Press "Enter" to skip to content

Posts published in “CyberSec report”

OSINT / CyberSec report 27.08.2026 00:04

1. CISA warned of active exploitation of a critical remote code execution vulnerability in Gitea tracked as CVE-2026-60004 (The Hacker News). 2. Oracle WebLogic Server vulnerability CVE-2026-21962 is under active exploitation allowing unauthenticated attackers to access critical data (The Hacker News). 3. Threat actors are actively exploiting a high-severity vulnerability in Zimbra Collaboration Suite to compromise over 270 servers (BleepingComputer). 4. Attackers are targeting unauthenticated…

OSINT / CyberSec report 25.08.2026 00:04

1. The Chinese speaking cybercrime group UAT 10147 is using AI to scale attacks against web servers in the education and technology sectors (https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html). 2. UAT 10147 deploys the SPECTRE malware alongside EDR bypass techniques and a Linux rootkit to maintain persistence (https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html). 3. The ToxicPanda Android malware has been updated to target 349 applications and now utilizes VPN permissions to block Google Play (https://www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play/).…

OSINT / CyberSec report 23.08.2026 00:03

1. GitLab vulnerability CVE-2026-19478 is under active exploitation allowing unauthenticated attackers to modify or delete projects (The Hacker News). 2. Microsoft confirmed active exploitation of a maximum severity remote code execution flaw in Entra ID tracked as CVE-2026-69836 (Bleeping Computer). 3. CISA ordered federal agencies to patch two actively exploited vulnerabilities affecting the TrueConf Server platform (Bleeping Computer). 4. A critical command injection vulnerability in…

OSINT / CyberSec report 21.08.2026 00:06

1. Attackers are actively exploiting a critical remote code execution vulnerability in the Zimbra Collaboration Suite. (BleepingComputer) 2. A critical vulnerability tracked as CVE-2026-32475 in the Elementor Pro WordPress plugin allows unauthenticated attackers to upload malicious files and execute code. (The Hacker News) 3. The new Manic Android malware targets users in Europe and utilizes nearby infected devices for data exfiltration. (BleepingComputer) 4. A campaign…

OSINT / CyberSec report 19.08.2026 05:41

1. Thousands of WordPress sites are being infected by the StopAndProtect ransomware family using ClickFix social engineering techniques (https://research.checkpoint.com/2026/thousands-of-hacked-wordpress-sites-one-operation-unmasking-stopandprotect/). 2. A critical vulnerability in the Ray distributed computing framework is currently being exploited in the wild (https://thehackernews.com/2026/08/cisa-flags-actively-exploited-ray-flaw.html). 3. Ransomware gangs are actively exploiting a high severity Windows Task Host vulnerability (https://www.bleepingcomputer.com/news/security/cisa-windows-task-host-flaw-now-exploited-by-ransomware-gangs/). 4. A critical flaw in the Forminator WordPress plugin allows unauthenticated remote code execution…

OSINT / CyberSec report 17.08.2026 00:07

1. A new Mirai based modular Linux botnet named Evooo1Bot is targeting internet facing gateway devices to turn them into SOCKS5 traffic relay nodes (bleepingcomputer.com). 2. Authorities in Brazil and Europe arrested seven individuals involved in a 30 million euro bank fraud scheme that exploited a service provider vulnerability to target Commerzbank customers (bleepingcomputer.com). 3. The NCSC warned that hackers are actively exploiting a macOS…

OSINT / CyberSec report 15.08.2026 00:07

1. Lazarus Group exploited a Windows zero day vulnerability to deploy backdoors against defense and aerospace firms in a campaign known as Operation Dream Job (bleepingcomputer.com). 2. Threat actors are actively exploiting a critical authentication bypass vulnerability in Microsoft SharePoint identified as CVE 2026 55040 following the release of proof of concept code (thehackernews.com). 3. A critical remote code execution flaw in VMware vCenter Server…

OSINT / CyberSec report 13.08.2026 00:08

1. Threat actors are actively exploiting a critical directory traversal vulnerability in VMware vCenter tracked as CVE-2026-59310 to gain persistent remote access (thehackernews.com). 2. CISA confirmed that ransomware groups are actively abusing a high severity remote code execution vulnerability in Microsoft SharePoint tracked as CVE-2026-55040 (bleepingcomputer.com). 3. Cisco reported that CVE-2026-20349, a high severity flaw in ASA and FTD software, is being exploited in the…

OSINT / CyberSec report 11.08.2026 00:12

1. Malicious Visual Studio Code extensions named Solidity Pro have been identified stealing browser wallet data and API keys from developers (thehackernews.com). 2. OpenAI has paused internal activities for its upcoming Astra AI model after evaluations showed it possessed advanced agentic coding and cybersecurity capabilities (thehackernews.com). 3. CISA warned that a critical command injection vulnerability in Progress Kemp LoadMaster is currently being exploited by attackers…

OSINT / CyberSec report 09.08.2026 00:06

1. A critical zero day vulnerability in Metabase software is being actively exploited in the wild to allow unauthenticated remote attackers to inject arbitrary SQL and gain administrative access (The Hacker News). 2. CISA added a critical command injection flaw in Progress Kemp LoadMaster tracked as CVE 2026 8037 to its Known Exploited Vulnerabilities catalog following active exploitation reports (The Hacker News). 3. A new…