Press "Enter" to skip to content

Posts tagged as “zero-day”

OSINT / CyberSec report 29.07.2026 00:10

1. Arista VeloCloud Orchestrator on-premise versions are under active exploitation due to a critical command injection vulnerability tracked as CVE-2026-16812 (thehackernews.com). 2. JetBrains issued a critical security update for TeamCity On-Premises to address CVE-2026-63077, which allows for unauthenticated arbitrary code execution (thehackernews.com). 3. Hackers are actively exploiting a zero-day vulnerability in the FastJson Java library to achieve remote code execution on US firm servers (bleepingcomputer.com).…

OSINT / CyberSec report 19.07.2026 00:08

1. A critical pre authentication remote code execution vulnerability in WordPress core known as wp2shell allows unauthenticated attackers to run malicious code on affected sites (https://thehackernews.com/2026/07/new-wp2shell-wordpress-core-flaw-lets.html). 2. CISA added a critical deserialization vulnerability in Microsoft SharePoint Server tracked as CVE-2026-58644 to its list of actively exploited vulnerabilities (https://thehackernews.com/2026/07/cisa-adds-exploited-sharepoint-rce-zero.html). 3. The HollowByte vulnerability in OpenSSL allows unauthenticated attackers to trigger a denial of service condition by…

OSINT / CyberSec report 17.07.2026 00:09

1. Microsoft released a record 622 patches for its July Patch Tuesday, including two zero-day vulnerabilities currently under active exploitation (The Hacker News). 2. CISA issued a warning regarding three actively exploited vulnerabilities in internet-exposed on-premises SharePoint Server instances (Bleeping Computer). 3. SonicWall confirmed active exploitation of two zero-day vulnerabilities in its SMA 1000 series appliances, including one allowing arbitrary command execution (The Hacker News).…

OSINT / CyberSec report 11.06.2026 00:10

1. Microsoft released a record number of security patches for June 2026 including fixes for YellowKey and GreenPlasma zero day vulnerabilities (https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-yellowkey-greenplasma-miniplasma-zero-days/) 2. A new Microsoft Defender zero day exploit named RoguePlanet was released by a researcher granting SYSTEM privileges on updated Windows systems (https://www.bleepingcomputer.com/news/microsoft/microsoft-defender-rogueplanet-zero-day-grants-system-privileges/) 3. ServiceNow confirmed that threat actors exploited a flaw to gain unauthorized access to customer instances (https://thehackernews.com/2026/06/servicenow-flaw-exploited-to-gain.html) 4. Ivanti patched…

OSINT / CyberSec report 09.06.2026 00:07

1. Miasma malware has impacted 73 Microsoft GitHub repositories leading to security concerns regarding repository integrity (Reddit). 2. Threat actor UNC3753 is conducting a financially motivated data theft and extortion campaign against U.S. professional and financial services (The Hacker News). 3. Over 20000 Instagram accounts were hijacked after attackers abused Meta AI support systems to reset user passwords (Bleeping Computer). 4. Hackers are actively exploiting…

OSINT / CyberSec report 07.06.2026 00:07

1. CISA added the high severity SolarWinds Serv-U denial of service vulnerability CVE-2026-28318 to its Known Exploited Vulnerabilities catalog following reports of active exploitation (The Hacker News). 2. Cisco warned that the high severity vulnerability CVE-2026-20245 in Catalyst SD-WAN Manager is currently being exploited in the wild with no patch yet available (The Hacker News). 3. The Miasma self-replicating supply chain attack has compromised 73…

OSINT / CyberSec report 01.05.2026 00:08

1. A critical Linux local privilege escalation vulnerability named Copy Fail tracked as CVE-2026-31431 allows unprivileged users to obtain root access (The Hacker News). 2. Official SAP npm packages were compromised in a supply chain attack to steal developer credentials and authentication tokens (Bleeping Computer). 3. Google patched a maximum severity remote code execution flaw in the Gemini CLI npm package and GitHub Actions workflow…

OSINT / CyberSec report 15.04.2026 00:08

1. A cluster of 108 malicious Google Chrome extensions was identified stealing user data and Telegram information from approximately 20000 users (thehackernews.com). 2. The critical ShowDoc remote code execution vulnerability CVE-2025-0520 is currently being actively exploited in the wild (thehackernews.com). 3. CISA added six vulnerabilities to its Known Exploited Vulnerabilities catalog including a critical SQL injection flaw in Fortinet FortiClient EMS tracked as CVE-2026-21643 (thehackernews.com).…

OSINT / CyberSec report 03.04.2026 00:08

1. ShinyHunters compromised Cisco source code and AWS keys by exploiting a supply chain vulnerability in Trivy. The breach resulted in the unauthorized cloning of over 300 repositories (https://www.reddit.com/r/netsec/comments/1sa8nld/cisco_source_code_stolen_by_shinyhunters_via/). 2. Google released a patch for a high severity Chrome zero day vulnerability identified as CVE 2026 5281 which is currently under active exploitation (https://thehackernews.com/2026/04/new-chrome-zero-day-cve-2026-5281-under.html). 3. Apple expanded the availability of iOS 18.7.7 and iPadOS 18.7.7…