Press "Enter" to skip to content

Posts tagged as “CVE”

OSINT / CyberSec report 05.06.2026 00:09

1. CISA added the critical Magento RCE vulnerability CVE-2026-45247 to its Known Exploited Vulnerabilities catalog following reports of active exploitation (The Hacker News). 2. A large scale malvertising campaign is using fake websites mimicking open source tools to distribute malware families like Remus Stealer and SessionGate (The Hacker News). 3. Attackers successfully compromised a senior executive at a global stock exchange, maintaining access to their…

OSINT / CyberSec report 01.06.2026 00:11

1. Palo Alto Networks confirmed that CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect, is under active exploitation in the wild. (The Hacker News) 2. Attackers are actively exploiting the GlobalProtect authentication bypass flaw to establish unauthorized VPN connections to corporate networks. (BleepingComputer) 3. A new local privilege escalation vulnerability named CIFSwitch has been identified in the Linux kernel, allowing attackers to gain root access…

OSINT / CyberSec report 29.05.2026 00:08

1. A new phishing campaign targeting Japanese online banking users is utilizing a domain and branding typo related to PayPoy (https://www.reddit.com/r/cybersecurity/comments/1tpvisr/new_phishing_campaign_targeting_japanese_online/). 2. Threat actor JINX-0164 is targeting cryptocurrency firms using fake recruiter lures and custom macOS malware to facilitate asset theft (https://thehackernews.com/2026/05/jinx-0164-targets-cryptocurrency-firms.html). 3. A malicious npm package named mouse5212-super-formatter was discovered stealing files from the local directory used by the Claude AI tool (https://thehackernews.com/2026/05/malicious-npm-package-stole-files-from.html). 4.…

OSINT / CyberSec report 25.05.2026 00:10

1. A critical SQL injection vulnerability in Drupal Core tracked as CVE-2026-9082 is being actively exploited with over 15000 attempts recorded across 6000 sites (The Hacker News). 2. The LiteSpeed User-End cPanel Plugin is under active exploitation via CVE-2026-48172 which allows attackers to execute arbitrary scripts with root privileges (The Hacker News). 3. The Megalodon campaign compromised over 5500 GitHub repositories within six hours by…

OSINT / CyberSec report 21.05.2026 00:07

1. GitHub is investigating a breach of approximately 3800 internal repositories after an employee installed a malicious VS Code extension (The Hacker News). 2. Microsoft released a mitigation for the YellowKey BitLocker bypass vulnerability tracked as CVE-2026-45585 (The Hacker News). 3. Grafana Labs confirmed a breach of its internal GitHub environment involving source code, though customer production systems remain unaffected (The Hacker News). 4. The…

OSINT / CyberSec report 19.05.2026 00:08

1. A critical heap buffer overflow vulnerability in NGINX tracked as CVE-2026-42945 is being actively exploited in the wild to cause worker crashes and potential remote code execution (The Hacker News). 2. Security researcher Chaotic Eclipse released a proof of concept for a Windows zero day exploit named MiniPlasma that grants attackers SYSTEM privileges on fully patched systems (Bleeping Computer). 3. The Tycoon2FA phishing kit…

OSINT / CyberSec report 11.05.2026 00:10

1. The ShinyHunters threat group claims to have stolen 275 million records from Canvas LMS affecting 9000 schools with a ransom deadline set for May 12 (Reddit). 2. Instructure reported a second security incident involving its Canvas platform following the massive data breach (Reddit). 3. The official JDownloader website was compromised to distribute malicious installers containing a Python based remote access trojan (BleepingComputer). 4. A…

OSINT / CyberSec report 03.05.2026 00:06

1. Trellix confirmed a security breach involving unauthorized access to a portion of its internal source code repository (thehackernews.com). 2. A Vietnamese-linked operation named AccountDumpling compromised 30,000 Facebook accounts using Google AppSheet as a phishing relay (thehackernews.com). 3. China-linked threat group SHADOW-EARTH-053 is conducting an espionage campaign targeting government and defense sectors across Asia and a NATO member state (thehackernews.com). 4. Cybercrime groups Cordial Spider…

OSINT / CyberSec report 01.05.2026 00:08

1. A critical Linux local privilege escalation vulnerability named Copy Fail tracked as CVE-2026-31431 allows unprivileged users to obtain root access (The Hacker News). 2. Official SAP npm packages were compromised in a supply chain attack to steal developer credentials and authentication tokens (Bleeping Computer). 3. Google patched a maximum severity remote code execution flaw in the Gemini CLI npm package and GitHub Actions workflow…

OSINT / CyberSec report 29.04.2026 00:08

1. Microsoft confirmed active exploitation of the Windows Shell spoofing vulnerability CVE 2026 32202 (The Hacker News). 2. A Chinese national linked to the Silk Typhoon threat group was extradited to the United States for cyberattacks against government agencies (The Hacker News). 3. French authorities arrested a 21 year old hacker known as HexDex for approximately 100 data breaches including the French Ministry of National…