This day 02:05 06:05 10:06 14:06 18:07 22:08
Info  2026-09-30 14:06Z · last 4h · 22 findings · glm-5.2:cloud

Threat Brief — 2026-09-30: TeamViewer and OpenSSL Flaws Demand Urgent Patching

Executive Summary

Two patching priorities lead today: TeamViewer is urging customers to immediately fix high-severity vulnerabilities in its client and host software, and OpenSSL has patched a DTLS flaw that can leak unencrypted heap memory across a connection. Active exploitation of the patched Citrix NetScaler vulnerability continues to evolve, with Mandiant now attributing post-exploitation activity to new tooling called WHIPSHOT and SLAPSHOT. A US-focused C-suite phishing campaign stealing Microsoft 365 sessions and deploying RMM tools, plus the exposure of over 13,000 internal developer images on GitHub via AI coding agents, round out the day's most actionable findings.

Top Items

Themes

Browser and remote-access tooling as the dominant attack surface pair. Today's findings converge on two interlocking vectors: browsers (76 Firefox vulnerabilities, M365 session token theft via phishing) and remote-access tools (TeamViewer severe flaws, RMM deployment in phishing campaigns, NetScaler exploitation). The browser is the most likely initial-access point; remote-access tooling — whether legitimate RMM or exploited vendor software — is the persistence bridge.

AI-assisted workflows as an unintentional data-exfiltration channel. The exposure of 13,000 internal images via AI coding agents is the latest in a pattern of findings showing that agentic AI tools can bypass traditional data-loss controls when granted access to internal artifacts and external publishing capabilities.

Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db