Security News

WAF Weekly: Cisco zero-day, record patch Tuesday, DDoS campaign, Sep 4-11

Cisco confirms an exploited Secure FMC zero-day, Microsoft ships a record near 1,000 patches, and a hacktivist DDoS campaign takes aim at Japan.

5 min read
WAF Weekly: Cisco zero-day, record patch Tuesday, DDoS campaign, Sep 4-11

This week was dominated by exploited flaws and a record patch flood. Cisco confirmed a max-severity Secure FMC flaw is under active attack, Microsoft pushed almost 1,000 fixes including two zero-days, and a pro-Russian hacktivist group relaunched its DDoS campaign against Japan. Meanwhile vendors shipped new controls for the AI agent era. Here is what mattered for web and app security.

Cisco confirms Secure FMC zero-day exploited in the wild

Cisco confirmed that CVE-2026-20079, a maximum-severity authentication bypass in Secure Firewall Management Center, is being actively exploited. The flaw scores a perfect 10.0 and lets an unauthenticated remote attacker execute commands as root by sending crafted HTTP requests to the web interface. CISA added it to the Known Exploited Vulnerabilities catalog and ordered federal agencies to patch by September 12. Cisco offers no workaround, only an upgrade. Log evidence from July suggests the flaw may have been exploited weeks before the vendor confirmed it in August.

The WAFplanet angle: management consoles are a high-value target because they sit at the center of a security stack. If a web-facing management interface allows unauthenticated command execution, no edge WAF that only inspects production traffic will save the devices it manages. Segment and restrict access to management planes, and treat firewalls themselves as assets worth defending.

Source: BleepingComputer

September Patch Tuesday: a record near 1,000 fixes and two zero-days

Microsoft shipped 964 fixes in September, a new record driven by AI-assisted bug discovery. Two zero-days are already exploited, including a heap overflow in Windows ALPC that escapes the sandbox. Experts warn a Windows DNS remote code execution flaw could be the spiritual successor to SigRed and could become wormable. Adobe patched an actively exploited Commerce zero-day dubbed StyleSmuggler that drops Linux backdoors, and Fortinet FortiWeb vendor confirmed ongoing exploitation of two older FortiOS authentication bypasses that seize edge firewalls.

The WAFplanet angle: patch volume is exploding faster than defenders can triage it. CVSS scores alone are no longer a useful filter. Prioritize by exploitability, network exposure, and what a compromise actually unlocks. Remote management and edge firewall interfaces should be top of the list, which is exactly where WAF and firewall vendors keep pushing admin consoles onto the public internet.

Source: CSO Online

NoName057(16) relaunches #OpJapan DDoS campaign

Pro-Russian hacktivist collective NoName057(16) relaunched its #OpJapan DDoS campaign on August 24, citing Japan's support for Ukraine and NATO. The group claimed 66 attacks against 26 Japanese organizations in the first week, concentrating on maritime and logistics plus government portals. Its DDoSia platform mixes simple floods with targeted requests at costlier endpoints like search, contact forms, and login pages, and varies request details to defeat filtering. Activity has since shifted to a new #OpEstonia campaign.

The WAFplanet angle: the attack pattern is worth studying because it targets the operations layer that WAFs and DDoS protection are built to defend. Rate limiting and caching on expensive endpoints, plus strict connection and timeout policies, blunt these floods. This is exactly the workload best handled by a CDN or WAF that scrubs traffic before it reaches the origin, rather than letting the origin do all the work.

Source: Check Point

N-able N-central suffers back-to-back RMM exploits

Managed service provider platform N-able N-central shipped four hotfixes in under a week after a string of vulnerabilities. Researchers at Huntress disclosed an undocumented exploit chain bypassing access controls, then a separate max-severity unauthenticated RCE tracked as CVE-2026-86218 was found exploited in the wild. The platform's "Take Control" remote management makes it especially valuable to attackers, who can create unauthorized admin accounts and interact with internal APIs. On-premises customers remain exposed until they upgrade.

The WAFplanet angle: remote monitoring and management platforms are the keys to the kingdom for MSPs. An unauthenticated RCE on the management console hands attackers the same reach as the administrator. App-layer security helps only if it protects the management interface itself. Restrict inbound access to consoles with IP allowlisting or a VPN, and audit account creation and permission changes aggressively. Do not leave RMM interfaces broad-exposed to the internet.

Source: CSO Online

Akeyless ships real-time enforcement for AI agents

Akeyless announced general availability of Agentic Runtime Authority, a real-time identity control layer for AI agent actions. It runs on top of its SecretlessAI credential protection, which keeps credentials out of agents entirely. Runtime Authority evaluates agent actions in real time and blocks those that violate policy before they execute, giving teams a kill switch when an agent goes off script. New integrations cover Claude Enterprise, OpenAI Codex, and Amazon Bedrock AgentCore.

The WAFplanet angle: AI agents are becoming a whole new class of request origin, and a prompt-injected agent behaves like an authorized client with bad intent. Traditional access controls answer whether an agent can get in, not what it does once inside. Intent-based enforcement layered on short-lived identity brokering is a sensible model, and it mirrors how edge security moved from network trust to per-request verification. Expect agents, not browsers, to drive the next round of identity and access controls.

Source: Help Net Security

Also notable

WAFplanet take

Two themes defined this week. First, the security industry has started to find and fix vulnerabilities at machine speed, and patch volume is now so large that raw counts are meaningless. The real work is prioritization, and exposed management interfaces are the common thread across the most dangerous incidents. Second, adversaries keep aiming at the operations layer, DDoS campaigns targeting expensive endpoints and attackers going after management consoles rather than the applications behind them. Edge protection earns its keep when it scrubs this traffic before it reaches vulnerable infrastructure, and that case only gets stronger as agents become a new class of origin.

We also read

  • CrowdSec ships bot detection in its WAF for Nginx, with a browser-side proof-of-work and fingerprint challenge (CrowdSec)
  • DataDome named a sample vendor in the Gartner Hype Cycle for Application Security 2026 (DataDome)
  • Securing AI agents, key controls and best practices (CSO Online)
  • When the prompt becomes the payload, a pen-testing guide for GenAI, LLM and RAG applications (CSO Online)
  • Mars Security debuts an automated threat engine that turns live cyber intelligence into validated rules within minutes (CSO Online)
  • Reflectiz launches agentic pentesting for websites with up to 10x coverage versus conventional pentests (CSO Online)
  • Post-quantum API security, why enterprises need to start preparing now (Prophaze)
  • A roundup of the top DDoS protection providers in the USA for 2026 (Prophaze)
  • New CISO appointments in 2026 (CSO Online)