Archive · daily briefs
All daily briefs
Every published brief, newest first · one page per UTC day. For the rolling window view, read the live brief.
Sat 03 Oct 2026Symantec: Warlock's operator steals SharePoint machine keys, forges signed payloads and ships ransomware via SYSVOL1 findingFri 02 Oct 2026Cisco confirms exploitation of an unauthenticated admin bypass in the SD-WAN controller; no workaround, fixes per trainFortinet confirms exploitation of an unauthenticated FortiMail file-write flaw; no branch has a fixed build yet · DIVD says two Zammad zero-days breached it; NCSC-NL…10 findings · 2 criticalWed 30 Sep 2026Apple patches a CoreGraphics zero-day exploited against targeted iPhone users; a crafted file can lead to code executionMicrosoft DART: one reset-compromised identity became a malicious pipeline that harvested Kubernetes credentials · Microsoft: Star Blizzard adds mass mailings and a…4 findingsTue 29 Sep 2026Microsoft: the same toolkit rides into victims regardless of which ransomware brand signs the noteCompromised security appliances, not a key theft, gave the attacker a path to Bitget's wallet server · Push Security's detection data: ClickFix has become the default…5 findingsMon 28 Sep 2026Citrix confirms in-the-wild exploitation of two default-configuration NetScaler zero-days and publishes no workaroundMicrosoft ties JADEPUFFER's cloud operations to two Azure service principals: one enumerated a tenant for 15+ hours, the other destroyed resources in minutes ·…4 findings · 1 criticalSun 27 Sep 2026Huntress: attacker JavaScript in a signed Windows AppX host drives Microsoft's own OAuth broker, so a genuine login yields MFA-surviving refresh…4 findingsSat 26 Sep 2026Kiteworks warned of an imminent attack; its 2026-09-30 advisories now include an unauthenticated root-level code-execution chain in the mail gatewayMicrosoft confirms active exploitation of a SharePoint bug it quietly re-rated a month earlier · Bern moves the critical-infrastructure breach-reporting duty into a new…3 findingsFri 25 Sep 2026A forged JWT with the wrong signature algorithm walks straight into admin on WSO2's API gateway stackSwiss parliament sends a sovereign-cloud mandate to the Federal Council despite its own recommendation to reject it2 findingsThu 24 Sep 2026WordPress's fix for a pre-auth file-inclusion bug is already outrun by a public Nuclei template and confirmed file-write attemptsArchived portal code undercuts Australia's 'AI agent hacked a government system' framing · ShinyHunters claims it stole FBI staff and applicant data via PeopleSoft; the…6 findings · 1 criticalWed 23 Sep 2026F5 confirms exploitation of an unauthenticated RCE in BIG-IP's OAuth authentication gatewayArista confirms exploitation of an SD-WAN orchestrator flaw that has no patch for two of its four release trains · Check Point patches a management-server zero-day it…8 findings · 3 criticalTue 22 Sep 2026Synology's own advisory implies trivial exploitation for two unauthenticated CVSS 9.8 DSM flaws, with no mitigation availableCISA adds a pre-auth Zyxel switch RCE to KEV after GreyNoise catches a Red Heron-linked actor exploiting it at scale · Project Zero details a reusable Windows…4 findingsMon 21 Sep 2026Elastic Security Labs: a Brazilian banking-fraud toolkit defeats Chromium's extension-integrity check by extracting the browser's own signing keys…Huntress: a fake Lenovo driver installs a working, private certificate authority into a victim's own trust store, able to fake 'clean' VirusTotal lookups · Huntress lays…9 findingsSun 20 Sep 2026Fifty credential-free, no-interaction flaws span Oracle's middleware, ERP, BI and telco-assurance lines in an off-quarter patch release50 CVEs1 findingSat 19 Sep 2026Unbound's DNSSEC validator can be pointed at attacker-controlled memory by a malicious zone it was only asked to resolveSeven agencies report DPRK's fake-interview crew infected 30,000+ devices and took $10.7M in crypto between December 2025 and July 2026 · CISA lists three separate Linux…3 findingsFri 18 Sep 2026A stack overflow in Check Point's unauthenticated management login reaches root. Patch or restrict management access nowBrevo's own integrity checks never saw the tampering because the attacker rewrote pages at Cloudflare's edge, not on Brevo's servers · Kaspersky: a single compromised…7 findingsThu 17 Sep 2026Cisco confirms active exploitation of an unauthenticated ISE API bypass that can reach root, found while resolving a customer support caseGoogle patches a Pixel modem zero-day that CISA lists as exploited, and TechCrunch reports Google as saying it may be under limited, targeted exploitation · Mandiant: a…7 findings · 1 criticalWed 16 Sep 2026Lumen: an unattributed cluster hides its command-and-control behind an IoT messaging broker so infected hosts never talk to the attacker directlyNCSC-UK, the FBI and AIVD detail an Iranian spyware family that gives every victim their own private Telegram bot for command and control2 findingsTue 15 Sep 2026Cisco's mail gateway can be rooted by a single crafted email, and Cisco found out from a real customer's compromiseA Swiss Bitcoin payment processor takes itself offline over a suspected breach, but says customer funds stay safe under its non-custodial design · Switzerland's…3 findings · 1 criticalMon 14 Sep 2026Anthropic: a freelance team used Claude Code to build a drone swarm that