HOTNEWS 2026  January(174) February(168) March(221) April(222) May(261) June(255) July(464) August(106) September(0) October(0) November(0) December(0) | HOTNEWS 2026(1706)  STATISTICS (7358)

DATE

NAME

INFO

CATEGORY

SUBCATE

18.8.26

Operation ASTERIX Operation ASTERIX: Anatomy of a Crypto Fraud Pipeline OPERATION OPERATION

18.8.26

CVE-2026-15748 A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. VULNEREBILITY VULNEREBILITY

18.8.26

APT42 APT42: AI-Assisted Rapport Phishing and a More Resilient TAMECAT AI AI

18.8.26

HOLLOWGRAPH HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels MALWARE MALWARE

17.8.26

CVE-2007-3010 Alcatel OmniPCX Enterprise Remote Code Execution Vulnerability VULNEREBILITY VULNEREBILITY

17.8.26

CVE-2016-6277 NETGEAR Multiple Routers Remote Code Execution Vulnerability VULNEREBILITY VULNEREBILITY

17.8.26

CVE-2018-14558 Tenda AC7, AC9, and AC10 Routers Command Injection Vulnerability VULNEREBILITY VULNEREBILITY

17.8.26

CVE-2019-14931 Mitsubishi Electric Europe B.V. ME-RTU devices and INEA ME-RTU devices remote Command Injection vulnerability VULNEREBILITY VULNEREBILITY

17.8.26

CVE-2020-10987 Tenda AC1900 Router AC15 Model Remote Code Execution Vulnerability VULNEREBILITY VULNEREBILITY

17.8.26

CVE-2021-46422 Telesquare SDT-CW3B1 Command Injection vulnerability VULNEREBILITY VULNEREBILITY

17.8.26

CVE-2022-37055 D-Link Routers Buffer Overflow Vulnerability VULNEREBILITY VULNEREBILITY

17.8.26

CVE-2024-29269 Telesquare TLR-2005KSH Command Injection Vulnerability VULNEREBILITY VULNEREBILITY

17.8.26

CVE-2025-10123 D-Link DIR-823X Command Injection Vulnerability VULNEREBILITY VULNEREBILITY

17.8.26

CVE-2025-55583 D-Link DIR-868L B1 router Command Injection Vulnerability VULNEREBILITY VULNEREBILITY

16.8.26

The Jewelbug Dossier China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business. REPORT REPORT

16.8.26

CVE-2026-12569 A critical remote code execution (RCE) vulnerability has been reported in PTC Windchill PDMlink and PTC FlexPLM. The vulnerability may be exploited through the deserialization of untrusted data. VULNEREBILITY VULNEREBILITY

16.8.26

Plug&Pwn: Weaponizing
Windows PnP
Every time a USB device is plugged into a Windows machine, the operating system may silently download a package from Microsoft and execute vendor code as NT AUTHORITY\SYSTEM. That can happen without administrator privileges, without a logged-on user, and in some environments even remotely through RDP USB redirection. ATTACK ATTACK

16.8.26

CVE-2019-10617 Low privilege users can access service configuration which contains registry data that admins uses to create or delete entries in the registry in QCA6174_9377.WIN.1.0 in QCA6174_9377 VULNEREBILITY VULNEREBILITY

15.8.26

Cloudflare DDoS Threat Report H1 2026 Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave ATTACK ATTACK

15.8.26

CVE-2026-45659 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. VULNEREBILITY VULNEREBILITY

15.8.26

CVE-2026-20337 A vulnerability in the zip archive parser of ClamAV could... VULNEREBILITY VULNEREBILITY

15.8.26

Follow-Up Analysis of the 29 December 2025 Energy Sector Incident On 29 December 2025, coordinated attacks targeted the energy sector in Poland, including 30 renewable energy facilities and a large combined heat and power (CHP) plant. These attacks were described in detail in the report published on 30 January 2026*. At the same time, another incident occurred at a smaller CHP plant supplying heat to 50,000 residents. REPORT REPORT

15.8.26

OSDI '26 20th USENIX Symposium on Operating Systems Design and Implementation (OSDI ’26)

CONGRESS

OSDI '26

15.8.26

NSDI '26 23rd USENIX Symposium on Networked Systems Design and Implementation (NSDI ’26)

CONGRESS

NSDI '26

15.8.26

FAST '26 24th USENIX Conference on File and Storage Technologies (FAST ’26)

CONGRESS

FAST '26

15.8.26

USENIX Security '26 Thanks to those who joined us for the 34th USENIX Security Symposium. We hope you enjoyed the event. CONGRESS USENIX Security '26

15.8.26

VehicleSec '26 Symposium on Vehicle Security and Privacy

CONGRESS

VehicleSec '26

15.8.26

WOOT '26 Conference on Offensive Technologies brings together both academics and practitioners in the field of offensive security research.

CONGRESS

WOOT

15.8.26

Evooo1Bot FortiGuard Labs analyzes Evooo1Bot, a modular Linux botnet targeting internet-facing devices with DDoS, SSH attacks, CVE exploits, and SOCKS relays BOTNET BOTNET

15.8.26

CVE-2026-65400 An authentication issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.9, macOS Sonoma 14.8.9, macOS Tahoe 26.6.1. An attacker on the network may be able to authenticate to Screen Sharing without valid credentials. VULNEREBILITY VULNEREBILITY

14.8.26

CVE-2026-20339 A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. VULNEREBILITY VULNEREBILITY

14.8.26

CVE-2026-20338 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. VULNEREBILITY VULNEREBILITY

14.8.26

CVE-2026-20337 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. VULNEREBILITY VULNEREBILITY

14.8.26

CVE-2026-70468 A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.4.3 through 7.4.5, FortiManager Cloud 7.2.5 through 7.2.9 may allow attacker to improper access control via <insert attack vector here> VULNEREBILITY VULNEREBILITY

14.8.26

CVE-2026-49975 Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache HTTP Server: from 2.4.17 through 2.4.67. VULNEREBILITY VULNEREBILITY

14.8.26

CVE-2026-71407 A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or commands in the context of the WAD daemon via crafted sockets, only if the explicit proxy is configured with Kerberos authentication and SOCKS enabled. VULNEREBILITY VULNEREBILITY

