HOT NEWS 2026 AUGUST January(174) February(168) March(221) April(222) May(261) June(255) July(405) August(446) September(6) October(0) November(0) December(0) | HOTNEWS 2026(1706) STATISTICS (7358)
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
|
31.8.26 |
HardBreacher | Kaspersky Antivirus For Endpoint ZeroDay Elevation of Privileges Vulnerability.So the problem is now leaking outside of Microsoft, there was poll held against either finding a bug in the home or commercial version and the poll results were the commercial version. | EXPLOIT | EXPLOIT |
|
31.8.26 |
BraZetsu | Group-IB uncovers BraZetsu, a new Python-based Windows malware that serves as a master toolkit for Initial Access Brokers and powers a unique, AI-enhanced underground marketplace for commercializing compromised Iberian and Latin American targets. | MALWARE | PYTHON |
|
31.8.26 |
Fire Ant | Fire Ant Evolves: From Hypervisors to Trusted Infrastructure | APT | APT |
|
31.8.26 |
CVE-2026-60004 | Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. | VULNEREBILITY | VULNEREBILITY |
|
31.8.26 |
CVE-2026-6876 | ServiceNow has remediated a sandbox escape security issue that was identified in the Now Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the Now Platform, potentially leading to more access to the Now Platform than intended. ServiceNow deployed a security update to hosted instances and ServiceNow provided the update to our partners and self-hosted customers. | VULNEREBILITY | VULNEREBILITY |
|
31.8.26 |
CVE-2026-74820 | ServiceNow has remediated a SQL injection vulnerability that was identified in in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary SQL statements against the instance's underlying database and gain access to, or modify, instance data beyond what was intended. | VULNEREBILITY | VULNEREBILITY |
|
31.8.26 |
CVE-2026-18886 | ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to create or modify instance data beyond what was intended, resulting in privilege escalation. | VULNEREBILITY | VULNEREBILITY |
|
31.8.26 |
CVE-2026-18885 | ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable an unauthenticated user, in certain circumstances, to execute arbitrary code in the ServiceNow platform and gain access to, or modify, instance data beyond what was intended. | VULNEREBILITY | VULNEREBILITY |
|
31.8.26 |
OpenAI – Hugging Face Incident Technical Report | In July 2026, during internal cybersecurity evaluations, OpenAI models in an internal evaluation environment circumvented controls intended to isolate them from the internet and performed computer network exploitation of OpenAI’s internal research infrastructure and Hugging Face systems. | REPORT | REPORT |
|
30.8.26 |
CVE-2026-76581 | (CVSS score: 9.8) - An authentication bypass flaw in the WPMU DEV Dashboard plugin that could allow an unauthenticated attacker, on sites connected to WPMU DEV with Hub Single-Sign On (SSO) enabled and mapped to an administrator, to obtain administrator access and achieve site takeover. (Affects all versions up to, and including, 5.0.1) | VULNEREBILITY | VULNEREBILITY |
|
30.8.26 |
CVE-2026-18431 | (CVSS score: 9.8) - An arbitrary file write flaw in the Avada theme for WordPress that makes it possible for an unauthenticated attacker to write attacker-controlled files to the server, which, in turn, can be exploited to create and execute arbitrary PHP files, resulting in remote code execution and complete site compromise. (Affects all versions up to, and including, 7.16, when the Fusion Builder plugin is installed and active in versions up to, and including, 3.16) | VULNEREBILITY | VULNEREBILITY |
|
30.8.26 |
CVE-2026-19632 | (CVSS score: 9.8) - A sensitive information exposure flaw in the "TranslatePress – Translate Multilingual sites with AI Translation" plugin that could allow an unauthenticated attacker to extract the raw administrator password-reset URL, including the plaintext reset key and login parameters, and enable full administrator account takeover. (Affects all versions up to, and including, 3.3.1 only when automatic string saving is enabled and the target administrator's profile locale is set to a published secondary language) | VULNEREBILITY | VULNEREBILITY |
|
30.8.26 |
CVE-2026-19598 | (CVSS score: 9.8) - A privilege escalation flaw in the "Pods – Custom Content Types and Fields" plugin that allows an unauthenticated attacker to escalate their privileges to Administrator or overwrite the password of any user account, including the site owner's, resulting in complete site takeover. (Affects all versions up to, and including, 3.3.9) | VULNEREBILITY | VULNEREBILITY |
|
30.8.26 |
CVE-2026-82222 | (CVSS score: 10.0) - A vulnerability in the GiveWP plugin that allows an attacker to execute arbitrary commands on the server of a GiveWP site that has one published donation form and one active payment gateway. (Affects all versions up to, and including, 4.16.7.1) | VULNEREBILITY | VULNEREBILITY |
|
29.8.26 |
CVE-2026-77554 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Talk Application to execute a Command Injection on the host device. | VULNEREBILITY | VULNEREBILITY |
|
29.8.26 |
CVE-2026-77550 | A malicious actor with access to the network could exploit an Improper Neutralization of CRLF Sequences vulnerability found in certain devices running UniFi OS to bypass authentication to such UniFi OS devices or instances. | VULNEREBILITY | VULNEREBILITY |
|
29.8.26 |
CVE-2026-77537 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device. | VULNEREBILITY | VULNEREBILITY |
|
29.8.26 |
CVE-2026-20896 | Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled. | VULNEREBILITY | VULNEREBILITY |
| 28.8.26 | HookEdge backdoor distributed by the BlueDelta threat group | Latest report from the Insikt Group researchers discusses recent malicious campaigns conducted by threat group BlueDelta (aka Forest Blizzard, or Fancy Bear) that have been targeting government, diplomatic, and defense manufacturing bodies in Romania, Spain, and Turkey. | ALERTS | APT |
| 28.8.26 | Unauthenticated RCE vulnerability in Apache Log4j2 (Issue 4255) | A newly disclosed vulnerability in Apache Log4j's FilteredObjectInputStream component enables unauthenticated remote code execution against services that receive serialized log events over a network connection. The unpatched flaw affects log4j-core 2.8.0 through 2.26.1 and log4j-api 2.11.0 through 2.26.1, and is limited to applications using Log4j's serialized log-event network receivers rather than to all Log4j deployments. | ALERTS | VULNEREBILITY |
| 28.8.26 | WeedHack Malware via SEO Poisoning | McAfee Labs has published a report on a campaign distributing WeedHack, a Malware-as-a-Service infostealer and remote access tool targeting Minecraft players. The attackers use SEO poisoning and YouTube videos to push malicious clone sites above official repositories on search engines, tricking gamers searching for popular clients and modifications like Xenon or Radium. | ALERTS | VIRUS |
| 28.8.26 | GoCaracal and Bandook Malware Target Communications Sector | Arctic Wolf has published a report on a new modular malware framework called GoCaracal, deployed by the cyberespionage group Dark Caracal. The threat actors have been observed targeting the communications sector in Venezuela and other parts of Latin America. The attack begins with financial-themed phishing emails containing weaponized SVG attachments, which initiate a sequence to download a lightweight GoCaracal executable to establish initial system access. | ALERTS | VIRUS |
| 28.8.26 | TwoStroke backdoor distributed by the Tortoiseshell threat group | Group-IB’s threat research into the IRGC-affiliated Iranian actor Tortoiseshell (aka Mirage Kitten, Nimbus Manticore) indicates broadened cyber campaigns extending across Europe and the Middle East. Tortoiseshell typically breaches defense, aerospace, military, and technology organizations using watering-hole attacks, supply-chain exploits, and fraudulent recruitment portals. | ALERTS | VIRUS |
| 28.8.26 | SparkRAT malware targets Cambodia in a recent campaign | Acronis’ researchers reported on a recent cyber campaign targeting entities across Cambodia using varied decoy materials, such as official state advisories, medical records or commercial promotions. The attack sequence initiates through an Inno Setup installer that triggers a legitimate Tencent binary, and performs DLL side-loading. The malicious loader subsequently retrieves and decrypts hidden shellcode embedded within PNG images. | ALERTS | VIRUS |
| 28.8.26 | CVE-2026-18885 | (CVSS score: 10.0) - A code injection vulnerability in the GraphQL Composite Data API that could enable an unauthenticated user to execute arbitrary code and gain access to, or modify, instance data | VULNEREBILITY | VULNEREBILITY |
| 28.8.26 | CVE-2026-18886 | (CVSS score: 10.0) - An improper access control vulnerability in the system configuration image upload processor that could enable an unauthenticated user to create or modify instance data, resulting in privilege escalation | VULNEREBILITY | VULNEREBILITY |
| 28.8.26 | CVE-2026-74820 | (CVSS score: 10.0) - A SQL injection vulnerability reached through a dynamic schema ORDER BY clause that could enable an unauthenticated user to execute arbitrary SQL statements against the instance's underlying database | VULNEREBILITY | VULNEREBILITY |
| 28.8.26 | CVE-2026-6876 | ServiceNow has remediated a sandbox escape security issue that was identified in the Now Platform. This security issue could allow an unauthenticated user to execute arbitrary code within the Now Platform, potentially leading to more access to the Now Platform than intended. | VULNEREBILITY | VULNEREBILITY |
| 28.8.26 | Zbtlink MQWrt infosrvd Command Injection | Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE2426-C firmware 19.1112, Zbtlink WE5926-EC_QP firmware 20.0516, Zbtlink WF3526-P firmware 19.051, | VULNEREBILITY | VULNEREBILITY |
| 28.8.26 | Zbtlink MQWrt yunmgrd Cloud C2 Implant | Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink ZBT-ZBT7621 firmware 1.0.0.3.001, MoreQuick MQAC-7620, MQAC-7620A, MQAP-7620, MQAP-7620A, and MQAP-7628 firmware 1.0.0.2.000, | VULNEREBILITY | VULNEREBILITY |
| 28.8.26 | CVE-2023-49105 | ownCloud Improper Authentication Vulnerability | KEV | KEV |
| 28.8.26 | CVE-2026-53362 | Linux Kernel Unspecified Vulnerability | KEV | KEV |
| 28.8.26 | CVE-2026-66384 | JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability | KEV | KEV |
| 28.8.26 | CVE-2026-65643 | Security: CVE-2026-65643 Vulnerability in cPanel’s Domain Parking Functionality - August 27, 2026 | VULNEREBILITY | VULNEREBILITY |
| 28.8.26 |
BlueDelta Targets Defense and Diplomacy with HOOKEDGE |
Insikt Group identified Russian statesponsored group BlueDelta (APT28) targeting government, diplomatic, anddefense organizations in Romania, Spain, and Türkiye between September 2025 and April 2026 | REPORT | REPORT |
| 28.8.26 | BlueDelta | BlueDelta Targets Defense and Diplomacy with HOOKEDGE | GROUP | GROUP |
| 28.8.26 | CISA Vulnerability Review Fiscal Years 2024 and 2025 | Cybersecurity conversations often focus on high-profile incidents involving nation-state adversaries, ransomware groups, and other sophisticated threat actors. However, most compromises have not relied on advanced techniques. They exploited simple, known software vulnerabilities that remain widespread and persistent in publicly exposed assets. Increasingly, cyber threat actors are using artificial intelligence (AI) to automate all the steps necessary to exploit these vulnerabilities. | REPORT | REPORT |
| 28.8.26 | CVE-2026-66384 | JFrog Artifactory Improper Limitation of a Pathname to a Restricted Directory Vulnerability: JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions. | ECV | ECV |
| 28.8.26 | CVE-2026-53362 | Linux Kernel Unspecified Vulnerability: Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux. | ECV | ECV |
| 28.8.26 | CVE-2023-49105 | ownCloud Improper Authentication Vulnerability: ownCloud contains an improper authentication vulnerability that allows an attacker to access, modify, or delete any file without authentication if the username of a victim is known, and the victim has no signing-key configured. | ECV | ECV |
| 28.8.26 | CVE-2019-1068 | Microsoft SQL Server Remote Code Execution Vulnerability: Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account. | ECV | ECV |
| 28.8.26 | CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability: Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service. | ECV | ECV |
| 28.8.26 | CVE-2022-0995 | Linux Kernel Out-of-Bounds Write Vulnerability: Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system. | ECV | ECV |
| 28.8.26 | CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability: Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. | ECV | ECV |
| 28.8.26 | CVE-2015-3246 | Red Hat Libuser Race Condition Vulnerability: Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation. | ECV | ECV |
| 28.8.26 | CVE-2021-23758 | Ajax.NET Professional Deserialization of Untrusted Data Vulnerability: Ajax.NET Professional (AjaxPro) contains a deserialization of untrusted data vulnerability that could allow for remote code execution via arbitrary .NET classes. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. | ECV | ECV |
| 28.8.26 | CVE-2026-60004 | Gitea Code Injection Vulnerability: Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account. | ECV | ECV |
| 28.8.26 | CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in contain an improper access control vulnerability that can result in unauthorized creation, deletion or modification access to critical data as well as unauthorized access to critical data or complete access to all Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in accessible data. | ECV | ECV |
| 28.8.26 | Threat landscape for industrial automation systems. Q2 2026 | In this section, we examine the most significant changes to indicators over the quarter, broken down by region and industry. Further diagrams can be found in the relevant chapters of the “Statistics across all threats” section. | REPORT | REPORT |
| 28.8.26 | CVE-2026-35603 | CVE-2026-35603: One Writable Folder, Every User Compromised: Exploiting Configuration Trust in AI Coding Tools | VULNEREBILITY | VULNEREBILITY |
| 28.8.26 | CVE-2026-75604 | Unauthenticated Remote Code Execution on windows-hosted servers | VULNEREBILITY | VULNEREBILITY |
| 28.8.26 | Drive-By Agent Hijacking | Drive-By Agent Hijacking: One Website Visit, Persistent Model Poisoning | HACKING | AI |
| 28.8.26 | Power Leak | Power Leak: Amazon Kiro IDE Prompt Injection Enables Data Exfiltration | HACKING | AI |
| 28.8.26 | Spark RAT | Cambodia-focused cluster uses multistage infection chain with localized lures | MALWARE | RAT |
| 28.8.26 | Dark Caracal | During a targeted intrusion investigation, Arctic Wolf uncovered GoCaracal, a previously undocumented, modular framework written in Go. Its long-term development offers new insight into the evolution of Dark Caracal’s capabilities, operations, and tradecraft. | MALWARE | GO |
| 27.8.26 | GPUThor: Amplifying Rowhammer Attacks via Non-Uniform Patterns to Exploit ECC-Protected GPUs | GDDR memory in GPUs is vulnerable to Rowhammer attacks, where rapid memory accesses induce bit flips in adjacent cells,enabling data tampering and privilege escalation. However, prior GPU Rowhammer attacks trigger only tens to hundreds of bit flips,orders of magnitude fewer than CPU attacks, severely limiting their practical impact. This gap stems from the reliance of existingGPU Rowhammer attacks on uniform hammering patterns that activate aggressor and dummy rows equally, which results in low hammering intensity for aggressor rows. | PAPERS | PAPERS |
| 27.8.26 | CVE-2015-3246 | Red Hat Libuser Race Condition Vulnerability | KEV | KEV |
| 27.8.26 | CVE-2015-5287 | Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability | KEV | KEV |
| 27.8.26 | CVE-2019-1068 | Microsoft SQL Server Remote Code Execution Vulnerability | KEV | KEV |
| 27.8.26 | CVE-2021-23758 | Ajax.NET Professional Deserialization of Untrusted Data Vulnerability | KEV | KEV |
| 27.8.26 | CVE-2022-0995 | Linux Kernel Out-of-Bounds Write Vulnerability | KEV | KEV |
| 27.8.26 | CVE-2026-8452 | Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability | KEV | KEV |
| 27.8.26 | USPS Smishing Kit | The Package That Never Shipped: Following a USPS Smishing Kit Through Censys DNS Data | PHISHING | KIT |
| 27.8.26 | Tortoiseshell | Tortoiseshell: New Toolset and Operational Infrastructure Exposed | OPERATION | OPERATION |
| 27.8.26 | China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems | The Federal Bureau of Investigation, National Security Agency, and Cyber National Mission Force are releasing this joint cybersecurity advisory to alert organizations concerning China-linked cyber threat actors, who use the acronyms QTFY, QT, and QTCYBER for themselves and their tools and have developed malicious distributed platforms to compromise the networks of US and foreign organizations. | REPORT | REPORT |
| 27.8.26 | DOUBLOON DREDGER | DOUBLOON DREDGER token harvesting: Notion abuse, EvilTokens, and a side of Tycoon2FA | PHISHING | KIT |
| 27.8.26 | Matrix | Introducing Matrix: A Microsoft 365 AiTM Platform Overlapping the Sneaky2FA Lineage | PHISHING | KIT |
| 27.8.26 | iAuthFlow v2 | iAuthFlow v2 Enrolls Google Passkeys That Survive Password Resets | PHISHING | KIT |
| 27.8.26 | ARToken | ARToken: The Device Code Phishing Platform Built for Full Microsoft 365 Takeover | PHISHING | KIT |
| 27.8.26 | LinXcoded (Mirage2FA) | LinXcoded (Mirage2FA): Microsoft 365 Phishing Platform Uses HTML Attachments to Steal Post-MFA Sessions | PHISHING | KIT |
| 27.8.26 | Blacksite | Blacksite: New AiTM Phishing Kit Evades URL Scanners via Cloaked.gg | PHISHING | KIT |
| 27.8.26 | ZeroTokens | ZeroTokens: Phishing Platform Gives Operators Real-Time Control of Attack Flow | PHISHING | KIT |
| 27.8.26 | Meet Bluekit | Meet Bluekit: The AI-Powered All-in-One Phishing Kit | PHISHING | KIT |
| 27.8.26 | NovaCookies | NovaCookies at scale: Inside the $320 Phishing Service Targeting Hundreds of Organizations | PHISHING | KIT |
| 26.8.26 | Vercel-hosted RMM attacks | As ANY.RUN analysis shows, a campaign that initially appears to target Canadians with fake Canada Revenue Agency (CRA) T4 tax documents is actually part of a much broader remote-access campaign spanning 46 countries, with 45% of observed activity associated with the United States. | CAMPAIGN | CAMPAIGN |
| 26.8.26 | Balonx Sistema | Group-IB exposes a Mexican PhaaS operation targeting over 20 financial institutions with live phishing, AI vishing, and mobile RAT capabilities. | PHISHING | PHaaS |
| 26.8.26 |
A Tale of Two SOCs: Insights From Two Red Team Assessments |
The Cybersecurity and Infrastructure Security Agency’s (CISA’s) red team simulates real‑world maliciouscyber operations to assess an organization’s ability to detect, investigate, and respond to malicious cyberactivity. Emulating cyber threat actor tradecraft, the red team attempts to gain and maintain persistentaccess to an organization’s network and sensitive business systems (SBSs) while avoiding detection. | REPORT | REPORT |
| 26.8.26 | SynkLoader Distributed via Teams | Researchers at Expel recently reported a new malware family dubbed SynkLoader, which utilizes a modular architecture bridging multiple programming languages to evade detection. Threat actors initiate the compromise via Microsoft Teams phishing, masquerading as internal IT personnel to persuade victims to download a malicious MSI installer hosted on an Azure endpoint. | ALERTS | VIRUS |
| 26.8.26 | PavinLoader Emerges as Loader-as-a-Service Delivering Information Stealers | A new campaign documented by Malwarebytes details the widespread deployment of PavinLoader across ClickFix social engineering lures, trojanized game releases, and fake software downloads. Operating as a potential Loader-as-a-Service, PavinLoader uses initial vector lures such as fake CAPTCHA prompts or Dropbox-hosted installers to execute malicious scripts or batch files on victim systems. | ALERTS | VIRUS |
| 26.8.26 | RedC2 AI-Powered Linux Implant | TrendAI identified a supply-chain campaign where deceptive npm packages masquerade as legitimate date and calendar utilities. Simply importing one of these compromised dependencies triggers an embedded Linux ELF binary to execute as an independent background process. The embedded payload, known as RedShell, functions as a Linux beacon for the commercial RedC2 4.0 command-and-control framework. | ALERTS | AI |
| 26.8.26 | Vidar infostealer distributed under the disguise of a Gemini installer | Darktrace recently analyzed an incident where users seeking a desktop version of Google Gemini installer could inadvertently download the Vidar infostealer variant instead. The attack leveraged search-driven discovery, leading the user to a Google Colab notebook that served a fraudulent executable. Once launched, this Go-based variant of Vidar would begin harvesting sensitive data from the compromised endpoint and attempt outbound communication with Telegram-based command-and-control infrastructure controlled by the attackers. | ALERTS | VIRUS |
| 26.8.26 | Kynx Stealer | A new malware family documented by SOCRadar reveals the growing intersection of artificial intelligence and credential theft. Dubbed Kynx, this C++-based Malware-as-a-Service is believed to be distributed through cracked software or fake update lures, displaying a deceptive system update progress bar upon initial execution. | ALERTS | VIRUS |
| 26.8.26 | Manic Android Threat Observed in Ukraine | ThreatFabric has recently identified a new Android malware family dubbed Manic that functions as a hybrid banking trojan and surveillance tool. The malware primarily targets financial institutions, government identity services, and messaging applications in Ukraine, with secondary victims across Europe and Russia. | ALERTS | VIRUS |
| 26.8.26 | ToxicPanda 2.0 Refines Overlay Attacks and Abuse of Accessibility Services | Researchers at Zimperium recently reported on ToxicPanda 2.0, an upgraded version of the Android banking Trojan with a significantly expanded global operational footprint. The threat targets over 340 banking, cryptocurrency, and e-wallet applications across 16 countries, abusing Android Accessibility Services to automate malicious actions and steal sensitive credentials. | ALERTS | VIRUS |
| 26.8.26 | RubyGems Supply Chain Attack Deploys Stealer | A campaign documented by OpenSourceMalware exposes a RubyGems supply chain attack dubbed StubMaker, targeting Windows developer environments. The actor published typosquats of high-traffic dependencies, weaponizing extconf.rb to execute code at install time while writing fake compiler stubs so the native extension phase reports a clean build. | ALERTS | HACKING |
| 26.8.26 | Core Werewolf Deploys Custom CoreRAT Malware | According to BI.ZONE, a previously undocumented RAT dubbed CoreRAT is being deployed by the Core Werewolf espionage actor against Russia's public sector and defense industry, observed June–July 2026 and traced back to at least March 2026. Initial access comes via phishing messages on Telegram delivering 7zSFX or Rust droppers named after military and government paperwork. | ALERTS | VIRUS |
| 26.8.26 | Disrupting a new covert influence campaign from Russia | Our mission is to ensure that artificial general intelligence benefits all of humanity. We advance this mission by deploying our innovations to build AI tools that help people solve hard problems. This includes building tools that enable us to detect, investigate, disrupt and expose covert influence operations (IO): deceptive attempts to manipulate public opinion or influence political outcomes without revealing the true identity or intentions of the actors behind them. | CAMPAIGN | CAMPAIGN |
| 26.8.26 | CVE-2026-19912 | Unauthenticated RCE via PHP object injection + path traversal | VULNEREBILITY | VULNEREBILITY |
| 26.8.26 | CVE-2026-19913 | Unauthenticated arbitrary file read. | VULNEREBILITY | VULNEREBILITY |
| 26.8.26 | Anatomy of a Frontier Lab Agent Intrusion: A Technical Timeline of the July 2026 Incident | A companion technical writeup to our incident disclosure. This post walks through how the intrusion actually worked: the two initial-access vectors, how the agent pivoted and moved laterally, representative examples of the commands that were run and how we investigated with GLM 5.2 (an open-source model). Live credentials, internal hostnames, and specific indicators have been redacted or genericized, while the techniques are described exactly as observed by Hugging Face. | INCIDENT | INCIDENT |
| 26.8.26 | Remote Code Execution and Arbitrary File Read Vulnerabilities in Kaltura Servers | The Kaltura HTML5 Player Library (mwEmbed / html5lib) contains two vulnerabilities, both involving the same insecure deserialization flaw, that enable arbitrary file read and remote code execution. Affected versions include html5lib v2.45, v2.103 and earlier, and other v2.x releases that expose the vulnerable mwEmbedLoader.php endpoint. Until a vendor patch is available, users are advised to restrict access to the affected endpoint or disable it entirely. | ALERT | ALERT |
| 26.8.26 | CVE-2026-60004 | Gitea Code Injection Vulnerability | KEV | KEV |
| 26.8.26 | CVE-2026-60004 | Gitea Code Injection Vulnerability | VULNEREBILITY | VULNEREBILITY |