picks its own targets and decides when to detonate1 findingSun 13 Sep 2026Anthropic discloses a Russia-linked actor whose AI agents detect their own malware getting caught and rebuild it, unattendedRevolut handed over customer identity documents and crypto histories because the request came from an authentic-looking government email address2 findingsSat 12 Sep 2026Two dormant JFrog Artifactory bugs, patched weeks ago, are now confirmed chained into full admin takeoverGitLab's maximum-severity file-read flaw went from patch to in-the-wild probing in about 24 hours · ConnectWise patches a ScreenConnect flaw Huntress had already watched…4 findings · 1 criticalFri 11 Sep 2026Apereo's own advisory: "you are affected if you simply run CAS", patch now, technical detail is still under embargoIvanti discloses two unauthenticated pre-auth RCEs in Neurons for ITSM, crediting LLM-assisted review with surfacing several of the disclosed flaws · Bern's cantonal…3 findingsThu 10 Sep 2026Two pre-auth code-execution flaws sit in the certificate-processing step every VPN negotiation runs before a user ever authenticatesSix espionage clusters ran the identical click-to-SYSTEM exploit kit within days of each other; Proofpoint calls it the same code, not parallel development · Two…5 findings · 1 criticalWed 09 Sep 2026Microsoft names two exploited Windows privilege-escalation zero-days, splitting the newest and legacy build linesCalif builds a self-propagating zero-click WeChat worm with AI help in about nine days; Tencent fixed it before disclosure2 findingsTue 08 Sep 2026Adobe rates its own emergency hotfix priority 1 for a flaw stores were already being compromised through since before Sansec publishedCloudSEK gained admin access to the panel and found custom code specifically written to defeat the one MFA class that structurally resists this attack · ANSSI…4 findings · 1 criticalMon 07 Sep 2026N-able ships a fourth emergency hotfix in a month after a fully patched N-central server was compromised again through a brand-new flawInsikt Group: the same six-tool stack followed thirteen unrelated CVEs into Exchange, SharePoint, FortiOS, Cisco IOS XE, F5 BIG-IP, GeoServer and Apache Shiro · ChimeraZ…4 findings · 1 criticalSun 06 Sep 2026CERT Polska confirms active exploitation of an unauthenticated SSH takeover chain against internet-exposed MikroTik RouterOS devicesCrowdStrike, Gen Digital and Kaspersky have all now remediated one researcher's four security-product PrivEsc PoCs, per LevelBlue's follow-up analysis · Dell's on-prem…7 findings · 1 criticalSat 05 Sep 2026Two GeoNetwork flaws chain into unauthenticated remote code execution on government geodata catalog backendsA court case-management SaaS vendor held undisclosed backup copies of sealed court data outside the courts' own visibility or control2 findingsFri 04 Sep 2026An attacker who never touched Coder's source code hijacked its CDN routing to serve credential-stealing Terraform modules for half a dayAn exposed self-hosted AI chat interface handed researchers the operators' playbook for a campaign against Mexican and Ecuadorian government infrastructure · HPE patches…7 findingsThu 03 Sep 2026The intrusion's most consequential step is a remote-management connection from a non-administrative process to systems that should never see oneA months-old, already-patched Langflow RCE draws 360 attack attempts in days once honeypots start counting · A field meant to hold a phone's IP address is concatenated…9 findingsWed 02 Sep 2026A broken email-verification check on one identity provider let attackers silently bind to any Dropbox account with 2FA disabledBern almost handed a hyperscaler the register that verifies whether a Swiss digital identity is genuine · An Iranian espionage actor's first scripting-language implants…3 findingsTue 01 Sep 2026JFrog patches a default-configuration authentication bypass that hands an unauthenticated network attacker full Artifactory adminKaspersky documents ValleyRAT distributed through a trojanized adware installer that disables Defender before loading the backdoor via DLL sideloading · Anthropic…3 findings · 1 criticalMon 31 Aug 2026Three unrelated AI platforms, three intrusions, one pattern: gateways and orchestrators concentrate the credentials and execution privilege attackers…The fake-CAPTCHA lure now targets a console that can run multi-line scripts, not the one-line Run box · A BI tool's own admin API handed over the production database…6 findingsSun 30 Aug 2026Applying the same patch twice writes an executable into $GIT_DIR of a bare clone, and Git then runs it as the Gitea userThe DMZ component enterprises trust as their gateway to WebLogic has been exploited since January; CISA listed it on 24 August · Berlin confirms extortion after a…3 findingsSat 29 Aug 2026A pre-auth RCE chain in PaperCut NG/MF was exploited before any patch existed; tested maintenance releases now replace three emergency patchesAn attacker defeated Switzerland's cantonal vehicle-registry rate limits at scale, and two operators were then extorted · ServiceNow patches four unauthenticated flaws…7 findings · 1 criticalFri 28 Aug 2026The UK's national CERT tells operators to stop assuming their OT is inaccessible from the internet, and to go verify itAn attacker can reconstruct admin credentials for an exposed refrigeration controller offline, then silently disable cooling while the display reports normal · An…36 findingsMon 24 Aug 2026SynkLoader pairs a fake Windows lock screen with a backconnect proxy, so the stolen domain password is used from the victim's own addressBACS report: the public sector remains the largest share of Swiss mandatory CI reports at 19.4%, and basic hygiene would have stopped the Poland sabotage · SilkParasite…6 findingsSun 23 Aug 2026No exploit and no payload, the victim approves the attacker's session, or issues a credential the second factor never seesBuild scripts execute before the crate's own code, so
