HOTNEWS 2026  January(174) February(168) March(221) April(222) May(261) June(255) July(464) August(446) September(518) October(115) November(0) December(0) | HOTNEWS 2026(2676)  STATISTICS (7358) | ARCHIVE

DATE

NAME

INFO

CATEGORY

SUBCATE

10.10.26

CVE-2025-30241 Certain web interface components in affected TP-Link Aginet devices do not validate and sanitize user-supplied input properly before passing it to system-level command execution functions. An authenticated adjacent attacker may inject specially crafted input to execute arbitrary operation system commands with elevated privileges. Successful exploitation may allow execution of arbitrary system commands, potentially leading to full device compromise.

VULNEREBILITY

VULNEREBILITY

10.10.26

CVE-2025-30240 The affected TP-Link Aginet devices do not properly validate symbolic links created on external USB storage devices. By placing a crafted symbolic link on supported storage media, an attacker may cause the system to resolve the link. Successful exploitation may allow unauthorized read access to sensitive files within the device filesystem.

VULNEREBILITY

VULNEREBILITY

10.10.26

CVE-2025-30239 In affected TP-Link Aginet devices, use of hardcoded cryptographic keys embedded in the firmware to protect sensitive configuration data may allow an attacker who has access to device storage to recover the keys and decrypt stored data. Successful exploitation may allow access to decrypted sensitive configuration data, including credentials and service-related information.

VULNEREBILITY

VULNEREBILITY

10.10.26

CVE-2025-30238 In affected TP-Link Aginet devices, insufficient authorization validation allows authenticated low-privileged users to execute higher-privileged operations. An attacker may perform administrative actions such as creating privileged accounts or modifying critical configuration settings.

VULNEREBILITY

VULNEREBILITY

10.10.26

CVE-2025-30237 The affected TP-Link Aginet devices contain a flaw in the web management interface where authentication checks are not consistently enforced on certain endpoints. An attacker can send specially crafted requests to bypass authentication and directly invoke privileged functionality without valid credentials. This issue arises from improper enforcement of access control mechanisms on sensitive operations. Successful exploitation may allow an unauthenticated attacker to execute privileged operations and gain full control of the device.

VULNEREBILITY

VULNEREBILITY

10.10.26

CVE-2026-47483 NVIDIA DCGM Exporter for all platforms contains a vulnerability in the /debug/pprof endpoints, where an attacker could cause uncontrolled resource consumption by submitting concurrent unauthenticated profiling requests.

VULNEREBILITY

VULNEREBILITY

10.10.26

GhostAction New GhostAction Wave Hits Hundreds of Repos, Expanding Beyond CI/CD Secrets to Cloud Credentials

CAMPAIGN

CAMPAIGN

10.10.26

ARTEX Unknown Threat Actor Uses AI-Driven ARTEX to Target South Korean Finance GROUPS GROUPS

10.10.26

SCARLET LOOP A model discovers and qualifies 6,171 companies that move money. An autonomous agent tests credentials and exploits login weaknesses. At least 11,832 credentials validated as active across 107 countries.

REPORT

REPORT

10.10.26

CVE-2015-3306

ProFTPD Improper Access Control Vulnerability: ProFTPD contains an improper access control vulnerability that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

ECV

ECV

10.10.26

CVE-2021-3199

ONLYOFFICE Docs Server Path Traversal Vulnerability: ONLYOFFICE Docs contains a path traversal vulnerability that can occur when JWT is used, via a /.. sequence in an image upload parameter and could allow for remote code execution.

ECV

ECV

10.10.26

CVE-2023-22894

Strapi Cleartext Storage of Sensitive Information Vulnerability: Strapi contains a cleartext storage of sensitive information vulnerability that could allow attackers with access to the admin panel to discover sensitive user details via the query filter. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version.

ECV

ECV

10.10.26

CVE-2016-3081

Apache Struts Command Injection Vulnerability: Apache Struts contains a command injection vulnerability that could allow remote attackers to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.

ECV

ECV

10.10.26

CVE-2015-5477

ISC BIND Data Processing Errors Vulnerability: ISC BIND contains a data processing errors vulnerability that could allow remote attackers to cause a denial of service via TKEY queries.

ECV

ECV

10.10.26

CVE-2026-88779

Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability: Citrix NetScaler ADC (formerly Citrix ADC) and Citrix NetScaler Gateway (formerly Citrix Gateway) contain an improper restriction of operations within the bounds of a memory buffer vulnerability that could allow for a denial of service.

ECV

ECV

10.10.26

Dire Wolf Ransomware

Dire Wolf Ransomware is a double-extortion ransomware first observed in April 2025. By August 2026, it had claimed 100 victims across 32 countries, including the United States and Brazil, mainly in professional services, manufacturing, healthcare, technology, and financial services.