| 26.8.26 | p1bot | Inside p1bot: A Vishing Platform Weaponizing ElevenLabs | PHISHING | VISHING |
| 26.8.26 | AnonyMousKIT | Exposing AnonyMousKIT: AI-Powered PhaaS Supply Chain | PHISHING | PHaaS |
| 26.8.26 | SLEEPWALKER | SLEEPWALKER: A Passive Backdoor With Its Own Command Language | MALWARE | BACKDOOR |
| 25.8.26 | Early Cascade Injection: From Windows Process Creation to Stealthy Injection | In this blog post we introduce a novel process injection technique named Early Cascade Injection, explore Windows process creation, and identify how several Endpoint Detection and Response systems (EDRs) initialize their in-process detection capabilities. | HACKING | WINDOWS |
| 25.8.26 | CVE-2026-75149 | marimo before 0.23.15 contains a code injection vulnerability in the notebook configuration handler that allows attackers to execute arbitrary commands by supplying a crafted MCP server entry with an attacker-controlled command value embedded in a notebook. | VULNEREBILITY | VULNEREBILITY |
| 25.8.26 | EarlyBird Technique: An Advanced Malware Evasion Strategy | As of recent advancements, malware authors are leveraging artificial intelligence (AI) and machine learning (ML) to dynamically alter their evasion techniques. This means that malware can now adapt in real-time to changes in security environments, such as modifications in antivirus software or intrusion detection systems, making traditional static signature-based defences increasingly ineffective. | HACKING | MALWARE |
| 25.8.26 | CVE-2026-61979 | (CVSS score: 8.1) - An unauthenticated privilege escalation vulnerability stemming from signature algorithm confusion (Fixed in version 17.0.5 for the Standard edition) | VULNEREBILITY | VULNEREBILITY |
| 25.8.26 | CVE-2026-15981 | (CVSS score: 9.8) - An authentication bypass vulnerability stemming from accepting malformed signatures as valid (Fixed in version 17.0.6 for the Standard edition) | VULNEREBILITY | VULNEREBILITY |
| 25.8.26 | CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability | KEV | KEV |
| 25.8.26 | CVE-2026-21962 | Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability | VULNEREBILITY | VULNEREBILITY |
| 24.8.26 | Konami's Metal Gear Online 3 contains a heap-based buffer overflow | Konami's Metal Gear Online 3 video game contains a heap-based buffer overflow that can be triggered by an input‑validation vulnerability that allows match hosts to remotely execute arbitrary code on lobby members' machines through specially crafted data. | ALERT | ALERT |
| 24.8.26 | CVE-2026-13757 | A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit when processing nested CKA_WRAP_TEMPLATE, CKA_UNWRAP_TEMPLATE, and CKA_DERIVE_TEMPLATE attributes. | VULNEREBILITY | VULNEREBILITY |
| 24.8.26 | CVE-2026-17048 | A flaw was found in the Keycloak Admin REST API, which is used to manage security realms and clients. The issue occurs when the system processes requests for rotated client secrets that are stored in a secure vault. | VULNEREBILITY | VULNEREBILITY |
| 24.8.26 | CVE-2026-15571 | A flaw was found in the legacy client-initiated account-linking endpoint of Keycloak, a widely used open-source identity and access management solution. | VULNEREBILITY | VULNEREBILITY |
| 24.8.26 | Enterprise AI Usage Risk Report 2026 | When the State of the Internet/Security report first analyzed the emerging artificial intelligence (AI) landscape in early 2025, enterprise adoption was largely characterized by caution and curiosity; today, it is a structural mandate. What began as sporadic experimentations with ChatGPT has evolved into a sprawling ecosystem of AI assistants, AI browsers, AI agents, AI extensions, and autonomous workflows that touch every aspect of enterprise work. | REPORT | REPORT |
| 24.8.26 | CVE-2026-14613 | A vulnerability was discovered in Keycloak's administrative interface that allows certain administrators to see information about groups they shouldn't have access to. When the new Fine-Grained Admin Permissions (FGAP v2) are turned on, an administrator who is allowed to see a specific "role" can also see a list of all groups assigned to that role. | VULNEREBILITY | VULNEREBILITY |
| 24.8.26 | CVE-2026-9796 | A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This allows the attacker to escalate their privileges to `realm-admin` for all users within the realm, granting them extensive control over the system. | VULNEREBILITY | VULNEREBILITY |
| 24.8.26 | CVE-2026-18963 | A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red Hat Build of Keycloak. | VULNEREBILITY | VULNEREBILITY |
| 24.8.26 | WordlistLoader | WordlistLoader Delivering Amatera via ClearFake Campaigns | MALWARE | LOADER |
| 24.8.26 | ClearFake | ClearFake gets more evasive with new living off the land (LOTL) techniques | CAMPAIGN | CAMPAIGN |
| 24.8.26 | Amatera Stealer 4.0.2 | Amatera Stealer 4.0.2 Beta: What's New in This Variant | MALWARE | STEALER |
| 24.8.26 | Heaven's Gate | Heaven’s Gate is a malware technique that hides dangerous 64-bit code inside seemingly harmless 32-bit processes. This clever trick makes it much harder for security tools to catch malware in action, giving attackers a major advantage in the cyber cat-and-mouse game | HACKING | MALWARE |
| 24.8.26 | UAT-10147 | deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities | GROUP | GROUP |
| 24.8.26 | UAT-10147 | Chinese-speaking adversary integrates agentic AI into post-compromise operations | GROUP | GROUP |
| 23.8.26 | CVE-2025-55241 | Azure Entra ID Elevation of Privilege Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
23.8.26 |
CVE-2026-65770 | Improper neutralization of argument delimiters in a command ('argument injection') in Azure Managed Instance for Apache Cassandra allows an unauthorized attacker to execute code over a network. | VULNEREBILITY | VULNEREBILITY |
| 23.8.26 | CVE-2026-65801 | Server-side request forgery (ssrf) in Microsoft Exchange Online allows an unauthorized attacker to elevate privileges over a network. | VULNEREBILITY | VULNEREBILITY |
|
23.8.26 |
CVE-2026-69555 | Incorrect authorization in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | VULNEREBILITY | VULNEREBILITY |
| 23.8.26 | SynkLoader | SynkLoader: when you throw in everything but the kitchen sink | MALWARE | LOADER |
|
23.8.26 |
CVE-2026-65816 | Use of incorrectly-resolved name or reference in Azure Arc allows an unauthorized attacker to elevate privileges over a network. | VULNEREBILITY | VULNEREBILITY |
| 23.8.26 | SmartApeSG ClickFix campaign leads to two RATs | Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website. | MALWARE TRAFFIC | MALWARE TRAFFIC |
| 23.8.26 | CVE-2026-3055 | Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread | VULNEREBILITY | VULNEREBILITY |
|
23.8.26 |
CVE-2026-4368 | Race Condition in NetScaler ADC and NetScaler Gateway when appliance is configured as Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server leading to User Session Mixup | VULNEREBILITY | VULNEREBILITY |
|
22.8.26 |
CVE-2025-60710 | Improper link resolution before file access ('link following') in Host Process for Windows Tasks allows an authorized attacker to elevate privileges locally. | VULNEREBILITY | VULNEREBILITY |
| 22.8.26 | Cisco Crosswork Security Hardening Release: August 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered | VULNEREBILITY | VULNEREBILITY |
| 22.8.26 | PlikanLocker Ransomware | Point Wild Threat Intelligence has recently identified a new .NET-based ransomware strain named PlikanLocker that blends file extortion with aggressive endpoint lockdown tactics. Distributed primarily through phishing attachments, malicious links, and social media lures, the malware targets general Windows environments by securing administrator rights via UAC prompts. | ALERTS | RANSOM |
|
22.8.26 |
Threat Actors Deploy WordlistLoader in Latest Amatera Attacks | Researchers at Gen Threat Labs recently reported a new malware family called WordlistLoader, which threat actors are utilizing to deliver the Amatera infostealer to a wide range of victims. According to their analysis, the attack begins on legitimate but compromised websites where visitors encounter a fake CAPTCHA prompt as part of a ClearFake campaign. | ALERTS | VIRUS |
|
22.8.26 |
Mirage2FA Campaigns | ANY.RUN has published a report on Mirage2FA, a commercial phishing-as-a-service (PhaaS) kit operated by LinX Coders that has been active between September 2024 and July 2026. | ALERTS | CAMPAIGN |
|
22.8.26 |
Grandoreiro Banking Trojan Resurfaces With DLL Sideloading Campaign in Mexico | In a recent write-up, Acronis details a campaign demonstrating the geographic expansion of the Grandoreiro banking trojan from South America into Mexican financial, logistics, and industrial sectors. Distributed through tax- and invoice-themed phishing emails containing malicious ZIP archive attachments or direct download links, the attack chain lures victims into executing a heavily padded installer binary. | ALERTS | VIRUS |
|
22.8.26 |
Threat Group UAT-10147 Deploys SPECTRE Backdoor and Linux Rootkits | Researchers at Cisco Talos recently reported on malicious campaigns conducted by the Chinese-speaking threat group UAT-10147 targeting Linux and Windows web servers across government, education, technology, media, and gaming sectors worldwide. | ALERTS | APT |
| 22.8.26 | AmnesiaStealer - a macOS infostealer written in Rust | Jamf Threat Labs researchers recently reported on AmnesiaStealer, an advanced multi-stage macOS malware written in Rust. Threat actors have been distributing this malware via "ClickFix" social engineering tactics, leveraging deceptive GitHub download pages. Once executed, the stealer extracts system passwords using native-looking prompts, exfiltrates Keychain data, and sweeps local storage for sensitive files, Apple Notes, and Telegram sessions. | ALERTS | VIRUS |
|
22.8.26 |
QUARTERLY THREAT LANDSCAPE REPORT The compression era: Q2
2026 has showed that traditional patch cycles are overwhelmed |
Q2 2026 was not just another busy quarter in cyber. It felt more like a stress test of the way we currently manage exposure. Traditional patch cycles are being overwhelmed by the sheer volume of vulnerabilities and attacker speed and precision. | REPORT | REPORT |
| 21.8.26 | Operation QUICSILVER | Contents Introduction Key Targets Industries Affected Geographical focus Infection Chain Campaign Timeline Initial Findings Looking into the Decoy Document Technical Analysis Stage 1 | OPERATION | OPERATION |
| 21.8.26 | CVE-2021-24092 | Microsoft Defender Elevation of Privilege Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
21.8.26 |
Calix GS7 XGS GS5239XG residential router contains missing authentication vulnerability | The Calix GS7 XGS GS5239XG router running firmware EXOS/6.6.47 contains a missing authentication vulnerability that exposes its UPnP (Universal Plug and Play) WANIPConnection service on the public WAN interface. | ALERT | ALERT |
| 21.8.26 | CVE-2026-72529 | TrueConf Server Missing Authentication for Critical Function Vulnerability | KEV | KEV |
| 21.8.26 | CVE-2026-72530 | TrueConf Server Code Injection Vulnerability | KEV | KEV |
|
21.8.26 |
CVE-2026-69836 | Microsoft Entra ID Remote Code Execution Vulnerability | VULNEREBILITY | VULNEREBILITY |
| 21.8.26 | Defending Against an Active Threat to Siemens S7 Series PLCs | This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape. | ICS | ICS |
|
20.8.26 |
Zero-click Grok data theft | Zero-click Grok data theft: Cryptographic Context Injection attack leaks chat histories | INCIDENT | INCIDENT |
|
20.8.26 |
Bypassing Prompt Guards in Production with Controlled-Release Prompting | Ball et al. recently established that prompt filtering for AI alignment faces a fundamental barrier: under standard cryptographic assumptions, no filter running significantly faster than the protected model can universally distinguish adversarial prompts from benign ones. We investigate whether this impossibility result translates to real-world vulnerabilities in deployed large language model (LLM) systems. | PAPERS | PAPERS |
|
20.8.26 |
Cryptographic Payload Injection | Cryptographic Payload Injection: A Novel Jailbreak Technique Against Gemini | HACKING | AI |
|
20.8.26 |
CVE-2026-19490 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. | VULNEREBILITY | VULNEREBILITY |
|
20.8.26 |
CVE-2026-19489 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. | VULNEREBILITY | VULNEREBILITY |
|
20.8.26 |
CVE-2026-73570 | A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user. | VULNEREBILITY | VULNEREBILITY |
|
20.8.26 |
RDK-B WebUI contains multiple vulnerabilities | RDK Central RDK-B WebUI version, rdkb-2025q4-kirkstone, contains multiple vulnerabilities involving memory corruption, improper authentication, race conditions, and insufficient input validation. | ALERT | ALERT |
