Press "Enter" to skip to content

Posts tagged as “exploit”

OSINT / CyberSec report 05.06.2026 00:09

1. CISA added the critical Magento RCE vulnerability CVE-2026-45247 to its Known Exploited Vulnerabilities catalog following reports of active exploitation (The Hacker News). 2. A large scale malvertising campaign is using fake websites mimicking open source tools to distribute malware families like Remus Stealer and SessionGate (The Hacker News). 3. Attackers successfully compromised a senior executive at a global stock exchange, maintaining access to their…

OSINT / CyberSec report 01.06.2026 00:11

1. Palo Alto Networks confirmed that CVE-2026-0257, an authentication bypass vulnerability in PAN-OS GlobalProtect, is under active exploitation in the wild. (The Hacker News) 2. Attackers are actively exploiting the GlobalProtect authentication bypass flaw to establish unauthorized VPN connections to corporate networks. (BleepingComputer) 3. A new local privilege escalation vulnerability named CIFSwitch has been identified in the Linux kernel, allowing attackers to gain root access…

OSINT / CyberSec report 31.05.2026 00:07

1. Palo Alto Networks confirmed that CVE-2026-0257, an authentication bypass vulnerability in PAN-OS and Prisma Access, is currently under active exploitation (thehackernews.com). 2. Dutch authorities successfully dismantled a massive botnet consisting of 17 million infected devices and seized over 200 associated servers (bleepingcomputer.com). 3. A Russian-linked threat actor named GREYVIBE has been identified conducting persistent AI-powered cyberattacks against Ukrainian entities since August 2025 (thehackernews.com). 4.…

OSINT / CyberSec report 25.05.2026 00:10

1. A critical SQL injection vulnerability in Drupal Core tracked as CVE-2026-9082 is being actively exploited with over 15000 attempts recorded across 6000 sites (The Hacker News). 2. The LiteSpeed User-End cPanel Plugin is under active exploitation via CVE-2026-48172 which allows attackers to execute arbitrary scripts with root privileges (The Hacker News). 3. The Megalodon campaign compromised over 5500 GitHub repositories within six hours by…

OSINT / CyberSec report 23.05.2026 00:08

1. Microsoft confirmed active exploitation of two Microsoft Defender vulnerabilities including CVE-2026-41091 which grants SYSTEM privileges (The Hacker News). 2. CISA added critical vulnerabilities in Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities catalog following evidence of active use (The Hacker News). 3. Cisco patched a maximum severity vulnerability CVE-2026-20223 in Secure Workload that allows unauthenticated remote attackers to access sensitive data…

OSINT / CyberSec report 21.05.2026 00:07

1. GitHub is investigating a breach of approximately 3800 internal repositories after an employee installed a malicious VS Code extension (The Hacker News). 2. Microsoft released a mitigation for the YellowKey BitLocker bypass vulnerability tracked as CVE-2026-45585 (The Hacker News). 3. Grafana Labs confirmed a breach of its internal GitHub environment involving source code, though customer production systems remain unaffected (The Hacker News). 4. The…

OSINT / CyberSec report 19.05.2026 00:08

1. A critical heap buffer overflow vulnerability in NGINX tracked as CVE-2026-42945 is being actively exploited in the wild to cause worker crashes and potential remote code execution (The Hacker News). 2. Security researcher Chaotic Eclipse released a proof of concept for a Windows zero day exploit named MiniPlasma that grants attackers SYSTEM privileges on fully patched systems (Bleeping Computer). 3. The Tycoon2FA phishing kit…

OSINT / CyberSec report 17.05.2026 00:06

1. Microsoft Exchange and Windows 11 were successfully compromised by researchers using zero day vulnerabilities during the Pwn2Own Berlin 2026 event (bleepingcomputer.com). 2. The Funnel Builder WordPress plugin is being actively exploited to inject malicious JavaScript into WooCommerce checkout pages to steal credit card data (bleepingcomputer.com). 3. A critical supply chain attack targeting the TanStack library impacted two OpenAI employee devices, prompting immediate security containment…

OSINT / CyberSec report 15.05.2026 00:08

1. A new Linux kernel local privilege escalation vulnerability named Fragnesia tracked as CVE-2026-46300 allows attackers to gain root access (The Hacker News). 2. A critical heap buffer overflow vulnerability in the NGINX rewrite module tracked as CVE-2026-42945 enables unauthenticated remote code execution (The Hacker News). 3. West Pharmaceutical Services confirmed a cyberattack involving data exfiltration and system encryption (BleepingComputer). 4. The Gentlemen ransomware group…

OSINT / CyberSec report 13.05.2026 00:09

1. A mass npm supply chain attack involving the Mini Shai-Hulud worm has compromised over 170 packages including TanStack and Mistral AI. (https://thehackernews.com/2026/05/mini-shai-hulud-worm-compromises.html) 2. Instructure reached an agreement with the ShinyHunters extortion group to prevent the leak of 3.65TB of stolen data. (https://thehackernews.com/2026/05/instructure-reaches-ransom-agreement.html) 3. A rogue version of the official Checkmarx Jenkins plugin was published on the Jenkins Marketplace containing an infostealer. (https://www.bleepingcomputer.com/news/security/official-checkmarx-jenkins-package-compromised-with-infostealer/) 4. A…