Press "Enter" to skip to content

OSINT / CyberSec report 09.07.2026 00:10

1. CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog including a critical path traversal flaw in Adobe ColdFusion. (thehackernews.com)

2. Federal agencies were ordered by CISA to prioritize patching an actively exploited authentication bypass vulnerability in the Langflow AI framework. (bleepingcomputer.com)

3. Researchers disclosed GhostLock CVE-2026-43499 a 15-year-old Linux kernel flaw that allows unprivileged users to gain root access and escape containers. (thehackernews.com)

4. IT services giant Accenture confirmed a security breach after a threat actor claimed to have stolen 35 GB of source code and internal data. (bleepingcomputer.com)

5. The Chinese APT actor UAT-7810 is actively using new LONGLEASH malware to compromise internet-facing networking devices and expand its ORB network. (thehackernews.com)

6. A new Linux kernel vulnerability dubbed Januscape allows attackers to escape virtual machines and execute arbitrary code on host systems. (bleepingcomputer.com)

7. Ubiquiti released security updates to address seven critical vulnerabilities in UniFi OS including a maximum-severity command injection flaw. (bleepingcomputer.com)

8. Vidar Stealer is being deployed in a new campaign using a novel evasion technique that combines DLL sideloading with a Go-compiled fake MpClient.dll. (unit42.paloaltonetworks.com)

9. A critical session isolation vulnerability codenamed WriteOut in the Writer AI platform could have allowed cross-tenant compromise. (thehackernews.com)

10. Researchers discovered a critical flaw in Google Dialogflow CX that could have allowed attackers to hijack chatbots and steal user data. (thehackernews.com)

11. A new Android banking malware operation called RedWing is being rented out on Telegram as a malware-as-a-service tool. (thehackernews.com)

12. A persistent Windows device ID was used by federal investigators to trace an alleged member of the Scattered Spider hacking group. (thehackernews.com)

13. Researchers demonstrated that public GitHub issues can be used to trick agentic workflows into leaking data from private repositories. (thehackernews.com)

14. A hidden authentication backdoor was identified in multiple Tenda router firmware versions allowing unauthorized administrative access. (bleepingcomputer.com)

15. Spanish police arrested a suspect linked to pro-Russian hacktivist groups CyberArmy of Russia Reborn and Z-Pentest. (bleepingcomputer.com)

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *