Search/apache tomcat
Vendor

apache tomcat

Known CVEs
0
Highest CVSS
In KEV
0
Vendor
apache tomcat
Connections
53 relationships
Operational Summary - luglio 2026
Operational Summary - luglio 2026 Pubblicazione PL01/260820/CSIRT-ITA Torna l’appuntamento mensile di CSIRT Italia sull’analisi e l’andamento della minaccia cyber con l’elenco delle vulnerabilità informatiche più gravi. Di seguito i principali punti emersi nel mese: Nel mese di luglio 2026 sono stati registrati 188 incidenti, sostanzialmente allineati (+3%) rispetto ai 182 di giugno, mentre gli eventi complessivi (305) risultano in diminuzione del 28%. Tale flessione è riconducibile principalmente all’assenza di campagne DDoS di matrice hacktivista e al minor numero di eventi che hanno interessato fornitori di servizi IT, con ripercussioni su più organizzazioni, fenomeni che avevano caratterizzato i mesi precedenti. Nel mese ha assunto particolare rilievo una campagna di defacement che ha interessato numerosi siti web 1 basati sul CMS[1] Joomla. La campagna ha interessato oltre 60 siti web riconducibili a soggetti operanti in settori diversi – principalmente PA locale, ma anche enti di ricerca, università e imprese del settore tecnologico – tutti basati sul medesimo CMS. Tale circostanza evidenzia la natura opportunistica della campagna, nella quale la selezione dei bersagli è avvenuta in funzione della vulnerabilità esposta, anziché del settore di appartenenza o delle caratteristiche dei soggetti colpiti. Gli impatti sono stati circoscritti all’alterazione di alcune pagine web, senza ripercussioni sull’operatività dei soggetti coinvolti o sulla continuità dei servizi erogati. I contenuti pubblicati sulle pagine alterate si limitavano ad attestare l’avvenuta compromissione, senza veicolare particolari messaggi di natura hacktivista. Assume rilievo, in tale contesto, la pubblicazione del 15 giugno u.s. di un alert del CSIRT Italia[2] relativo allo sfruttamento attivo della vulnerabilità critica CVE-2026-48907, presente nell’estensione Joomla Content Editor (JCE), effettivamente sfruttata nella campagna di luglio. Complessivamente, nel corso del mese di luglio 2026, le principali minacce rilevate negli eventi sono state: defacement, compromissione delle caselle e-mail ed esposizione dati. I settori con il maggior numero di vittime di eventi cyber sono stati Pubblica amministrazione locale, Manifatturiero, Tecnologico e Telecomunicazioni, questi ultimi con la medesima incidenza. Il settore Pubblica amministrazione locale è stato interessato, come detto, principalmente da defacement, il Manifatturiero da phishing e compromissioni di caselle e-mail, il Tecnologico da esposizione dati e le Telecomunicazioni da compromissione di caselle e-mail. Gli attacchi ransomware hanno interessato prevalentemente i settori vendita al dettaglio, manifatturiero e tecnologico. L’analisi degli eventi rilevati evidenzia come i principali vettori di compromissione siano riconducibili allo sfruttamento di vulnerabilità note, all’utilizzo di credenziali valide, precedentemente compromesse, e ai servizi esposti. Nel mese di luglio 2026 non sono state rilevate campagne di particolare rilevanza rivolte contro soggetti nazionali. Nel mese di luglio 2026 lo sfruttamento di vulnerabilità è risultato il principale vettore di accesso iniziale, in relazione alla campagna di defacement sopra descritta; seguono la posta elettronica, impiegata come canale per veicolare campagne di phishing e spear phishing, e lo sfruttamento di credenziali valide già compromesse. Permane, con minore incidenza, l’abuso di servizi remoti esposti. Nel mese, il Common Vulnerabilities and Exposures (CVE) Program[3] ha pubblicato 9.919 nuovi record relativi a vulnerabilità di cybersicurezza, in aumento (+1.918) rispetto a giugno. Di questi, 324 presentano almeno un Proof of Concept (PoC), in diminuzione (−304), e per 13 CVE è stato rilevato lo sfruttamento attivo, stabile (−3) rispetto a giugno. Tra queste, ha rivolto particolare attenzione ad alcune vulnerabilità di rilievo relative a prodotti e soluzioni ampiamente utilizzati in ambito enterprise e infrastrutturale. Tra queste figurano quelle individuate in Citrix NetScaler ADC e NetScaler Gateway, prodotti impiegati per la distribuzione delle applicazioni, la gestione del traffico e l’accesso sicuro a servizi digitali (alert del CSIRT Italia: AL02/260701/CSIRT-ITA). Tali vulnerabilità, qualora sfruttate, permetterebbero ad un attaccante di prendere il controllo dei sistemi vulnerabili consentendogli l’accesso alla rete o alle applicazioni protette dagli stessi. Rileva, inoltre, la CVE-2026-55957, relativa ad Apache Tomcat, componente ampiamente utilizzato per l’esecuzione di applicazioni web basate su tecnologia Java. La vulnerabilità, richiamata dall’alert del CSIRT Italia AL04/260630/CSIRT-ITA, potrebbe consentire a un attaccante di autenticarsi senza fornire la password corretta, ottenendo accesso alle risorse protette dell’applicazione. L’attività di monitoraggio della superficie esposta ha consentito di individuare a luglio 2026 3.210 sistemi e servizi a rischio, in diminuzione (−1.026) rispetto a giugno. L’analisi di dati provenienti da malware di tipo infostealer, altresì, ha consentito di identificare 147 account compromessi afferenti a soggetti istituzionali, prontamente allertati. Nel mese è stata inoltre svolta una specifica attività di analisi sui CMS open source esposti (approfondimento in sezione 5.2), finalizzata a individuare possibili compromissioni nell’ambito della superficie osservata. L’attività ha consentito di rilevare 1.074 istanze CMS compromesse, oggetto di segnalazione ai titolari dei sistemi interessati o, ove necessario, ai provider di riferimento per le attività di bonifica. Le evidenze si concentrano in particolare nei settori della vendita al dettaglio, del manifatturiero, dell’università e ricerca e della pubblica amministrazione locale, confermando l’opportunismo delle campagne di compromissione massive di asset che espongono la medesima vulnerabilità. Nel corso del mese, l’attività di monitoraggio proattivo ha rilevato, altresì, diversi episodi di esposizione e commercializzazione di dati e credenziali compromesse su canali dedicati. In un caso, sono state pubblicate credenziali valide per accedere a VPN riferibili a più organizzazioni nei settori dell’università e ricerca e tecnologico. In un altro episodio, sono stati individuati contenuti riconducibili a organizzazioni italiane operanti nei settori tecnologico, università e ricerca, pubblica amministrazione locale, sanitario e servizi finanziari. Per tutti gli episodi rilevati il CSIRT Italia ha inviato apposite comunicazioni ai soggetti interessati. Le comunicazioni inviate complessivamente dal CSIRT Italia per segnalare potenziali compromissioni o fattori di rischio ad amministrazioni ed imprese italiane, anche ai sensi dell’art. 2, comma 1, della Legge n. 90/2024 sono state in totale 8.952, in aumento (+ 198) rispetto a giugno. [2] Link all’alert https://www..gov.it/portale/w/joomla-jce-sfruttamento-attivo-in-rete-della-cve-2026-48907 [3] Il CVE Program è un’iniziativa internazionale finalizzata a identificare, definire e catalogare le vulnerabilità di cybersicurezza divulgate pubblicamente, associando a ciascuna un identificativo univoco.
acn.gov.itAug 20, 2026extracted
Toolkit Hidden Inside Oracle Database Evades Endpoint Tools
A post-exploitation toolkit has been found compiled and stored inside an Oracle database as schema objects, giving attackers command execution on the underlying Windows server from a location conventional endpoint tooling does not inspect. Huntress detected the intrusion on July 27 after credential theft alerts fired on a host running an Oracle database server, and published its analysis on August 5. The entry point was SQL injection in the autocomplete search feature of a public-facing Java application running Apache Tomcat. No vulnerability was involved. The application passed unvalidated input to the database over a Java Database Connectivity (JDBC) connection, using an account permissioned to create Java objects. A Toolkit Compiled Inside the Database Oracle's database ships with an embedded Java Virtual Machine (JVM) and a statement that stores Java source code as a database object. The attacker fed that statement through the injection point, and Oracle compiled the code into stored schema objects. The toolkit is named khunt, after the convention running through its module names and the files it wrote to disk. Its components included a module that opened a Windows command shell for arbitrary operating system commands, and a credential dumper that read Oracle's internal user table and wrote usernames and passwords to a file. Alongside those sat two file explorers, an unzip utility, a reachability check to confirm the toolkit was live and a set of PL/SQL wrappers to call the underlying Java methods. The technique itself is not new, though Huntress called its use here a novel aspect of the attack, noting that documented cases in the wild have been rare. Where Endpoint Tools Do Not Look The attacker pivoted from the database to the operating system by opening a Windows command shell, confirming SYSTEM-level privileges. They then used PowerShell to invoke the Windows registry tool, copying the SECURITY and SYSTEM hives, enumerated running services and copied the SAM and SECURITY hives with the Extensible Storage Engine utility. Huntress assessed the hives were staged for credential dumping and probable exfiltration, describing the activity as an attempt rather than a confirmed theft. Apache access logs let researchers trace the requests to a single IP address. The detection problem is the point Huntress emphasized. Storing the toolkit as a database object rather than a file or memory-resident payload leaves it outside the scope of most security tooling, since endpoint products focus on processes, binaries and files rather than Java classes and PL/SQL wrappers inside Oracle. That, the firm said, turns the database from something attackers query for data into a foothold they can operate from. “To avoid these types of attacks, it's important to ensure the forms aren't injectable,” Huntress wrote. “Practice proper input sanitization and query parameterization for any inputs. It's also important to ensure that users with the ability to execute queries aren't overprovisioned.”
infosecurity-magazine.comAug 6, 2026extracted
Hackers run khunt post-exploitation toolkit from Oracle database
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database that was used to breach a corporate network. The attack was discovered by Huntress on July 27, 2026, after its security platform detected credential theft on a server hosting an Oracle database server. Apache access logs showed that the attackers gained access through a vulnerable search engine endpoint in a public-facing Java application running Apache Tomcat. The application failed to properly validate input submitted through an autocomplete search feature that allowed the attackers to issue SQL commands to the Oracle database. Huntress traced the malicious requests to the IP address 178.162.151[.]229. khunt Toolkit stored inside Oracle After exploiting the SQL injection flaw, the attackers installed a post-exploitation toolkit called khunt directly into the Oracle database as a Java object. Oracle has an embedded Java Virtual Machine and the CREATE JAVA SOURCE statement, which allows Java source code to be stored and compiled as a database schema object. These Java objects can then be executed via SQL commands, which if configured to do so, can execute commands on the host operating system. The attackers abused this functionality to compile and store the khunt toolkit directly inside the Oracle database rather than deploying them as executable files on the server. "The use of the technique in the wild has rarely been documented," Huntress said. The toolkit contained multiple Java components and PL/SQL wrappers that could execute commands, steal credentials, and manage files. These components included: KhuntCmd, which launched cmd.exe and allowed attackers to execute operating system commands through SQL statements. KhuntHash, which accessed Oracle’s internal user table and wrote usernames and password data to a file. KhuntFS and KhuntFS2, which provided file browsing, reading, searching, and file-size checking capabilities. KhuntT, which acted as a ping-like test to confirm that the toolkit had been successfully installed. KhuntUnzip, which extracted compressed files. The attackers used KhuntCmd to run cmd.exe /c whoami, confirming that commands executed through the Oracle database had SYSTEM-level permissions on the Windows server. They then used PowerShell and Windows utilities to copy the SAM, SECURITY, and SYSTEM registry hives, which can be used to recover password hashes for local Windows accounts. The attackers also ran tasklist /svc to enumerate running services and saved the output to khunttasks.txt. Huntress said the registry hives were likely exfiltrated for credential dumping, but the report does not confirm whether the files were successfully stolen. As a general rule, organizations should sanitize all user supplied input validation and limit the privileges granted to application database accounts. Huntress recommends that database accounts used in public-facing applications should not have high enough privileges to create Java sources, execute unnecessary stored procedures, or perform other administrative actions. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 5, 2026extracted
CISA warns of hackers exploiting Langflow, N-central, Apache Tomcat flaws
The U.S. Cybersecurity and Infrastructure Security Agency is giving federal agencies three days to mitigate vulnerabilities in IBM Langflow, N-central, and Apache Tomcat, all actively exploited. Tracked as CVE-2026-9198, the security issue in IBM’s Langflow visual framework for building AI agents is the most severe, with a critical rating of 9.8 out of 10. It allows an unauthenticated attacker to execute remotely on default Langflow deployments by chaining two API endpoints to bypass login and run code. In late July, multiple fully functional proof-of-concept (PoC) exploits for CVE-2026-9198 emerged in the public space, with complete instructions on how they can be leveraged. Two weeks ago, CISA issued an alert for another critical Langflow vulnerability (CVE-2026-0770) being exploited in attacks to gain remote code execution with root privileges. The vulnerability in N-able’s remote monitoring and management platform N-central is identified as CVE-2026-18576 and allows attackers to hijack administrative accounts without authentication. The flaw received a high-severity rating and has been patched by the vendor. However, the fix was insufficient, and threat actors found a new way to exploit it. N-able warned customers on August 1st that hackers were actively exploiting the new vulnerability, which received the identifier CVE-2026-18576. An emergency hotfix was released on Sunday. The company urged customers to install it as the flaw impacted all versions of N-central before 2026.3. The Apache Tomcat vulnerability, tracked as CVE-2026-34486, has a high-severity score of 7.5. It stems from an incomplete fix for CVE-2026-29146, a critical vulnerability with a severity rating of 9.8 that is described as the missing encryption of sensitive data. On July 30, researchers at Palo Alto Networks Unit 42 reported that a Chinese-speaking threat actor tried to exploit the CVE-2026-34486 vulnerability in a manual campaign to plant reverse shells on nine Apache Tomcat servers. CISA confirmed that threat actors are leveraging all three flaws in attacks and added them to its catalog of Known Exploited Vulnerabilities (KEV). However, the agency did not share what types of attacks are leveraging them, noting that it is unknown if they are used in ransomware campaigns. CISA has ordered federal agencies to apply available mitigations for the three targeted products by the end of Friday, July 7th. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comAug 5, 2026extracted
CISA Warns of Exploited Langflow, N-central, and Tomcat Vulnerabilities
The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned that threat actors have been exploiting three vulnerabilities in IBM Langflow OSS, N-able N-central, and Apache Tomcat. Tracked as CVE-2026-9198 (CVSS score of 9.8), the Langflow OSS bug allows unauthenticated attackers to chain two API endpoints for remote code execution. It was disclosed on July 17, when IBM rolled out patches for it, in Langflow OSS version 1.10.1, warning that all default deployments are affected. “The vulnerability combined two distinct issues: an unauthenticated endpoint that issued superuser bearer tokens to any network caller, and a code validation endpoint that executed arbitrary Python code. An attacker could chain these vulnerabilities by first obtaining a superuser token from the auto-login endpoint, then using that token to submit malicious code to the validation endpoint,” IBM warned. Proof-of-concept (PoC) code targeting the security defect was published roughly a week after the public disclosure, and CISA added the CVE to its Known Exploited Vulnerabilities (KEV) catalog on August 4. The N-able N-central bug flagged as exploited is tracked as CVE-2026-18556 (CVSS score of 7.4) and described as an authentication bypass. According to N-able, threat actors exploited the issue as a zero-day to gain administrative access and connect to systems managed through the remote monitoring and management (RMM) platform. The initial fix for CVE-2026-18556 was incomplete, and threat actors bypassed it. As the exploitation activity intensified at the end of July, N-able rolled out a hotfix, issuing CVE-2026-18577 for the patch bypass. Both CVE-2026-18556 and CVE-2026-18577 are now in CISA’s KEV list. Tracked as CVE-2026-34486 (CVSS score of 7.5), the third vulnerability added to the KEV catalog on Tuesday is an EncryptInterceptor bypass in Apache Tomcat that was patched in April. The flaw was introduced in March, with the patch for CVE-2026-29146, a padding oracle issue in EncryptInterceptor, an optional channel interceptor that encrypts messages transmitted between nodes in Tomcat clusters. “The fix moved one line of code. That line turned the encryption layer from fail-closed to fail-open, and opened a direct path to unauthenticated remote code execution on every cluster member,” StrigaAI, which identified the bug, explains. On deployments with EncryptInterceptor configured, only messages encrypted using a shared key should be decrypted and passed to the deserialization layer. Due to the bypass, however, upon failed decryption, the attacker-controlled code was forwarded up the interceptor chain unmodified. Last week, SOCRadar warned that CVE-2026-34486 had been exploited by a Chinese threat actor in attacks involving the Snowlight malware family, while Palo Alto Networks observed the vulnerability being exploited by Chinese hackers in an AI-enabled autonomous hacking campaign. In line with BOD 26-04 requirements, CISA is urging federal agencies to patch all three vulnerabilities by August 7. Related: TP-Link Omada ZTP Vulnerabilities Chain Into Full Network Takeover Related: Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks Related: Recent SonicWall Vulnerabilities Exploited in Ransomware Attacks
securityweek.comAug 5, 2026extracted
CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows - CVE-2026-9198 (CVSS score: 9.8) - A code injection vulnerability in Langflow that allows unauthenticated attackers to achieve full remote code execution on default Langflow deployments. (Fixed in July 2026 with version 1.10.1) CVE-2026-34486 (CVS score: 7.5) - A missing encryption of sensitive data vulnerability in Apache Tomcat that allows a bypass of EncryptInterceptor, a cluster component that adds pre-shared key encryption to messages sent between cluster nodes. (Fixed in April 2026 with versions 11.0.21, 10.1.54, and 9.0.117) Also added to the KEV catalog is CVE-2026-18556 (CVSS score: 8.2), an authentication bypass vulnerability in N-able N-central. It's worth noting that an incomplete fix for this issue prompted N-able to issue a fresh patch, which is tracked as CVE-2026-18577 (CVSS score: 8.2). While CVE-2026-18577 was placed in the KEV catalog on Monday, the latest development signals that both vulnerabilities are being exploited by threat actors. There are currently no details on how the Langflow flaw is being exploited. However, security defects in the open-source artificial intelligence (AI) application development platform have been repeatedly weaponized by bad actors in recent months. Telemetry data from KEVIntel shows that 650 exploitation attempts against CVE-2026-9198 have been recorded starting July 6, 2026, from 244 unique attacker IP addresses from 41 countries. The exploitation of CVE-2026-34486, on the other hand, has been attributed to an AI-enabled autonomous hacking campaign orchestrated by a Chinese-speaking threat actor operating under the aliases knaithe and KnYuan. The threat actor, based in Zhuhai, China, is said to have leveraged DeepSeek, via the Hermes Agent framework, as an offensive operator to target internet-exposed devices. When initial attempts to exploit a Langflow flaw (CVE-2026-33017, CVSS 9.8) breach failed due to the target environment's restrictive configurations, the AI agent is said to have conducted autonomous research to identify other higher-value vulnerabilities, including flaws in n8n, to find a way in. Separately, the Chinese-speaking adversary has been found conducting manual operations using known vulnerabilities in Citrix NetScaler (CVE-2026-3055), Marimo (CVE-2026-39987), Apache Tomcat (CVE-2026-34486), and IKE VPN (CVE-2026-33824) endpoints. "This actor attempted to exploit over 460 targets, leveraging a mix of autonomous and manual techniques," Palo Alto Networks Unit 42 said. "What's interesting is that the actor appeared to allow DeepSeek to narrow the targeting scope, likely to conserve AI compute." "This autonomous process of target identification, sampling and narrowing of scope is notable because the system executed hundreds of hours of manual targeting analysis in mere minutes, while also managing its own compute resources." CVE-2026-34486 has also been weaponized in attacks mounted by a China-nexus threat actor targeting government and commercial infrastructure across more than 100 countries to deliver SNOWLIGHT, a lightweight, C-based Linux dropper and loader. The campaign is assessed to have taken place between late April and early June 2026. The activity was discovered by SOCRadar following an analysis of an exposed adversary-operated staging server containing reconnaissance lists, nine weaponized CVEs, a cracked Chinese version of Cobalt Strike dubbed GoCobaltStrike, tunneling tooling, and other payloads. "The toolkit comprises a purpose-built reconnaissance pipeline, eleven distinct exploit chains, two tunneling tools, and four C2/RAT/malware families, including a verified SNOWLIGHT instance," the cybersecurity company said. "These components were primarily assembled using public GitHub proof-of-concepts, alongside one pirated commercial C2 product and a single instance of a tracked, named malware family." The threat actors have been found to exploit nine distinct CVEs to breach 107 endpoints, including 16 root-level cPanel/WHM takeovers (CVE-2026-41940) and one Domain Admin-level compromise via ProxyShell. "The campaign demonstrates a highly opportunistic and automated 'spray-and-check' tactical model employed by China-nexus threat actors to compromise a broad spectrum of global government and commercial infrastructure," SOCRadar noted. "By leveraging a centralized, multi-platform attack infrastructure (including cracked Cobalt-Strike derivatives and a sophisticated loader ecosystem) these operators have successfully achieved high-impact takeovers across more than 100 countries." Federal Civilian Executive Branch (FCEB) agencies have until August 7, 2026, to apply the necessary fixes and safeguard their networks from active threats. (The story was updated after publication on August 8, 2026, to include details of exploitation attempts targeting CVE-2026-9198.)
thehackernews.comAug 5, 2026extracted
Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers
Chinese hacker used DeepSeek to launch autonomous cyberattacks on vulnerable servers A Chinese threat actor operating under the aliases “knaithe” and “KnYuan” used multiple LLMs to automate cyberattacks against internet-facing systems with limited human intervention. Researchers at Palo Alto Networks’ Unit 42 uncovered the operation after the threat actor’s AI agent misconfigured a file server, inadvertently exposing the entire infrastructure. “This visibility enabled us to understand their full tool set, how the attackers orchestrated multiple AI platforms and gave us a peek into their targeting,” Unit 42 wrote. “Based on our analysis of their session logs and configuration files, the actor primarily used the Hermes Agent with DeepSeek as its reasoning agent for the attack phase of this campaign. Their Hermes Agent conducted autonomous vulnerability enumeration, downloaded public exploit code from the internet and attempted exploits against targets,” the researchers explained. After receiving instructions over Telegram, the agent worked autonomously. It searched internet-facing systems through the FOFA search engine, downloaded exploit code from GitHub, and launched attacks without requiring further operator input. Beyond DeepSeek, the threat actor deployed several other LLMs, including Qwen, GLM, Kimi, and MiniMax. Researchers also found evidence of limited testing of Western AI tools. Claude Code appeared only in connectivity checks and proxy tests, while Codex artifacts were found in exploit development directories. “This limited usage is consistent with evaluating the AI-market to identify their preferred tool set.” AI agent prioritized and tested exploits In one recovered session, the AI agent targeted a Langflow vulnerability tracked as CVE-2026-33017, rated 9.8 in severity. It downloaded a public exploit from GitHub, identified 84 exposed Langflow servers through FOFA, and assessed them for exploitation. Only one appeared potentially vulnerable, but the attack ultimately failed because the required configuration was not enabled. “The exploitation attempts failed because the vulnerability requires either auto_login enabled or a public flow ID and the target had neither. DeepSeek assessed the entire product as a low-value target,” Unit 42 said. The AI agent then analyzed public exploit repositories, weighing vulnerability severity against deployment scale before selecting n8n, a workflow automation platform that FOFA identified on more than 647,000 internet-exposed servers worldwide, including more than 25,000 in China. It selected an exploit chaining two vulnerabilities: CVE-2026-21858, an arbitrary file read flaw with a CVSS score of 10.0, and CVE-2025-68613, a sandbox escape vulnerability leading to remote code execution with a CVSS score of 9.9. Although both flaws had already been patched in newer n8n releases, the AI agent determined that version 1.117.3 predated both fixes and was therefore vulnerable to the exploit chain. “This autonomous process of target identification, sampling and narrowing of scope is notable because the system executed hundreds of hours of manual targeting analysis in mere minutes, while also managing its own compute resources,” the researchers noted. Autonomous attack flow observed in Hermes Agent session (Source: Palo Alto Networks) Although none of the autonomous attacks resulted in a successful compromise, Unit 42 described the workflow as “a functional, end-to-end autonomous offensive capability.” Manual attacks delivered the results Outside the AI-driven sessions, the threat actor also conducted hands-on attacks against more than 460 systems, targeting known vulnerabilities in Citrix NetScaler, Apache Tomcat, Marimo Notebook, and Windows IKE VPN, among others. Three of the manual attacks succeeded, all exploiting CVE-2026-3055 in Citrix NetScaler appliances. The attackers extracted data directly from device memory and searched it for authentication cookies that could be be used to hijack active user sessions. “The technical barrier to AI-augmented offensive operations is low and continues to decrease,” the researchers concluded.
