HOT NEWS 2026 AUGUST January(174) February(168) March(221) April(222) May(261) June(255) July(405) August(106) September(0) October(0) November(0) December(0) | HOTNEWS 2026(1706) STATISTICS (7358)
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
|
10.8.26 |
Соціальна інженерія у виконанні UAC-0145: компрометація у процесі працевлаштування | CERT-UA отримано інформацію щодо застосування просунутих методів соціальної інженерії кластером кіберзагроз UAC-0145 (субкластер UAC-0002, також відомий як Sandworm, APT44, Seashell Blizzard). Зокрема, на сайтах пошуку роботи зловмисники, попередньо вивчивши резюме кандидата, від імені ІТ компанії (наприклад, ATLAS Business Group) виходять на зв'язок з потенційною жертвою, як правило системним адміністратором/ІТ фахівцем. | BATTLEFIELD UKRAINE | BATTLEFIELD UKRAINE |
|
10.8.26 |
WhiteCobra Chassis | Solidity Pro's WhiteCobra Chassis: Cloudflare C2 to Telegram Infostealer | MALWARE | STEALER |
|
9.8.26 |
Safe RET Interrupt Vulnerability | An external researcher has reported a potential vulnerability affecting AMD "Zen" architecture processors. The report claims that an attacker executing code on an affected system could inject an interrupt at a precise moment to disrupt “Safe RET,” the default Linux mitigation for Speculative Return Stack Overflow (SRSO), which could potentially weaken that protection and may result in information disclosure. | VULNEREBILITY | VULNEREBILITY |
|
8.8.26 |
CVE-2026-20339 | A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. | VULNEREBILITY | VULNEREBILITY |
|
8.8.26 |
CVE-2026-20338 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. | VULNEREBILITY | VULNEREBILITY |
|
8.8.26 |
CVE-2026-20337 | A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. | VULNEREBILITY | VULNEREBILITY |
|
8.8.26 |
CVE-2026-20294 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist | VULNEREBILITY | VULNEREBILITY |
|
8.8.26 |
CVE-2023-38646 | Metabase RCE Vulnerability Explained | VULNEREBILITY | VULNEREBILITY |
|
8.8.26 |
DOUBLECUP Loader-as-a-Service Deploys Stealthy RATs via Fake CRM Portals | Researchers at SOCRadar's Threat Research Unit recently reported on DOUBLECUP, a Russian Loader-as-a-Service platform built for ClickFix-style social engineering campaigns and active since early June 2026. | ALERTS | VIRUS |
|
8.8.26 |
Fake CAPTCHA Prompts Leverage ClickFix Tactics to Infect macOS Systems | In a recent write-up, Huntress details a macOS stealer malware campaign that uses ClickFix social engineering tricks to compromise Apple systems and siphon cryptocurrency wallets. Initiated through malicious links in email messages, the attack presents victims with a fake CAPTCHA window instructing them to paste a shell command into the macOS Terminal. | ALERTS | VIRUS |
|
8.8.26 |
Vanta Stealer | Dubbed Vanta Stealer, a Python-based information stealer has been analyzed by the Lat61 Threat Intelligence Team, who describe it as a PyInstaller-packaged Windows executable with PyArmor-obfuscated bytecode protecting its core logic. | ALERTS | VIRUS |
|
8.8.26 |
Greatness PhaaS Campaigns Continue | In a recent write-up, ZeroBEC details a campaign utilizing the Greatness phishing-as-a-service (PhaaS) platform, tracked under the HoneyStorm tag by URLQuery. | ALERTS | CAMPAIGN |
|
8.8.26 |
Popular NPM Packages Hijacked with New Shai-Hulud Malware | Researchers at Aikido Security recently reported an active supply chain attack impacting widely downloaded npm libraries, including keyv and related caching utilities. The campaign leverages compromised maintainer credentials to publish poisoned package versions containing malicious preinstall hooks. | ALERTS | VIRUS |
|
8.8.26 |
Abuse of ScreenConnect RMM and Cloudflare Tunnels in SMOKE#SCREEN Campaign | Researchers at Securonix recently reported an active multi-stage campaign dubbed SMOKE#SCREEN that abuses legitimate ScreenConnect remote monitoring and management (RMM) software to gain persistent access to enterprise endpoints. The operation targets both Windows and macOS environments using social engineering lures themed around Zoom updates, corporate document reviews, and system utilities. | ALERTS | CAMPAIGN |
|
8.8.26 |
CVE-2026-8037 | Progress LoadMaster Command Injection Vulnerability | KEV | KEV |
|
8.8.26 |
The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerability | A heap buffer overflow vulnerability exists in the stb TrueType library created by nothings. Exploitation of this vulnerability can occur when handling malformed font data and may lead to both Denial of Service (DoS) and Information Disclosure. | ALERT | ALERT |
|
8.8.26 |
Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations | A cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iCalendar) invitations. The vulnerability has been actively exploited in the wild, as confirmed by VirusTotal sightings. | ALERT | ALERT |
|
8.8.26 |
MythStealer | A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. | MALWARE | STEALER |
|
8.8.26 |
Token Jacking | It’s three a.m., do you know what your AI agent is doing? Unit 42 has responded to a growing number of AI token jacking cases resulting in staggering financial losses. | AI | AI |
|
8.8.26 |
Flooding Dropper | 'Flooding Dropper' Campaign Hits npm With Nearly 850 Malicious Packages | CAMPAIGN | CAMPAIGN |
|
8.8.26 |
Pink | New Data Extortion Group “Pink” Goes Big Game Hunting With Evasive Phishing Kits | GROUP | GROUP |
|
8.8.26 |
UNC6671 | UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments | GROUP | GROUP |
|
8.8.26 |
CVE-2026-64638 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79) | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
Payroll Pirates | Payroll Pirates: Strange New Tides in Business Email Compromise | CAMPAIGN | CAMPAIGN |
|
7.8.26 |
SCTPhantom | SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
CVE-2026-64564 | In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
CVE-2026-44613 | Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an attacker who lures an authenticated user to a malicious site to perform actions on the user's behalf through REST and WebSocket endpoints. | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
ChainDrop | ChainDrop: When Opening a Repository Becomes Execution | CAMPAIGN | CAMPAIGN |
|
7.8.26 |
CVE-2026-54316 | Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to --allowedTools restrictions | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
CVE-2026-12537 | Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker to achieve pre-sandbox host-level code execution a maliciously crafted .gemini/.env file. | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
CVE-2026-63913 | In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check An unintended behavior in the TCP conntrack state machine allows a connection to be forced into the CLOSE state using an RST packet with an invalid sequence number. | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
CVE-2026-56181 | Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
natjack | A NEW ATTACK CLASS AGAINST NETWORK INFRASTRUCTURE DEVICES | ATTACK | ATTACK |
|
7.8.26 |
CVE-2026-64561 | A flaw was found in KVM in the Linux kernel. This vulnerability occurs due to improper validation of memory management unit (MMU) page roots after these pages are made available. An attacker could exploit this by triggering a scenario where KVM attempts to map memory into an invalid root, causing child shadow pages to inherit an invalid state. | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
ShadowRay 2.0 | New Intelligence Links TeamPCP to ShadowRay 2.0 and Traces Activity back to 2020 | CAMPAIGN | CAMPAIGN |
|
7.8.26 |
CVE-2026-64561 | In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. | VULNEREBILITY | VULNEREBILITY |
|
7.8.26 |
Zapscape | Zapscape (CVE-2026-64561) is a use-after-free vulnerability that occurs in the shadow MMU of KVM/x86. When an attacker-controlled guest that uses nested virtualization makes KVM recursively zap a root shadow page that is still in use during MMU page quota reclaim, KVM keeps handling the fault on a root that has already become invalid. As a result an invalid child enters the active MMU page list, and afterwards the same list link is attached to two lists at once and then freed, producing a dangling link and a post-free write. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
TONTOU: On the Exploitability of Time-of-Neutralization to Time-of-Use Windows | Recently deployed Spectre v2 mitigations neutralize branch predictor state when switching privilege contexts or immediately prior to indirect branch execution, either through domain isolation or sanitization. These defenses assume that subsequent branch predictor behavior remains free from attacker influence until the neutralized state is used. | EXPLOIT | EXPLOIT |
|
6.8.26 |
