HOTNEWS 2026 January(174) February(168) March(221) April(222) May(261) June(255) July(464) August(446) September(305) October(0) November(0) December(0) | HOTNEWS 2026(2086) STATISTICS (7358) | ARCHIVE
|
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
|
17.9.26 |
KREMLIN toolkit leveraged in malicious operation REF9334 | Elastic Security Labs researchers have documented findings concerning a sophisticated Brazilian cybercrime operation tracked as REF9334 that impersonates roughly a dozen regional financial institutions to deploy rogue browser extensions. | ALERTS | VIRUS |
|
17.9.26 |
AutoIT delivery campaign distributing AsyncRAT malware | Point Wild Threat Intelligence documented a sophisticated, multi-tiered intrusion chain that deploys AsyncRAT malware variant. The compromise initiates via a deceptive batch script masquerading as an invoice file. Upon execution, this launcher invokes a covert PowerShell instance that pieces together ten fragmented Base64 strings, eliminates obfuscating filler characters, and unscrambles the data using a repeating XOR key. | ALERTS | CAMPAIGN |
|
17.9.26 |
VectraRAT - a new malware-as-a-service (MaaS) variant | SOCRadar’s research team has identified VectraRAT, a novel Malware-as-a-Service (MaaS) platform engineered entirely from the ground up. Architecturally, the ecosystem pairs a Go-based central command hub with an integrated Vue3 management console and a native C++ Windows client, utilizing a custom binary MessagePack TCP protocol for communication. | ALERTS | VIRUS |
|
17.9.26 |
Hagaseca THost9 - a multi-stage Android RAT Loader | The Hagaseca malware cluster targets Android systems, exploiting vulnerable, internet-facing Android Debug Bridge (ADB) ports as well as containerized Redroid environments. As reported by Dark Atlas researchers, the intrusion chain relies on a specialized packer and launcher, exemplified by the THost9 APK build. | ALERTS | VIRUS |
|
17.9.26 |
VHDX malware distribution campaign | Cybersecurity researchers from CYFIRMA uncovered a sophisticated malware operation mimicking India's Income Tax Department to compromise Windows systems. The adversaries deployed a number of fraudulent web domains designed to imitate authentic government revenue portals. The attack delivers its payload inside a virtual hard disk container (VHDX) masquerading as an official tax return utility. | ALERTS | CAMPAIGN |
|
17.9.26 |
PhantomRaven infostealer | CrowdStrike researchers recently identified a financially motivated threat actor, operating legitimately as a bug bounty researcher, who distributed a JavaScript-based infostealer dubbed PhantomRaven. The actor targeted software developers on the open-source npm registry by uploading typosquatted packages that housed benign code, like a basic "Hello, world!" script. | ALERTS | VIRUS |
|
17.9.26 |
KATARU IoT malware | KATARU is a novel IoT malware built atop a conventional Mirai foundation. As reported by Nozomi Networks researchers, the botnet exhibits unusually sophisticated technical capabilities, integrating local privilege escalation exploits, anti-analysis routines, decoy traffic generation, and broad persistence mechanisms spanning Android, desktop, router, and embedded Linux environments. | ALERTS | VIRUS |
|
17.9.26 |
CVE-2026-18574 | An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. | ||
|
17.9.26 |
CVE-2026-91843 | CVE-2026-91843 - Stack overflow in login process to the Security Management and Log Servers | ||
|
17.9.26 |
Protecting Tokens and Assertions from Forgery, Theft, and Misuse |
Implementation Recommendations for Agencies and Cloud Service Providers |
Security guidance | Security guidance |
|
17.9.26 |
Identifying and Mitigating Living Off the Land Techniques |
This guide, authored by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), Federal Bureau of Investigation (FBI), and the following agencies (hereafter referred to as the authoring agencies), provides information on common living off the land (LOTL) techniques and common gaps in cyber defense capabilities. | Security guidance | Security guidance |
|
17.9.26 |
Using Cyber Decoys to Strengthen Detection and Response |
This guidance explains how organizations can strengthen their cyber defenses by deploying realistic decoy systems and information assets to quickly detect and disrupt malicious activity inside their networks. It uses the MITRE Engage™ and MITRE ATT&CK® frameworks to provide practical, low-complexity steps for planning, implementing, and refining decoy operations that reduce time to detection and improve use of defensive resources. | Security guidance | Security guidance |
|
17.9.26 |
SparroWock | ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group | MALWARE | BACKDOOR |
|
17.9.26 |
CHOSEN BRICK | Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves. | MALWARE | BOT |
|
17.9.26 |
HEAVYGRAM | HEAVYGRAM: A Telegram-based Surveillance Backdoor Linked to Handala Hack | MALWARE | BACKDOOR |
|
17.9.26 |
MovieReaper | Torrent trackers have long been abused for distributing malicious software, disguised as popular films, games, and other content. Our previous research has shown that cybercriminals repeatedly turn torrents as an initial infection vector, using trojanized cracks and installers to reach a large number of users. | MALWARE | TROJAN |
|
17.9.26 |
MLflow dspy and statsmodels flavors bypass pickle deserialization control | A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels flavor does not apply the control. | ALERT | ALERT |
|
17.9.26 |
Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment | A vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation results in arbitrary code execution within the coding‑agent environment and access to connected source repositories. This vulnerability is tracked as CVE-2026-90999. | ALERT | ALERT |
|
17.9.26 |
Iranian Cyber Targeting of Dissidents, Activists and Journalists | CHOSEN BRICK is a malware family that has been used to target individuals around the world including in the UK, US and the Netherlands from at least 2025. CHOSEN BRICK enables Iranian state cyber actors to collect information on a target’s contacts, emails and social media messages, which could enable tracking of their movements. | IC3 | IC3 INDUSTRY |
|
17.9.26 |
Update on Government of Iran Cyber Actors' Deployment of Telegram C2 to Push Malware to Identified Targets | The Federal Bureau of Investigation (FBI) is releasing this FLASH to disseminate a detailed malware analysis of the HEAVYGRAM malware. | IC3 | IC3 INDUSTRY |
|
17.9.26 |
CVE-2026-58704 | Google Pixel Improper Authorization Vulnerability | KEV | KEV |
|
17.9.26 |
CVE-2026-76460 | Cisco Identity Services Engine Incorrect Use of Privileged APIs Vulnerability | KEV | KEV |
|
17.9.26 |
CVE-2026-87886 | Acronis Backup Incorrect Default Permissions Vulnerability | KEV | KEV |
|
17.9.26 |
Cisco Advance Notification for Publication of September 16, 2026, Security Advisories | On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the | ||
|
17.9.26 |
Cisco BroadWorks CommPilot Application Software Authorization Bypass Vulnerability | A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device.This vulnerability is due to missing authorization checks. An | ||
|
17.9.26 |
Cisco Identity Services Engine 802.1X Session Hijack and Information Disclosure Vulnerabilities | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an unauthenticated, local attacker to either conduct an authentication bypass or disclose sensitive information.For more information about these vulnerabilities, see the Details | ||
