ITsecurity Daily
Daily Briefing
CISA flags four actively exploited flaws — in Check Point, Arista, and F5 gear — as WordPress and Chrome ship urgent fixes
Good morning. CISA added four vulnerabilities to its Known Exploited Vulnerabilities Catalog, citing evidence of active exploitation. Per CISA, the four affect Check Point (an improper certificate validation flaw and a path traversal flaw across multiple products), Arista VeloCloud Orchestrator (improper input validation), and F5 BIG-IP APM. If you run any of these, prioritise them.
The Check Point entries connect to a separate disclosure. The Hacker News reported that Check Point warned attackers exploited a previously unknown flaw in its Security Management Server in a handful of targeted attacks on July 23. The Hacker News says the flaw lets an attacker who can access the server's web service run scripts on it without logging in, and that Check Point released a fix on September 2.
WordPress patched a critical core flaw. The Hacker News reported that the flaw lets an attacker with no account make a site load a PHP file from outside its theme folders, and on some servers run their own code; the fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch.
Zoom out: Three of the day's items — Check Point's management-server flaw, a campaign against ZyXEL switches, and a PeopleSoft breach claim — turn internet-facing infrastructure against the organisations that run it.
Vulnerability in focus
CVE-2026-93374 — Google. CVSS 9.6
Affected: chrome.
What to do: Follow the vendor advisory for the fixed release and any interim mitigation.
Elsewhere
- SecurityWeek: Check Point Patches Exploited Management Server Zero-Day Read it
- Help Net Security: Prismor: Open-source runtime control plane for AI agents Read it
- Help Net Security: Product showcase: Scamwise checks the red flags before you take the bait Read it
- Help Net Security: Nearly two-thirds of tested websites fail every bot test Read it
- Help Net Security: NetBSD 10.2 security fixes close a remote kernel bug in ipfilter Read it
- BleepingComputer: Rogue external MFA providers can steal passwords during logins Read it
- BleepingComputer: Chinese hackers exploit multiple technologies to steal govt data Read it
- CISA: CISA Adds Four Known Exploited Vulnerabilities to Catalog Read it
- The Record: Canadian regulator opens probe of IDScan for allegedly violating data privacy laws Read it
- The Hacker News: Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials Read it
- The Hacker News: WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers Read it
- The Hacker News: Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks Read it
Sources
- Rogue external MFA providers can steal passwords during logins BleepingComputer
- Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions The Register
- Canadian regulator opens probe of IDScan for allegedly violating data privacy laws The Record
- Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks The Hacker News
- BigCommerce Data Stolen via Ribon Apps Hack SecurityWeek
- Researchers uncover malware that uses AI to choose its next move Help Net Security
- CISA Adds Four Known Exploited Vulnerabilities to Catalog CISA
- GPT-6 Astra Breaks an Old Enigma Message Schneier on Security
- Sweden fines Miljödata $183,000 over breach affecting 2.2 million BleepingComputer
- Chinese hackers exploit multiple technologies to steal govt data BleepingComputer
- ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach BleepingComputer
- New ClosedQuorum Windows malware uses AI for attack decisions BleepingComputer
- WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers The Hacker News
- Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials The Hacker News
Share this issue
Facebook · X · Reddit · LinkedIn · WhatsApp · Email · Bluesky
Every briefing is on the site, with the advisory record behind it. All briefings