Press "Enter" to skip to content

Posts tagged as “ransomware”

OSINT / CyberSec report 07.07.2026 00:07

1. CISA issued a warning regarding the active exploitation of a Linux kernel zero day vulnerability identified as CVE 2026 43456 (reddit.com). 2. Researchers discovered the TrojPix attack which exfiltrates data from air gapped systems by manipulating screen pixels to radiate radio signals via video cables (thehackernews.com). 3. A new Java based remote access trojan named QuimaRAT is being distributed under a malware as a…

OSINT / CyberSec report 05.07.2026 00:05

1. CISA confirmed that a remote code execution vulnerability in Microsoft SharePoint is currently being actively exploited (Reddit). 2. Google and the FBI disrupted the NetNut residential proxy network, cutting off access for approximately 2 million compromised devices (BleepingComputer). 3. A new Linux kernel vulnerability named Bad Epoll tracked as CVE-2026-46242 allows unprivileged users to gain root access on servers and Android devices (The Hacker…

OSINT / CyberSec report 03.07.2026 00:08

1. CISA added the critical SharePoint remote code execution vulnerability CVE-2026-45659 to its Known Exploited Vulnerabilities catalog following reports of active exploitation (The Hacker News). 2. Security researchers identified the first end-to-end ransomware attack executed by an AI agent, which exploited a Langflow remote code execution flaw to encrypt a production database (The Hacker News). 3. The FortiBleed campaign, which compromised 75000 Fortinet firewalls, has…

OSINT / CyberSec report 01.07.2026 00:07

1. A critical vulnerability in Progress Kemp LoadMaster tracked as CVE-2026-8037 allows unauthenticated attackers to execute arbitrary commands as root (thehackernews.com). 2. The Oracle E-Business Suite vulnerability CVE-2026-46817 is currently being exploited in the wild to take over susceptible instances (thehackernews.com). 3. Ransomware gangs are actively exploiting the Windows BlueHammer privilege escalation flaw in Microsoft Defender (bleepingcomputer.com). 4. The Blackfield ransomware group has demanded a…

OSINT / CyberSec report 23.06.2026 00:07

1. The Canadian Security Intelligence Service utilized a first of its kind threat reduction warrant to neutralize two foreign run botnets by accessing infected servers and routers on Canadian soil (The Hacker News). 2. A new malware family identified as AryStinger has compromised at least 4300 legacy routers to establish a distributed reconnaissance and proxy network (The Hacker News). 3. Researchers report that AryStinger is…

OSINT / CyberSec report 21.06.2026 00:05

1. CISA added a critical Splunk Enterprise remote code execution vulnerability CVE-2026-20253 to its known exploited vulnerabilities catalog after reports of active exploitation (https://www.reddit.com/r/cybersecurity/comments/1ua3npz/cisa_adds_splunk_enterprise_rce_cve202620253_to/). 2. International law enforcement agencies disrupted the SocGholish botnet infrastructure and cleaned nearly 15000 infected WordPress sites in an operation linked to the Evil Corp cybercrime group (https://thehackernews.com/2026/06/operation-endgame-disrupts-socgholish.html). 3. CISA issued a warning regarding the FortiBleed campaign which has compromised over…

OSINT / CyberSec report 15.06.2026 00:11

1. Splunk Enterprise is affected by a critical unauthenticated remote code execution vulnerability tracked as CVE-2026-20253 (The Hacker News). 2. The ShinyHunters threat group is actively exploiting a zero day vulnerability in Oracle PeopleSoft to compromise hundreds of organizations (Reddit). 3. CISA has issued an emergency directive requiring federal agencies to patch a maximum severity Ivanti vulnerability within three days (Reddit). 4. The Lapsus ransomware…

OSINT / CyberSec report 13.06.2026 00:08

1. CISA issued a binding operational directive requiring federal agencies to patch an actively exploited vulnerability in Ivanti Sentry within three days (bleepingcomputer.com). 2. The ShinyHunters extortion group is actively exploiting a critical remote code execution vulnerability in Oracle PeopleSoft tracked as CVE-2026-35273 (thehackernews.com). 3. Researchers identified a critical vulnerability chain in the LangGraph AI framework that allows for remote code execution via SQL injection…

OSINT / CyberSec report 11.06.2026 00:10

1. Microsoft released a record number of security patches for June 2026 including fixes for YellowKey and GreenPlasma zero day vulnerabilities (https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-yellowkey-greenplasma-miniplasma-zero-days/) 2. A new Microsoft Defender zero day exploit named RoguePlanet was released by a researcher granting SYSTEM privileges on updated Windows systems (https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/) 3. ServiceNow confirmed that threat actors exploited a flaw to gain unauthorized access to customer instances (https://thehackernews.com/2026/06/servicenow-flaw-exploited-to-gain.html) 4. Ivanti patched…

OSINT / CyberSec report 05.06.2026 00:09

1. CISA added the critical Magento RCE vulnerability CVE-2026-45247 to its Known Exploited Vulnerabilities catalog following reports of active exploitation (The Hacker News). 2. A large scale malvertising campaign is using fake websites mimicking open source tools to distribute malware families like Remus Stealer and SessionGate (The Hacker News). 3. Attackers successfully compromised a senior executive at a global stock exchange, maintaining access to their…