|
17.9.26 |
Cisco Identity Services Engine Authenticated Remote Code Execution and API Vulnerabilities | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct SQL injections, modify data, or execute arbitrary commands on the underlying operating system on an affected device.For more information about these vulnerabilities, | ||
|
17.9.26 |
Cisco Identity Services Engine Authentication Bypass Vulnerabilities | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on an affected device.For more | ||
|
17.9.26 |
Cisco Identity Services Engine Authentication Bypass Vulnerability | A vulnerability in an API of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to bypass authentication.This vulnerability is due to insufficient authentication control on an API endpoint. An attacker could exploit this vulnerability by sending a | ||
|
17.9.26 |
Cisco Identity Services Engine Authorization Bypass Vulnerabilities | Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device.These vulnerabilities are | ||
|
17.9.26 |
Cisco Identity Services Engine Command Injection Vulnerabilities | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to perform command injection attacks on an affected device and execute arbitrary commands as the root user. To exploi | ||
|
17.9.26 |
Cisco Identity Services Engine Cross-Site Scripting Vulnerability | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface.This vulnerability exists because the web-based | ||
|
17.9.26 |
Cisco Identity Services Engine Hardening Release: September 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) engineering teams have conducted a comprehensive internal security review. This review resulted in software hardening | ||
|
17.9.26 |
Cisco Identity Services Engine Information Disclosure Vulnerability | A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials.This vulnerability is due to | ||
|
17.9.26 |
Cisco Identity Services Engine Multiple Path Traversal Vulnerabilities | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to conduct path traversal attacks on an affected device.For more information about these vulnerabilities, see the | ||
|
17.9.26 |
Cisco Identity Services Engine RADIUS Denial of Service Vulnerability | A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device.This vulnerability is due to improper handling of certain RADIUS requests. An attacker could | ||
|
17.9.26 |
Cisco Identity Services Engine Remote Code Execution Vulnerabilities | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected device. To exploit these vulnerabilities, the attacker must have valid administrative | ||
|
17.9.26 |
Cisco Identity Services Engine SQL and HQL Injection Vulnerabilities | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct SQL or HQL injection attacks on an affected device.These vulnerabilities are due to insufficient validation of | ||
|
17.9.26 |
Cisco Identity Services Engine SQL Injection Vulnerabilities | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to conduct SQL injection attacks on an affected device.For more information about these vulnerabilities, see the Details section of this advisory.Cisco has | ||
|
17.9.26 |
Cisco Identity Services Engine Vulnerabilities | Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to bypass authentication to the REST API, achieve remote code execution, perform SQL injection, and conduct XML External Entity injection attacks on | ||
|
17.9.26 |
Cisco Integrated Management Controller Argument Injection Vulnerabilities | Multiple vulnerabilities in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to | ||
|
17.9.26 |
Cisco IOS XR Software Security Hardening Release: September 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. | ||
|
17.9.26 |
Cisco Nexus Dashboard Software Security Hardening Release: September 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Nexus Dashboard engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered | ||
|
17.9.26 |
Cisco Secure Email Gateway and Secure Email and Web Manager Security Hardening Release: September 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address | ||
|
17.9.26 |
Cisco Secure Email Gateway SQL Injection Vulnerability | A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system.This vulnerability is due to insufficient | ||
|
17.9.26 |
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability | A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, adjacent attacker to cause the device to reload unexpectedly, resulting in a denial of service | ||
|
17.9.26 |
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability | A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to | ||
|
17.9.26 |
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability | A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an | ||
|
17.9.26 |
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability | A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause high CPU utilization on an affected | ||
|
17.9.26 |
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilities | Multiple vulnerabilities in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to bypass configured | ||
|
17.9.26 |
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability | A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of | ||
|
17.9.26 |
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability | Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that this vulnerability affects all Cisco | ||
|
17.9.26 |
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability | A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the TCP DNS response handler to unexpectedly restart, | ||
|
17.9.26 |
Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure Firewall Threat Defense (FTD) Software and Cisco Secure Firewall Management Center (FMC) Software engineering team has conducted a | ||
|
17.9.26 |
Cisco Secure Firewall Management Center and Secure Firewall Threat Defense Software sftunnel Vulnerabilities | Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated attacker to perform an sftunnel authentication bypass or sftunnel denial of service (DoS) attack.For more information | ||
|
17.9.26 |
Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating | ||
|
17.9.26 |
Cisco Secure Firewall Management Center Software Java Deserialization Remote Code Execution Vulnerability | A vulnerability in the External Database Access feature of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to execute arbitrary commands as root on an affected device.This vulnerability is due to insecure | ||
|
17.9.26 |
Cisco Secure Firewall Management Center Software sftunnel Root Arbitrary Code Execution Vulnerability | A vulnerability in the sftunnel inter-device communication protocol of Cisco Secure Firewall Management Center (FMC) Software could allow an authenticated, remote attacker to execute arbitrary commands as root.This vulnerability exists because a registered sftunnel peer has | ||
|
17.9.26 |
Cisco Secure Firewall Management Center Software Static Credential Vulnerability | A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems.This vulnerability is due | ||
|
17.9.26 |
Cisco Secure Firewall Management Center Software Vulnerabilities | Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software could allow a remote attacker to gain root access and perform session forgery or session impersonation.For more information about these vulnerabilities, see the | ||
|
17.9.26 |