|
20.8.26 |
CVE-2026-64849 | MLflow Server-Side Request Forgery Vulnerability | KEV | KEV |
|
20.8.26 |
Zombie Credit Cards Attack | When Zombie Credit Cards Attack: UMass Researchers Discover Loophole That Can Reanimate Expired Cards | HACKING | HACKING |
|
20.8.26 |
XRING | XRING: Crashing XQUIC with spec-compliant QPACK instructions | HACKING | HACKING |
|
20.8.26 |
CDN Tsunami:
Exploiting HTTP/3-HTTP/1.1 Conversion for DoS Attacks |
Content Delivery Networks (CDNs) provide high availability, accelerate content delivery for their host websites, but are also vulnerable to different types of Denial-of-Service (DoS) attacks. Prior works have studied a variety of DoS attacks with HTTP/1.1 or HTTP/2 connections, but most of them are being fixed, making CDNs robust against such attacks. | PAPERS | PAPERS |
|
20.8.26 |
Manic | Manic: Blend between Banking Malware & Spyware | MALWARE | BANKING |
|
20.8.26 |
ToxicPanda | The ToxicPanda Never Sleeps: ToxicPanda 2.0 Prepares its Next Strike on Mobile | MALWARE | ANDROID |
|
20.8.26 |
GoldDigger | Striking gold: Inside the GoldDigger Android malware | MALWARE | ANDROID |
|
20.8.26 |
CVE-2026-69414 | Microsoft Defender Elevation of Privilege Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
20.8.26 |
CVE-2026-32475 | Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1. | VULNEREBILITY | VULNEREBILITY |
|
20.8.26 |
Dynamic Process Isolation | In the quest for efficiency and performance, edgecomputing providers eliminate isolation boundaries between tenants, such as strict process isolation, and instead let them compute in a more lightweight multi-threaded single-process design. Edgecomputing providers support a high number of tenants per machine to reduce the physical distance to customers without requiring a large number of machines. Isolation is provided by sandboxing mechanisms, e.g., tenants can only run sandboxed V8 JavaScript code. | PAPERS | PAPERS |
|
20.8.26 |
Remote-Timer-as-a-Service: Efficient Microarchitectural Leakage in the Cloud with Remote Timers |
Edge computing solutions have become a crucial part of the industry, delivering fast, flexible and scalable applications close to the end users, with typical use cases including dynamic content creation, image resizing and chatbots. Cloudflare Workers is onesuch framework, which handles millions of HTTP requests per second across the world. | PAPERS | PAPERS |
|
20.8.26 |
Cisco Crosswork Security Hardening Release: August 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. | VULNEREBILITY | VULNEREBILITY |
|
20.8.26 |
Cisco Secure Workload Software Security Hardening Release: August 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. | VULNEREBILITY | VULNEREBILITY |
|
20.8.26 |
Cisco BroadWorks Out-of-Band Blind XML External Entity Injection Vulnerability | A vulnerability in the Open Client Interface (OCI) XML Parser of Cisco BroadWorks could allow an unauthenticated, remote attacker to read sensitive configuration information on an affected system. | VULNEREBILITY | VULNEREBILITY |
|
20.8.26 |
Cisco Unified Intelligence Center SQL Injection Vulnerability | A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated, local attacker to perform a blind SQL injection attack against an affected device. | VULNEREBILITY | VULNEREBILITY |
|
20.8.26 |
Cisco RoomOS Stack Overflow Vulnerability | A vulnerability in the USB driver of Cisco RoomOS could allow an unauthenticated, local attacker with physical access to the USB port on an affected device to execute arbitrary code with root privileges. | VULNEREBILITY | VULNEREBILITY |
|
20.8.26 |
Cisco Industrial Ethernet 1000 Series Switches Stored Cross-Site Scripting Vulnerability | A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. | VULNEREBILITY | VULNEREBILITY |
|
20.8.26 |
Cisco Industrial Ethernet 1000 Series Switches Denial of Service Vulnerability | A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an unauthenticated, remote attacker to cause the device manager, SSH, or API to become inaccessible. | VULNEREBILITY | VULNEREBILITY |
|
20.8.26 |
Cisco Packaged Contact Center Enterprise and Cisco Unified Contact Center Enterprise Server-Side Request Forgery Vulnerability | A vulnerability in Cisco Packaged Contact Center Enterprise (Packaged CCE) and Cisco Unified Contact Center Enterprise (Unified CCE) could allow an authenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device. | VULNEREBILITY | VULNEREBILITY |
|
19.8.26 |
StealNui - a new Linux RAT variant | Security researchers at ExaTrack report on StealNui, an emerging C++-based Remote Access Trojan (RAT) crafted for Linux platforms. The malware provides operators with extensive espionage and surveillance functionality. Its toolkit includes screen capture utilities, a keystroke logger, reverse shell access, local file exfiltration, and arbitrary remote command execution and a cryptocurrency clipper module. | ALERTS | VIRUS |
|
19.8.26 |
JWR PhaaS | In a recent write-up, Cisco Talos details an undocumented phishing framework dubbed JWR, which is built to impersonate major payment and e-commerce platforms. Delivered primarily through SMS lures disguised as postal and toll authorities in Southeast Asia and the Middle East, the framework operates as a highly interactive, real-time threat rather than a static credential harvester. | ALERTS | PHISHING |
|
19.8.26 |
QUICAgent Backdoor Hidden in VHD Lures | Researchers at Seqrite recently reported a campaign orchestrated by a China-nexus threat actor targeting Myanmar's government and IT sectors. Dubbed Operation QUICSILVER, the attacks single out diplomats and officials by using deceptive Burmese-language graduation ceremony invitations packaged inside Virtual Hard Disk (VHD) files. | ALERTS | VIRUS |
|
19.8.26 |
Lucid Stealer malware | Lucid Stealer is a sophisticated information-harvesting malware variant promoted through Telegram that masquerades as a legitimate Node.js JavaScript runtime. Upon execution, the malware deploys native modular components to conduct data harvesting operations. | ALERTS | VIRUS |
|
19.8.26 |
A new C2Looper backdoor variant identified | Kaspersky’s GReAT team has identified a major upgrade to the CoolClient backdoor, used by the Mustang Panda (aka HoneyMyte) APT group against government and corporate targets across Asia and Russia. Deployed alongside PlugX, CoolClient is sideloaded via a legitimate Sangfor application, executes an RPC-based privilege escalation, and injects into a suspended system process. | ALERTS | VIRUS |
|
19.8.26 |
Defending Against an Active Threat to Siemens S7 Series PLCs | This advisory relates to an active threat to Siemens S7 Series programmable logic controllers (PLCs). However, ongoing PLC targeting activity is broader than Siemens PLCs. All PLC owners and operators should apply relevant mitigations to reduce the risk to their devices and systems. The Siemens-specific content in this advisory should be understood and applied as one subset of the wider threat landscape. | IC3 | IC3 |
|
19.8.26 |
NodeEdgeRAT | (JavaScript), which ships its entire functionality spanning command execution, file management, and file transfer in one script. | MALWARE | RAT |
|
19.8.26 |
GoginRAT | (Go), which has architectural similarities with NomadRAT and uses a separate transmitter for C2, and implements file system and shell capabilities as independent plugins. The results of the plugin execution are routed through a shared callback. | MALWARE | RAT |
|
19.8.26 |
NomadRAT | (C++), which features a main orchestrator, a dedicated transmitter library that handles all C2 traffic, and plugins fetched from the server by numeric identifiers only when they are required. | MALWARE | RAT |
|
19.8.26 |
CookiETagRAT | (C++), which uses HTTP Cookie / ETag response headers as C2 to receive and execute commands. | MALWARE | RAT |
|
19.8.26 |
DriveSilkRAT | (.NET/C++), which uses Google Drive as command-and-control (C2) to poll a specific folder for tasking, run it through an in-memory .NET plugin system, and upload the results of the execution back to the same folder. It supports 12 plugins for process listing, system and network enumeration, file management, and command execution. | MALWARE | RAT |
|
19.8.26 |
SilkParasite | SilkParasite: Tracking a China-Nexus APT Across Central Asia | APT | APT |
|
19.8.26 |
CVE-2025-31702 | A vulnerability exists in certain Dahua embedded products. Third-party malicious attacker with obtained normal user credentials could exploit the vulnerability to access certain data which are restricted to admin privileges, such as system-sensitive files through specific HTTP request. | VULNEREBILITY | VULNEREBILITY |
|
19.8.26 |
CVE-2021-33044 | The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can bypass device identity authentication by constructing malicious data packets. | VULNEREBILITY | VULNEREBILITY |
|
19.8.26 |
CVE-2024-39943 | rejetto HFS (aka HTTP File Server) 3 before 0.52.10 on Linux, UNIX, and macOS allows OS command execution by remote authenticated users (if they have Upload permissions). This occurs because a shell is used to execute df (i.e., with execSync instead of spawnSync in child_process in Node.js). | VULNEREBILITY | VULNEREBILITY |
|
19.8.26 |
MacSync Stealer | On 5 May 2026, an RST Cloud customer’s Jamf Protect blocked a download from jacksonvillemma[.]com. Four days earlier, the operator’s prior MacSync C2 had been publicly disclosed. Twenty-four hours after that disclosure, the new C2’s TLS certificate had been issued. Three days later, the new C2 was attempting to deliver its loader to a managed endpoint in our customer’s estate. | MALWARE | STEALER |
|
19.8.26 |
PurpleDelta's Fraudulent Employment Operations | PurpleDelta operates at an industrial scale, using at least 22 personas to apply to over 1,100 companies and submitting more than 60 applications per day. | REPORT | REPORT |
|
19.8.26 |
Operation CameraSwarm | Operation CameraSwarm: Over 14,000 Dahua cameras compromised across Ukraine and Russia | OPERATION | OPERATION |
|
19.8.26 |
CVE-2026-65400 | Apple macOS Improper Authentication Vulnerability: Apple macOS contains an improper authentication vulnerability that could allow an attacker on the network to authenticate to Screen Sharing without valid credentials. | ECV | ECV |
|
19.8.26 |
CVE-2026-55040 | Microsoft SharePoint Weak Authentication Vulnerability: Microsoft SharePoint contains a weak authentication vulnerability which allows an unauthorized attacker to bypass a security feature over a network. | ECV | ECV |
|
19.8.26 |
CVE-2026-59310 | Broadcom VMware vCenter Path Traversal Vulnerability: Broadcom VMware vCenter contains a path traversal vulnerability which could allow a threat actor with network access to vCenter to execute arbitrary code. | ECV | ECV |
|
19.8.26 |
CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability: Microsoft Internet Key Exchange (IKE) Service Extensions contains a double free vulnerability that could enable remote code execution. | ECV | ECV |
|
19.8.26 |
#StopRansomware: Medusa Ransomware | Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. As of April 2026, Medusa developers and affiliates—referred to as “Medusa actors” in this advisory—have impacted over 500 victims from a variety of critical infrastructure sectors. Affected industries include medical, education, legal, insurance, technology, and manufacturing. Per FBI, the Medusa ransomware variant is unrelated to the MedusaLocker variant and the Medusa mobile malware variant. | IC3 | IC3 |
|
19.8.26 |
#StopRansomware: Medusa Ransomware | Medusa is a ransomware-as-a-service (RaaS) variant first identified in June 2021. As of April 2026, Medusa developers and affiliates—referred to as “Medusa actors” in this advisory—have impacted over 500 victims from a variety of critical infrastructure sectors. Affected industries include medical, education, legal, insurance, technology, and manufacturing. Per FBI, the Medusa ransomware variant is unrelated to the MedusaLocker variant and the Medusa mobile malware variant. | RANSOM | RANSOM |
|
19.8.26 |
MAJINAHANASHI RANSOMWARE | This is the initial intelligence gathering and analysis based on the newly found IOCs of Ransomware and also uncovered new File Servers and Communication Channel of the Group. | RANSOM | RANSOM |
|
19.8.26 |
CRPX0 Ransomware | CRPX0 Ransomware Group, releasing samples (which has not yet been public as of now) and uncovering a Scam Service which was running by the same group, before launching Ransomware Program. | RANSOM | RANSOM |
|
19.8.26 |
TENGU RANSOMWARE | This is the initial report of Tengu Ransomware. New Information was last added on 16th March 2026. | RANSOM | RANSOM |
|
19.8.26 |
CVE-2026-24301 | Microsoft Copilot Information Disclosure Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
19.8.26 |
CVE-2026-64849 | (CVSS score: 9.3) - An unauthenticated Server-Side Request Forgery (SSRF) vulnerability in MLflow that can allow an attacker who can reach the Tracking Server (mlflow server) to issue HTTP requests to arbitrary internal cloud metadata endpoints and extract sensitive data. (Affects versions < 3.15.0) | VULNEREBILITY | VULNEREBILITY |
|
19.8.26 |
CVE-2026-25895 | (CVSS score: 9.5) - A missing authentication for a critical function and path traversal vulnerability in FUXA that can allow an unauthenticated, remote attacker to write arbitrary files to the server file system and achieve remote code execution. (Affects versions <= 1.2.9) | VULNEREBILITY | VULNEREBILITY |
|
19.8.26 |
CVE-2026-33824 | Microsoft Internet Key Exchange (IKE) Service Extensions Double Free Vulnerability | KEV | KEV |
|
19.8.26 |
CVE-2026-55040 | Microsoft SharePoint Weak Authentication Vulnerability | KEV | KEV |
|
19.8.26 |
CVE-2026-59310 | Broadcom VMware vCenter Path Traversal Vulnerability | KEV | KEV |
|
19.8.26 |
CVE-2026-65400 | Apple macOS Improper Authentication Vulnerability | KEV | KEV |
|
19.8.26 |
AgentWorm: Self-Propagating
Attacks Across LLM Agent Ecosystems |
Autonomous LLM-based agents increasingly operate as long-running processes forming densely interconnected multiagentecosystems, whose security properties remain largely unexplored. Systems such as OpenClaw, an open-source platform with over 40,000 active instances, persistent configurations, toolexecution privileges, and cross-platform messaging, are deployed at scale, yet the security of such agent ecosystems remains largely unexplored. | PAPERS | PAPERS |
|
19.8.26 |
PROMPT INFECTION: LLM-TO-LLM PROMPT INJECTION WITHIN MULTI-AGENT SYSTEMS | As Large Language Models (LLMs) grow increasingly powerful, multi-agent systems—where multiple LLMs collaborate to tackle complex tasks—are becoming more prevalent in modern AI applications. Most safety research, however, has focused on vulnerabilities in single-agent LLMs | PAPERS | PAPERS |
|
19.8.26 |
Thought Virus:
Viral Misalignment via Subliminal Prompting in Multi-Agent Systems |
Subliminal prompting is a phenomenon inwhich language models are biased towards certain concepts or traits through prompting with semantically unrelated tokens. While prior work has examined subliminal prompting in user-LLMinteractions, potential bias transfer in multi-agent systems and its associated security implications remain unexplored. | PAPERS | PAPERS |
|
19.8.26 |
Mind Viruses:
Self-Propagating Ideas in Multi-Agent LLM Systems |
AI agents are becoming more autonomous and increasingly interconnected, exposing them to new emergent risks arising from agent-to-agent interaction. One such risk is the spread of mind viruses: ideas or goals that propagate through multiagent systems by inducing the agents that adopt them to transmit them onward. | PAPERS | PAPERS |
|
18.8.26 |
Mustang Panda Updates CoolClient Backdoor with Rootkit | Kaspersky’s GReAT team has identified a major upgrade to the CoolClient backdoor, used by the Mustang Panda (aka HoneyMyte) APT group against government and corporate targets across Asia and Russia. Deployed alongside PlugX, CoolClient is sideloaded via a legitimate Sangfor application, executes an RPC-based privilege escalation, and injects into a suspended system process. | ALERTS | APT |
|
18.8.26 |
Majinahanashi Ransomware | Researchers at The Raven File recently reported a new ransomware family known as Majinahanashi, marking the emergence of another Japanese-themed extortion group. Translating to "ghost stories," the operators follow the branding patterns of earlier threats like Yurei and Tengu. The group leverages a non-vanity Tor domain for its data leak site. | ALERTS | RANSOM |
|
18.8.26 |
ClickFix Lures Drop CNCMachineRMS RAT | LevelBlue SpiderLabs has published a report on a previously undocumented remote administration tool named CNCMachineRMS, distributed through a deceptive ClickFix lure. The infection flow abuses a legitimately signed IBM executable to activate a sequence of decoy dynamic link libraries, ultimately executing a BabaDeda shellcode loader | ALERTS | VIRUS |
|
18.8.26 |
Gh0st RAT malware distribution continues to be observed in the wild | The researchers from Checkpoint recently presented an update on ongoing malicious deployments of the Gh0st RAT, which is a well known Remote Access Trojan designed to grant cybercriminals covert, full-scale surveillance and unauthorized control over compromised endpoints. | ALERTS | VIRUS |
|
18.8.26 |
Evooo1Bot Linux botnet | Discovered by FortiGuard Labs, Evooo1Bot is an emerging Linux malware family named after a hardcoded string embedded in its binaries. Active against internet-exposed systems across multiple regions since at least July 2026, the botnet expands upon Mirai’s leaked DDoS engine with a sophisticated, modular toolset. | ALERTS | BOTNET |
|
18.8.26 |
Project CAV3RN abuses trusted Google infrastructure for resilient espionage | Project CAV3RN is an evolving cyberespionage framework distinguished by its modular architecture and stealthy communication methods. Recent intelligence presented by the researchers from Securelist reveals the attackers leveraging command-and-control mechanism orchestrated through a 64-bit .NET 8 NativeAOT module. | ALERTS | HACKING |
|
18.8.26 |
PATCHCORD Malware Cluster Targets Telecom and Critical Infrastructure | A new campaign documented by Acronis Threat Research Unit reveals an ongoing cyber espionage cluster targeting Afghan telecommunications providers and government, defense, and energy organizations across South Asia. The threat actors deliver socially engineered lures, including fake VPN installers and management software impersonating Afghan Telecom and Salaam Telecom, to trick personnel into executing the payload. | ALERTS | VIRUS |
|
18.8.26 |
CVE-2025-62593 | Ray-Project Ray Code Injection Vulnerability: Ray-Project Ray contains a code injection vulnerability that could allow remote code execution. Developers using Ray as a development tool may be exposed to this vulnerability exploitable through Firefox and Safari. | ECV | ECV |
|
18.8.26 |
CVE-2026-72898 | Metabase SQL Injection Vulnerability: Metabase contains a SQL Injection vulnerability that allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, which can give them administrator access to the instance. From there, the attacker could change the application configuration, steal stored credentials for the connected databases, read any data accessible through those connections, and export data. | ECV | ECV |
|
18.8.26 |
CVE-2026-68820 | Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability: Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. | ECV | ECV |
|
18.8.26 |
CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability: Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. | ECV | ECV |
|
18.8.26 |
CVE-2026-19650 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to improper request validation in GraphQL multiplex query handling. | VULNEREBILITY | VULNEREBILITY |
|
18.8.26 |
CVE-2026-19478 | GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive. | VULNEREBILITY | VULNEREBILITY |
|
18.8.26 |
CVE-2025-62593 | Ray-Project Ray Code Injection Vulnerability | KEV | KEV |
|
18.8.26 |
Operation ASTERIX | Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline | OPERATION | OPERATION |
|
18.8.26 |
CVE-2026-15748 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | VULNEREBILITY | VULNEREBILITY |
|
18.8.26 |
APT42 | APT42: AI-Assisted Rapport Phishing and a More Resilient TAMECAT | AI | AI |
|
18.8.26 |
HOLLOWGRAPH | HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels | MALWARE | MALWARE |
|
17.8.26 |
CVE-2007-3010 | Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
17.8.26 |
CVE-2016-6277 | NETGEAR Multiple Routers Remote Code Execution Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
17.8.26 |
CVE-2018-14558 | Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
17.8.26 |
CVE-2019-14931 | Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability | VULNEREBILITY | VULNEREBILITY |
|
17.8.26 |
CVE-2020-10987 | Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
17.8.26 |
CVE-2021-46422 | Telesquare SDT-CW3B1 Command Injection vulnerability | VULNEREBILITY | VULNEREBILITY |
|
17.8.26 |
CVE-2022-37055 | D-Link Routers Buffer Overflow Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
17.8.26 |
CVE-2024-29269 | Telesquare TLR-2005KSH Command Injection Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
17.8.26 |
CVE-2025-10123 | D-Link DIR-823X Command Injection Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
17.8.26 |
CVE-2025-55583 | D-Link DIR-868L B1 router Command Injection Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
16.8.26 |
The Jewelbug Dossier | China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business. | REPORT | REPORT |
|
16.8.26 |
CVE-2026-12569 | A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. | VULNEREBILITY | VULNEREBILITY |
|
16.8.26 |
Plug&Pwn: Weaponizing Windows PnP |
Every time a USB device is plugged into a Windows machine, the operating system may silently download a package from Microsoft and execute vendor code as NT AUTHORITY\SYSTEM. That can happen without administrator privileges, without a logged-on user, and in some environments even remotely through RDP USB redirection. | ATTACK | ATTACK |
|
16.8.26 |
CVE-2019-10617 | Low privilege users can access service configuration which contains registry data that admins uses to create or delete entries in the registry in QCA6174_9377.WIN.1.0 in QCA6174_9377 | VULNEREBILITY | VULNEREBILITY |
|
15.8.26 |
Cloudflare DDoS Threat Report H1 2026 | Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave | ATTACK | ATTACK |
|
15.8.26 |
CVE-2026-45659 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | VULNEREBILITY | VULNEREBILITY |
|
15.8.26 |
CVE-2026-20337 | A vulnerability in the zip archive parser of ClamAV could... | VULNEREBILITY | VULNEREBILITY |
|
15.8.26 |
Follow-Up Analysis of the 29 December 2025 Energy Sector Incident | On 29 December 2025, coordinated attacks targeted the energy sector in Poland, including 30 renewable energy facilities and a large combined heat and power (CHP) plant. These attacks were described in detail in the report published on 30 January 2026*. At the same time, another incident occurred at a smaller CHP plant supplying heat to 50,000 residents. | REPORT | REPORT |
|
15.8.26 |
OSDI '26 | 20th USENIX Symposium on Operating Systems Design and Implementation (OSDI ’26) |
CONGRESS |
OSDI '26 |
|
15.8.26 |
NSDI '26 | 23rd USENIX Symposium on Networked Systems Design and Implementation (NSDI ’26) |
CONGRESS |
NSDI '26 |
|
15.8.26 |
FAST '26 | 24th USENIX Conference on File and Storage Technologies (FAST ’26) |
CONGRESS |
FAST '26 |
|
15.8.26 |
USENIX Security '26 | Thanks to those who joined us for the 34th USENIX Security Symposium. We hope you enjoyed the event. | CONGRESS | USENIX Security '26 |
|
15.8.26 |
VehicleSec '26 | Symposium on Vehicle Security and Privacy |
CONGRESS |
VehicleSec '26 |
|
15.8.26 |
WOOT '26 | Conference on Offensive Technologies brings together both academics and practitioners in the field of offensive security research. |
CONGRESS |
WOOT |
|
15.8.26 |
Evooo1Bot | FortiGuard Labs analyzes Evooo1Bot, a modular Linux botnet targeting internet-facing devices with DDoS, SSH attacks, CVE exploits, and SOCKS relays | BOTNET | BOTNET |
|
15.8.26 |
CVE-2026-65400 | An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials. | VULNEREBILITY | VULNEREBILITY |
|
14.8.26 |
CVE-2026-20339 | A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. | VULNEREBILITY | VULNEREBILITY |
|
14.8.26 |
CVE-2026-20338 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. | VULNEREBILITY | VULNEREBILITY |
|
14.8.26 |
CVE-2026-20337 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. | VULNEREBILITY | VULNEREBILITY |
|
14.8.26 |
CVE-2026-70468 | A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here> | VULNEREBILITY | VULNEREBILITY |
|
14.8.26 |
CVE-2026-49975 | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. | VULNEREBILITY | VULNEREBILITY |
|
14.8.26 |
CVE-2026-71407 | A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled. | VULNEREBILITY | VULNEREBILITY |
|
14.8.26 |
CVE-2026-71408 | A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via <insert attack vector here> | VULNEREBILITY | VULNEREBILITY |
|
14.8.26 |
