ITsecurity Daily
Daily Briefing
CISA flags two actively exploited flaws in WSO2 and Adobe Commerce/Magento — patch on the clock
Good morning. CISA added two vulnerabilities to its Known Exploited Vulnerabilities Catalog on 24 September, based on evidence of active exploitation. CISA lists CVE-2026-5430, a path traversal vulnerability in multiple WSO2 products, and CVE-2026-71362, an incorrect authorization vulnerability in Adobe Commerce and Magento. CISA states these types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. If you run either product, match your versions against the vendor advisories and treat remediation as time-sensitive; CISA's alert points to its binding operational directive for prioritizing remediation.
The Register reported that Salesforce Agentforce carried security flaws, dubbed "SalesBleed," that allowed zero-click CRM data theft and anonymous phishing. The Register reported the flaws lead to very unexpected consequences. If you use Agentforce, treat it as affected.
The Hacker News reported that a researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access — the highest level of control over an Android phone — on a OnePlus 15 running the latest OxygenOS, using a malicious app that asks for no special permissions. The Hacker News reports the flaws are unpatched.
Zoom out: Multiple outlets reported the same theme — attackers wiring AI agents into intrusion, from a single operator's automated scans to malware that installs an AI framework on the hosts it hijacks.
Elsewhere
- SecurityWeek: Roundcube Webmail Vulnerability in Attackers’ Crosshairs Read it
- The Hacker News: WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV Read it
- The Hacker News: Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data Read it
- Help Net Security: Stop watching what AI agents say and start watching what they do Read it
- Help Net Security: Half of threat hunters say bad data is their biggest problem Read it
- Help Net Security: Your incident count is missing a few incidents Read it
- Help Net Security: New infosec products of the month: September 2026 Read it
- The Register: Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs Read it
- SecurityWeek: Autonomous AI Hacks Raise Thorny Questions of Legal Accountability Read it
- The Record: Digital forensics firm with US federal contracts covered up ties to Russia, DOJ alleges Read it
- CISA: CISA Adds Two Known Exploited Vulnerabilities to Catalog Read it
- The Register: Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing Read it
Sources
- Crook used three open source agents to break into a Fortune 500 hospitality company, a major US airline and 25+ other orgs The Register
- MacSync malware uses public iCloud calendars to deliver new payloads BleepingComputer
- Autonomous AI Hacks Raise Thorny Questions of Legal Accountability SecurityWeek
- Digital forensics firm with US federal contracts covered up ties to Russia, DOJ alleges The Record
- Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions The Hacker News
- Symphony Risk Intelligence uses AI agents to streamline financial crime investigations Help Net Security
- CISA Adds Two Known Exploited Vulnerabilities to Catalog CISA
- Malicious npm Packages That Evade Defenses Schneier on Security
- Lawmakers introduce bill for voluntary telecom cyber rules after Salt Typhoon hacks The Record
- New Carbonato malware uses AI agents to hijack exposed Docker hosts BleepingComputer
- Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing The Register
- Rydox cybercriminal marketplace operator pleads guilty following co-conspirator brothers’s deportation The Record
- ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories The Hacker News
- Exposed GitLab project email addresses let attackers push code BleepingComputer
Share this issue
Facebook · X · Reddit · LinkedIn · WhatsApp · Email · Bluesky
Every briefing is on the site, with the advisory record behind it. All briefings