Press "Enter" to skip to content

OSINT / CyberSec report 07.08.2026 00:07

1. CISA confirmed that CVE-2026-63077, a critical remote code execution flaw in JetBrains TeamCity, is currently under active exploitation in the wild (thehackernews.com).

2. CISA issued an urgent warning for federal agencies to mitigate actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat within three days (bleepingcomputer.com).

3. A 26-year-old Canadian man pleaded guilty to his role in the 2024 Snowflake cloud data breaches that compromised records of at least 100 million people (thehackernews.com).

4. Maksim Silnikau, the creator of the Ransom Cartel ransomware-as-a-service operation, was sentenced to 16 years in prison for attacks against at least 18 companies (thehackernews.com).

5. Attackers are exploiting a SQL injection vulnerability to install the khunt post-exploitation toolkit directly within Oracle database engines to gain system-level access (thehackernews.com).

6. Researchers discovered a factory-shipped backdoor in at least 20 Zbtlink router models that allows unauthenticated attackers to gain root shell access (thehackernews.com).

7. A new Linux kernel vulnerability codenamed OVSwrap allows local users to gain root privileges via the Open vSwitch datapath (thehackernews.com).

8. A phishing campaign targeting US organizations uses the Kali365 kit to weaponize Microsoft authentication and steal corporate access tokens (thehackernews.com).

9. A macOS ClickFix campaign using over 250 domains employs browser fingerprinting to deliver malware lures while evading security sandboxes (thehackernews.com).

10. Security flaws in agent infrastructure from AWS, Google, and Vercel allow attackers to trigger tools without model authorization or guardrail intervention (thehackernews.com).

11. Critical vulnerabilities were patched in Veeam Service Provider Console, Terraform MCP, and Django, including a cross-tenant bug rated 10.0 (thehackernews.com).

12. Gitea released a fix for CVE-2026-59774, a critical flaw that allowed unauthenticated attackers to read arbitrary server files using Org-mode markup (thehackernews.com).

13. Researchers identified 77 malicious extensions on the Open VSX marketplace that impersonated developer tools to exfiltrate system data (thehackernews.com).

14. Cyberattacks targeting operational technology in water utilities have expanded to 12 US states, with incidents linked to Iranian-affiliated actors (therecord.media).

15. A vulnerability in the KARR Security System allows attackers within Bluetooth range to unlock, disable, or control over 2 million vehicles (schneier.com).

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *