~/greenteam/nerd

Friday, September 4, 2026

Daily digest

Heavy vulnerability day across the stack: an actively-exploited Chrome zero-day, critical unauthenticated RCE flaws in Cisco Nexus/IOS XR, and a critical HPE ArubaOS-CX RCE all landed within 24 hours — prioritize patching for network infrastructure and browsers.

cybersec BleepingComputer

Google Patches Actively Exploited Chrome V8 Zero-Day

Google released Chrome updates addressing 12 vulnerabilities, including CVE-2026-85046, a high-severity type confusion bug in the V8 JavaScript engine that is under active exploitation. The fix is included in Chrome 152.0.7977.82 and later.

Why it matters: Chrome is the default browser across most GCC High and Intune-managed fleets; push this update via Intune/browser management immediately given confirmed in-the-wild exploitation.

cybersec The Hacker News

Critical Cisco Nexus 9000 and IOS XR Flaws Allow Root-Level Remote Code Execution

Cisco patched a critical flaw (CVE-2026-20212, CVSS 9.8) in Silicon One-based Nexus 9000 switches that lets unauthenticated attackers execute code as root, alongside an IOS XR hardening release bundling seven CVEs, two rated 9.8, with no workaround available for any IOS XR version.

Why it matters: If Nexus 9000 or IOS XR devices sit in the network path, these are unauthenticated root-level compromises with no IOS XR workaround — treat as emergency patching, not routine maintenance.

cybersec BleepingComputer

HPE Patches Critical ArubaOS-CX Remote Code Execution Flaw

Hewlett Packard Enterprise released patches for a critical remote code execution vulnerability in the ArubaOS-CX network operating system used on its switching platforms.

Why it matters: Aruba switching gear is common in CMMC-scoped networks; confirm firmware inventory and schedule patching to maintain 800-171 configuration management requirements.

cybersec The Hacker News

Shai-Hulud npm Worm Now Scans 469 Credential Locations

GitGuardian researchers found the Shai-Hulud infostealer worm has expanded from scanning 189 to 469 credential storage locations across developer environments, CI/CD tooling, cloud configs, and AI tool configurations. The worm continues to spread through compromised npm packages.

Why it matters: This worm actively targets cloud and CI/CD credentials — audit any npm dependencies in Ansible tooling, self-hosted AI stack pipelines, or automation scripts for exposure, and rotate any secrets stored in scanned locations.

cybersec BleepingComputer

Coder's Registry Infrastructure Compromised to Push Malicious Terraform Modules

Attackers compromised Coder's Cloudflare infrastructure and injected unauthorized registry servers that served malicious Terraform modules containing credential-stealing code.

Why it matters: If Terraform is used for AWS GovCloud or Nutanix provisioning, verify module sources and pin to trusted registries/hashes — this is a direct IaC supply-chain compromise vector.

cybersec The Hacker News

Thomson Reuters' Court Software Breach Exposed SSNs and Sealed Records

Thomson Reuters disclosed that an unauthorized party accessed files from C-Track, its West Publishing court case management platform, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario. Discovered June 30, 2026, the breach may have exposed names, SSNs, and sealed court records.

cybersec Microsoft Security Blog

ASCII Smuggling Technique Moves From AI Prompt Injection to Phishing Evasion

Microsoft reported that invisible Unicode characters originally used to hide instructions from AI models are now being used by attackers to obfuscate phishing content and evade email filters.

Why it matters: This technique can bypass Exchange Online/Defender for Office 365 filtering in GCC High tenants; confirm mail flow rules and Defender detections account for hidden Unicode obfuscation.

infrastructure BleepingComputer

Exchange Online Outage Delays External Email

Microsoft is working to resolve an ongoing Exchange Online outage causing delays and 'Server busy' errors for email sent to and received from external domains.

Why it matters: GCC High tenants share underlying Exchange Online infrastructure patterns; monitor Microsoft 365 Service Health for GCC High-specific advisories and set user expectations for delayed external mail.

infrastructure AWS Security Blog

AWS Publishes Part 2 of CloudTrail Incident Response Guide

AWS released the second installment of its incident response guide for analyzing CloudTrail logs, building on Part 1's coverage of S3 ransomware-style deletion and CloudFormation-based cryptomining scenarios with additional real-world investigative techniques.

Why it matters: Directly applicable to AWS GovCloud incident response playbooks and 800-171 audit log review procedures — worth incorporating into IR runbooks.

cmmc DefenseScoop

Pentagon Pursues Fleet of Portable SCIFs for Contractors

The Department of Defense launched an initiative, dubbed the 'Secure Space Network,' to develop mobile/portable Sensitive Compartmented Information Facilities (SCIFs) that could let more nontraditional contractors collaborate with government teams and compete for classified work.

Why it matters: Could lower the barrier for smaller CMMC L2/L3-aspiring contractors to access classified-adjacent work; watch for procurement details if pursuing higher-level DoD contracts.

cmmc FedScoop

GAO Finds DOGE/DHS IT Contract Cuts Didn't Save Money

A Government Accountability Office audit found that IT contract terminations made by DOGE and DHS to cut costs did not achieve the intended savings, part of a broader forthcoming series of reports examining last year's cost-cutting efforts.

cmmc NextGov

Former CISA Employee Pleads Guilty to Secretly Holding Contractor Jobs

Richeline Fung, a former CISA employee, pleaded guilty to defrauding the government by secretly holding contractor jobs tied to six agencies while working full-time at CISA, at times claiming up to 33-hour workdays.