RANSOM

RANSOM

10.10.26

Earth Sirrush

Earth Sirrush has repeatedly changed its tools and delivery methods, but TrendAI™ Research reveals how shared code, reused artifacts, and infrastructure patterns continue to expose the links between its campaigns.

CAMPAIGN

CAMPAIGN

10.10.26

Tensorlake

tensorlake@0.5.144 on npm steals credentials when you install it, then tries to spread to other packages and repos. It also sets a trap. If you revoke the GitHub token it stole, a background job on your machine deletes your home directory.

MALWARE

PYTHON

10.10.26

NEBULA

CloudSEK uncovered NEBULA, a malicious npm supply-chain campaign involving seven fake AI SDK packages distributed through four attacker-controlled accounts. Disguised as legitimate developer tools, these packages deploy a modified KNTRAT Windows trojan capable of stealthy remote access, camera and microphone surveillance, and persistence.

MALWARE

PYTHON

10.10.26

AgentCorruption: One Role to Rule Them Al

Exploring what the agent's default execution role and stolen credentials can actually do, and how they became an entry point to the entire region - discovering and invoking other agents, reading, deleting and hijacking private conversations through chat history tampering, and more.

HACKING

AI

10.10.26

AgentCorruption: Credential Theft from AWS's Secrets Manager and More

Up to now, we showed how far we could get once we had the over-privileged role in hand: we were able to pull container images, talk to other agents that we were never allowed to, read private conversations, plant short- and long-term memories to control agents’ behavior and delete user data. All of this stays within the AWS region boundary.

HACKING

AI

10.10.26

AgentCorruption: Weaponizing Agent Memory for Persistent Hijacking

How access to AgentCore Memory let us plant instructions that survived beyond the initial compromise, turning an agent's remembered context into a channel for persistent command and control.

HACKING

AI

10.10.26

AgentCorruption: Initial IMDS Access

How a single prompt to a public-facing AgentCore agent exposed the instance metadata endpoint, the agent's cloud identity, and its container image: the foothold for everything that follows in this series.

HACKING

AI

10.10.26

DarkSword/Coruna

Open directories on five hosts exposed the full DarkSword/Coruna iOS exploit-and-harvest platform, from the C2 delivery server to the per-wallet theft modules. The infrastructure was still in use at triage time.

EXPLOIT

EXPLOIT

10.10.26

Warden Stealer

Gen Threat Labs has been tracking Warden Stealer, an emerging and actively developed malware-as-a-service (MaaS) infostealer written in the Rust programming language that has, within just a few months, already become one of the most prevalent infostealers in our user base.

MALWARE

STEALER

10.10.26

UAT-11985

Cisco Talos identified an advanced persistent threat (APT) spear-phishing campaign against individuals affiliated with Taiwan research organizations. The operation leveraged legitimate public event themes and impersonated reputable academic and policy institutions to establish credibility.

GROUPS

APT

10.10.26

MATCHBOIL

ESET Research catalogs the changes of UAC-0099’s MATCHBOIL downloader from 2024 to 2026

MALWARE

DOWNLOADER

9.10.26

CVE-2026-105133

(CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java" component.

VULNEREBILITY

VULNEREBILITY

9.10.26

CVE-2026-105134

(CVSS v4 score: 9.3) - An operating system command injection vulnerability in the Replication Receiver component.

VULNEREBILITY

VULNEREBILITY

9.10.26

CVE-2015-3306

(CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow remote attackers to read and write to arbitrary files via the site cpfr and site cpto commands.

VULNEREBILITY

VULNEREBILITY

9.10.26

CVE-2021-3199

(CVSS score: 9.8) - A path traversal vulnerability in ONLYOFFICE Docs that can occur when JSON Web Token (JWT) is used, via a "/.." sequence in an image upload parameter and could allow for remote code execution.

VULNEREBILITY

VULNEREBILITY

9.10.26

CVE-2023-22894

(CVSS score: 7.2) - A cleartext storage of sensitive information vulnerability in Strapi that could allow an attacker with access to the admin panel to discover sensitive user details via the query filter.

VULNEREBILITY

VULNEREBILITY

9.10.26

CVE-2016-3081

(CVSS score: 8.1) - A command injection vulnerability in Apache Struts that could allow a remote attacker to execute arbitrary code via method:prefix when Dynamic Method Invocation is enabled.

VULNEREBILITY

VULNEREBILITY

9.10.26

CVE-2015-5477

(CVSS score: 7.5) - A reachable assertion vulnerability in ISC BIND that could allow a remote attacker to cause a denial-of-service via TKEY queries.

