September 22, 2026 by sig9
Hacker Wars - September 22, 2026
Your daily dose of infosec chaos
CISA’s Known Exploited Vulnerabilities catalog had a busy morning: Zyxel switches, Veeam backup servers and the Linux kernel all made the list, so your patch backlog is now a to-do list with a body count. WordPress also shipped a fix for a flaw that let anonymous commenters weaponize admin sessions, BigCommerce storefronts caught skimmers through a third-party app, and Japan just evicted its first North Korean laptop farm. Coffee first, then the patching sprint.
Zyxel And Veeam Flaws Land On CISA’s Hit List
CISA added a flaw in Zyxel GS1900 switches (CVE-2026-7273) to its KEV catalog after attackers were caught abusing it for data theft, with federal agencies ordered to patch by Thursday. Veeam vulnerabilities that hand attackers command execution and SYSTEM-level access are also being exploited in the wild, and backup servers are a lovely place to stage ransomware from.
What to do: Patch Zyxel and Veeam deployments now and hunt for signs of prior access - KEV listing means someone already wrote the exploit for you.
WordPress Comment2Shell Turns Comment Spam Into Server Takeover
A now-patched WordPress core flaw dubbed Comment2Shell (CVE-2026-93485) let anonymous visitors plant hidden scripts via comments; when a logged-in admin viewed the page, the script hijacked their session into full remote code execution. No plugin needed, no authentication required - just patience and a comment box.
What to do: Update WordPress core immediately and audit comment queues and server logs for anything that smells like planted payloads.
BigCommerce Breach Slips Skimmers Into Trusted Storefronts
BigCommerce warned merchants of breaches after attackers stole credentials for third-party Ribon apps and used them to inject malicious scripts into online stores, skimming customer data from pages nobody thought to audit. The moral stays the same: your attack surface includes every app vendor with keys to your storefront.
What to do: Rotate all integration credentials, review installed apps and their script permissions, and sweep live pages for unfamiliar JavaScript.
CISA Flags Three Linux Kernel Flaws Under Active Attack
CISA is warning that three Linux kernel vulnerabilities, one rated critical, are being actively exploited - which puts your VM hosts, container nodes and every unloved appliance in scope. The kernel is the one dependency you can’t uninstall, and privilege escalation bugs in it don’t age gracefully.
What to do: Patch kernels everywhere including hosts and hypervisors, and review for unexpected privilege escalation on internet-facing Linux boxes.
Japan Evicts Its First North Korean Laptop Farm
Japanese authorities dismantled the country’s first known North Korean laptop farm, where remote IT workers use borrowed identities and other people’s networks to hold down Western jobs and route salaries to Pyongyang. The US, Japan, Germany and Australia published a joint advisory on the wider WaterPlum scheme, so expect the hiring-fraud radar to get louder.
What to do: Screen remote candidates for identity reuse and impossible travel, and investigate residential IPs that never match the claimed location.
That’s a wrap. Back tomorrow with more digital warfare.
Brought to you by sig9 - sig9.ch | Protecting the unseen, securing the unknown
This bulletin is provided for informational purposes. Contact us for tailored security analysis.