Skip to content

Response, New York. Noah Park: Check Point Patches Actively Exploited Management Server Path Traversal.

SOCtember.com

Always First. Fast SOC News.

Threat Intel

Threat intelligence and threat hunting as they inform daily security operations.

THREAT INTEL · SINGAPORE

Arista Confirms Actively Exploited VeloCloud Orchestrator Flaw

SINGAPORE - Arista Advisory 0183, published September 22, 2026 and revised to 1.1 on September 23, 2026, covers CVE-2026-93952 in the on-premises VeloCloud Orchestrator. The flaw was discovered externally and is actively exploited.

Priya Shah, Threat Intel, Singapore

Read the story
A technician at monitors in a data-center monitoring room. Not a photograph of an Arista or VeloCloud incident.
Photo: Derrick Coetzee

THREAT INTEL · SAN JOSE

Talos Documents CLOSEDQUORUM, Windows Implant That Lets AI Models Vote on C2 Moves

SAN JOSE - Cisco Talos researchers have documented CLOSEDQUORUM, which they describe as the first publicly reported Windows implant in their knowledge that uses a panel of commercial large language models as tactical command and control after deployment. The finding appears in a Talos blog by Ryan Fetterman dated Tuesday, September 22, 2026, and was uncovered with CAIRN, Talos' new open-source toolkit for tracking AI-integrated malware. Talos has not confirmed in-the-wild deployment.

Priya Shah, Threat Intel, Singapore

Read the story

Text desk note. No incident photograph.