VULNEREBILITY

VULNEREBILITY

9.10.26

CVE-2026-107406

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-107406

VULNEREBILITY

VULNEREBILITY

9.10.26

CVE-2026-88779

Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

KEV

KEV

9.10.26

CVE-2026-102489

Zammad GmbH Zammad Session Fixation Vulnerability

KEV

KEV

9.10.26

CVE-2026-102490

Zammad GmbH Zammad Improper Privilege Management Vulnerability

KEV

KEV

9.10.26

Chinese Government-linked Cyber Threat
Actors Combine Automated and Handson Hacking Tools to Steal Sensitive Data

Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal sensitive data from organizations worldwide, including US critical infrastructure sectors.

REPORT

REPORT

8.10.26

RatPressto Phish Kit

Fortra Intelligence and Research Experts (FIRE) has discovered an active phishing campaign leveraging a reusable Adobe-themed phishing kit deployed across multiple compromised WordPress websites.

PHISHING

Phish Kit

8.10.26

MALFEX campaign

MALFEX npm Malware Campaign: Three Payloads And An Adversary That Signs Their Work

CAMPAIGN

CAMPAIGN

8.10.26

Cisco Meraki Security Hardening Release: October 2026

As part of Cisco's ongoing commitment to proactive security and product quality, engineering teams conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

VULNEREBILITY

VULNEREBILITY

8.10.26

Cisco License (Smart Software Manager) On-Prem Vulnerabilities

Multiple vulnerabilities in the web-based management interface and API endpoints of Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), could allow a remote attacker to gain unauthorized access, access sensitive information, cause a denial of service (DoS)

VULNEREBILITY

VULNEREBILITY

8.10.26

Cisco Nexus 3000 and 9000 Series Switches NGOAM Remote Code Execution Vulnerabilities

Multiple vulnerabilities in the Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software, known as Next Generation OAM (NGOAM), could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS)

VULNEREBILITY

VULNEREBILITY

8.10.26

Cisco NX-OS Software NX-API Remote Code Execution Vulnerability

A vulnerability in the NX-API feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient input

VULNEREBILITY

VULNEREBILITY

8.10.26

Cisco Nexus 3000 and 9000 Series Switches MPLS OAM Remote Code Execution Vulnerability

A vulnerability in the MPLS Operation, Administration, and Maintenance (OAM) feature of Cisco NX-OS Software for Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges or

VULNEREBILITY

VULNEREBILITY

8.10.26

Cisco License (Smart Software Manager) On-Prem Security Hardening Release: October 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the engineering team for Cisco License On-Prem, formerly Cisco Smart Software Manager On-Prem (SSM On-Prem), has conducted a comprehensive internal security review. This review resulted in software hardening

VULNEREBILITY

VULNEREBILITY

8.10.26

Cisco NX-OS Software Security Hardening Release: October 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco NX-OS Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities.

VULNEREBILITY

VULNEREBILITY

8.10.26

Cisco Application Policy Infrastructure Controller Security Hardening Release: October 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple

VULNEREBILITY

VULNEREBILITY

8.10.26

Cisco Finesse Server-Side Request Forgery Vulnerability

A vulnerability in the web-based management interface of Cisco Finesse could allow an unauthenticated, remote attacker to conduct server-side request forgery (SSRF) attacks through an affected device.This vulnerability is due to improper input validation for specific HTTP requests

VULNEREBILITY

VULNEREBILITY

8.10.26

Cisco NX-OS Software Control Plane Denial of Service Vulnerability

A vulnerability in Cisco NX-OS Software could allow an unauthenticated, remote attacker to exhaust system resources, causing a denial of service (DoS) condition.This vulnerability exists because rate limiting was improperly applied to some protocols. An attacker could exploit this

VULNEREBILITY

VULNEREBILITY

8.10.26

Cisco NX-OS Software Python Sandbox Escape Vulnerability

A vulnerability in the Python interpreter of Cisco NX-OS Software could allow an authenticated, local attacker with low privileges to escape the Python sandbox and gain unauthorized access to the underlying operating system of an affected device.This vulnerability is due to

VULNEREBILITY

VULNEREBILITY

8.10.26

Cisco Application Policy Infrastructure Controller Unauthorized File Access Vulnerability

A vulnerability in the export policies functionality of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to access sensitive files on an affected device. To exploit this vulnerability, the attacker must have valid

VULNEREBILITY

VULNEREBILITY

8.10.26

Cisco Application Policy Infrastructure Controller API Command Injection Vulnerability

A vulnerability in the web-based management API for Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, remote attacker to execute arbitrary commands as the root user. To exploit this vulnerability, the attacker must have valid administrative

VULNEREBILITY

VULNEREBILITY

8.10.26

Cisco Nexus 9000 Series Fabric Switches in ACI Mode Endpoint Group Contract Bypass Vulnerability

A vulnerability in the endpoint group (EPG) contract functionality of Cisco Nexus 9000 Series Fabric Switches in ACI Mode could allow an unauthenticated, remote attacker to bypass configured EPG contracts.This vulnerability is

VULNEREBILITY

VULNEREBILITY

8.10.26

PoeLLM

Canto incognito: tracking the PoeLLM malware

MALWARE

AI

8.10.26

CVE-2026-102255

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. By abusing this path, a remote unauthenticated attacker could potentially exploit this vulnerability to direct the appliance to issue requests on their behalf and reach internal functionality and perform unauthorized operations.

VULNEREBILITY

VULNEREBILITY

8.10.26

CVE-2026-105192

LMCache multiprocess mode, also called distributed mode, opens an unauthenticated ZeroMQ ROUTER so worker processes can register and share KV cache blocks. Messages on that socket are msgpack.

VULNEREBILITY

VULNEREBILITY

8.10.26

CVE-2026-105756

Loose `cache_salt` validation lets a single request kill EngineCore on LMCache-MP deployments — uncaught downstream `ValueError` denial of service

VULNEREBILITY

VULNEREBILITY

7.10.26

FortiBleed Operations Continue Targeting Exposed Systems Leading to Reports of Lockouts

FortiBleed refers to a credential-harvesting and access-broker operation whose internal workflow became visible only after the threat actors unintentionally exposed their own backend server. The open directory revealed a mature, multi-stage campaign targeting FortiGate SSL VPN appliances, harvesting credentials at scale, and cracking them using a distributed graphics processing unit (GPU) cluster.

IC3

IC3 INDUSTRY

7.10.26

LUNEXSTEALER

In September 2026, CERT-UA specialists discovered over 100 compromised websites to which malicious JavaScript code had been added by attackers. When visiting such a site, the user was shown a fake Cloudflare verification page, which, under the pretext of confirming that the visitor was a human, offered to execute a command.

MALWARE

LINUX

7.10.26

CyberXero

SOCRadar’s Threat Research Unit (STRU) has documented CyberXero, a Russian-speaking, financially motivated Initial Access Broker that pairs commodity offensive tooling with an AI orchestration layer running on its own infrastructure.

HACKING

AI

7.10.26

CrocoRat

ClickFix campaigns have become one of the most effective ways to turn a browser session into code execution. The technique is simple: show the victim a fake verification page, place a command on the clipboard, and convince them to paste it into the Windows Run dialog.

MALWARE

RAT

7.10.26

IronChain

During Cybersecurity Awareness Month, ransomware remains one of the clearest examples of how a cyber incident can become a business continuity issue. IronChain shows why. It puts business-critical data at risk of permanent loss and can bring operations to a halt.

RANSOM

RANSOM

7.10.26

Android Security Bulletin—October 2026

This Android Security Bulletin contains details of security vulnerabilities that affect Android devices. Security patch levels of 2026-10-01 or higher address all of these issues. To learn how to check a device's security patch level, see Check and update your Android version.

VULNEREBILITY

SOFTWARE PATCH REPORTS

7.10.26

Pixel Update Bulletin—October 2026

The Pixel Update Bulletin contains details of security vulnerabilities and functional improvements affecting supported Pixel devices (Google devices). For Google devices, security patch levels of 2026-10-05 or later address all issues in this bulletin and all issues in the October 2026 Android Security Bulletin.

VULNEREBILITY

SOFTWARE PATCH REPORTS

7.10.26

BPFDoor

SMTP is the key: BPFDoor and AVERAT hitting the network edge

MALWARE

DROPPER

6.10.26

CVE-2026-71168

Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability.

VULNEREBILITY

VULNEREBILITY

6.10.26

CVE-2026-63697

Dell System Update, versions prior to 2.3.0.0, contains an Improper Certificate Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution.

VULNEREBILITY

VULNEREBILITY

6.10.26

CVE-2026-86362

Dell System Update, versions prior to 2.3.0.0, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

VULNEREBILITY

VULNEREBILITY

6.10.26

CVE-2026-86361

Dell System Update, versions prior to 2.3.0.0, contains an Incorrect Permission Assignment for Critical Resource vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges.

VULNEREBILITY

VULNEREBILITY

6.10.26

CVE-2026-86360

Dell System Update, versions prior to 2.3.0.0, contains an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Filesystem access for attacker.

VULNEREBILITY

VULNEREBILITY

6.10.26

ClickFix & Beyond 

Mapping the expanding family of user-assisted malware delivery techniques Report | September 2026

REPORT

REPORT

6.10.26

CVE-2021-26086

Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path traversal vulnerability in the /WEB-INF/web.xml endpoint. The affected versions are before version 8.5.14, from version 8.6.0 before 8.13.6, and from version 8.14.0 before 8.16.1.