14.8.26

CVE-2026-71408 A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via <insert attack vector here> VULNEREBILITY VULNEREBILITY

14.8.26

GhostDesk via Fake Softwares A new campaign documented by Malwarebytes details the distribution of a malicious Google Chrome extension dubbed GhostDesk, delivered through counterfeit software installers. Threat actors are luring Windows users to spoofed download portals for popular utilities, including CCleaner, 7-Zip, and Adobe Acrobat. ALERTS VIRUS

14.8.26

WindRelay and SpyNote Drive NFC Fraud Researchers at Group-IB recently reported a new malware family combination involving a custom near-field communication (NFC) relay tool dubbed WindRelay deployed alongside the known SpyNote remote access trojan (RAT). ALERTS VIRUS

14.8.26

Sandworm-Linked Group Uses Fake Job Interviews to Deploy Trojanized WireGuard Client According to CERT-UA, the Russian state-sponsored threat group Sandworm (tracked in this campaign as UAC-0145) is actively targeting system administrators and IT staff through fake job recruitment offers. ALERTS APT

14.8.26

Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side A months-long investigation by the Symantec Threat Hunter Team has produced unprecedented visibility into the activities of Jewelbug (aka Earth Alux, REF7707, CL-STA-0049), a China-based APT group that has been breaking into government ministries across Asia and the Middle East while quietly running a cryptocurrency fraud business on the side. ALERTS APT

14.8.26

Chaos Malware Variant Targeting Linux Cloud Infrastructure A new variant documented by Darktrace highlights how the Go-based Chaos botnet has shifted its targeting from edge routers to Linux cloud environments. Following an initial infection that quickly deletes its own footprint from the disk, the malware establishes long-term persistence using systemd services alongside a keep-alive script. ALERTS VIRUS

14.8.26

Gunra Ransomware expands its operations A joint cybersecurity advisory released by international law enforcement and intelligence agencies including CISA, the FBI, NSA, USSS, DC3, and South Korea’s KNPA warns organizations of Gunra, an escalating ransomware-as-a-service (RaaS) threat. ALERTS RANSOM

14.8.26

A new variant of the Kimwolf botnet identified in the wild Researchers at Unit 42 of Palo Alto Networks detailed the operation of Aeternum, a C++ botnet loader that uses public Polygon blockchain smart contracts to manage decentralized command-and-control (C2) operations. ALERTS BOTNET

14.8.26

Jewelbug Jewelbug: APT Group Runs Espionage and Crypto Fraud Operations Side by Side APT APT

14.8.26

NFC skimming attacks How criminals exploit the familiar “tap your phone to pay” feature to steal your money. ATTACK ATTACK

14.8.26

WindRelay Gone with the WindRelay: A New Malware Combo Behind a Growing Fraud Scheme MALWARE RAT/NFC

14.8.26

PATCHCORD PATCHCORD: New malware cluster targets Afghan telecom and South Asian critical infrastructure MALWARE BACKDOOR

14.8.26

AmnesiaStealer AmnesiaStealer: a multi-stage Rust-based macOS infostealer that hijacks Chromium browsers MALWARE STEALER

13.8.26

SmartApeSG ClickFix leads to two RATs Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website. MALWARE TRAFFIC MALWARE TRAFFIC

13.8.26

CVE-2026-15409 A Server-side request forgery (SSRF) vulnerability has been identified in the SMA1000 Appliance Work Place interface. A remote unauthenticated attacker could potentially cause the appliance to make requests to unintended location. VULNEREBILITY VULNEREBILITY

13.8.26

CVE-2026-15410 Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands. VULNEREBILITY VULNEREBILITY

13.8.26

CVE-2025-49113 Roundcube Webmail before 1.5.10 and 1.6.x before 1.6.11 allows remote code execution by authenticated users because the _from parameter in a URL is not validated in program/actions/settings/upload.php, leading to PHP Object Deserialization. VULNEREBILITY VULNEREBILITY

13.8.26

CVE-2026-68820 Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability VULNEREBILITY VULNEREBILITY

12.8.26

Head Mare Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants APT APT

12.8.26

Stealing Reasoning Traces from Proprietary LLM APIs Leading large language model providers now conceal their models’ step-by-step reasoning, or chainof-thought, to protect intellectual property and limit information leakage. Rather than storing these traces server-side, providers return them to the client as blocks of encrypted text, which the client passes back with each subsequent request. PAPERS PAPERS

12.8.26

CVE-2026-48362 (CVSS score: 10.0) - An operating system command injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23) VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-48273 (CVSS score: 9.9) - An eval injection vulnerability in ColdFusion that could lead to arbitrary code execution (Fixed in 2025.0.12 and 2023.0.23) VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-71384 (CVSS score: 9.6) - An incorrect authorization vulnerability in ColdFusion that could lead to an application denial-of-service (Fixed in 2025.0.12 and 2023.0.23) VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-71362 (CVSS score: 9.1) - An incorrect authorization vulnerability in Commerce that could lead to privilege escalation VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-71398 (CVSS score: 10.0) - An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400) VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-27302 (CVSS score: 10.0) - An incorrect authorization vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400) VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-48381 (CVSS score: 9.0) - An SQL injection vulnerability in Campaign Classic that could lead to arbitrary code execution (Fixed in ACC v7 7.4.4 build 9400) VULNEREBILITY VULNEREBILITY

12.8.26

TCG TPM 2.0 reference code found vulnerable to information leakage and timing side-channel attacks Two vulnerabilities have been identified in the Trusted Platform Module (TPM) 2.0 reference implementation: CVE-2026-6726 – Information leakage via falsified TPM keys.CVE-2026-6727 – A timing side-channel vulnerability in RSA OAEP decryption.An attacker with privileged access to a TPM command interface may be able to exploit these vulnerabilities by sending specially crafted TPM commands. ALERT ALERT

12.8.26

CVE-2026-20349

Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability

KEV

KEV

12.8.26

CVE-2026-68820

Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

KEV

KEV

12.8.26

CVE-2026-72898

Metabase SQL Injection Vulnerability

KEV

KEV

12.8.26

Aeternum Botnet Researchers at Unit 42 of Palo Alto Networks detailed the operation of Aeternum, a C++ botnet loader that uses public Polygon blockchain smart contracts to manage decentralized command-and-control (C2) operations. The threat actors leverage JSON-RPC requests to public Polygon endpoints to bypass conventional IP and domain blocking, staging secondary payloads including XWorm RAT, XMRig cryptocurrency miners, data stealers, and Telegram-controlled Python backdoors. ALERTS BOTNET

