Saturday , September 26 2026
Cursor

Cursor, SonicWall, SharePoint 0-day exploited to the wild

A serious security flaw in Cursor, a popular AI code editor used by more than 7 million developers, lets attackers run any code on Windows systems. Just opening a harmful repository can start this process. It doesn’t need any clicks, confirmations, or approvals from the user. The flaw was found by Mindgard, a security company, on December 15, 2025, and told to Cursor’s security team that same day.

The vulnerability stems from how Cursor resolves Git binaries when loading a development project. Among the locations Cursor searches is the workspace root itself.

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

If an attacker plants a malicious file named git.exe in that root directory, Cursor executes it automatically as part of its normal path resolution routine. Because the editor performs this search implicitly, it triggers execution without any security prompt or user warning.

SonicWall

SonicWall says that hackers are using two SMA1000 weaknesses, named CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and tells customers to install the new security updates.

CVE-2026-15409 is a serious (CVSS 10.0) server-side request forgery (SSRF) flaw in the SMA1000 Appliance Work Place interface. It lets a remote, unauthorized person make the appliance send requests to wrong places.

CVE-2026-15410 is a serious issue (CVSS 7.2) in the SMA1000 Appliance Management Console. It lets a remote admin who is logged in run any commands on the operating system.

SonicWall says it investigated multiple incidents and confirmed that both vulnerabilities are being actively exploited.

“SonicWall PSIRT has investigated multiple cases indicating the active exploitation of the vulnerabilities described in this advisory,” SonicWall warned.

“Customers are strongly urged to upgrade to the hotfix release as soon as possible to remediate these vulnerabilities”

The vulnerabilities affect SMA1000 models 6210, 7210, and 8200v running platform-hotfix releases 12.4.3-03245, 12.4.3-03387, 12.4.3-03434, 12.5.0-02283, 12.5.0-02624, and 12.5.0-02800. Fixes are available in platform-hotfix versions 12.4.3-03453 and 12.5.0-02835, and later releases.

SonicWall advises moving to the newest hotfix and checking if any of the listed IOCs are there.

SharePoint

The Cybersecurity and Infrastructure Security Agency (CISA) has put a serious flaw in Microsoft SharePoint Server, called CVE-2026-56164, in its list of known exploited vulnerabilities because it is being actively used by bad actors.

CVE-2026-56164 is a missing-authentication issue that affects important parts of Microsoft SharePoint Server.

An attacker can use this weakness without having real SharePoint credentials. CISA’s advice says that if they succeed, an unauthorized attacker could get higher access on a network.

CISA put this weakness in its Known Exploited Vulnerabilities list on July 14, 2026, showing that the agency knows it has been used in real attacks.

They set a deadline for fixing the problem by July 17, 2026, giving federal agencies just three days to deal with it. Just because this weakness is in the list does not mean it is used in ransomware attacks.

Check Also

Chrome

Google issues warning of new Chrome zero-day flaw exploited

Google has updated the Chrome browser to fix a serious security issue in the V8 …