Cisco Secure Firewall Management Center Software Vulnerabilities | Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software could allow a remote attacker to gain root access, download sensitive files, perform a SQL injection attack, or cause a denial of service (DoS) condition.For more information about these | ||
|
17.9.26 |
Cisco Secure Firewall Threat Defense Software Snort 2 SSL/TLS Denial of Service Vulnerability | A vulnerability in SSL/TLS certificate parsing in the Snort 2 Detection Engine of Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the Snort 2 Detection Engine to restart.This vulnerability is due to incomplete validation of | ||
|
17.9.26 |
Cisco Secure Firewall Threat Defense Software TLS 1.3 Denial of Service Vulnerability | A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition.This vulnerability is due to | ||
|
17.9.26 |
Cisco ThousandEyes Virtual Appliance Authenticated Web Interface Command Injection Vulnerability | A vulnerability in the web-based management interface of Cisco ThousandEyes Virtual Appliance could allow an authenticated, remote attacker to inject arbitrary operating system commands.This vulnerability is due to improper validation of user-supplied input to the web-based management | ||
|
17.9.26 |
Cisco UCS and UCS-Based Appliances UEFI Shell Secure Boot Bypass Vulnerability | A vulnerability in the Unified Extensible Firmware Interface (UEFI) Shell implementation of Cisco UCS Servers and UCS-based appliances could allow an authenticated attacker with valid credentials for a user account with the role of user or 'mce-annotation tox-comment | ||
|
17.9.26 |
If a BIND resolver has cached a tree of SVCB/HTTPS AliasMode records, ... |
|||
|
17.9.26 |
A BIND resolver encountering an SVCB/HTTPS AliasMode record referencin ... |
|||
|
17.9.26 |
If a BIND resolver sends a query for a DNSSEC-signed authoritative zon ... |
|||
|
17.9.26 |
A malformed zone may contain an NS or DNAME node above its origin, whi ... |
|||
|
17.9.26 |
An attacker can cause `named` to abort by sending a crafted DNS-over-H .. |
|||
|
17.9.26 |
A validly signed NSEC3 from an unrelated sibling zone may be accepted ... |
|||
|
17.9.26 |
If BIND is loaded with a "`named.conf`" file that contains no global " .. |
|||
|
17.9.26 |
In a query response, an attacker may send `named` multiple copies of a ... |
|||
|
17.9.26 |
An inapplicable NSEC record may be accepted by a `named` resolver as p ... |
|||
|
17.9.26 |
A BIND recursive resolver may experience excessive resource consumptio ... |
|||
|
17.9.26 |
If an attacker-controlled authoritative server can produce a negative ... |
|||
|
17.9.26 |
On a resolver configured to use ``dns64``, if an applicable answer fro ... |
|||
|
17.9.26 |
An attacker may be able to cause a `named` resolver to abort. The atta ... |
|||
|
17.9.26 |
For a secondary zone with transfers restricted by TSIG, `named` may st ... |
|||
|
17.9.26 |
If a `named` caching resolver is configured with `serve-stale-enable` ... |
|||
|
17.9.26 |
The Issabel Framework, the web framework supporting Issabel PBX software, before commit b97dbaf contains a hard-coded HS256 JWT signing key in the pbxapi index.php file that is identical across every installation, allowing unauthenticated remote attackers to forge valid bearer tokens. |
|||
|
17.9.26 |
BragJack: How We Hijacked 5 Of The World's Most Popular Browsers Using Their Built-In AI Assistants |
AI |
||
|
17.9.26 |
Microsoft Exchange Server Remote Code Execution Vulnerability |
|||
|
17.9.26 |
Parallels Desktop runs prl_disp_service as root. Local clients reach it on the world-writable socket /var/run/prl_disp_service.socket. PrlSrv_LoginLocal accepts peer credentials. |
|||
|
17.9.26 |
N0va Phishkit Targets North America and Europe Through Microsoft Logins |
PHISHING KIT |
||
|
16.9.26 |
Tajin Group detailed its operational challenges and announced key plans and changes, showcasing its ability to adapt and evolve to conduct payment card theft and money laundering activities. |
|||
|
16.9.26 |
Tajin Group detailed its operational challenges and announced key plans and changes, showcasing its ability to adapt and evolve to conduct payment card theft and money laundering activities. |
|||
|
16.9.26 |
In late August 2026, eSentire's Threat Response Unit (TRU) identified an active device code phishing campaign distributed through web contact forms. In the campaign, threat actors posed as a procurement officer of a legitimate business. TRU is tracking the device code phishing kit used in the campaign as "GhostCode". |
|||
|
16.9.26 |
A widespread smishing campaign was identified in which victims received fraudulent SMS messages impersonating official entities and were instructed to click a link inside the SMS in order to “complete a verification“, “settle an outstanding fee”, or “re-confirm delivery details”. |
|||
|
16.9.26 |
The Pixel Update Bulletin contains details of security vulnerabilities and functional improvements affecting supported Pixel devices (Google devices). For Google devices, security patch levels of 2026-09-05 or later address all issues in this bulletin and all issues in the September 2026 Android Security Bulletin. To learn how to check a device's security patch level, see Check and update your Android version. |
|||
|
16.9.26 |
Local privilege escalation due to insecure file permissions |
|||
|
16.9.26 |
In Cellular Modem, there is a possible permission bypass due to a logic error in the code. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. |
|||
|
16.9.26 |
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.3 via the parse_array function. This is due to insufficient validation of the widget 'classes' map, allowing a plain-array payload to bypass the is_safe_widget_instance() object check and reach the callable-invocation sink in Element_Classes::parse_array(). |
|||
|
16.9.26 |
The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 6.17.4 via the is_safe_widget_instance function. This is due to insufficient protection in is_safe_widget_instance, which can be bypassed because PHP fires magic methods during its pre-parse, combined with enable_rendering_widget_copied() forging a valid wp_hash integrity attribute before unserialize() is reached. |
|||
|
16.9.26 |
The JWT authentication mechanism accepts tokens signed with algorithms other than those explicitly configured or supported. This allows an attacker to craft a JWT with an unsupported algorithm, which is then incorrectly validated, leading to unauthorized access. |
|||
|
16.9.26 |
The extension you never installed: KREMLIN forges Chrome's own integrity checks to steal banking sessions |
BANKING |
||
|
15.9.26 |
Ransomware has always needed a human involved somewhere: an affiliate navigating a network by hand, or at minimum, a person who wrote the script the malware executed. Agentic ransomware breaks that assumption. |
|||
|
15.9.26 |
SOCRadar’s Threat Research Unit (STRU) has documented VectraRAT, a Malware-as-a-Service platform built entirely from scratch rather than forked from leaked RAT code. Renting from $250 a month, it gives operators hidden-desktop control, keylogging, clipboard hijacking, browser credential theft, and a UAC bypass that elevates with no prompt. |
RAT |
||
|
15.9.26 |
Cisco Secure Email Gateway SQL Injection Vulnerability |
|||
|
15.9.26 |
Cisco Secure Email Gateway SQL Injection Vulnerability |
|||
|
15.9.26 |
Researchers reported a physical attack technique that they say can potentially undermine the integrity guarantees of AMD Secure Encrypted Virtualization – Secure Nested Paging (SEV-SNP) on systems using DDR5 memory. According to their report, an adversary who has privileged software access and physical access to the motherboard can insert a t hardware device between the processor and a DDR5 memory module. |
|||
|
15.9.26 |
DDRop: Active
Memory Interposer Attacks on Confidential VMs |
Trusted Execution Environments (TEEs) are increasingly deployed in the cloud to protect sensitive workloads through hardwareenforced isolation, remote attestation, and transparent memory encryption. However, to meet memory performance and size demands, modern TEEs omit cryptographic freshness guarantees, leaving them vulnerable to replay attacks by adversaries with physical memory access. |
||
|
15.9.26 |
A out-of-bounds write in Fortinet FortiOS versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13, 6.4.0 through 6.4.14, 6.2.0 through 6.2.15, 6.0.0 through 6.0.17, FortiProxy versions 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14, 2.0.0 through 2.0.13, 1.2.0 through 1.2.13, 1.1.0 through 1.1.6, 1.0.0 through 1.0.7 allows attacker to execute unauthorized code or commands via specifically crafted requests |
|||
|
15.9.26 |
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation. |
|||
|
15.9.26 |
Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit |
|||
|
13.9.26 |
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and the branch office VPN using IKEv2 when configured with a dynamic gateway peer. |
|||
|
12.9.26 |
DoppelCart: 119,000 Domains in What May Be the Largest Documented Fake-Shop Network |
|||
|
12.9.26 |
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application. |
|||
|
12.9.26 |
SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system. |
|||
|
12.9.26 |
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks |
AI |
||
|
12.9.26 |
Researchers at Zscaler ThreatLabz uncovered SloppyRAT, an emerging malware strain linked to ransomware operators aiming to establish initial footholds and facilitate lateral network traversal across victim environments. Delivered primarily through multi-stage ClickFix delivery campaigns, this remote access trojan supplies attackers with an expansive suite of built-in, PowerShell-like commands alongside reverse SOCKS proxy capabilities. |
|||
|
12.9.26 |
Researchers at Proofpoint recently reported on targeted spearphishing campaigns involving multiple state-aligned espionage groups utilizing a novel exploit framework dubbed BlueMoon. The campaigns primarily involve China-nexus threat groups, such as Sheathminer (aka APT31, TA412), targeting entities globally using newly staged infrastructure. |
|||
|
12.9.26 |
Symantec has observed a campaign using an unobfuscated VBScript downloader distributed as a fake Adobe plugin update. The script fingerprints the host, attempts to disable Windows Defender and Smart App Control through registry policy writes, and then invokes msiexec to install a remotely hosted MSI package that deploys the ConnectWise ScreenConnect client, giving the actor access. |
|||
|
12.9.26 |
Researchers at Zimperium recently reported on Mantax Otax, a dual-function Android malware strain originating from threat actors based in Indonesia. The hybrid threat targets regional Android users by combining intrusive espionage tools and file-encryption capabilities into a single payload. |
|||
|
12.9.26 |
GoldFactory threat group abuses Android Work Profiles with Vwork clone tool |
Cybersecurity researchers at Group-IB discovered a novel defense-evasion technique used by the threat group GoldFactory, creators of the Gigabud Android banking trojan. The operators pair their malware with Vwork, an adapted variant of the open-source utility Shelter that exploits Android’s Work Profile architecture. |
||
|
12.9.26 |
Unit 42 researchers uncovered an extensive, two-year cybercrime scheme designated as CL-CRI-1171. The group responsible functions as a commercial pay-per-install marketplace that distributes diverse payloads for third-party adversaries. The operation funnels traffic through two deceptive avenues: manipulated search engine results and influential gaming-focused YouTube channels. |
|||
|
12.9.26 |
An out-of-bounds (OOB) memory access vulnerability involving unchecked array indexing has been identified in the exllamav3_ext compute unified device architecture (CUDA) extension. Successful exploitation can lead to an immediate denial of service or application instability. This vulnerability is tracked as CVE-2026-84286. |
|||
|
12.9.26 |
GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability |
|||
|
12.9.26 |
JFrog Artifactory Incorrect Authorization Vulnerability |
|||
|
12.9.26 |
JFrog Artifactory Improper Authentication Vulnerability |
|||
|
12.9.26 |
ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability |
|||
|
12.9.26 |
Path Traversal issue in repository commits API impacts GitLab CE/EE |
|||
|
12.9.26 |
Insecure Deserialization issue in GraphQL subscription serializer impacts GitLab EE |
|||
|
12.9.26 |
Buffer Overflow issue in Unicode conversion wrapper impacts GitLab EE |
|||
|
12.9.26 |
Scheduled Pipeline Execution Policy test allows Developers to access protected CI/CD variables |
|||
|
12.9.26 |
Cross-site Scripting issue in Markdown JSON table renderer impacts GitLab CE/EE |
|||
|
12.9.26 |
Incorrect Authorization issue in CI/CD environment variable scope matcher impacts GitLab CE/EE |
|||
|
12.9.26 |
Denial of Service issue in GraphQL complexity limiter impacts GitLab CE/EE |
|||
|
12.9.26 |
Denial of Service issue in GraphQL complexity limiter impacts GitLab CE/EE |
|||
|
12.9.26 |
Race Condition issue in Merge Request Pipelines impacts GitLab CE/EE |
|||
|
12.9.26 |
Improper Authentication issue in SAML SSO sign-in restriction enforcement impacts GitLab CE/EE |
|||
|
12.9.26 |
Insufficiently Protected Credentials issue in Workhorse senddata emitters impacts GitLab CE/EE |
|||
|
12.9.26 |
Cross-site Scripting issue in Content Editor impacts GitLab CE/EE |
|||
|
12.9.26 |
Access Control Implementation issue in protected environment approval rules impacts GitLab EE |
|||
|
12.9.26 |
Authorization Bypass issue in protected environment approval rules impacts GitLab EE |
|||
|
12.9.26 |
Missing Authorization issue in Generic Package Registry impacts GitLab CE/EE |
|||
|
12.9.26 |
Improper Input Validation issue in Namespace Transfer impacts GitLab CE/EE |
|||
|
12.9.26 |
Missing Authorization issue in Compliance Framework management impacts GitLab EE |
|||
|
12.9.26 |
Improper Input Validation issue in Terraform State API impacts GitLab CE/EE |
|||
|
12.9.26 |
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitLab server due to improper path confinement and missing authentication enforcement in the repository commits API. |
|||
|
12.9.26 |
In August 2026, FortiGuard Labs observed a Casbaneiro attack campaign targeting users in Latin America, using phishing emails and PDF files themed around fake invoices and legal notices as the initial stage. |
BANKING |
||
|
12.9.26 |
ZeroBEC uncovered a phishing campaign we track as ShadowPane that uses browser-in-the-browser deception to make malicious RMM installations appear to originate from Adobe. |
|||
|
12.9.26 |
In June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being delivered through a multi-stage ClickFix infection chain. |
RAT |
||
|
12.9.26 |
Executive Summary MacSync Stealer is a family of macOS information stealers and remote-access stagers designed to evade detection and sold commercially under a malware-as-a-service (MaaS) model. In the attack chain, MacSync binaries are native stagers and multi-part exfiltration engines.... |
MACOS |
||
|
12.9.26 |
One click. Three critical failures. One backdoor. |
BACKDOOR |
||
|
12.9.26 |
LLM-based code scanners won’t help attackers build a nuclear weapon, but that refusal could work in their favor |
AI |
||
|
12.9.26 |
(CWE-78): a contact-sheet handler runs an attacker-chosen filename through a shell, so a file uploaded with a command in its name executes it. |
|||
|
12.9.26 |
(CWE-78): a superuser settings test endpoint passes an operator-supplied argument straight to a shell and reflects the output, a direct command channel. |
|||
|
12.9.26 |
(CWE-89): a delegated (non-superuser) administrator turns a control-panel field into raw SQL, including stacked statements. |
|||
|
12.9.26 |
(CWE-502): a permission blob deserialized on every page load instantiates arbitrary classes, which the SQL injection above weaponizes into a file write. |
|||
|
11.9.26 |
Over the past eight months, our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity. In this report, we share case studies from those operations and describe how malicious use of Claude has evolved since our previous threat reports in March, August, and November 2025. |
|||
|
11.9.26 |
An incorrect permissions assignment vulnerability in the amwrtdrv.sys kernel driver, included with AOMEI Backupper 8.4.0, allows an unprivileged local user to perform arbitrary writes to the physical disk. |
|||
|
11.9.26 |
MikroTik RouterOS Missing Authentication for Critical Function Vulnerability |
|||
|
11.9.26 |
MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability |
|||
|
11.9.26 |
Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website. |
|||
|
11.9.26 |
Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website. |
|||
|
11.9.26 |
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. |
|||
|
11.9.26 |
JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope. |
|||
|
11.9.26 |
JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources. |
|||
|
11.9.26 |
Inappropriate implementation in V8 in Google Chrome prior to 95.0.4638.69 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. |
|||
|
11.9.26 |
Hagaseca: Inside a Packed Android RAT Loader |
RAT |
||
|
11.9.26 |
Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration |
|||
|
10.9.26 |
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability: Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. |
|||
|
10.9.26 |
Google Chromium V8 Out of Bounds Write Vulnerability: Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. |
|||
|
10.9.26 |
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability: Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets. |
|||
|
10.9.26 |
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability: Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication. |
|||
|
10.9.26 |
Microsoft Windows Heap-Based Buffer Overflow Vulnerability: Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally. |
|||
|
10.9.26 |
N-able N-central Static Code Injection Vulnerability: N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution. |
|||
|
10.9.26 |
Microsoft Windows Link Following Vulnerability: Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM. |
|||
|
10.9.26 |
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability: Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code. |
|||
|
10.9.26 |
Google Chromium V8 Type Confusion Vulnerability: Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera. |
|||
|
10.9.26 |
SonicWall SMA1000 Appliances OS Command Injection Vulnerability: SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. |
|||
|
10.9.26 |
This Strategy sets the course for FBI Cyber Division to defend the American people and the nation’s critical infrastructure in cyberspace. It defines our priorities, objectives, and framework for countering malicious cyber activity directed at the United States. |
IC3 INDUSTRY |
||
|
10.9.26 |
China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy |
IC3 INDUSTRY |
||
|
10.9.26 |
MacSync Stealer is a commercial macOS malware framework functioning primarily as a stealthy stager and data-exfiltration engine. As reported by Seqrite analysts, the infection typically begins through malvertising or "ClickFix" social engineering schemes, wherein victims unwittingly paste malicious commands into Terminal after encountering counterfeit verification challenges or prompts. |
|||
|
10.9.26 |
Researchers at Cisco Talos reported on widespread credential- and cryptocurrency-harvesting operation centered on the Amatera stealer and attributed to a threat actor designated as UAT-10820. |
|||
|
10.9.26 |
Researchers at Rapid7 recently reported a campaign by suspected North Korean state-sponsored actors targeting the media and automotive sectors in South Korea. Seeking long-term espionage, the attackers initially compromise edge web servers—often through vulnerable groupware portals—to deploy a sophisticated Linux toolkit. |
|||
|
10.9.26 |
BL4CK SP1D3R is a Windows ransomware family first publicly documented in July 2026. It encrypts user data, appends the .bl4ck extension, replaces the desktop wallpaper, sets a custom file-type icon, and drops ransom notes that direct the victim to a contact channel and a per-machine identifier. |
|||
|
10.9.26 |
Attackers impersonate IT support in Microsoft Teams to deploy persistent Node.js backdoors |
Threat researchers at Microsoft have documented a targeted intrusion campaign that exploits Microsoft Teams communications. |
||
|
10.9.26 |
Self-propagating Go-based Botnet enrolls vulnerable IoT devices for DDoS campaigns |
A newly identified IoT botnet written in Go combines autonomous self-propagation with centralized remote execution to launch distributed denial-of-service (DDoS) campaigns. |
||
|
10.9.26 |
Updated python-based NodeStealer variant distributed in the wild |
Security researchers at Netscope have identified an updated variant of the Python-based NodeStealer malware. Originally developed to harvest web browser data and commercial Facebook accounts, the threat has evolved into comprehensive spyware. |
||
|
10.9.26 |
Check Point Research has uncovered an extensive cyber campaign by a Chinese-speaking threat group named “Gambling Goblin,” an entity linked to the Earth Berberoka cluster. |
|||
|
10.9.26 |
NetScaler ADC and NetScaler Gateway Security Bulletin for CVE-2026-19490 |
|||
|
10.9.26 |
Vwork: Weaponized Open-source Software as an Addon for Gigabud |
ANDROID |
||
|
10.9.26 |
Authentication Bypass and Remote Code Execution in Remote Access and Site-to-Site VPN |
|||
|
10.9.26 |
ASN.1 decoding heap overflow leading to a remote code execution |
|||
|
10.9.26 |
Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability |
|||
|
10.9.26 |
Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability |
|||
|
10.9.26 |
Google Chromium V8 Out of Bounds Write Vulnerability |
|||
|
10.9.26 |
Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel |
|||
|
10.9.26 |
Anubis Market is a multi-category Dark Web marketplace operating as a Tor hidden service, with escrow-backed trading in Bitcoin (BTC) and Monero (XMR). Its visible category strip displays more than 11,000 listings, and while narcotics account for the largest share of physical goods, its Digital section is the single biggest category on the market. |
|||
|
9.9.26 |
Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium) |
|||
|
9.9.26 |