VULNEREBILITY

VULNEREBILITY

6.10.26

CVE-2026-21589

CVE-2026-21589 - Arbitrary File Access Vulnerability impacts Multiple Products

VULNEREBILITY

VULNEREBILITY

6.10.26

CVE-2026-96940

Microsoft Exchange Server Elevation of Privilege Vulnerability

VULNEREBILITY

VULNEREBILITY

5.10.26

ClingSTUN

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

MALWARE

BACKDOOR

5.10.26

Horizon3’s Tales from the Trenches: Anthropic’s Mythos and Rejetto HFS

Anthropic started Project Glasswing with the mission of securing the world’s most critical software. Since joining the project in July of 2026, Horizon3 has used Anthropic’s Mythos model in its vulnerability research pipelines to discover many critical vulnerabilities. Horizon3’s participation in the project came with our own internal mission to find vulnerabilities likely to be found and exploited in the wild by threat actors at scale.

VULNEREBILITY

VULNEREBILITY

5.10.26

CVE-2026-88779

Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability

KEV

KEV

5.10.26

CVE-2026-61500

Rejetto HFS 3.0.0 through 3.2.0 derives its session...

VULNEREBILITY

VULNEREBILITY

5.10.26

CVE-2026-88779

Citrix NetScaler ADC and Citrix NetScaler Gateway Security Bulletin for CVE-2026-88779

VULNEREBILITY

VULNEREBILITY

5.10.26

Atomic macOS (AMOS) Stealer infection from malicious ad impersonating Claude Code

Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website.

MALWARE TRAFFIC

MALWARE TRAFFIC

5.10.26

SmartApeSG ClickFix pushes CNCmachineRMS RAT

Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website.

MALWARE TRAFFIC

MALWARE TRAFFIC

5.10.26

Macfinger ClickFix activity

Zip files are password-protected. Of note, this site has a new password scheme. For the password, see the "about" page of this website.

MALWARE TRAFFIC

MALWARE TRAFFIC

5.10.26

TA419

Hallucinating Credibility: China-Aligned TA419 Impersonates its Way into US AI Policy Circles

GROUPS

GROUPS

4.10.26

Decoding
emergence
2026 Microsoft Digital Defense Report

The challenge confronting security leaders today is no longer a lack of information. It is the growing complexity of the environments they are responsible for protecting.

REPORT

REPORT

4.10.26

CVE-2026-104286

An improper limitation of a pathname to a restricted directory ('path traversal') vulnerability in Fortinet FortiMail 8.0.0 through 8.0.1, FortiMail 7.6.0 through 7.6.6, FortiMail 7.4.0 through 7.4.8, FortiMail 7.2.0 through 7.2.9 may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

VULNEREBILITY

VULNEREBILITY

4.10.26

FBI INTERNET CRIME REPORT 2025

In 2025, the FBI Internet Crime Complaint Center (IC3) celebrated its 25th anniversary as the central hub for reporting cyber-enabled crime. This milestone signifies the FBI's enduring commitment to fighting the ever-evolving cyber threat. Our success in protecting individuals and organizations is driven by public participation and robust data analysis.

REPORT

REPORT

4.10.26

Warlock

Warlock Ransomware Attackers Hit Water and Telecom Operators

RANSOM

RANSOM

4.10.26

CVE-2026-92371

TeamViewer Full Client and Host for Linux prior version 15.82 contains an improper path validation vulnerability in the Cloud Session Recording (CSR) functionality. By exploiting a race condition during path validation and subsequent file access, a local authenticated attacker may cause privileged file operations in unintended locations on the affected system.

VULNEREBILITY

VULNEREBILITY

4.10.26

CVE-2026-92369

TeamViewer Full Client and Host prior to version 15.82 on Windows contain a TOCTOU race condition in the installer rollback mechanism. A local low-privileged attacker can replace rollback backup files stored in a user-writable temporary directory before they are restored by an elevated installer, resulting in privilege escalation to NT AUHORITY/SYSTEM. Exploitation requires successful timing of the race condition and a rollback during installation or update.

VULNEREBILITY

VULNEREBILITY

4.10.26

CVE-2026-19743

Improper path validation in the local IPC service of TeamViewer Full Client and Host on Windows, Linux, and macOS prior to version 15.82 allows a local authenticated user with low privileges to perform arbitrary file writes with elevated privileges (NT AUTHORITY/SYSTEM \ root). By sending crafted IPC commands to the local service daemon, an attacker could manipulate file paths, leading to local privilege escalation.

