Press "Enter" to skip to content

Posts published in “CyberSec report”

OSINT / CyberSec report 19.07.2026 00:08

1. A critical pre authentication remote code execution vulnerability in WordPress core known as wp2shell allows unauthenticated attackers to run malicious code on affected sites (https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html). 2. CISA added a critical deserialization vulnerability in Microsoft SharePoint Server tracked as CVE-2026-58644 to its list of actively exploited vulnerabilities (https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html). 3. The HollowByte vulnerability in OpenSSL allows unauthenticated attackers to trigger a denial of service condition by…

OSINT / CyberSec report 17.07.2026 00:09

1. Microsoft released a record 622 patches for its July Patch Tuesday, including two zero-day vulnerabilities currently under active exploitation (The Hacker News). 2. CISA issued a warning regarding three actively exploited vulnerabilities in internet-exposed on-premises SharePoint Server instances (Bleeping Computer). 3. SonicWall confirmed active exploitation of two zero-day vulnerabilities in its SMA 1000 series appliances, including one allowing arbitrary command execution (The Hacker News).…

OSINT / CyberSec report 15.07.2026 00:09

1. CISA issued a warning regarding actively exploited remote code execution vulnerabilities in Joomla extensions iCagenda and Balbooa Forms. (BleepingComputer) 2. The US Treasury sanctioned a VPN service provider and two individuals for enabling ransomware attacks against American organizations. (The Hacker News) 3. AssuranceAmerica disclosed a data breach affecting 7 million people after attackers compromised employee credentials. (Check Point Research) 4. Lidl confirmed a data…

OSINT / CyberSec report 13.07.2026 00:09

1. The jscrambler npm package release 8.14.0 was compromised to drop and execute a malicious Rust infostealer on Windows, macOS, and Linux systems (https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html). 2. Suspected China and India aligned threat actors conducted sustained cyber espionage campaigns against the Balochistan Police portal between February 2024 and April 2026 (https://thehackernews.com/2026/07/hackers-weaponize-balochistan-police.html). 3. Progress Software urged ShareFile customers to shut down Storage Zone Controllers due to a credible…

OSINT / CyberSec report 11.07.2026 00:07

1. Attackers are exploiting the Ill Bloom vulnerability in cryptocurrency wallet software to drain funds by predicting recovery phrases generated with weak randomness (thehackernews.com). 2. A former ransomware negotiator was sentenced to 70 months in prison for conspiring with the BlackCat ransomware group to extort victims (thehackernews.com). 3. The new GodDamn ransomware family is using the PoisonX kernel driver to disable endpoint security software (thehackernews.com).…

OSINT / CyberSec report 09.07.2026 00:10

1. CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog including a critical path traversal flaw in Adobe ColdFusion. (thehackernews.com) 2. Federal agencies were ordered by CISA to prioritize patching an actively exploited authentication bypass vulnerability in the Langflow AI framework. (bleepingcomputer.com) 3. Researchers disclosed GhostLock CVE-2026-43499 a 15-year-old Linux kernel flaw that allows unprivileged users to gain root access and escape…

OSINT / CyberSec report 07.07.2026 00:07

1. CISA issued a warning regarding the active exploitation of a Linux kernel zero day vulnerability identified as CVE 2026 43456 (reddit.com). 2. Researchers discovered the TrojPix attack which exfiltrates data from air gapped systems by manipulating screen pixels to radiate radio signals via video cables (thehackernews.com). 3. A new Java based remote access trojan named QuimaRAT is being distributed under a malware as a…

OSINT / CyberSec report 05.07.2026 00:05

1. CISA confirmed that a remote code execution vulnerability in Microsoft SharePoint is currently being actively exploited (Reddit). 2. Google and the FBI disrupted the NetNut residential proxy network, cutting off access for approximately 2 million compromised devices (BleepingComputer). 3. A new Linux kernel vulnerability named Bad Epoll tracked as CVE-2026-46242 allows unprivileged users to gain root access on servers and Android devices (The Hacker…

OSINT / CyberSec report 03.07.2026 00:08

1. CISA added the critical SharePoint remote code execution vulnerability CVE-2026-45659 to its Known Exploited Vulnerabilities catalog following reports of active exploitation (The Hacker News). 2. Security researchers identified the first end-to-end ransomware attack executed by an AI agent, which exploited a Langflow remote code execution flaw to encrypt a production database (The Hacker News). 3. The FortiBleed campaign, which compromised 75000 Fortinet firewalls, has…

OSINT / CyberSec report 01.07.2026 00:07

1. A critical vulnerability in Progress Kemp LoadMaster tracked as CVE-2026-8037 allows unauthenticated attackers to execute arbitrary commands as root (thehackernews.com). 2. The Oracle E-Business Suite vulnerability CVE-2026-46817 is currently being exploited in the wild to take over susceptible instances (thehackernews.com). 3. Ransomware gangs are actively exploiting the Windows BlueHammer privilege escalation flaw in Microsoft Defender (bleepingcomputer.com). 4. The Blackfield ransomware group has demanded a…