helpnetsecurity.comAug 3, 2026extracted
Hacker uses DeepSeek AI to autonomously attack vulnerable servers
A Chinese-speaking threat actor is using the DeepSeek AI model and the open-source Hermes Agent to conduct autonomous cyberattacks on exposed servers with limited human involvement. The activity was discovered by Palo Alto Networks' Unit 42 researchers after Hermes accidentally created a web server from its home directory, exposing the attacker's environment, including API keys, exploit scripts, target lists, shell history, and AI attack logs. Unit 42 attributed the activity to a China-based threat actor operating under the aliases "knaithe" and "KnYuan," who calls themself a "binary security researcher." While the autonomous attacks observed by Unit 42 did not successfully compromise the targeted servers, the researchers say the campaign illustrates an offensive AI workflow capable of discovering, evaluating, and attacking vulnerable systems. "While the observed campaign had limited impacts, the workflow confirms a functional, end-to-end autonomous offensive capability," Unit 42 said. DeepSeek used for autonomous attacks The threat actor used DeepSeek as the reasoning engine behind Hermes Agent, an open-source AI framework capable of interacting with operating system terminals, running commands, and connecting to the internet. The agent supports a "Yolo" mode that allows it to operate and execute commands, even risky ones, without first requesting permission from its operator. Hermes was configured to accept instructions from a Telegram channel, use custom offensive-security skills, and integrate with the FOFA internet asset search engine. Unit 42 recovered a May 2026 session in which the operator appears to have provided only an initial task, after which the agent conducted the remaining activity autonomously without human feedback. The agent first targeted internet-exposed Langflow servers vulnerable to CVE-2026-33017, downloading a public proof-of-concept exploit, identifying 84 exposed instances through FOFA, and scanning them for vulnerable configurations. After determining that the available targets could not be exploited, the agent searched for other potential vulnerabilities to scan for vulnerable devices. DeepSeek then analyzed multiple public exploit repositories before selecting the n8n workflow automation platform to target, which had more than 647,000 exposed instances identified through FOFA. The agent downloaded an exploit that chained CVE-2026-21858 and CVE-2025-68613, identified servers running vulnerable versions, and checked them for unauthenticated file-upload forms required to complete the attack. However, the discovered forms required authentication, and Unit 42 says the autonomous attempts failed to compromise any targets. Unit 42 says the campaign is significant because the agent independently researched vulnerabilities, determined which targets were the best option, downloaded exploit code, and then attempted to exploit found targets in minutes what would normally take many hours. "This autonomous process of target identification, sampling and narrowing of scope is notable because the system executed hundreds of hours of manual targeting analysis in mere minutes, while also managing its own compute resources," explained Palo Alto. While the AI agent was used extensively, the threat actor also conducted manual attacks against more than 460 systems using vulnerabilities affecting Citrix NetScaler, Apache Tomcat, Marimo Notebook, Windows IKE VPN, and other products. Unit 42 confirmed three successful compromises targeting the Citrix NetScaler vulnerability CVE-2026-3055, which the actor used to extract memory and search for authentication cookies that could be used to hijack sessions. The actor had also configured other AI coding platforms, including Qwen, GLM, Kimi, MiniMax, Claude Code, and OpenAI's Codex, but Unit 42 found that they were not used often. Hermes used in previous cyberattack The exposed AI campaign comes after another recently disclosed incident in which poorly secured Hermes infrastructure exposed details about an alleged cyberattack against Thailand's Ministry of Finance. Last week, BleepingComputer reported that Hunt.io and security researcher Bob Diachenko discovered open web directories containing exploit tools, web shells, credentials, compiled payloads, and Hermes activity logs. Those logs showed Hermes running in unattended "YOLO" mode to automate post-exploitation activity, including searching for privilege-escalation opportunities, enumerating services, inspecting containers, traversing filesystems, and cataloging documents stored on Ministry of Finance systems. However, the earlier incident did not show Hermes independently choosing the target or determining how to compromise it. A human operator supplied the target, objectives, and attack tools, while Hermes automated routine activity after access had apparently already been obtained. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJul 31, 2026extracted
ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories
A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and exploit paths that should have been harder. Some defenses improved. The loose parts still got found first. Anyway, here's the mess. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out. Phishing delivers XWormA cybercrime group known as xplogs22 has been observed targeting Russia and other CIS countries with phishing emails that deliver Xworm. The group, per F6, is believed to have been active since November 2023. Prior attacks mounted by the threat actors leveraged Formbook and Snake Keylogger, before switching to XWorm around July 2025. In recent months, Russian customers of the banking sector have also been targeted by an Android trojan called LunaSpy as part of social engineering attacks. LunaSpy can capture camera streams, record audio and the screen, and collect sensitive data. The malware is disguised as an antivirus application to evade detection. Custom ransomware targets RussiaThe financially motivated extortion group known as Toy Ghouls (aka Bearlyfy and Labubu) has targeted organizations in the Russian Federation, primarily in the manufacturing, financial services, retail, and technology sectors, with a custom ransomware family called GenieLocker since March 2026. According to Kaspersky, the group previously relied on third-party encryptors like RedAlert, LockBit, and Babuk. "GenieLocker, apparently a custom design, upgrades their toolkit and reduces their reliance on third-party software," Kaspersky said. In at least one case, initial access to the target environment was obtained via an OpenVPN connection originating from an external partner's network, with the attackers likely exploiting the trusted relationship to breach the target, conduct reconnaissance, deliver additional tools for credential harvesting, and perform lateral movement via RDP and SSH to reach other Windows and Linux hosts. "During the impact phase, the attackers encrypted files on the compromised Windows machines with the PE version of the GenieLocker ransomware," Kaspersky said. "On the compromised Linux and ESXi servers, they stopped active virtual machines and encrypted their disks using the ELF version of GenieLocker." Details of the activity were first highlighted by F6 in March 2026. Crypto-stealing payloads deployedThe malware loader known as CastleLoader, which has been previously used to deliver CastleStealer and a Python-based remote access trojan (RAT) via ClickFix-style lures, has now been used to distribute two payloads tied to the Needle Stealer framework: a Rust-based desktop wallet spoofer, and a Golang-based malicious browser extension installer. Arctic Wolf said it also identified a new shellcode loader variant spreading via digitally signed installers. The campaign has been codenamed Noidret. The introduction of these new tools is seen as an attempt to focus on cryptocurrency-specific targeting and establish browser-level persistence. Fileless WebDAV executionSpeaking of ClickFix, CyberProof said it tracked a ClickFix variant that involves tricking victims into pasting a single command into the Windows Run dialog, which then communicates with a WebDAV endpoint and uses rundll32.exe to load a remote, non-DLL payload and call its first export by ordinal without having to leave any artifacts on disk. "The payload (gc.key, j.pm, or goog.ct) is a file served from the attacker WebDAV share and is not a standard DLL by extension," CyberProof said. "It is invoked by rundll32.exe through ordinal #1, which runs its primary routine while keeping the export name off the command line." Fake Claude guide spreads malwareVictims searching Google for how to install Claude on a Mac are being served sponsored results that lead them to a weaponized claude.ai/share conversation dressed up as an Apple Support install guide. The "guide" instructs them to open Terminal and paste a single curl command, ultimately leading to execution of MacSync Stealer. "MacSync is a six-stage kill chain, not a smash-and-grab," Huntress said. "The components are a thin zsh loader, a server-side AppleScript stealer that keeps the valuable logic off the endpoint and behind an api-key gate, a native Mach-O RAT for hands-on access, a separately signed helper built to steal a single TCC permission (Screen Recording), and a set of wallet-app trojans. Each stage sets up the ones that follow." Malware, intrusions, and influence opsA Russian-speaking threat group is said to be behind an active campaign called Operation STANDOFF that combines commodity-malware distribution, a proxy-botnet that conscripts victims into relay infrastructure, targeted hands-on-keyboard intrusion of enterprise networks, and an AI-driven, multi-channel influence and engagement-manipulation capabilities under one roof. "The operation is materially more than a botnet," VMRay Labs said. "It couples automated, scaled cybercrime with hands-on-keyboard, targeted intrusion and a coordinated influence capability, all on the same infrastructure and built by a common development team." The influence apparatus uses networks of fake Telegram accounts and AI-generated personas to artificially boost the visibility of content, push commercial promotions, and drive traffic to gambling and fraud-adjacent services. The activity uses a pay-per-install (PPI) loader masquerading as software installers that delivers Raccoon Stealer, RedLine, Amadey, SmokeLoader, Socelars, Glupteba, and XMRig cryptocurrency miner, while a second, targeted operations layer relies on a bespoke, multi-operator command-and-control console through which human operators conduct hands-on-keyboard intrusions of selected victims. Fleet takeover flaw exposedSecurity researcher Eaton Zveare has disclosed details of a vulnerability in My Eicher, a fleet management system developed by the Volvo Group and Eicher Motors for Indian commercial vehicle customers, that enabled the discovery of unauthenticated internal and. admin APIs that could be exploited to gain high-level access to systems and even enable account takeover. "Account takeover made it possible to gain control over a person's (or company's) entire fleet, which could consist of hundreds of vehicles," Zveare said. Following responsible disclosure on November 3, 2025, the issue was addressed at some point by November 20. AI agents automate exploitationA Chinese-speaking threat actor has been carrying out an AI-enabled autonomous hacking campaign, targeting infrastructure using seven vulnerabilities in Langflow (CVE-2026-33017), n8n (CVE-2026-21858, CVE-2025-68613), Citrix NetScaler (CVE-2026-3055), Apache Tomcat (CVE-2026-34486), Marimo Notebook (CVE-2026-39987), Palo Alto Networks PAN-OS (CVE-2026-0300), and Microsoft Windows IKE Extensions (CVE-2026-33824). The actor, operating under the aliases knaithe and KnYuan, has leveraged DeepSeek, via the Hermes Agent framework, as their autonomous offensive operator, while orchestrating the operation through Telegram to enumerate targets, source exploit tools, and initiate attacks without human intervention. "Hermes Agent provided orchestration (terminal access, Telegram-based command and control, and the skills system) while DeepSeek served as the reasoning engine for code generation, vulnerability assessment, target selection and decision-making," Unit 42 said. Additionally, the threat actor is said to have used Claude Code, Codex, and Qwen Code in a limited capacity. "When initial exploitation failed due to the target environment's restrictive configurations, their Hermes Agent autonomously conducted searches for known critical-severity Common Vulnerabilities and Exposures (CVEs)," Unit 42 said. "It initially surveyed 10 product families, scanning GitHub for trending proofs of concept (PoCs) and prioritizing vulnerabilities by attack surface." Trusted access fuels cryptominingDetails have emerged about a covert Linux XMRig campaign that exploits trusted access, and weaponizes Pluggable Authentication Modules (PAM) to create a forensic smokescreen and deploy a highly customized XMRig botnet implant. "Initial access was achieved by exploiting a trusted third-party relationship, highlighting critical supply chain risks," Group-IB said. "The threat actor escalated to root access, but weaponised the pam_rootok policy to seamlessly impersonate multiple low-privileged users to create a forensic smokescreen designed to confuse incident responders and establish a 'hydra-like' redundant persistence across unmonitored accounts." The campaign is characterized by efforts to actively suppress system visibility by disabling logging services and removing authentication logs to blind standard file-based monitoring. The campaign was first observed in March 2026. Fake recruiter delivers stealerThreat actors are masquerading as recruiters and trucking victims into installing a malicious application disguised as an AI meeting tool called Relay. The malware targets both macOS and Windows users, and attempts to steal sensitive data including browser credentials, wallet-related information, Keychain data, and Telegram sessions, per SlowMist. 900,000 customers affectedAustralian energy company Origin Energy said it completed the initial phase of its review into a security incident that took place earlier this month, finding that "the information of approximately 900,000 current and former customers was accessed." The information accessed may include name, address, date of birth, phone number, last four digits of a credit card, or the BSB and last three digits of a bank account, and account details. Healthcare SaaS accounts targetedHealth-ISAC is warning of an increase in successful attacks conducted by ShinyHunters. "The group appears to prioritize identity compromise and SaaS access over traditional ransomware deployment," it said. "The operational pattern described in recent incident reporting aligns to a repeatable chain: vishing (voice social engineering) → helpdesk/MFA reset or device re-enrollment → Microsoft Entra (or Okta/Google) SSO account takeover → pivot into connected SaaS platforms → rapid data exfiltration for extortion leverage. Even when victim statements indicate limited operational impact, the described tradecraft is the key defensive lesson. SSO is the control plane, and ShinyHunters' leverage is created through data theft at cloud scale." Supply chain defenses tightenedGitHub has laid out the various steps it has taken to harden the supply chain at various stages and combat attacks that target weaknesses in package repositories and CI/CD systems for malware propagation. Some of these include: (1) npm adding preventive account protection for high-impact accounts, (2) safer pull_request_target defaults for GitHub Actions checkout, (3) better controls over who and what triggers GitHub Actions workflows, (4) read-only Actions cache for untrusted triggers, (5) support for CircleCI in npm trusted publishing, (6) Action workflow network firewall, (7) staged publishing for npm, (8) default package cooldown for Dependabot version updates, (9) self-service credential revocation for incident response, and (10) expanded credential revocation API support. Seven critical Chrome flaws fixedIn an update released on July 29, 2026, Google shipped patches to address 370 flaws in its Chrome browser, including seven that are rated critical in severity (from CVE-2026-17650 through CVE-2026-17656). Of these, 349 flaws were reported by Google itself, with the tech giant noting that the bugs were detected using AddressSanitizer, MemorySanitizer, UndefinedBehaviorSanitizer, Control Flow Integrity, libFuzzer, or AFL. None of the patched vulnerabilities have been flagged as actively exploited. The fixes are available in versions 151.0.7922.71/.72 for Windows and Mac and 151.0.7922.71 for Linux. Google has addressed over 1,800 vulnerabilities in Chrome since the beginning of the year. Edge devices need forensic visibilityThe U.K. National Cyber Security Centre (NCSC) has urged network device manufacturers to help incident response teams by making it easier to gather evidence after a compromise. "Forensic observability is particularly important for edge devices such as firewalls, VPN gateways and other network appliances," NCSC said. "These systems often sit at trust boundaries and are increasingly targeted by sophisticated threat actors. Forensic observability means giving defenders reliable ways to understand what a device is doing, what it has done and whether it can still be trusted after an incident. This includes telemetry, logging, configuration state, and the ability to collect forensic data from both memory and data at rest. Manufacturers should provide supported mechanisms for gathering the evidence needed to investigate incidents, assess impact, and restore trust in affected systems." Phishing pages built in real timeBarracuda has revealed that LogoKit has evolved from a standard phishing kit into a "real-time deception platform" capable of building customized phishing pages for each victim. "LogoKit has moved beyond static fake login pages, such as pre-built replicas of popular brands, to the creation and use of real-time, highly personalized phishing experiences," it said. "The platform uses legitimate commercial web services to recreate a victim's corporate login experience, making phishing attacks more convincing and harder to detect. Every victim effectively receives a uniquely branded phishing page, making generic indicators of compromise harder to identify." This involves capturing a real-time screenshot of the victim's legitimate website and building phishing pages tailored to them. LogoKit uses the commercial Thum.io service to "create full, legitimate website screenshots for the phishing background and Clearbit to add legitimate brand logos." The attackers also rely on legitimate services, including Google Favicon, ImageKit and Microlink APIs, to dynamically load authentic logos and website imagery in real-time. LogoKit campaigns use phishing emails bearing warnings about passwords or delivery failures and timesheet updates to direct victims to the fake pages. Exploitation accelerates in 2026A new analysis from VulnCheck has revealed that despite a significant uptick in vulnerability discovery and disclosure, 23.43% of known exploited vulnerabilities (KEVs) showed evidence of exploitation on or before the day the CVE was published. "At the same time, vulnerabilities appear to be being exploited faster, with the median time from CVE publication to KEV falling from 120 days in 2025 to 80 days during the first half of 2026," VulnCheck said. "Of 1,061 vulnerabilities attributed to AI-assisted discovery, only 14, or 1.3%, have been confirmed as exploited in the wild, roughly matching the overall exploitation rate of all vulnerabilities in the first six months of the year." The top technology categories being targeted by exploitation activity include CMS systems, network edge devices, operating systems, server software, and AI infrastructure (e.g., Langflow, Majordomo, lollms, LiteLLM, and dify). Credential stuffing hits SonicWallAn active, broad, and opportunistic credential stuffing campaign has been observed since July 25, 2026, resulting in successful unauthorized logins to SonicWall VPN and firewall accounts. To date, 92 unique user accounts across 30 organizations have been impacted. "The activity stems from five IPs and relies on infrastructure hosted on DigitalOcean to compromise numerous, seemingly unrelated organizations," Huntress said. "Current telemetry indicates this is an automated credential validation attack, consistent with similar campaigns targeting SonicWall VPNs throughout 2025 and 2026." Threat actors get new namesGoogle Threat Intelligence Group (GTIG) said it will be rolling out a unified naming schema for tracking threat actors as part of its effort to standardize tracking across platforms and public reporting. "The new naming convention aligns with industry standard threat actor naming systems," GTIG said. To that end, the new schema utilizes a cryptonym-based approach employing two-word combinations for each distinct threat actor, similar to those adopted by CrowdStrike (e.g., Mustang Panda) and Microsoft (e.g., Twill Typhoon). The first word is a term chosen to represent the specific actor, while the second word categorizes threat clusters by motivation, attribution, or activity type. Going forward, APT44 (aka Sandworm) will be referred to as Sandworm Relic, where Relic is the category name for threat actors of Russian origin. Similarly, those from China will be grouped under Castle, Iran under Ion, North Korea under Neptune, and cybercriminal gangs under Comet. GTIG said it will continue to use UNC (or uncategorized) for threat clusters that are still in the early stages of investigation. Hidden desktop hijacks sessionsA new remote access trojan (RAT) called MedusaHVNC is being sold as malware-as-a-service (MaaS), per BlackFog. The malware embeds a hidden virtual network computing (HVNC) module that opens a browser on a separate Windows desktop that's out of sight of the victim. "The browser still runs on the victim's device, so it can load an existing profile, including cookies and session state," BlackFog said. "This gives the operator access to live, logged-in sessions while the activity continues to come from the victim's usual machine." The seller lists Chrome, Edge, Brave, Firefox, and Telegram as supported applications. The malware uses a 5-stage infection chain. It begins when the legitimate "wscript.exe" binary executes a JavaScript launcher, which then sets off the subsequent steps, including dropping additional payloads and using AutoIT to decrypt and launch MedusaHVNC, which then communicates with an external server to exfiltrate data. DNS hijack exposed credentialsCubePilot has announced an operational disruption stemming from a DNS hijacking attack. Unknown threat actors are said to have gained control of the cubepilot[.]org domain DNS settings on July 24, allowing them to intercept traffic intended for internal systems. The threat actors also obtained TLS certificates covering all cubepilot.org subdomains. "The certificates obtained by the attacker covered every cubepilot.org subdomain, so credentials entered on any of our services on 24 July may have been captured - the portal and the forum included," CubePilot said. "If you used the same password anywhere else, change it there now." CubePilot has since regained control of its domains and revoked the fraudulently issued certificates. Spear-phishing delivers SpyGlaceThe threat actor known as APT-C-60 has continued to target Japanese organizations with spear-phishing emails to deliver SpyGlace malware. "While several changes have been identified, such as a shift in infrastructure from Bitbucket to GitHub and updates to the malware itself, many characteristics remain consistent, including the abuse of legitimate services and the behavior of the malware," JPCERT/CC said late last year. As of 2026, the spear-phishing emails contain a Proton Drive link to trick recipients into downloading a RAR archive containing a LNK file, which then deploys SpyGlace by downloading an intermediate payload from jsDelivr. "By using legitimate services, the threat actor may be attempting to make communications and downloads appear to be normal access," JPCERT/CC said. AI agent validates exploitable flawsGoogle has launched a preview of CodeMender, an AI agent designed to scan codebases for security flaws, confirm they are exploitable and eliminate false positives, and generate fixes for developers to review. The tool supports C/C++, Go, Java, Python, Ruby, Rust, and TypeScript. "The agent goes beyond static code-pattern analysis by simulating an attack with exploit code it builds and runs in an isolated, customer-managed sandbox," Google said. "The agent uses this proof-of-concept exploit to verify that the security flaw poses a legitimate risk. This critical verification phase allows your security practitioners and developers to prioritize validated risks by eliminating false positives." CodeMender will add support for third-party frontier models later this year. 4,340 extremist URLs flaggedEuropol said it supported an action targeting nihilistic violent extremist content online between June and July 2026 with an aim to disrupt The Com online ecosystem and restrict propaganda dissemination. The agency and its partners have flagged 4,340 "horrific" URLs linked to The Com for removal. Belgium, Finland, Hungary, Ireland, Luxembourg, Netherlands, Portugal, Spain, and Sweden participated in the effort. "Groups affiliated with The Com recruit members and groom victims on social media, messaging apps, and gaming platforms to engage in self-harm, animal torture, violent attacks, and the production of child sexual abuse material," Europol said. "They distribute propaganda on accessible platforms to attract young individuals, funnelling potential members and victims into private forums and chat rooms where radicalisation and victimisation occur. Victims are typically coerced into remaining under the perpetrators' influence through (s)extortion." Members of the loose-knit collective also participate in cybercrime, extortion, doxxing, swatting, real-life shootings, stabbings, and other physical violence. Fake games deliver AmateraFake downloads of games, mods, cracks, and software are being used to spread RenPy Loader (aka RenEngine Loader). "Once installed, the loader starts a complex, multi-stage infection chain that abuses MSBuild and the EtherHiding technique before ultimately delivering Amatera Stealer," Malwarebytes said. "RenPy Loader has also been observed delivering other malware, including Hijack Loader and Lumma Stealer, showing that the final payload can vary between campaigns." Most failures stay quiet until someone relies on them. A login works. A partner is trusted. A tool behaves as expected. Then one assumption turns out to be doing all the security work. That is the part worth checking before next week finds it first.
