Skip to content
September 2026 Page 57

September 2026

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Swati KhandelwalSep 02, 2026Vulnerability / Web Security Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals.… 

Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands

Swati KhandelwalSep 02, 2026Malware / Cybercrime The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send… 

Get 50 AI models and no recurring payments with a lifetime subscription to AskAnyModelAI Pro for .99

Get 50 AI models and no recurring payments with a lifetime subscription to AskAnyModelAI Pro for $39.99

TL;DR: Save time (and credits) by comparing results from more than 50 AIs with a lifetime subscription to AskAnyModelAI Pro Plan for $39.99, 91% off the $499 regular price. There’s a lot of AI models out there, and… 

Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

Forescout Research – Vedere Labs said it used Anthropic’s Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live… 

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Ravie LakshmananSep 02, 2026Vulnerability / Network Security Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586…