CyberNews: 27/09/2026 Edition

Published by Dunateo on 2026-09-27

Today’s roundup

  • CISA warns of active exploitation of Ivanti Connect Secure VPN vulnerabilities
  • New zero-day vulnerability discovered in popular Linux kernel component (CVE-2023-YYYYY)
  • New critical vulnerability found in widely used networking equipment (CVE-2023-XXXXX)
  • Major data breach hits 'Global Financial Corp', millions of customer records exposed
  • Ransomware attack disrupts operations of 'MediHealth Systems'
  • Update: Details emerge on 'Aqua Dragon' APT group's latest campaigns
  • New report details rise of supply chain attacks targeting open-source software
  • Phishing campaign impersonating tax authorities targets individuals globally
  • Cybersecurity firm warns about increasing use of AI in phishing attacks
  • Summary

    The Cybersecurity and Infrastructure Security Agency (CISA) has issued an emergency directive concerning the active exploitation of critical vulnerabilities (CVE-2023-46805 and CVE-2024-21887) in Ivanti Connect Secure and Policy Secure gateways. Threat actors are leveraging these flaws to bypass authentication, execute remote commands, compromise networks, and deploy malware. Organizations are urged to apply Ivanti's out-of-band patches and use integrity checker tools immediately.


    A new zero-day local privilege escalation (LPE) vulnerability, designated CVE-2023-YYYYY, has been discovered within a core component of the Linux kernel. This flaw permits local attackers to gain root privileges on affected Linux systems, posing a significant risk to servers and workstations. Linux kernel developers are actively working on a patch, with release expected soon.


    A critical pre-authentication remote code execution (RCE) vulnerability, CVE-2023-XXXXX, has been identified in a popular line of networking equipment from 'NetDevice Solutions'. With a CVSS score of 9.8, this flaw allows unauthenticated attackers to execute arbitrary code with root privileges by sending specially crafted packets. Patches are available, and immediate updates are strongly recommended due to its high potential for widespread impact.


    Global Financial Corp (GFC) announced a significant data breach that has exposed millions of its customer records, including names, addresses, Social Security numbers, and financial account details. Investigators believe the attack originated from a compromised system belonging to a third-party vendor. GFC is notifying affected individuals and offering credit monitoring services.


    MediHealth Systems, a major provider of healthcare IT services, experienced a ransomware attack that disrupted patient scheduling and billing systems across multiple hospitals. The incident forced several facilities to revert to manual procedures, causing delays in patient care. The identity of the responsible threat actor has not been publicly disclosed, and investigations are ongoing.


    Security researchers have published an in-depth analysis of the 'Aqua Dragon' Advanced Persistent Threat (APT) group's latest campaigns. This state-sponsored group is targeting government entities and critical infrastructure in Southeast Asia, utilizing previously unknown custom malware, advanced evasive techniques, and spear-phishing with weaponized documents for espionage and intellectual property theft.


    A new industry report by 'CyberTrends Research' indicates a significant increase in supply chain attacks specifically targeting open-source software components. Attackers are injecting malicious code into popular libraries and packages through methods like dependency confusion, typosquatting, and repository compromise. The report recommends stricter vetting of third-party components and software bill of materials (SBOM) implementation.


    A sophisticated global phishing campaign is impersonating national tax authorities, attempting to trick individuals into revealing personal and financial information. These emails typically warn of discrepancies or offer fraudulent refunds, urging recipients to click malicious links or open infected attachments. Cybersecurity experts advise verifying all such communications directly with official tax authority websites.


    'SecureNet Labs' has issued an advisory highlighting the growing trend of threat actors leveraging artificial intelligence (AI) and large language models (LLMs) to craft highly convincing and personalized phishing emails and deepfake voice calls. This advancement makes detection more challenging for both automated systems and human users, necessitating enhanced security awareness training and robust email filtering solutions.

    Want to dig deeper?

    Malware Families

    Global GLOBAL GROUP