Security Observatory Blog
Latest cybersecurity news, incidents and AI-model developments — observed and analyzed daily by the Mithril research team.
-
F5 disclosed on September 22 that a critical zero-day in BIG-IP APM's OAuth path (CVE-2026-94127, CVSS 9.8) allows unauthenticated remote code execution, and confirmed in-the-wild exploitation. CISA added it to the KEV catalog the same day with a September 25 federal deadline. Arista VCO and two Check Point management-server flaws also entered KEV that day — we examine the convergence of attacks on boundary appliances' management and identity planes.
-
On September 18, CISA added three actively exploited Linux kernel flaws (CVE-2025-39682, CVE-2026-53266, CVE-2025-39964) to the KEV catalog and Red Hat confirmed public exploit code exists. The same day, working exploits for four kernel LPEs (DirtyAH6, TUNderflow, PPPoEject, DiagSpill) were published under coordinated disclosure. We examine why shared-host privilege escalation is following boundary appliances into the spotlight.
-
Cisco ISE / ISE-PIC 的 API 认证绕过 CVE-2026-76460(CVSS 10.0)正处于实际攻击之下。CISA 已于 9 月 16 日将其列入 KEV 目录,联邦机构的修复期限为 9 月 19 日。该漏洞没有 workaround,iACL 仅是缓解措施。本文梳理其与 9 月 14 日公开的 Secure Email Gateway 零日(CVE-2026-76461)在一周内并行的“边界设备 root 侵害”结构,以及被侵害设备自身的日志不再是一手信息这一含义。
-
BerriAI LiteLLM 的 MCP 认证绕过(CVE-2026-59822)已被列入 CISA 的 KEV 目录,Microsoft 报告有攻击者经 LiteLLM 网关分发 XMRig。Wiz 的研究指出,约 3,000 个公开实例中约一成接受默认密钥 sk-1234 或完全无认证。本文梳理 AI 基础设施作为"凭证宝库"的含义。
-
Forever Security 的实证显示,一个仅持有普通权限的浏览器扩展就能驱动五款产品——Chrome、Comet、Edge、Opera Neon 与 Claude——的内置 AI 助手。另一方面,Mandiant 报告了一起攻击者劫持 AI 编码助手会话、把 Shai-Hulud 蠕虫扩散到约 100 个仓库的事件。本文梳理智能体运行时的信任边界。
-
Volexity 观测到 BlueMoon 攻击链——Chrome V8 沙箱内任意读写、沙箱逃逸与 Windows ALPC 滥用——被至少多个中国背景攻击集群共用。上游 Chromium 已有修复,但稳定版 Chrome 尚未发布相应更新,形成危险的"补丁空窗期"。本文梳理其影响。
-
每天观测、分析网络安全新闻、重大事件与 AI 模型动态,并在此发布。
-
CVE-2026-76461(CVSS 9.8)正被实际利用,并已加入 CISA 的 KEV 目录。本文梳理反复出现的"边界设备 root 沦陷"攻击模式,以及当设备自身日志不再可信时意味着什么。
-
A $900M AUM, operator-led fund built by former CISOs and founders. We map its two funds and ~40-company portfolio against mithril.fund's position.