Cisco Talos reports active exploitation of two vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software. The key takeaway for defenders: perimeter and management-plane flaws are still translating into real-world intrusion paths, not just theoretical risk. Organizations running affected FMC versions should prioritize detection for post-exploitation activity and accelerate patch/mitigation validation across environments.
Source: Cisco Talos
Microsoft Patch Tuesday Breaks Records: 2 Actively Exploited Zero-Days Among ~1,000 Fixes
Microsoft’s September 2026 Patch Tuesday delivered an exceptionally large update set—reported as 964 (and other counts in the ~970 range) fixes—plus two zero-days already under active exploitation. The operational lesson is urgency plus triage: teams must quickly separate “exploited now” fixes from the long tail, then confirm coverage (including on high-exposure systems like internet-facing servers and identity components). Patch velocity and validation matter as much as patching itself.
Source: Malwarebytes Blog
Chrome Zero-Day CVE-2026-87491 Patched After In-the-Wild Code Execution Indications
Google patched 230 Chrome vulnerabilities, including CVE-2026-87491, described as actively exploited in the wild. The vulnerability affects V8 (Chrome’s JavaScript/WebAssembly engine) via an out-of-bounds write bug, emphasizing how browser engines continue to be prime targets for reliable remote compromise. For enterprises, this is a reminder to treat browser updates as security-critical and to measure deployment lag, not just availability.
Source: Help Net Security
F5 BIG-IP APM Compromise Uses Memory-Resident Rootkit to Evade Disk-Based Detection
Reports describe attackers deploying a Linux rootkit on F5 BIG-IP APM devices that hides a web shell in memory instead of writing artifacts to disk. This directly targets a common defensive assumption: that evidence will appear on the filesystem for incident responders and file-based security tools to catch. Organizations using F5 APM should hunt for behavioral indicators (processes, abnormal module loads, unexpected outbound connections) and ensure mitigations include configurations that reduce APM exposure.
Source: Help Net Security
Stealthy New Phishing Technique Builds Pages Inside Victims’ Browsers via Blob URLs
Researchers report phishing campaigns that route users through legitimate Microsoft OAuth/Teams infrastructure, then generate a fake login experience entirely within the victim’s browser using blob URLs. This can reduce defender visibility because there’s no traditional externally hosted phishing page to block at the web gateway. The key defensive shift: strengthen identity protections (conditional access, risky-sign-in detection) and improve browser/session-level monitoring for anomalous OAuth outcomes.
Source: Security Week
US Warns of Industrial-Scale AI “Distillation” to Extract Frontier Capabilities
CISA, NSA, and FBI issued an advisory warning that China-based AI firms are using knowledge distillation at industrial scale to extract restricted capabilities from US models. Distillation—often framed as legitimate AI development—can be misused to copy functional capability without direct access to proprietary model internals. The policy and security implication: frontier model governance must increasingly account for adversarial model-extraction workflows, not only data or model theft.
Source: Help Net Security
Fake Stores at Scale: 100,000+ DoppelCart “Retail Clone” Operations Target Card Data and OTPs
DoppelCart is associated with large-scale fake storefronts that impersonate real retailers to capture payment card details and one-time bank confirmation codes. This reflects the continuing convergence of e-commerce fraud and credential/OTP theft—where the “second factor” becomes the attacker’s goal rather than the victim’s defense. Merchants and consumers should treat suspicious checkout behavior and unusual redirects as immediate red flags, while security teams consider stronger fraud and session anomaly controls.
Source: Malwarebytes Blog
You May Also Be Interested In... Cisco Secure FMC ongoing exploitation coverage
Australia proposes user choice over social media feeds
More on F5 APM memory-resident web shell malware