VULNEREBILITY

VULNEREBILITY

4.10.26

CVE-2026-92368

TeamViewer Full Client and Host for Linux and macOS prior version 15.82 contain a heap-based buffer overflow vulnerability in the processing of .tvs session recording files. A size mismatch during decompression of recorded session data can result in out-of-bounds heap writes. By convincing a user to open a specially crafted session recording through the "Play or convert recorded session…" feature, an attacker may achieve arbitrary code execution with the privileges of the current user

VULNEREBILITY

VULNEREBILITY

4.10.26

CVE-2026-92370

An improper access control vulnerability in TeamViewer Full Client, Host, and related affected modules on Windows, Linux, and macOS allows an authenticated remote attacker to bypass user-configured permission settings during session establishment. By modifying access control parameters for restricted features, an attacker can perform actions that were explicitly denied by the victim's configuration.

VULNEREBILITY

VULNEREBILITY

3.10.26

CVE-2026-102489

Zammad GmbH Zammad Session Fixation Vulnerability: Zammad GmbH Zammad contains a session fixation vulnerability that can lead to remote code execution as the zammad user. This vulnerability can be chained with CVE-2026-102490.

ECV

ECV

3.10.26

CVE-2026-102490

Zammad GmbH Zammad Improper Privilege Management Vulnerability: Zammad GmbH Zammad contains an improper privilege management vulnerability that can allow the local zammad user to escalate privileges to root. This vulnerability can be chained with CVE-2026-102489.

ECV

ECV

3.10.26

CVE-2026-104286

Fortinet FortiMail Path Traversal Vulnerability: Fortinet FortiMail contains a path traversal and an improper neutralization of NULL byte or NULL character vulnerability that may allow an unauthenticated attacker to write arbitrary files on the underlying system via crafted HTTP or HTTPS requests.

ECV

ECV

3.10.26

CVE-2026-76504

Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability: Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.

ECV

ECV

3.10.26

Cisco Catalyst SD-WAN Manager API Authentication Bypass Vulnerability

A vulnerability in the API session-based authentication management of Cisco Catalyst SD-WAN Manager could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user.This vulnerability is due to improper handling of URI encoding

VULNEREBILITY

VULNEREBILITY

3.10.26

Cisco IOS XE Software Security Hardening Release: August 2026

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered

VULNEREBILITY

VULNEREBILITY

3.10.26

CloudSyncD

CloudSyncD: a two-stage macOS backdoor that hides a phished password in zero-width Unicode

MALWARE

MACOS

3.10.26

CVE-2026-90970

GitLab has remediated a vulnerability in the GitLab AI Gateway component affecting all versions of the AI Gateway from 18.1.6 before 19.2.4, 19.3 before 19.3.2, and 19.4 before 19.4.1 that, under certain conditions, could have allowed an authenticated user with Duo Agent Platform access to escape the prompt template sandbox via a specially crafted flow configuration, resulting in arbitrary command execution on the AI Gateway.

VULNEREBILITY

VULNEREBILITY

3.10.26

UAT-11587

China-nexus UAT-11587 targets government and policy organizations across Asia with Antino backdoor

GROUPS

GROUPS

3.10.26

CVE-2026-67273

(CVSS score: 9.6) - An improper neutralization of special elements used in a template engine vulnerability that a low-privilege attacker with remote access could exploit to escalate privileges, access sensitive information, and carry out unauthorized RBAC tampering.

VULNEREBILITY

VULNEREBILITY

3.10.26

CVE-2026-61421

(CVSS score: 9.8) - A use of hard-coded cryptographic key vulnerability in the JWT authentication component of karavi-authorization that a remote unauthenticated attacker with knowledge of this publicly available signing secret could exploit to forge authentication tokens and gain administrative privileges.

VULNEREBILITY

VULNEREBILITY

3.10.26

CVE-2026-54472

(CVSS score: 9.8) - A use of hard-coded credentials vulnerability in the CSM Authorization module that a remote unauthenticated attacker could exploit to forge cryptographically valid administrative tokens and gain unauthorized administrative access to the CSM Authorization proxy.

VULNEREBILITY

VULNEREBILITY

3.10.26

CVE-2026-67269

(CVSS score: 9.9) - An improper privilege management vulnerability in the ContainerStorageModule Custom Resource reconciler that a low-privilege remote attacker could exploit to escalate privileges and gain root-level access on cluster nodes.

VULNEREBILITY

VULNEREBILITY

3.10.26

CVE-2026-63692

(CVSS score: 10.0) - A missing authentication for critical function vulnerability in the authorization proxy and tenant service that an unauthenticated network attacker could exploit to bypass authentication controls and gain administrative-level privileges.

VULNEREBILITY

VULNEREBILITY

3.10.26

CVE-2026-63688

(CVSS score: 10.0) - A missing authentication for critical function vulnerability in the csm-authorization-storage gRPC server that an unauthenticated remote attacker could exploit to obtain unauthorized access to storage backend administrator credentials for all registered storage arrays.