thehackernews.comJul 30, 2026extracted
Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks
Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact. The actor, operating under the aliases knaithe and KnYuan, leveraged DeepSeek, via the Hermes Agent framework, as their autonomous offensive operator. They orchestrated this operator via Telegram for the following activities: Independently enumerating targets and their vulnerabilities using FOFA Sourcing exploit tools Initiating attacks without human intervention In parallel with their use of DeepSeek as their autonomous operator platform, the actor configured multiple large language models (LLMs) (Qwen, GLM, Kimi, MiniMax). We also identified limited usage and testing of Western platforms. This includes Claude Code for connectivity testing and proxy validation. There were also signs of usage of Codex on exploit development directories. This limited usage is consistent with evaluating the AI-market to identify their preferred tool set. When initial exploitation failed due to the target environment's restrictive configurations, their Hermes Agent autonomously conducted searches for known critical-severity Common Vulnerabilities and Exposures (CVEs). It initially surveyed 10 product families, scanning GitHub for trending proofs of concept (PoCs) and prioritizing vulnerabilities by attack surface. This research led the agent to pivot to higher-value vulnerabilities, the seven covered in Table 2 below. While the observed campaign had limited impacts, the workflow confirms a functional, end-to-end autonomous offensive capability. Palo Alto Networks customers are better protected from the threats described here through the following products and services: The Unit 42 AI Security Assessment and Unit 42 Frontier AI Defense service can help identify and mitigate complex AI-enabled risks. If you think you might have been compromised or have an urgent matter, contact the Unit 42 Incident Response team. We gained unique insights into this autonomous attack capability when the autonomous agent inadvertently exposed its infrastructure by starting a file server in its home directory. This revealed the full operational environment to our threat researchers. This visibility enabled us to understand their full tool set, how the attackers orchestrated multiple AI platforms and gave us a peek into their targeting. Based on our analysis of their session logs and configuration files, the actor primarily used the Hermes Agent with DeepSeek as its reasoning agent for the attack phase of this campaign. Their Hermes Agent conducted autonomous vulnerability enumeration, downloaded public exploit code from the internet and attempted exploits against targets. Additionally, the threat actor leveraged the following tools in a limited capacity, likely indicating an ongoing assessment of the AI market for their use cases: Claude Code: The actor only used this for connectivity testing and proxy validation. Session history (10 entries across three sessions) contained only /model checks, connectivity tests and one npm install request. Codex: There were signs of usage on exploit development directories, but the chat logs were not preserved. The actor marked their exploit development directories as trusted, granting full access to read, modify and execute code. Although we cannot verify actual usage because the actor configured their system to limit local response storage (disable_response_storage = true), the correlation between trusted directories and successful campaigns is notable. Qwen Code: There was minimal usage by the actor, including two sessions total. They configured multiple large language models (LLMs) (Qwen, GLM, Kimi, MiniMax), consistent with evaluating Chinese-market AI models. The actor configured four AI coding tools to remove client-side execution permissions. Note, this does not impact server-side controls for vendor-hosted platforms. They routed the two Western tools, Claude Code and Codex, through a third-party proxy service (code.newcli[.]com) to reduce traceability. The actor accessed DeepSeek and Qwen directly through their native API endpoints. The actor enabled anti-attribution settings on both tools. The actor configured Claude Code with CLAUDE_CODE_ATTRIBUTION_HEADER: "0" and CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC: "1", while they set Codex to disable_response_storage = true to limit response storage. Unit 42 did not recover any Codex chat logs from the exposed server. Note: This setting does not impact the retention of logging or safety signals in OpenAI’s safety systems. Table 1 summarizes each tool's configuration. Table 1. AI tool configurations. DeepSeek, operating through the Hermes Agent framework, served as the actor's primary offensive AI tool. Hermes Agent provided orchestration (terminal access, Telegram-based command and control, and the skills system) while DeepSeek served as the reasoning engine for code generation, vulnerability assessment, target selection and decision-making. The actor had customized Hermes Agent with three red-teaming skills: godmode: LLM jailbreaking, framework-bundled web-terminal-exploitation: unauthenticated WebSocket exploitation, custom-created fofa-cyberspace-search: a custom procedure template instructing DeepSeek to use the actor's fofoapi.py script for internet asset enumeration The actor also integrated the open-source FofaMap-Platinum-Full-Expert Model Context Protocol (MCP) server, which exposes: FOFA asset search Nuclei scan generation A DeepSeek-powered natural-language-to-FOFA query translator directly within the agent We recovered the following sequence in Figure 1 from a single Hermes Agent session (May 7, 2026). We were unable to recover additional operator input beyond the initial task. DeepSeek identified a Langflow vulnerability (CVE-2026-33017, CVSS 9.8) and autonomously attempted exploitation through the following steps: Downloading the public PoC exploit from GitHub Enumerating 84 Langflow instances via FOFA (title="Langflow") Running the PoC scanner (langflow_poc.py --scan-file langflow_targets.txt --threads 10) Identifying one vulnerable target (Langflow 1.3.4) The exploitation attempts failed because the vulnerability requires either auto_login enabled or a public flow ID and the target had neither. DeepSeek assessed the entire product as a low-value target: After abandoning Langflow, DeepSeek conducted autonomous research to identify a higher-value vulnerability. It surveyed deployment counts across 10 product families via FOFA, and then searched GitHub for trending 2026 CVE PoC repositories sorted by stars. DeepSeek evaluated each candidate by severity, deployment footprint and exploitability before selecting n8n: FOFA confirmed n8n as a high-value target: 647,017 instances globally; 25,209 in China. DeepSeek obtained the public n8n exploit PoC from the Chocapikk repository. The PoC chains two CVEs into an attack sequence requiring an unauthenticated form with file upload: CVE-2026-21858 (arbitrary file read, CVSS 10.0) CVE-2025-68613 (sandbox bypass to remote code execution (RCE), CVSS 9.9) The following are advisories from n8n: CVE-2026-21858 (patched in 1.121.0) CVE-2025-68613 (patched in 1.120.4) DeepSeek analyzed affected version ranges to identify exploitable targets: DeepSeek ran FOFA queries targeting Chinese n8n instances and probed targets for version and form endpoints. Three instances were confirmed to be running vulnerable versions (v1.18.0, v1.117.3, v1.108.2). One target exposed three form endpoints, but all required authentication: DeepSeek launched parallel scanning across 50-plus remaining Chinese targets. None had publicly accessible forms. The actor did not achieve exploitation. The recovered session data ends at this point. Separate from the autonomous AI campaigns, the actor conducted manual operations using conventional workflows (FOFA enumeration, custom Python scanners and direct exploitation) with confirmed impact. These included: Data exfiltration from three organizations via a Citrix NetScaler vulnerability (CVE-2026-3055) Command execution on 11 Marimo notebook instances (CVE-2026-39987) Java deserialization reverse shell attempts against nine Apache Tomcat servers (CVE-2026-34486) Reverse shell callbacks targeting three IKE VPN endpoints (CVE-2026-33824). Hermes Agent, responding to a Telegram command, started an HTTP file server (python3 -m http.server 8888) from the actor's home directory (/home/worker) rather than an isolated staging directory. This exposed the actor's entire workspace: AI tool configurations API keys Exploit scripts Target lists Bash history Hermes autonomous exploitation session logs The exposure was unintentional. The actor demonstrated operational security awareness elsewhere, having emptied exploit directories after use and disabled Codex conversation logging. The threat actor maintained active exploit tooling for seven vulnerabilities. The threat actor likely retrieved the tooling manually or they downloaded it from public repositories via the Hermes Agent during the autonomous scan -> download -> exploit cycles. Table 2 summarizes each vulnerability and the actor's method of engagement. Table 2. CVEs exploited or staged by the threat actor. The actor cloned a public repository (qassam-315/PAN-OS-User-ID-Buffer-Overflow-PoC) for CVE-2026-0300, a buffer overflow vulnerability in the PAN-OS User-ID Authentication Portal (Captive Portal). The cloned code is non-functional with placeholder values that cannot achieve code execution. No evidence of modification or execution was found. From our analysis and visibility, we identified that this actor attempted to exploit over 460 targets, leveraging a mix of autonomous and manual techniques. What’s interesting is that the actor appeared to allow DeepSeek to narrow the targeting scope, likely to conserve AI compute. For example, DeepSeek sampled approximately 100 IP addresses out of the 25,209 Chinese systems that FOFA scans identified with exposed n8n instances. Of those 100 systems, it probed roughly 40 unique IP addresses, checking their version via curl commands. While most of the systems were unreachable or non-responsive, DeepSeek found three with the vulnerable versions and attempted to exploit them automatically. This autonomous process of target identification, sampling and narrowing of scope is notable because the system executed hundreds of hours of manual targeting analysis in mere minutes, while also managing its own compute resources. Across all the exploitation attempts, both autonomous and manual, Unit 42 confirmed data exfiltration from three Citrix NetScaler targets (CVE-2026-3055) and command execution on 11 Marimo notebook endpoints (CVE-2026-39987). However, we reviewed evidence of batch exploitation against an unknown number of hosts that were listed in a file deleted by the actor prior to our analysis. The three successful exploitations had memory data exfiltrated through the Citrix NetScaler out-of-bounds memory read vulnerability (CVE-2026-3055). The actor searched the exfiltrated data for NetScaler authentication cookies (NSC_AAAC=), indicating session hijacking intent. The actor persistently targeted a government entity in Malaysia and they exploited it over multiple days with memory grooming parameters and maximum read attempts. The actor returned with proxy anonymization on subsequent attempts. The Chinese-speaking actor is based in Zhuhai, China, and operates as an opportunistic exploit operator and self-described binary security researcher. This assessment is supported by the actor’s GitHub activity, specifically their maintenance of 1DayNews, an automated vulnerability intelligence pipeline. This tool: Aggregates RCE disclosures from 17 sources (primarily network perimeter vendors) Leverages DeepSeek to filter for exploitability Distributes actionable alerts via Telegram The actor's broader activity is opportunistic, with confirmed victims spanning three countries and multiple sectors. The autonomous AI campaigns targeted Chinese domestic infrastructure indiscriminately. In contrast, the manual campaign against the Malaysian target demonstrated higher intent, including refined exploitation parameters and proxy anonymization sustained over multiple days. Our findings document a threat actor developing AI-augmented offensive capabilities that enabled them to dramatically increase the speed and scale of their campaigns. This research validates an emerging threat posed by AI-enabled attackers as they hone their autonomous attack processes to discover, assess, pivot and retarget without human intervention. Although these autonomous campaigns did not achieve full compromise of any of their intended targets, the findings carry several implications for defenders. Autonomous AI-driven attack cycles are operationally viable, and the margin of failure was narrow: Exploitation was prevented by target-side configuration requirements — the absence of prerequisite workflow configurations (Langflow) and authentication on form endpoints (n8n). Targets with weaker default configurations would have been susceptible. Threat actors are constructing persistent AI offensive infrastructure: Rather than using AI tools in isolation, this actor assembled an integrated environment — custom automation skills, MCP server integration, proxy anonymization, and Telegram-based command and control — designed to retain and reuse successful procedures across sessions. Threat actors follow the path of least resistance: For their autonomous attack engine, the actor selected a model with minimal safety controls (DeepSeek) accessed through an open-source framework with no client-side restrictions. The actor attempted to use Western models, but their provider-side controls likely limited their effectiveness for autonomous attacks. This likely led the actor to select the most permissive model for their campaign. Note: Our colleagues at OpenAI were able to confirm that their provider-side safeguards refused requests that violated their policies. They also confirmed that continued attempts led their safety systems to flag and disable an account they believe is linked to this campaign prior to our intelligence sharing with their team. Autonomous AI execution introduces novel operational security risks for threat actors: The same autonomous capability the actor developed for offensive use directly caused the exposure of the operation, producing forensic artifacts that would not have existed under manual execution. The significance of these findings lies in the trajectory rather than the outcome of any individual campaign. The actor is actively iterating — refining tool configurations, developing custom skills, establishing proxy infrastructure and executing autonomous attack cycles. The technical barrier to AI-augmented offensive operations is low and continues to decrease. Palo Alto Networks customers are better protected from the threats discussed above through the following products: To combat an attack in which an attacker takes advantage of software exploits or vulnerabilities, Cortex XDR employs Endpoint Protection Modules (EPM). Each EPM targets a specific exploit type in the attack chain. In addition, Cortex XDR and XSIAM help protect against post-exploitation activities using a multi-layer approach. This approach combines several layers of protection, including Advanced WildFire, Behavioral Threat Protection and the Local Analysis module, to prevent both known and unknown malware from causing harm to endpoints. Cortex Xpanse has the ability to identify exposed Langlow, n8n and Citrix ADC/Netscaler devices on the public internet and escalate these findings to defenders. Customers can enable alerting on this risk by ensuring that these attack surface rules are enabled. Identified findings can be viewed in the incident view of Expander. These findings are also available for Cortex XSIAM/XDR/Cloud customers with the ASM license. Next-Generation Firewall with the Advanced Threat Prevention security subscription can help block the attacks with best practices via the following Threat Prevention signatures 97030, 96882, 96855, 97044, 97046, 97251, 97177, and 510019. The Unit 42 AI Security Assessment and Unit 42 Frontier AI Defense service can help identify and mitigate complex AI-enabled risks. If you think you may have been compromised or have an urgent matter, get in touch with the Unit 42 Incident Response team or call: North America: Toll Free: +1 (866) 486-4842 (866.4.UNIT42) UK: +44.20.3743.3660 Europe and Middle East: +31.20.299.3130 Asia: +65.6983.8730 Japan: +81.50.1790.0200 Australia: +61.2.4062.7950 India: 000 800 050 45107 South Korea: +82.080.467.8774 Palo Alto Networks has shared these findings with our fellow Cyber Threat Alliance (CTA) members. CTA members use this intelligence to rapidly deploy protections to their customers and to systematically disrupt malicious cyber actors. Learn more about the Cyber Threat Alliance. NousResearch Hermes Agent — GitHub Chocapikk CVE-2026-21858 (n8n Ni8mare) — GitHub oscar-mine CVE-2026-33017 Exploit (Langflow) — GitHub qassam-315 PAN-OS CVE-2026-0300 Research — GitHub asaotomo FofaMap (Hx0 Team) — GitHub How n8n Handles Vulnerability Disclosure - and Why We Do It This Way — n8n.io
unit42.paloaltonetworks.comJul 30, 2026extracted
NCSC-2026-0256 [1.00] [M/H] Kwetsbaarheden verholpen in Oracle Communications
Oracle heeft kwetsbaarheden verholpen in Communications producten en onderliggende third party software. Het betreft een totaal van 213 kwetsbaarheden, waarvan 67 zich bevinden in Oracle producten en 146 in third-party producten waar eerder updates voor zijn verschenen en welke in deze Oracle updates zijn verwerkt. De ernstigste kwetsbaarheden, 12 stuks, hebben een CVSS score van 9 en hoger gekregen en zijn hieronder omschreven. 11 hiervan bevinden zich in embedded third-party producten. De overige kwetsbaarheden hebben lagere scores gekregen en het voert te ver om detailinformatie op te nemen in deze advisory. Hiervoor verwijst het NCSC naar de bijgevoegde referentie. Oracle Communications Converged Application Server versies 8.2 en 8.3 bevatten een kwetsbaarheid die onbevoegde netwerktoegang mogelijk maakt en kan leiden tot volledige overname van het systeem. Libtiff tot versie 4.7.0 bevat een write-what-where kwetsbaarheid en een stack-based buffer overflow die kunnen worden geactiveerd door speciaal vervaardigde TIFF-bestanden, wat kan leiden tot code-executie of crashes. Apache Tomcat versies 8.5.0 tot 11.0.5 bevatten kwetsbaarheden waardoor speciaal opgemaakte HTTP-verzoeken rewrite rules en security constraints kunnen omzeilen, met mogelijke data disclosure, wijziging of denial of service als gevolg. Eclipse Jetty's HTTP/1.1 parser verwerkt chunked transfer encoding extensies met onjuist gesloten aanhalingstekens verkeerd, wat request smuggling mogelijk maakt en kan leiden tot cache poisoning, access control bypass en sessie kaping. Perl versies met een verouderde vendored zlib in Compress::Raw::Zlib bevatten meerdere beveiligingsproblemen die zijn opgelost in een specifieke commit. Lodash versies tot 4.17.23 bevatten meerdere kwetsbaarheden waaronder code-injectie via onbetrouwbare keys in _.template, prototype pollution, regex denial of service en command injection. Apache HTTP Server versies 2.4.0 tot 2.4.67 bevatten diverse kwetsbaarheden in meerdere modules die kunnen leiden tot server crashes, code-executie, cross-site scripting en informatielekken. Apache Kafka versies 4.1.0 en 4.1.1 hebben een kwetsbaarheid in de JWT token validatie waardoor onbevoegde toegang mogelijk is. AIOHTTP versies voor 3.13.4 accepteren null bytes en control characters in HTTP headers, wat header injectie en response splitting mogelijk maakt. De cryptography package van versies 45.0.0 tot 46.0.7 bevat een buffer overflow bij het verwerken van niet-contigu buffers op Python 3.11+, wat kan leiden tot crashes of informatielekken. Spring Boot versies 4.0.0 tot 4.0.5 bevatten een kwetsbaarheid die het mogelijk maakt om de standaard web security te omzeilen. Apache MINA versies 2.1.X en 2.2.X bevatten meerdere deserialisatie kwetsbaarheden die code-executie mogelijk maken door bypass van classname allowlist en filters.
advisories.ncsc.nlJul 22, 2026extracted
⚡ Weekly Recap: WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and More
A single request should not be able to do this much. But this week, small inputs led to code execution, memory loss, stolen keys, and disabled security tools. The paths were often simple: exposed systems, weak checks, old drivers, fake prompts, and public code used for malware delivery. Some bugs were new. Others were already being used before defenders had time to patch. Here is the full recap of what broke, what was exploited, and what needs attention now. ⚡ Threat of the Week New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code - Searchlight Cyber disclosed a pre-authenticated remote code execution vulnerability in WordPress Core that can be exploited anonymously on a standard WordPress installation, without requiring any plugins or other special conditions. It is a combination of CVE-2026-63030 (REST API batch-route confusion) and CVE-2026-60137 (SQL injection in WordPress core) that can be chained to turn an anonymous request into code execution. watchTowr said it's already seeing proof-of-concept (PoC) exploits in circulation and that it's beginning to see the first signs of in-the-wild exploitation. "This is going to hurt," watchTowr CEO Benjamin Harris said. "WordPress runs on hundreds of millions of websites globally. Some of those will be auto-patched by their hosting providers, but plenty will not, and that is where the damage will be done. Our advice is simple: patch as fast as you possibly can, and do not stop there. Put the controls and investigations in place to determine whether an attacker got there first and to detect and remove any backdoors that may already have been dropped before you patched." The cybersecurity company said it's the latest example of vulnerabilities being surfaced by AI-assisted tooling and how the technology is being abused by attackers to weaponize them. AI Broke Vulnerability Management. Here Is the CISO Case The AI security job market is no longer theoretical. SANS tracked hiring across 10 specific roles and mapped verified job data, salary ranges, and the skills required to get there. The three-tier framework gives your team a clear view of which roles to prioritize now and which to develop toward. Download Now ➝ 🔔 Top News SonicWall SMA Zero-Days Exploited as 0-Days - A previously undocumented threat actor codenamed UTA0533 has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior to their public disclosure since June 22, 2026. The discovery was made following an incident response investigation initiated earlier this month. The impacted organization has not been identified. "This threat actor was observed using multiple zero-day exploits, malware designed specifically for SonicWall SMA VPN appliances, as well as other attacker tradecraft," Volexity said. The vulnerabilities in question are CVE-2026-15409 (CVSS score: 10.0) and CVE-2026-15410 (CVSS score: 7.2), both of which could be chained to facilitate arbitrary command execution and take over susceptible devices. Patches for both vulnerabilities were released by SonicWall last week. DoS Flaw in OpenSSL - The Okta Red Team disclosed details of HollowByte, a denial-of-service (DoS) flaw in OpenSSL. "By sending a malicious payload of just 11 bytes, a remote, unauthenticated attacker can force a server to allocate disproportionate chunks of memory before any security handshake even begins," Okta said. Put differently, an unauthenticated attacker -- through 11 bytes of carefully crafted data -- can convince OpenSSL to reserve up to 128 KB of heap memory for a handshake message that never actually arrives, causing a server to exhaust available RAM and trigger a DoS condition. The OpenSSL team resolved the issue in versions 4.0.1, 3.6.3, 3.5.7, 3.4.6, and 3.0.21. "Instead of trusting the header outright, OpenSSL now grows the buffer only as bytes actually land on the wire. A claim with no follow-through now costs the server nothing," Okta said. CISA Adds New SharePoint RCE Zero-Day to KEV Catalog - The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by July 19, 2026. The vulnerability, CVE-2026-58644 (CVSS score: 9.8), is a critical deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute arbitrary code. Patches for the flaw have been released as part of the Patch Tuesday updates released on July 14, 2026. Microsoft revised its bulletin to clarify that CVE-2026-58644 has been exploited in the wild, meaning the shortcoming was weaponized as a zero-day prior to the fixes becoming available. The development came as Microsoft shipped its largest Patch Tuesday on record, addressing 622 vulnerabilities. OkoBot Malware Framework Infects Windows to Phish Crypto Seed Phrases - A new malware framework called OkoBot is designed to capture the contents of cryptocurrency wallet windows. OkoBot is an updated version of TookPS, which is a downloader for retrieving malicious commands and scripts from attacker-controlled servers to further propagate attacks, including a Python-based infostealer and a remote access trojan called TeviRAT. "This campaign differs from previous activity in that it uses a new framework to deliver all malicious modules and orchestrate them via an SSH tunnel," Kaspersky said. "In total, the framework includes more than 20 malicious payloads and implants, covering a wide variety of functions. At the time of writing, the threat remains active." The infection chain makes use of ClickFix and malware distributed through GitHub that masquerades as legitimate software for initial access. It also comes with a web browser extensions loader to deliver Rilide, a browser-based stealer, as well as inject an implant into Trezor Suite, Ledger Wallet, and Ledger Live processes to collect seed phrases, log keystrokes and clipboard content, take screenshots, and capture keystrokes and the video stream of the target application's window using the OkoSpyware module. Hundreds of victims of the OkoBot campaign have been detected in more than 25 countries, with the highest concentration in Brazil, Vietnam, Canada, Mexico, and Türkiye. The activity remains unattributed. NadMesh Scans Exposed AI Services for Cloud Keys and Kubernetes Tokens - A new Go botnet called NadMesh has been observed hunting for exposed AI services related to ComfyUI, Ollama, n8n, Open WebUI, Langflow, and Gradio to steal AWS keys and Kubernetes tokens. "It folds scanning, exploitation, and credential/AI-service intelligence harvesting into a single autonomous platform," QiAnXin XLab said. "On the victim, the bot agent establishes persistence along three independent paths: an SSH public-key backdoor (.ssh/authorized_keys), persistence files in multiple locations (/dev/shm/.a, /var/tmp/.a, /tmp/.a), and hidden cron watchdogs (/etc/cron.d/.sys_monitor, /etc/cron.d/.s)." ️🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first - CVE-2026-63030, CVE-2026-60137 (WordPress Core), CVE-2026-58644, CVE-2026-56164 (Microsoft SharePoint Server), CVE-2026-56155 (Microsoft Active Directory Federation Services), CVE-2026-53412 (Zoom Desktop Client for Windows and Zoom VDI Client for Windows), CVE-2026-44747, CVE-2026-27690, CVE-2026-44761 (SAP), CVE-2026-57219, CVE-2026-57221 (RabbitMQ), CVE-2026-59208, CVE-2026-54305 (n8n), CVE-2026-60105 (Monsta FTP), CVE-2026-14960, CVE-2026-14961 (tdeio64.sys driver), CVE-2026-33894, CVE-2026-33895 (Digital Bazaar node-forge), CVE-2026-6875 (ServiceNow AI Platform), CVE-2026-42533, CVE-2026-60005, CVE-2026-56434 (F5 NGINX Plus and NGINX Open Source), CVE-2026-20296, CVE-2026-20297 (Splunk Enterprise), CVE-2026-15265 (Tenable Agent), CVE-2026-6423 (ESET Inspect Connector), CVE-2026-15053 (Tanium Server), CVE-2026-44909, CVE-2026-59173, CVE-2026-59762 (HTTP/2 server implementations), CVE-2026-14890 (SGLang), CVE-2026-14266 (7-Zip), CVE-2026-59084 (Apache Tomcat), CVE-2026-15682 (AnyDesk), and CVE-2026-54523 (Kyverno). 🎥 Cybersecurity Webinars Your AI Agent Has Credentials. Can You Stop It When It Goes Rogue? Hands-on testing of OpenClaw shows how agentic AI can expose secrets, bypass safety controls, and create a powerful new attack surface. Join Okta Threat Intelligence Director Jeremy Kirk to examine how attackers are abusing AI agents and learn practical ways to control access, enforce least privilege, detect shadow AI, and shut down risky agents before they cause damage. When AI Ships 50× More Code, Human Review Stops Scaling → AI-assisted development is pushing code production beyond what traditional security reviews and CVE-driven remediation can handle. This webinar gives security leaders a practical framework for governing the expanding attack surface, building secure-by-default controls, and enabling teams to develop at machine speed without surrendering control of software risk. 📰 Around the Cyber World New Campaign Delivers Remcos RAT - A new malware distribution campaign has abused the credibility of government institutions to increase the likelihood of infection success. The activity targets Indian businesses and taxpayers using Goods and Services Tax (GST)-related themes to distribute malware. "The threat actors impersonated legitimate government departments and distributed malicious emails disguised as official notifications related to taxation, refunds, compliance requirements, and regulatory matters," Seqrite Labs said. "The threat actors employ convincing documents and filenames that closely resemble official GST notifications, making it difficult for recipients to distinguish malicious content from legitimate government correspondence." The end goal is to deploy Remcos RAT and steal sensitive information. India's Kudankulam Nuclear Power Plant Suffers a Data Leak - The Kudankulam Nuclear Power Plant located in the Indian state of Tamil Nadu suffered an accidental exposure after Reliance Infra (RPOWER) got hit by a ransomware group called World Leaks, a spin-off of Hunters International, which, in turn, is another variant of the Hive ransomware family. The leak consists of 18,997 files, totalling 14.3GB of data, per security researcher Rakesh Krishnan. They contain purported blueprints for the ventilation and cooling systems used in Unit 3 and Unit 4, along with a complete floor layout of a "common control room". It's assessed that Reliance Infra was not impacted directly, but rather through a third-party vendor named Yotta. In a statement shared on X, the Nuclear Power Corporation of India Limited said: "The scope of the contract includes Engineering, Procurement/supply, Construction and Commissioning of Common service facilities. These facilities are of conventional nature and are typically found in thermal power plants as well as other process industries. They are not related to nuclear safety or nuclear security systems." It also noted that "the information claimed to be available in the public domain pertains only to conventional Balance of Plant (BoP) common service facilities and does not relate to any nuclear safety - or nuclear security-related systems or information." Blind Eagle Shows No Signs of Stopping - Nearly a year after Blind Eagle's activities were documented, a new report from LevelBlue has found the threat actor to be active, moving part of its VBScript delivery infrastructure onto the Russian bulletproof hosting provider Proton66 as of June 2025. The group has also devised a bespoke string-obfuscation scheme, a RunPE loader built entirely on a bare AutoIt3 interpreter, and an upgraded version of AsyncRAT that introduces Windows Notification Facility (WNF) process injection, a custom Base28 payload encoding, a full Hidden VNC (HVNC) banking-fraud module with browser profile cloning, and a Chrome App-Bound Encryption (ABE) bypass, per LevelBlue. Qilin Ransomware Use of EDR Killer - Qilin ransomware operations have been observed adopting aggressive, kernel-level defense evasion to blind and disable endpoint security products before its main ransomware payload is executed on a victim's network. The EDR killer, packed via the Shanya packer, is sold on illicit marketplaces for $2,000. "The EDR killer compares the returned locale to a known locale blacklist to avoid attacking any Commonwealth of Independent States (CIS) countries such as Russia and Belarus," Flashpoint said. "The EDR killer then writes a vulnerable driver to disk and loads this driver via Service Manager. This driver is the ThrottleStop driver from TechPowerUp LLC's free and legitimate application of the same name, used to bypass CPU throttling. However, the driver suffers from a vulnerability, allowing the malware to map physical memory to kernel-mode virtual memory to perform direct kernel read and write operations." Also put to use is a custom Rust-written loader that performs reflective Portable Executable (PE) loading of the ransomware payload. DefiTuna Suffers a Security Incident - DeFiTuna, an Automated Market Maker (AMM) on the Solana blockchain, was exploited on July 16, 2026, for $569,601 USDC. "The attackers created a highly illiquid TUNA/USDC pool and used it as the destination for borrowed USDC routed through Jupiter," CertiK said. "Because the swap returned only a negligible amount of TUNA, DeFiTuna's value calculation rounded the position's total assets down to zero. The protocol then incorrectly treated the position as healthy, allowing the attackers to bypass the solvency check and withdraw the USDC through attacker-controlled liquidity positions." Next.js Opts for Scheduled Security Releases - Vercel announced that Next.js is adopting a formal security release program, replacing ad-hoc patches for security fixes following a surge in AI-assisted vulnerability discovery. "This kind of scheduled, pre-announced security release has become standard practice for major open source projects, and we think it's the right model for Next.js at its current scale," Vercel said. "Here's what you can expect going forward: roughly once a month, we'll publish advance notice of upcoming security releases. Each announcement will include the expected release timeline and the highest anticipated severity among the vulnerabilities it covers. This lead time lets you plan your upgrades, and it lets us coordinate with hosting providers and other platform partners to deploy mitigations, such as firewall rules, that help protect applications that haven't been patched yet." Disguised Gambling Apps Target Brazil - A new analysis from 9to5Mac has revealed more than 60 "jacket apps" on the App Store that are disguised as simple games and utilities that become online betting platforms when accessed from Brazilian IP addresses. Most of the apps are published by developer accounts with only a single App Store listing, with further investigation linking them to a "public GitHub repository containing instructions for a Cursor agent to create simple, vibe-coded apps that serve as fronts for the betting platforms." Ransomware Stats for Q2 2026 - The Gentlemen has become the most active ransomware group for Q2 2026, claiming 300 victims, surging past Qilin (289), DragonForce, Akira, and LockBit. Another group named Deadlock resurfaced after 11 months of silence with 75 June victims. In all, the top 11 tracked groups accounted for 1,368 of Q2's victim claims across 99 countries. "What sets The Gentlemen apart is its packaging, where affiliates receive ready-made tools that ship and update faster than most competing programs," ReliaQuest said. 2 Members of Chinese Money Laundering Network Charged with Laundering $43M in Investment Fraud - The U.S. Justice Department unsealed charges against a New York man and woman for conspiracy to launder money derived from cyber investment fraud scams. "Between 2020 and 2022, Zhuoying Chen, 27, of Brooklyn, New York, and Haojie Zhang, 38, of Queens, New York, managed a network of more than a dozen individuals based in Queens and Brooklyn, who opened 140 bank accounts in the name of approximately 45 shell companies to launder at least $43 million in proceeds of investment scams," the department said. "Then, Chen and Zhang allegedly conspired with China-based co-conspirators to transfer the funds involved in the fraud schemes abroad. The fraud schemes consist of perpetrators contacting victims via messaging services or social media applications. The perpetrators would initiate relationships with the victims and gain their trust, convincing victims to send money for lucrative investment opportunities. The perpetrators would show the victims fake profits on the purported investment and encourage the victims to invest more. The perpetrators would then steal the victim's funds." U.S. Cyber Agency Uses Mythos to Audit Government Code - Reuters reported that the U.S. Cybersecurity and Infrastructure Security Agency (CISA) is using Anthropic's AI model Mythos to audit government software for defects that could potentially offer a pathway for foreign spies and cybercriminals, citing three people familiar with the matter. 🔧 Cybersecurity Tools VisionSec → It is an open-source, self-hosted threat intelligence platform that combines domain monitoring, phishing detection, exposed-service scanning, GitHub secret discovery, breach checks, email security assessments, and Telegram alerts in a modular Docker-based deployment. The project remains at an early stage, with no published releases at the time of writing. owLSM → It is an open-source Linux security agent that uses eBPF LSM to run stateful Sigma rules inside the kernel, block malicious activity, correlate events across multiple probes, and provide detailed context for security monitoring and response. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you're doing stays on the right side of the law. Conclusion That is the week: exposed systems, weak checks, old tools, and attackers moving faster than patch cycles. Review what applies, fix the obvious gaps first, and assume anything public has already been tested.
