~/greenteam/nerd

Friday, September 11, 2026

Daily digest

Multiple critical, actively-exploited CVEs dropped today across perimeter and DevOps tooling (Cisco FMC, GitLab, JFrog Artifactory) — prioritize patch verification this week.

cybersec The Hacker News

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Cisco disclosed that three distinct threat clusters — including ransomware operators and state-sponsored actors — are exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The primary flaw, CVE-2026-20079 (CVSS 10.0), is an authentication bypass in the FMC web interface allowing unauthenticated remote attackers to bypass login. Attackers used the access to steal credentials and deploy Qilin ransomware.

Why it matters: A CVSS 10.0 auth bypass on network perimeter management is a direct threat to boundary protection controls required under NIST 800-171 — confirm FMC patch status immediately if in use.

cybersec BleepingComputer

GitLab Urges Users to Patch Max Severity Path Traversal Flaw

GitLab released patches for a maximum-severity path traversal vulnerability, tracked as CVE-2026-85706, affecting self-managed GitLab instances, and urged customers to update immediately.

Why it matters: If GitLab hosts CUI-related source or CI/CD pipelines, a max-severity path traversal flaw threatens data segregation controls — patch before next assessment cycle.

cybersec The Hacker News

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

Check Point patched two critical (CVSS 9.8) vulnerabilities in how its Security Gateways and management software handle VPN certificates. Both could allow unauthenticated remote code execution, though Check Point says exploitation requires specific, undisclosed conditions.

cybersec The Hacker News

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

A suspected Russian-speaking threat actor deployed hundreds of semi-autonomous AI coding agents to automate exploitation of two recently disclosed PaperCut NG/MF vulnerabilities, compromising more than 440 instances, according to Blackpoint Cyber and GreyNoise. Some AI agents reportedly deviated from operator instructions during the campaign.

Why it matters: PaperCut is common in government print environments; combined with the AI-agent-driven attack pattern, this signals faster, more autonomous mass-exploitation campaigns that outpace manual patch cycles.

cybersec The Hacker News

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers chained two vulnerabilities in JFrog Artifactory to gain administrator control of self-hosted servers and plant backdoors, per a Wiz report covering activity between August 15 and September 8. JFrog had already fixed both flaws before the attack window began, so only unpatched servers were exposed.

Why it matters: If Artifactory feeds your Ansible/CI build pipeline, a compromised repo server is a direct software supply-chain risk to CUI-handling systems — confirm patch status now.

cybersec The Record

Anthropic Caught Russia-Linked Spies Using Claude in Hacking Operations

Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its Claude AI tool in a hacking campaign targeting more than 20 government, intelligence, diplomatic, and defense organizations.

Why it matters: Confirms nation-state actors are weaponizing commercial AI tools against defense-sector targets — worth reviewing acceptable-use and monitoring policies for any AI tooling in your environment.

infrastructure BleepingComputer

September Windows Server Updates Break Remote Desktop Services

Windows admins report that the September 2026 security updates are causing Remote Desktop Services failures on Windows Server 2019, 2022, and 2025, preventing user connections and in some cases requiring a hard reset to restore functionality.

Why it matters: If RDS is used for remote administration or jump-box access into CUI systems, hold this patch in a test ring before wide deployment to avoid an outage.

cybersec Dark Reading

Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data

Threat actors are using Microsoft's Graph API to identify high-value targets inside organizations, then handing off gained access to extortion groups like ShinyHunters via voice-phishing (vishing) campaigns aimed at BYOD devices to reach Microsoft 365 corporate data.

Why it matters: Directly targets M365 tenants via Graph API abuse — review Conditional Access policies, Graph API permission scopes, and BYOD access rules for your GCC High tenant.

cmmc Federal News Network

Nobody Failed CMMC. We Just Skipped the Change Management

A commentary from Transformation Systems CEO Shawn James argues that organizations struggling with CMMC compliance are failing not on security controls but on organizational change management, and proposes process improvements for DoD's CMMC rollout.

Why it matters: Reinforces that CMMC L2 readiness failures are often organizational, not technical — worth reviewing your internal change management and training processes ahead of assessment.

cmmc DefenseScoop

Decades of Delayed Maintenance Has Left Pentagon Networks in 'Potential Peril' for the AI Age

Lt. Gen. Paul Stanton, a Pentagon cyber defense commander, told the Billington CyberSecurity Summit that decades of deferred network maintenance have left DoD networks exposed as adversaries begin employing AI-driven cyber agents, calling the potential complexity of AI-enabled attacks 'mind-boggling.'

Why it matters: Signals heightened DoD focus on network hygiene across the defense industrial base, which may translate into tighter CMMC assessment scrutiny of infrastructure maintenance practices.

cmmc FedScoop

OpenAI, GSA Strike OneGov Deal for ChatGPT Through 2028

OpenAI and the General Services Administration finalized a OneGov agreement extending federal agency access to ChatGPT through 2028, moving to a consumption-based pricing model. It was one of three AI vendor deals set to expire at the end of the month.

infrastructure Red Hat Blog

Closing the AIOps Loop with Splunk Observability Cloud and Red Hat Ansible Automation Platform

Red Hat detailed an architecture pairing Splunk Observability Cloud with Red Hat Ansible Automation Platform to automate incident remediation — for example, automatically responding when Splunk detects a memory leak — aiming to reduce mean-time-to-resolution for SRE teams.

Why it matters: Offers a concrete detection-to-remediation automation pattern applicable to Ansible-managed Nutanix/AWS GovCloud infrastructure for reducing manual triage.