GhostDesk via Fake Softwares | A new campaign documented by Malwarebytes details the distribution of a malicious Google Chrome extension dubbed GhostDesk, delivered through counterfeit software installers. Threat actors are luring Windows users to spoofed download portals for popular utilities, including CCleaner, 7-Zip, and Adobe Acrobat. | ALERTS | VIRUS |
|
14.8.26 |
WindRelay and SpyNote Drive NFC Fraud | Researchers at Group-IB recently reported a new malware family combination involving a custom near-field communication (NFC) relay tool dubbed WindRelay deployed alongside the known SpyNote remote access trojan (RAT). | ALERTS | VIRUS |
|
14.8.26 |
Sandworm-Linked Group Uses Fake Job Interviews to Deploy Trojanized WireGuard Client | According to CERT-UA, the Russian state-sponsored threat group Sandworm (tracked in this campaign as UAC-0145) is actively targeting system administrators and IT staff through fake job recruitment offers. | ALERTS | APT |
|
14.8.26 |
Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side | A months-long investigation by the Symantec Threat Hunter Team has produced unprecedented visibility into the activities of Jewelbug (aka Earth Alux, REF7707, CL-STA-0049), a China-based APT group that has been breaking into government ministries across Asia and the Middle East while quietly running a cryptocurrency fraud business on the side. | ALERTS | APT |
|
14.8.26 |
Chaos Malware Variant Targeting Linux Cloud Infrastructure | A new variant documented by Darktrace highlights how the Go-based Chaos botnet has shifted its targeting from edge routers to Linux cloud environments. Following an initial infection that quickly deletes its own footprint from the disk, the malware establishes long-term persistence using systemd services alongside a keep-alive script. | ALERTS | VIRUS |
|
14.8.26 |
Gunra Ransomware expands its operations | A joint cybersecurity advisory released by international law enforcement and intelligence agencies including CISA, the FBI, NSA, USSS, DC3, and South Korea’s KNPA warns organizations of Gunra, an escalating ransomware-as-a-service (RaaS) threat. | ALERTS | RANSOM |
|
14.8.26 |
A new variant of the Kimwolf botnet identified in the wild | Researchers at Unit 42 of Palo Alto Networks detailed the operation of Aeternum, a C++ botnet loader that uses public Polygon blockchain smart contracts to manage decentralized command-and-control (C2) operations. | ALERTS | BOTNET |
|
14.8.26 |
Jewelbug | Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side | APT | APT |
|
14.8.26 |
NFC skimming attacks | How criminals exploit the familiar “tap your phone to pay” feature to steal your money. | ATTACK | ATTACK |
|
14.8.26 |
WindRelay | Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme | MALWARE | RAT/NFC |
|
14.8.26 |
PATCHCORD | PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure | MALWARE | BACKDOOR |
|
14.8.26 |
AmnesiaStealer | AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers | MALWARE | STEALER |
|
13.8.26 |
SmartApeSG ClickFix leads to two RATs | Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website. | MALWARE TRAFFIC | MALWARE TRAFFIC |
|
13.8.26 |
CVE-2026-15409 | A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location. | VULNEREBILITY | VULNEREBILITY |
|
13.8.26 |
CVE-2026-15410 | Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. | VULNEREBILITY | VULNEREBILITY |
|
13.8.26 |
CVE-2025-49113 | Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization. | VULNEREBILITY | VULNEREBILITY |
|
13.8.26 |
CVE-2026-68820 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
Head Mare | Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants | APT | APT |
|
12.8.26 |
Stealing Reasoning Traces from Proprietary LLM APIs | Leading large language model providers now conceal their models’ step-by-step reasoning, or chainof-thought, to protect intellectual property and limit information leakage. Rather than storing these traces server-side, providers return them to the client as blocks of encrypted text, which the client passes back with each subsequent request. | PAPERS | PAPERS |
|
12.8.26 |
CVE-2026-48362 | (CVSS score: 10.0) - An operating system command injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23) | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-48273 | (CVSS score: 9.9) - An eval injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23) | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-71384 | (CVSS score: 9.6) - An incorrect authorization vulnerability in ColdFusion that could lead to an application denial-of-service (Fixed in 2025.0.12 and 2023.0.23) | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-71362 | (CVSS score: 9.1) - An incorrect authorization vulnerability in Commerce that could lead to privilege escalation | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-71398 | (CVSS score: 10.0) - An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400) | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-27302 | (CVSS score: 10.0) - An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400) | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-48381 | (CVSS score: 9.0) - An SQL injection vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400) | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks | Two vulnerabilities have been identified in the Trusted Platform Module (TPM) 2.0 reference implementation: CVE-2026-6726 – Information leakage via falsified TPM keys.CVE-2026-6727 – A timing side-channel vulnerability in RSA OAEP decryption.An attacker with privileged access to a TPM command interface may be able to exploit these vulnerabilities by sending specially crafted TPM commands. | ALERT | ALERT |
|
12.8.26 |
Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability |
|||
|
12.8.26 |
Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability |
|||
|
12.8.26 |
Metabase SQL Injection Vulnerability |
|||
|
12.8.26 |
Aeternum Botnet | Researchers at Unit 42 of Palo Alto Networks detailed the operation of Aeternum, a C++ botnet loader that uses public Polygon blockchain smart contracts to manage decentralized command-and-control (C2) operations. The threat actors leverage JSON-RPC requests to public Polygon endpoints to bypass conventional IP and domain blocking, staging secondary payloads including XWorm RAT, XMRig cryptocurrency miners, data stealers, and Telegram-controlled Python backdoors. | ALERTS | BOTNET |
|
12.8.26 |
DeadLock Ransomware Combines Resource-Aware Encryption with Resilient Extortion Protocols | Researchers at SOCRadar's Threat Research Unit recently reported on DOUBLECUP, a Russian Loader-as-a-Service platform built for ClickFix-style social engineering campaigns and active since early June 2026. Operators license access to a client panel and embed DOUBLECUP's front-end logic into lure pages, including sites spoofing NetSuite, Odoo, HubSpot, and Salesforce login portals. | ALERTS | RANSOM |
|
12.8.26 |
CRPxO Ransomware | Researchers at SOCRadar's Threat Research Unit recently reported on DOUBLECUP, a Russian Loader-as-a-Service platform built for ClickFix-style social engineering campaigns and active since early June 2026. Operators license access to a client panel and embed DOUBLECUP's front-end logic into lure pages, including sites spoofing NetSuite, Odoo, HubSpot, and Salesforce login portals | ALERTS | RANSOM |
|
12.8.26 |
Largest AI Supply Chain Breach of 2026 | 2,500+ Companies and 434,000 CI/CD Pipelines Exposed in the Largest AI Supply Chain Breach of 2026 | AI | AI |
|
12.8.26 |
CVE-2026-33634 | Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-58231 | SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-44772 | (CVSS score: 9.9) - A code injection vulnerability in Manufacturing Integration and Intelligence | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-34265 | (CVSS score: 9.8) - An out-of-bounds write vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform that allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This could be exploited to disclose sensitive system information or crash the system. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-44758 | (CVSS score: 9.1) - A code injection vulnerability in Manufacturing Integration and Intelligence that could allow an attacker with high privileges to execute arbitrary commands on the underlying operating system. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-20349 | Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-59124 | Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-62878 | Microsoft reports that CVE-2026-62878 is neither exploited in the wild nor publicly disclosed; it is a Critical Windows DNS Server remote code execution vulnerability with a CVSS score of 9.8. The flaw is a stack-based buffer overflow in Windows DNS that can be triggered remotely by an unauthenticated attacker sending a specially crafted packet to an affected service over the network, with no user interaction required, potentially allowing code execution on the target DNS server. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-72971 | This vulnerability was publicly disclosed before Patch Tuesday, making it a zero-day, but Microsoft says it has not been exploited in the wild; it is rated Important with a CVSS score of 5.5. The flaw is an improper link-resolution, or “link following,” issue in the Windows Container Isolation file system filter driver, unionfs.sys, affecting Windows 11 Version 26H1 on x64 and ARM64 systems. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-62832 | Microsoft says this vulnerability has been publicly disclosed but has not been exploited in the wild, making it a zero-day disclosure without confirmed exploitation at this time. Rated Important with a CVSS score of 7.8, this Windows User Profile Service flaw is an improper link resolution, or “link following,” issue that could allow a local authenticated attacker to elevate privileges. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-68820 | This Important-severity elevation of privilege vulnerability is listed by Microsoft as exploited in the wild but not publicly disclosed, and it has a CVSS score of 7.0. The flaw is a use-after-free issue in the Windows Ancillary Function Driver for WinSock affecting supported Windows client and server versions; a locally authenticated attacker with low privileges could run a specially crafted application to trigger a race condition and, if successful, gain SYSTEM privileges. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-62815 | This Critical Microsoft QUIC remote code execution vulnerability is not listed as exploited in the wild or publicly disclosed. It carries a CVSS score of 9.8 and is a use-after-free flaw that could allow an unauthenticated remote attacker to send a specially crafted packet to an affected service over the network and execute code on the target system, with no user interaction required. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-53415 | Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-53414 | Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
CVE-2026-53413 | Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access. | VULNEREBILITY | VULNEREBILITY |
|
12.8.26 |
Kimwolf v7 | Kimwolf v7: An Evolution of the Kimwolf Botnet | BOTNET | BOTNET |
|
11.8.26 |
DeadLock ransomware | DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure | RANSOM | RANSOM |
|
11.8.26 |
CVE-2026-63520 | Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.1 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing stack overflow. Users should upgrade to version 2.1.1 to receive a patch. No known workarounds are available. | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
CVE-2026-55040 | Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
CVE-2026-31431 | Linux privilege escalation (“Copy Fail”) | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
CVE-2026-34197 | ActiveMQ Remote Code Execution | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
CVE-2026-8512 | Use-after-free in Chrome's File System Access API on macOS | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
CVE-2026-45185 | EXIM unauthenticated Remote Code Execution | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
CVE-2026-22738 | SpringAI SpEL Remote Code Execution | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
CVE-2026-20339 | A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
CVE-2026-20338 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
CVE-2026-20337 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. | VULNEREBILITY | VULNEREBILITY |
|
11.8.26 |
Sexual Exploitation Actors Stealing and Leaking Explicit Content | The Federal Bureau of Investigation (FBI) warns the public about sexual exploitation (SE) actors targeting adult and underage victims1 by illegally accessing their social media and personal accounts to steal and post their explicit content (also known as non-consensual intimate images, or NCII) for sale on criminal marketplaces. | IC3 | IC3 PRESS |
