CISA added four actively exploited vulnerabilities to its KEV catalog, Cisco confirmed exploitation of a Secure Firewall Management Center flaw, and a healthcare provider confirmed a breach affecting 4.1 million people, while researchers detailed an exploit kit shared by four espionage groups.
🔴 CRITICAL (3)
CISA adds Citrix NetScaler authentication bypass CVE-2026-19490 to KEV after active exploitation Confirmed
CISA added CVE-2026-19490 to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. The flaw is an unauthenticated authentication bypass rated CVSS 9.3 in Citrix NetScaler ADC and NetScaler Gateway, edge appliances widely used for remote access. CISA sets a September 12 remediation deadline for federal agencies and urges all operators to apply Citrix fixes or mitigations and check for unauthorized access.
CISA adds Fortinet heap-based buffer overflow CVE-2025-25249 to KEV after active exploitation Confirmed
CISA added CVE-2025-25249, a heap-based buffer overflow affecting Fortinet products including FortiOS, to its Known Exploited Vulnerabilities catalog based on evidence of active exploitation. The memory-corruption flaw can be exploited to compromise vulnerable Fortinet devices, which often sit at network perimeters. Operators should apply Fortinet fixes or mitigations before the September 12 remediation deadline and review appliances for signs of intrusion.
Sources CISA
Cisco confirms CVE-2026-20079 Secure Firewall Management Center flaw exploited; CISA adds to KEV Confirmed
Cisco confirmed that CVE-2026-20079, a maximum-severity authentication bypass in Secure Firewall Management Center (FMC) and related firewall management products, is being actively exploited in attacks. CISA added the vulnerability to its Known Exploited Vulnerabilities catalog with a September 12 remediation deadline, following Cisco Talos reporting of active intrusions against FMC deployments. Organizations running FMC should apply Cisco fixes or mitigations and hunt for signs of compromise on the management plane.
Sources BleepingComputer|CISA
🟠 HIGH (2)
AdaptHealth confirms data of 4.1 million people exposed in July ShinyHunters cyberattack Confirmed
US medical equipment provider AdaptHealth confirmed that a July 2026 cyberattack attributed to the ShinyHunters group exposed data of about 4.1 million people. The intrusion began with social engineering that compromised a privileged account in cloud business applications holding names, addresses, dates of birth, medical information and health insurance data. Affected individuals should stay alert to phishing, and organizations should treat privileged cloud accounts as a primary social-engineering target.
Sources BleepingComputer
Researchers track BlueMoon exploit kit used by four espionage groups within a week Confirmed
Proofpoint documented BlueMoon, a previously undocumented exploit kit that chains Google Chrome and Microsoft Windows vulnerabilities and was deployed by at least four espionage-motivated clusters, including the China-aligned group APT31, within roughly one week. Rapid shared use of a single kit suggests the groups obtained it from a common supplier or broker. Defenders should keep Chrome and Windows patched and watch endpoints for exploit-kit activity.
Sources The Hacker News|Proofpoint
🟡 MEDIUM (1)
Trezor warns of phishing after breach at its email service provider Confirmed
Hardware wallet maker Trezor said attackers breached its email service provider and used the channel to send a fake security alert claiming a hardware flaw could expose users’ recovery phrases. Such messages are phishing attempts to steal seed phrases, which legitimate companies never ask for. Trezor users should delete unsolicited security-alert emails and visit the official site only by typing the address directly.
Sources Decrypt
⚪ WATCH (3)
CERT/CC warns Skullcandy Dime 3 earbuds accept unwanted Bluetooth pairings Confirmed
CERT/CC warned that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without user interaction, so an attacker in range can hijack the connection and access headset features including the microphone. The issue stems from unauthenticated pairing behavior in the Airoha Bluetooth audio SDK. No in-the-wild exploitation has been reported; users should install any firmware update and disable Bluetooth when the earbuds are not in use.
Sources BleepingComputer|CERT/CC
Microsoft publishes Cloud Web Applications Threat Matrix for cloud app defenders Confirmed
Microsoft released the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework mapping attacker techniques against cloud-hosted web applications and serverless platforms. It is designed to help security teams understand and prioritize threats across identity, application and infrastructure layers. Teams securing cloud applications can use it as a detection and hardening reference.
Sources Microsoft Security Blog
Malone Lam pleads guilty as ringleader of $245 million crypto theft scheme Confirmed
Malone Lam, a 22-year-old tied to Miami and Singapore, pleaded guilty to leading a ring that stole about $245 million in cryptocurrency, including 4,100 bitcoin, from victims through online scams and home invasions. The plea closes a case that underscored how crypto theft can combine digital fraud with physical threats. Crypto holders should treat information about large holdings as sensitive.
Sources CoinDesk
Methodology: compiled from vendor advisories, government feeds (CISA KEV, MSRC), security news sources and on-chain/security-firm alerts. Grouping: one incident, one entry, with every source cited. Unconfirmed reports are labeled. Crypto items are incident reporting, not investment advice. Corrections from prior digests are noted at the top when applicable.