Press "Enter" to skip to content

Posts tagged as “phishing”

OSINT / CyberSec report 07.08.2026 00:07

1. CISA confirmed that CVE-2026-63077, a critical remote code execution flaw in JetBrains TeamCity, is currently under active exploitation in the wild (thehackernews.com). 2. CISA issued an urgent warning for federal agencies to mitigate actively exploited vulnerabilities in IBM Langflow, N-central, and Apache Tomcat within three days (bleepingcomputer.com). 3. A 26-year-old Canadian man pleaded guilty to his role in the 2024 Snowflake cloud data breaches…

OSINT / CyberSec report 03.08.2026 00:08

1. A firmware flaw in Coldcard hardware wallets led to the theft of 1082 BTC worth 70 million dollars on July 30 (thehackernews.com). 2. Rails patched a critical Active Storage vulnerability that allows unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (bleepingcomputer.com). 3. Adobe released a fix for a maximum severity CVSS 10.0 vulnerability in Campaign Classic that enables arbitrary code…

OSINT / CyberSec report 29.07.2026 00:10

1. Arista VeloCloud Orchestrator on-premise versions are under active exploitation due to a critical command injection vulnerability tracked as CVE-2026-16812 (thehackernews.com). 2. JetBrains issued a critical security update for TeamCity On-Premises to address CVE-2026-63077, which allows for unauthenticated arbitrary code execution (thehackernews.com). 3. Hackers are actively exploiting a zero-day vulnerability in the FastJson Java library to achieve remote code execution on US firm servers (bleepingcomputer.com).…

OSINT / CyberSec report 27.07.2026 00:09

1. Threat actors are abusing Steam discussion forums with ClickFix attacks that trick users into downloading XMRig cryptominers under the guise of game fixes (bleepingcomputer.com). 2. A malvertising campaign dubbed SourTrade impersonates financial platforms to force browsers to assemble malicious Windows executables in memory using legitimate runtime environments (thehackernews.com). 3. Attackers are actively exploiting a critical remote code execution vulnerability in the Fastjson library tracked…

OSINT / CyberSec report 23.07.2026 00:14

1. Microsoft SharePoint vulnerability CVE-2026-50522 is under active exploitation to steal machine keys and maintain persistent access (The Hacker News). 2. Qilin ransomware actors are actively exploiting the Palo Alto Networks PAN-OS authentication bypass flaw CVE-2026-0257 for initial network access (The Hacker News). 3. Critical vulnerabilities in WordPress Core known as wp2shell are being exploited to install persistent webshells and malicious plugins (Bleeping Computer). 4.…

OSINT / CyberSec report 17.07.2026 00:09

1. Microsoft released a record 622 patches for its July Patch Tuesday, including two zero-day vulnerabilities currently under active exploitation (The Hacker News). 2. CISA issued a warning regarding three actively exploited vulnerabilities in internet-exposed on-premises SharePoint Server instances (Bleeping Computer). 3. SonicWall confirmed active exploitation of two zero-day vulnerabilities in its SMA 1000 series appliances, including one allowing arbitrary command execution (The Hacker News).…

OSINT / CyberSec report 15.07.2026 00:09

1. CISA issued a warning regarding actively exploited remote code execution vulnerabilities in Joomla extensions iCagenda and Balbooa Forms. (BleepingComputer) 2. The US Treasury sanctioned a VPN service provider and two individuals for enabling ransomware attacks against American organizations. (The Hacker News) 3. AssuranceAmerica disclosed a data breach affecting 7 million people after attackers compromised employee credentials. (Check Point Research) 4. Lidl confirmed a data…

OSINT / CyberSec report 13.07.2026 00:09

1. The jscrambler npm package release 8.14.0 was compromised to drop and execute a malicious Rust infostealer on Windows, macOS, and Linux systems (https://thehackernews.com/2026/07/compromised-jscrambler-8140-npm-release.html). 2. Suspected China and India aligned threat actors conducted sustained cyber espionage campaigns against the Balochistan Police portal between February 2024 and April 2026 (https://thehackernews.com/2026/07/hackers-weaponize-balochistan-police.html). 3. Progress Software urged ShareFile customers to shut down Storage Zone Controllers due to a credible…

OSINT / CyberSec report 11.07.2026 00:07

1. Attackers are exploiting the Ill Bloom vulnerability in cryptocurrency wallet software to drain funds by predicting recovery phrases generated with weak randomness (thehackernews.com). 2. A former ransomware negotiator was sentenced to 70 months in prison for conspiring with the BlackCat ransomware group to extort victims (thehackernews.com). 3. The new GodDamn ransomware family is using the PoisonX kernel driver to disable endpoint security software (thehackernews.com).…

OSINT / CyberSec report 05.07.2026 00:05

1. CISA confirmed that a remote code execution vulnerability in Microsoft SharePoint is currently being actively exploited (Reddit). 2. Google and the FBI disrupted the NetNut residential proxy network, cutting off access for approximately 2 million compromised devices (BleepingComputer). 3. A new Linux kernel vulnerability named Bad Epoll tracked as CVE-2026-46242 allows unprivileged users to gain root access on servers and Android devices (The Hacker…