CVE-2026-20303 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20304 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20310 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20310 are related to improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-59. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20269 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20269 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20268 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20268 are related to issues with improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20267 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20267 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-284. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20289 | A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enabling a specific logging level and then collecting the system logs. A successful exploit could allow the attacker to view sensitive information like user login credentials. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20294 | A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20028 | Preact, a lightweight web development framework, JSON serialization protection to prevent Virtual DOM elements from being constructed from arbitrary JSON. A regression introduced in Preact 10.26.5 caused this protection to be softened. In applications where values from JSON payloads are assumed to be strings and passed unmodified to Preact as children, a specially-crafted JSON payload could be constructed that would be incorrectly treated as a valid VNode. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20308 | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20311 | A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in the web-based management interface. An attacker could exploit this vulnerability by authenticating with a malformed certificate. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20316 | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20200 | CVE-2026-20200: Cisco Cisco Unified Computing System (Standalone): A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with… | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20288 | A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20301 | CVE-2026-20301: Cisco: A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol,… | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20263 | GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20124 | The PhotoStack Gallery plugin for WordPress is vulnerable to SQL Injection via the 'postid' parameter in all versions up to, and including, 0.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-20079 | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-63077 | JetBrains TeamCity Deserialization of Untrusted Data Vulnerability | KEV | KEV |
|
6.8.26 |
CVE-2026-18236 | A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute unauthorized tools by forging a tool confirmation response. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
CVE-2026-18830 | Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required. | VULNEREBILITY | VULNEREBILITY |
|
6.8.26 |
ENDLESSDOORS | ENDLESSDOORS Is Phoning Home. Pick Up. | MALWARE | MALWARE |
|
6.8.26 |
Cost of a Data Breach Report 2026 The AI tipping point |
Welcome to the 21st annual Cost of a Data Breach Report. Frontier AI models have radically shifted the cybersecurity threat landscape. | REPORT | REPORT |
|
6.8.26 |
macOS ClickFix campaign | From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide | CAMPAIGN | CAMPAIGN |
|
5.8.26 |
CVE-2026-58073 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-58072 | A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-58067 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-58071 | A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
Breaking the Paperclip | Critical Vulnerabilities in AI Agent Orchestration | ||
|
5.8.26 |
CVE-2026-41679 | Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-64531 | In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guard preventing a generated nested action attribute from exceeding U16_MAX. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
OVSwrap | OVSwrap (CVE-2026-64531) local root exploit: mitigation for CloudLinux 9, 10, and CloudLinux for Ubuntu | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-60004 | . When these hook scripts are subsequently triggered during Git operations, they execute arbitrary shell commands with the privileges of the Gitea process user. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-49774 | Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0. | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
keyv and cacheable compromise | On August 4, 2026, a threat actor compromised the source or release credentials for the widely used keyv and cacheable npm packages and published trojanized versions of at least ten packages, beginning with keyv@6.0.0 at 09:35 UTC. Unlike a typical dependency swap, each version carries a malicious preinstall hook (setup.mjs) that downloads a standalone Bun runtime and executes an obfuscated ~728 KB second stage (Math_Symbol.js). | CAMPAIGN | CAMPAIGN |
|
5.8.26 |