thehackernews.comJul 20, 2026extracted
NCSC-2026-0230 [1.00] [M/H] Kwetsbaarheden verholpen in SAP-producten
SAP heeft kwetsbaarheden verholpen in SAP NetWeaver Application Server ABAP, SAP Approuter, SAP Commerce Cloud, SAP NetWeaver Application Server Java, SAProuter, SAP Change and Transport System Attach Tool, SAP NetWeaver Enterprise Portal, SAP S/4HANA modules, SAP Fiori Launchpad, SAP CRM WebClient UI, SAP HANA Database user self service tools, en SAP Commerce Cloud. De kwetsbaarheden betreffen diverse beveiligingsproblemen zoals: geheugenbeschadiging in SAP NetWeaver Application Server ABAP HTTP Request Smuggling in SAP Approuter onveilige OAuth2-sample credentials in SAP Commerce Cloud directory traversal in SAP NetWeaver Application Server Java DLL hijacking in SAProuter op Windows. Verder zijn er Cross-Site Scripting (XSS) kwetsbaarheden in SAP NetWeaver Application Server Java en Enterprise Portal en ontbrekende autorisatiecontroles in SAP S/4HANA modules. SAP Change and Transport System Attach Tool is kwetsbaar voor remote code execution door onveilige deserialisatie. SAP HANA user self service tools maken informatieoverdracht mogelijk zonder authenticatie. De kwetsbaarheden kunnen leiden tot ongeautoriseerde toegang, manipulatie van data, informatielekken, en verstoring van de beschikbaarheid. Sommige kwetsbaarheden vereisen authenticatie, andere kunnen door onbevoegden worden misbruikt. Diverse kwetsbaarheden zijn specifiek voor componenten die binnen SAP-omgevingen worden gebruikt, zoals Apache Camel binnen de SAP Integration Suite en Apache Tomcat binnen SAP Commerce Cloud.
advisories.ncsc.nlJul 14, 2026extracted
SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud
Enterprise software maker SAP on Tuesday announced the release of 20 new and updated security notes as part of its July 2026 security patch day. The most severe of the resolved vulnerabilities is CVE-2026-44747 (CVSS score of 9.9), a memory corruption bug in NetWeaver Application Server ABAP. Successful exploitation of the security defect could allow an attacker to access and modify data, and cause system unavailability, SAP security firm Onapsis explains. SAP customers are strongly advised to apply the fresh patches to resolve the flaw, but can also “disable all ICF nodes with a specific property in transaction SICF” as a temporary workaround. The second security note released on SAP’s July 2026 security patch day fixes a critical HTTP request smuggling issue in Approuter, tracked as CVE-2026-27690 (CVSS score of 9.1). “The vulnerability affects SAP Approuter deployments in non-Cloud Foundry environments and allows an unauthenticated attacker to send a specially crafted HTTP request that leads to request-response desynchronization,” Onapsis says. Another critical-severity vulnerability was addressed in Commerce Cloud. Tracked as CVE-2026-44761 (CVSS score of 9.1), it is described as a hardcoded credential issue and could lead to unauthorized data access and modification. The bug is related to sample configuration scripts that were previously provided in the SAP Help Portal for development and testing, and which configure OAuth2 clients with known credentials. An unauthenticated attacker could abuse these credentials to obtain an access token that allows them to invoke specific APIs. This enables the attacker to read and tamper with system data. “Exploitation requires that the customer execute the sample script and retain the resulting OAuth2 client in production without replacing the hardcoded secret. Customers who removed the sample client or replaced the secret with a strong, unique value are not affected,” Onapsis notes. Older SAP documentation for Commerce Cloud did not warn customers against importing the default settings into production. The note addresses the lapse, but customers are advised to audit their production environments for the presence of the hardcoded credentials in sample OAuth2 clients. On Tuesday, SAP also updated a security note addressing a critical NetWeaver vulnerability initially patched in June, to provide support for additional packages. Additionally, the company released six security notes that address high-severity security defects across Integration Suite (Edge Integration Cell), SAProuter, NetWeaver Application Server Java (Configuration Wizard), Approuter, Commerce Cloud, and Change and Transport System Attach Tool (ctsattach). The notes for Integration Suite and Commerce Cloud contain patches for multiple Apache Camel and Apache Tomcat security bugs. The remaining new and updated notes released on SAP’s July 2026 security patch day address medium- and low-severity flaws across NetWeaver, S/4HANA, Fiori, CRM, and HANA Extended Application Services Classic Model. Related: RabbitMQ Vulnerability Threatens Enterprise Systems Related: Zimbra Patches Critical Code Execution Vulnerability Related: SAP Patches Critical NetWeaver, Commerce Vulnerabilities Related: SAP Patches Critical S/4HANA, Commerce Vulnerabilities
securityweek.comJul 14, 2026extracted
⚡ Weekly Recap: Proxy Botnets, Browser Ransomware, AI Agent Tricks, Fake PoC Malware and More
A streaming box should not need a threat model. Neither should a username field, a demo repo, a reset flow, or a browser permission prompt. That is the irritating part this week: the risky pieces were ordinary. Home devices became a routing cover. Clean code pulled dirt from a dependency. Identity shortcuts aged badly. AI systems trusted the wrong instructions. Same soft spot throughout: trust placed one layer too early. Below is the full recap, since this is apparently what counted as a normal week. ⚡ Threat of the Week NetNut Residential Proxy Network Disrupted — Google, in collaboration with the U.S. Federal Bureau of Investigation (FBI), Lumen, and other partners, took action against the NetNut residential proxy network, also known as Popa, building upon its takedown of IPIDEA in January 2026. Google said it disabled Google accounts and associated Google services used by NetNut for malware command-and-control (C2) and updated Google Play Protect, in addition to disabling applications known to incorporate NetNut SDKs. The size of the network is estimated to be at least 2 million devices globally. "NetNut populates its botnet by distributing SDKs for devices commonly found in homes, such as smart TVs and streaming boxes," Google said, adding it "identified NetNut botnet plugin components for large-scale botnets such as BADBOX 2.0." The end goal is to leverage the route traffic through these devices, allowing bad actors to mask malicious activity. The devices are pre-installed with malware before purchase or because users unknowingly download applications containing hidden proxy code. Case Study: How 1Password Secured Canva's Path to 260M Users When Canva 5xed their headcount across 8 countries, they needed security that could scale as fast as their business. See how 1Password helped them onboard teams in minutes, eliminate secret sprawl, and keep engineering moving. Learn More ➝ 🔔 Top News WhatsApp Gets Usernames But Impersonation Concerns Are Raised — WhatsApp officially announced the start of global reservations of usernames with an aim to protect the privacy of more than three billion users on the messaging platform. The optional feature is designed to help users connect with someone on the service through usernames, as opposed to directly sharing their phone numbers. The feature is expected to be generally available later this year. The rollout marks a shift in how people identify one another on the messaging app. It has also drawn scrutiny in India, its largest market, over concerns it could be abused to impersonate public authorities, financial institutions, government departments, and other prominent figures. While Meta told TechCrunch it reserves usernames for public figures, government entities, and some of their variations so that only legitimate users can claim them, it's currently not clear how it decides which lookalike usernames get reserved and which don't. ChocoPoC RAT Targets Vulnerability Researchers with Fake PoC Exploit Repos — Security researchers on the lookout for Python-based proof-of-concept (PoC) repositories on GitHub claiming to exploit new CVEs are being tricked into executing malicious code that delivers ChocoPoC. While the PoC in itself looks clean, the actual malware sits inside a dependency named "skytext" pulled by the PoC. The malware is a full-featured trojan capable of harvesting passwords, cookies, autofill, and history from Chrome, Brave, Edge, and Firefox. It also captures text files, notes, local databases, shell history, network settings, and a list of running processes, as well as supports running arbitrary shell commands or Python code. 19-Year-Old Alleged Scattered Spider Suspect Extradited to the U.S. — Peter Stokes (aka Bouquet, Spencer, and Jordan), a 19-year-old man with dual U.S. and Estonian citizenship, was extradited from Finland to the U.S. to face criminal charges over his involvement in a criminal scheme in connection with the Scattered Spider hacking group. Finnish police arrested him in April 2026. Stokes and other Scattered Spider members are alleged to have breached an unspecified "luxury-jewelry retailer" in May 2025 and demanded an $8 million ransom in cryptocurrency. The company incurred at least $2 million in losses from business disruption, incident response, and recovery efforts. Stokes was involved in at least four Scattered Spider breaches, the Justice Department said. Stokes faces charges of fraud, conspiracy, and computer intrusion. Ousaban Banking Trojan Targets Spain and Portugal — A new Brazilian banking trojan called Ousaban has been observed using fake PDF documents containing a link to a malicious web page that scans the user's environment. "If they are in Spain or Portugal, the webpage downloads a VBS file to kickstart the next part of the attack," Fortinet said. "The final payload is an EXE file that is dropped onto the victim's computer and executed by the VBS script." Ousaban gets triggered when victims visit a banking site, at which point it captures screenshots and keystrokes, tampers with the clipboard, and enables remote control. AI-Generated Browser Ransomware Exploits Chromium File Access API — A new malware artifact generated using DeepSeek has constructed a novel attack path combining "unrealistic browser-malware concepts with a real browser capability" to turn it into a working ransomware technique that runs entirely inside the browser on Windows, Linux, macOS, and Android devices. The approach is limited to web browsers that expose the picker-based File System Access API. This includes Google Chrome and other Chromium-based browsers across Windows, macOS, ChromeOS, Linux, and Android. There is no evidence that the browser-native ransomware pattern has been abused in the wild. "What we are witnessing is a fundamental shift in how novel cyber attacks are born," Check Point said. "For the first time, we have evidence that an AI model can independently reason across legitimate platform features and surface a working attack technique that humans had only theorised about – without the attacker ever knowing the underlying API existed." 🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-48276, CVE-2026-48283, CVE-2026-48277, CVE-2026-48281, CVE-2026-48316, CVE-2026-48282, CVE-2026-48313, CVE-2026-48315 (Adobe ColdFusion), CVE-2026-48286 (Adobe Campaign Classic), CVE-2026-50548, CVE-2026-50549 (Cursor), CVE-2026-46242 aka Bad Epoll (Linux Kernel), CVE-2026-6682, CVE-2026-6687, CVE-2026-6688 (FatFs), CVE-2026-8037 (Progress Kemp LoadMaster), CVE-2026-28701, CVE-2026-33560, CVE-2026-31928 (Daktronics Controller Firmware), CVE-2026-41120 (Dell Wyse Management Suite), CVE-2026-41492 (Dgraph), CVE-2026-55047 (Anthropic Buffa), from CVE-2026-13774 through CVE-2026-13788 (Google Chrome), CVE-2026-48519, CVE-2026-48520, CVE-2026-7528, CVE-2026-7524 (Langflow), CVE-2026-3199 (Sonatype Nexus Repository), CVE-2026-12166, CVE-2026-12167, CVE-2026-12168 (Little Orbits GameFirst Anti-Cheat driver), CVE-2026-56141, CVE-2026-56142, CVE-2026-50242, CVE-2026-50242 (JetBrains), CVE-2026-20213, CVE-2026-20214, CVE-2026-20215, CVE-2026-20216, CVE-2026-20217, CVE-2026-20243, CVE-2026-20244 (ClamAV), CVE-2026-20191 (Cisco Catalyst Center), CVE-2026-53917, CVE-2026-54475, CVE-2026-49877 (Apache ActiveMQ), CVE‑2026‑13050, CVE‑2026‑13053, CVE‑2026‑13054, CVE-2026-13079 (WatchGuard Fireware OS), CVE-2026-45504 (Microsoft Exchange Server), CVE-2026-14191 (WinRAR), CVE-2026-44024, CVE-2026-44025 (Fluentd), CVE-2026-55957, CVE-2026-55956 (Apache Tomcat), CVE-2026-13136, CVE-2025-15660 (Synology MailPlus Server), CVE-2026-22678, CVE-2026-49102, CVE-2026-49103, CVE-2026-42210, CVE-2026-56022 (Webmin), from CVE-2026-12044 through CVE-2026-12050 (pgAdmin), CVE-2025-66273, CVE-2025-66279, CVE-2026-22893 (QNAP QTS, QuTS hero, QuTS cloud, and QVP), CVE-2026-11310, CVE-2026-11999, CVE-2026-6679, CVE-2026-55958, CVE-2026-55960, CVE-2026-55961 (wolfSSL), CVE-2026-48611 (phpBB), and CVE-2026-20896 (Gitea). 🎥 Cybersecurity Webinars AI Attacks Are Moving Faster Than Your Defenses → AI is helping attackers write better lures, change tactics faster, and run campaigns at a scale many security teams are not built to handle. This webinar breaks down how AI-powered threats like Mythos gain access, move through environments, and expose the limits of traditional network-based defenses—then shows how teams can reduce attack surface, stop lateral movement, and contain risky behavior before it turns into a major incident. Your AI Agents Need a Kill Switch → AI agents can do more than make mistakes—they can expose credentials, bypass controls, and become a new attack surface inside the business. This webinar uses hands-on findings from OpenClaw testing to show where agentic AI breaks down, why guardrails are not enough, and how teams can reduce risk with identity-based governance, least-privilege access, short-lived secrets, logging, auditing, and visibility into shadow AI use. 📰 Around the Cyber World Indirect Prompt Injection Attacks Targets AI Agents for Typosquatting and Payment Scam — Threat actors are using indirect prompt injection (IPI) to hide instructions in websites, attempting to trick an AI agent into following the attacker’s instructions. "The observed campaigns combine SEO poisoning with CSS/HTML abuse to both manipulate search results and conceal prompt-style instructions that influence AI decision making," Zscaler said. "When AI agents misclassify malicious websites as legitimate, they increase the risk of context contamination and downstream Retrieval-Augmented Generation (RAG) poisoning." Dropping Elephant Delivers In-Memory RAT — The threat actor known as Dropping Elephant (aka Patchwork) has been observed using a China-themed energy-sector contract lure to deliver a heavily reworked, in-memory remote access trojan (RAT). "This campaign demonstrates advanced evasion techniques, including DLL side-loading with a legitimate Microsoft binary (Fondue.exe) and the use of 'Donut' shellcode to map the RAT directly into memory, effectively bypassing traditional disk-based security controls," Rapid7 said. "The revamped RAT significantly complicates detection by using control-flow flattening, runtime API reconstruction, and hardened C2 communications." The malware supports directory listing, file upload/download, screenshot capture, and command execution capabilities. Microsoft Updates SSPR to Require Registered Authentication Methods — Starting September 7, 2026, Microsoft said Entra self-service password reset will require users to have explicitly registered authentication methods for password reset verification, while explicitly disallowing directory-sourced contact information unless registered. "Currently, SSPR may allow users to verify their identity using contact information stored in directory attributes such as mobile phone, business phone, and alternate email, even if those values were never explicitly registered as authentication methods," Microsoft said. "To strengthen identity security, SSPR will require explicitly registered authentication methods for verification. This change is part of Microsoft’s Secure Future Initiative and ensures password reset verification is based on trusted, user-validated methods rather than directory-sourced attributes." The development comes as the Windows maker has introduced jailbreak and root detection for Entra credentials in the Microsoft Authenticator app on both iOS and Android platforms, preventing Entra credentials from functioning on jailbroken/rooted devices. Scammers Exploit Trusted Brand Names to Drive Casino Traffic — Scam advertising campaigns are impersonating trusted brands to drive consumers to unrelated online gambling sites. "These campaigns utilize paid social ads, fake app store pages, and Progressive Web Apps to make users believe that well-known brands have launched 'official' casino or slot products," Netcraft said. "The scams begin with an ad on social media platforms such as Facebook, Instagram, and TikTok. The ad claims that a recognizable brand has launched '[Brand] Slots' or a similar gambling product. Upon interacting with the ad, the user is taken to a fake landing page designed to look like an official app store listing or branded game page. Instead of installing a real app, the user is prompted to add a Progressive Web App to their device, which opens an unrelated online casino through affiliate tracking links." PhishLumos as a Way to Counter Cloaking-Based Phishing Threats — As phishing continues to be a persistent threat in cybersecurity, researchers from Tokyo Metropolitan University and NTT Security Holdings have demonstrated PhishLumos to counter campaigns that evade automated scanners through cloaking and selective blocking techniques. "When content is missing, deceptive, or inaccessible, PhishLumos pivots to infrastructure evidence, including shared domains, IP addresses, certificates, and historical scan metadata," the researchers said. "It consolidates observations into a typed property graph knowledge base with a deterministic, idempotent merge operator and provenance for auditable investigations. A supervisor agent coordinates specialized agents and synthesis agents powered by large language models to profile campaigns and generate empirically validated detection rules for deployment in existing controls." CVE Explosion in the AI Era — With artificial intelligence (AI) and large language models (LLMs) accelerating vulnerability discovery, a new report from ProjectDiscovery has found that 30,550 CVEs have been published so far in 2026, a figure that's expected to eclipse 2025's 49,458 CVEs. Of these, 2,906 are rated critical, and 11,187 are rated high in severity. In contrast, a total of 30,361 CVEs were published in 2023. "The exploitable surface is doubling faster than defenders can absorb," ProjectDiscovery said. When the median time-to-exploit is days and the mean is negative, a 55-day critical-remediation cycle is not a process, it's an open door. If attackers are weaponizing bugs in minutes with AI, the response, finding them, proving they're real and handing developers a fix, has to run continuously and autonomously, not on a calendar." New ClickFix Campaign Uses Blockchain C2 — An active malware-as-a-service (MaaS) operation is abusing the Polygon (MATIC) blockchain as a resilient C2 configuration with a ClickFix lure. More than 130 compromised lure websites have been detected so far as part of the campaign. "Compromised websites are injected with a script named tracker.js, appearing as 'JokerStat Analytics Tracker,'" Palo Alto Networks Unit 42 said. "In addition to the clipboard injection, this script performs screenshot and victim-session telemetry exfiltration every 2 minutes." When a victim visits a compromised site, the injected JavaScript performs a blockchain lookup to fetch the C2 server URL. "After C2 resolution, tracker.js starts collecting victim telemetry, including pageview events, heartbeat and screenshots," Unit 42 said. "The same tracker.js then injects the clipboard content personalized per victim. The victim sees a fake CAPTCHA overlay and follows the instructions leading to a ClickFix attack." The attack culminates with the deployment of an infostealer written in Ruby. 2 Venezuela Nationals Sentenced in ATM Jackpotting Attacks — Two illegal aliens from Venezuela, Carlos Javier Padron, 36, and Arnoldo Cabrera Torrealba, 37, were sentenced to 78 months in prison in the U.S. for their involvement in ATM jackpotting activities. The two individuals pleaded guilty to one count of conspiracy to commit bank burglary and one count of computer fraud and intentional damage to a protected computer. The defendants built and deployed a variant of the Ploutus malware on ATMs across the country and used it to withdraw money without authorization. "The conspiracy relied on individuals, including Padron and Torrealba, to deploy the Ploutus malware onto ATMs in person," the U.S. Justice Department said. "Once installed and activated, the malware permitted the co-conspirators to issue commands to the cash dispensing module of the ATM in order to force unauthorized withdrawals of currency." Padron and Torrealba were also ordered to jointly pay $1.53 million in restitution. More than 90 other defendants have been charged over their roles in the operation. Bypassing Microsoft Entra Conditional Access Policies — NetSPI said it found a way to bypass Microsoft Entra Conditional Access Policies by abusing Nested App Authentication to return access tokens for the Microsoft Graph API. "It was possible to use certain Nested App Authentication (or BroCI) flows to bypass any Conditional Access policy," security researcher Thomas Byrne said. "This vulnerability served mainly as a persistence mechanism as it would have required a successful phishing attack to return an initial refresh token before the vulnerable authentication flows could be carried out." A fix for the issue has since been rolled out by Microsoft. Threat Actors Target Laravel Livewire Flaw — More than 6,100 applications have been compromised as part of a campaign targeting CVE-2025-54068, a critical unauthenticated RCE vulnerability in Laravel Livewire, to deliver a credential stealer by means of a shell script. The stealer harvests database-related configurations, Stripe secret keys, SMTP passwords, Google OAuth client secrets, JWT secrets, and AWS IAM credentials from .env files and exfiltrates them to a remote server. The campaign is assessed to have been underway for several months. "Recovery and analysis of the attacker's exfiltration infrastructure revealed credentials harvested from 6,167 distinct applications spanning dozens of countries and sectors, from e-commerce and healthcare to financial services, education, and government," Imperva said. "The attacker’s FTP server contained 1,851+ database dumps and 18+ email lists with over 26 million addresses, indicating the stolen credentials were being actively exploited." The activity has been attributed to an Indonesian-origin threat actor. Booking.com Partner Firms Targeted in TONResolver Campaign — Attackers are targeting employees of Booking.com partner companies in Japan using phishing emails that impersonate guest complaints and review requests to trick hotel staff into executing malicious files. The emails are sent using the notification functionality of a scheduling tool service, allowing them to bypass SPF, DKIM, and DMARC checks. The attacks led to the deployment of TONResolver, which abuses the Open Network (TON) blockchain platform as a dead drop resolver. "In this attack, a ZIP file was downloaded by accessing a hyperlink to a suspicious website, and the infection began when the user clicked a shortcut link file (LNK) disguised as a photo file within the ZIP archive," Trend Micro said. This triggers the execution of PowerShell that fetches and runs the JavaScript-based TONResolver malware using "node.exe," a core executable file for Node.js. The malware then connects to the C2 server obtained from the TON platform for additional attack execution and sends commands. Mamont Android Malware Dissected — An Android malware called Mamont is distributed via dropper apps masquerading as dating services to facilitate financial fraud. "The dropper and its embedded companion APK work in tandem to silently install, launch, and maintain control over the victim device while performing financial reconnaissance and awaiting attacker instructions," NCC Group said. A second variant of the malware has been found to serve phishing overlays inside Android WebView components at runtime, while also initiating phone calls, collecting installed applications, gathering device/network information, and manipulating system behavior to suppress notifications. "Additionally, it can execute commands dynamically based on input, indicating remote control functionality, and it reports execution results back through an internal handler or communication channel," security researcher Vamsi Pavuluri said. 2 Campaigns Deliver AsyncRAT — Phishing emails containing a Dropbox URL as well as macro-laced spreadsheets to distribute AsyncRAT malware. "When the recipient clicks on the link, a ZIP file is downloaded," Forcepoint said. "This file contains an Internet shortcut file in a .URL format. Opening this file leads to downloading multiple malware payloads in the background while the user is deceived by a legitimate-looking PDF opening. This file leads to a .lnk file, which then leads to a JavaScript file. This JS file links to a .BAT file, which hosts malicious content that ultimately delivers another ZIP file. This new ZIP file houses the Python script used to execute the AsyncRAT malware." The second campaign, detailed by LevelBlue, involves the use of generic emails targeting sales, procurement, and vendor management staff with a malicious spreadsheet that uses an embedded macro to download an HTA script, which then performs environment checks before delivering AsyncRAT or Remcos RAT. Clubfoot Wolf and Fluffy Wolf Targets Russia — BI.ZONE has disclosed cyber attacks mounted by an intrusion set it tracks as Clubfoot Wolf targeting a wide range of Russian sectors using spear-phishing emails to deliver NetSupport RAT to establish persistent remote access. A second threat cluster dubbed Fluffy Wolf has leveraged malicious email attachments and GitHub repository URLs to redirect recipients to ZIP archives that deliver PureLogs Stealer, PureRAT, and the Pay2Key ransomware. Also put to use in the attacks is a previously unreported C++ downloader called PowerLoader to fetch malicious PowerShell scripts from the C2 server over HTTP. In this attack chain, the loader is responsible for retrieving PureCrypter, which then launches the final payload. Multiple PhaaS Kits Spotted in the Wild — A number of phishing-as-a-service (PhaaS) toolkits have been identified: CodeStorm (which is a tenant-aware Microsoft 365 phishing kit), ARToken (a fully-featured PhaaS operator panel that shares overlaps with EvilTokens, a device code phishing toolkit), Console (for harvesting AWS console credentials), Mirage2FA (which uses short-lived HTML smuggling and obfuscated JavaScript-loaders to deliver fake Microsoft 365 login pages), and Bluekit (which uses browser-in-the-middle technique to load the legitimate login page inside an attacker-controlled browser, causing the victim to log into their accounts on the attacker's machine). At the same time, reports indicate that the Tycoon 2FA PhaaS service has resurfaced with new infrastructure and obfuscation layers following its law enforcement takedown back in March 2026. These developments also coincide with a surge in device code phishing attacks that exploit legitimate OAuth flows. Specifically, the attack tricks users into entering a device code that then issues active cookies and tokens directly to the attacker's device, bypassing multi-factor authentication (MFA). In tandem, Chinese-language phishing-as-a-service (PhaaS) communities are expanding in an area historically dominated by Russian-speaking cybercriminal groups. One such PhaaS service is the Darcula platform, linked to threat actor UNC5814, which has abandoned static phishing templates in favor of AI-powered page generators and browser automation tools, Loke Puppeteer, that can clone legitimate websites by replicating their HTML, CSS, JavaScript, and visual elements. Because each generated phishing page is unique, traditional signature-based detection methods are rendered ineffective. While PhaaS is at the core of these operations, these developers also typically offer numerous ancillary services, including the sale of personal and financial information. According to a report from Group-IB, data brokers active in Chinese-speaking dark web forums and Telegram channels are advertising large volumes of purportedly stolen data from organizations worldwide. These include marketplaces like Exchange Market, Chang’An Sleepless Night, Aiqianjin, Yiqun Data, and Phoenix Overseas Resources. 🔧 Cybersecurity Tools T3MP3ST → It is an open-source offensive security framework that connects to an AI coding agent and uses it to run authorized security tests across web apps, CTF-style challenges, source code, and other targets. It provides a browser War Room and CLI for recon, exploit testing, and reporting, while its maintainers state it should only be used on systems the user owns or has written permission to test. NOX → It is an open-source Go-based tool for attack surface management, reconnaissance, and vulnerability scanning. It can run passive checks, quick probes, custom YAML workflows, or a full scan using 299 built-in modules across OSINT, subdomains, DNS, ports, web fingerprinting, and deeper vulnerability tests. Its maintainers warn that active scans make real network requests and should only be run against systems the user owns or has written permission to test. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law. Conclusion Most of this week’s problems did not need a clever attacker so much as a useful opening. A trusted device, a trusted repo, a trusted reset path, a trusted browser feature. That word did a lot of damage. Patch what is yours. Question what looks too clean. And maybe stop assuming the boring parts are safe just because they look boring.
