Daily digest,
Apple Addresses CoreGraphics Zero-Day Vulnerability Amid (+7 more)
Vulnerabilities
Apple Addresses CoreGraphics Zero-Day Vulnerability Amid
On September 30, 2026, Apple released a patch for a zero-day vulnerability in CoreGraphics that was reportedly being. The flaw, identified as CVE-2026-1234, allows attackers to execute arbitrary code on affected systems. Users of macOS and iOS are particularly at risk, as the vulnerability affects multiple versions of these operating systems. Apple has urged all users to update their systems immediately to mitigate the risk of exploitation. The vulnerability was discovered during routine security assessments, and its was confirmed by security researchers. This incident highlights the ongoing threat posed by zero-day vulnerabilities in widely used software.
Vulnerability · 4 sources · score 73
High-Risk Vulnerabilities in OpenClaw Windows Node Disclosed
Two vulnerabilities, CVE-2026-101880 and CVE-2026-101884, were disclosed for OpenClaw Windows Node versions prior to 2026.7.1. CVE-2026-101880 allows arbitrary command execution via an authorization bypass, while CVE-2026-101884 enables remote code execution through environment variable manipulation. Both vulnerabilities are rated high severity, with CVSS scores of 8.7 and 7.7 respectively. Attackers with low privileges can exploit these flaws to gain control over affected Windows hosts, potentially leading to data theft or service disruption. No active exploitation has been confirmed, but proof-of-concept indicators exist. Organizations using OpenClaw should prioritize patching and restricting access to vulnerable nodes. The vulnerabilities were published on September 30, 2026.
Vulnerability · 3 sources · score 68 · CVE-2026-101880, CVE-2026-101884, GHSA-39cf-qcfw-g8pg
Path Traversal Vulnerability in ZeroClaw Plugins
A path traversal vulnerability identified as CVE-2026-101885 affects ZeroClaw versions prior to 0.8.5 built with the plugins-wasm feature. This flaw allows attackers to craft malicious plugins that can write arbitrary files outside the designated plugins directory, potentially enabling code execution. The vulnerability arises from the failure to validate the wasm_path manifest field during plugin installation. Users installing untrusted plugins are at high risk, especially on developer workstations and self-hosted environments. A proof-of-concept exists, but there are no confirmed reports of active exploitation. Users are advised to upgrade to version 0.8.5 or disable WASM plugin support if not needed. The CVSS score for this vulnerability is 8.5, categorized as high concern. Mitigation strategies include reviewing plugin manifests and monitoring for unauthorized file changes.
Vulnerability · 3 sources · score 64 · CVE-2026-101885, Path Traversal
Remote Code Execution Vulnerability in WatchGuard FireWare OS
A remote code execution vulnerability has been identified in WatchGuard FireWare OS affecting its samld SAML session handling. Attackers who can write to the samld session directory can exploit this flaw, which arises from improper validation of user-supplied data leading to deserialization of untrusted data. The vulnerability has been assigned CVE-2026-13046, and WatchGuard has released an update to mitigate the issue. The advisory was publicly released on September 30, 2026, following a report to the vendor on May 22, 2026. The flaw allows attackers to execute arbitrary code in the context of the samld service, potentially leading to significant security breaches. Users are advised to apply the available patches immediately to protect their systems.
Vulnerability · 3 sources · score 57 · Deserialization Of Untrusted Data
Threat actors and malware
MALFEX Campaign Targets npm with Windows RAT and Data Theft
The MALFEX campaign, uncovered by CloudSEK, has been active since August 2023, using malicious npm packages to deploy the Overlord RAT and steal data from Windows systems. The operator, identified as Portuguese-speaking, has uploaded at least 12 npm packages and a GitHub repository linked to the operation. The attack involves two delivery chains: one that downloads a Windows executable disguised as a PNG file to install the Overlord RAT, and another that retrieves a Node.js bundle to steal Discord tokens and browser data. Three malicious packages remain active, including function-flag, which has been continuously malicious since July 2025. The campaign highlights ongoing vulnerabilities in the npm ecosystem, with some malicious packages still available despite advisories. Defenders are advised to block specific packages and monitor for persistence artifacts.
Malware · 2 sources · score 72 · Movinlike, Overlord, Overlord RAT, Shai-hulud, Malfex
Supply Chain Attacks Targeting MSPs Pose Significant Risks
In 2026, supply chain attacks have emerged as a critical threat to managed service providers (MSPs), allowing attackers to breach multiple client environments through a single compromised vendor. The 2021 Kaseya breach exemplified this risk, affecting around 60 MSPs and up to 1,500 customers. Attackers exploit vulnerabilities in remote management tools, backup systems, and identity management platforms used by MSPs. Once inside, they can deploy malware or ransomware to client endpoints, often undetected due to the trust placed in MSPs. Weak security practices, such as missing multi-factor authentication and shared administrator accounts, increase the potential blast radius of these attacks. Experts recommend that MSPs implement rigorous vendor risk management processes to mitigate these systemic threats.
Supply Chain · 2 sources · score 70 · Kaseya Breach
New macOS Malware CloudSyncD Disguised as Zoom Installer
CloudSyncD is a newly identified macOS malware that masquerades as a legitimate Zoom installer. Discovered by Jamf Threat Labs, it operates as a backdoor, capturing the user's administrator password and allowing remote command execution. The malware is delivered via a disk image named 'Zoom' that prompts users to bypass macOS's Gatekeeper security. Once installed, it can send data to attackers and execute additional malicious commands. The malware does not collect browser data or access keychain items, focusing instead on maintaining a low profile until further access is needed. It affects both Apple Silicon and Intel Macs. The attack vector relies on social engineering to trick users into providing their passwords. Current reports indicate that the malware is actively being deployed.
Malware · 5 sources · score 62 · CloudSyncD
TraceX Labs Reports High Threat from Google Apps Script Abuse
TraceX Labs released a report on September 30, 2026, detailing the abuse of Google Apps Script Web Apps for various malicious activities, including phishing, fraud, and malware distribution. The report categorizes the overall threat as high, highlighting how legitimate cloud infrastructure can be exploited for phishing, SEO manipulation, and spam. It notes that Apps Script URLs can be encountered through search engines, social media, or emails, leading users to malicious sites. The report emphasizes the need for vigilance against phishing tactics that use Apps Script as intermediaries. TraceX Labs also identified indicators of SEO manipulation and spam, linking these activities to MITRE ATT&CK techniques. While the report does not label Google Apps Script itself as malicious, it warns of its potential misuse by threat actors. The report is significant for organizations using Google services, as it underscores the risks associated with cloud-based applications.
Phishing · 2 sources · score 57
New on leak sites
32 victims listed on ransomware leak sites by 16 groups in the 24 hours before this issue. The most active:
Also moving
- CVEs: CVE-2026-88772, CVE-2026-88771, CVE-2026-65660, CVE-2026-35273, CVE-2023-54397
- Malware: Pegasus, ACR Stealer, Amatera Stealer, Carbonato, ClickFix
- APT groups: Apt29, Cozy Bear
- Vulnerabilities: CoreGraphics Zero-day, Path Traversal, BeyondTrust Privileged Remote Access And Remote Support, Cream Hack
- Ransomware groups: Blacknet-00
Get the next one by email
The digest is free and arrives every morning. One click to leave.
A free account turns the digest into a personal watchlist: choose what you want to follow.