Security: CVE-2026-67401 SQL Injection Vulnerability in cPanel's EmailTrack Functionality - September 8, 2026 |
|||
|
9.9.26 |
When a BIG-IP APM access policy is configured on a virtual server, specific malicious traffic can lead to Remote Code Execution (RCE). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |
|||
|
9.9.26 |
Microsoft has failed to properly patch ShieldBreak CVE-2026-69414, under specific conditions it is still possible to trigger the exact same problem that was caused by ShieldBreak. While Microsoft fixed several things to prevent re-exploiting the issue, they missed a spot where ShieldBreak can still be exploited. |
|||
|
9.9.26 |
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. |
|||
|
9.9.26 |
On 8th of September 2026, SAP security patch day saw the release of 19 new security notes. There is 1 update to previously released security note. |
|||
|
9.9.26 |
(CVSS score: 8.1) - A double free vulnerability in Microsoft Exchange Server that allows an unauthorized attacker to execute code over a network |
|||
|
9.9.26 |
(CVSS score: 8.6) - An improper authentication vulnerability in Microsoft Authenticator that allows an unauthorized attacker to elevate privileges locally |
|||
|
9.9.26 |
(CVSS score: 8.8) - A missing authorization vulnerability in Microsoft Office SharePoint that allows an authorized attacker to execute code over a network |
|||
|
9.9.26 |
(CVSS score: 9.6) - An injection vulnerability in SQL Server allows an unauthorized attacker to elevate privileges over a network |
|||
|
9.9.26 |
(CVSS score: 9.8) - A use-after-free vulnerability in Windows Remote Desktop Services that allows an unauthorized attacker to execute code over a network |
|||
|
9.9.26 |
(CVSS score: 9.8) - A use-after-free vulnerability in Windows Services for NFS ONCRPC XDR Driver that allows an unauthorized attacker to execute code over a network |
|||
|
9.9.26 |
(CVSS score: 9.8) - A use-after-free vulnerability in Windows DNS server that allows an unauthorized attacker to execute code over a network |
|||
|
9.9.26 |
(CVSS score: 9.8) - A heap-based buffer overflow vulnerability in Windows Shell that allows an unauthorized attacker to execute code over a network |
|||
|
9.9.26 |
(CVSS score: 9.8) - A use-after-free vulnerability in Windows DHCP Server that allows an unauthorized attacker to execute code over a network |
|||
|
9.9.26 |
(CVSS score: 7.8) - A heap-based buffer overflow vulnerability in Windows Advanced Local Procedure Call (ALPC) that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges |
|||
|
9.9.26 |
(CVSS score: 7.8) - An improper link resolution vulnerability in the Windows Update Stack that allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges |
|||
|
9.9.26 |
UEFI Shell module embedded in SPI Flash can be used to bypass Secure Boot |
The UEFI Shell program may expose raw memory access capabilities that, if present in platform firmware for debugging or advanced support use cases, could be abused to undermine UEFI Secure Boot protections. |
||
|
9.9.26 |
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability |
|||
|
9.9.26 |
Microsoft Windows Link Following Vulnerability |
|||
|
9.9.26 |
Microsoft Windows Heap-Based Buffer Overflow Vulnerability |
|||
|
9.9.26 |
N-able N-central Static Code Injection Vulnerability |
|||
|
9.9.26 |
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability |
|||
|
9.9.26 |
Microsoft Windows Link Following Vulnerability |
|||
|
9.9.26 |
Microsoft Windows Heap-Based Buffer Overflow Vulnerability |
|||
|
9.9.26 |
N-able N-central Static Code Injection Vulnerability |
|||
|
9.9.26 |
Technical Analysis of the Web Injects in Android Botnet Operations |
WEB |
||
|
9.9.26 |
SURXRAT is an actively developed Android Remote Access Trojan (RAT) commercially distributed through a Telegram-based malware-as-a-service (MaaS) ecosystem under the SURXRAT V5 branding. |
RAT |
||
|
9.9.26 |
TAXISPY RAT : Analysis of TaxiSpy RAT – Russian Banking – Focused Android Malware with Full Remote Control |
RAT |
||
|
9.9.26 |
Sophisticated Android Malware Strikes Users in Thailand, Philippines, and Peru |
RAT |
||
|
9.9.26 |
Trojan/Linux.MikeDor |
BACKDOOR |
||
|
9.9.26 |
CROWDSTRIKE 2026 THREAT HUNTING REPORT |
|||
|
9.9.26 |
BeatBanker: A dual‑mode Android Trojan |
ANDROID |
||
|
9.9.26 |
PixRevolution: The Agent-Operated Android Trojan Hijacking Brazil’s PIX Payments in Real Time |
ANDROID |
||
|
9.9.26 |
SLIM SPIDER is an eCrime adversary that has been actively targeting Brazilian financial institutions since at least March 2026. The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment service Pix, digital asset platforms, and financial entities’ cloud environments. SLIM SPIDER’s primary tool is MikeDor, a custom cross-compiled, Go-... |
|||
|
9.9.26 |
Extended IOCs for TaxiSpy Android Banking Malware |
SPY |
||
|
8.9.26 |
Detection and Removal of the Syslogk Rootkit in a Linux Environment |
ROOTKIT |
||
|
8.9.26 |
HVNC Backdoor Targets LATAM Organizations with Fake Tax and DocuSign Lures |
BACKDOOR |
||
|
8.9.26 |
CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. |
|||
|
8.9.26 |
Kimsuky Integrates AI into Attack Operations, From AI-Generated Decoy Documents to a Local LLM |
|||
|
8.9.26 |
The first zero-click worm to spread through WeChat calls across iOS and Android. |
WORM |
||
|
8.9.26 |
A flaw was found in FreeIPA's idp-add command, where insufficiently validated --organization/--base-url input reaches a constrained eval() call before the corresponding LDAP access control check is enforced. |
|||
|
8.9.26 |
A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule evaluator incorrectly matches an anonymous LDAP client's empty bind DN against an empty stored attribute value, allowing an unauthenticated client to satisfy access control checks intended to require a matching authenticated identity. |
|||
|
8.9.26 |
A flaw was found in FreeIPA. The self-managed OTP token ACI does not require authentication and does not restrict which attributes may be added alongside the token entry |
|||
|
8.9.26 |
Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. |
|||
|
8.9.26 |
BengalSEO Part 1: Anatomy of the Operation |
|||
|
7.9.26 |
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a deserialization vulnerability in the persistence utilities allows unsafe type instantiation from attacker-influenced persisted state, which can lead to remote code execution. |
|||
|
7.9.26 |
In Progress® Telerik® UI for AJAX prior to v2026.2.708, a path traversal vulnerability in the file-based persistence storage provider can be exploited when the storage key is derived from user-controlled input, enabling attacker-controlled deserialization and remote code execution. |
|||
|
7.9.26 |
In Progress® Telerik® UI for AJAX prior to v2026.2.708, applications using cookie-based storage in RadPersistenceManager or RadDockLayout deserialize attacker-controlled cookie content, allowing unauthenticated remote code execution. |
|||
|
7.9.26 |
In Progress® Telerik® UI for AJAX prior to v2026.2.708, when Telerik.Upload.ConfigurationHashKey is absent and machineKey is not explicitly configured, upload metadata integrity protection may fall back to a predictable default key, enabling attackers to forge protected upload metadata and unlock further exploit chains. |
|||
|
7.9.26 |
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values. |
|||
|
7.9.26 |
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers. |
|||
|
7.9.26 |
