- Incentives
- Insufficient
- Confidence70
Rapid7 published a Metasploit module for CVE-2026-85706, an unauthenticated file read it says is already exploited against self-hosted GitLab. Every CE and EE build from 18.7 stays exposed until 19.1.8, 19.2.6 or 19.3.2.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+15
- Incentives35
- Confidence55
Researcher Rasmus Moorats published a two-flaw root chain for the OnePlus 15 on September 24, 127 days after OnePlus confirmed it and with no fix shipped. Until a patch lands, owners of affected OnePlus and OPPO phones can defend only by keeping untrusted apps off them.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+5
- Incentives60
- Confidence55
F5 disclosed CVE-2026-94127 on September 22 with hotfixes and evidence of exploitation. It is a data plane heap overflow, so a locked-down management interface still leaves the system exploitable, and federal agencies had until September 25.
Perspective Coverage
6 publishers
- Builder
- Builder 19%
- Operator
- Operator 64%
- Investor
- Investor 17%
Reality
- Evidence78
- Adoption40
- Hype gap+10
- Incentives30
- Confidence75
Rapid7's research with Zimbra turned up more than 50 vulnerabilities, several of which let an attacker send mail as another user with no password involved. The operational item today is CVE-2026-73570, the SNMP command injection CISA gave federal agencies three days to fix.
Reality
- Evidence55
- Adoption60
- Hype gap+25
- Incentives78
- Confidence55
CVE-2026-76460 scores a CVSS 10.0, affects Cisco ISE and ISE-PIC in every configuration, and has no workaround. CISA added it to the KEV catalog the day the patches shipped and gave federal agencies three days.
Perspective Coverage
16 publishers
- Builder
- Builder 18%
- Operator
- Operator 64%
- Investor
- Investor 18%
Reality
- Evidence82
- Adoption58
- Hype gap−8
- Incentives62
- Confidence80
CVE-2026-76461 was in use before Monday's advisory and Cisco says multiple customers were likely compromised first, so a gateway patched this week still needs a hunt against indicators that root access can erase.
Reality
- Evidence72
- Adoption58
- Hype gap0
- Incentives55
- Confidence66
Sixteen new modules landed in the framework, ten of them exploits, and Rapid7 counts five of those against CISA's exploited list. The SonicWall entry runs September's zero-day chain from SSRF to root.
Reality
- Evidence64
- Adoption55
- Hype gap+12
- Incentives74
- Confidence62
Earlier coverage
- Takedowns pushed fraud buyers into smaller specialised shops, Rapid7 says
Security · September 11, 2026 · 1 publisher
- CVE-2026-15409 handed one operator 534 Active Directory accounts through SonicWall WorkPlace portals
Security · September 11, 2026 · 1 publisher
- Rapid7 scan engines now ask credentialed hosts for their own listening port list
Security · September 9, 2026 · 1 publisher
- Attackers seized MSP N-central servers through the bypass N-able's incomplete fix left open
Security · September 9, 2026 · 1 publisher
- A backdoor built as an HAProxy filter suppresses the log lines that would show it
Build · September 8, 2026 · 1 publisher
- Two chained N-central bugs hand an unauthenticated caller a System administrator account
Security · September 8, 2026 · 1 publisher
- Rapid7 carries CVE-2026-66066 from a Rails upload to Kernel#spawn
Security · September 1, 2026 · 1 publisher
- Fulfilment breach exposes data of 13,689 Trezor customers, opening door to phishing
Invest · August 30, 2026 · 1 publisher
- Sixteen Metasploit modules reduce this quarter's advisories to one-command checks
Security · August 28, 2026 · 1 publisher
- Rapid7 counts 476 executive SSN records across three dark web markets
Security · August 27, 2026 · 1 publisher
- Honeypots logged a SharePoint JWT bypass hunting for a Business Data Catalog sink
Build · August 27, 2026 · 1 publisher
- AWS detection gets a shortlist: seven ATT&CK tactics, and only what has been seen in the wild
Build · August 24, 2026 · 1 publisher
- Copilot built the fake Ledger app. A human still only made 20 lookups in two weeks.
Invest · August 20, 2026 · 1 publisher
- Prompts, shell history, a jailbreak: AI assistants turn up inside a crypto-fraud build pipeline
Security · August 18, 2026 · 1 publisher
- A North Korean IT worker got hired by a federal agency. Vetting is a security control now.
Security · August 14, 2026 · 1 publisher
- Thirteen new Metasploit modules close the patch window on SonicWall SMA1000, Ghost CMS and Langflow
Security · August 14, 2026 · 1 publisher
- SharePoint flaw went from PoC to honeypot hits in a day, and Microsoft's advisory is still silent
Security · August 14, 2026 · 1 publisher