cargo build was the whole exploit; Wiz ties the infrastructure to two DPRK-linked npm campaigns · Both flaws are…11 findingsSat 22 Aug 2026The advisory records carry no version data at all; a national CERT's structured copy yields the one fixed release4.4.20 fixed a flaw in every version; 4.4.21 fixed a second one in 4.4.20 itself, with no identifier to track it by · The fixed-firmware table runs to nineteen rows, and…6 findingsFri 21 Aug 2026CERT Polska discloses 13 ATutor flaws against an end-of-life product; one is pre-auth to administrator, and no fix is coming13 CVEs1 findingThu 20 Aug 2026The agencies say the targeting is not limited to Siemens, and that what they see is reconnaissance rather than confirmed manipulationCSDD's own staff found the intrusion and stopped it in hours; the outsourced monitoring never raised it, and the supervisory board has resigned · 943 patches in a…10 findingsWed 19 Aug 2026The blocklist matches MIME keys exactly, so a pipe-alternative key walks a PHP file past itAn identity provider's account-recovery path is the account-takeover path, and one affected Red Hat product has no fix at all · GitLab breaks its own release cadence for…7 findingsTue 18 Aug 2026A developer's own browser is the attack path into a local Ray cluster, CISA catalogued the flaw as exploited on 17 AugustDeliberate trace removal turned a scoped breach notification into a blanket one at an Austrian public-law body · Zurich District Court sentences the Stadler Rail…3 findingsMon 17 Aug 2026Akira reboots a SonicWall-VPN victim into Safe Mode to strip EDR, and starves its own encryptorEspionage implants run command-and-control through the Google Sheets API and persist by rewriting browser shortcuts2 findingsSun 16 Aug 2026Adobe Commerce carries an unauthenticated customer account takeover, and Sansec says its WAF is already blocking attemptsA hack-for-hire group hit 15+ government webmail tenants with one script tag, then escaped the browser via a fake Edge helper · A new Mirai-derived botnet carries…3 findingsSat 15 Aug 2026CISA publishes a maximum-severity, CISA-assessed-automatable command injection in an HMI gateway deployed across energy, water and manufacturingDGFiP confirms a 678,000-record theft via a stolen agent account and a third party's credentials, missed by its own post-intrusion access checks · GeoServer zero-day…9 findingsThu 13 Aug 2026A Polish health-records processor confirms an intrusion, and because it is not the data controller it cannot tell the affected peopleA Siemens industrial edge gateway exposes a flow-programming interface to anyone who can reach it, with maximum privileges and no credentials required · Group-IB…4 findingsWed 12 Aug 2026Microsoft has now shipped an engine fix (1.1.26080.3), and the same researcher claims a partial bypass of itCisco confirms exploitation of an unauthenticated ASA/FTD VPN denial-of-service flaw; hardening releases now replace the hot fixes, with no workaround · SAP's August…5 findingsTue 11 Aug 2026Six agencies publish the Gunra RaaS playbook, edge exploitation, an OTP-value MFA backdoor, and a recoverable Linux keyTen organisations filed Dutch breach reports over one logistics provider's order-processing intrusion · An eIDAS-qualified eID browser bridge let any website read the…3 findingsMon 10 Aug 2026A European carrier serving 193 public administrations disclosed a two-month-old Qilin intrusion in a right-of-reply, not a press releaseA ransomware operator acquired a memory image and ran hashdump and cachedump offline against it, leaving traces that look like an IR engagement · FreeBSD's…13 findingsSun 09 Aug 2026A twelve-year-old PRNG in crypto-js reduces a nominal 128-bit secret to a search space commodity hardware can enumerateAn unauthenticated request to a PAM appliance's REST API yields product-administrator control of the vault it exists to protect · One unauthenticated endpoint returns…5 findingsSat 08 Aug 2026Attackers exploit a macOS Screen Sharing flaw that lets a network attacker in as root without valid credentials, fixed in 26.6.1Two years inside North Korean C2 infrastructure produces a victim count, an EU government confirmation, and a contractor with access to 30 companies · The AI toolchain…10 findingsFri 07 Aug 2026The group behind BlackFile never stopped: GTIG ties four newer extortion brands to one operator whose lure attacks passkey enrolment, not the passkeyKeycloak's identity broker stopped checking SAML signatures on a metadata-import edge case, one of seven CVEs fixed in 26.4.14 / 26.6.5 / 26.7.1 · Adobe ships a second…8 findingsThu 06 Aug 2026A self-propagating npm worm reaches packages totalling 1.3 billion monthly downloads, and its C2 address lives on-chainA second Swiss public-sector SharePoint victim in 48 hours, and the intrusion sat unnoticed for a week · Veeam patches ten flaws across the console that manages backups…7 findingsWed 05 Aug 2026CISA flags an evidence-integrity flaw in the DNA analyzers forensic and clinical labs run, no patchThe actor who wiped Romania's cadastre reaches a second EU government body through legacy WebLogic · Tomcat clustering flaw KEV-listed in August; SNOWLIGHT operators…11 findingsTue 04 Aug 2026A targeted attack on Liechtenstein's beneficial-ownership register yielded a targeting dataset on the owners behind Swiss- and EU-administered…Unit 42 shows three ways endpoint malware defeats Google synced passkeys without elevation, unlock or user interaction, and one of them cannot be revoked · Two national…5 findingsMon 03 Aug 2026N-able hotfixes an exploited N-central auth bypass after its earlier fix proved bypassableSix unauthenticated flaws in Gladinet CentreStack; a key identical in every install forges admin tokens · Bouncy Castle publishes 32 CVE write-ups for a July release…3 findings · 1 criticalSun 02 Aug 2026CERT@VDE publishes 20 CVEs in Phoenix Contact EV charging controllers with the fixing firmware unreleased; segmentation is the only control to 12…Adobe ships a priority-1 fix for a CVSS 10.0 unauthenticated code-execution flaw in Campaign Classic; only self-hosted and hybrid installs need action · The Joomla page…6 findingsSat 01 Aug 2026IBM ships interim APARs, not a fix pack, for a pre-auth deserialization RCE and a missing-authentication flaw in the WebSphere admin consoleMicrosoft attributes worldwide captive-portal traffic manipulation to Storm-2945, delivering the CornFlake RAT and ChocoShell stealer to travellers · SolarWinds patches…6 findingsFri 31 Jul 2026The autonomous agent landed nothing; the operator's hand-driven work took data from three NetScaler targets and ran commands on 11 Marimo serversOne confirmed government breach inside a leak-site victim list that a threat-intel vendor assesses is more likely invented than real · Rails patches a…6 findingsThu 30 Jul 2026One unauthenticated request reached command execution in the Ruflo AI-agent host, and a patched redeploy does not undo the poisoned agent memoryValid credentials, not a CVE, opened 92 SonicWall remote-access accounts in 41 hours, and nobody came back to use them · Broadcom patches two pre-auth CVSS 9.8 flaws in…7 findingsWed 29 Jul 2026Minnesota confirms a coordinated attack on field OT at more than 30 community water systems, days after a US advisory update on internet-exposed PLCsSophos tracks a Teams-vishing cluster that abandoned tenant spoofing for its own domains and pins its C2 to hardcoded issuer certificates · VulnCheck's canaries show…10 findingsTue 28 Jul 2026Arista patches an actively exploited unauthenticated command-injection flaw in on-prem VeloCloud OrchestratorCISA KEV-lists a FortiOS flaw that defeats Fortinet's own fix for SSL-VPN symlink persistence · MedusaHVNC rides real logged-in browser sessions on a hidden Windows…5 findings · 1 criticalMon 27 Jul 2026Exploited fastjson 1.x RCE has no patch, Spring Boot fat-JAR estates need SafeMode or migration nowOfficials doxxed over the EU Chat Control file, dossiers assembled from years of unrelated breach data2 findingsSun 26 Jul 2026The Joomla extension disclosure wave adds a cookie-forgery auth bypass, one anonymous request reaches Super User, and Super User means PHPAn espionage toolkit that only decrypts its final implant on the target machine, and talks C2 through the Telegram Bot API · Two national CERTs escalated the July Oracle…6 findingsSat 25 Jul 2026GRU-assessed TA458 keeps a live half-click zero-day supply across five self-hosted webmail platformsPublic PoC drops the bar on an AD CS Domain-Controller-impersonation flaw patched in July Patch Tuesday · Exposed operator infrastructure shows an open-source AI agent…5 findingsFri 24 Jul 202616-nation advisory: Russia's LAUNDRY BEAR exfiltrates government mail through a view-based Zimbra exploit, and patching alone does not evict itA pre-auth RCE in the widely-embedded libIEC61850 substation library, energy and water OEMs, not a single product, are affected · Talos dissects a RAT that offloads all…7 findingsThu 23 Jul 2026Check Point patches an actively-exploited SmartConsole authentication bypass granting full management-server adminSolarWinds patches 15 critical IDOR-to-root flaws in the internet-facing Serv-U managed-file-transfer server · CrowdStrike documents SANDWORM_MODE, an npm worm that…4 findingsWed 22 Jul 2026CISA KEV-lists a third Langflow RCE as IBM patches 15 more, including an unauthenticated superuser-account-creation path to code executionZimbra ships 10.1.20 with the permanent fix for an SNMP command-injection RCE; NCSC-CH and BSI flag it for on-prem mail operators · BitLocker-for-impact extortion via…5 findingsTue 21 Jul 2026Hugging Face discloses a weekend-long intrusion driven end-to-end by an autonomous AI-agent framework, the second real-world case after Sygnia's AWS…Group-IB details HOLLOWGRAPH, a .NET implant using a victim's own M365 calendar as two-way C2 over the Graph API, with DNS-tunneled Entra credential refresh · Proofpoint…4 findingsMon 20 Jul 2026F5 out-of-band patches a 15-year-old pre-auth heap overflow in nginx's script engine; credited researcher shows it reaches RCEGRU's Sandworm adopts ClickFix, blockchain-hidden C2 (EtherHiding) and a Signal-lured Android backdoor, transferable tradecraft