Security Observatory Blog
Latest cybersecurity news, incidents and AI-model developments — observed and analyzed daily by the Mithril research team.
-
F5 disclosed on September 22 that a critical zero-day in BIG-IP APM's OAuth path (CVE-2026-94127, CVSS 9.8) allows unauthenticated remote code execution, and confirmed in-the-wild exploitation. CISA added it to the KEV catalog the same day with a September 25 federal deadline. Arista VCO and two Check Point management-server flaws also entered KEV that day — we examine the convergence of attacks on boundary appliances' management and identity planes.
-
On September 18, CISA added three actively exploited Linux kernel flaws (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) to the KEV catalog and Red Hat confirmed public exploit code exists. The same day, working exploits for four kernel LPEs (DirtyAH6, TUNderflow, PPPoEject, DiagSpill) were published under coordinated disclosure. We examine why shared-host privilege escalation is following boundary appliances into the spotlight.
-
Cisco ISE / ISE-PIC의 인증 우회 취약점 CVE-2026-76460(CVSS 10.0)이 실제 악용 아래에 있다. CISA는 9월 16일 이를 KEV 카탈로그에 추가했고, 연방 기관의 수정 기한은 9월 19일이다. 이 취약점에는 workaround가 없으며, iACL은 어디까지나 완화 조치일 뿐이다. 본고는 9월 14일 공개된 Secure Email Gateway 제로데이(CVE-2026-76461)와 한 주 동안 병행해 진행된 “경계 장비 root 침해” 구조, 그리고 침해된 장비 자신의 로그가 1차 정보가 아니게 된다는 함의를 정리한다.
-
BerriAI LiteLLM's MCP authentication bypass (CVE-2026-59822) has landed in CISA's KEV catalog, and Microsoft reports attackers using LiteLLM gateways to deliver XMRig. Wiz research found roughly 1 in 10 of ~3,000 public instances accepted the default key sk-1234 or ran with no auth. We examine what it means that AI infrastructure is a vault of credentials.
-
Forever Security showed that a single ordinary browser extension could drive the built-in AI of five products — Chrome, Comet, Edge, Opera Neon, and Claude. Separately, Mandiant reported an attacker hijacking an AI coding-assistant session and spreading the Shai-Hulud worm across about 100 repositories. We map the trust boundaries of agentic runtimes.
-
Volexity observed the BlueMoon chain — Chrome V8 sandbox read/write, sandbox escape, and Windows ALPC abuse — shared by multiple China-nexus clusters. The upstream Chromium fixes had not yet shipped in stable Chrome, creating a dangerous "patch gap". We unpack the implications.
-
Daily observation and analysis of cybersecurity news, incidents and AI-model developments, published here.
-
CVE-2026-76461 (CVSS 9.8) is being actively exploited and was added to CISA's KEV catalog. We break down the recurring "root compromise of a boundary appliance" pattern — and what it means when the appliance's own logs can no longer be trusted.
-
A $900M AUM, operator-led fund built by former CISOs and founders. We map its two funds and ~40-company portfolio against mithril.fund's position.