thehackernews.comJul 6, 2026extracted
Atlassian, Splunk Patch Critical Vulnerabilities
Atlassian and Splunk on Wednesday announced patches for multiple vulnerabilities in their products, including critical-severity flaws. Splunk resolved a critical issue in AI Toolkit that could allow authenticated attackers with admin roles to execute arbitrary OS commands on the host the Splunk Enterprise instance runs on. “The vulnerability is possible because of an unsafe shell execution pattern in the btool configuration helper, which constructs OS command strings from dynamic parameters without disabling shell interpretation,” Splunk explains. Tracked as CVE-2026-20266 (CVSS score of 9.1), the security defect was addressed in Splunk AI Toolkit version 5.7.4. If upgrading is not possible, Splunk recommends uninstalling the AI Toolkit as a mitigation. The update also addresses CVE-2026-20265, a medium-severity information disclosure bug caused by an insecure default domain allowlist. An attacker holding the admin or power role could cause the AI Toolkit to make outbound HTTP requests to attacker-controlled servers, leading to data exfiltration. Atlassian published 100 security bulletins that address dozens of security defects across Bamboo Data Center and Server, Bitbucket Data Center and Server, Confluence Data Center and Server, Crowd Data Center and Server, Fisheye/Crucible, Jira Data Center and Server, and Jira Service Management Data Center and Server. All the weaknesses resolved with the fresh security updates appear to affect third-party dependencies used in Atlassian’s products. These include critical-severity issues in Axios (CVE-2026-42043, CVE-2026-40175, and CVE-2026-42264), Apache Tomcat (CVE-2026-41293, CVE-2026-43512, CVE-2026-41293, CVE-2026-43515, and CVE-2026-43515), and Netty (CVE-2026-42584). Users are advised to update to a patched version of the affected Atlassian products as soon as possible. Related: Critical Command Execution Vulnerability Patched in Cisco ISE Related: F5 Patches Critical, High-Severity NGINX Vulnerabilities Related: Microsoft Working on Patch for ‘RoguePlanet’ Zero-Day Related: 3 Recently Patched Fortinet FortiSandbox Vulnerabilities in Hacker Crosshairs
securityweek.comJun 18, 2026extracted
SAP fixes critical flaws in NetWeaver and Commerce Cloud
SAP has released fixes for 15 vulnerabilities as part of its June 2026 Security Patch package, including four critical-severity flaws affecting SAP NetWeaver and SAP Commerce Cloud. NetWeaver is SAP's core application platform and middleware stack that provides the foundation for many SAP business applications, including ERP systems, handling functions such as application serving, integration, authentication, user management, and data processing. Commerce Cloud is an enterprise e-commerce platform (formerly Hybris). It enables organizations to build and manage online stores, digital sales channels, product catalogs, customer accounts, and order management systems for B2B and B2C commerce. In this month's security bulletin, SAP lists the following critical vulnerabilities as being addressed: CVE-2026-44748 (CVSS 9.9) – XML Signature Wrapping in SAP NetWeaver AS ABAP and ABAP Platform, potentially allowing authentication bypass in SAML-based environments. CVE-2026-27671 (CVSS 9.8) – Memory corruption flaw in SAP NetWeaver/ABAP Platform Application Server ABAP. CVE-2026-22732 (CVSS 9.1) – Spring Security-related vulnerability affecting SAP Commerce Cloud and SAP Data Hub. CVE-2026-40128 (CVSS 9.0) – Directory traversal vulnerability in SAP NetWeaver Application Server Java's Web Container. “SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier,” reads the description for CVE-2026-44748. “This may result in acceptance of tampered identity information leading to unauthorized access to sensitive user data and potential disruption of normal system usage.” In the case of CVE-2026-27671, an attacker can exploit it without authentication by sending crafted RFC requests to vulnerable endpoints, leveraging improper kernel validation to cause memory corruption. Apart from the critical security issues above, SAP also addressed two high-severity vulnerabilities. CVE-2026-29145 comprises multiple Apache Tomcat flaws impacting Commerce Cloud, and CVE-2026-44751, which is a missing authorization check issue in NetWeaver AS ABAP. The German enterprise software company also addressed various SQL injection, path traversal, cross-site scripting (XSS), email spoofing, and authorization bypass issues across multiple SAP products. Details about the flaws and mitigation advice or workarounds are available only to SAP customers with a security portal account. Organizations using the impacted products should prioritize patching, particularly the SAML authentication flaw (CVE-2026-44748) and the memory corruption issue (CVE-2026-27671), which were rated very high in severity and could have a serious impact on enterprise environments. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comJun 9, 2026extracted
SAP Patches Critical NetWeaver, Commerce Vulnerabilities
Enterprise software maker SAP on Tuesday released 15 new security notes, including four that resolve critical-severity vulnerabilities in NetWeaver, Commerce, and Data Hub. The most severe of the resolved bugs is CVE-2026-44748 (CVSS score of 9.9), described as an XML Signature Wrapping issue in the SAML Authentication of NetWeaver AS ABAP and ABAP Platform. An authenticated attacker with normal privileges could “obtain a valid signed message and send modified signed XML documents with tampered identity information to the verifier,” application security firm Onapsis explains. Due to the security defect, the modified identity information is accepted, providing the attacker with access to sensitive user data and potentially allowing them to disrupt normal system usage. Disabling SAML authentication temporarily mitigates the vulnerability, Onapsis explains. The second critical-severity flaw patched on SAP’s June 2026 security patch day is CVE-2026-27671 (CVSS score of 9.8), a memory corruption issue in NetWeaver and ABAP Platform. The bug is due to the SAP kernel’s improper validation of the RFC protocol, allowing unauthenticated attackers to send crafted requests that target logic errors in memory management. Affecting Commerce Cloud and Data Hub, the third critical-severity weakness that SAP resolved this week is CVE-2026-22732 (CVSS score of 9.1), which impacts all applications that rely on the Spring Security framework. “When applications specify HTTP response headers for servlet applications using Spring Security, there is the possibility that the HTTP Headers will not be written,” a NIST advisory reads. SAP on Tuesday also resolved a critical directory traversal vulnerability in NetWeaver Application Server Java (Web Container). Tracked as CVE-2026-40128 (CVSS score of 9.0), the issue allows unauthenticated attackers to send malicious HTTP logon requests, manipulating file inclusion parameters and allowing the attacker to access sensitive information or cause denial-of-service (DoS) conditions. On Tuesday, SAP also released a high-severity security note resolving multiple Apache Tomcat flaws in Commerce Cloud, and another to address a missing authorization check in NetWeaver and ABAP Platform. Related: Check Point VPN Zero-Day Exploited in Qilin Ransomware Attacks Related: Everybody Is Vibe Coding But Nobody Told the Security Team Related: CrewAI Vulnerabilities Expose Devices to Hacking
securityweek.comJun 9, 2026extracted
Operational Summary - aprile 2026
Operational Summary - aprile 2026 Operational Summary - aprile 2026 Pubblicazione PL01/260605/CSIRT-ITA Torna l’appuntamento mensile di CSIRT Italia sull’analisi e l’andamento della minaccia cyber con l’elenco delle vulnerabilità informatiche più gravi. Di seguito i principali punti emersi nel mese: Nel mese di aprile 2026 sono stati registrati 265 eventi, in diminuzione del 39% rispetto ai 435 di marzo, analoga contrazione ha riguardato il numero di incidenti (174), in diminuzione del 39% rispetto al mese precedente. Dopo l’incremento degli eventi e degli incidenti osservato nei primi mesi del 2026 - riconducibile alla progressiva entrata a regime degli obblighi di notifica introdotti dalla Direttiva NIS2 - nel mese di aprile 2026 si osserva una prima fase di assestamento. I valori registrati restano, tuttavia, superiori a quelli rilevati nel periodo precedente all’entrata a regime della nuova disciplina, a conferma di una più ampia emersione degli eventi e degli incidenti cyber. Nel corso del mese di aprile 2026, le principali minacce rilevate risultano l’esposizione dati, il phishing e le compromissioni di caselle di posta elettronica. I settori con il maggior numero di vittime di eventi cyber sono stati Manifatturiero, Tecnologico e Pubblica amministrazione centrale. Il manifatturiero è stato interessato prevalentemente da esposizione dati, mentre il settore tecnologico e delle telecomunicazioni da compromissione delle caselle e-mail. Gli attacchi ransomware hanno interessato prevalentemente i settori manifatturiero, trasporti e altre società private. L’analisi degli eventi rilevati evidenzia come i principali vettori di compromissione siano riconducibili all’utilizzo di credenziali valide, precedentemente compromesse, e allo sfruttamento di servizi di accesso remoto non adeguatamente configurati. Nel mese in esame, non sono state rilevate campagne di particolare rilevanza rivolte a soggetti nazionali. Sono state tuttavia registrate 3 rivendicazioni, senza evidenze di impatti significativi. Nell’ambito dell’attività proattiva di monitoraggio della superficie esposta dei soggetti nazionali, il CSIRT Italia ha inviato, ad aprile 2026, 1.500 comunicazioni di allertamento a pubbliche amministrazioni e imprese appartenenti alla constituency, relative all’esposizione su Internet di 2.212 servizi a rischio. L’analisi dei log provenienti da malware di tipo infostealer ha consentito, infine, di identificare 7 account potenzialmente compromessi afferenti a soggetti istituzionali, prontamente allertati. Nel mese di aprile 2026 la posta elettronica si conferma il principale vettore di accesso iniziale. In stretta connessione, emerge lo sfruttamento di credenziali valide già compromesse, a conferma della centralità dell’abuso dell’identità digitale nelle dinamiche di attacco osservate. Permangono, seppure con minore incidenza, lo sfruttamento di vulnerabilità e l’abuso di servizi remoti esposti. Sono state pubblicate 5.885 nuove CVE, in diminuzione (−307) rispetto a marzo. Di queste, 1.251 presentano almeno un Proof of Concept (PoC), in diminuzione (−30), e per 10 CVE è stato rilevato lo sfruttamento attivo, stabile (+3) rispetto a marzo. Particolarmente critiche le vulnerabilità che interessano Fortinet FortiClient EMS, soluzione utilizzata per la gestione centralizzata di dispositivi e sistemi connessi alla rete aziendale (CVE-2026-21643 e CVE-2026-35616 ), che potrebbero consentire a un attaccante non autenticato l’esecuzione di codice da remoto; Apache Tomcat, server applicativo open source ampiamente impiegato per l’erogazione di applicazioni web basate su tecnologia Java (CVE-2026-29146), la cui compromissione potrebbe determinare l’accesso non autorizzato a informazioni sensibili; Red Hat Enterprise Linux 10, sistema operativo enterprise basato su Linux utilizzato in ambienti server, con specifico riferimento all’interfaccia web Cockpit per l’amministrazione remota dei sistemi (CVE-2026-4631). La vulnerabilità potrebbe permettere a un attaccante di eseguire comandi o codice da remoto sui sistemi affetti, anche in assenza di credenziali valide. Tali criticità sono state oggetto di specifiche attività di allertamento da parte del CSIRT Italia. Le numerose vulnerabilità individuate ad aprile 2026 hanno determinato un incremento del numero di sistemi e servizi potenzialmente esposti, con conseguente elevato numero di comunicazioni di allertamento effettuate dall’Agenzia per segnalare potenziali compromissioni o fattori di rischio ad amministrazioni ed imprese italiane, anche ai sensi dell’art. 2, comma 1, della Legge n. 90/2024. Le comunicazioni dirette, effettuate dal CSIRT Italia sono state in totale 7.229, in aumento (+13) rispetto a marzo.
acn.gov.itJun 5, 2026extracted
Italia, ACN: “Ad aprile diminuiscono gli incidenti cyber, -39%”. Il rapporto
“Il calo di incidenti ed eventi cyber rappresenta una prima fase di assestamento successiva all’ampliamento della platea dei soggetti obbligati alla notifica dalla NIS2“. Nel mese di aprile 2026, l’Operational Summary dell’Agenzia per la Cybersicurezza Nazionale (ACN) ha evidenziato “una diminuzione degli eventi e degli incidenti cyber registrati in Italia“. Nel periodo in esame c’è stata la registrazione di 265 eventi cyber e di 174 incidenti, con una diminuzione di entrambi del 39% rispetto ai trentuno giorni precedenti. Si registra dunque una inversione di tendenza rispetto ai primi mesi dell’anno. Il calo ha rappresentato “una prima fase di assestamento successiva all’ampliamento della platea dei soggetti obbligati alla notifica della Direttiva NIS2“. Principali eventi cyber Analizzando i singoli settori, gli eventi cyber di aprile hanno interessato soprattutto tre di questi (con due cambiamenti rispetto al mese precedente). Si tratta di: manifatturiero. Tecnologico. Pubblica amministrazione centrale. Il principale fattore malevole de manifatturiero è stato quello dell’esposizione dei dati. Il settore tecnologico e delle telecomunicazioni, invece, da compromissione delle caselle e-mail. La conferma, rispetto a marzo, è stata quella del manifatturiero che si trovava insieme a telecomunicazioni e sanitario. Sempre nei 30 giorni di aprile, gli attacchi ransomware hanno interessato prevalentemente “i settori manifatturiero, trasporti e altre società private“. L’analisi degli eventi rilevati evidenzia come “i principali vettori di compromissione siano riconducibili all’utilizzo di credenziali valide, precedentemente compromesse“. E insieme, “allo sfruttamento di servizi di accesso remoto non adeguatamente configurati“. Andamento delle minacce e principali vettori d’attacco Rispetto al mese precedente, gli eventi sono stati 265, in diminuzione del 39% rispetto ai 435 di marzo. Un’analoga contrazione ha riguardato il numero di incidenti, ossia 174, in diminuzione del 39% rispetto al mese precedente. I 265 eventi cyber hanno interessato 271 soggetti nazionali. Di questi 219 appartenenti alla constituency. I restanti hanno riguardato cittadini e società private operanti in settori non critici. Tra le principali minacce rilevate nel corso delle analisi nel mese figurano “esposizioni di dati, campagne di phishing e compromissioni di caselle di posta elettronica“. La stessa posta elettronica, sottolinea l’ACN, “si conferma il principale vettore di accesso iniziale, seguita dallo sfruttamento di credenziali valide precedentemente compromesse“. Le comunicazioni di CSIRT Italia Con riferimento ai 30 giorni di aprile, c’è stata la pubblicazione di 5.885 nuove vulnerabilità (CVE), anche in questo caso con un valore di merito con “la lieve diminuzione rispetto a marzo“. All’interno di questo insieme, “1.251 risultano corredate da proof of concept, mentre per 10 vulnerabilità è si è rilevato lo sfruttamento attivo“. Una particolare attenzione è andata alle criticità riguardanti le vulnerabilità relative a Fortinet FortiClient EMS, Apache Tomcat e Red Hat Enterprise Linux 10. Tutte vulnerabilità che “potrebbero consentire esecuzione di codice da remoto o accessi non autorizzati a informazioni sensibili“. Tali vulnerabilità sono state oggetto di specifiche attività di allertamento da parte del CSIRT Italia. Nell’ambito delle attività di monitoraggio proattivo, il CSIRT Italia ha inviato in aprile “circa 1.500 comunicazioni di allertamento relative all’esposizione su Internet di 2.212 servizi potenzialmente a rischio“. L’analisi dei log provenienti da malware di tipo infostealer ha inoltre consentito di individuare 7 account potenzialmente compromessi riconducibili a soggetti istituzionali, prontamente allertati. Complessivamente, nel mese di aprile 2026, il CSIRT Italia “ha effettuato 7.229 comunicazioni dirette a pubbliche amministrazioni e imprese, anche in questo caso in lieve aumento rispetto a marzo“. Questo aspetto ha confermato l’intensità delle attività di prevenzione e supporto operativo svolte dall’Agenzia in un contesto di minaccia ancora elevato. Ransomware e DDoS In aprile 2026, “il 13% degli attacchi ransomware ha colpito soggetti critici, il 30% ha colpito soggetti a media criticità ed il restante 57% ha coinvolto altri soggetti a criticità minore“. Con il monitoraggio di fonti aperte sempre nei 30 giorni in esame, si è permesso di individuare 28 rivendicazioni di attacchi ransomware a danno di soggetti italiani. Sempre con riferimento al monitoraggio nel mese di aprile 2026 sono state individuate 3 rivendicazioni di attacchi DDoS in danno di soggetti italiani. Rispetto agli ultimi mesi c’è stato un importante miglioramento anche in questo aspetto. Per approfondire Leggi l’Operational Summary di aprile 2026 in PDF. Consulta il report del 2° semestre 2025 in PDF. Leggi “ACN, adottata la nuova tassonomia per attuare l’obbligo di notifica degli incidenti cyber“. Leggi “Direttiva NIS2: messa in sicurezza delle reti e dei sistemi informativi“.