12.8.26

DeadLock Ransomware Combines Resource-Aware Encryption with Resilient Extortion Protocols Researchers at SOCRadar's Threat Research Unit recently reported on DOUBLECUP, a Russian Loader-as-a-Service platform built for ClickFix-style social engineering campaigns and active since early June 2026. Operators license access to a client panel and embed DOUBLECUP's front-end logic into lure pages, including sites spoofing NetSuite, Odoo, HubSpot, and Salesforce login portals. ALERTS RANSOM

12.8.26

CRPxO Ransomware Researchers at SOCRadar's Threat Research Unit recently reported on DOUBLECUP, a Russian Loader-as-a-Service platform built for ClickFix-style social engineering campaigns and active since early June 2026. Operators license access to a client panel and embed DOUBLECUP's front-end logic into lure pages, including sites spoofing NetSuite, Odoo, HubSpot, and Salesforce login portals ALERTS RANSOM

12.8.26

Largest AI Supply Chain Breach of 2026 2,500+ Companies and 434,000 CI/CD Pipelines Exposed in the Largest AI Supply Chain Breach of 2026 AI AI

12.8.26

CVE-2026-33634 Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-58231 SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application. VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-44772 (CVSS score: 9.9) - A code injection vulnerability in Manufacturing Integration and Intelligence VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-34265 (CVSS score: 9.8) - An out-of-bounds write vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform that allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This could be exploited to disclose sensitive system information or crash the system. VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-44758 (CVSS score: 9.1) - A code injection vulnerability in Manufacturing Integration and Intelligence that could allow an attacker with high privileges to execute arbitrary commands on the underlying operating system. VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-59124 Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-62878 Microsoft reports that CVE-2026-62878 is neither exploited in the wild nor publicly disclosed; it is a Critical Windows DNS Server remote code execution vulnerability with a CVSS score of 9.8. The flaw is a stack-based buffer overflow in Windows DNS that can be triggered remotely by an unauthenticated attacker sending a specially crafted packet to an affected service over the network, with no user interaction required, potentially allowing code execution on the target DNS server. VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-72971 This vulnerability was publicly disclosed before Patch Tuesday, making it a zero-day, but Microsoft says it has not been exploited in the wild; it is rated Important with a CVSS score of 5.5. The flaw is an improper link-resolution, or “link following,” issue in the Windows Container Isolation file system filter driver, unionfs.sys, affecting Windows 11 Version 26H1 on x64 and ARM64 systems. VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-62832 Microsoft says this vulnerability has been publicly disclosed but has not been exploited in the wild, making it a zero-day disclosure without confirmed exploitation at this time. Rated Important with a CVSS score of 7.8, this Windows User Profile Service flaw is an improper link resolution, or “link following,” issue that could allow a local authenticated attacker to elevate privileges. VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-68820 This Important-severity elevation of privilege vulnerability is listed by Microsoft as exploited in the wild but not publicly disclosed, and it has a CVSS score of 7.0. The flaw is a use-after-free issue in the Windows Ancillary Function Driver for WinSock affecting supported Windows client and server versions; a locally authenticated attacker with low privileges could run a specially crafted application to trigger a race condition and, if successful, gain SYSTEM privileges. VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-62815 This Critical Microsoft QUIC remote code execution vulnerability is not listed as exploited in the wild or publicly disclosed. It carries a CVSS score of 9.8 and is a use-after-free flaw that could allow an unauthenticated remote attacker to send a specially crafted packet to an affected service over the network and execute code on the target system, with no user interaction required. VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-53415 Use after Free in the annotator function of Zoom Clients may allow a meeting participant to achieve remote code execution of another participant via network access. VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-53414 Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting participant to conduct a denial of service on another participant via network access. VULNEREBILITY VULNEREBILITY

12.8.26

CVE-2026-53413 Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access. VULNEREBILITY VULNEREBILITY

12.8.26

Kimwolf v7 Kimwolf v7: An Evolution of the Kimwolf Botnet BOTNET BOTNET

11.8.26

DeadLock ransomware DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure RANSOM RANSOM

11.8.26

CVE-2026-63520 Multer is a node.js middleware for handling `multipart/form-data`. A vulnerability in Multer prior to version 2.1.1 allows an attacker to trigger a Denial of Service (DoS) by sending malformed requests, potentially causing stack overflow. Users should upgrade to version 2.1.1 to receive a patch. No known workarounds are available. VULNEREBILITY VULNEREBILITY

11.8.26

CVE-2026-55040 Weak authentication in Microsoft Office SharePoint allows an unauthorized attacker to bypass a security feature over a network. VULNEREBILITY VULNEREBILITY

11.8.26

CVE-2026-31431 Linux privilege escalation (“Copy Fail”) VULNEREBILITY VULNEREBILITY

11.8.26

CVE-2026-34197 ActiveMQ Remote Code Execution VULNEREBILITY VULNEREBILITY

11.8.26

CVE-2026-8512 Use-after-free in Chrome's File System Access API on macOS VULNEREBILITY VULNEREBILITY

11.8.26

CVE-2026-45185 EXIM unauthenticated Remote Code Execution VULNEREBILITY VULNEREBILITY

11.8.26

CVE-2026-22738 SpringAI SpEL Remote Code Execution VULNEREBILITY VULNEREBILITY

11.8.26

CVE-2026-20339 A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. VULNEREBILITY VULNEREBILITY

11.8.26

CVE-2026-20338 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. VULNEREBILITY VULNEREBILITY

11.8.26

CVE-2026-20337 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. VULNEREBILITY VULNEREBILITY

11.8.26

Sexual Exploitation Actors Stealing and Leaking Explicit Content The Federal Bureau of Investigation (FBI) warns the public about sexual exploitation (SE) actors targeting adult and underage victims1 by illegally accessing their social media and personal accounts to steal and post their explicit content (also known as non-consensual intimate images, or NCII) for sale on criminal marketplaces. IC3 IC3 PRESS

