~/greenteam/nerd

Tuesday, September 22, 2026

Daily digest

Heavy patch-and-exploit day: a mislabeled SharePoint RCE, an actively-exploited Zyxel switch flaw now on CISA's KEV list, and a fresh Windows Defender zero-day all warrant prompt attention alongside routine M365 admin housekeeping.

cybersec The Hacker News

SharePoint Flaw Initially Listed as Spoofing Actually Enables Authenticated RCE

Microsoft originally rated CVE-2026-65660 as a 6.5 spoofing flaw, but full technical details published by a Viettel Cyber Security researcher show it enables authenticated remote code execution. The vulnerability affects SharePoint Server 2016, 2019, and Subscription Edition; patches are already available.

Why it matters: If you run on-prem SharePoint alongside GCC High, verify this patch was applied — the original low severity rating may have caused it to be deprioritized in patch cycles.

cybersec The Hacker News

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

CVE-2026-89775 is a flaw in the Linux kernel's KVM virtualization code for ARM64 processors that exposes freed host memory to guest VMs on hosts with nested virtualization enabled. The researcher who found it says the bug can be used to escape the guest and execute code on the host machine.

cybersec The Hacker News

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

CISA added CVE-2026-7273, a stack-based buffer overflow in Zyxel GS1900 series switches (CVSS 8.8), to its Known Exploited Vulnerabilities catalog citing active exploitation. A separate Veeam flaw enabling SYSTEM-level access is also being actively exploited in the wild.

Why it matters: Federal agencies must remediate the Zyxel flaw by CISA's deadline; check any Zyxel switches in your network and confirm Veeam backup infrastructure is patched given its role in ransomware kill chains.

cmmc BleepingComputer

CISA Orders Feds to Patch Zyxel Flaw Exploited for Data Theft by Thursday

CISA issued a binding directive requiring federal agencies to patch the actively exploited Zyxel GS1900 switch vulnerability by Thursday, following confirmed evidence of exploitation for data theft.

Why it matters: This is a Binding Operational Directive deadline — contractors supporting federal networks should confirm compliance status and document remediation for NIST 800-171 audit evidence.

cybersec BleepingComputer

New Windows Defender Zero-Day Blocks Microsoft Antivirus Updates

Security researcher Abdelhamid Naceri released a new Microsoft Defender zero-day exploit over the weekend that blocks antivirus signature updates. This is a follow-up disclosure from the same researcher who has previously released multiple Defender bypass exploits.

Why it matters: This directly affects Intune-managed Windows 11 endpoints relying on Defender as primary AV — monitor for Microsoft's patch and consider compensating EDR alerting in the interim.

cybersec The Hacker News

Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR

A fake LastPass Authenticator installer distributed via GitHub installs a Windows kernel driver — signed through Microsoft's hardware-compatibility program — that disables antivirus and security software before deploying a password stealer. The driver scored zero detections on VirusTotal when researchers tested it.

Why it matters: A legitimately Microsoft-signed EDR-killer driver undermines trust in code-signing as a control; review application allowlisting and driver-blocklist policies (WDAC) on managed endpoints.

cybersec Dark Reading

ShinyHunters Hacked Clop. Now What About Clop's Victims?

The ShinyHunters extortion group defaced Clop ransomware's dark web leak site and claims to have stolen victim data. ShinyHunters is now demanding eight-figure extortion payments and threatening to expose organizations that previously paid Clop ransoms to keep breaches quiet.

cybersec The Hacker News

Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto

North Korean threat actors behind the Contagious Interview campaign have compromised over 30,000 devices across 100+ countries, according to a joint cybersecurity advisory, siphoning credentials and funds from more than 7,000 cryptocurrency wallets. Targets are primarily web designers, engineers, and crypto specialists lured through fake job interviews.

cmmc FedScoop

30,000-Plus Veterans Affected by Baylor Genetics Cybersecurity Breach

A mid-June breach at Baylor Genetics exposed names, dates of birth, medical testing information, lab results, health insurance data, and partial Social Security numbers for over 30,000 veterans, according to a VA notification email.

Why it matters: Illustrates third-party/subcontractor breach risk for organizations handling CUI or PII on behalf of federal agencies — a reminder to validate FCI/CUI flow-down and vendor risk assessments in your supply chain.

cmmc FedScoop

Inside the Bipartisan Backlash to the $27 Billion VA-Oracle EHRM Contract

Congress is expressing bipartisan frustration over the VA's fourth attempt at electronic health records modernization with Oracle, a contract that has spanned three administrations, billions of dollars, and dozens of hearings without resolution.

infrastructure The Register

Gartner Predicts 55% of Enterprise VMware Users Will Investigate an Exit by 2029

Gartner projects that more than half of enterprise VMware customers will be actively evaluating alternatives by 2029, citing licensing complexity and cost concerns following Broadcom's acquisition. Analysts note that migration alternatives also carry maturity and complexity challenges.

Why it matters: Reinforces the strategic case for continued Nutanix AHV investment as VMware licensing pressure pushes more organizations toward alternative hypervisor platforms.

infrastructure BleepingComputer

Microsoft to Retire Microsoft 365 Companion Apps in December

Microsoft will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16 and has instructed admins to remove them from managed devices ahead of the deadline.

Why it matters: Add removal of these companion apps to Intune application management policies before the December 16 retirement to avoid broken app experiences on managed Windows 11 devices.