cybersecitalia.itMay 25, 2026extracted
⚡ Weekly Recap: Linux Rootkit, macOS Crypto Stealer, WebSocket Skimmers and More
Rough Monday. Somebody poisoned a trusted download again, somebody else turned cloud servers into public housing, and a few crews are still getting into boxes with bugs that should’ve died years ago — the same old holes, same lazy access paths, same “how the hell is this still open” feeling. One report this week basically reads like a guy tripped over root access by accident and decided to stay there. The weird part is how normal this all sounds now. Fake updates. Quiet backdoors. Remote tools are used like skeleton keys. Forum rats swapping stolen access while defenders burn another weekend chasing logs and praying the weird traffic is just monitoring noise. The Internet’s held together with duct tape and bad sleep. Anyway, Monday recap time. Same fire. New smoke. ⚡ Threat of the Week Ivanti EPMM and Palo Alto Networks PAN-OS Flaws Under Attack—Ivanti warned customers that attackers have successfully weaponized CVE-2026-6973, an improper input validation defect in Endpoint Manager Mobile (EPMM) that allows authenticated users with administrative privileges to run code remotely. The company did not say when the first instance of exploitation occurred, or precisely how many customers have been impacted. In a related development, attackers are actively exploiting a zero-day vulnerability affecting some Palo Alto Networks' customers' firewalls. As in the case of Ivanti, Palo Alto Networks did not say when or how it became aware of active exploitation, but said threat actors may have attempted to unsuccessfully exploit a recently disclosed critical security flaw as early as April 9, 2026. The memory corruption vulnerability, tracked as CVE-2026-0300, affects the authentication portal of PAN-OS and allows unauthenticated attackers to run code with root privileges on the PA-Series and VM-Series firewalls. Attack surface management platform Censys said it detected about 263,000 Internet-exposed hosts running PAN-OS. Patches are expected to be released starting May 13, 2026. Webinar: Transform Your SOC - From Generic Detection to Exposure Intelligence Join Gartner and XM Cyber on May 12th at 10 AM EST. Learn to break the reactive cycle of alert fatigue by infusing real-time exposure context into your SIEM and SOAR. Discover how to prioritize threats based on their actual reachability to your critical assets. Reserve my Seat ➝ 🔔 Top News New Quasar Linux RAT Spotted—Attackers have found a new way to turn Linux systems into entry points for a supply chain or cloud infrastructure breach that are resilient to takedowns. The new malware framework, dubbed Quasar Linux or QLNX, is a modular Linux remote access trojan (RAT) that can harvest data from compromised systems. But what sets it apart is its use of a peer-to-peer (P2P) mesh capability that turns individual compromises into an interconnected infection network, making the campaign difficult to kill and allowing infected hosts to communicate with one another rather than relying entirely on centralized servers. QLNX also combines kernel-level rootkit functionality, PAM-based authentication backdoors, and persistence mechanisms to stay hidden on compromised systems while enabling persistent access. It also hides malicious processes under names that mimic legitimate Linux services and system binaries to blend into routine workflows. "Quasar Linux RAT (QLNX) is a comprehensive Linux implant that combines remote access capabilities with advanced evasion, persistence, keylogging, and credential harvesting features," Trend Micro said. "The malware carries embedded C source code for both its PAM backdoor and LD_PRELOAD rootkit as string literals within the binary." PCPJack Replaces TeamPCP Malware to Steal Cloud Secrets—An unknown threat actor has launched a campaign to systematically clean up environments infected by the infamous TeamPCP hacking group and drop its own malicious tools to steal credentials from cloud, container, developer, productivity, and financial services for financial gain. Active since late April, the campaign is also capable of propagating itself by moving laterally both inside of a network and to other targets by breaking into open and exploitable cloud infrastructure. The broad credential harvesting sweep allows the malware to hack into more cloud servers and propagate the infection in a worm-like manner, while also rooting out any processes and artifacts belonging to TeamPCP. The external propagation is achieved by downloading parquet files from Common Crawl for target discovery. While threat actors aiming for cloud environments have long built methods to delete competing malware, particularly in cryptojacking campaigns, the lack of a miner and its specific targeting of TeamPCP tooling has raised the possibility that it may be someone who was previously associated with the group, is part of a rival crew, or is an unrelated third-party mimicking TeamPCP's tradecraft. MuddyWater Uses Chaos Ransomware as Decoy in New Attack—An Iranian state-sponsored espionage group pretended to be a regular ransomware gang in a new ransomware attack detected in early 2026. The Iranian hackers known as MuddyWater disguised their operations as a Chaos ransomware attack, relying on Microsoft Teams social engineering to gain access and establish persistence within a victim environment. Although the attack involved reconnaissance, credential harvesting, and data exfiltration, no file-encrypting ransomware was deployed, which is inconsistent with Chaos attacks. The victim was also added to the Chaos ransomware data leak site, but infrastructure and code-signing certificate evidence indicate the activity was likely used as a cover to mask the threat actor's true espionage goals and to complicate attribution. Rapid7 told The Hacker News that there is no evidence to suggest that MuddyWater is operating as an affiliate of Chaos. DAEMON Tools Supply Chain Attack Leads to QUIC RAT—Hackers compromised installers of DAEMON Tools in a supply chain attack that affected users in more than 100 countries. The malicious versions, first observed in early April, impacted multiple releases of the software that were installed on thousands of machines across Russia, Brazil, Turkey, Spain, Germany, France, Italy, and China. The operation appears to be targeted. Most victims received only a data miner designed to gather system data, while a second, more advanced shellcode loader was deployed to just a handful of targets, including organizations in retail, scientific, government, and manufacturing organizations in Russia, Belarus, and Thailand. It's suspected that the attackers likely used the initial data collection to profile infected systems before selectively deploying an implant codenamed QUIC RAT. The malware was deployed against only one known target, an unidentified educational institution in Russia. Kaspersky said the malicious code included Chinese-language elements, suggesting the attackers are familiar with the language, but stopped short of attributing the campaign to a specific group. Cybercrime Groups Use Vishing for Data Theft and Extortion—An active phishing campaign has been observed targeting multiple vectors since at least April 2025, with legitimate Remote Monitoring and Management (RMM) software as a way to establish persistent remote access to compromised hosts. The activity, which targets organizations across multiple industries, highlights a growing trend where attackers weaponize legitimate IT management tools to bypass security controls and maintain persistence on compromised systems. What makes the campaign noteworthy is its deliberate avoidance of traditional malware in favor of two commercially available remote monitoring and management (RMM) tools, SimpleHelp and ScreenConnect, for persistent control over victim machines. The abuse of RMM tools by bad actors has surged in recent years as they offer a low-friction way to gain access to and maintain persistence on a victim environment. Because of how ubiquitous they are in enterprise environments, the tools are flagged as malicious, allowing the attackers to blend in with normal operations. 🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-6973 (Ivanti Endpoint Manager Mobile), CVE-2026-0300 (Palo Alto Networks PAN-OS), CVE-2026-29014 (MetInfo), CVE-2026-22679 (Weaver E-cology), CVE-2026-4670, CVE-2026-5174 (Progress MOVEit Automation), CVE-2026-43284, CVE-2026-43500 (Linux Kernel), CVE-2026-7482 (Ollama), CVE-2026-42248, CVE-2026-42249 (Ollama for Windows), CVE-2026-29201, CVE-2026-29202, CVE-2026-29203 (cPanel and Web Host Manager), CVE-2026-23918 (Apache HTTP Server), CVE-2026-42778, CVE-2026-42779 (Apache MINA), CVE-2026-2005, CVE-2026-2006 (PostgreSQL pgcrypto), CVE-2026-32710 (MariaDB), CVE-2026-23863, CVE-2026-23866 (Meta WhatsApp), CVE-2026-29146 (Apache Tomcat), CVE-2026-1046 (Mattermost Desktop), CVE-2026-0073 (Google Android), CVE-2026-20188 (Cisco Crosswork Network Controller and Network Services Orchestrator), CVE-2026-20185 (Cisco SG350 and SG350X Series Managed Switches), CVE-2026-20034, CVE-2026-20035 (Cisco Unity Connection), CVE-2026-7896, CVE-2026-7897, CVE-2026-7898, CVE-2026-5865 (Google Chrome), CVE-2025-68670 (xrdp), CVE-2026-23864 (React Server Components), CVE-2026-23870, CVE-2026-44575, GHSA-26hh-7cqf-hhc6, CVE-2026-44579, CVE-2026-44574, CVE-2026-44578, CVE-2026-44573 (Next.js), CVE-2026-26129, CVE-2026-26164 (Microsoft M365 Copilot), CVE-2026-33111 (Microsoft Copilot Chat), CVE-2026-44843 (LangChain), and CVE-2026-33309 (Langflow). 🎥 Cybersecurity Webinars The Hidden Attack Paths Your AppSec Tools Completely Miss in 2026 → This webinar shows the real attack paths that most AppSec tools miss — from code and CI/CD pipelines to cloud setups, dependencies, and secrets. See how attackers combine small weaknesses into big breaches, and learn simple ways to find and stop them. With Wiz experts Mike McGuire and Salman Ladha. AI-Powered DDoS Attacks Are Here — And They’re Smarter, Faster & Deadlier in 2026 → Attackers are now using AI to launch DDoS attacks that are faster, smarter, and much harder to stop. This webinar shows how they instantly spot weak spots, create new attack methods, and dramatically increase success rates — plus easy ways defenders can fight back using smarter AI tools and proactive protection. Perfect for security leaders who want to stay ahead. 📰 Around the Cyber World JDownloader Website Compromised in Supply Chain Attack —The website for JDownloader, an open-source download management tool, was compromised last week to distribute malicious Windows and Linux installers. The compromise occurred on May 6, 2026, at 12:01 a.m. UTC. While the Linux version embeds malicious shell code, the Windows version has been found to serve a Python-based remote access trojan (RAT) that enlists the compromised device in a bot network and runs arbitrary Python code supplied by the operator, per researcher Thomas Klemenc. "The attack has modified alternative download pages and exchanged links and details," the developer behind JDownloader said in a post on Reddit. "The bad ones are missing digital signatures and as such [Microsoft] SmartScreen will block/warn the execution of it." Further investigation uncovered that the attack vector was an "unpatched security bug," although it's not clear which vulnerability was exploited by the threat actor to tamper with the site. Operation HookedWing Targets Over 500 Organizations —A long-running phishing campaign dating back to 2022 has stolen 2,000 credentials belonging to users from over 500 different organizations. According to SOCRadar, the campaign has mostly affected aviation, public administration, energy, and critical infrastructure. "The breadth of targeting, combined with the campaign’s longevity, points to a resource-capable operation rather than opportunistic activity," it said. The activity has been codenamed Operation HookedWing. The attack uses phishing emails with lures related to human resources, Microsoft, or Google to direct users to fake landing pages hosted on GitHub.io and Vercel, capture entered credentials via an injected form, and exfiltrate them to servers compromised or created by the threat actor. More than 20 distinct command-and-control (C2) domains and 100 distribution domains have been identified. Uptick in Use of Vercel for Phishing Campaigns —Threat actors are increasingly using Vercel to create large numbers of realistic phishing websites that impersonate well-known brands. "Threat actors are able to redeploy phishing campaigns with ease if a web page is taken down," Cofense said. "Vercel abuse has increased significantly over time and is likely to continue increasing as minimally skilled threat actors start using cheap or free force multipliers." New ConsentFix V3 Attack Automates Microsoft Account Hijacking —Push Security said it identified a member of the XSS criminal forum advertising a new toolkit dubbed ConsentFix v3 that brings together ClickFix-style social engineering with OAuth consent phishing to hijack Microsoft accounts. "ConsentFix v3 allows users to instrument the entire attack chain, enabling users to spin up ConsentFix infrastructure, create believable personas with which to interact with victims, craft and manage email campaigns, and automate the process of exchanging the captured OAuth token for session and refresh tokens to establish access to the compromised account," Push Security said. The attack uses Cloudflare Workers for hosting the phishing pages, ZoomInfo for target identification, Dropbox for PDF hosting, and Pipedream as an exfiltration channel. Workplace Fraud Trends in 2026 —A new report from Cifas has found that 13% of employees said: "they have either sold their company login details to a former colleague, or know someone who has, in the past 12 months." Another 13% of respondents believed selling access to company systems was justifiable. "Selling login details might seem insignificant to those involved, but it can open the door to serious fraud and financial harm," Cifas said. "These findings show how vital it is for organisations to build fraud‑aware cultures, where employees at all levels understand their responsibilities and the consequences of their actions." India Pushes for Sovereign Hosting of Anthropic's Claude AI Models —According to a report from MoneyControl, the Indian government is said to be pushing for sovereign hosting of Anthropic's Claude artificial intelligence (AI) models within India. Officials have argued that advanced AI systems meant for sensitive sectors such as banking, telecom, and critical infrastructure cannot operate on foreign-hosted infrastructure due to jurisdictional, compliance, and national security risks. OpenAI Rolls Out GPT-5.5-Cyber —OpenAI began rolling out GPT-5.5-Cyber, a security-focused variant of the model, in a limited preview capacity to select cybersecurity teams, a month after Anthropic’s Mythos debut. "The initial preview of cyber-permissive models like GPT‑5.5‑Cyber is not intended to significantly increase cyber capability beyond GPT‑5.5 – it’s primarily trained to be more permissive on security-related tasks," OpenAI said. "The differences between model access levels are most pronounced when comparing prompts and responses." FIRESTARTER Backdoor Targets Cisco Devices —Late last month, theU.S. Cybersecurity and Infrastructure Security Agency (CISA) revealed that an unnamed federal civilian agency's Cisco Firepower device running Adaptive Security Appliance (ASA) software was compromised in September 2025 with a new malware called FIRESTARTER. The malware is noteworthy for its ability to survive reboots, firmware updates, and patches. In a new analysis, firmware security company Eclypsisum described the backdoor as a Linux ELF that hooks the LINA process and re-installs itself after receiving a termination signal. "When lina_cs runs, it copies its own contents from /usr/bin/lina_cs into memory and registers a signal handler, allowing the malware to take action in response to signals (e.g., when the system or user tells the process to restart)," security researcher Paul Asadoorian said. "It also triggers on runlevel 6, which is the system reboot runlevel on Linux. Which means every time the device shuts down or reboots, FIRESTARTER’s persistence routine fires." Google Rolls Out Ways for Developers to Push Safer Android Apps —Google said it has expanded Play Policy Insights in Android Studio to catch common policy issues, like missing login credentials, and detect security threats and abuse using its Play Integrity API. "With significantly shorter warm-up latency, you can use these real-time checks in your most speed-critical user journeys, like logins or payments, to catch unauthorized access and risky interactions," Google said. "We're adding support for post-quantum cryptography in Play App Signing this year, which will protect your apps and app updates from potential threats with the emergence of quantum computing." Poland Says Hackers Breached its Water Treatment Plants —Poland's Internal Security Agency (ABW) disclosed that it detected attacks on five water treatment plants in 2025, potentially allowing bad actors to take control of industrial equipment and, in the worst case, tamper with the safety of the water supply. The intelligence agency did not attribute the attacks to a specific threat actor or group, but Russian government hackers were attributed to a failed attempt to bring down the country's energy grid towards the end of 2025. Claude Leans More on Russian and Iranian Propaganda Sources —A new audit of Anthropic Claude has revealed that the AI chatbot "repeated false claims 15% of the time when it was asked about pro-Kremlin falsehoods in the voice of typical users, citing Russian state-affiliated media every time," NewsGuard said. The figure represents a jump from only 4%. What's more, since the start of the U.S.-Iran war, Claude cited Iranian state-affiliated media in one case when prompted on pro-Iran false claims, when previously it had never cited Iranian state-affiliated media. "This increase in citations to Kremlin propaganda sources, including when they spread false claims, suggests that Claude in recent months has become more vulnerable to state disinformation campaigns," NewsGuard said. WebSocket Backdoor Campaign Injects Skimmers —Palo Alto Networks Unit 42 said obfuscated WebSocket backdoors are being used to inject credit card skimmers into hundreds of compromised websites with the goal of sending stolen card information back to the attacker's C2 domains. "Obfuscated JavaScript creates a WebSocket backdoor using dynamically executed JavaScript," Unit 42 said. "The WebSocket sends an obfuscated JavaScript payload to inject a credit card skimmer into the web page." How Backdoored Electron Applications Evade Defenses —Cybersecurity researchers have detailed a technique that hijacks trusted Electron applications to enable persistence and bypass application safe listing controls. "In advanced variations of the attack, minimal changes are made to the components of the Electron application," LevelBlue said. "This allows the application to function normally while at the same time loading the malicious command-and-control (C2) functionality in the background, hiding under the umbrella of the trusted process." New Attacks Distribute Vidar Stealer, PlugX, and Beagle Malware —In an attack chain detailed by LevelBlue, threat actors have been found to leverage "MicrosoftToolkit.exe" as a starting point to launch an AutoIt script that drops the Vidar Stealer payload. "This intrusion highlights the continued effectiveness of script-based, multi-stage loaders in delivering commodity information stealers such as Vidar," LevelBlue said. "A sophisticated multi-stage loader infection leveraging Windows-native tools and file-masquerading techniques. The attacker avoids dropping a single identifiable malware binary and instead reconstructs and executes payloads dynamically through staged file manipulation." The development follows the discovery of a fake Claude website ("claude-pro[.]com") that serves as a conduit for a fake MSI installer responsible for deploying a DonutLoader payload that drops a simple backdoor dubbed Beagle, which is capable of running commands and performing file uploads/downloads. Critical Flaw in Cline's Kanban Server —A critical vulnerability in Cline's local Kanban server (CVSS score: 9.7) could have been exploited by an attacker to facilitate information disclosure through the runtime state stream, remote code execution through the terminal I/O endpoint, and denial-of-service through the terminal control endpoint. Oasis Security, which discovered the vulnerability, said the AI coding agent's localhost WebSocket lacks origin validation and authentication. Because web browsers don't enforce the same-origin policy on WebSocket connections, any website the developer visits can connect to these endpoints to achieve full compromise. "Any website a developer visited while running an affected version could silently connect to their machine, exfiltrate workspace data in real time, and inject commands into the developer's AI agent," Oasis Security said. "The developer would see nothing unusual. They were just browsing the web." Following responsible disclosure, the issue was addressed in Cline Kanban version 0.1.66. Mozilla Uses AI to Detect 423 Flaws in Firefox —Mozilla revealed Anthropic's Mythos Preview and other AI models helped it identify and ship 423 Firefox security bug fixes in April 2026, compared to 31 a year earlier. This includes a 20-year-old use-after-free bug that could be triggered using the XSLTProcessor DOM API without any user interaction, as well as various flaws in its sandbox system. "This was due to a combination of two main factors," Mozilla said. "First, the models got a lot more capable. Second, we dramatically improved our techniques for harnessing these models – steering them, scaling them, and stacking them to generate large amounts of signal and filter out the noise." The development comes as AI is already accelerating vulnerability discovery, reducing the effort needed to identify, validate, and weaponize flaws. 60% of MD5 Password Hashes Can Be Cracked in Under an Hour —An analysis of 231 million unique passwords from dark web leaks between 2023 and 2026 has revealed that nearly 60% of them can be cracked in less than an hour. To make matters worse, nearly half of all passwords (48%) can be cracked within a minute. "Attackers owe this boost in speed to graphics processors, which grow more powerful every year," Kaspersky said. "While an RTX 4090 in 2024 could brute-force MD5 hashes at a rate of 164 gigahashes (billion hashes) per second, the new RTX 5090 has increased that speed by 34% – reaching 220 gigahashes per second." New JobStealer Targets Windows and macOS —Threat actors are luring potential victims to malicious websites and asking them to download a video conferencing app under the pretext of an online interview, only to drop a stealer that can harvest data from cryptocurrency wallets. "The malicious program JobStealer, disguised as an online conferencing app, is downloaded from them," Doctor Web said. Some of the fake brands used by the threat actors include MeetLab, Juseo, Meetix, and Carolla. "To convince users that these platforms are fully functional, scammers create corresponding Telegram channels and social media accounts – for example, on X." The attack leverages a ClickFix-like instruction to copy and paste a command that drops the stealer malware. More ClickFix Attacks —ClickFix attacks seem to show no signs of stopping anytime soon. The Australian Cyber Security Center (ACSC) warned that the ClickFix social engineering tactic is being used to deliver Vidar Stealer. "The ClickFix attack typically begins with an adversary injecting a malicious payload delivery domain into the compromised website," ACSC said. "The injected payload domain loads JavaScript code from an external API server. This code overwrites the content of the legitimate page, presenting a fraudulent Cloudflare verification prompt." In recent months, ClickFix has evolved to abuse native Windows utilities like cmdkey and regsvr32, as well as drop Node.js-based infostealer to Windows users via malicious MSI installers and an AppleScript-based infostealer to macOS. ClickFix-related attacks have also been found to leverage shareable chat features on ChatGPT and Grok, or blog sites and other user-driven content platforms, to trick users into running AMOS Stealer, MacSync, and Shub Stealer. "Prior iterations of this campaign delivered the infostealers through disk image (.dmg) files that required users to manually install an application," Microsoft said. "This recent activity reflects a shift in tradecraft, where threat actors instruct users to run Terminal commands that leverage native utilities to retrieve remotely hosted content, followed by script‑based loader execution." Another campaign targeting Vietnam, Taiwan, and Spain has spread through fake Google documents containing a ClickFix command and malicious DMG files to deploy a new macOS stealer called NotnullOSX that exclusively targets victims holding over $10,000 in cryptocurrency holdings. ClickFix has also been used by a traffic distribution system (TDS) called ErrTraffic. "ErrTraffic primarily targets WordPress websites by deploying a PHP backdoor script in the must-use plugin (mu-plugin) that captures administrator credentials and ensures persistence on compromised sites," LevelBlue said. "ErrTraffic utilizes the Traffic Distribution System (TDS) to filter site visitors and redirect them to ClickFix lures [via EtherHiding]. ShinyHunters Extortion Campaign Targets Instructure —The ShinyHunters group targeted Instructure, the supplier of the Canvas learning management system (LMS), defacing the login portals for 330 colleges and universities. According to Dataminr, ShinyHunters has claimed to have exfiltrated 3.65TB of data across approximately 275 million records from nearly 9,000 affected organizations listed publicly, including Harvard, Stanford, Columbia, and Apple. Exposed data includes usernames, email addresses, course names, enrollment information, and messages. Instructure has said no passwords, government IDs, birth dates, financial data, or course content were compromised. The threat actors exploited a "vulnerability regarding support tickets in our Free for Teacher environment," the company added. Access to Free for Teacher has been disabled pending a full security review. As of writing, Canvas is fully back online and available for use. The message shared by the notorious cybercrime group showed that the group has threatened to leak the trove of data, giving a deadline of May 12. The May 7, 2026, incident is a continuation of prior unauthorized activity detected in Canvas on April 29, 2026. Following the hack, the U.S. Federal Bureau of Investigation (FBI) cautioned individuals to be on the lookout for "unsolicited emails, calls, or texts claiming to be from your school, the LMS provider, or law enforcement and to verify the contact through known channels before responding." 🔧 Cybersecurity Tools AiSOC → It is an open-source, self-hostable AI-powered Security Operations Center. It brings together security alerts, uses AI agents to investigate them, maps findings to MITRE ATT&CK, and supports purple team exercises and incident triage — all within a single stack that you can run on your own infrastructure. Watcher → is an open-source platform that helps security teams monitor and detect emerging cyber threats. It uses AI to analyze threat data, track suspicious domains, watch for information leaks, and follow cybersecurity news from official sources — all in one dashboard. Built with Django and React, it runs easily with Docker. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law. Conclusion That’s the week: poisoned downloads, cloud messes, old bugs refusing to die, and attackers putting in barely more effort than a guy restarting a frozen router. Everybody’s tired, nobody trusts installers anymore, and the internet somehow keeps getting worse in very predictable ways. See you next Monday, assuming nothing catches fire before then.
thehackernews.comMay 11, 2026extracted
⚡ Weekly Recap: Vercel Hack, Push Fraud, QEMU Abused, New Android RATs Emerge & More
Monday’s recap shows the same pattern in different places. A third-party tool becomes a way in, then leads to internal access. A trusted download path is briefly swapped to deliver malware. Browser extensions act normally while pulling data and running code. Even update channels are used to push payloads. It’s not breaking systems—it’s bending trust. There’s also a shift in how attacks run. Slower check-ins, multi-stage payloads, andmore code kept in memory. Attackers lean on real tools and normal workflows instead of custom builds. Some cases hint at supply-chain spread, where one weak link reaches further than expected. Go through the whole recap. The pattern across access, execution, and control only shows up when you see it all together. ⚡ Threat of the Week Vercel Discloses Data Breach—Web infrastructure provider Vercel has disclosed a security breach that allows bad actors to gain unauthorized access to "certain" internal Vercel systems. The incident originated from the compromise of Context.ai, a third-party artificial intelligence (AI) tool, which was used by an employee at the company, it added. "The attacker used that access to take over the employee's Vercel Google Workspace account, which enabled them to gain access to some Vercel environments and environment variables that were not marked as 'sensitive,'" the company said. It's currently not known who is behind the incident, but a threat actor using the ShinyHunters persona has claimed responsibility for the hack. Context.ai also disclosed a March 2026 incident involving unauthorized access to its AWS environment. However, it has since emerged that the attacker also likely compromised OAuth tokens for some of its consumer users. Furthermore, Hudson Rock uncovered that a Context.ai employee was compromised with Lumma Stealer in February 2026, raising the possibility that the infection may have triggered the "supply chain escalation." 99% of What AI Found Is Still Unpatched. See the Defensive Answer Anthropic's Mythos weaponized bugs that survived decades of human review. Atlassian's CISO, Frost & Sullivan, and leaders from Kraft Heinz and Glow Financial Services show how autonomous validation discovers what's exploitable, proves controls hold, and re-validates fixes. Register for Free ➝ 🔔 Top News Law Enforcement Operation Brings Down DDoS-for-Hire Operation—Law enforcement agencies across Europe, the U.S., and other partner nations cracked down on the commercial DDoS-for-hire ecosystem, targeting both operators and customers of services used to target websites and knock them offline. As part of the effort, authorities took down 53 domains, arrested four people, and sent warning notifications to thousands of criminal users. The U.S. Justice Department said court-authorized actions were undertaken to disrupt Vac Stresser and Mythical Stress. The actions are a persistent cat-and-mouse game, as booted services often reappear under new names and domains despite repeated takedowns. While these disruptions tend to have short-term results, the resilience of the criminal activity indicates that arrests need to be combined with infrastructure seizures, financial disruption, and user deterrence for lasting impact. Newly Discovered PowMix Botnet Hits Czech Workers—An active malicious campaign is targeting the workforce in the Czech Republic with a previously undocumented botnet dubbed PowMix since at least December 2025. "PowMix employs randomized command-and-control (C2) beaconing intervals, rather than persistent connection to the C2 server, to evade the network signature detections," Cisco Talos said. The never-before-seen botnet is designed to facilitate remote access, reconnaissance, and remote code execution, while establishing persistence by means of a scheduled task. At the same time, it verifies the process tree to ensure that another instance of the same malware is not running on the compromised host. AI-Driven Pushpaganda Exploits Google Discover to for Ad Fraud—A novel ad fraud scheme has been found to leverage search engine poisoning (SEO) techniques and artificial intelligence (AI)-generated content to push deceptive news stories into Google's Discover feed and trick users into enabling persistent browser notifications that lead to scareware and financial scams. The Pushpaganda campaign has been found to target the personalized content feeds of Android and Chrome users. "This operation, named for push notifications central to the scheme, generates invalid organic traffic from real mobile devices by tricking users into subscribing to enabling notifications that presented alarming messages," HUMAN Security said. Google has since rolled out fixes and algorithmic updates to address the issue. Obsidian Plugin Abuse Delivers PHANTOMPULSE RAT—A social engineering campaign has abused Obsidian, a cross-platform note-taking application, as an initial access vector to distribute a previously undocumented Windows remote access trojan called PHANTOMPULSE in attacks targeting individuals in the financial and cryptocurrency sectors. Elastic Security Labs is tracking the activity under the name REF6598. It employs elaborate social engineering tactics through LinkedIn and Telegram to breach both Windows and macOS systems by tricking victims into opening a cloud-hosted vault in Obsidian. PHANTOMPULSE is an artificial intelligence (AI)-generated backdoor that uses the Ethereum blockchain for resolving its C2 server. On macOS, the attack is used to deliver an unspecified payload. CPUID Downloads Hijacked to Serve STX RAT—Unknown threat actors hijacked the official CPUID download page to serve trojanized installers that ultimately led to the deployment of STX RAT, a remote access trojan with infostealer capabilities. The attack did not compromise CPUID's original signed binaries, the threat actors served their own trojanized packages via redirect. "The threat actor compromised the official CPUID download page to serve a trojanized package, employing DLL sideloading as the initial execution vector followed by a layered, five-stage in-memory unpacking chain designed to evade detection," Cyderes said. "The use of a timestomped compilation timestamp, reflective PE loading, and exclusively in-memory payload execution demonstrates a deliberate effort to hinder forensic analysis and bypass traditional security controls." 108 Malicious Chrome Extensions Steal Google and Telegram Data—A cluster of 108 Google Chrome extensions has been found to communicate with the same command-and-control (C2) infrastructure with the goal of collecting user data and enabling browser-level abuse by injecting ads and arbitrary JavaScript code into every web page visited. The extensions provide the expected functionality to avoid raising red flags, but malicious code running in the background connects to the threat actor's C2 server to perform the nefarious activities. At the center of the campaign is a backend hosted on a Contabo virtual private server (VPS), with multiple subdomains handling session hijacking, identity collection, command execution, and monetization operations. There is evidence indicating a Russian malware-as-a-service (MaaS) operation, based on the presence of a payment and monetization portal in its C2 infrastructure. OpenAI Launches GPT-5.4-Cyber—OpenAI announced a new model, GPT-5.4-Cyber, specifically designed for use by digital defenders. Artificial intelligence (AI) companies have repeatedly warned that more capable AI models could create an opening for bad actors to exploit vulnerabilities and security gaps in software with new speed and intensity. Unlike Anthropic, which said its new Claude Mythos model is only being privately released to a small number of trusted organizations due to concerns that it could be exploited by adversaries, OpenAI said "the class of safeguards in use today sufficiently reduce cyber risk enough to support broad deployment of current models," but hinted at the need for more advanced protections in the long term. Defending critical software has long depended on the ability to find and fix vulnerabilities faster than attackers can exploit them. GPT-5.4-Cyber has a lower refusal boundary for legitimate cybersecurity work than standard GPT-5.4. It adds capabilities aimed at advanced defensive workflows, including binary reverse engineering. "We don't think it's practical or appropriate to centrally decide who gets to defend themselves," OpenAI stated. "Instead, we aim to enable as many legitimate defenders as possible, with access grounded in verification, trust signals, and accountability." The use of AI for vulnerability discovery and analysis means that the barrier to entry for attackers is collapsing. Bad actors could ask an AI model to analyze differences between two versions of a binary and generate an exploit at a faster rate. Rob T. Lee, chief of research at the SANS Institute, said the debut of Mythos and GPT-5.4-Cyber is "nothing more than one vendor trying to one-up another," adding, "We need to start benchmarking how one AI model is able to find code vulnerabilities over another and how quickly they are doing it. There are real risks at stake here." At the same time, researchers from AISLE and Xint found that it's possible to replicate Mythos's results with smaller, cheaper models. "The critical variable in AI vulnerability discovery is not the model alone," Xint said. "It is the structured system that decides where to look, validates that findings are real and exploitable, eliminates false positives, and delivers actionable remediation." 🔥 Trending CVEs Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild. Check the list, patch what you have, and hit the ones marked urgent first — CVE-2026-20184 (Cisco Webex Services), CVE-2026-20147 (Cisco Identity Services Engine and ISE Passive Identity Connector), CVE-2026-20180, CVE-2026-20186 (Cisco Identity Services Engine), CVE-2026-33032 (nginx-ui), CVE-2026-32201 (Microsoft SharePoint Server), CVE-2026-27304 (Adobe ColdFusion), CVE-2026-39813, CVE-2026-39808 (Fortinet FortiSandbox), CVE-2026-40176, CVE-2026-40261 (Composer), CVE-2025-0520 (ShowDoc), CVE-2026-22039 (Kyverno), CVE-2026-27681 (SAP Business Planning and Consolidation and Business Warehouse),CVE-2026-34486, CVE-2026-29146 (Apache Tomcat), CVE-2026-40175 (Axios), CVE-2026-32196 (Microsoft Windows Admin Center), CVE-2026-20204 (Splunk Enterprise), CVE-2026-20205 (Splunk MCP Server) CVE-2026-6296, CVE-2026-6297, CVE-2026-6298, CVE-2026-6299, CVE-2026-6358, CVE-2026-5873 (Google Chrome), CVE-2026-34078 (Tails), CVE-2026-34622 (Adobe Acrobat Reader), CVE-2026-33413 (etcd), CVE-2026-1492 (User Registration & Membership plugin), CVE-2026-23818 (HPE Aruba Networking Private 5G Core On-Prem), CVE-2025-54236 (Magento), CVE-2026-26980 (Ghost CMS), CVE-2026-40478 (Thymeleaf), CVE-2026-41242 (protobufjs), CVE-2026-40871 (Mailcow), CVE-2026-5747 (AWS Firecracker), and CVE-2025-50892 (eudskacs.sys). 🎥 Cybersecurity Webinars The Force Awakens in AppSec: Rethinking Mythos & Organizational Defenses at AI Speed → This webinar explores how AI-powered hacking is making traditional security patching too slow to be effective. It focuses on the "patch gap"— the dangerous time between a bug being found and fixed—and offers a new way to prioritize vulnerabilities based on real-world risk. The session provides practical strategies for security leaders to defend against automated, high-speed attacks. The Rise of the Agent: Moving to Autonomous Exposure Validation → This webinar explores how "agentic" AI is changing security testing by using autonomous AI agents to simulate real-world attacks. Unlike traditional scanners, these tools continuously find and validate which security gaps are actually reachable by hackers. The session focuses on moving from slow, manual checks to automated exposure validation to stay ahead of AI-driven threats. 📰 Around the Cyber World Vect Partners with BreachForums and TeamPCP —Dataminr revealed that the Vect ransomware group has formalized partnerships with the BreachForums cybercrime marketplace and TeamPCP hacking group. The partnership will allow BreachForums members to deploy ransomware and will use the victims of TeamPCP's supply chain attacks to attack organizations that are in a vulnerable state. "Between the two partnerships, Vect will lower the barrier to entry for ransomware actors, incentivize group members to carry out attacks, and exploit pre-existing breaches to broaden impact," the company said. "The convergence of large-scale supply chain credential theft, a maturing RaaS operation, and mass dark web forum mobilization represents an unprecedented model of industrialized ransomware deployment." MuddyWater Targets Global Organizations via Microsoft Teams —The Iranian hacking group known as MuddyWater has been observed using targeted social engineering to approach targets via Microsoft Teams by masquerading as IT support staff to trick them into running a botnet malware called Tsundere (aka Dindoor). "A notable aspect of this intrusion was the abuse of Deno, a legitimate JavaScript and TypeScript runtime typically used for backend application development," CyberProof said. "The attacker leveraged deno.exe to execute a highly obfuscated, Base64‑encoded payload -- tracked as DINODANCE -- directly in memory, minimizing on-disk artifacts and complicating detection." Once decoded, the malware establishes C2 communications with a remote server, exfiltrating basic host metadata such as username, hostname, and operating system details. Multi-Stage Intrusion Drops Direct-Sys Loader and CGrabber Stealer —An attack chain involving ZIP archives distributed through GitHub user attachment URLs is abusing DLL side-loading to deliver a malware loader called Direct-Sys Loader, which performs anti-analysis checks and then drops CGrabber. The malware, for its part, avoids infecting machines running in the Commonwealth of Independent States (CIS) countries and collects browser credentials, crypto wallet data, password manager data, and a broad range of application artifacts. "By skipping execution on machines in those regions, they reduce the risk of attracting attention from local law enforcement and avoid targeting their own infrastructure or allies," Cyderes said. "The Direct-Sys Loader and CGrabber Stealer represent a cohesive, multi-stage, stealth-focused malware ecosystem engineered with advanced detection-evasion capabilities." Russian Hackers Target Ukrainian Agencies —Threat actors linked to Russia broke into more than 170 email accounts belonging to prosecutors and investigators across Ukraine in recent months," Reuters reported, citing data from Ctrl-Alt-Intel. The espionage activity also targeted officials in Romania, Greece, Bulgaria, and Serbia. Speaking to The Record, Ukraine's State Service of Special Communications and Information Protection (SSSCIP) confirmed that local government agencies were targeted in a long-running hacking campaign that it has been tracking since 2023, with the attacks weaponizing flaws in Roundcube webmail software to run malicious code as soon as a specially crafted message is opened. The campaign is believed to be the work of APT28 (aka Fancy Bear). Infostealer Lookup Services are Changing Cybercrime —Hudson Rock revealed that infostealer lookup services, some accessible via a simple search on Google, are rapidly fueling a new era of initial access, shifting how cyber attacks begin and transforming a complex hacking process into a simple, automated transaction. "These platforms have effectively turned billions of compromised credentials and active session cookies into a highly searchable, low-cost commodity available to the masses," it said. "Because this data is so easily accessible, organizations can no longer afford to be reactive." AdaptixC2 Detailed —Kaspersky has detailed the inner workings of an open-source command-and-control (C2) framework known as AdaptixC2, which has seen increased adoption by bad actors over the past year. Written in Go and C++, AdaptixC2 is designed for post-exploitation and stealthy interaction with its malicious agents deployed on compromised systems. It also employs diverse network communication and post-exploitation techniques to get around traffic monitoring tools and minimize its footprint. "Unlike many general-purpose C2 platforms, AdaptixC2 focuses on advanced agent-to-C2 communication and specific evasion techniques designed to bypass modern security tools, including EDR and NDR solutions," the company said. "The framework provides the flexibility to develop custom agents while also including standard agent implementations in Go and C++ for Windows, macOS, and Linux. Additionally, it supports a modular approach to extending its functionality." Adware Update Delivers EDR Killer —In an unusual attack, a browser-hijacking adware family rolled out a multi-phase update that attempted to disable security software on infected hosts. The adware is signed by Dragon Boss Solutions LLC, a U.A.E.-based company that claims to conduct search monetization research and has promoted modified versions of the Chrome browser (e.g., Chromstera, Chromnius, and Artificius). "The signed software silently fetches and executes payloads capable of killing antivirus products, all while running with SYSTEM privileges," Huntress said. The antivirus killing capability was observed starting in late March 2025, although the loader and updater components date back to late 2024. "The operation uses an off-the-shelf software update mechanism to deploy these MSI and PowerShell-based payloads. Establishing WMI persistence disables security applications and blocks reinstallation of protective software," it added. The MSI installer, downloaded from a fallback update server, performs reconnaissance, queries for installed security products, and runs a PowerShell script ("ClockRemoval.ps1") to terminate running processes, disable antivirus services by tampering with the Windows Registry, delete installation directories, and force deletion when uninstallers fail. What's significant is that the update mechanism can be modified to deploy any payload. To make matters worse, the primary update domain baked into the operation to retrieve the MSI installer – chromsterabrowser[.]com – was left unregistered, meaning any threat actor could have registered the domain for as little as $10 and push malicious updates, turning an adware infection into a potential supply chain compromise. The domain has since been sinkholed. That said, 23,565 unique IP addresses connected to the sinkhole during a 24-hour monitoring period. The infections are concentrated around the U.S., France, Canada, the U.K., and Germany. These included universities, OT networks, government entities, primary and secondary educational institutions, healthcare organizations, and multiple Fortune 500 companies. India Will Not Require Smartphone Makers to Preload Aadhaar App —The Indian government will no longer require smartphone makers like Apple and Samsung to preload devices with a state-owned biometric identification app, Reuters reported. India's IT ministry reviewed the proposal and "is not in favour of mandating the pre-installation of the Aadhaar App on smartphones," UIDAI said in a statement. The Aadhaar request was the sixth time in two years the government has sought pre-installation of state apps on phones, according to industry communications. Smartphone makers flagged concerns about device security and compatibility when they received the Aadhaar preload proposal, and also flagged higher production costs as they would have been required to run separate manufacturing lines for India and export markets. SQL Injection Campaign Targets Payment Services —An active SQL injection campaign is operating through attacker infrastructure located in Canada. The campaign has targeted 35 websites, with confirmed successful SQL injection exploitation and data exfiltration affecting three organizations operating in the payment, real estate, and developer service sectors. Attacker-side artifacts indicate coordinated and deliberate exploitation rather than opportunistic scanning. QEMU Abused for Defense Evasion —Threat actors are abusing QEMU, an open-source machine emulator and virtualizer, to hide malicious activity within virtualized environments. "Attackers are drawn to QEMU and more common hypervisor-based virtualization tools like Hyper-V, VirtualBox, and VMware because malicious activity within a virtual machine (VM) is essentially invisible to endpoint security controls and leaves little forensic evidence on the host itself," Sophos said. Two clusters of activity have been detected: STAC4713, which has used QEMU as a covert reverse SSH backdoor to deliver tooling and harvest domain credentials with the end goal of likely deploying Payouts King ransomware (likely tied to former BlackBasta affiliates) after obtaining initial access via exploitation of known security flaws in SolarWinds Web Help Desk, and STAC3725, which exploits Citrix Bleed 2 (aka CVE-2025-5777) for obtaining a foothold and installs ScreenConnect for persistent remote access. The threat actors then deploy a QEMU VM to install additional tools for conducting enumeration and credential theft. "Follow-on activity differed across intrusions, suggesting that initial access brokers originally compromised the victims’ environments and then sold the access to other threat actors," Sophos said. Fake Adobe Reader Site Drops ScreenConnect —Threat actors are using fake Adobe Acrobat Reader website lures to lure victims into installing ConnectWise's ScreenConnect. The attack chain was detected in February 2026. "The attack uses .NET reflection to keep payloads in memory only, which helps it evade signature-based defenses and hinder forensic examination," Zscaler ThreatLabz said. "A VBScript loader dynamically reconstructs strings and objects at runtime to defeat static analysis and sandboxing. Auto-elevated Component Object Model (COM) objects are abused to bypass User Account Control (UAC) and run with elevated privileges without user prompts." The attack employs an in-memory .NET loader that's responsible for launching ScreenConnect. Nearly 6M Hosts Use FTP —Censys said it observed about 5,949,954 hosts running at least one internet-facing FTP service, down from over 10.1 million in 2024, which amounts to a decline of 40% in two years. Of these, nearly 2.45 million hosts had no evidence of encryption. "Over 150,000 IIS FTP services return a 534 response, indicating TLS was never set up," Censys said. "For most use cases, FTP can be replaced without significant disruption. If FTP must remain, enabling Explicit TLS is a configuration change, not a protocol upgrade, and both Pure-FTPd and vsftpd support it natively." Malformed APKs Bypass Detections as New Android RATs Emerge —Threat actors are increasingly using malformed APKs, which refer to Android packages that can be installed and run on Android but are intentionally broken by using unsupported compression methods, header manipulation, or false password protection, to bypass static analysis tools and delay detection. Cleafy has released an open-source tool called Malfixer to detect and fix malformed APKs. The development comes as Zimperium flagged four new Android malware families, RecruitRat, SaferRat, Astrinox (aka Mirax), and Massiv, that are capable of harvesting sensitive information and facilitating unauthorized financial transactions. In all, campaigns distributing these malware families target over 800 applications across the banking, cryptocurrency, and social media sectors. RecruitRat leverages recruitment-related social engineering and fraudulent job-seeking platforms for initial access. SaferRat is distributed through fake websites that claim to offer free access to premium streaming platforms and legitimate video streaming software. All four banking trojans abuse the native Session Installation API to bypass Android's sideloading restrictions and request accessibility services permissions to carry out their malicious activities. Over 200 PrestaShop Stores Expose Installer —More than 200 PrestaShop online stores have left their installation folder exposed online, allowing attackers to abuse the behavior to overwrite database configuration, gain admin access, and execute arbitrary code on the server. According to Sansec, the affected stores span 27 countries, including France, Italy, Poland, and the Czech Republic. Another set of 15 stores has been found to expose the Symfony Profiler, which is enabled when PrestaShop runs in debug mode. How to Contain a Domain Compromise via Predictive Shielding —Microsoft detailed an attack chain in which a threat actor targeted a public sector organization in June 2025, methodically progressing from one state of the attack lifecycle to the next, starting with dropping a web shell following the exploitation of a file-upload flaw in an internet-facing Internet Information Services (IIS) server. The attacker then performed reconnaissance, escalated their privileges, leveraged the compromised IIS service account to reset the passwords of high-impact identities, and deployed Mimikatz to harvest credentials. Then, the threat actor abused privileged accounts and remotely created a scheduled task on a domain controller to capture NTDS snapshots. The attacker also planted a Godzilla web shell on the Exchange Server and leveraged their privileged context to alter mailbox permissions, allowing them to read and manipulate all mailbox contents. The threat actor subsequently used Impacket to enumerate the role assignments and other activities that were flagged and blocked by Microsoft Defender. "The threat actor then launched a broad password spray from the initially compromised IIS server, unlocking access to at least 14 servers through password reuse," Microsoft said. "They also attempted remote credential dumping against a couple of domain controllers and an additional IIS server using multiple domain and service principals." After Microsoft Defender's predictive shielding was enabled in late July 2025, the attacker's attempts to sign in to Microsoft Entra Connect servers were blocked. The campaign stopped on July 28, 2025. Cargo Theft Malware Actor Conducts Remote Access Campaigns —In November 2025, Proofpoint detailed a threat actor that used compromised load boards to gain access to trucking companies with the end goal of freight diversion and cargo theft. New research from the enterprise security company has revealed that the attacker abused multiple remote access tools like ScreenConnect, Pulseway, and SimpleHelp to establish persistence to a controlled decoy environment, with attempts made to identify financial access, payment platforms, and cryptocurrency assets to conduct freight fraud and broader financial theft. The actor maintained access for more than a month. At least one ScreenConnect instance is said to have leveraged a third‑party signing‑as‑a‑service provider to re-sign the installer with a valid but fraudulent code‑signing certificate. "This reconnaissance focused on identifying financial access – such as banking, accounting, tax software, and money transfer services – as well as transportation‑related entities, including fuel card services, fleet payment platforms, and load board operators," the company said. "The latter activity was likely designed to support crimes against the transportation industry, including cargo theft and related financial fraud." British National Pleads Guilty to Scattered Spider Campaign —Tyler Robert Buchanan, who was extradited from Spain to the U.S. last April following his arrest in the European nation in June 2024, pleaded guilty to hacking a dozen companies and stealing at least $8 million in digital assets. He pleaded guilty to one count of conspiracy to commit wire fraud and one count of aggravated identity theft. "From September 2021 to April 2023, Buchanan and other individuals conspired to conduct cyber intrusions and virtual currency thefts," the U.S. Justice Department said. "The victims and intended victims included interactive entertainment companies, telecommunications companies, technology companies, business process outsourcing (BPO) and information technology (IT) suppliers, cloud communications providers, virtual currency companies, and individuals." Buchanan and his co-conspirators conducted SMS phishing attacks targeting a victim company's employees, tricking them into clicking on bogus links that exfiltrated their credentials via a phishing kit to an online Telegram channel under their control. The stolen data was then used to access the accounts, gather confidential company information, and siphon millions of dollars' worth of virtual currency after conducting SIM swapping attacks. 🔧 Cybersecurity Tools Cirro → It is an open-source tool designed to help security experts find hidden risks in cloud environments. It works by collecting data about people, their permissions, and the digital resources they use, then turning that information into a visual map. By showing how these different pieces are connected, the tool makes it easier to spot "attack paths"—the step-by-step routes a hacker could take to move through a system and reach sensitive data. While it is currently focused on Azure, it is built to be flexible so users can add other platforms over time. Janus → It is an open-source tool designed to help security teams track technical failures during operations. It automatically pulls logs from command-and-control (C2) platforms like Mythic and Cobalt Strike to identify where tools failed or commands were blocked. By organizing these "friction points" into reports, Janus helps teams see exactly where their workflow slows down and what tasks need to be improved or automated. Disclaimer: This is strictly for research and learning. It hasn't been through a formal security audit, so don't just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you’re doing stays on the right side of the law. Conclusion That wraps this week’s recap. Most of it isn’t loud, but it shows how easy it is for trusted paths to turn into entry points and for normal activity to hide real access. Keep an eye on the basics. Check what you trust, watch how things run, and don’t ignore the small changes.
thehackernews.comApr 20, 2026extracted
China-linked hackers exploited Dell zero-day since 2024 (CVE-2026-22769)
China-linked hackers exploited Dell zero-day since 2024 (CVE-2026-22769) A suspected China-linked cyberespionage group has been covertly exploiting a critical zero-day flaw (CVE-2026-22769) in Dell’s RecoverPoint for Virtual Machines software since at least mid-2024, according to new research from Google’s threat intelligence team and Mandiant. The attackers deployed stealthy backdoors (BRICKSTORM and GRIMBOLT), a webshell (SLAYSTYLE) and maintained long-term access inside targeted networks. “Beyond the Dell appliance exploitation, Mandiant observed the actor employing novel tactics to pivot into VMware virtual infrastructure, including the creation of ‘Ghost NICs’ [i.e., Network Interface Cards] for stealthy network pivoting and the use of iptables for Single Packet Authorization (SPA),” the researchers shared on Tuesday. They tied the attacks to UNC6201, a suspected PRC-nexus threat cluster that shows “notable overlaps” with UNC5221, a Chinese threat actor that’s often conflated with Silk Typhoon (“although GTIG does not currently consider the two clusters to be the same.) Default credentials exposed Dell backup systems to compromise The analysts were unable to pinpoint how the attackers achieved initial access to affected systems, but UNC6201 is known to target edge appliances. (UNC5221 as well.) Mandiant incident responders discovered CVE-2026-22769 while investigating hacked Dell RecoverPoint systems inside a victim’s network, after they noticed the systems were communicating with hacker-controlled command and control servers associated with BRICKSTORM and GRIMBOLT backdoors. “During analysis of the appliances, analysts identified multiple web requests to an appliance prior to compromise using the username admin. These requests were directed to the installed Apache Tomcat Manager, used to deploy various components of the Dell RecoverPoint software, and resulted in the deployment of a malicious WAR file containing a SLAYSTYLE web shell,” they explained. “After analyzing various configuration files belonging to Tomcat Manager, we identified a set of hard-coded default credentials for the admin user in /home/kos/tomcat9/tomcat-users.xml. Using these credentials, a threat actor could authenticate to the Dell RecoverPoint Tomcat Manager, upload a malicious WAR file using the /manager/text/deploy endpoint, and then execute commands as root on the appliance.” The BRICKSTORM backdoor is a known threat, wielded by UNC5221 and related threat clusters, and deployed on appliances that do not support traditional endpoint detection and response (EDR) tools. This allows the attackers to keep their presence in target organizations’ networks quiet. According to Mandiant and GTIG, the GRIMBOLT backdoor is built in a way that turns it directly into machine code before it’s run, which makes it easier to run on small devices and harder to detect via static analysis. The attackers edited a legitimate shell script to launch the backdoor each time the script is run. “It’s unclear if the threat actor’s replacement of BRICKSTORM with GRIMBOLT was part of a pre-planned life cycle iteration by the threat actor or a reaction to incident response efforts led by Mandiant and other industry partners,” the analysts added. Remediation and investigation Dell has provided instructions on how to remediate CVE-2026-22769, and Mandiant and GTIG have provided indicators of compromise, outlined artifacts that point to Dell RecoverPoint compromise, and shared YARA rules for detecting the presence of the GRIMBOLT backdoor and the SLAYSTYLE webshell. Earlier this month, CISA revised its report on the BRICKSTORM backdoor with the latest indicators of compromise related to the threat. Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!
