Security Highlights Of The Day [10/02/26]
BeyondTrust Patches Critical RCE Vulnerability
BeyondTrust has released patches for a critical vulnerability in Remote Support (RS) and Privileged Remote Access (PRA) that could allow unauthenticated remote code execution. Tracked as CVE-2026-1731 (CVSS 9.9), the flaw can be exploited via specially crafted requests to execute OS commands as the site user. Successful exploitation requires no authentication or user interaction and may result in system compromise, unauthorized access, data exfiltration, and service disruption. The issue affects RS versions 25.3.1 and earlier and PRA versions 24.3.4 and earlier. Approximately 8,500 internet-exposed on-prem RS deployments are believed to be potentially affected.
Source: SecurityWeek
Fortinet Patches Critical SQL Injection Flaw Allowing Unauthenticated Code Execution
Fortinet has issued security updates addressing CVE-2026-21643 (CVSS 9.1), a critical SQL injection vulnerability in FortiClientEMS. The flaw allows unauthenticated attackers to execute arbitrary code or commands via specially crafted HTTP requests. Improper neutralization of special elements in SQL commands enables remote exploitation without authentication. Organizations using vulnerable FortiClientEMS versions are advised to apply patches immediately to prevent system compromise.
Source: The Hacker News
Warlock Ransomware Breaches SmarterTools via Unpatched SmarterMail Server
SmarterTools confirmed that the Warlock (Storm-2603) ransomware group breached its network by exploiting an unpatched SmarterMail instance. The compromised server had not been updated to the latest version and was reportedly set up outside standard patch management oversight. Although approximately 30 SmarterMail servers were deployed across the network, one unmaintained VM enabled initial access. SmarterTools stated that core business applications and customer account data were not affected.
Source: The Hacker News
Largest Multi-Agency Cyber Operation Targets APT UNC3886 in Singapore
Singapore authorities disclosed that Advanced Persistent Threat actor UNC3886 conducted a deliberate and targeted campaign against the country’s telecommunications sector. All four major telecom operators – M1, SIMBA Telecom, Singtel, and StarHub – were targeted. The campaign was identified in July 2025, with operational details withheld to preserve security. The coordinated response involved multiple agencies to contain and counter the threat posed to critical infrastructure.
Source: Cyber Security Agency of Singapore
New SSHStalker Linux Botnet Uses Legacy Exploits and IRC-Based Control
A newly identified Linux botnet dubbed SSHStalker relies on exploitation techniques dating back to 2009. The botnet uses IRC-based command and control, multiple Linux kernel exploits, cron-based persistence mechanisms, and watchdog relaunch models. It deploys scanners and additional malware across infected systems. While artifacts resemble Romanian-linked botnet campaigns such as Outlaw and Dota, researchers have not confirmed a direct link, suggesting a derivative or copycat operator may be responsible.
Source: SecurityWeek