11.8.26

#StopRansomware: Gunra Ransomware Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. IC3 IC3 INDUSTRY

11.8.26

#StopRansomware: Gunra Ransomware Gunra is a ransomware-as-a-service (RaaS) used by affiliates to target government, critical infrastructure, and other organizations. The Gunra ransomware variant first appeared in 2025 and expanded to RaaS operations in 2026. The actors leverage a double-extortion model, both encrypting data and threatening to publish exfiltrated data to a dedicated leak site (DLS) if the ransom is not paid. GROUP RANSOM

11.8.26

Opencart ecommerce platform contains directory traversal vulnerability The OpenCart v4.2.0.0 extension installer contains a directory traversal vulnerability. The extension installation process extracts uploaded .zip files then uses the zip entry filenames as filesystem paths, without validating that the resolved path stays inside the intended directory. This vulnerability is tracked as CVE-2026-18412. ALERT ALERT

11.8.26

AA26-222A StopRansomware Gunra Ransomware The FBI originally observed Gunra ransomware in April 2025. The threat actors quickly established a DLS on the Tor network to list victims and publish exfiltrated data. As of January 2026, Gunra launched a formal RaaS affiliate program on dark web forums, providing affiliates with access to a management panel, a configurable ransomware builder, cross-platform locker payloads, and structured affiliate documentation. GROUP RANSOM

10.8.26

Operation Capsule Vault Operation Capsule Vault: RokRAT Attack Chain Analysis Using EMBED_PAYLOAD_v2 OPERATION OPERATION

10.8.26

Pass-the-Passkey Family of Attacks Coming from the field of enterprise security, we have spent much of our careers studying privilege escalation and lateral movement through attacks against Windows Integrated Authentication. But as more companies adopt cloud services, we decided to shift our attention to passkeys, which are slowly but steadily becoming the norm. REPORT REPORT

10.8.26

CVE-2026-34348 CVE-2026-34348 is a medium-severity information disclosure vulnerability (CVSS score 6.5) in the Windows Event Logging Service. It stems from a protection mechanism failure where sensitive data, such as passkey assertions or authentication material, is improperly logged in a recoverable form, letting an authorized attacker view data over a VULNEREBILITY VULNEREBILITY

10.8.26

CVE-2026-33691 The OWASP core rule set (CRS) is a set of generic attack detection rules for use with compatible web application firewalls. Prior to versions 3.3.9 and 4.25.0, a bypass was identified in OWASP CRS that allows uploading files with dangerous extensions (.php, .phar, .jsp, .jspx) by inserting whitespace padding in the filename (e.g. photo. php or shell.jsp ). VULNEREBILITY VULNEREBILITY

10.8.26

CVE-2026-3502 TrueConf Client downloads application update code and applies it without performing verification. An attacker who is able to influence the update delivery path can substitute a tampered update payload. VULNEREBILITY VULNEREBILITY

10.8.26

Соціальна інженерія у виконанні UAC-0145: компрометація у процесі працевлаштування CERT-UA отримано інформацію щодо застосування просунутих методів соціальної інженерії кластером кіберзагроз UAC-0145 (субкластер UAC-0002, також відомий як Sandworm, APT44, Seashell Blizzard). Зокрема, на сайтах пошуку роботи зловмисники, попередньо вивчивши резюме кандидата, від імені ІТ компанії (наприклад, ATLAS Business Group) виходять на зв'язок з потенційною жертвою, як правило системним адміністратором/ІТ фахівцем. BATTLEFIELD UKRAINE BATTLEFIELD UKRAINE

10.8.26

WhiteCobra Chassis Solidity Pro's WhiteCobra Chassis: Cloudflare C2 to Telegram Infostealer MALWARE STEALER

9.8.26

Safe RET Interrupt Vulnerability An external researcher has reported a potential vulnerability affecting AMD "Zen" architecture processors. The report claims that an attacker executing code on an affected system could inject an interrupt at a precise moment to disrupt “Safe RET,” the default Linux mitigation for Speculative Return Stack Overflow (SRSO), which could potentially weaken that protection and may result in information disclosure. VULNEREBILITY VULNEREBILITY

8.8.26

CVE-2026-20339 A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of&nbsp;memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during scanning, which may result in an integer overflow. VULNEREBILITY VULNEREBILITY

8.8.26

CVE-2026-20338 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip files during scanning. An attacker could exploit this vulnerability by submitting a crafted zip file for scanning. VULNEREBILITY VULNEREBILITY

8.8.26

CVE-2026-20337 A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper boundary checks for content in zip files during scanning, which may result in an out-of-bounds write condition. VULNEREBILITY VULNEREBILITY

8.8.26

CVE-2026-20294 A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist VULNEREBILITY VULNEREBILITY

8.8.26

CVE-2023-38646 Metabase RCE Vulnerability Explained VULNEREBILITY VULNEREBILITY

8.8.26

DOUBLECUP Loader-as-a-Service Deploys Stealthy RATs via Fake CRM Portals Researchers at SOCRadar's Threat Research Unit recently reported on DOUBLECUP, a Russian Loader-as-a-Service platform built for ClickFix-style social engineering campaigns and active since early June 2026. ALERTS VIRUS

8.8.26

Fake CAPTCHA Prompts Leverage ClickFix Tactics to Infect macOS Systems In a recent write-up, Huntress details a macOS stealer malware campaign that uses ClickFix social engineering tricks to compromise Apple systems and siphon cryptocurrency wallets. Initiated through malicious links in email messages, the attack presents victims with a fake CAPTCHA window instructing them to paste a shell command into the macOS Terminal. ALERTS VIRUS

8.8.26

Vanta Stealer Dubbed Vanta Stealer, a Python-based information stealer has been analyzed by the Lat61 Threat Intelligence Team, who describe it as a PyInstaller-packaged Windows executable with PyArmor-obfuscated bytecode protecting its core logic. ALERTS VIRUS

8.8.26

Greatness PhaaS Campaigns Continue In a recent write-up, ZeroBEC details a campaign utilizing the Greatness phishing-as-a-service (PhaaS) platform, tracked under the HoneyStorm tag by URLQuery. ALERTS CAMPAIGN

