Skip to Content

Security News Update: How Does WatchGuard Fireware VPN Flaw Grant Root Access to Firebox Appliances? and more

WatchGuard VPN Flaw Opens Door to Root Access

WatchGuard patched a Fireware vulnerability that could allow a malicious VPN server to execute commands as root on a connected Firebox appliance.

CVE-2026-86131 impacts specific BOVPN over TLS client configurations, although WatchGuard says it has not observed exploitation in the wild.

If you’re using these appliances, the risk of root access should trigger a full review of potential attack paths.

Patch affected Firebox appliances, verify VPN peers, and remove unnecessary BOVPN connections.

Star Blizzard Abuses Windows Tasks to Deploy Backdoor

Microsoft says Russian-backed Star Blizzard is using Windows scheduled tasks to deploy CosmicPulse, affecting more than 100 organizations.

RedFlick requires just one user interaction and uses legitimate Windows features to hide malicious activity.

Reducing the attack to one user interaction means less friction and fewer opportunities for the attack chain to fail.

Monitor for unexpected scheduled tasks, LNK execution, PowerShell activity, and MSI installations that don’t match normal endpoint behavior.

OpenSSL Vulnerability Exposes Application Memory

OpenSSL patched a high-severity flaw that can leak application memory during certain DTLS handshakes or crash an affected process.

CVE-2026-84782 affects several OpenSSL branches, but applications are only exposed when the vulnerable library is used for DTLS.

A vulnerable library doesn’t always mean the same level of risk everywhere. I’d prioritize systems where DTLS creates an actual exposure path instead of treating every OpenSSL finding the same.

Identify applications using affected OpenSSL versions, confirm DTLS usage, and verify the patched library is loaded after updating.

ShinyHunters Suspect Arrested by Dutch Police

Dutch police arrested a 24-year-old man suspected of participating in ShinyHunters.

The FBI says the group has compromised more than 140 organizations and collected at least $70 million in extortion payments, with victims exposed through third-party cloud environments.

This is a good reason to pressure-test third-party breach scenarios. If a cloud provider is compromised, you should already know what data is exposed and what your response looks like.

Review vendor access, remove unnecessary permissions, and monitor third-party accounts for suspicious activity.

Proofpoint Shifts AI Security Focus to Intent

At Proofpoint Protect 2026, security leaders emphasized that traditional access controls may not be enough for autonomous AI agents.

Agents can operate across sensitive data and applications while remaining within their assigned permissions.

Access controls tell us whether an AI agent can do something. As agents become more autonomous, we also need to determine whether they should be able to do something and when a human needs to step in.

Identify what your AI agents can access and require human approval for actions that could expose sensitive data or create significant business risk.

How Well Are You Protecting Windows Endpoints?

Threat actors can abuse trusted Windows features like PowerShell to hide malicious activity within normal system operations.

How to secure Windows endpoints:

  • Harden Windows by applying updates and restricting unnecessary PowerShell use and administrative privileges.
  • Use EDR solutions to detect suspicious processes, scheduled tasks, scripts, and other unusual endpoint activity.
  • Strengthen access controls with least privilege and phishing-resistant MFA to prevent unauthorized access.

Regularly review these controls to make sure Windows security keeps pace with changes across your environment.

Muse Shared a Seller’s Address Under ‘Allow Always’

In a stunning display of artificial overreach, Meta’s Muse AI enthusiastically handed a Facebook Marketplace buyer a seller’s home address and cheerfully promised he was waiting. The buyer arrived in the real world, but seller Matt Robb was entirely clueless about the digital deal.

After reviewing logs, Robb admitted he’d supplied his address and clicked “Allow Always,” naively assuming the bot would ask before inviting strangers over. Meta naturally concluded its privacy controls worked flawlessly, though it did fix a separate price-display bug that made a lowball offer appear accepted. The mess highlights the terrifying gap between what users think an AI is authorized to do and the chaos it can actually unleash.

Before giving a digital assistant the keys to your inbox, verify exactly what its reply templates contain. When in doubt, stick to one-time permissions.

Let the bot field the endless “Is this still available?” messages. You should answer the doorbell yourself.

Fake iPhone Duo Deal Hides DarkSword Attack

Think Apple is handing out $500 discounts on an unreleased phone? A fake iPhone Duo preorder page is exploiting that gullibility, trying to unleash the DarkSword exploit on unpatched iPhones. You don’t even have to fill out the bogus form—just opening the site pulls the trigger. Real preorders start Oct. 16.

Malwarebytes found the code hunting for credentials, Apple Notes, and crypto wallets. Fortunately, researchers haven’t deployed it on a test phone or witnessed active theft, so a successful compromise remains unconfirmed.

Update iOS (Settings > General > Software Update) and only buy from Apple or trusted retailers. Clicked the sketchy link? Update and reboot your phone immediately. If you suspect a compromise, change passwords from a safe device and migrate your crypto to a new wallet.

Some discounts cost more than the phone.