Press "Enter" to skip to content

Posts tagged as “exploit”

OSINT / CyberSec report 21.08.2026 00:06

1. Attackers are actively exploiting a critical remote code execution vulnerability in the Zimbra Collaboration Suite. (BleepingComputer) 2. A critical vulnerability tracked as CVE-2026-32475 in the Elementor Pro WordPress plugin allows unauthenticated attackers to upload malicious files and execute code. (The Hacker News) 3. The new Manic Android malware targets users in Europe and utilizes nearby infected devices for data exfiltration. (BleepingComputer) 4. A campaign…

OSINT / CyberSec report 17.08.2026 00:07

1. A new Mirai based modular Linux botnet named Evooo1Bot is targeting internet facing gateway devices to turn them into SOCKS5 traffic relay nodes (bleepingcomputer.com). 2. Authorities in Brazil and Europe arrested seven individuals involved in a 30 million euro bank fraud scheme that exploited a service provider vulnerability to target Commerzbank customers (bleepingcomputer.com). 3. The NCSC warned that hackers are actively exploiting a macOS…

OSINT report hourly 16.08.2026 12:02

1. Region: Ukraine. Ukrainian forces launched a massive overnight drone attack on August 16, 2026, targeting critical logistics hubs in the Moscow region, including the Wildberries fulfillment center in Koledino and the Severnoye Domodedovo complex. Source: Al Jazeera. 2. Region: Ukraine. Russian missile strikes on August 16, 2026, hit the ArcelorMittal metallurgical complex in Kryvyi Rih, killing one person and injuring 13 employees, while also…

OSINT / CyberSec report 15.08.2026 00:07

1. Lazarus Group exploited a Windows zero day vulnerability to deploy backdoors against defense and aerospace firms in a campaign known as Operation Dream Job (bleepingcomputer.com). 2. Threat actors are actively exploiting a critical authentication bypass vulnerability in Microsoft SharePoint identified as CVE 2026 55040 following the release of proof of concept code (thehackernews.com). 3. A critical remote code execution flaw in VMware vCenter Server…

OSINT / CyberSec report 13.08.2026 00:08

1. Threat actors are actively exploiting a critical directory traversal vulnerability in VMware vCenter tracked as CVE-2026-59310 to gain persistent remote access (thehackernews.com). 2. CISA confirmed that ransomware groups are actively abusing a high severity remote code execution vulnerability in Microsoft SharePoint tracked as CVE-2026-55040 (bleepingcomputer.com). 3. Cisco reported that CVE-2026-20349, a high severity flaw in ASA and FTD software, is being exploited in the…

OSINT / CyberSec report 11.08.2026 00:12

1. Malicious Visual Studio Code extensions named Solidity Pro have been identified stealing browser wallet data and API keys from developers (thehackernews.com). 2. OpenAI has paused internal activities for its upcoming Astra AI model after evaluations showed it possessed advanced agentic coding and cybersecurity capabilities (thehackernews.com). 3. CISA warned that a critical command injection vulnerability in Progress Kemp LoadMaster is currently being exploited by attackers…

OSINT / CyberSec report 09.08.2026 00:06

1. A critical zero day vulnerability in Metabase software is being actively exploited in the wild to allow unauthenticated remote attackers to inject arbitrary SQL and gain administrative access (The Hacker News). 2. CISA added a critical command injection flaw in Progress Kemp LoadMaster tracked as CVE 2026 8037 to its Known Exploited Vulnerabilities catalog following active exploitation reports (The Hacker News). 3. A new…

OSINT / CyberSec report 07.08.2026 00:07

1. CISA confirmed that CVE-2026-63077, a critical remote code execution flaw in JetBrains TeamCity, is currently under active exploitation in the wild (thehackernews.com). 2. CISA issued an urgent warning for federal agencies to mitigate actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat within three days (bleepingcomputer.com). 3. A 26-year-old Canadian man pleaded guilty to his role in the 2024 Snowflake cloud data breaches…

OSINT / CyberSec report 05.08.2026 00:07

1. CISA added the high severity authentication bypass vulnerability CVE-2026-18577 in N-able N-central to its Known Exploited Vulnerabilities catalog after active exploitation was confirmed (The Hacker News). 2. INC Ransomware is identified as the primary threat actor exploiting security flaws in SonicWall SMA 1000 series VPN appliances (The Hacker News). 3. Microsoft linked a global campaign targeting hospitality Wi-Fi networks to the Russian state-sponsored actor…

OSINT / CyberSec report 31.07.2026 00:08

1. Cisco Secure Firewall Management Center is under active exploitation via a zero day vulnerability tracked as CVE 2026 20316 which allows unauthenticated remote access (The Hacker News). 2. Russian state sponsored threat actors are exploiting a zero day vulnerability in Microsoft Outlook Web Access to maintain long term mailbox access via a backdoor named OWAReaper (The Hacker News, BleepingComputer). 3. A coordinated cyberattack targeted…