Hump Hump Locker Ransomware | Symantec's Threat Intelligence teams worldwide offer unparalleled analysis and commentary on current cyberthreats impacting businesses. Symantec's browser extensions integrate this intelligence directly into your browser, enabling effective detection and blocking of various web-borne threats. | ALERTS | RANSOM |
|
5.8.26 |
Ongoing Threats of Swatting and Indicators for Community Members |
This Public Service Announcement (PSA) is an update to Alert Number I-042925-PSA titled, "Threat Actors Use 'Swatting' to Target Victims Nationwide." This PSA contains updated information about the ongoing threat posed by “swatting” incidents targeting a variety of locations across the United States, including educational institutions, government buildings, religious institutions, public transportation centers, hospitals, and other public buildings. |
IC3 PRESS |
|
|
5.8.26 |
IBM Langflow Code Injection Vulnerability: Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. |
IBM | Langflow |
||
|
5.8.26 |
Apache Tomcat Missing Encryption of Sensitive Data Vulnerability: Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. |
Apache | Tomcat |
||
|
5.8.26 |
N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability: N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass. |
N-able | N-central |
||
|
5.8.26 |
CVE-2026-18577 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability: N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. | N-able | N-central | ECV |
|
5.8.26 |
CVE-2026-9198 | IBM Langflow Code Injection Vulnerability | KEV | KEV |
|
5.8.26 |
CVE-2026-18556 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | KEV | KEV |
|
5.8.26 |
CVE-2026-34486 | Apache Tomcat Missing Encryption of Sensitive Data Vulnerability | KEV | KEV |
|
5.8.26 |
CVE-2026-9198 | (CVSS score: 9.8) - A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. (Fixed in July 2026 with version 1.10.1) | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
CVE-2026-34486 | (CVS score: 7.5) - A missing encryption of sensitive data vulnerability in Apache Tomcat that allows a bypass of EncryptInterceptor, a cluster component that adds pre-shared key encryption to messages sent between cluster nodes. (Fixed in April 2026 with versions 11.0.21, 10.1.54, and 9.0.117) | VULNEREBILITY | VULNEREBILITY |
|
5.8.26 |
Security Incident INC-2026-07-28-01 | The UK AI Security Institute (AISI) exists to equip governments with a scientific understanding of the risks posed by advanced AI. To achieve that goal, AISI routinely evaluates the capabilities of frontier AI systems in domains such as cybersecurity. | REPORT | REPORT |
|
5.8.26 |
QuickFox | QuickFox Supply Chain Attack Used to Deploy FDMTP Implant | CAMPAIGN | CAMPAIGN |
|
5.8.26 |
Telegram-Distributed M365 AiTM PhaaS | ZeroBEC threat research on the Greatness phishing-as-a-service (PhaaS) platform, a commercially distributed kit sold via Telegram that combines adversary-in-the-middle (AiTM) credential and token theft with device code phishing in a single operator product. | PHISHING | PhaaS |
|
4.8.26 |
Powercat malware campaign | Powercat malware campaign: Fake game cheats deliver infostealer | CAMPAIGN | CAMPAIGN |
|
4.8.26 |
Fake Xeno Roblox | Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums | MALWARE | JAVA |
|
4.8.26 |
SMOKE#SCREEN | Analyzing SMOKE#SCREEN: ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures | CAMPAIGN | CAMPAIGN |
|
4.8.26 |
Zero Day Provisioning | Chaining TP-Link ZTP Vulnerabilities to Infiltrate Networks | REPORT | REPORT |
|
4.8.26 |
CVE-2025-9290 | An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality. | VULNEREBILITY | VULNEREBILITY |
|
4.8.26 |
CVE-2025-9289 | A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. | VULNEREBILITY | VULNEREBILITY |
|
4.8.26 |
Agent-to-Agent Privilege Boundary Failures | I'll Just Call You: Agent-to-Agent Privilege Boundary Failures in CI/CD on Google's ADK Repository | AI | AI |
|
4.8.26 |
CVE-2026-58047 | HTTP Smuggling in cPanel allows potential leak of credentials. | VULNEREBILITY | VULNEREBILITY |
|
4.8.26 |
CVE-2026-58048 | Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. | VULNEREBILITY | VULNEREBILITY |
|
4.8.26 |
DOUBLECUP | Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs | MALWARE | LOADER |
|
4.8.26 |
Critical N-able N-central Vulnerability and Active Exploitation | N-able has disclosed a critical vulnerability impacting all current versions of N-central, including 2026.3, across both hosted and on‑prem deployments. The flaw can give attackers unauthenticated, "god-mode" access to the RMM console. | EXPLOIT | EXPLOIT |
|
4.8.26 |
CVE-2026-18577 | N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability | KEV | KEV |
|
3.8.26 |
SonicWall SMA Exploit Chain | From WSProxy to Root: INC ransomware and SonicWall SMA Exploit Chain | EXPLOIT | EXPLOIT |
|
3.8.26 |