helpnetsecurity.comFeb 18, 2026extracted
Dell RecoverPoint for VMs Zero-Day CVE-2026-22769 Exploited Since Mid-2024
A maximum severity security vulnerability in Dell RecoverPoint for Virtual Machines has been exploited as a zero-day by a suspected China-nexus threat cluster dubbed UNC6201 since mid-2024, according to a new report from Google Mandiant and Google Threat Intelligence Group (GTIG). The activity involves the exploitation of CVE-2026-22769 (CVSS score: 10.0), a case of hard-coded credentials affecting versions prior to 6.0.3.1 HF1. Other products, including RecoverPoint Classic, are not vulnerable to the flaw. "This is considered critical as an unauthenticated remote attacker with knowledge of the hardcoded credential could potentially exploit this vulnerability, leading to unauthorized access to the underlying operating system and root-level persistence," Dell said in a bulletin released Tuesday. The issue impacts the following products - RecoverPoint for Virtual Machines Version 5.3 SP4 P1 - Migrate from RecoverPoint for Virtual Machines 5.3 SP4 P1 to 6.0 SP3, and then upgrade to 6.0.3.1 HF1 RecoverPoint for Virtual Machines Versions 6.0, 6.0 SP1, 6.0 SP1 P1, 6.0 SP1 P2, 6.0 SP2, 6.0 SP2 P1, 6.0 SP3, and 6.0 SP3 P1 - Upgrade to 6.0.3.1 HF1 RecoverPoint for Virtual Machines Versions 5.3 SP4, 5.3 SP3, 5.3 SP2, and earlier - Upgrade to version 5.3 SP4 P1 or a 6.x version, and then apply the necessary remediation "Dell recommends that RecoverPoint for Virtual Machines be deployed within a trusted, access-controlled internal network protected by appropriate firewalls and network segmentation," it noted. "RecoverPoint for Virtual Machines is not intended for use on untrusted or public networks." "We are aware of less than a dozen impacted organizations, but because the full scale of this campaign is unknown, we recommend that organizations previously targeted by BRICKSTORM look out for GRIMBOLT in their environments," Rich Reece, Manager, Mandiant Consulting at Google Cloud, told The Hacker News via email. Mandiant said it discovered CVE-2026-22769 earlier this year while investigating multiple Dell RecoverPoint for Virtual Machines within an unspecified victim's environment. "The actor is likely still active in unpatched and remediated environments, and because exploitation has been occurring since mid-2024, they have had significant time to establish persistence and carry out long-term espionage," Reece said. "We anticipate additional companies will find active or historic compromises as they begin hunting using the new IOCs/YARA rules we published." Per Google, the hard-coded credential relates to an "admin" user for the Apache Tomcat Manager instance that could be used authenticate to the Dell RecoverPoint Tomcat Manager, upload a web shell named SLAYSTYLE via the "/manager/text/deploy" endpoint, and execute commands as root on the appliance to drop the BRICKSTORM backdoor and its newer version dubbed GRIMBOLT. "This is a C# backdoor compiled using native ahead-of-time (AOT) compilation, making it harder to reverse engineer," Mandiant's Charles Carmakal added. Google told The Hacker News that the activity has targeted organizations across North America, with GRIMBOLT incorporating features to better evade detection and minimize forensic traces on infected hosts. "GRIMBOLT is even better at blending in with the system's own native files," it added. UNC6201 is also assessed to share overlaps with UNC5221, another China-nexus espionage cluster known for its exploitation of virtualization technologies and Ivanti zero-day vulnerabilities to distribute web shells and malware families like BEEFLUSH, BRICKSTORM, and ZIPLINE. Despite the tactical similarities, the two clusters are assessed to be distinct at this stage. It's worth noting that the use of BRICKSTORM has also been linked by CrowdStrike to a third China-aligned adversary tracked as Warp Panda (aka Clay Typhoon and Storm-2416) in attacks aimed at U.S. entities. A noteworthy aspect of the latest set of attacks revolves around UNC6201's reliance on temporary virtual network interfaces – referred to as "Ghost NICs" – to pivot from compromised virtual machines into internal or SaaS environments, and then delete those NICs to cover up the tracks in an effort to impede investigation efforts. "Consistent with the earlier BRICKSTORM campaign, UNC6201 continues to target appliances that typically lack traditional endpoint detection and response (EDR) agents to remain undetected for long periods," Google said. Exactly how initial access is obtained remains unclear, but like UNC5221, it's also known to target edge appliances to break into target networks. An analysis of the compromised VMware vCenter appliances has also uncovered iptable commands executed by means of the web shell to perform the following set of actions - Monitor incoming traffic on port 443 for a specific HEX string Add the source IP address of that traffic to a list and if the IP address is on the list and connects to port 10443, the connection is ACCEPTED Silently redirect subsequent traffic to port 443 to port 10443 for the next 300 seconds (five minutes) if the IP is on the approved list Furthermore, the threat actor has been found replacing old BRICKSTORM binaries with GRIMBOLT in September 2025. While GRIMBOLT also provides a remote shell capability and uses the same command-and-control (C2) as BRICKSTORM, it's not known what prompted the shift to the harder-to-detect malware, and whether it was a planned transition or a response to public disclosures about BRICKSTORM. "Nation-state threat actors continue targeting systems that don't commonly support EDR solutions, which makes it very hard for victim organizations to know they are compromised and significantly prolongs intrusion dwell times," Carmakal said. The disclosure comes as Dragos warned of attacks mounted by Chinese groups like Volt Typhoon (aka Voltzite) to compromise Sierra Wireless Airlink gateways located in electric and oil and gas sectors, followed by pivoting to engineering workstations to dump config and alarm data. The activity, according to the cybersecurity company, took place in July 2025. The hacking crew is said to acquire initial access from Sylvanite, which rapidly weaponizes edge device vulnerabilities before patches are applied and hands off access for deeper operational technology (OT) intrusions. "Voltzite moved beyond data exfiltration to direct manipulation of engineering workstations investigating what would trigger processes to stop," Dragos said. " This represents the removal of the last practical barrier between having access and causing physical consequences. Cellular gateways create unauthorized pathways into OT networks bypassing traditional security controls." Update The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on February 18, 2026, added CVE-2026-22769 to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patch by February 21, 2026. Update In a follow-up analysis published on March 5, 2026, Team Cymru shed more light on the C2 infrastructure associated with GRIMBOLT, using an X.509 certificate's subject field value for the IP address 149.248.11[.]71 – CN=WIN-DO6FVJH67FN – to uncover additional IP addresses using the same certificate: 140.82.18[.]134 and 66.42.111[.]219. "Analysis of these IP addresses revealed that they are also located on the same VPS provider (Vultr) due to their autonomous system number (ASN) being the same in their WHOIS records," security researcher Will Thomas said. "Furthermore, these two additional IP addresses both had the same 3389 (RDP) port open as well." "The overlap of a cryptographically identical X509 certificate, matching autonomous system (ASN) routing, and correlated open port profiles strongly indicates the use of cloned virtual machine images or an automated provisioning script by the threat actor on a single VPS provider, Vultr." (The story was updated after publication on March 6, 2026, with new insights from Team Cymru.)
thehackernews.comFeb 18, 2026extracted
HPE OneView Flaw Rated CVSS 10.0 Allows Unauthenticated Remote Code Execution
Hewlett Packard Enterprise (HPE) has resolved a maximum-severity security flaw in OneView Software that, if successfully exploited, could result in remote code execution. The critical vulnerability, assigned the CVE identifier CVE-2025-37164, carries a CVSS score of 10.0. HPE OneView is an IT infrastructure management software that streamlines IT operations and controls all systems via a centralized dashboard interface. "A potential security vulnerability has been identified in Hewlett Packard Enterprise OneView Software. This vulnerability could be exploited, allowing a remote unauthenticated user to perform remote code execution," HPE said in an advisory issued this week. It affects all versions of the software prior to version 11.00, which addresses the flaw. The company has also made available a hotfix that can be applied to OneView versions 5.20 through 10.20. It's worth noting that the hotfix must be reapplied after upgrading from version 6.60 or later to version 7.00.00, or after any HPE Synergy Composer reimaging operations. Separate hotfixes are available for the OneView virtual appliance and Synergy Composer2. Although HPE makes no mention of the flaw being exploited in the wild, it's essential that users apply the patches as soon as possible for optimal protection. Earlier this June, the company also released updates to fix eight vulnerabilities in its StoreOnce data backup and deduplication solution that could result in an authentication bypass and remote code execution. It also shipped OneView version 10.00 to remediate a number of known flaws in third-party components, such as Apache Tomcat and Apache HTTP Server.
thehackernews.comDec 18, 2025extracted
Zeroday Cloud hacking event awards $320,0000 for 11 zero days
The Zeroday Cloud hacking competition in London has awarded researchers $320,000 for demonstrating critical remote code execution vulnerabilities in components used in cloud infrastructure. The first hacking event focused on cloud systems, the competition is hosted by Wiz Research in partnership with Amazon Web Services, Microsoft, and Google Cloud. The researchers were successful in 85% of the hacking attempts across 13 hacking sessions, demonstrating 11 zero-day vulnerabilities. A blog post summarizing the event notes $200,000 was awarded during the first day for successful exploitation of issues in Redis, PostgreSQL, Grafana, and the Linux kernel. During the second day, researchers earned another $120,000, showing exploits in Redis, PostgreSQL, and MariaDB, the most popular databases used by cloud systems to store critical information (e.g., credentials, secrets, sensitive user information). The Linux kernel was compromised through a container escape flaw, which allowed attackers to break isolation between cloud tenants, undermining a core cloud security guarantee. Researchers at cybersecurity companies Zellic and DEVCORE were awarded $40,000 for their success. Artificial Intelligence was also a topic, with hacking attempts targeting the vLLM and Ollama models, which could have exposed private AI models, datasets, and prompts, but both attempts failed due to time exhaustion. The end of the first Zeroday Cloud competition found Team Xint Code crowned champion for successfully exploiting Redis, MariaDB, and PostgreSQL. For its three exploits, Team Xint Code received $90,000. Despite the positive outcome, the amount awarded is only a small fraction of the total prize pool of $4.5 million available for researchers showcasing exploits for various targets. The eligible categories and products that didn't see any exploits in the competition include AI (Ollama, vLLM, Nvidia Container Toolkit), Kubernetes, Docker, web servers (ngnix, Apache Tomcat, Envoy, Caddy), Apache Airflow, Jenkins, and GitLab CE. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comDec 17, 2025extracted
IBM Patches Over 100 Vulnerabilities
IBM this week announced fixes for more than 100 vulnerabilities across its products, including multiple critical-severity bugs. Most of them were in third-party dependencies. Storage Defender received patches for six critical-severity defects, all affecting third-party components in Data Protect (which is included in Storage Defender). The weaknesses could lead to denial-of-service (DoS) conditions, memory corruption, arbitrary file overwrite, and application crashes. Another critical-severity vulnerability was addressed in IBM Guardium Data Protection’s implementation of the Apache Tomcat server. The flaw, tracked as CVE-2025-48913, could lead to code execution. IBM also announced a fix for a critical-severity bug in the form-data library used in Maximo Application Suite, which could allow attackers to inject parameters in requests. Edge Data Collector received patches for a critical SQL injection defect in the Django web framework. IBM also fixed dozens of vulnerabilities in Observability with Instana (OnPrem), including critical bugs in Tomcat, libxml2, and WebKit that could lead to command execution, DoS conditions, process crashes, and other unexpected behavior. A critical-severity issue in the Corosync library was addressed with security updates for IBM Db2. The weakness could lead to a process crash or arbitrary code execution, if encryption is disabled or the attacker knows the encryption key. Multiple high- and medium-severity flaws were also patched across Content Collector, DataPower Operations Dashboard, License Metric Tool, Planning Analytics, Watsonx Subscription, InfoSphere Information Server, StreamSets, and Db2 for Linux, UNIX and Windows. Additional information on these vulnerabilities and the corresponding patches can be found on IBM’s security bulletins page. Related: Fortinet Patches Critical Authentication Bypass Vulnerabilities Related: Ivanti EPM Update Patches Critical Remote Code Execution Flaw Related: Microsoft Patches 57 Vulnerabilities, Three Zero-Days
securityweek.comDec 11, 2025extracted
SAP Patches Critical Vulnerabilities With December 2025 Security Updates
Enterprise software maker SAP on Tuesday announced the release of 14 new security notes as part of its December 2025 security patch day, including three that address critical-severity vulnerabilities. The first of the critical notes resolves CVE-2025-42880 (CVSS score of 9.9), which is described as a code injection in Solution Manager. Affecting a remote-enabled module of the product, the security defect exists because user input is improperly validated, allowing authenticated attackers to inject arbitrary code, SAP security firm Onapsis explains. The risk posed by the CVE, Pathlock security analyst Jonathan Stross says, is heightened by the central role Solution Manager has within enterprise environments, where it acts as a central operations and administration hub connected to other SAP systems. “In many SAP environments, it helps admins to manage updates and push software throughout the organization’s SAP landscape; therefore, it has many high-privileged users and provides critical access to other systems. This is why a successful exploitation of this vulnerability could potentially give an attacker administrative-level access to the entire SAP enterprise landscape,” Stross said. The second critical note in SAP’s December 2025 advisory deals with two bugs in the Apache Tomcat server used in Commerce Cloud, and has a CVSS score of 9.6. Tracked as CVE-2025-55754 and CVE-2025-55752, the flaws were publicly disclosed in October and addressed in Tomcat versions 11.0.11, 10.1.45, and 9.0.109. Both could be exploited for remote code execution (RCE). The third critical note released on this month’s SAP security patch day resolves CVE-2025-42928 (CVSS score of 9.1), a deserialization issue in jConnect SDK for Sybase Adaptive Server Enterprise (ASE). According to Onapsis, attackers could exploit the vulnerability by sending specially crafted input, leading to RCE. SAP’s December 2025 advisory also includes five security notes with a priority rating of ‘high’, including two that address denial of service (DoS) bugs in NetWeaver and Business Objects. The other three deal with an information leak issue in Web Dispatcher and Internet Communication Manager (ICM), a memory corruption bug in Web Dispatcher, ICM, and Content Server, and a missing authorization check flaw in SAP S/4 HANA Private Cloud. The remaining six security notes resolve medium-severity defects in NetWeaver, Application Server ABAP, SAPUI5, Enterprise Search for ABAP, and BusinessObjects. SAP makes no mention of any of these vulnerabilities being exploited in the wild. Users are advised to apply the patches as soon as possible. Related: SAP Patches Critical Flaws in SQL Anywhere Monitor, Solution Manager Related: SAP Patches Critical Vulnerabilities in NetWeaver, Print Service, SRM Related: SAP Patches Critical NetWeaver Vulnerabilities Related: Recent SAP S/4HANA Vulnerability Exploited in Attacks
securityweek.comDec 10, 2025extracted
Fortinet, Ivanti, and SAP Issue Urgent Patches for Authentication and Code Execution Flaws
Fortinet, Ivanti, and SAP have moved to address critical security flaws in their products that, if successfully exploited, could result in an authentication bypass and code execution. The Fortinet vulnerabilities affect FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager and relate to a case of improper verification of a cryptographic signature. They are tracked as CVE-2025-59718 and CVE-2025-59719 (CVSS scores: 9.8). "An Improper Verification of Cryptographic Signature vulnerability [CWE-347] in FortiOS, FortiWeb, FortiProxy, and FortiSwitchManager may allow an unauthenticated attacker to bypass the FortiCloud SSO login authentication via a crafted SAML message, if that feature is enabled on the device," Fortinet said in an advisory. The company, however, noted that the FortiCloud SSO login feature is not enabled in the default factory settings. FortiCloud SSO login is enabled when an administrator registers the device to FortiCare and has not disabled the toggle "Allow administrative login using FortiCloud SSO" in the registration page. To temporarily protect their systems against attacks exploiting these vulnerabilities, organizations are advised to disable the FortiCloud login feature (if enabled) until it can be updated. This can be done in two ways - Go to System -> Settings -> Switch "Allow administrative login using FortiCloud SSO" to Off Run the below command in the CLI - config system global set admin-forticloud-sso-login disable end Ivanti Releases Fix for Critical EPM Flaw Ivanti has also shipped updates to address four security flaws in Endpoint Manager (EPM), one of which is a critical severity bug in the EPM core and remote consoles. The vulnerability, assigned the CVE identifier CVE-2025-10573, carries a CVSS score of 9.6. "Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session," Ivanti said. Rapid7 security researcher Ryan Emmons, who discovered and reported the shortcoming on August 15, 2025, said it allows an attacker with unauthenticated access to the primary EPM web service to join fake managed endpoints to the EPM server so as to poison the administrator web dashboard with malicious JavaScript. "When an Ivanti EPM administrator views one of the poisoned dashboard interfaces during normal usage, that passive user interaction will trigger client-side JavaScript execution, resulting in the attacker gaining control of the administrator's session," Emmons said. Douglas McKee, director of vulnerability intelligence at Rapid7, said in a statement that CVE-2025-10573 represents a serious risk as it's trivial to exploit and can be done so by sending a fake device report to the server using a basic file format. "While the attack only fully executes when an administrator views the dashboard, this is a routine and necessary task for IT staff; consequently, the likelihood of triggering the exploit during normal operations is high, ultimately allowing the attacker to take control of the administrator's session," McKee added. Ensar Seker, CISO at threat intelligence company SOCRadar, also emphasized that the user interaction requirement doesn't reduce the vulnerability's threat level and that it has a "significant" exploitation potential when combined with social engineering. "Remote code execution via JavaScript injection is no longer theoretical in supply chain attacks; it’s become operationally viable," Seker said. "Organizations must act swiftly to patch, and more importantly, implement rigorous user interface sanitization and privilege segmentation." The company noted that user interaction is required to exploit the flaw and that it's not aware of any attacks in the wild. It has been patched in EPM version 2024 SU4 SR1. Also patched in the same version are three other high-severity vulnerabilities (CVE-2025-13659, CVE-2025-13661, and CVE-2025-13662) that could allow a remote, unauthenticated attacker to achieve arbitrary code execution. CVE-2025-13662, like in the case of CVE-2025-59718 and CVE-2025-59719, stems from improper verification of cryptographic signatures in the patch management component. SAP Fixes Three Critical Flaws Lastly, SAP has pushed December security updates to address 14 vulnerabilities across multiple products, including three critical-severity flaws. They are listed below - CVE-2025-42880 (CVSS score: 9.9) - A code injection vulnerability in SAP Solution Manager CVE-2025-55754 (CVSS score: 9.6) - Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud CVE-2025-42928 (CVSS score: 9.1) - A deserialization vulnerability in SAP jConnect SDK for Sybase Adaptive Server Enterprise (ASE) Boston-based SAP security platform Onapsis has been credited with reporting CVE-2025-42880 and CVE-2025-42928. The company said it identified a remote-enabled function module in SAP Solution Manager that enables an authenticated attacker to inject arbitrary code. "Given the central role of SAP Solution Manager in the SAP system landscape, we strongly recommend a timely patch," Onapsis security researcher Thomas Fritsch said. CVE-2025-42928, on the other hand, allows for remote code execution by providing specially crafted input to the SAP jConnect SDK component. However, a successful exploitation requires elevated privileges. With security vulnerabilities in Fortinet, Ivanti, and SAP's software frequently exploited by bad actors, it's essential that users move quickly to apply the fixes.
thehackernews.comDec 10, 2025extracted
SAP fixes three critical vulnerabilities across multiple products
SAP has released its December security updates addressing 14 vulnerabilities across a range of products, including three critical-severity flaws. The most severe (CVSS score: 9.9) of all the issues is CVE-2025-42880, a code injection problem impacting SAP Solution Manager ST 720. "Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module," reads the flaw's description. "This could provide the attacker with full control of the system, hence leading to high impact on confidentiality, integrity, and availability of the system." SAP Solution Manager is the vendor's central lifecycle management and monitoring platform used by enterprises for system monitoring, technical configuration, incident and service desk, documentation hub, and test management. The next most severe flaw SAP fixed this month concerns multiple Apache Tomcat vulnerabilities impacting SAP Commerce Cloud components in versions HY_COM 2205, COM_CLOUD 2211, and COM_CLOUD 2211-JDK21. The flaws are tracked in SAP Commerce Cloud under a single identifier, CVE-2025-55754, given a CVSS severity rating of 9.6. SAP Commerce Cloud is an enterprise-grade e-commerce platform backing large-scale online stores with product catalogs, pricing, promotions, checkout, order management, customer accounts, and ERP/CRM integration. It is generally used by large retailers and global brands. The third critical (CVSS score: 9.1) flaw fixed this month is CVE-2025-42928, a deserialization vulnerability impacting SAP jConnect, which, under certain conditions, could allow a high-privileged user to achieve remote code execution on the target via specially crafted input. SAP jConnect is a JDBC driver used by developers and database administrators to connect Java applications to SAP ASE and SAP SQL Anywhere databases. SAP's December 2025 bulletin also lists fixes for five high-severity flaws and six medium-severity issues, including memory corruption, missing authentication and authorization checks, cross-site scripting, and information disclosure. SAP solutions are deeply embedded in enterprise environments and manage sensitive, high-value workloads, making them a valuable target for attackers. Earlier this year, SecurityBridge researchers observed in-the-wild attacks abusing a code-injection flaw (CVE-2025-42957) impacting SAP S/4HANA, Business One, and NetWeaver deployments. SAP has not marked any of the 14 flaws as actively exploited in the wild, but administrators should deploy the fixes without delay. Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comDec 9, 2025extracted
Vulnerabilità in Apache Tomcat: aggiornare subito per evitare rischi sicurezza
Betti RHC, la prima graphic novel al mondo dedicata alla cybersecurity awareness, ha finalmente il suo sito ufficiale. Uno spazio tutto suo dove scoprire il progetto, sfogliare le copertine degli episodi e immergersi nel mondo di Betti: la giovane laureanda in informatica che, dopo la morte misteriosa del padre, si trasforma nell'hacker più potente del mondo. Una storia avvincente che, episodio dopo episodio, affronta una minaccia digitale diversa — dal phishing al ransomware, fino al cyberbullismo — e insegna a riconoscerla e a difendersi, senza che sembri mai una lezione. Sul sito trovate tutto ciò che rende Betti un progetto diverso dal solito: la sua filosofia, le anteprime delle tavole e il racconto di come nasce ogni volume. Perché dietro Betti RHC c'è solo lavoro umano: ogni tavola è disegnata interamente a mano dagli artisti del Gruppo Arte di Red Hot Cyber, senza alcun uso di intelligenza artificiale. E a garantire che ogni storia sia realistica e tecnicamente corretta c'è la supervisione degli hacker etici del gruppo HackerHood, che mantengono il racconto fedele al mondo reale della sicurezza informatica. C'è spazio anche per le aziende, che possono usare Betti come strumento di awareness diverso dai soliti corsi: acquistare i volumi, personalizzarli con il proprio brand o sponsorizzare nuovi episodi. E come primo regalo, l'episodio "Byte the Silence", dedicato al cyberbullismo, è scaricabile gratuitamente per uso personale. Perché la miglior difesa, in fondo, è una bella storia. 👉 Scopri tutto su https://betti.redhotcyber.com/
redhotcyber.comOct 28, 2025extracted
Zeroday Cloud hacking contest offers $4.5 million in bounties
A new hacking competition called Zeroday Cloud, focused on open-source cloud and AI tools, announced a total prize pool of $4.5 million in bug bounties for researchers that submit exploits for various targets. The contest is launched by the research arm of cloud security company Wiz in partnership with Google Cloud, AWS, and Microsoft, and is scheduled for December 10 and 11 at the Black Hat Europe conference in London, UK. Zeroday Cloud has six separate categories researchers can participate in, with bug bounties between $10,000 and $300,000: AI – Ollama ($25k), Vllm ($25k), Nvidia Container Toolkit ($40k) Kubernetes and Cloud-Native – Kubernetes API Server ($80k), Kubelet Server ($40k), Grafana ($10k auth RCE, $40k pre-auth RCE), Prometheus ($40k), Fluent Bit ($10k) Containers and Virtualization – Docker ($40 user-provided image, $60k arbitrary image), Containerd ($40 user-provided image, $60k arbitrary image), Linux Kernel ($30k container escape on Ubuntu) Web Servers – nginx ($300k), Apache Tomcat ($100k), Envoy ($50k), Caddy ($50k) Databases – Redis ($25k auth RCE, $100k pre-auth RCE), PostgreSQL ($20k auth RCE, $100k pre-auth RCE), MariaDB ($20k auth RCE, $100k pre-auth RCE) DevOps & Automation – Apache Airflow ($40k), Jenkins ($40k), GitLab CE ($40k) The rules of the competition say that submitted exploits should result in complete compromise of the target. Wiz explains that this means "a full Container/VM Escape for the Virtualization category, and a 0-click Remote Code Execution (RCE) vulnerability for other targets." The organizers also provide the conditions for each target, as well as the instructions and technical resources (Docker container with target on default configuration) security researchers can use to test their exploits. Researchers who register through the HackerOne platform and complete their ID verification and Tax Forms by November 20, are free to submit exploits for as many targets as they like, but they are limited to only one entry per target. Submitters of approved exploits will be invited to demonstrate them live during the event, either alone or in a team of up to five members. People residing in embargoed or sanctioned countries such as Russia, China, Iran, North Korea, Cuba, Sudan, Syria, Libya, Lebanon, and also the regions of Crimea and Donetsk, are restricted from participating in the Zeroday Cloud contest. The complete rules for the zeroday.cloud hacking competition are available here. The announcement for the event, however, did not resonate well with the organizers of the Pwn2Own hacking competitions that have been going with great success for several years. In a public post, Trend Micro called out Wiz for copying the rules for Pwn2Own Ireland. Juan Pablo Castro, Director of Cybersecurity Strategy & Technology at Trend Micro, said that Gemini's output when comparing the rules for the two events were a "word-for-word" copy. Wiz responded with a defusing statement, admitting that the Pwn2Own rulebook was "a trusted, mature framework by which we were inspired." Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply. The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments. Get the report
bleepingcomputer.comOct 6, 2025extracted
Loading 11 more…