|
11.8.26 |
#StopRansomware: Gunra Ransomware | Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. | IC3 | IC3 INDUSTRY |
|
11.8.26 |
#StopRansomware: Gunra Ransomware | Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. | GROUP | RANSOM |
|
11.8.26 |
Opencart ecommerce platform contains directory traversal vulnerability | The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability. The extension installation process extracts uploaded .zip files then uses the zip entry filenames as filesystem paths, without validating that the resolved path stays inside the intended directory. This vulnerability is tracked as CVE-2026-18412. | ALERT | ALERT |
|
11.8.26 |
AA26-222A StopRansomware Gunra Ransomware | The FBI originally observed Gunra ransomware in April 2025. The threat actors quickly established a DLS on the Tor network to list victims and publish exfiltrated data. As of January 2026, Gunra launched a formal RaaS affiliate program on dark web forums, providing affiliates with access to a management panel, a configurable ransomware builder, cross-platform locker payloads, and structured affiliate documentation. | GROUP | RANSOM |
|
10.8.26 |
Operation Capsule Vault | Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2 | OPERATION | OPERATION |
|
10.8.26 |
Pass-the-Passkey Family of Attacks | Coming from the field of enterprise security, we have spent much of our careers studying privilege escalation and lateral movement through attacks against Windows Integrated Authentication. But as more companies adopt cloud services, we decided to shift our attention to passkeys, which are slowly but steadily becoming the norm. | REPORT | REPORT |
|
10.8.26 |
CVE-2026-34348 | CVE-2026-34348 is a medium-severity information disclosure vulnerability (CVSS score 6.5) in the Windows Event Logging Service. It stems from a protection mechanism failure where sensitive data, such as passkey assertions or authentication material, is improperly logged in a recoverable form, letting an authorized attacker view data over a | VULNEREBILITY | VULNEREBILITY |
|
10.8.26 |
CVE-2026-33691 | The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the filename (e.g. photo. php or shell.jsp ). | VULNEREBILITY | VULNEREBILITY |
|
10.8.26 |
CVE-2026-3502 | TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. | VULNEREBILITY | VULNEREBILITY |
|
10.8.26 |
Соціальна інженерія у виконанні UAC-0145: компрометація у процесі працевлаштування | CERT-UA отримано інформацію щодо застосування просунутих методів соціальної інженерії кластером кіберзагроз UAC-0145 (субкластер UAC-0002, також відомий як Sandworm, APT44, Seashell Blizzard). Зокрема, на сайтах пошуку роботи зловмисники, попередньо вивчивши резюме кандидата, від імені ІТ компанії (наприклад, ATLAS Business Group) виходять на зв'язок з потенційною жертвою, як правило системним адміністратором/ІТ фахівцем. | BATTLEFIELD UKRAINE | BATTLEFIELD UKRAINE |
|
10.8.26 |
WhiteCobra Chassis | Solidity Pro's WhiteCobra Chassis: Cloudflare C2 to Telegram Infostealer | MALWARE | STEALER |
|
9.8.26 |
Safe RET Interrupt Vulnerability | An external researcher has reported a potential vulnerability affecting AMD "Zen" architecture processors. The report claims that an attacker executing code on an affected system could inject an interrupt at a precise moment to disrupt “Safe RET,” the default Linux mitigation for Speculative Return Stack Overflow (SRSO), which could potentially weaken that protection and may result in information disclosure. | VULNEREBILITY | VULNEREBILITY |
|
8.8.26 |
CVE-2026-20339 | A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. | VULNEREBILITY | VULNEREBILITY |
|
8.8.26 |
CVE-2026-20338 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. | VULNEREBILITY | VULNEREBILITY |
|
8.8.26 |
CVE-2026-20337 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. | VULNEREBILITY | VULNEREBILITY |
|
8.8.26 |
CVE-2026-20294 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist | VULNEREBILITY | VULNEREBILITY |
|
8.8.26 |
CVE-2023-38646 | Metabase RCE Vulnerability Explained | VULNEREBILITY | VULNEREBILITY |
|
8.8.26 |
DOUBLECUP Loader-as-a-Service Deploys Stealthy RATs via Fake CRM Portals | Researchers at SOCRadar's Threat Research Unit recently reported on DOUBLECUP, a Russian Loader-as-a-Service platform built for ClickFix-style social engineering campaigns and active since early June 2026. | ALERTS | VIRUS |
|
8.8.26 |
Fake CAPTCHA Prompts Leverage ClickFix Tactics to Infect macOS Systems | In a recent write-up, Huntress details a macOS stealer malware campaign that uses ClickFix social engineering tricks to compromise Apple systems and siphon cryptocurrency wallets. Initiated through malicious links in email messages, the attack presents victims with a fake CAPTCHA window instructing them to paste a shell command into the macOS Terminal. | ALERTS | VIRUS |
|
8.8.26 |
Vanta Stealer | Dubbed Vanta Stealer, a Python-based information stealer has been analyzed by the Lat61 Threat Intelligence Team, who describe it as a PyInstaller-packaged Windows executable with PyArmor-obfuscated bytecode protecting its core logic. | ALERTS | VIRUS |
|
8.8.26 |
Greatness PhaaS Campaigns Continue | In a recent write-up, ZeroBEC details a campaign utilizing the Greatness phishing-as-a-service (PhaaS) platform, tracked under the HoneyStorm tag by URLQuery. | ALERTS | CAMPAIGN |
|
8.8.26 |
Popular NPM Packages Hijacked with New Shai-Hulud Malware | Researchers at Aikido Security recently reported an active supply chain attack impacting widely downloaded npm libraries, including keyv and related caching utilities. The campaign leverages compromised maintainer credentials to publish poisoned package versions containing malicious preinstall hooks. | ALERTS | VIRUS |
|
8.8.26 |
Abuse of ScreenConnect RMM and Cloudflare Tunnels in SMOKE#SCREEN Campaign | Researchers at Securonix recently reported an active multi-stage campaign dubbed SMOKE#SCREEN that abuses legitimate ScreenConnect remote monitoring and management (RMM) software to gain persistent access to enterprise endpoints. The operation targets both Windows and macOS environments using social engineering lures themed around Zoom updates, corporate document reviews, and system utilities. | ALERTS | CAMPAIGN |
|
8.8.26 |
CVE-2026-8037 | Progress LoadMaster Command Injection Vulnerability | KEV | KEV |
|
8.8.26 |
The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerability | A heap buffer overflow vulnerability exists in the stb TrueType library created by nothings. Exploitation of this vulnerability can occur when handling malformed font data and may lead to both Denial of Service (DoS) and Information Disclosure. | ALERT | ALERT |
|
8.8.26 |
Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations | A cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iCalendar) invitations. The vulnerability has been actively exploited in the wild, as confirmed by VirusTotal sightings. | ALERT | ALERT |
|
8.8.26 |
MythStealer | A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. | MALWARE | STEALER |
|
8.8.26 |
Token Jacking | It’s three a.m., do you know what your AI agent is doing? Unit 42 has responded to a growing number of AI token jacking cases resulting in staggering financial losses. | AI | AI |
|
8.8.26 |
Flooding Dropper | 'Flooding Dropper' Campaign Hits npm With Nearly 850 Malicious Packages | CAMPAIGN | CAMPAIGN |
|
8.8.26 |
Pink | New Data Extortion Group “Pink” Goes Big Game Hunting With Evasive Phishing Kits | GROUP | GROUP |
|
8.8.26 |
UNC6671 | UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments | GROUP | GROUP |
|
8.8.26 |
CVE-2026-64638 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79) | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
Payroll Pirates | Payroll Pirates: Strange New Tides in Business Email Compromise | CAMPAIGN | CAMPAIGN |
|
7.8.26 |
SCTPhantom | SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
CVE-2026-64564 | In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
CVE-2026-44613 | Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an attacker who lures an authenticated user to a malicious site to perform actions on the user's behalf through REST and WebSocket endpoints. | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
ChainDrop | ChainDrop: When Opening a Repository Becomes Execution | CAMPAIGN | CAMPAIGN |
|
7.8.26 |
CVE-2026-54316 | Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to --allowedTools restrictions | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
CVE-2026-12537 | Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker to achieve pre-sandbox host-level code execution a maliciously crafted .gemini/.env file. | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
CVE-2026-63913 | In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check An unintended behavior in the TCP conntrack state machine allows a connection to be forced into the CLOSE state using an RST packet with an invalid sequence number. | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
CVE-2026-56181 | Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
natjack | A NEW ATTACK CLASS AGAINST NETWORK INFRASTRUCTURE DEVICES | ATTACK | ATTACK |
|
7.8.26 |
CVE-2026-64561 | A flaw was found in KVM in the Linux kernel. This vulnerability occurs due to improper validation of memory management unit (MMU) page roots after these pages are made available. An attacker could exploit this by triggering a scenario where KVM attempts to map memory into an invalid root, causing child shadow pages to inherit an invalid state. | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
ShadowRay 2.0 | New Intelligence Links TeamPCP to ShadowRay 2.0 and Traces Activity back to 2020 | CAMPAIGN | CAMPAIGN |
|
7.8.26 |
CVE-2026-64561 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
Zapscape | Zapscape (CVE-2026-64561) is a use-after-free vulnerability that occurs in the shadow MMU of KVM/x86. When an attacker-controlled guest that uses nested virtualization makes KVM recursively zap a root shadow page that is still in use during MMU page quota reclaim, KVM keeps handling the fault on a root that has already become invalid. As a result an invalid child enters the active MMU page list, and afterwards the same list link is attached to two lists at once and then freed, producing a dangling link and a post-free write. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
TONTOU: On the Exploitability of Time-of-Neutralization to Time-of-Use Windows | Recently deployed Spectre v2 mitigations neutralize branch predictor state when switching privilege contexts or immediately prior to indirect branch execution, either through domain isolation or sanitization. These defenses assume that subsequent branch predictor behavior remains free from attacker influence until the neutralized state is used. | EXPLOIT | EXPLOIT |
|
6.8.26 |
CVE-2026-20303 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20304 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20310 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20310 are related to improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-59. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20269 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20269 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20268 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20268 are related to issues with improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20267 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20267 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20289 | A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enabling a specific logging level and then collecting the system logs. A successful exploit could allow the attacker to view sensitive information like user login credentials. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20294 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20028 | Preact, a lightweight web development framework, JSON serialization protection to prevent Virtual DOM elements from being constructed from arbitrary JSON. A regression introduced in Preact 10.26.5 caused this protection to be softened. In applications where values from JSON payloads are assumed to be strings and passed unmodified to Preact as children, a specially-crafted JSON payload could be constructed that would be incorrectly treated as a valid VNode. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20308 | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20311 | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in the web-based management interface. An attacker could exploit this vulnerability by authenticating with a malformed certificate. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20316 | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20200 | CVE-2026-20200: Cisco Cisco Unified Computing System (Standalone): A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with… | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20288 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20301 | CVE-2026-20301: Cisco: A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol,… | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20263 | GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20124 | The PhotoStack Gallery plugin for WordPress is vulnerable to SQL Injection via the 'postid' parameter in all versions up to, and including, 0.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20079 | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-63077 | JetBrains TeamCity Deserialization of Untrusted Data Vulnerability | KEV | KEV |