In Progress® Telerik® UI for AJAX prior to v2026.2.708, forged upload metadata can influence AsyncUploadTypeName processing and trigger unsafe attacker-controlled type resolution, enabling remote code execution in affected deployments. |
|||
|
7.9.26 |
SourTrade: Browser-Assembled Malware Delivered Through Malvertising |
|||
|
7.9.26 |
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. |
|||
|
7.9.26 |
An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs |
|||
|
7.9.26 |
A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4 |
|||
|
7.9.26 |
An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs |
|||
|
7.9.26 |
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode |
JAVASCRIPT |
||
|
6.9.26 |
During its own research, CERT Polska discovered vulnerabilities in MikroTik RouterOS software and participated in coordinating their disclosure. Details on how these vulnerabilities were found, along with other related information, are available in our separate article. |
|||
|
6.9.26 |
Malware and Vulnerability Trends |
|||
|
6.9.26 |
Elastic Security Labs details emerging infostealer targeting gamers |
|||
|
6.9.26 |
Elastic Security Labs deep dives into REVSTEALER, an emerging infostealer targeting browsers, wallets, and gaming accounts. |
STEALER |
||
|
6.9.26 |
StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack |
|||
|
6.9.26 |
The Acronis Cyberthreats Report covers the global threat landscape as encountered by the Acronis Threat Research Unit (TRU) and Acronis sensors in the second half of 2025. General threat data (including malware, ransomware, web and email threats, vulnerabilities, etc.) presented in the report is gathered from January–December of 2025 and reflects threats targeting endpoints we observed in this time frame |
|||
|
5.9.26 |
HGFS stack buffer-overflow vulnerability |
|||
|
5.9.26 |
VMXNET3 integer-overflow vulnerability |
|||
|
5.9.26 |
Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website. |
|||
|
5.9.26 |
Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website. |
|||
|
4.9.26 |
Google Chromium V8 Type Confusion Vulnerability |
|||
|
4.9.26 |
ASCII smuggling crosses over from AI prompt injection to phishing evasion |
AI |
||
|
4.9.26 |
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors |
BACKDOOR |
||
|
4.9.26 |
PostGREShell: The database powering much of the internet had an open door for 12 years |
|||
|
4.9.26 |
Researchers at CERTAINITY recently reported on Zawoo Team, a ransomware operation. The actor has been active since at least early August 2026 and brought its leak site online on 30 August, listing 19 victims at once, concentrated among small and micro enterprises in German-speaking Europe across engineering, industrial software, construction, hospitality and real estate. Access came through the victim's VPN using valid credentials for an already privileged account with no multi-factor authentication enforced, and no exploitation or escalation was observed. |
|||
|
4.9.26 |
Mirage Kitten Expands Toolset with Cross-Platform NodeRabbit and PollCat RATs |
In a recent write-up, Kaspersky details a campaign by the Iranian threat group Mirage Kitten targeting aviation, FinTech, and technology organizations across the Middle East and Africa. The threat actor recruits candidates on professional networking platforms and entices software engineers to download trojanized coding challenges hosted on cloud storage. |
||
|
4.9.26 |
SleepWalker is a stealthy Windows backdoor identified by an independent researcher at r136a1 that departs from typical malware by staying dormant rather than beaconing to an external command server. Disguised as a native Microsoft dynamic link library with falsified ESET metadata, the implant relies on DLL side-loading to run inside the official ESET Management Agent executable. |
|||
|
4.9.26 |
Between March and July 2026, attackers who compromised a technology start-up in Asia ran into a problem: almost every payload they attempted to deploy, including AdaptixC2 agents and Cobalt Strike Beacon, was blocked on the victim's network. Their response was to download the official Node.js installer from nodejs.org and use the trusted, signed runtime to execute a malicious implant. |
|||
|
4.9.26 |
Researchers at Sophos recently reported on the post-exploitation tactics and intrusion mechanics associated with The Gentlemen Ransomware-as-a-service (RaaS) operations. This activity is attributed to the GOLD SHERWOOD threat group. Threat actors reportedly gain initial access through various means, such as exploiting unpatched edge devices or by leveraging compromised VPN user credentials without multi-factor authentication. |
|||
|
4.9.26 |
Discovered by Group-IB analysts and attributed with high confidence to the Brazilian cybercrime group Exilware, BraZetsu is a modular, Python-based malware framework designed specifically for Initial Access Brokers (IABs). The codebase suggest heavy reliance on generative AI during the development process. |
|||
|
4.9.26 |
Casdoor authentication server is vulnerable to authorization bypass |
Casdoor is an open-source Access Management (IAM) platform used to manage web applications. An authorization bypass vulnerability affects Casdoor versions 3.115.0 and earlier. |
||
|
4.9.26 |
Cisco IOS XR Software Security Hardening Release: September 2026 |
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. |
||
|
4.9.26 |
Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the server owner (and a /api/resources call reveals other servers accessible by that server owner). |
|||
|
4.9.26 |
Unrestricted Upload of File with Dangerous Type vulnerability in Elementor Elementor Pro allows Using Malicious Files. This issue affects Elementor Pro: from n/a through 4.2.1. |
|||
|
4.9.26 |
CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including executable PHP files, leading to remote code execution. (Fixed in version 6.3.314) |
|||
|
4.9.26 |
Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading to full compromise of the panel. |
|||
|
4.9.26 |
This is a collaborative follow-up to our original post, developed jointly with Emmanuel C., a security researcher not affiliated with LevelBlue, who contributed additional infrastructure and tooling findings based on an analysis of the same GitHub staging account. |
|||
|
3.9.26 |
Group-IB uncovers BraZetsu, a new Python-based Windows malware that serves as a master toolkit for Initial Access Brokers and powers a unique, AI-enhanced underground marketplace for commercializing compromised Iberian and Latin American targets. |
PYTHON |
||
|
3.9.26 |
FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in Crowdstrike Falcon Sensor, obviously by the time I drop this Crowdstrike would already have detections for it so if you want to test you either have to add it to the exclusions or obfuscate the PoC and change the dll load technique. |
|||
|
3.9.26 |
Communicating Under |
Service outages impacting IT and operational technology (OT)
systems can be damaging and disruptive for customers, network defenders,
critical infrastructure |
||
|
3.9.26 |
Cisco IOS XR Software Security Hardening Release: September 2026 |
These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by their underlying vulnerability class - Common Weakness Enumeration (CWE) - and assigned a single Common Vulnerabilities and Exposures identifier (CVE ID) to each CWE grouping. |
||
|
3.9.26 |
Cisco Nexus 9000 Series Switches Silicon One Remote Code Execution Vulnerability |
