CyberNews: 04/09/2026 Edition

Published by Dunateo on 2026-09-04

Today’s roundup

  • Critical Zero-Day in Adobe ColdFusion Under Active Exploitation (CVE-2023-26369)
  • Russian Hackers Exploit Microsoft Outlook Flaw to Access Government Accounts
  • Cl0p Ransomware Group Exploits Zero-Day in PaperCut MF/NG Printing Software
  • Critical Vulnerability in Zyxel Firewalls and APs Under Active Attack (CVE-2023-28771)
  • Google Patches Actively Exploited Zero-Day in Chrome (CVE-2023-2033)
  • Cyberattack on ION Trading Systems Disrupts Derivatives Markets
  • Atlassian Confluence Server & Data Center Critical Vulnerability (CVE-2023-22501)
  • New Phishing Campaign Impersonates Microsoft 365 Login Pages to Steal Credentials
  • CISA Warns of Exploited Vulnerability in VMware vCenter Server (CVE-2023-34039)
  • Critical RCE Vulnerability Found in Zoho ManageEngine ServiceDesk Plus (CVE-2023-47120)
  • Summary

    Adobe ColdFusion is facing active zero-day exploitation through CVE-2023-26369, a critical deserialization vulnerability that allows remote code execution. Administrators are urged to apply vendor patches immediately to mitigate the threat.

    Russian state-sponsored hackers (APT28, Fancy Bear) are exploiting CVE-2023-23397, an elevation of privilege flaw in Microsoft Outlook. The campaign targets government entities by stealing NTLM v2 hashes via malicious calendar invites, enabling token theft and access to accounts.

    The Cl0p ransomware group is actively exploiting a zero-day vulnerability (CVE-2023-27350) in PaperCut MF and NG print management software. This authentication bypass flaw can lead to unauthenticated remote code execution, posing a significant risk to organizations using these systems.

    Zyxel firewalls and access points are under active attack exploiting CVE-2023-28771, an unauthenticated command injection vulnerability. Successful exploitation grants attackers the ability to execute arbitrary commands, potentially compromising network infrastructure.

    Google has released an emergency patch for an actively exploited zero-day vulnerability (CVE-2023-2033) in its Chrome browser. The flaw is a type confusion bug in the V8 JavaScript engine, which could lead to arbitrary code execution.

    ION Trading UK, a critical financial software provider, was hit by a LockBit ransomware attack in January 2023. The incident severely disrupted derivative markets, affecting clients globally and forcing manual processing for several days.

    A critical remote code execution vulnerability (CVE-2023-22501) has been discovered in Atlassian Confluence Server and Data Center. This unauthenticated flaw allows attackers to execute arbitrary code without credentials, requiring immediate patching.

    A new sophisticated phishing campaign is impersonating Microsoft 365 login pages to steal credentials. These attacks are designed to bypass multi-factor authentication, posing a significant threat to enterprise security.

    CISA has issued a warning regarding the active exploitation of CVE-2023-34039 in VMware vCenter Server. This vulnerability allows for arbitrary file upload, leading to remote code execution and potential full compromise of virtualized environments.

    A critical unauthenticated remote code execution vulnerability (CVE-2023-47120) has been identified in Zoho ManageEngine ServiceDesk Plus. This flaw enables attackers to execute arbitrary code, necessitating urgent patching for affected installations.

    Want to dig deeper?

    Vulnerabilities

    CVE-2023-26369 High
    CVE-2023-28771 Critical
    CVE-2023-2033 High
    CVE-2023-22501 Critical
    CVE-2023-34039 Critical
    CVE-2023-47120 Medium
    CVE-2023-23397 High
    CVE-2023-27350 Critical

    Cyber Groups

    APT28 IRON TWILIGHT, SNAKEMACKEREL, Swallowtail, Group 74, Sednit, Sofacy, Pawn Storm, Fancy Bear, STRONTIUM, Tsar Team, Threat Group-4127, TG-4127, Forest Blizzard, FROZENLAKE, GruesomeLarch