CrowdStrike Falcon Sensor 'FalconFlank' Local Privilege Escalation LPE
The 'FalconFlank' zero-day exploit targets the CrowdStrike Falcon Sensor on Windows, facilitating Local Privilege Escalation (LPE) to NT AUTHORITY\SYSTEM. The vulnerability stems from a flaw in the sensor's remediation logic when processing malicious Microsoft Office macros, allowing an attacker with local access to bypass security controls on fully patched systems. A public Proof-of-Concept (PoC) was released on GitHub by researcher Chaotic Eclipse on September 3, 2026, without prior vendor coordination. This flaw enables full host compromise and potentially allows attackers to evade the sensor's detection and prevention capabilities.
Breeze Comet Exploits PIX Transaction Signing Mechanisms within Brazilian Financial Infrastructure
The financially motivated threat actor Breeze Comet (UNC5669) is conducting highly sophisticated attacks against the Brazilian financial sector, specifically targeting the PIX instant payment system. Unlike traditional fraud involving credential theft or forgery, Breeze Comet utilizes specialized modules to manipulate banking software and the transaction signing processes. By exploiting vulnerabilities in how retail e-commerce payment integrations and banking gateways handle transaction signatures, the actor executes hundreds of unauthorized transfers that appear technically valid. This exploitation poses a systemic risk to the integrity of the PIX infrastructure and the broader Brazilian e-commerce ecosystem.
Google Chrome: CVE-2026-87491 V8 Zero-Day Enables Arbitrary Code Execution
Google has patched CVE-2026-87491, a critical out-of-bounds (OOB) write vulnerability in the V8 JavaScript and WebAssembly engine, following reports of active exploitation in the wild. Threat actors are leveraging this zero-day to achieve arbitrary code execution (ACE) via malicious web content or specifically crafted WebAssembly payloads. Intelligence indicates Chinese-linked APTs are integrating this flaw into multi-stage exploit chains designed to bypass Windows security controls and facilitate full system compromise. Immediate remediation is required by updating Google Chrome to version 153.0.8010.36/37 across Windows, macOS, and Linux to mitigate the risk of remote exploitation and subsequent host-level persistence.
SonicWall SMA 1000 Series Mass Exploitation and UK Public Sector Breach
This campaign involves the mass exploitation of a critical vulnerability in SonicWall SMA 1000 series devices to gain initial perimeter access. Attackers utilize weaponized payloads to compromise the VPN gateway, subsequently pivoting to internal Active Directory (AD) environments for credential harvesting and NTDS.dit theft. This lifecycle resulted in the operational disruption of the Borough Council of King's Lynn and West Norfolk and indicates a systemic risk to UK public sector infrastructure. The attack progression focuses on achieving total domain dominance to facilitate large-scale data exfiltration or ransomware deployment, mirroring patterns seen in recent critical infrastructure hits including the NHS Synnovis incident.
Critical VM Escape Vulnerabilities in VMware Workstation and Fusion VMSA-2026-0007
VMSA-2026-0007 addresses critical vulnerabilities in VMware Workstation and Fusion that enable guest-to-host escapes. Attackers with administrative privileges on a guest VM can exploit memory corruption flaws—including heap overflows, Use-After-Free (UAF), and type confusion—within device emulation components such as the SVGA device and USB controllers. Successful exploitation allows arbitrary code execution (ACE) on the underlying host operating system with the privileges of the VMware process. This breaks the fundamental isolation premise of virtualization, facilitating full host compromise, data exfiltration, and lateral movement across the physical network. Immediate updates to patched versions are required to mitigate these high-CVSS risks.
Critical Authentication Bypass in JFrog Artifactory CVE-2026-82329
A critical authentication bypass vulnerability, identified as CVE-2026-82329, is being actively exploited in JFrog Artifactory. With a CVSS score of 9.8, the flaw allows unauthenticated remote attackers to circumvent security controls and programmatically "mint" administrative tokens. This enables full instance takeover, unauthorized retrieval of proprietary software artifacts, and potential supply chain compromise through malicious artifact injection. Intelligence from watchTowr confirms high-velocity exploitation occurring within days of public disclosure, signaling a rapid transition from vulnerability discovery to active n-day exploitation against critical DevOps infrastructure.
AI-Augmented Espionage via Anthropic Claude: Russian APT Malware Evasion
Russian state-sponsored APTs utilized Anthropic's Claude LLM to automate the creation of polymorphic and obfuscated malware, specifically targeting over 20 entities in the global defense, intelligence, and diplomatic sectors. By employing sophisticated prompt injection and jailbreaking techniques to bypass safety guardrails, attackers refactored existing payloads to evade signature-based and heuristic EDR/XDR detections. This AI-augmented workflow allows for rapid code mutation, reducing the effectiveness of traditional indicator-based defenses and complicating incident response. The campaign demonstrates a critical shift toward AI-driven offensive capabilities to achieve high-stealth persistence within high-value geopolitical targets.
Liquid Network: $320M BTC Breach via Elements Protocol Vulnerability in Blockstream’s Liquid Network
A critical logic flaw within the Elements Protocol, the foundational architecture of Blockstream’s Liquid Network, has resulted in the unauthorized withdrawal of approximately 4,000 BTC (~$320M) from the Liquid Federation wallet. The exploit bypasses standard withdrawal controls by targeting vulnerabilities in the underlying Elements codebase, specifically within the federated sidechain model. Unlike traditional ransomware, the threat actors claim "white hat" status, demanding a permanent architectural remediation of the protocol rather than a direct monetary ransom. This incident has forced a total suspension of Liquid Network transaction processing, exposing systemic vulnerabilities in federated sidechain architectures utilized by cryptocurrency exchanges for high-speed settlement.
GitLab Critical Path Traversal Vulnerability CVE-2025-13761 Enables RCE
A critical path traversal vulnerability, identified as CVE-2025-13761, has been discovered in the GitLab API, specifically within the Commits API. Attacking via a single HTTP request, threat actors can bypass file system restrictions to perform arbitrary file reads. This vulnerability allows for the unauthorized extraction of sensitive data, including /etc/passwd, SSH keys, and application secrets, which facilitates privilege escalation to Remote Code Execution (RCE). With a CVSS score of 10.0, the flaw is currently subject to active exploitation and widespread automated scanning. Immediate upgrade to GitLab version 19.3.2 or later is required to prevent full server compromise.
Chinese-based AI Firms: Systematic Extraction of US Frontier AI Models via Knowledge Distillation
U.S. intelligence agencies (CISA, FBI, IC3) have identified a coordinated industrial-scale campaign by Chinese AI firms to extract proprietary capabilities from U.S. frontier AI models. Adversaries are utilizing automated API probing and systematic querying to implement "knowledge distillation," a process where a student model is trained on the outputs of a high-performing teacher model to mimic its logic and functionality. This technique bypasses traditional R&D costs and computational requirements, resulting in the unauthorized transfer of intellectual property and a significant erosion of U.S. technological leadership in artificial intelligence.