This vulnerability exists because TCP ports 43210 and 43211 are accessible in the default Layer 3 (L3) virtual routing and forwarding (VRF). A successful exploit could allow the attacker to connect to an affected device and send crafted input that could be executed as code with root privileges. The exploitation of this vulnerability could also cause the S1HAL process to crash, which could cause the device to reload. |
||
|
3.9.26 |
A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. |
|||
|
3.9.26 |
At the time of publication, these vulnerabilities affected Cisco Secure Email devices if they were running Cisco AsyncOS Software Release 16.5.0 or earlier and had S/MIME configured for communication between email gateways. |
|||
|
3.9.26 |
Cisco Advance Notification for Publication of September 2, 2026, Security Advisories |
Under the Cisco risk-based disclosure process, hardening releases and other security advisories are scheduled to publish on the first and third Wednesday of each month. To help customers prepare, we provide this seven-day advance notice of upcoming security vulnerability disclosures. However, this schedule is not a final commitment of releases. If updates are delayed or unforeseen changes arise, specific products may be removed and rescheduled. Products may also be added when releases are ready ahead of schedule. The latest status is available in the Revision History section of this advance notice. |
||
|
3.9.26 |
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Crosswork engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that addresses multiple internally discovered vulnerabilities. |
|||
|
3.9.26 |
(CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations. |
|||
|
3.9.26 |
(CVSS score: 7.8) - A post-authentication operating system command injection vulnerability in SonicWall SMA 1000 Appliances that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. |
|||
|
3.9.26 |
(CVSS score: 9.3) - An SQL injection vulnerability in Sangoma Switchvox that could allow an unauthenticated remote attacker to execute arbitrary SQL statements against the backend PostgreSQL database using a single crafted request, including database operations and remote code execution. |
|||
|
3.9.26 |
(CVSS score: 9.8) - An improper authentication vulnerability in JFrog Artifactory that under default configuration could allow an unauthenticated attacker with network access to obtain administrative privileges. |
|||
|
3.9.26 |
(CVSS score: 6.5) - An HTTP request/response smuggling vulnerability in Kludex Starlette that could allow attackers to inject paths into the host part, prepending the actual path, leading to issues such as authentication bypass when the authentication depends on the reconstructed URL's path. |
|||
|
3.9.26 |
(CVSS score: 10.0) - An operating system command injection vulnerability in Kestra OSS that could allow an unauthenticated remote attacker to create and execute arbitrary workflows without credentials. |
|||
|
3.9.26 |
(CVSS score: 8.8) - An improper authentication vulnerability in Berri LiteLLM's Model Context Protocol (MCP) Streamable HTTP endpoint that could allow an unauthenticated attacker to establish an authenticated MCP session using an arbitrary Bearer token. |
|||
|
3.9.26 |
Arbitrary command execution in goose CLI via `goose review` via git core.fsmonitor |
|||
|
2.9.26 |
RevStealer is an infostealer variant found to be commonly distributed under the disguise of trojanized Electron desktop application. As reported by researchers from Morphisec, this malware strain is primarily spread through game-cheat websites and fake GitHub repositories. |
|||
|
2.9.26 |
Symantec has collected and analyzed a ransomware binary that belongs to a likely new double-extortion ransomware actor who goes by the name of "Fiasco". They utilize a Rust-written Windows 64Bit PE to encrypt files and append a .secure extension. |
|||
|
2.9.26 |
KryBit is a cross-platform Ransomware-as-a-Service (RaaS) that targets endpoints, virtual machines, and network storage spanning Windows, Linux, and VMware ESXi environments. As per a recent report from Picus Security, the attackers behind this ransomware variant are employing a double-extortion model, and exfiltrating sensitive data before encrypting sensitive files, appending them with a .KRYBIT extension and leaving a ransom note in the form of a .txt file. |
|||
|
2.9.26 |
Kaspersky has published a report on a campaign distributing the ValleyRAT backdoor disguised as adware. The malware arrives through installer files that, depending on a naming variant, install a decoy application such as a collaboration tool or browser while covertly deploying a modified version of a legitimate Chinese wallpaper utility. They're using that utility for DLL sideloading, so the malicious library gets to run under cover of a signed process. |
|||
|
2.9.26 |
BGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root Access |
|||
|
2.9.26 |
Mirax: a new Android RAT turning infected devices into potential residential proxy nodes |
RAT |
||
|
2.9.26 |
Uncovering StreamRat: From Meta Ads to Full Device Takeover |
RAT |
||
|
2.9.26 |
A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations. |
|||
|
2.9.26 |
Post-authentication Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution. |
|||
|
2.9.26 |
Hugging Face Transformers library writes remote code to disk prior to consent check |
A vulnerability in the Hugging Face Transformers library (versions 4.49.0 through 5.8.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. The library performs a remote module fetch and local cache write before evaluating the trust_remote_code consent prompt, violating the security contract enforced across other dynamic module-loading paths in the library. |
||
|
2.9.26 |
Malicious Cyber Actors Gain Access to Victim Accounts Through Consent Phishing |
Since late 2025, malicious cyber actors have been targeting prominent victims, their family members, and personal acquaintances by directly messaging personal accounts with malicious links leveraging a technique known as "OAuth consent phishing." |
||
|
2.9.26 |
Unauthenticated file upload via missing authorization on formatter upload endpoint |
|||
|
2.9.26 |
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) |
|||
|
2.9.26 |
An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa endpoint processes XML content beginning with <PolycomIPPhone> and directly concatenates the user-controlled PhoneIP value into PostgreSQL queries without sanitization or parameterization. |
|||
|
2.9.26 |
New Details on Plump Spider's Operations in Pix Fraud Schemes |
|||
|
2.9.26 |
JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. |
|||
|
1.9.26 |
GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability. Another zeroday in an antimalware provider, I'm not sure but I believe this vulnerability affect other GenDigital products as well (such as AVG, Norton...) |
|||
|
1.9.26 |
PaperCut NG/MF Missing Authentication for Critical Function Vulnerability |
|||
|
1.9.26 |
PaperCut NG/MF Unsafe Reflection Vulnerability |
|||
|
1.9.26 |
PaperCut NG/MF Missing Authentication for Critical Function Vulnerability |
|||
|
1.9.26 |
PaperCut NG/MF Unsafe Reflection Vulnerability |
|||
|
1.9.26 |
(CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. |
|||
|
1.9.26 |
aka KindaRails2Shell (CVSS score: 9.5) - A vulnerability that could allow an unauthenticated attacker to read arbitrary files from the server, leak Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials, and API tokens, ultimately leading to remote code execution. |