Press "Enter" to skip to content

Posts tagged as “phishing”

OSINT / CyberSec report 01.07.2026 00:07

1. A critical vulnerability in Progress Kemp LoadMaster tracked as CVE-2026-8037 allows unauthenticated attackers to execute arbitrary commands as root (thehackernews.com). 2. The Oracle E-Business Suite vulnerability CVE-2026-46817 is currently being exploited in the wild to take over susceptible instances (thehackernews.com). 3. Ransomware gangs are actively exploiting the Windows BlueHammer privilege escalation flaw in Microsoft Defender (bleepingcomputer.com). 4. The Blackfield ransomware group has demanded a…

OSINT / CyberSec report 29.06.2026 00:08

1. Russian intelligence services are conducting a long-running campaign using fake support messages to steal credentials from government and military officials in Ukraine, the U.S., and Europe (The Hacker News). 2. The FBI and CISA warned that Russian hackers are now targeting Signal Backup Recovery Keys to gain access to historical message data (Bleeping Computer). 3. A critical remote code execution vulnerability in PTC Windchill…

OSINT / CyberSec report 27.06.2026 00:07

1. Attackers are actively exploiting a critical vulnerability in Cisco Unified CM and Unified CM SME deployments that enables server side request forgery and privilege escalation to root (Dark Reading). 2. A critical code injection vulnerability in Lantronix EDS5000 series devices tracked as CVE 2025 67038 is being actively exploited in the wild (The Hacker News). 3. Threat actors exploited the Cisco Catalyst SD WAN…

OSINT / CyberSec report 25.06.2026 00:07

1. Threat actors are actively exploiting a critical vulnerability in Cisco Unified Communications Manager tracked as CVE-2026-20230 to achieve remote file writes (thehackernews.com). 2. The FortiBleed campaign has targeted over 430,000 FortiGate firewalls globally to harvest approximately 110 million credentials (thehackernews.com). 3. Two members of the Scattered Spider cybercrime group pleaded guilty to charges related to the 2024 cyberattack on Transport for London (bleepingcomputer.com). 4.…

OSINT / CyberSec report 23.06.2026 00:07

1. The Canadian Security Intelligence Service utilized a first of its kind threat reduction warrant to neutralize two foreign run botnets by accessing infected servers and routers on Canadian soil (The Hacker News). 2. A new malware family identified as AryStinger has compromised at least 4300 legacy routers to establish a distributed reconnaissance and proxy network (The Hacker News). 3. Researchers report that AryStinger is…

OSINT / CyberSec report 17.06.2026 00:08

1. Cisco released security updates for a vulnerability in Catalyst SD-WAN Manager tracked as CVE-2026-20262 which is currently being exploited in the wild (thehackernews.com). 2. CISA added the LiteSpeed cPanel Plugin vulnerability CVE-2026-54420 to its Known Exploited Vulnerabilities catalog due to active exploitation for root privilege escalation (thehackernews.com). 3. Threat actors are actively exploiting multiple critical vulnerabilities in the Fortinet FortiSandbox platform to compromise systems…

OSINT / CyberSec report 13.06.2026 00:08

1. CISA issued a binding operational directive requiring federal agencies to patch an actively exploited vulnerability in Ivanti Sentry within three days (bleepingcomputer.com). 2. The ShinyHunters extortion group is actively exploiting a critical remote code execution vulnerability in Oracle PeopleSoft tracked as CVE-2026-35273 (thehackernews.com). 3. Researchers identified a critical vulnerability chain in the LangGraph AI framework that allows for remote code execution via SQL injection…

OSINT report hourly 10.06.2026 00:09

1. Region: Middle East. A US Army AH-64E Apache helicopter was downed near the Strait of Hormuz after being struck by an Iranian Shahed-style one-way attack drone. Source: CNN. 2. Region: Russia. Three explosions struck a main gas pipeline and infrastructure in Kizilyurt, Dagestan, causing a massive fire and evacuations. Source: AP News. 3. Region: Ukraine. Ukrainian Unmanned Systems Forces conducted a mass strike on…

OSINT / CyberSec report 07.06.2026 00:07

1. CISA added the high severity SolarWinds Serv-U denial of service vulnerability CVE-2026-28318 to its Known Exploited Vulnerabilities catalog following reports of active exploitation (The Hacker News). 2. Cisco warned that the high severity vulnerability CVE-2026-20245 in Catalyst SD-WAN Manager is currently being exploited in the wild with no patch yet available (The Hacker News). 3. The Miasma self-replicating supply chain attack has compromised 73…

OSINT / CyberSec report 03.06.2026 00:08

1. A supply chain attack compromised Red Hat npm packages to distribute the Miasma credential stealing worm (thehackernews.com). 2. A critical Windows Netlogon remote code execution vulnerability is being actively exploited in the wild (bleepingcomputer.com). 3. Nearly 2000 WordPress sites were infected with malware using Steam profiles as command and control infrastructure (bleepingcomputer.com). 4. The Pakistan linked SideCopy group is targeting the Afghanistan Ministry of…