8.8.26

Popular NPM Packages Hijacked with New Shai-Hulud Malware Researchers at Aikido Security recently reported an active supply chain attack impacting widely downloaded npm libraries, including keyv and related caching utilities. The campaign leverages compromised maintainer credentials to publish poisoned package versions containing malicious preinstall hooks. ALERTS VIRUS

8.8.26

Abuse of ScreenConnect RMM and Cloudflare Tunnels in SMOKE#SCREEN Campaign Researchers at Securonix recently reported an active multi-stage campaign dubbed SMOKE#SCREEN that abuses legitimate ScreenConnect remote monitoring and management (RMM) software to gain persistent access to enterprise endpoints. The operation targets both Windows and macOS environments using social engineering lures themed around Zoom updates, corporate document reviews, and system utilities. ALERTS CAMPAIGN

8.8.26

CVE-2026-8037 Progress LoadMaster Command Injection Vulnerability KEV KEV

8.8.26

The nothings stb TrueType library, up to version 1.26, contains a heap buffer overflow vulnerability A heap buffer overflow vulnerability exists in the stb TrueType library created by nothings. Exploitation of this vulnerability can occur when handling malformed font data and may lead to both Denial of Service (DoS) and Information Disclosure. ALERT ALERT

8.8.26

Alinto SOGo v5.12.7 vulnerable to cross-site scripting via malformed ICS calendar invitations A cross-site scripting (XSS) vulnerability in Alinto SOGo v5.12.7 allows attackers to achieve remote code execution by embedding malicious SVG (Scalable Vector Graphics) objects in ICS (iCalendar) invitations. The vulnerability has been actively exploited in the wild, as confirmed by VirusTotal sightings. ALERT ALERT

8.8.26

MythStealer A credential-stealing worm hidden in more than 400 compromised npm packages automatically spread across software ecosystems by republishing malicious updates. MALWARE STEALER

8.8.26

Token Jacking It’s three a.m., do you know what your AI agent is doing? Unit 42 has responded to a growing number of AI token jacking cases resulting in staggering financial losses. AI AI

8.8.26

Flooding Dropper 'Flooding Dropper' Campaign Hits npm With Nearly 850 Malicious Packages CAMPAIGN CAMPAIGN

8.8.26

Pink New Data Extortion Group “Pink” Goes Big Game Hunting With Evasive Phishing Kits GROUP GROUP

8.8.26

UNC6671 UNC6671 Rebrands: Multi-Brand Vishing Extortion Targets Financial Services and Enterprise Cloud Environments GROUP GROUP

8.8.26

CVE-2026-64638 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79) VULNEREBILITY VULNEREBILITY

7.8.26

Payroll Pirates Payroll Pirates: Strange New Tides in Business Email Compromise CAMPAIGN CAMPAIGN

7.8.26

SCTPhantom SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free VULNEREBILITY VULNEREBILITY

7.8.26

CVE-2026-64564 In the Linux kernel, the following vulnerability has been resolved: sctp: don't free the ASCONF's own transport in DEL-IP processing sctp_process_asconf() caches the transport the ASCONF chunk is processed against in asconf->transport (== chunk->transport, set once in sctp_rcv()). VULNEREBILITY VULNEREBILITY

7.8.26

CVE-2026-44613 Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. The default CORS configuration allowed cross-origin state-changing requests and accepted text/plain request bodies, allowing an attacker who lures an authenticated user to a malicious site to perform actions on the user's behalf through REST and WebSocket endpoints. VULNEREBILITY VULNEREBILITY

7.8.26

ChainDrop ChainDrop: When Opening a Repository Becomes Execution CAMPAIGN CAMPAIGN

7.8.26

CVE-2026-54316 Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled model repositories—was auto-approved without a permission prompt or being subject to --allowedTools restrictions VULNEREBILITY VULNEREBILITY

7.8.26

CVE-2026-12537 Improper Neutralization used in an OS Command in the container launcher in Google Gemini CLI (versions prior to 0.39.1) and run-gemini-cli GitHub Action (versions prior to 0.1.22) on headless CI platforms allows an unprivileged attacker to achieve pre-sandbox host-level code execution a maliciously crafted .gemini/.env file. VULNEREBILITY VULNEREBILITY

7.8.26

CVE-2026-63913 In the Linux kernel, the following vulnerability has been resolved: netfilter: conntrack: tcp: do not force CLOSE on invalid-seq RST without direction check An unintended behavior in the TCP conntrack state machine allows a connection to be forced into the CLOSE state using an RST packet with an invalid sequence number. VULNEREBILITY VULNEREBILITY

7.8.26

CVE-2026-56181 Origin validation error in Windows Network Address Translation (NAT) allows an unauthorized attacker to perform spoofing over an adjacent network. VULNEREBILITY VULNEREBILITY

7.8.26

natjack A NEW ATTACK CLASS AGAINST NETWORK INFRASTRUCTURE DEVICES ATTACK ATTACK

7.8.26

CVE-2026-64561 A flaw was found in KVM in the Linux kernel. This vulnerability occurs due to improper validation of memory management unit (MMU) page roots after these pages are made available. An attacker could exploit this by triggering a scenario where KVM attempts to map memory into an invalid root, causing child shadow pages to inherit an invalid state. VULNEREBILITY VULNEREBILITY

7.8.26

ShadowRay 2.0 New Intelligence Links TeamPCP to ShadowRay 2.0 and Traces Activity back to 2020 CAMPAIGN CAMPAIGN

7.8.26

CVE-2026-64561 In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Check for invalid/obsolete root *after* making MMU pages available Check for a "stale" page fault, i.e. for an invalid and/or obsolete root, after making MMU pages available for the shadow MMU. VULNEREBILITY VULNEREBILITY

7.8.26

Zapscape Zapscape (CVE-2026-64561) is a use-after-free vulnerability that occurs in the shadow MMU of KVM/x86. When an attacker-controlled guest that uses nested virtualization makes KVM recursively zap a root shadow page that is still in use during MMU page quota reclaim, KVM keeps handling the fault on a root that has already become invalid. As a result an invalid child enters the active MMU page list, and afterwards the same list link is attached to two lists at once and then freed, producing a dangling link and a post-free write. VULNEREBILITY VULNEREBILITY

