🚨 ACTIVE EXPLOITS & INCIDENTS
-
CISA warns admins to patch actively exploited SharePoint flaws — BleepingComputer
CISA alerts that threat actors are actively exploiting three critical vulnerabilities in Internet-exposed on-premises SharePoint Server instances. Immediate patching is strongly advised to prevent unauthorized access and data compromise. -
Progress Confirms Zero-Day Vulnerability Behind ShareFile Disruption — SecurityWeek
Progress has confirmed a zero-day exploited in the wild that caused outages in ShareFile Storage Zones Controller. A patch is now available and customers are urged to apply it immediately to restore service and block ongoing attacks.
🔓 VULNERABILITIES & CVEs
-
Joomla Extension 4Analytics - Unauthenticated Stored XSS (CVE-2026-58077) — CVE ThreatInt
An unauthenticated stored XSS vulnerability in 4Analytics <5 could allow website takeover via specially crafted requests. Exploitation risk is high due to lack of authentication requirements. -
Joomla Extension 4Analytics - Unauthenticated Stored XSS in AI Analysis Feature (CVE-2026-57833) — CVE ThreatInt
Another unauthenticated stored XSS affecting the AI analysis feature of 4Analytics <5. This vulnerability enables remote code injection vectors without user authentication, increasing risk of site compromise.
📋 VENDOR BULLETINS & ADVISORIES
- ICS Patch Tuesday: Vulnerabilities Fixed by Siemens, Schneider, Rockwell — SecurityWeek
Siemens, Schneider Electric, and Rockwell Automation released patches addressing dozens of vulnerabilities in ICS products. CISA and VDE CERT also issued advisories; immediate review and patching recommended for critical infrastructure operators.
🕵️ THREAT RESEARCH & DEEP DIVES
- Compromised AsyncAPI npm Packages Deliver Multi-Stage Botnet Malware — The Hacker News
Four npm packages in the @asyncapi namespace were compromised to distribute a multi-stage botnet loader. Affected versions include@asyncapi/generator-helpers@1.1.1,@asyncapi/generator-components@0.7.1,@asyncapi/generator@3.3.1, and@asyncapi/specs(v6.11.2 and v6.11.2-alpha.1). Developers should audit dependencies and remove these packages immediately.