4 Sep 2026
Week in review
Greetings,
After more than two decades in the shadows, one of the internet’s longest-running botnets has finally been disrupted. An international operation involving authorities and cyber security researchers from the US, Bulgaria, Hungary and Romania, alongside CrowdStrike and the Shadowserver Foundation, has isolated more than 15,000 infected systems and seized domains linked to the Sality botnet.
Unlike traditional botnets that rely on central command-and-control servers, Sality used a peer-to-peer network, making it harder to disrupt or dismantle. Researchers exploited this architecture to interfere with communications between infected machines and disrupt the botnet. Sality has been used to distribute malware and facilitate various forms of cyber crime, including cryptocurrency theft.
Organisations should not assume that older malware is no longer a threat. Effective endpoint protection, timely patching, network monitoring and investigation of legacy malware detections remain essential. The continued activity of threats such as Sality demonstrates that malware can persist for years, making it important to detect and respond to both emerging and long-standing threats.
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
Date: 2026-08-28
Author: The Hacker News
cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user.
The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM.
Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs
Date: 2026-08-31
Author: Security Week
Hackers are exploiting a critical-severity Ruby on Rails vulnerability that leads to remote code execution (RCE), VulnCheck warns.
Tracked as CVE-2026-66066 (CVSS score of 9.5) and referred to as KindaRails2Shell, the flaw is described as an arbitrary file read leading to secret exposure, RCE, and lateral movement.
The security defect was disclosed in late July, when Ruby on Rails rolled out patches for it, urging the immediate patching of all Rails applications that rely on libvips for Active Storage image processing and allow image uploads from untrusted users.
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Date: 2026-09-01
Author: Bleeping Computer
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes.
Tracked as CVE-2026-62911 and reported by DEVCORE Research Team's Orange Tsai, this security flaw affects Exchange Server 2016, Exchange Server 2019, and Exchange Server Subscription Edition (SE) software. Threat actors with basic privileges on the targeted server can exploit it in low-complexity attacks that require user interaction.
PaperCut issues emergency patches as threat actors target chained vulnerabilities
Date: 2026-08-31
Author: Cybersecurity Dive
[See AUSCERT bulletin: https://portal.auscert.org.au/bulletins/ASB-2026.0208/]
PaperCut issued emergency patches on Friday to address critical vulnerabilities in its print-management software.
The company confirmed in a security advisory that multiple customers were successfully targeted and that it is working with security researchers at Huntress and watchTowr to respond to the attacks.
The vulnerabilities include an improper access-control flaw in PaperCut MF and NG. CVE-2026-81578 enables an unauthenticated attacker to modify certain system configurations and CVE-2026-82078 enables an attacker to execute arbitrary Java bytecode.
BGP Hijack Diverts Softaculous Traffic to Deliver Malicious Virtualizor Update
Date: 2026-09-01
Author: Cyber Security News
Attackers hijacked BGP routing for Softaculous last week and delivered a malicious Virtualizor update to a handful of hypervisor servers, according to a vendor incident report.
Hosting providers use Virtualizor to manage VPS nodes on KVM, Xen, LXC, OpenVZ, and Proxmox, and a single master can control hundreds of virtualization servers, placing a poisoned update high in the hosting stack. The product publicly lists hundreds of NOC partners, so a compromise here hits hosting infrastructure rather than a single website panel.
ESB-2026.10412 – Cisco Nexus 9000 Series Switches: CVSS (Max): 9.8
Cisco has released software updates that addresses vulnerabilities in Cisco Nexus 9000 Series Switches.
ASB-2026.0208 – PaperCut NG / MF: CVSS (Max): 9.4
PaperCut NG and PaperCut MF are affected by two vulnerabilities that can be chained by attackers to bypass authentication and execute arbitrary code on vulnerable servers.
ESB-2026.10356 – Firefox ESR: CVSS (Max): 10.0
Internally found bugs present in Firefox 154, Firefox ESR 153.1, Firefox ESR 140.14 and Firefox ESR 115.39.
ESB-2026.10351 – Rockwell Automation Logix Platform: CVSS (Max): 7.5
A denial-of-service vulnerability exists in the affected Logix platforms due to improper validation of input length during CIP message processing.
ESB-2026.10167 – Tenable Enclave Security: CVSS (Max): 9.9
Several vulnerabilities have been identified, reported to Tenable and resolved.
Stay safe, stay patched and have a good weekend!
The AUSCERT team