for EU CI defenders2 findingsSun 19 Jul 2026EY discloses client tax-data exposure after a third-party ITSM support-ticket platform was breachedRomanian land-registry authority ANCPI down for days after a cyberattack; data-leak operator ByteToBreach claims theft and ransomware · ClickLock: a modular macOS…3 findingsSat 18 Jul 2026WordPress core's REST batch endpoint + a WP_Query SQL injection chain to unauthenticated RCE on a stock install, patch 7.0.2/6.9.5/6.8.6 shipped…Broadcom patches a pre-auth authentication bypass on the VMware Avi Load Balancer control plane (CVE-2026-47865), reported by NATO NCSC · The official Microsoft 365…8 findingsFri 17 Jul 2026NCSC-CH flags an unauthenticated RCE (CVSS 9.8) in Abacus ERP; reachable endpoint is the only prerequisiteTalos details UAT-11795, ClickFix-delivered Starland RAT with a blockchain dead-drop C2 and a bespoke WLDR PowerShell implant · Microsoft documents two ClickFix-rooted…6 findingsThu 16 Jul 2026Oracle E-Business Suite Payments pre-auth takeover (CVE-2026-46817) confirmed exploited and KEV-listed, patch or pull exposed instances off the…World Leaks leaks ~858k files from a Kudankulam nuclear-plant contractor breached at a third-party data-centre host, a lesson for energy-CI operators · Elastic details…5 findingsWed 15 Jul 2026A fake client_id on Entra ID's ROPC token endpoint lets attackers enumerate and validate credentials while leaving a blank application name in the…CISA republishes four Rockwell/ABB OT advisories led by a CVSS 10.0 debug-port takeover on an energy/water EtherNet/IP adapter, fixed in firmware 3.0112 findingsTue 14 Jul 2026SonicWall confirms active exploitation of an unauthenticated SMA1000 SSRF chained to code injection for full appliance takeoverMicrosoft patches two exploited zero-days on-prem: an AD FS privilege escalation and an unauthenticated SharePoint EoP, both KEV-listed same day · Attacker abuses an…11 findingsMon 13 Jul 2026ServiceNow patches an unauthenticated code-execution sandbox escape in its AI Platform; self-hosted and partner-managed instances are the residual…Progress told every on-prem ShareFile Storage Zone Controller customer to power off, then named a path-traversal flaw and shipped fixed builds · 19-agency advisory…6 findingsSun 12 Jul 2026Quiet windowNo finding cleared the bar · the run record is the artifact.run record onlySat 11 Jul 2026Two more Joomla extensions patch file-upload-to-RCE flaws, RSFiles! is reachable with no login at all (CVSS 10.0)PraisonAI: three critical CVEs, unsandboxed LLM code execution leaks all env secrets, plus tool-call RCE and DDL injection · Kaspersky names Armored Likho…8 findingsFri 10 Jul 2026CISA KEV-lists an actively-exploited unauth RCE in the iCagenda Joomla extension, RCE hits Joomla 6, auth bypass hits all versionsReliaQuest: new 'Helix' extortion cluster (BlackFile/ShinyHunters lineage) vishes staff into device-code sign-ins, then bulk-loots SharePoint · Huntress: device-code…15 findingsThu 09 Jul 2026Balbooa patches an actively-exploited unauthenticated file-upload RCE in its Joomla Forms extension, the third such flaw in the ecosystem in two weeksCERT-PL: Ghostwriter/UNC1151 now phishes Gmail with a live 2FA-relay panel that defeats TOTP and SMS · Januscape (CVE-2026-53359): 16-year-old KVM shadow-MMU UAF gives a…19 findingsWed 08 Jul 2026GhostLock (CVE-2026-43499): 15-year-old Linux rtmutex UAF gets a public 97%-reliable root + container-escape exploitLangflow IDOR (CVE-2026-55255) hits KEV; Sysdig shows one operator chaining it with the RCE CVE-2026-33017 · NCSC-CH flags critical pre-auth bypass in BeyondTrust RS/PRA…10 findingsMon 06 Jul 2026Quiet windowNo finding cleared the bar · the run record is the artifact.run record onlySun 05 Jul 2026cve-search patches a pre-auth flaw that reads admin credential hashes via /fetch_cve_dataRansom-ISAC case study: a US county paid ~$1M to data-theft extortion actor Kairos; no encryptor was ever deployed2 findingsSat 04 Jul 2026PamStealer impersonates the Maccy clipboard app and confirms a stolen macOS password through pam_authenticate before sending itAvalon framework chains a signed-binary MSBuild loader, ETW/AMSI patching and the CrownX ransomware payload in one implant · Sysdig documents JADEPUFFER, an end-to-end…3 findingsFri 03 Jul 2026CVE-2026-57517, Control Web Panel: pre-auth SQLi to RCE via INTO DUMPFILE (CVSS 9.8)CVE-2026-13368, WatchGuard Firebox: pre-auth RCE in the IKEv2 VPN daemon (CVSS 9.2) · CVE-2026-34038, Coolify: authenticated command injection to RCE and secrets…7 findingsThu 02 Jul 2026Cisco Talos: "ARToken" exposes a full BEC-as-a-service toolkit on top of Microsoft 365 device-code phishingCVE-2026-48276, -48277, -48281, -48282, -48283, -48316, Adobe ColdFusion: six CVSS 10.0 unauthenticated RCE paths · CVE-2026-45659, Microsoft SharePoint Server…9 findingsWed 01 Jul 2026CVE-2026-8451, Citrix NetScaler ADC/Gateway: pre-auth SAML memory overread (CitrixBleed lineage), public PoCCVE-2026-46817, Oracle E-Business Suite (Oracle Payments): pre-auth RCE now exploited in the wild · Aflac discloses a Japan-subsidiary breach, 4.38 million policyholders…7 findingsTue 30 Jun 2026CVE-2026-48558, SimpleHelp RMM: OIDC SSO authentication bypass, actively exploitedProgress Kemp LoadMaster pre-auth RCE in the /accessv2 API is exploited in the wild and KEV-listed, with fixes in GA 7.2.63.2 and LTSF 7.2.54.18 · CERT Polska