Press "Enter" to skip to content

Posts tagged as “CVE”

OSINT / CyberSec report 31.07.2026 00:08

1. Cisco Secure Firewall Management Center is under active exploitation via a zero day vulnerability tracked as CVE 2026 20316 which allows unauthenticated remote access (The Hacker News). 2. Russian state sponsored threat actors are exploiting a zero day vulnerability in Microsoft Outlook Web Access to maintain long term mailbox access via a backdoor named OWAReaper (The Hacker News, BleepingComputer). 3. A coordinated cyberattack targeted…

OSINT / CyberSec report 25.07.2026 00:09

1. Check Point patched a critical authentication bypass vulnerability in SmartConsole tracked as CVE-2026-16232 which is currently under active exploitation (The Hacker News). 2. Russian state-sponsored group Laundry Bear is exploiting a zero-click vulnerability in Zimbra Collaboration servers to steal emails and credentials (BleepingComputer). 3. The Clop ransomware gang is conducting a data theft extortion campaign targeting internet-exposed PTC Windchill and FlexPLM instances (BleepingComputer). 4.…

OSINT / CyberSec report 21.07.2026 00:10

1. A critical remote code execution vulnerability in the ServiceNow AI Platform identified as CVE-2026-6875 is currently being exploited in the wild (BleepingComputer). 2. The Hugging Face AI model repository suffered a data breach after an autonomous AI agent gained unauthorized access to internal datasets and credentials (The Hacker News). 3. WordPress core vulnerabilities collectively known as wp2shell are being actively exploited to achieve remote…

OSINT / CyberSec report 09.07.2026 00:10

1. CISA added four actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog including a critical path traversal flaw in Adobe ColdFusion. (thehackernews.com) 2. Federal agencies were ordered by CISA to prioritize patching an actively exploited authentication bypass vulnerability in the Langflow AI framework. (bleepingcomputer.com) 3. Researchers disclosed GhostLock CVE-2026-43499 a 15-year-old Linux kernel flaw that allows unprivileged users to gain root access and escape…

OSINT / CyberSec report 03.07.2026 00:08

1. CISA added the critical SharePoint remote code execution vulnerability CVE-2026-45659 to its Known Exploited Vulnerabilities catalog following reports of active exploitation (The Hacker News). 2. Security researchers identified the first end-to-end ransomware attack executed by an AI agent, which exploited a Langflow remote code execution flaw to encrypt a production database (The Hacker News). 3. The FortiBleed campaign, which compromised 75000 Fortinet firewalls, has…

OSINT / CyberSec report 27.06.2026 00:07

1. Attackers are actively exploiting a critical vulnerability in Cisco Unified CM and Unified CM SME deployments that enables server side request forgery and privilege escalation to root (Dark Reading). 2. A critical code injection vulnerability in Lantronix EDS5000 series devices tracked as CVE 2025 67038 is being actively exploited in the wild (The Hacker News). 3. Threat actors exploited the Cisco Catalyst SD WAN…

OSINT / CyberSec report 25.06.2026 00:07

1. Threat actors are actively exploiting a critical vulnerability in Cisco Unified Communications Manager tracked as CVE-2026-20230 to achieve remote file writes (thehackernews.com). 2. The FortiBleed campaign has targeted over 430,000 FortiGate firewalls globally to harvest approximately 110 million credentials (thehackernews.com). 3. Two members of the Scattered Spider cybercrime group pleaded guilty to charges related to the 2024 cyberattack on Transport for London (bleepingcomputer.com). 4.…

OSINT / CyberSec report 21.06.2026 00:05

1. CISA added a critical Splunk Enterprise remote code execution vulnerability CVE-2026-20253 to its known exploited vulnerabilities catalog after reports of active exploitation (https://www.reddit.com/r/cybersecurity/comments/1ua3npz/cisa_adds_splunk_enterprise_rce_cve202620253_to/). 2. International law enforcement agencies disrupted the SocGholish botnet infrastructure and cleaned nearly 15000 infected WordPress sites in an operation linked to the Evil Corp cybercrime group (https://thehackernews.com/2026/06/operation-endgame-disrupts-socgholish.html). 3. CISA issued a warning regarding the FortiBleed campaign which has compromised over…

OSINT / CyberSec report 19.06.2026 00:09

1. CISA has issued an urgent directive for federal agencies to patch a maximum severity vulnerability in the Widget Factory Joomla Content Editor plugin, which is currently being exploited in the wild (The Hacker News). 2. Microsoft is developing a patch for a zero day privilege escalation vulnerability in the Defender Malware Protection Engine codenamed RoguePlanet (The Hacker News). 3. Threat actors are actively exploiting…

OSINT / CyberSec report 15.06.2026 00:11

1. Splunk Enterprise is affected by a critical unauthenticated remote code execution vulnerability tracked as CVE-2026-20253 (The Hacker News). 2. The ShinyHunters threat group is actively exploiting a zero day vulnerability in Oracle PeopleSoft to compromise hundreds of organizations (Reddit). 3. CISA has issued an emergency directive requiring federal agencies to patch a maximum severity Ivanti vulnerability within three days (Reddit). 4. The Lapsus ransomware…