CyberNews: 13/09/2026 Edition

Published by Dunateo on 2026-09-13

Today’s roundup

  • Fortinet Warns of New RCE Flaw in FortiNAC, Actively Exploited in the Wild
  • Over 100,000 Fortinet Devices Still Unpatched for Critical Flaw
  • Critical Vulnerability in SolarWinds Access Rights Manager (CVE-2023-33297) Allows RCE
  • New BlackCat (ALPHV) Ransomware Variant Targets VMware ESXi Servers
  • Cloudflare Suffers Major Outage Affecting Websites Globally
  • MOVEit Transfer Zero-Day Exploitation Leads to Mass Data Breaches
  • FIN7 Group Suspected in New Wave of Point-of-Sale (POS) Malware Attacks
  • Microsoft Patch Tuesday Addresses 98 Vulnerabilities, Including 6 Zero-Days
  • New Phishing Campaign Impersonates Microsoft 365 to Steal Credentials
  • Researchers Uncover Stealthy Backdoor in Open-Source Libraries
  • Summary

    Fortinet issued an urgent alert for a critical RCE vulnerability (CVE-2023-33299, CVSS 9.6) in its FortiNAC solution. Actively exploited, this flaw allows unauthenticated attackers root access. Immediate patching is urged.

    Over 100,000 Fortinet FortiGate and FortiProxy devices remain unpatched for the critical authentication bypass (CVE-2022-40684), disclosed and actively exploited last year. This ongoing vulnerability continues to expose organizations to compromise.

    SolarWinds disclosed a critical RCE vulnerability (CVE-2023-33297, CVSS 9.8) in its Access Rights Manager (ARM). Unauthenticated attackers can execute arbitrary code with elevated privileges. Users must update to 2023.2 HF1 or 2023.4.

    A new Linux-based BlackCat (ALPHV) ransomware variant has been identified, specifically designed to encrypt virtual machines on VMware ESXi servers, enhancing its capability against critical infrastructure. Organizations are advised to strengthen backups and network segmentation.

    Cloudflare experienced a widespread global outage, impacting numerous websites for several hours due to a data center configuration error, not a cyberattack. The incident highlighted significant reliance on major internet infrastructure providers.

    A zero-day vulnerability (CVE-2023-34362) in MOVEit Transfer is actively exploited by the Clop ransomware group, causing widespread data breaches. CISA added this critical SQL injection to its Known Exploited Vulnerabilities Catalog, mandating urgent patching for federal agencies.

    The FIN7 cybercrime group is suspected of new point-of-sale (POS) malware attacks across retail and hospitality. New custom malware and TTPs, primarily via phishing and supply chain attacks, aim to steal credit card data.

    Microsoft's latest Patch Tuesday addressed 98 vulnerabilities, including six actively exploited zero-days. Critical flaws in Windows MSMQ, SharePoint, and Kernel, with RCE and privilege escalation, require immediate patching.

    A sophisticated phishing campaign impersonates Microsoft 365 login pages to steal user credentials. It uses convincing spoofed emails, bypasses filters, and leverages compromised accounts. MFA enforcement and employee training are advised.

    Researchers uncovered a stealthy backdoor embedded in popular open-source libraries, enabling unauthorized access and command execution on systems. This supply chain attack underscores third-party code risks, urging dependency audits and updates.

    Want to dig deeper?

    Vulnerabilities

    CVE-2023-33297 High
    CVE-2023-33299 Critical
    CVE-2022-40684 Critical
    CVE-2023-34362 Critical

    Cyber Groups

    FIN7 GOLD NIAGARA, ITG14, Carbon Spider, ELBRUS, Sangria Tempest

    Malware Families

    Global GLOBAL GROUP