Canadian Cyber Security Journal
SOCIAL:
Filed under: News

Cybersecurity Daily Brief — Wednesday, September 30, 2026

Here are today’s top cybersecurity stories for Wednesday, September 30, 2026.

Cisco Warns of Catalyst SD-WAN Manager Zero-Day Under Active Attack
Cisco disclosed CVE-2026-76504, an authentication bypass in Catalyst SD-WAN Manager, formerly vManage. Improper handling of URI encoding in an HTTP request lets an unauthenticated remote attacker gain administrator access through the API. Cisco confirmed active exploitation and released fixed builds for each supported release train. BleepingComputer

Researchers Find 543,000 Valid Credentials in Public GitHub Repositories
Truffle Security found 543,699 unique valid credentials across 224 million repositories in a dataset built for training large language models. The median exposure time was 784 days, and 36.8 percent of the credentials appeared after GitHub enabled default push protection in February 2024. Google Cloud service account keys made up the largest group of valid entries at 69,041. BleepingComputer

CISA Warns of Pre-Authentication Remote Code Execution Flaw in MikroTik RouterOS
CISA flagged CVE-2026-84411, an integer underflow in HTTP request body handling in the RouterOS web management service. A single request lets an unauthenticated attacker run code as root or crash the device. Fixed releases 7.24.4 and 7.23.7 have been available since September 16, and CISA says it has no knowledge of active exploitation. BleepingComputer

Bitget Says Zero-Days in Third-Party Security Products Led to $387.5 Million Theft
Bitget now puts its loss at $387.5 million and says attackers used zero-day flaws in two third-party security products. They placed web shells on a compromised appliance, moved to production wallet servers, and pushed out fraudulent transfers over nearly three hours on September 25. CEO Gracy Chen attributes the attack to North Korean hackers, and SlowMist and Mandiant are investigating. BleepingComputer

TeamViewer Urges Customers to Patch Five Vulnerabilities
TeamViewer released version 15.82 to fix five flaws, led by CVE-2026-92370, an access control weakness in remote sessions in the Full Client and Host on Windows, Linux, and macOS. Other fixes cover a heap-based buffer overflow, a path traversal, a race condition, and a path validation error allowing local escalation to SYSTEM or root. TeamViewer is not aware of public disclosure or exploitation in the wild. BleepingComputer

Microsoft Will Block Script Injection on Entra ID Sign-In Pages Starting October
Microsoft will enforce a Content Security Policy on Entra ID browser sign-ins, allowing only scripts from Microsoft-hosted CDN domains. Rollout begins in mid-October and finishes in late October. Browser extensions and tools injecting code into login.microsoftonline.com stop working, while MSAL and API-based flows are unaffected. BleepingComputer

AI Coding Agents Exposed 13,000 Internal Images on GitHub
Security firm Glow found more than 13,000 internal images from over 300 organizations in public GitHub repositories created by AI coding agents. Agents asked to show visual code changes used an open-source tool called gitshot, which posts images to a public repository under a developer’s personal account. The images included customer billing records, internal dashboards, unreleased features, and treasury console screens. The Hacker News

CSuite Phishing Campaign Steals Microsoft 365 Sessions and Installs Remote Management Tools
ANY.RUN analyzed 351 sandbox submissions from a campaign targeting executives with lures posing as Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365. Attackers steal Microsoft 365 sessions through credential harvesting and device-code phishing, then use BAT and VBS droppers to install ScreenConnect and Action1. Half of the submissions came from the United States, and activity also appeared in Canada, the UK, Australia, and the Philippines. The Hacker News

Russia’s Star Blizzard Targets More Than 100 Organizations With Fake Event Invitations
Microsoft reports the FSB-linked group has targeted more than 100 organizations since January 2026, using invitations posing as Chatham House and Atlantic Council events. The campaigns deliver the Python backdoor CosmicPulse and, in one March variant, the DarkSword iPhone exploit kit. Most affected organizations are in the United States and the United Kingdom, including government bodies, NGOs, and think tanks tied to Ukraine. The Hacker News

OpenSSL and wolfSSL Patch High-Severity Vulnerabilities
OpenSSL fixed 14 vulnerabilities, including CVE-2026-84782 (CVSS 8.2), which lets a remote peer obtain heap memory fragments or crash DTLS applications. wolfSSL 5.9.4, released September 25, fixes three high-severity certificate validation flaws tracked as CVE-2026-93302, CVE-2026-89102, and CVE-2026-89136. SecurityWeek

South Africa Seeks Help After Cyberattack on Air Traffic Control
Air Traffic and Navigation Services found malware associated with early-stage ransomware attacks on an operational technology network supporting weather services. Evidence points to data exfiltration to IP addresses in China. The company requested quotes from cyber-forensics firms by September 18, and affected sites include Port Elizabeth airport, with East London and Maputo also under review. Dark Reading

Stay tuned for today’s in-depth analysis posts.

Enjoy this article? Don’t forget to share.