Press "Enter" to skip to content

Posts tagged as “exploit”

OSINT / CyberSec report 15.09.2026 00:10

1. A malicious Twitch browser extension named Twitch Enhanced Viewer JeetBot has leaked OAuth tokens for nearly 31000 users to Russian proxy servers (https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html). 2. Fintech company Revolut disclosed a data breach involving the exposure of customer financial information and passports after an employee was tricked by a threat actor impersonating a government agency (https://www.bleepingcomputer.com/news/security/revolut-discloses-data-breach-exposing-financial-info-passports/). 3. CISA warned that hackers are actively exploiting a maximum…

OSINT / CyberSec report 13.09.2026 00:04

1. GitLab issued an urgent patch for a maximum severity path traversal vulnerability tracked as CVE-2026-85706 which is currently being exploited in the wild (thehackernews.com). 2. Anthropic reported that seven China-based AI labs conducted industrial-scale distillation attacks against its Claude models (thehackernews.com). 3. A Russia-linked cyber espionage group identified as GTG-20006 abused Claude AI to develop workflows for malware reconstruction and evasion (thehackernews.com). 4. Threat…

OSINT / CyberSec report 11.09.2026 00:06

1. Cisco confirmed that a maximum severity authentication bypass vulnerability CVE 2026 20079 in its Secure Firewall Management Center is being actively exploited in the wild (https://www.reddit.com/r/cybersecurity/comments/1wbzdsv/cisco_confirms_maxseverity_fmc_bug_cve202620079/). 2. CISA reported that ransomware gangs are actively exploiting a critical WatchGuard Firebox firewall vulnerability (https://www.bleepingcomputer.com/news/security/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/). 3. Google issued a warning regarding a new Chrome zero day vulnerability that is currently being exploited in attacks (https://www.reddit.com/r/cybersecurity/comments/1wbprfh/google_warns_of_new_chrome_zeroday_bug_exploited/). 4. Multiple…

OSINT / CyberSec report 09.09.2026 00:05

1. Adobe released patches for a critical zero day vulnerability in Magento and Adobe Commerce tracked as CVE 2026 75650 which is being actively exploited to deploy backdoors (thehackernews.com). 2. A Vietnam linked database leak exposed 220 million traveler and crew records including passport numbers and flight details via a cloud path using default credentials (bleepingcomputer.com). 3. The BigBear 2.0 phishing as a service framework…

OSINT / CyberSec report 07.09.2026 00:09

1. Attackers are actively exploiting MikroTik routers by targeting internet exposed SSH services to gain full administrative control without authentication (The Hacker News). 2. A new unpatched zero day vulnerability in Magento and Adobe Commerce dubbed StyleSmuggler is being exploited to inject malicious code into online stores (The Hacker News). 3. JetBrains confirmed that threat actors exploited a critical vulnerability in TeamCity to breach its…

OSINT / CyberSec report 05.09.2026 00:09

1. Google released a security update to patch CVE-2026-85046, a high-severity type confusion vulnerability in the V8 engine that is currently being exploited in the wild (The Hacker News). 2. Over 440,000 exploit attempts have been recorded targeting critical remote code execution flaws in WordPress plugins Super Forms and Elementor Pro (The Hacker News). 3. Cisco issued patches for a critical vulnerability in Nexus 9000…

OSINT / CyberSec report 31.08.2026 00:06

1. TerminalFix campaigns are using fake Cloudflare CAPTCHAs to trick users into executing malicious commands via Windows Terminal or PowerShell (thehackernews.com). 2. The ShinyHunters extortion group claims to have stolen 284 million patient records from McKesson following a voice phishing attack (bleepingcomputer.com). 3. Berlin state government officials confirmed a data breach and stated they will not pay the ransom demanded by the hackers (thehackernews.com). 4.…

OSINT / CyberSec report 29.08.2026 00:04

1. PaperCut is actively investigating and patching a zero day vulnerability affecting all versions of its NG and MF print management software. (thehackernews.com) 2. Manchester Airports Group confirmed a data breach involving the theft of customer information including Wi Fi sign up data from three major UK airports. (bleepingcomputer.com) 3. Australian authorities arrested two individuals linked to the TeamPCP hacking group responsible for supply chain…

OSINT / CyberSec report 25.08.2026 00:04

1. The Chinese speaking cybercrime group UAT 10147 is using AI to scale attacks against web servers in the education and technology sectors (https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html). 2. UAT 10147 deploys the SPECTRE malware alongside EDR bypass techniques and a Linux rootkit to maintain persistence (https://thehackernews.com/2026/08/uat-10147-uses-ai-to-scale-server.html). 3. The ToxicPanda Android malware has been updated to target 349 applications and now utilizes VPN permissions to block Google Play (https://www.bleepingcomputer.com/news/security/toxicpanda-android-malware-uses-vpn-permissions-to-block-google-play/).…

OSINT / CyberSec report 23.08.2026 00:03

1. GitLab vulnerability CVE-2026-19478 is under active exploitation allowing unauthenticated attackers to modify or delete projects (The Hacker News). 2. Microsoft confirmed active exploitation of a maximum severity remote code execution flaw in Entra ID tracked as CVE-2026-69836 (Bleeping Computer). 3. CISA ordered federal agencies to patch two actively exploited vulnerabilities affecting the TrueConf Server platform (Bleeping Computer). 4. A critical command injection vulnerability in…