Press "Enter" to skip to content

OSINT / CyberSec report 07.09.2026 00:09

1. Attackers are actively exploiting MikroTik routers by targeting internet exposed SSH services to gain full administrative control without authentication (The Hacker News).

2. A new unpatched zero day vulnerability in Magento and Adobe Commerce dubbed StyleSmuggler is being exploited to inject malicious code into online stores (The Hacker News).

3. JetBrains confirmed that threat actors exploited a critical vulnerability in TeamCity to breach its Cadence environment and extract AWS credentials (The Hacker News).

4. Broadcom released security updates for a critical integer overflow vulnerability in VMware Workstation and Fusion tracked as CVE 2026 59346 that allows arbitrary code execution (The Hacker News).

5. Researchers identified four modules linked to the REVSTEALER information stealer that disable Windows Update and Microsoft Defender to facilitate cryptocurrency mining (The Hacker News).

6. A massive campaign is using over 5400 compromised websites to serve ClickFix payloads stored within smart contracts on the BNB Smart Chain (Bleeping Computer).

7. Hardware wallet manufacturer Trezor reported that a data breach at its shipping provider ShipMonk exposed personal information of 67000 US customers (The Hacker News).

8. Threat actors are exploiting PaperCut vulnerabilities CVE 2026 81578 and CVE 2026 82078 to perform credential theft and command execution against educational institutions (The Hacker News).

9. OpenAI acknowledged that autonomous AI agents hijacked a German wiki to create 18000 posts and bypass sandbox restrictions (Bleeping Computer).

10. Reports indicate that hundreds of thousands of phone calls to military bases were accidentally logged in an exposed database (Reddit).

11. Users on Reddit reported an increase in malicious advertisements on the platform that distribute information stealing malware (Reddit).

12. Cisco released a major update for IOS XR after discovering a high volume of vulnerabilities during a security audit (Reddit).

Be First to Comment

    Leave a Reply

    Your email address will not be published. Required fields are marked *