6.8.26

TONTOU: On the Exploitability of Time-of-Neutralization to Time-of-Use Windows Recently deployed Spectre v2 mitigations neutralize branch predictor state when switching privilege contexts or immediately prior to indirect branch execution, either through domain isolation or sanitization. These defenses assume that subsequent branch predictor behavior remains free from attacker influence until the neutralized state is used. EXPLOIT EXPLOIT

6.8.26

CVE-2026-20303 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20303 are related to improper input validation issues that are grouped under the Common Weakness Enumeration (CWE) CWE-20. VULNEREBILITY VULNEREBILITY

6.8.26

CVE-2026-20304 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in a software hardening release that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20304 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) CWE-284. VULNEREBILITY VULNEREBILITY

6.8.26

CVE-2026-20310 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20310 are related to improper link resolution before file access issues that are grouped under the Common Weakness Enumeration (CWE) CWE-59. VULNEREBILITY VULNEREBILITY

6.8.26

CVE-2026-20269 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20269 are related to issues with improper control of a resource through its lifetime that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-664. VULNEREBILITY VULNEREBILITY

6.8.26

CVE-2026-20268 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by CVE-2026-20268 are related to issues with improper restriction of operations within the bounds of a memory buffer that are grouped under the Common Weakness Enumeration (CWE) Pillar CWE-119. VULNEREBILITY VULNEREBILITY

6.8.26

CVE-2026-20267 As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. The vulnerabilities tracked by&nbsp;CVE-2026-20267 are related to improper access control issues that are grouped under the Common Weakness Enumeration (CWE) Pillar&nbsp;CWE-284. VULNEREBILITY VULNEREBILITY

6.8.26

CVE-2026-20289 A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is due to the logging of sensitive information. An attacker could exploit this vulnerability by enabling a specific logging level and then collecting the system logs. A successful exploit could allow the attacker to view sensitive information like user login credentials. VULNEREBILITY VULNEREBILITY

6.8.26

CVE-2026-20294 A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text on an affected system. This vulnerability is due to insufficient access control enforcement for specific template types that are not included in the encryption allowlist. A low-privileged attacker could exploit this vulnerability by viewing logs on the local system or on a remote logging server. A successful exploit could allow the attacker to view sensitive authentication credentials, which could lead to further compromise of network infrastructure and connected services. VULNEREBILITY VULNEREBILITY

6.8.26

CVE-2026-20028 Preact, a lightweight web development framework, JSON serialization protection to prevent Virtual DOM elements from being constructed from arbitrary JSON. A regression introduced in Preact 10.26.5 caused this protection to be softened. In applications where values from JSON payloads are assumed to be strings and passed unmodified to Preact as children, a specially-crafted JSON payload could be constructed that would be incorrectly treated as a valid VNode. VULNEREBILITY VULNEREBILITY

6.8.26

CVE-2026-20308 A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial of service (DoS) attack against an affected device. This vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by sending crafted input to the web-based management interface of an affected device. A successful exploit could allow the attacker to cause the web-based management interface to become unresponsive. VULNEREBILITY VULNEREBILITY

6.8.26

CVE-2026-20311 A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient error handling in the web-based management interface. An attacker could exploit this vulnerability by authenticating with a malformed certificate. A successful exploit could allow the attacker to cause the affected device to reload, resulting in a DoS condition. VULNEREBILITY VULNEREBILITY

6.8.26

CVE-2026-20316 A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. VULNEREBILITY VULNEREBILITY

6.8.26

CVE-2026-20200 CVE-2026-20200: Cisco Cisco Unified Computing System (Standalone): A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with… VULNEREBILITY VULNEREBILITY

6.8.26

CVE-2026-20288 A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with&nbsp;Admin privileges to execute arbitrary commands on the underlying operating system of an affected system and elevate privileges to root.&nbsp; VULNEREBILITY VULNEREBILITY

6.8.26

CVE-2026-20301 CVE-2026-20301: Cisco: A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol,… VULNEREBILITY VULNEREBILITY

6.8.26

CVE-2026-20263 GLPI is a free asset and IT management software package. From 11.0.0 to before 11.0.6, an unauthenticated time-based blind SQL injection exists in GLPI's Search engine. This vulnerability is fixed in 11.0.6. VULNEREBILITY VULNEREBILITY

6.8.26

CVE-2026-20124 The PhotoStack Gallery plugin for WordPress is vulnerable to SQL Injection via the 'postid' parameter in all versions up to, and including, 0.4.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database. VULNEREBILITY VULNEREBILITY

6.8.26

CVE-2026-20079 A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system.&nbsp; VULNEREBILITY VULNEREBILITY

6.8.26

CVE-2026-63077 JetBrains TeamCity Deserialization of Untrusted Data Vulnerability KEV KEV

6.8.26

CVE-2026-18236 A vulnerability in the Agent Development Kit (ADK) allows for continuation forgery in tool confirmations. An attacker who is able to manipulate or inject events into the session history can execute unauthorized tools by forging a tool confirmation response. VULNEREBILITY VULNEREBILITY

6.8.26

CVE-2026-18830 Insufficient input validation in Amazon Bedrock AgentCore harness might allow an authenticated remote user to execute configured tools bypassing model invocation and security controls via crafted content blocks in conversation messages. AWS has addressed this issue. No customer action is required. VULNEREBILITY VULNEREBILITY

6.8.26

ENDLESSDOORS ENDLESSDOORS Is Phoning Home. Pick Up. MALWARE MALWARE

6.8.26

Cost of a Data Breach Report 2026
The AI tipping point
Welcome to the 21st annual Cost of a Data Breach Report. Frontier AI models have radically shifted the cybersecurity threat landscape. REPORT REPORT

6.8.26

macOS ClickFix campaign From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide CAMPAIGN CAMPAIGN

5.8.26

CVE-2026-58073 A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials. VULNEREBILITY VULNEREBILITY

5.8.26

CVE-2026-58072 A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution. VULNEREBILITY VULNEREBILITY

5.8.26

CVE-2026-58067 A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service. VULNEREBILITY VULNEREBILITY

5.8.26

CVE-2026-58071 A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session begins. VULNEREBILITY VULNEREBILITY

5.8.26

Breaking the Paperclip Critical Vulnerabilities in AI Agent Orchestration

5.8.26

CVE-2026-41679 Paperclip is a Node.js server and React UI that orchestrates a team of AI agents to run a business. Prior to version 2026.416.0, an unauthenticated attacker can achieve full remote code execution on any network-accessible Paperclip instance running in `authenticated` mode with default configuration. VULNEREBILITY VULNEREBILITY

5.8.26

CVE-2026-64531 In the Linux kernel, the following vulnerability has been resolved: net: openvswitch: reject oversized nested action attrs Open vSwitch stores generated flow actions as nlattrs, whose nla_len field is u16. Commit a1e64addf3ff ("net: openvswitch: remove misbehaving actions length check") allowed the total sw_flow_actions stream to grow beyond 64 KiB, which is valid, but also removed the last guard preventing a generated nested action attribute from exceeding U16_MAX. VULNEREBILITY VULNEREBILITY

5.8.26

OVSwrap OVSwrap (CVE-2026-64531) local root exploit: mitigation for CloudLinux 9, 10, and CloudLinux for Ubuntu VULNEREBILITY VULNEREBILITY

5.8.26

CVE-2026-60004 . When these hook scripts are subsequently triggered during Git operations, they execute arbitrary shell commands with the privileges of the Gitea process user. VULNEREBILITY VULNEREBILITY

5.8.26

CVE-2026-49774 Improper Control of Generation of Code ('Code Injection') vulnerability in Filipe Nasc RD Station allows Remote Code Inclusion. This issue affects RD Station: from n/a through 5.6.0. VULNEREBILITY VULNEREBILITY

5.8.26

keyv and cacheable compromise On August 4, 2026, a threat actor compromised the source or release credentials for the widely used keyv and cacheable npm packages and published trojanized versions of at least ten packages, beginning with keyv@6.0.0 at 09:35 UTC. Unlike a typical dependency swap, each version carries a malicious preinstall hook (setup.mjs) that downloads a standalone Bun runtime and executes an obfuscated ~728 KB second stage (Math_Symbol.js). CAMPAIGN CAMPAIGN

5.8.26

Hump Hump Locker Ransomware Symantec's Threat Intelligence teams worldwide offer unparalleled analysis and commentary on current cyberthreats impacting businesses. Symantec's browser extensions integrate this intelligence directly into your browser, enabling effective detection and blocking of various web-borne threats. ALERTS RANSOM

5.8.26

Ongoing Threats of Swatting and Indicators for Community Members

This Public Service Announcement (PSA) is an update to Alert Number I-042925-PSA titled, "Threat Actors Use 'Swatting' to Target Victims Nationwide." This PSA contains updated information about the ongoing threat posed by “swatting” incidents targeting a variety of locations across the United States, including educational institutions, government buildings, religious institutions, public transportation centers, hospitals, and other public buildings.

IC3

IC3 PRESS

5.8.26

CVE-2026-9198

IBM Langflow Code Injection Vulnerability: Langflow contains a code injection vulnerability that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments.

IBM | Langflow

ECV

5.8.26

CVE-2026-34486

Apache Tomcat Missing Encryption of Sensitive Data Vulnerability: Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor.

Apache | Tomcat

ECV

5.8.26

CVE-2026-18556

N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability: N-able N-central contains an authentication bypass using an alternate path or channel that allows for authentication bypass.

N-able | N-central

ECV

5.8.26

CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability: N-able N-central contains an authentication bypass using an alternate path or channel allows for authentication bypass and account takeover in N-central. N-able | N-central ECV

5.8.26

CVE-2026-9198 IBM Langflow Code Injection Vulnerability KEV KEV

5.8.26

CVE-2026-18556 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability KEV KEV

5.8.26

CVE-2026-34486 Apache Tomcat Missing Encryption of Sensitive Data Vulnerability KEV KEV

5.8.26

CVE-2026-9198 (CVSS score: 9.8) - A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. (Fixed in July 2026 with version 1.10.1) VULNEREBILITY VULNEREBILITY

5.8.26

CVE-2026-34486 (CVS score: 7.5) - A missing encryption of sensitive data vulnerability in Apache Tomcat that allows a bypass of EncryptInterceptor, a cluster component that adds pre-shared key encryption to messages sent between cluster nodes. (Fixed in April 2026 with versions 11.0.21, 10.1.54, and 9.0.117) VULNEREBILITY VULNEREBILITY

5.8.26

Security Incident INC-2026-07-28-01 The UK AI Security Institute (AISI) exists to equip governments with a scientific understanding of the risks posed by advanced AI. To achieve that goal, AISI routinely evaluates the capabilities of frontier AI systems in domains such as cybersecurity. REPORT REPORT

5.8.26

QuickFox QuickFox Supply Chain Attack Used to Deploy FDMTP Implant CAMPAIGN CAMPAIGN

5.8.26

Telegram-Distributed M365 AiTM PhaaS ZeroBEC threat research on the Greatness phishing-as-a-service (PhaaS) platform, a commercially distributed kit sold via Telegram that combines adversary-in-the-middle (AiTM) credential and token theft with device code phishing in a single operator product. PHISHING PhaaS

4.8.26

Powercat malware campaign Powercat malware campaign: Fake game cheats deliver infostealer CAMPAIGN CAMPAIGN

4.8.26

Fake Xeno Roblox Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums MALWARE JAVA

4.8.26

SMOKE#SCREEN Analyzing SMOKE#SCREEN: ScreenConnect RMM Abuse, Cloudflare Tunnels, and Trusted Software Lures CAMPAIGN CAMPAIGN

4.8.26

Zero Day Provisioning Chaining TP-Link ZTP Vulnerabilities to Infiltrate Networks REPORT REPORT

4.8.26

CVE-2025-9290 An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline precomputation, potentially exposing sensitive information and compromising confidentiality. VULNEREBILITY VULNEREBILITY

4.8.26

CVE-2025-9289 A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. VULNEREBILITY VULNEREBILITY

4.8.26

Agent-to-Agent Privilege Boundary Failures I'll Just Call You: Agent-to-Agent Privilege Boundary Failures in CI/CD on Google's ADK Repository AI AI

4.8.26

CVE-2026-58047 HTTP Smuggling in cPanel allows potential leak of credentials. VULNEREBILITY VULNEREBILITY

4.8.26

CVE-2026-58048 Improper preservation of SQL mode when renaming databases in cPanel allows execution of SQL in root context. VULNEREBILITY VULNEREBILITY

4.8.26

DOUBLECUP Introducing DOUBLECUP, a ClickFix Loader Delivering CountLoader and DeviceManager RATs MALWARE LOADER

4.8.26

Critical N-able N-central Vulnerability and Active Exploitation N-able has disclosed a critical vulnerability impacting all current versions of N-central, including 2026.3, across both hosted and on‑prem deployments. The flaw can give attackers unauthenticated, "god-mode" access to the RMM console. EXPLOIT EXPLOIT

4.8.26

CVE-2026-18577 N-able N-central Authentication Bypass Using an Alternate Path or Channel Vulnerability KEV KEV

3.8.26

SonicWall SMA Exploit Chain From WSProxy to Root: INC ransomware and SonicWall SMA Exploit Chain EXPLOIT EXPLOIT

3.8.26

Larva-24009 Analysis of a Phishing Email Attack Case by the Larva-24009 Threat Actor GROUP GROUP

3.8.26

DarkSword DarkSword's Panel Sprawl: How One Body Hash Unravels a Six-Panel, Two-Codebase Operator Cluster EXPLOIT EXPLOIT

3.8.26

ExfilSquad ExfilSquad Targets Misconfigured Microsoft Power Pages Portals CAMPAIGN CAMPAIGN

3.8.26

CVE-2026-17883 Inappropriate implementation in Headless in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium) VULNEREBILITY VULNEREBILITY

3.8.26

CVE-2026-18577 An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 VULNEREBILITY VULNEREBILITY

3.8.26

CVE-2026-18556 Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1. VULNEREBILITY VULNEREBILITY

3.8.26

FaceHugger FaceHugger: Vulnerabilities in Hugging Face Diffusers Open Door to Supply Chain Attacks on Enterprise AI VULNEREBILITY VULNEREBILITY

3.8.26

CVE-2026-44827 (CVSS score: 8.8) - A code injection vulnerability that allows arbitrary code to be loaded through the custom_pipeline flow from a Hub repository by means of a crafted pipeline with the name "None.py" despite passing trust_remote_code=False (or omitting it, which is the default). VULNEREBILITY VULNEREBILITY

3.8.26

CVE-2026-45804 (CVSS score: 7.5) - A race condition vulnerability that allows arbitrary code to be introduced to a repository by modifying the configuration between the hf_hub_download and snapshot_download HTTP calls to the Hub, leading to code execution. VULNEREBILITY VULNEREBILITY

3.8.26

CVE-2026-44513 (CVSS score: 8.8) - A code injection vulnerability that allows arbitrary code to be loaded through the custom_pipeline flow from a Hub repository despite passing trust_remote_code=False (or omitting it). VULNEREBILITY VULNEREBILITY

2.8.26

AUR Attack Prompts Adoption Lock A new round of Arch User Repository malware has prompted the disabling of package adoption. ATTACK AI

2.8.26

Threat H1 2026 December 2025 – May 2026 Report Welcome to the H1 2026 issue of the ESET Threat Report! REPORT REPORT

2.8.26

Alert to Countries, Companies, and Other Entities Regarding North Korean IT Workers North Korea relies upon a network of skilled Information Technology (IT) workers, deployed within and outside of North Korea, to obtain false identities and remotely earn income to fund North Korea’s unlawful nuclear weapons and ballistic missile programs. IC3 IC3 INDUSTRY

2.8.26

VirtualGHOST A "VirtualGHOST" (or just Ghost) is a VMware Virtual Machine on an ESXi host that has been powered on manually from the command line. MALWARE VMware ESXi

2.8.26

CVE-2026-63077 In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remote code execution was possible via the agent polling protocol VULNEREBILITY VULNEREBILITY

1.8.26

CVE-2026-61511 vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval injection vulnerability in the vB5_Template_Runtime::runMaths() method within the template runtime that allows unauthenticated remote attackers to execute arbitrary PHP code by supplying crafted input through the pagenav[pagenumber] parameter. VULNEREBILITY VULNEREBILITY

1.8.26

CVE-2013-4786 The IPMI 2.0 specification supports RMCP+ Authenticated Key-Exchange Protocol (RAKP) authentication, which allows remote attackers to obtain password hashes and conduct offline password guessing attacks by obtaining the HMAC from a RAKP message 2 response from a BMC. VULNEREBILITY VULNEREBILITY

1.8.26

ValleyRAT distribution campaign targeting organizations in Japan As reported by the researchers from Cato Networks, the Monarch threat group (aka SilverFox) has recently launched a malicious campaign targeting a Japanese industrial manufacturing company to deliver ValleyRAT, a persistent remote access trojan. Initiated via invoice-themed phishing emails linked to attacker-controlled content hosted on legitimate Tencent Cloud and QQ services, the attack drops a compressed file containing an initial downloader executable. ALERTS VIRUS

1.8.26

AtlasRAT malware variant AtlasRAT is a Remote Access Trojan (RAT) variant delivered through malicious setup files disguised as legitimate Flash Player software. As reported by researchers from ASEC, to obfuscate its command-and-control traffic, AtlasRAT utilizes ChaCha20 encryption over TLS, employing self-signed certificates spoofed to resemble Microsoft update infrastructure. ALERTS VIRUS

1.8.26

SmartApeSG ClickFix campaign pushes unidentified RAT Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website. MALWARE TRAFFIC MALWARE TRAFFIC

1.8.26

Seven days of scans and probes and web traffic hitting my web server Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website. MALWARE TRAFFIC MALWARE TRAFFIC

1.8.26

CVE-2026-48448 Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability that could lead to disclosure of sensitive memory. VULNEREBILITY VULNEREBILITY

1.8.26

CVE-2026-48449 Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. VULNEREBILITY VULNEREBILITY

1.8.26

CaptiveCrunch CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft CAMPAIGN CAMPAIGN

1.8.26

Matryoshka Nested Trust: HollowFrame’s Layered Loader and Matryoshka Backdoors MALWARE Backdoor