
Cyber Security News for September 24 2026 - Daily DefSec Brief
Show notes
1. Roundcube pre-login SQL injection now exploited — CVE-2026-48842 — Fixed: 1.6.16 or 1.7.1 — Do: Upgrade Roundcube webmail — https://roundcube.net/news/2026/05/24/security-updates-1.6.16-and-1.7.1
2. TeamCity RCE now used in ransomware campaigns — CVE-2026-63077 — Fixed: 2025.11.7 or 2026.1.3 — Do: Patch TeamCity and check it for intruders — https://www.rapid7.com/blog/post/etr-cve-2026-63077-critical-unauthenticated-remote-code-execution-in-jetbrains-teamcity/
3. Spraying hit only forgotten M365 service accounts — Do: Lock down forgotten Microsoft 365 service accounts — https://www.proofpoint.com/us/blog/threat-insight/Spraying-in-the-Andes-TeamFiltration-Returns
4. Public Ubuntu container escape, no kernel fix yet — CVE-2026-80521 — Do: Keep untrusted containers off Ubuntu hosts — https://ubuntu.com/security/CVE-2026-80521
5. Windows app host hands Microsoft tokens to attackers — Do: Turn off app sideloading where it isn't needed — https://www.huntress.com/blog/stealing-oauth-tokens-through-microsofts-front-door
6. Malicious providers on HashiCorp's Terraform registry — Do: Check Terraform lock files for the typosquat — https://www.aikido.dev/blog/graphalgo-terraform-go-modules
7. Any cPanel account can get root via CalDAV — CVE-2026-87899, CVE-2026-87900, CVE-2026-68490 — Fixed: 11.134.0.57, 11.136.0.41, 11.138.0.8; WP Toolkit 6.11.3 — Do: Update cPanel and WP Toolkit — https://support.cpanel.net/hc/en-us/articles/43591715125271-Security-CVE-2026-87899-Vulnerability-in-cPanel-s-CalDAV-CardDAV-September-22-2026
8. Foxit PDF Reader update fixes updater SYSTEM flaw — CVE-2026-91813 — Fixed: Reader 2026.2.1; Editor 2026.2.1, 14.0.8 or 13.2.7 — Do: Push the Foxit PDF update — https://www.foxit.com/support/security-bulletins.html
9. Hundreds of leaked GitHub App keys still work — Do: Audit your GitHub Apps and rotate their keys — https://blog.gitguardian.com/github-app-private-keys-leaked/
10. New injection technique slips past four EDRs — Do: Ask your EDR vendor about parameter poisoning — https://flashpoint.io/blog/process-parameter-poisoning-edr-evasion-technique/
11. A GitLab email address can commit code as you — Do: Reset your GitLab incoming email token — https://www.aikido.dev/blog/gitlab-email-push-to-main