|
6.8.26 |
CVE-2026-18236 | A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute unauthorized tools by forging a tool confirmation response. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-18830 | Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
ENDLESSDOORS | ENDLESSDOORS Is Phoning Home. Pick Up. | MALWARE | MALWARE |
|
6.8.26 |
Cost of a Data Breach Report 2026 The AI tipping point |
Welcome to the 21st annual Cost of a Data Breach Report. Frontier AI models have radically shifted the cybersecurity threat landscape. | REPORT | REPORT |
|
6.8.26 |
macOS ClickFix campaign | From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide | CAMPAIGN | CAMPAIGN |
|
5.8.26 |
CVE-2026-58073 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-58072 | A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-58067 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-58071 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
Breaking the Paperclip | Critical Vulnerabilities in AI Agent Orchestration | ||
|
5.8.26 |
CVE-2026-41679 | Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-64531 | In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guard preventing a generated nested action attribute from exceeding U16_MAX. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
OVSwrap | OVSwrap (CVE-2026-64531) local root exploit: mitigation for CloudLinux 9, 10, and CloudLinux for Ubuntu | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-60004 | . When these hook scripts are subsequently triggered during Git operations, they execute arbitrary shell commands with the privileges of the Gitea process user. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-49774 | Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
keyv and cacheable compromise | On August 4, 2026, a threat actor compromised the source or release credentials for the widely used keyv and cacheable npm packages and published trojanized versions of at least ten packages, beginning with keyv@6.0.0 at 09:35 UTC. Unlike a typical dependency swap, each version carries a malicious preinstall hook (setup.mjs) that downloads a standalone Bun runtime and executes an obfuscated ~728 KB second stage (Math_Symbol.js). | CAMPAIGN | CAMPAIGN |
|
5.8.26 |
Hump Hump Locker Ransomware | Symantec's Threat Intelligence teams worldwide offer unparalleled analysis and commentary on current cyberthreats impacting businesses. Symantec's browser extensions integrate this intelligence directly into your browser, enabling effective detection and blocking of various web-borne threats. | ALERTS | RANSOM |
|
5.8.26 |
Ongoing Threats of Swatting and Indicators for Community Members |
This Public Service Announcement (PSA) is an update to Alert Number I-042925-PSA titled, "Threat Actors Use 'Swatting' to Target Victims Nationwide." This PSA contains updated information about the ongoing threat posed by “swatting” incidents targeting a variety of locations across the United States, including educational institutions, government buildings, religious institutions, public transportation centers, hospitals, and other public buildings. |
IC3 PRESS |
|
|
5.8.26 |
IBM Langflow Code Injection Vulnerability: Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. |
IBM | Langflow |
||
|
5.8.26 |
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability: Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. |
Apache | Tomcat |
||
|
5.8.26 |
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability: N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. |
N-able | N-central |
||
|
5.8.26 |
CVE-2026-18577 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability: N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. | N-able | N-central | ECV |
|
5.8.26 |
CVE-2026-9198 | IBM Langflow Code Injection Vulnerability | KEV | KEV |
|
5.8.26 |
CVE-2026-18556 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | KEV | KEV |
|
5.8.26 |
CVE-2026-34486 | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability | KEV | KEV |
|
5.8.26 |
CVE-2026-9198 | (CVSS score: 9.8) - A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. (Fixed in July 2026 with version 1.10.1) | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-34486 | (CVS score: 7.5) - A missing encryption of sensitive data vulnerability in Apache Tomcat that allows a bypass of EncryptInterceptor, a cluster component that adds pre-shared key encryption to messages sent between cluster nodes. (Fixed in April 2026 with versions 11.0.21, 10.1.54, and 9.0.117) | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
Security Incident INC-2026-07-28-01 | The UK AI Security Institute (AISI) exists to equip governments with a scientific understanding of the risks posed by advanced AI. To achieve that goal, AISI routinely evaluates the capabilities of frontier AI systems in domains such as cybersecurity. | REPORT | REPORT |
|
5.8.26 |
QuickFox | QuickFox Supply Chain Attack Used to Deploy FDMTP Implant | CAMPAIGN | CAMPAIGN |
|
5.8.26 |
Telegram-Distributed M365 AiTM PhaaS | ZeroBEC threat research on the Greatness phishing-as-a-service (PhaaS) platform, a commercially distributed kit sold via Telegram that combines adversary-in-the-middle (AiTM) credential and token theft with device code phishing in a single operator product. | PHISHING | PhaaS |
|
4.8.26 |
Powercat malware campaign | Powercat malware campaign: Fake game cheats deliver infostealer | CAMPAIGN | CAMPAIGN |
|
4.8.26 |
Fake Xeno Roblox | Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums | MALWARE | JAVA |
|
4.8.26 |
SMOKE#SCREEN | Analyzing SMOKE#SCREEN: ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures | CAMPAIGN | CAMPAIGN |
|
4.8.26 |
Zero Day Provisioning | Chaining TP-Link ZTP Vulnerabilities to Infiltrate Networks | REPORT | REPORT |
|
4.8.26 |
CVE-2025-9290 | An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality. | VULNEREBILITY | VULNEREBILITY |
|
4.8.26 |
CVE-2025-9289 | A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. | VULNEREBILITY | VULNEREBILITY |
|
4.8.26 |
Agent-to-Agent Privilege Boundary Failures | I'll Just Call You: Agent-to-Agent Privilege Boundary Failures in CI/CD on Google's ADK Repository | AI | AI |
|
4.8.26 |
CVE-2026-58047 | HTTP Smuggling in cPanel allows potential leak of credentials. | VULNEREBILITY | VULNEREBILITY |
|
4.8.26 |
CVE-2026-58048 | Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. | VULNEREBILITY | VULNEREBILITY |
|
4.8.26 |
DOUBLECUP | Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs | MALWARE | LOADER |
|
4.8.26 |
Critical N-able N-central Vulnerability and Active Exploitation | N-able has disclosed a critical vulnerability impacting all current versions of N-central, including 2026.3, across both hosted and on‑prem deployments. The flaw can give attackers unauthenticated, "god-mode" access to the RMM console. | EXPLOIT | EXPLOIT |
|
4.8.26 |
CVE-2026-18577 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | KEV | KEV |
|
3.8.26 |
SonicWall SMA Exploit Chain | From WSProxy to Root: INC ransomware and SonicWall SMA Exploit Chain | EXPLOIT | EXPLOIT |
|
3.8.26 |
Larva-24009 | Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor | GROUP | GROUP |
|
3.8.26 |
DarkSword | DarkSword's Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster | EXPLOIT | EXPLOIT |
|
3.8.26 |
ExfilSquad | ExfilSquad Targets Misconfigured Microsoft Power Pages Portals | CAMPAIGN | CAMPAIGN |
|
3.8.26 |
CVE-2026-17883 | Inappropriate implementation in Headless in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium) | VULNEREBILITY | VULNEREBILITY |
|
3.8.26 |
CVE-2026-18577 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 | VULNEREBILITY | VULNEREBILITY |
|
3.8.26 |
CVE-2026-18556 | Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1. | VULNEREBILITY | VULNEREBILITY |
|
3.8.26 |
FaceHugger | FaceHugger: Vulnerabilities in Hugging Face Diffusers Open Door to Supply Chain Attacks on Enterprise AI | VULNEREBILITY | VULNEREBILITY |
|
3.8.26 |
CVE-2026-44827 | (CVSS score: 8.8) - A code injection vulnerability that allows arbitrary code to be loaded through the custom_pipeline flow from a Hub repository by means of a crafted pipeline with the name "None.py" despite passing trust_remote_code=False (or omitting it, which is the default). | VULNEREBILITY | VULNEREBILITY |
|
3.8.26 |
CVE-2026-45804 | (CVSS score: 7.5) - A race condition vulnerability that allows arbitrary code to be introduced to a repository by modifying the configuration between the hf_hub_download and snapshot_download HTTP calls to the Hub, leading to code execution. | VULNEREBILITY | VULNEREBILITY |
|
3.8.26 |
CVE-2026-44513 | (CVSS score: 8.8) - A code injection vulnerability that allows arbitrary code to be loaded through the custom_pipeline flow from a Hub repository despite passing trust_remote_code=False (or omitting it). | VULNEREBILITY | VULNEREBILITY |
|
2.8.26 |
AUR Attack Prompts Adoption Lock | A new round of Arch User Repository malware has prompted the disabling of package adoption. | ATTACK | AI |
|
2.8.26 |
Threat H1 2026 December 2025 – May 2026 Report | Welcome to the H1 2026 issue of the ESET Threat Report! | REPORT | REPORT |
|
2.8.26 |
Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers | North Korea relies upon a network of skilled Information Technology (IT) workers, deployed within and outside of North Korea, to obtain false identities and remotely earn income to fund North Korea’s unlawful nuclear weapons and ballistic missile programs. | IC3 | IC3 INDUSTRY |
|
2.8.26 |
VirtualGHOST | A "VirtualGHOST" (or just Ghost) is a VMware Virtual Machine on an ESXi host that has been powered on manually from the command line. | MALWARE | VMware ESXi |
|
2.8.26 |
CVE-2026-63077 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol | VULNEREBILITY | VULNEREBILITY |
|
1.8.26 |
CVE-2026-61511 | vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. | VULNEREBILITY | VULNEREBILITY |
|
1.8.26 |
CVE-2013-4786 | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC. | VULNEREBILITY | VULNEREBILITY |
|
1.8.26 |
ValleyRAT distribution campaign targeting organizations in Japan | As reported by the researchers from Cato Networks, the Monarch threat group (aka SilverFox) has recently launched a malicious campaign targeting a Japanese industrial manufacturing company to deliver ValleyRAT, a persistent remote access trojan. Initiated via invoice-themed phishing emails linked to attacker-controlled content hosted on legitimate Tencent Cloud and QQ services, the attack drops a compressed file containing an initial downloader executable. | ALERTS | VIRUS |
|
1.8.26 |
AtlasRAT malware variant | AtlasRAT is a Remote Access Trojan (RAT) variant delivered through malicious setup files disguised as legitimate Flash Player software. As reported by researchers from ASEC, to obfuscate its command-and-control traffic, AtlasRAT utilizes ChaCha20 encryption over TLS, employing self-signed certificates spoofed to resemble Microsoft update infrastructure. | ALERTS | VIRUS |
|
1.8.26 |
SmartApeSG ClickFix campaign pushes unidentified RAT | Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website. | MALWARE TRAFFIC | MALWARE TRAFFIC |
|
1.8.26 |
Seven days of scans and probes and web traffic hitting my web server | Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website. | MALWARE TRAFFIC | MALWARE TRAFFIC |
|
1.8.26 |
CVE-2026-48448 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. | VULNEREBILITY | VULNEREBILITY |
|
1.8.26 |
CVE-2026-48449 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | VULNEREBILITY | VULNEREBILITY |
|
1.8.26 |
CaptiveCrunch | CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | CAMPAIGN | CAMPAIGN |
|
1.8.26 |
Matryoshka | Nested Trust: HollowFrame’s Layered Loader and Matryoshka Backdoors | MALWARE | BACKDOOR |
|
|
|
|
|
|