discloses…8 findings · 1 criticalMon 29 Jun 2026Mozilla 0DIN: a "clean" GitHub repo coerces AI coding agents into a reverse shell via three-stage indirectionKDDI third-party email platform breach exposes up to 14.22 million credentials across six Japanese ISPs2 findingsSun 28 Jun 2026Keycloak JWT algorithm confusion (CVE-2026-11800): forging federated identity in the EU public sector's dominant IdPCVE-2026-55200, libssh2 heap out-of-bounds write in ssh2_transport_read() with public PoC; companion pre-auth DoS CVE-2026-55199 · CVE-2026-58053, Gitea act_runner…9 findingsSat 27 Jun 2026"The Gentlemen" ransomware claims 478 victims and adds worm propagation, Switzerland the second-most-targeted European countryCVE-2026-43503, Linux kernel "DirtyClone": page-cache corruption via XFRM/IPsec skb cloning (working PoC) · FBI/CISA: Russian intelligence now phishing Signal Backup…11 findingsFri 26 Jun 2026ESET's 2025 Gamaredon paper: exfil and C2 moved wholesale onto trusted cloud services (ANNUAL REPORT)macOS.Gaslight, a DPRK-aligned Rust backdoor that targets the LLM-assisted analyst · ShinyHunters used a single vishing call into the company's identity platform to…5 findingsThu 25 Jun 2026"Cordyceps"; the GitHub Actions pull_request_target pwn-request class is still widely exploitable at scaleCVE-2026-56447, CVE-2026-56446, CVE-2026-56425, CVE-2026-56424, CVE-2026-56423, CVE-2026-56422, MISP 2.5.42: two site-admin RCE paths plus Azure-AD auth and · "Mistic"…6 findingsWed 24 Jun 2026Ubiquiti UniFi OS triple-flaw chain to unauthenticated root (CVE-2026-34908 / -34909 / -34910)CVE-2026-20230, Cisco Unified CM: WebDialer SSRF to arbitrary file write to root, reconnaissance-stage exploitation observed · WhatsApp-borne VBScript silently installs…10 findingsTue 23 Jun 2026SonicWall CVE-2024-40766: why patched firewalls keep falling to Akira and Fog"Squidbleed", a 29-year-old heap over-read in Squid's FTP gateway leaks other users' cleartext HTTP credentials (CVE-2026-47729) · Gitea Docker instances with…7 findingsMon 22 Jun 2026AryStinger: a reconnaissance-and-proxy botnet built on end-of-life D-Link routers and QNAP NASeBanking phishing hides its landing-page address in IPv4-mapped IPv6 notation to slip past URL scanners · Brazil's national Cell Broadcast alert platform hijacked to…4 findingsSun 21 Jun 2026Prinz Eugen: a Go-based encryptor that targets recent files first and leaves no ransom noteKlue OAuth-token breach, victim list grows, CRM-API abuse chain detailed · CVE-2026-4020, Gravity SMTP WordPress plugin: unauthenticated config-dump of email-connector…8 findingsSat 20 Jun 2026PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management planeusbliter8, a permanent SecureROM boot-chain exploit for Apple A12/A13 silicon · CVE-2026-52806, Gogs self-hosted Git server: argument injection to OS command execution…8 findings · 1 criticalFri 19 Jun 2026Nightmare/Chaotic Eclipse zero-day wave; the Defender LPE now carries a CVE, a public PoC, and Microsoft's "Exploitation More Likely" rating, with no…CVE-2026-12046 / CVE-2026-12045 / CVE-2026-12048, pgAdmin 4: unauthenticated pickle deserialization RCE, AI-Assistant read-only-transaction bypass, stored XSS ·…11 findingsThu 18 Jun 2026Mastra npm supply-chain compromise (easy-day-js)CVE-2026-0647 et al. Rockwell Automation FLEX I/O unauthenticated password reset (CVSS 9.4) and Logix CIP denial-of-service, flagged by NCSC-CH · CVE-2026-46978 /…9 findingsWed 17 Jun 2026CVE-2026-48907, Widget Factory Joomla Content Editor (JCE) before version 2.9.99.5: unauthenticated profile-import → PHP RCE (CVSS v4 10.0)DragonForce abuses Microsoft Teams TURN relays for C2 and chains four vulnerable drivers (BYOVD) · FishMonger (I-SOON) ports its SprySOCKS backdoor to Windows with a…8 findings · 1 criticalTue 16 Jun 2026CVE-2026-54420: LiteSpeed cPanel plugin root escalation on CloudLinux/CageFS shared hosting, exploited in the wild (CISA KEV)CVE-2026-20262, Cisco Catalyst SD-WAN Manager: authenticated arbitrary file write to root RCE (CISA KEV) · WordPress supply-chain compromise via Awesome Motive's CDN…10 findingsMon 15 Jun 2026Handala breaches California Water Service through an internet-exposed RTKBase GNSS platform, billing PII for ~2M customers leaked, no OT access1 findingSun 14 Jun 2026Sekoia: APT28 (GRU Unit 26165) tradecraft shifts to LLM-generated payloads and cloud-native C2CVE-2026-20253, Splunk Enterprise: unauthenticated pre-auth RCE via the PostgreSQL sidecar proxy · CVE-2026-10795, UpdraftPlus WordPress backup plugin: unauthenticated…7 findingsSat 13 Jun 2026Velvet Ant "Operation Highland": subverting the Linux authentication stack for a decadeGoogle sues China-based "Outsider" PhaaS network for weaponising Gemini to mass-produce phishing pages · CVE-2026-48558, SimpleHelp RMM: unauthenticated OIDC…8 findingsFri 12 Jun 2026MariaDB CVE-2026-49261: Galera wsrep_notify_cmd shell injection (CVSS 10.0)Defused reports exploitation of three pre-auth FortiSandbox flaws and CISA lists two in KEV; upgrading to 5.0.6 or 4.4.9 fixes all three · June 2026 Patch Tuesday: four…11 findingsThu 11 Jun 2026ShinyHunters Oracle PeopleSoft campaign: gadget-chain access, SSH default-credential lateral movement, mass exfiltrationWindows Netlogon RCE CVE-2026-41089 now confirmed exploited in the wild in the EU; CERT-EU issues advisory 2026-007 · CVE-2026-5027, Langflow: unauthenticated path…8 findings · 1 criticalWed 10 Jun 2026CVE-2026-10520 / CVE-2026-10523, Ivanti Sentry: pre-auth OS command injection to root (CVSS 10.0), public PoC published todayCVE-2026-44748, SAP June Patch Day: SAML XML Signature Wrapping in NetWeaver AS ABAP (CVSS 9.9) plus an unauth RFC kernel memory-corruption (CVSS 9.8) · CVE-2026-47291…18 findings · 1 criticalTue 09 Jun 2026Check Point IKEv1 VPN auth bypass exploited since 7 May, actor assessed with medium confidence to use Qilin. CISA KEV, public PoC, apply sk185033TeamPCP open-sources its Mini Shai-Hulud framework, spawning a new "Phantom Gyp" derivative · Exodus Intelligence publishes working exploit for a one-character Linux…9 findings · 1 criticalMon 08 Jun 2026CVE-2026-49200 / CVE-2026-49201, Acer Wave-7 mesh routers: cleartext-credential log + hardcoded backup key, CVSS 10.0, no patchCVE-2026-3300, Everest Forms Pro (WordPress): unauthenticated eval() injection, actively exploited at scale · ICO secures Proceeds-of-Crime confiscation from former RAC…6 findingsSun 07 Jun 2026Keycloak 26.6.3: privilege escalation via OAuth token-exchange and SSRF in the EU public sector's reference identity platformAn autonomous AI agent finds 21 zero-days in FFmpeg for ~$1,000, nine numbered (CVE-2026-39210 to -39218), parser bugs up to 23 years old · CVE-2026-10881, Google Chrome…6 findingsSat 06 Jun 2026Luna Moth / Silent Ransom Group (UNC3753): vishing-to-physical-access data-theft extortion against legal and professional servicesCVE-2026-10868, MISP: critical mass-assignment account-takeover in the EU threat-sharing platform · CVE-2026-28318, SolarWinds Serv-U: unauthenticated DoS added to CISA…7 findingsFri 05 Jun 2026Redis CVE-2026-23479: a public use-after-free→GOT-overwrite RCE in a database 80% of cloud estates run passwordlessGMO Flatt Security: one GitHub issue could hijack any public repo running Anthropic's claude-code-action, and could have poisoned the action itself · CVE-2026-34906 /…8 findingsThu 04 Jun 2026HTTP/2 Bomb (CVE-2026-49975): a single-connection memory-exhaustion DoS against every major web serverCVE-2026-20230, Cisco Unified Communications Manager: unauthenticated SSRF to OS-root file write · CVE-2026-8206 + CVE-2026-8181, Kirki and Burst Statistics WordPress…14 findingsWed 03 Jun 2026Linux cgroups v1 release_agent container escape (CVE-2022-0492) re-enters active exploitationCVE-2025-48595, Android Framework: actively-exploited integer-overflow privilege escalation · CVE-2024-21182, Oracle WebLogic Server: unauthenticated T3/IIOP data…9 findingsTue 02 Jun 2026Operation Dragon Weave: China-nexus espionage against Czech government with Azure Blob Storage dead-drop C2"Miasma" worm backdoors 32 Red Hat Cloud Services npm packages via OIDC trusted-publishing abuse · Spain arrests doxer who published personal data on INCIBE…9 findingsMon 01 Jun 2026Italy's low-cost commercial spyware economy: Accessibility-API abuse as the cheap alternative to zero-daysSmartApeSG ClickFix stages an unnamed RAT that pivots to a weaponised NetSupport Manager · Two concurrent npm dependency-confusion campaigns target internal corporate…3 findingsSun 31 May 2026Cisco Talos maps the DICOM-format attack surface against Orthanc PACS, network-ingested medical images as a heap out-of-bounds-write primitiveCalifornia AG sues former 23andMe (Chrome Holding Co.) over the 2023 genetic-data breach, bulk-enumeration coding error plus absent credential-stuffing · "Signal…4 findingsSat 30 May 2026CVE-2026-0257, Palo Alto PAN-OS GlobalProtect: Pre-Auth Authentication Bypass via Certificate ReuseESET APT Activity Report Q4 2025–Q1 2026: Sandworm strikes NATO energy, Lazarus targets EU drone sector, UNC5221 pivots to Ivanti SPAWN toolset · CVE-2026-48710…13 findings · 1 criticalFri 29 May 2026CVE-2026-4408 & CVE-2026-4480, Samba: unauthenticated RCE in SAMR RPC and print-command subsystems (CVSS 10.0)Dutch Police + NCSC dismantle Asocks residential-proxy botnet (~17 M devices, 200 NL-hosted servers seized) · Carnival Corporation confirms 5.99 M-record ShinyHunters…16 findingsThu 28 May 2026Nx Console / TanStack / DAEMON Tools supply-chain cascade lands three CISA KEV entriesCVE-2026-35087 / CVE-2026-35089 / CVE-2026-35090, Slican PBX telephony exchanges, triple pre-authentication admin bypass (CERT Polska) · CVE-2026-48842, Roundcube…12 findingsWed 27 May 2026Tycoon 2FA after the March 2026 takedown: two-tier AiTM operator architecture and the OAuth device-code variantShinyHunters Salesforce campaign; Charter and 7-Eleven both confirm; 7-Eleven count put at ~185,000 affected · CVE-2026-9312, GitHub Enterprise Server (< 3.22)…5 findingsTue 26 May 2026Lazarus "RemotePE": a three-stage memory-only RAT that unhooks EDR and blinds ETWGoogle's threat-intel group maps a Chinese-language PhaaS ecosystem doing real-time OTP relay over RCS/iMessage · CVE-2026-9058, Szafir SDK (KIR): signature-verification…6 findingsMon 25 May 2026"Underminr": a multi-tenant-CDN domain-fronting variant that blinds DNS-layer filteringCVE-2026-26980, Ghost CMS Content API: unauthenticated blind SQL injection in the slug filter, actively exploited · Ghost CMS CVE-2026-26980 → ClickFix: the…4 findingsSun 24 May 2026Packagist supply-chain wave: Laravel-Lang autoloader backdoor and the cross-ecosystem postinstall strandDeleted Google Cloud API keys keep authenticating for up to 23 minutes · DNS-resolver patch cluster, Unbound 1.25.1 (11 CVEs) and ISC BIND 9.18.49 / 9.20.237 findingsSat 23 May 2026Unit 42, Iran's Screening Serpens (UNC1549 / Smoke Sandstorm / Nimbus Manticore): AppDomainManager hijacking silently disables ETW + strong-name…FBI PSA260521, Kali365 OAuth device-code PhaaS bypasses M365 MFA without credential capture · Megalodon mass-poisons 5,561 GitHub repos in a 6-hour window; SysDiag +…12 findingsFri 22 May 2026CVE-2026-34926, Trend Micro Apex One On-Premise: post-auth directory traversal by admin-credential holder injects code deployed fleet-wide to all…CVE-2026-20223, Cisco Secure Workload: CVSS 10.0 zero-auth REST API grants Site Admin privileges across all tenants, no workaround · CVE-2025-34291, Langflow AI Workflow…8 findings · 1 criticalThu 21 May 2026Verizon 2026 DBIR: vulnerability exploitation overtakes credentials as primary breach vector for the first time in 19 yearsCVE-2026-42822, Microsoft Azure Local Disconnected Operations (ALDO): CVSS 10.0 unauthenticated network elevation-of-privilege, "Exploitation More Likely" · Webworm…8 findingsWed 20 May 2026Prepare emergency Drupal patch window for today 17:00–21:00 UTCDrupal core "highly critical" pre-patch warning, unauthenticated, zero-complexity, patch window today 17:00–21:00 UTC · Storm-2949 SSPR-to-Key-Vault Azure kill chain14 findings · 2 criticalTue 19 May 2026CVE-2026-42231 / -42232 / -44789 / -44790 / -44791, n8n self-hosted automation: chained prototype-pollution and injection flaws enabling…7-Eleven confirms ShinyHunters breach of 600,000+ Salesforce franchise-application records, same campaign as Instructure, Vimeo, Wynn Resorts, Vercel · CISA contractor…10 findingsMon 18 May 2026CVE-2026-42897 Exchange OWA, EM Service auto-mitigation depends on outbound connectivity to officemitigations.microsoft.comTycoon2FA after the March 2026 takedown, OAuth Device Authorization Grant abuse on Microsoft 365 · CVE-2026-42945 NGINX Rift, in-the-wild exploitation confirmed by…5 findings · 1 criticalSun 17 May 2026Pwn2Own Berlin 2026: Master-of-Pwn outcomes, the new AI Agents category, and the compound-Exchange-threat picture for European defendersCVE-2026-41553, DHTMLX PDF Export Module: unauthenticated server-side JavaScript injection RCE (CVSS 4.0 score 10.0), with CVE-2026-41552 and CVE-2026-7182 ·…7 findingsSat 16 May 2026CVE-2026-42897, Microsoft Exchange Server 2016 / 2019 / SE: stored XSS in OWA, actively exploited, no permanent patchCVE-2026-44112 / CVE-2026-44113 / CVE-2026-44115 / CVE-2026-44118, OpenClaw "Claw Chain": four chainable flaws in autonomous-agent platform enable sandbox · node-ipc npm…9 findings · 1 criticalFri 15 May 2026CVE-2026-20182, Cisco Catalyst SD-WAN Controller/Manager: pre-auth authentication bypass enabling full fabric takeoverCVE-2026-42945, NGINX Open Source / Plus / F5 WAF products: 18-year-old heap buffer overflow in rewrite module ("NGINX Rift"), PoC public · CVE-2026-45691, Nextcloud…11 findings · 1 criticalThu 14 May 2026FamousSparrow Three-Wave Intrusion of an Azerbaijani Energy Operator: ProxyNotShell Re-exploitation and a Wave-1 DLL-Sideload Loader That Overrides…The Gentlemen RaaS, backend "Rocket" database leaked (16.22 GB), Check Point analysis exposes operator handles, ZeroPulse C2 internals, 1,570+ victims · CVE-2026-0300…6 findingsWed 13 May 2026CVE-2026-41089 / CVE-2026-41096 / CVE-2026-41103 / CVE-2026-42898; Microsoft May 2026 Patch Tuesday (120+ CVEs, no zero-days)CVE-2026-34263 / CVE-2026-34260, SAP Commerce Cloud pre-auth RCE, S/4HANA Enterprise Search SQL injection · CVE-2026-45185, Exim "Dead.Letter" use-after-free in…12 findings · 1 criticalTue 12 May 2026GTIG AI Threat Tracker (May 2026): First Confirmed AI-Generated Zero-Day Exploit ITW and the Behavioural Class of AI-Augmented MalwareTeamPCP (UNC6780 / PCPJack ecosystem) backdoors the Checkmarx Jenkins AST plugin, third Checkmarx supply-chain compromise in three months, SANDCLOCK · Palo Alto PAN-OS…7 findingsMon 11 May 2026CVE-2026-6722, PHP SOAP extension use-after-free in SOAP_GLOBAL(ref_map), CVSS 9.5 (with companion CVE-2026-7261, CVE-2026-7262)SMS-blaster smishing establishing itself in Switzerland, portable IMSI-catchers force 2G downgrade, bypass operator SMS filtering · BSI flags Netgate pfSense Community…4 findingsSun 10 May 2026cPanel/WHM second emergency TSR in 10 days, embargo lifted on CVE-2026-29202 (post-auth Perl RCE, CVSS 8.8), CVE-2026-29203 (CVSS 8.8)…CVE-2026-26030 / CVE-2026-25592, Microsoft Semantic Kernel: prompt-injection-to-RCE in the Python and .NET SDKs of Microsoft's AI agent orchestration · Groupe 3R (Réseau…9 findingsSat 09 May 2026CVE-2026-44128 et al. SEPPmail Secure Email Gateway: CVSS 9.3 unauthenticated RCE and five additional CVEsCVE-2026-42208, LiteLLM Proxy pre-authentication SQL injection: CISA KEV deadline 2026-05-11; all upstream LLM API keys at risk · CVE-2026-43284 / CVE-2026-43500, Linux…13 findingsFri 08 May 2026Instructure/Canvas extortion: 330 institutions across six countries; May 12 extortion deadline; 44 Dutch institutions confirmedCVE-2026-0300 (PAN-OS Captive Portal unauthenticated root RCE): CISA KEV deadline is today (2026-05-09); no patch until 2026-05-13 · Ivanti's exploited EPMM flaw needs…13 findingsThu 07 May 2026Quiet windowNo finding cleared the bar · the run record is the artifact.run record onlyWed 06 May 2026Quiet windowNo finding cleared the bar · the run record is the artifact.run record only