Larva-24009 | Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor | GROUP | GROUP |
|
3.8.26 |
DarkSword | DarkSword's Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster | EXPLOIT | EXPLOIT |
|
3.8.26 |
ExfilSquad | ExfilSquad Targets Misconfigured Microsoft Power Pages Portals | CAMPAIGN | CAMPAIGN |
|
3.8.26 |
CVE-2026-17883 | Inappropriate implementation in Headless in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium) | VULNEREBILITY | VULNEREBILITY |
|
3.8.26 |
CVE-2026-18577 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 | VULNEREBILITY | VULNEREBILITY |
|
3.8.26 |
CVE-2026-18556 | Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1. | VULNEREBILITY | VULNEREBILITY |
|
3.8.26 |
FaceHugger | FaceHugger: Vulnerabilities in Hugging Face Diffusers Open Door to Supply Chain Attacks on Enterprise AI | VULNEREBILITY | VULNEREBILITY |
|
3.8.26 |
CVE-2026-44827 | (CVSS score: 8.8) - A code injection vulnerability that allows arbitrary code to be loaded through the custom_pipeline flow from a Hub repository by means of a crafted pipeline with the name "None.py" despite passing trust_remote_code=False (or omitting it, which is the default). | VULNEREBILITY | VULNEREBILITY |
|
3.8.26 |
CVE-2026-45804 | (CVSS score: 7.5) - A race condition vulnerability that allows arbitrary code to be introduced to a repository by modifying the configuration between the hf_hub_download and snapshot_download HTTP calls to the Hub, leading to code execution. | VULNEREBILITY | VULNEREBILITY |
|
3.8.26 |
CVE-2026-44513 | (CVSS score: 8.8) - A code injection vulnerability that allows arbitrary code to be loaded through the custom_pipeline flow from a Hub repository despite passing trust_remote_code=False (or omitting it). | VULNEREBILITY | VULNEREBILITY |
|
2.8.26 |
AUR Attack Prompts Adoption Lock | A new round of Arch User Repository malware has prompted the disabling of package adoption. | ATTACK | AI |
|
2.8.26 |
Threat H1 2026 December 2025 – May 2026 Report | Welcome to the H1 2026 issue of the ESET Threat Report! | REPORT | REPORT |
|
2.8.26 |
Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers | North Korea relies upon a network of skilled Information Technology (IT) workers, deployed within and outside of North Korea, to obtain false identities and remotely earn income to fund North Korea’s unlawful nuclear weapons and ballistic missile programs. | IC3 | IC3 INDUSTRY |
|
2.8.26 |
VirtualGHOST | A "VirtualGHOST" (or just Ghost) is a VMware Virtual Machine on an ESXi host that has been powered on manually from the command line. | MALWARE | VMware ESXi |
|
2.8.26 |
CVE-2026-63077 | In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol | VULNEREBILITY | VULNEREBILITY |
|
1.8.26 |
CVE-2026-61511 | vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. | VULNEREBILITY | VULNEREBILITY |
|
1.8.26 |
CVE-2013-4786 | The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC. | VULNEREBILITY | VULNEREBILITY |
|
1.8.26 |
ValleyRAT distribution campaign targeting organizations in Japan | As reported by the researchers from Cato Networks, the Monarch threat group (aka SilverFox) has recently launched a malicious campaign targeting a Japanese industrial manufacturing company to deliver ValleyRAT, a persistent remote access trojan. Initiated via invoice-themed phishing emails linked to attacker-controlled content hosted on legitimate Tencent Cloud and QQ services, the attack drops a compressed file containing an initial downloader executable. | ALERTS | VIRUS |
|
1.8.26 |
AtlasRAT malware variant | AtlasRAT is a Remote Access Trojan (RAT) variant delivered through malicious setup files disguised as legitimate Flash Player software. As reported by researchers from ASEC, to obfuscate its command-and-control traffic, AtlasRAT utilizes ChaCha20 encryption over TLS, employing self-signed certificates spoofed to resemble Microsoft update infrastructure. | ALERTS | VIRUS |
|
1.8.26 |
SmartApeSG ClickFix campaign pushes unidentified RAT | Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website. | MALWARE TRAFFIC | MALWARE TRAFFIC |
|
1.8.26 |
Seven days of scans and probes and web traffic hitting my web server | Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website. | MALWARE TRAFFIC | MALWARE TRAFFIC |
|
1.8.26 |
CVE-2026-48448 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. | VULNEREBILITY | VULNEREBILITY |
|
1.8.26 |
CVE-2026-48449 | Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. | VULNEREBILITY | VULNEREBILITY |
|
1.8.26 |
CaptiveCrunch | CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft | CAMPAIGN | CAMPAIGN |
|
1.8.26 |
Matryoshka | Nested Trust: HollowFrame’s Layered Loader and Matryoshka Backdoors | MALWARE | BACKDOOR |
|
|
|
|
|
|