VULNEREBILITY

VULNEREBILITY

3.10.26

Milk Dragon

Milk Dragon, also known as NaiLong is an Adversary-in-the-Middle (AiTM) phishing kit active since October 2025. Unlike conventional phishing tactics that rely on fear and urgency, Milk Dragon lures victims with big discounts on consumer goods distributed via Facebook and TikTok marketplace advertisements.

APT

APT

3.10.26

SmokeLoader

This week, the SonicWall Capture Labs Threat Research Team reviewed a sample of SmokeLoader malware. This is a modular program used by a variety of criminal and APT groups to gain a foothold on a system. It has vigorous anti-VM, anti-AV, and anti-analysis checks and capabilities. SmokeLoader can be used with RATs, ransomware, backdoors or botnets and uses both file and fileless methods of persistence.

MALWARE

LOADER

3.10.26

VioletRAT v6.5

Recently, the SonicWall Capture Labs Threat Research Team discovered a sophisticated multi-stage .NET malware campaign that delivers VioletRAT v6.5 through a heavily obfuscated infection chain. The malware uses multiple .NET loader stages, an obfuscated batch script, in-memory assembly loading, and process injection into Msbuild.exe before executing the final VioletRAT payload.

MALWARE

RAT

2.10.26

Malicious packages posing as KakaoTalk messaging app installers

ASEC Ahnlab researchers reported about an evolution of recently monitored campaigns where adversaries are manipulating search engine optimization (SEO) to steer unsuspecting users toward counterfeit KakaoTalk installers. The packaging of these trojanized setup packages progressively shifted across NSIS, Advanced Installer, and Inno Setup formats, bundling authentic software alongside malicious components.

ALERTS

VIRUS

2.10.26

Antino Malware Targets Asian Governments

In a recent write-up, Cisco Talos details UAT-11587, a China-nexus cluster active since September 2025 that delivers a previously undocumented Rust backdoor named Antino. The targets are government, defense, diplomatic, legislative and research organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, Myanmar and Syria.

ALERTS

VIRUS

2.10.26

CloudSyncD macOS Backdoor Delivered via Fake Zoom Installer

According to Jamf Threat Labs, researchers discovered a two-stage macOS backdoor dubbed CloudSyncD that arrives hidden inside fake Zoom application installers. The malicious dropper convinces users into bypassing Gatekeeper protections and entering their system password

ALERTS

VIRUS

2.10.26

Warlock ransomware targets water and telecom operators

The China-nexus group behind Warlock ransomware is still breaking into organizations through Microsoft SharePoint vulnerabilities, a tactic that brought it to prominence a year ago. In the past two months, the group, which Symantec tracks as Longlegs (aka Storm-2603), attacked at least four organizations in Portuguese- and Spanish-speaking countries across Europe, Africa, and Latin America.

ALERTS

RANSOM

2.10.26

BotHelper RAT

Researchers at Point Wild recently reported a new malware family dubbed BotHelper, a .NET remote access trojan equipped with real-time desktop monitoring functions. Targeting Windows environments, the infection begins with a native executable stager that fingerprints the host machine and intentionally disables TLS certificate validation to retrieve an encrypted payload from a remote server.

ALERTS

VIRUS

2.10.26

Brimstone APT Delivers ComicPulse Backdoor Through RedFlick Technique

Researchers at Microsoft Threat Intelligence recently reported on evolving cyberespionage tradecraft from the Russian state-sponsored group Brimstone (aka Star Blizzard). The group has pivoted from narrow spear-phishing toward broader initial-contact email operations while adopting compromised host platforms to distribute malicious content.

ALERTS

APT

2.10.26

Multi-stage attack leveraging KMS Auto that leads to scareware

A recent K7 Security Labs investigation highlights a multi-phase intrusion campaign wherein adversaries leverage KMS Auto, which is an an unofficial third-party utility used to bypass licensing and activate various Microsoft products.

ALERTS

SPAM

2.10.26

LxBase RAT Hits Russian Firms

In a recent write-up, BI.ZONE Threat Intelligence details a new campaign deploying LxBase RAT against Russian organizations. Between July and September 2026, attackers targeted a wide array of domestic industries, including finance, energy, retail, logistics, and engineering.

ALERTS

VIRUS

2.10.26

New PamStealer Variant Targets macOS Users

A new variant documented by Jamf Threat Labs targets macOS environments with an upgraded version of the PamStealer infostealer. Attackers trick users into downloading a malicious disk image by impersonating a multichain cryptocurrency wallet called Wavel.

ALERTS

VIRUS

2.10.26

InsydeH2O IHISI SMM is vulnerable to unsafe memory write operations

An Out-of-bounds Write vulnerability in the InsydeH2O IHISI software used by HP PC BIOS can allow a local attacker with OS kernel privileges to perform arbitrary physical memory writes, including writes to System Management RAM (SMRAM). Because the vulnerable code executes in System Management Mode (SMM), successful exploitation can allow an attacker to modify SMM-protected memory and potentially achieve arbitrary code execution in SMM.

