2026-10-09 17:17 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-09 17:25 UTC
Threat actors are exploiting one critical and one medium-severity vulnerability still unpatched in the AhsayCBS backup management platform to deploy webshells and cryptocurrency miners. [...]
P0
2026-10-09 12:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 14:35 UTC
Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below - CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java"
P5
2026-10-09 12:21 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 12:55 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, following their abuse by a China-linked threat actor known as Flax Typhoon. The vulnerabilities in question are listed below - CVE-2015-3306 (CVSS score: 10.0) - An improper access control vulnerability in ProFTPD that could allow
P35
2026-10-08 20:00 UTC
Security Journalism
Huntress · indexed 2026-10-09 07:50 UTC
Threat actors are exploiting AhsayCBS flaws, including CVE-2026-105133 and CVE-2026-105134, to deploy webshells and XMRig cryptominers. Update to 10.3.4 and restrict access now.
P5
2026-10-08 15:26 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 15:40 UTC
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware has been put to use in attacks targeting Ukrainian government personnel. The cybersecurity company is tracking the cluster under the name Earth Sirrush (previously SHADOW-EARTH-065). ASHVEIN,
P0
2026-10-08 14:04 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-08 14:10 UTC
Threat actors have started targeting CVE-2026-21589, a critical vulnerability in Atlassian’s self-hosted Data Center products. The post Attackers Target Critical Atlassian Vulnerability Within Hours of PoC Publication appeared first on SecurityWeek.
P15
2026-10-08 07:26 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-08 08:10 UTC
Threat actors are exploiting CVE-2026-21589, a critical Atlassian flaw that can expose sensitive files across multiple Data Center products. Threat actors have started exploiting CVE-2026-21589 (CVSS score of 9.3), a critical arbitrary file access flaw in Atlassian Data Center products. The vulnerability could allow attackers to access sensitive files under certain conditions. Affected products include […]
P5
2026-10-07 22:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Eyal Rafian · indexed 2026-10-07 22:10 UTC
Unit 42 details how threat actors leverage Web3 infrastructure and open-source supply chain attacks to breach enterprise cloud environments The post Evolution of Web3 in Cloud Supply Chain Attacks appeared first on Unit 42.
P0
2026-10-07 17:43 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 17:55 UTC
Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK and Checkmarx. The activity is assessed to be the work of a lone threat actor who appears to have published 12 packages since August 2023, eight of which have
P0
2026-10-07 11:49 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-07 12:20 UTC
Threat actors have begun to exploit a newly disclosed critical security flaw impacting Atlassian Data Center products that could allow access to sensitive files under certain conditions. The arbitrary file access flaw, tracked as CVE-2026-21589 (CVSS score: 9.3) affects multiple products, including Bitbucket Data Center, Confluence Data Center, Jira Service Management Data Center, Jira Software
P5
2026-10-06 20:32 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-10-06 20:50 UTC
Threat actors are now hiding payloads by using DNS TXT records and browser cache pre-fetching, making it tougher to spot early attack stages.
P0
2026-10-06 18:24 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 20:15 UTC
Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name their malicious software after a legitimate operating system component or a process as a defense evasion measure. By borrowing the name of a real binary, it may
P0
2026-10-06 13:16 UTC
Community
SANS Internet Storm Center · indexed 2026-10-06 09:55 UTC
It seems that a trend started… I continue my journey discovering more RMM ("Remote Management & Monitoring") tools abused by threat actors! A few days ago, I wrote a diary[1] about ScreenConnect used in the wild. Today, I found another one.
P20
2026-10-05 11:46 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 13:20 UTC
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report
P0
2026-10-03 14:36 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-03 15:25 UTC
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure, government, and education organizations. "In the
P15
2026-10-02 17:33 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-02 17:45 UTC
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar, involves the deployment of a previously undocumented backdoor codenamed Antino. Cisco Talos is tracking the cluster
P0
2026-10-01 19:32 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-10-01 19:40 UTC
Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. [...]
P0
2026-10-01 14:37 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 14:50 UTC
Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed SC after the "SC_" markers present in the injected content. Sucuri has described the malware as a "self-healing mesh" that's
P0
2026-10-01 13:00 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-10-01 13:00 UTC
A year-old Chinese threat actor looks like a cybercrime gang, acts like a state-associated APT, and attacks organizations in unexpected places.
P15
2026-10-01 05:32 UTC
Community
SANS Internet Storm Center · indexed 2026-10-01 05:50 UTC
Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing applications...
P0
2026-10-01 04:35 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 04:45 UTC
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler
P0
2026-09-30 21:25 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-30 21:40 UTC
In yet another ClickFix-style campaign, threat actors abuse legitimate domains from OpenAI and Google to fool unsuspecting users.
P0
2026-09-30 16:46 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 17:55 UTC
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol
P20
2026-09-30 15:00 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 15:30 UTC
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared
P0
2026-09-30 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-30 14:45 UTC
Written by: Robin Grunewald, Supriya Mazumdar, Kelli Vanderlee Introduction Google Threat Intelligence Group (GTIG) examines vulnerability disclosure and exploitation statistics to evaluate the impact of artificial intelligence (AI) on the vulnerability threat landscape. We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered. Key findings: Vulnerability discl…
P60
2026-09-30 09:14 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-30 10:10 UTC
Threat actors abused fake ChatGPT Custom GPTs and ClickFix to deliver a multi-stage RAT. ChatGPT’s Custom GPT feature is the latest legitimate surface being turned into a delivery mechanism, and Huntress researchers caught it in action across at least 40 incidents. A Custom GPT (now simply called a GPT) is essentially a version of ChatGPT […]
P0
2026-09-30 08:24 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 09:55 UTC
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional
P0
2026-09-30 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-30 13:10 UTC
Huntress SOC found a threat actor exploiting a file upload flaw in recreation management to breach 3 municipal servers and steal payment data.
P0
2026-09-29 15:00 UTC
Vendor Research
Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-09-29 15:35 UTC
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”. The post Star Blizzard refines phishing and malware delivery with the RedFlick technique appeared first on Microsoft Security Blog.
P0
2026-09-29 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-29 14:00 UTC
Introduction In late September 2026, Mandiant Consulting and Google Threat Intelligence Group (GTIG) identified active, in-the-wild exploitation of a zero-day vulnerability (CVE-2026-88772) affecting Citrix NetScaler ADC and NetScaler Gateway appliances. We have observed evidence that organizations in North America and Europe in the government, financial services, technology, education, and legal and professional services sectors were likely impacted by this exploitation campaign, which has bee…
P30