Press "Enter" to skip to content

Posts tagged as “botnet”

OSINT / CyberSec report 25.08.2026 00:04

1. The Chinese speaking cybercrime group UAT 10147 is using AI to scale attacks against web servers in the education and technology sectors (https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html). 2. UAT 10147 deploys the SPECTRE malware alongside EDR bypass techniques and a Linux rootkit to maintain persistence (https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html). 3. The ToxicPanda Android malware has been updated to target 349 applications and now utilizes VPN permissions to block Google Play (https://www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play/).…

OSINT / CyberSec report 23.08.2026 00:03

1. GitLab vulnerability CVE-2026-19478 is under active exploitation allowing unauthenticated attackers to modify or delete projects (The Hacker News). 2. Microsoft confirmed active exploitation of a maximum severity remote code execution flaw in Entra ID tracked as CVE-2026-69836 (Bleeping Computer). 3. CISA ordered federal agencies to patch two actively exploited vulnerabilities affecting the TrueConf Server platform (Bleeping Computer). 4. A critical command injection vulnerability in…

OSINT / CyberSec report 17.08.2026 00:07

1. A new Mirai based modular Linux botnet named Evooo1Bot is targeting internet facing gateway devices to turn them into SOCKS5 traffic relay nodes (bleepingcomputer.com). 2. Authorities in Brazil and Europe arrested seven individuals involved in a 30 million euro bank fraud scheme that exploited a service provider vulnerability to target Commerzbank customers (bleepingcomputer.com). 3. The NCSC warned that hackers are actively exploiting a macOS…

OSINT / CyberSec report 13.08.2026 00:08

1. Threat actors are actively exploiting a critical directory traversal vulnerability in VMware vCenter tracked as CVE-2026-59310 to gain persistent remote access (thehackernews.com). 2. CISA confirmed that ransomware groups are actively abusing a high severity remote code execution vulnerability in Microsoft SharePoint tracked as CVE-2026-55040 (bleepingcomputer.com). 3. Cisco reported that CVE-2026-20349, a high severity flaw in ASA and FTD software, is being exploited in the…

OSINT / CyberSec report 21.07.2026 00:10

1. A critical remote code execution vulnerability in the ServiceNow AI Platform identified as CVE-2026-6875 is currently being exploited in the wild (BleepingComputer). 2. The Hugging Face AI model repository suffered a data breach after an autonomous AI agent gained unauthorized access to internal datasets and credentials (The Hacker News). 3. WordPress core vulnerabilities collectively known as wp2shell are being actively exploited to achieve remote…

OSINT / CyberSec report 21.06.2026 00:05

1. CISA added a critical Splunk Enterprise remote code execution vulnerability CVE-2026-20253 to its known exploited vulnerabilities catalog after reports of active exploitation (https://www.reddit.com/r/cybersecurity/comments/1ua3npz/cisa_adds_splunk_enterprise_rce_cve202620253_to/). 2. International law enforcement agencies disrupted the SocGholish botnet infrastructure and cleaned nearly 15000 infected WordPress sites in an operation linked to the Evil Corp cybercrime group (https://thehackernews.com/2026/06/operation-endgame-disrupts-socgholish.html). 3. CISA issued a warning regarding the FortiBleed campaign which has compromised over…

OSINT / CyberSec report 09.06.2026 00:07

1. Miasma malware has impacted 73 Microsoft GitHub repositories leading to security concerns regarding repository integrity (Reddit). 2. Threat actor UNC3753 is conducting a financially motivated data theft and extortion campaign against U.S. professional and financial services (The Hacker News). 3. Over 20000 Instagram accounts were hijacked after attackers abused Meta AI support systems to reset user passwords (Bleeping Computer). 4. Hackers are actively exploiting…

OSINT / CyberSec report 01.06.2026 00:11

1. Palo Alto Networks confirmed that CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect, is under active exploitation in the wild. (The Hacker News) 2. Attackers are actively exploiting the GlobalProtect authentication bypass flaw to establish unauthorized VPN connections to corporate networks. (BleepingComputer) 3. A new local privilege escalation vulnerability named CIFSwitch has been identified in the Linux kernel, allowing attackers to gain root access…

OSINT / CyberSec report 31.05.2026 00:07

1. Palo Alto Networks confirmed that CVE-2026-0257, an authentication bypass vulnerability in PAN-OS and Prisma Access, is currently under active exploitation (thehackernews.com). 2. Dutch authorities successfully dismantled a massive botnet consisting of 17 million infected devices and seized over 200 associated servers (bleepingcomputer.com). 3. A Russian-linked threat actor named GREYVIBE has been identified conducting persistent AI-powered cyberattacks against Ukrainian entities since August 2025 (thehackernews.com). 4.…

OSINT / CyberSec report 23.05.2026 00:08

1. Microsoft confirmed active exploitation of two Microsoft Defender vulnerabilities including CVE-2026-41091 which grants SYSTEM privileges (The Hacker News). 2. CISA added critical vulnerabilities in Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities catalog following evidence of active use (The Hacker News). 3. Cisco patched a maximum severity vulnerability CVE-2026-20223 in Secure Workload that allows unauthenticated remote attackers to access sensitive data…