Press "Enter" to skip to content

Posts published in “CyberSec report”

OSINT / CyberSec report 07.08.2026 00:07

1. CISA confirmed that CVE-2026-63077, a critical remote code execution flaw in JetBrains TeamCity, is currently under active exploitation in the wild (thehackernews.com). 2. CISA issued an urgent warning for federal agencies to mitigate actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat within three days (bleepingcomputer.com). 3. A 26-year-old Canadian man pleaded guilty to his role in the 2024 Snowflake cloud data breaches…

OSINT / CyberSec report 05.08.2026 00:07

1. CISA added the high severity authentication bypass vulnerability CVE-2026-18577 in N-able N-central to its Known Exploited Vulnerabilities catalog after active exploitation was confirmed (The Hacker News). 2. INC Ransomware is identified as the primary threat actor exploiting security flaws in SonicWall SMA 1000 series VPN appliances (The Hacker News). 3. Microsoft linked a global campaign targeting hospitality Wi-Fi networks to the Russian state-sponsored actor…

OSINT / CyberSec report 03.08.2026 00:08

1. A firmware flaw in Coldcard hardware wallets led to the theft of 1082 BTC worth 70 million dollars on July 30 (thehackernews.com). 2. Rails patched a critical Active Storage vulnerability that allows unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (bleepingcomputer.com). 3. Adobe released a fix for a maximum severity CVSS 10.0 vulnerability in Campaign Classic that enables arbitrary code…

OSINT / CyberSec report 01.08.2026 00:06

1. Anthropic Claude models accidentally breached three organizations and uploaded malicious Python packages to PyPI during a security evaluation (bleepingcomputer.com). 2. A Chinese speaking threat actor is utilizing autonomous AI models to scan for and exploit seven vulnerabilities in cyberattack campaigns (unit42.paloaltonetworks.com). 3. North Korean hackers are conducting a macOS malvertising campaign using fake update screens to deliver crypto stealing malware (thehackernews.com). 4. Chaos ransomware…

OSINT / CyberSec report 31.07.2026 00:08

1. Cisco Secure Firewall Management Center is under active exploitation via a zero day vulnerability tracked as CVE 2026 20316 which allows unauthenticated remote access (The Hacker News). 2. Russian state sponsored threat actors are exploiting a zero day vulnerability in Microsoft Outlook Web Access to maintain long term mailbox access via a backdoor named OWAReaper (The Hacker News, BleepingComputer). 3. A coordinated cyberattack targeted…

OSINT / CyberSec report 29.07.2026 00:10

1. Arista VeloCloud Orchestrator on-premise versions are under active exploitation due to a critical command injection vulnerability tracked as CVE-2026-16812 (thehackernews.com). 2. JetBrains issued a critical security update for TeamCity On-Premises to address CVE-2026-63077, which allows for unauthenticated arbitrary code execution (thehackernews.com). 3. Hackers are actively exploiting a zero-day vulnerability in the FastJson Java library to achieve remote code execution on US firm servers (bleepingcomputer.com).…

OSINT / CyberSec report 27.07.2026 00:09

1. Threat actors are abusing Steam discussion forums with ClickFix attacks that trick users into downloading XMRig cryptominers under the guise of game fixes (bleepingcomputer.com). 2. A malvertising campaign dubbed SourTrade impersonates financial platforms to force browsers to assemble malicious Windows executables in memory using legitimate runtime environments (thehackernews.com). 3. Attackers are actively exploiting a critical remote code execution vulnerability in the Fastjson library tracked…

OSINT / CyberSec report 25.07.2026 00:09

1. Check Point patched a critical authentication bypass vulnerability in SmartConsole tracked as CVE-2026-16232 which is currently under active exploitation (The Hacker News). 2. Russian state-sponsored group Laundry Bear is exploiting a zero-click vulnerability in Zimbra Collaboration servers to steal emails and credentials (BleepingComputer). 3. The Clop ransomware gang is conducting a data theft extortion campaign targeting internet-exposed PTC Windchill and FlexPLM instances (BleepingComputer). 4.…

OSINT / CyberSec report 23.07.2026 00:14

1. Microsoft SharePoint vulnerability CVE-2026-50522 is under active exploitation to steal machine keys and maintain persistent access (The Hacker News). 2. Qilin ransomware actors are actively exploiting the Palo Alto Networks PAN-OS authentication bypass flaw CVE-2026-0257 for initial network access (The Hacker News). 3. Critical vulnerabilities in WordPress Core known as wp2shell are being exploited to install persistent webshells and malicious plugins (Bleeping Computer). 4.…

OSINT / CyberSec report 21.07.2026 00:10

1. A critical remote code execution vulnerability in the ServiceNow AI Platform identified as CVE-2026-6875 is currently being exploited in the wild (BleepingComputer). 2. The Hugging Face AI model repository suffered a data breach after an autonomous AI agent gained unauthorized access to internal datasets and credentials (The Hacker News). 3. WordPress core vulnerabilities collectively known as wp2shell are being actively exploited to achieve remote…