ALERT

ALERT

2.10.26

ollama.sys

Elastic Security Labs reports that RONINGLOADER writes ollama.sys to a temporary directory, creates a temporary service to load it, and sends target process IDs to the driver to terminate antivirus processes. The service is deleted after the termination request.

VULNEREBILITY

DRIVE

2.10.26

SC WordPress Malware

SC WordPress Malware: A Self-Healing Mesh of Loaders, Drop-Ins, and a Blockchain-Controlled Backdoor

MALWARE

LOADER

2.10.26

CVE-2026-104286

Fortinet FortiMail Path Traversal Vulnerability

KEV

KEV

1.10.26

CVE-2026-86950

CVE-2026-86950: The Great Glyph Grift

VULNEREBILITY

VULNEREBILITY

1.10.26

CVE-2026-86134 Fireware OS Pre-Authentication NULL Pointer Dereference Allows Remote Denial of Service

Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21

VULNEREBILITY

VULNEREBILITY

1.10.26

CVE-2026-86104 Fireware OS Resource Exhaustion in Login Process Allows Denial of Service

Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21

VULNEREBILITY

VULNEREBILITY

1.10.26

CVE-2026-18145 Fireware OS Stack-based Buffer Overflow in spamd Allows Remote Code Execution

Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21

VULNEREBILITY

VULNEREBILITY

1.10.26

CVE-2026-13046 Fireware OS Deserialization of Untrusted Data in samld Allows Remote Code Execution

Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21

VULNEREBILITY

VULNEREBILITY

1.10.26

CVE-2026-86101 Fireware OS Authorization Bypass in SAML Login Allows Unauthorized SSLVPN Access

Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21

VULNEREBILITY

VULNEREBILITY

1.10.26

CVE-2026-86133 Fireware OS Pre-Authentication Integer Underflow in iked Allows Remote Denial of Service

Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21

VULNEREBILITY

VULNEREBILITY

1.10.26

CVE-2026-13224 Fireware OS Path Traversal in WebUI Management Agent Allows Arbitrary Local File Read

Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21

VULNEREBILITY

VULNEREBILITY

1.10.26

CVE-2026-86132 Fireware OS Pre-Authentication Integer Underflow in iked Allows Denial of Service

Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21

VULNEREBILITY

VULNEREBILITY

1.10.26

CVE-2026-86105 Fireware OS Improper Authorization in Access Portal Reverse Proxy

Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21

VULNEREBILITY

VULNEREBILITY

1.10.26

CVE-2026-90441 Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant B

Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21

VULNEREBILITY

VULNEREBILITY

1.10.26

CVE-2026-86131 Fireware OS Code Injection in BOVPN Over TLS Client Allows Remote Code Execution

Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21

VULNEREBILITY

VULNEREBILITY

1.10.26

CVE-2026-86136 Fireware OS Missing Authorization in wgagent Management API Allows Denial of Service - Variant A

Default>= 2026.0, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21

VULNEREBILITY

VULNEREBILITY

1.10.26

CVE-2026-81433 Fireware OS Pre-Authentication Stack Buffer Overflow in fingerd Allows Remote Code Execution

Fireware OS>= 2026.3, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3

VULNEREBILITY

VULNEREBILITY

1.10.26

CVE-2026-86128 Fireware OS NULL Pointer Dereference in NetFlow IPv6 Traffic Processing Allows Remote Denial of Service

Default>= 2026.3, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21

VULNEREBILITY

VULNEREBILITY

1.10.26

CVE-2026-18105 Fireware OS Uncontrolled Resource Consumption in Diagnostic Tasks Allows Denial of Service

Default>= 2026.3, < 2026.3.2, >= 2025.0, < 2026.2.3, >= 12.0, < 12.12.3>= 2026.3.2, >= 2026.2.3, >= 12.12.3T15/T35>= 12.0, < 12.5.21>= 12.5.21

VULNEREBILITY

VULNEREBILITY

1.10.26

CVE-2026-101891 WatchGuard AP Improper Access Control in API Service Allows Unauthenticated Access

WatchGuard AP>= 1.0, < 3.4.8>= 3.4.8

VULNEREBILITY

VULNEREBILITY

1.10.26

CVE-2026-86102 WatchGuard AP Command Injection in Internal Management API Allows Command Execution

WatchGuard AP>= 1.0, < 3.4.8>= 3.4.8

VULNEREBILITY

VULNEREBILITY

1.10.26

CVE-2026-87969 WatchGuard AP Authenticated Command Injection in Diagnostic CLI

WatchGuard AP>= 1.0, < 3.4.8>= 3.4.8

VULNEREBILITY

VULNEREBILITY