π¨ ACTIVE EXPLOITS & INCIDENTS
-
Massive Supply Chain Attack Hits Nichirei Logistics, Japan β @metacurity
A cyberattack on Nichirei, a frozen foods logistics company, has escalated into a widespread supply chain incident impacting grocery stores nationwide, beyond initial targets like KFC and Pocky manufacturers. This disruption highlights risks in food supply chain IT infrastructure and third-party vendor security. -
Scattered Spider TfL Hackers Sentenced to 5.5 Years β @metacurity
UKβs National Crime Agency sentenced members of the Scattered Spider group responsible for the largest-ever UK cybercrime against Transport for London. This marks a significant law enforcement milestone in disrupting financially motivated ransomware and credential theft gangs.
π VULNERABILITIES & CVEs
-
HCL DFXServer Broken Authentication (CVE-2026-35147) β CVE ThreatInt
Critical broken authentication flaw via direct API access allows attackers to bypass user verification on specific endpoints. CVSS likely high; immediate patching or mitigation advised for affected HCL DFXServer deployments. -
HCL DFXServer Authentication Bypass via Server Response Manipulation (CVE-2026-35149) β CVE ThreatInt
An attacker can intercept and alter server responses to bypass authentication controls, enabling unauthorized access without credentials. This vulnerability compounds risks in HCL DFXServer environments. -
HCL DFXServer Missing Access Control (CVE-2026-35148) β CVE ThreatInt
Certain API endpoints are accessible without authentication in alternate browsers, exposing sensitive functions to unauthorized users. Urgent review of access controls recommended. -
HCL DFXServer Unencrypted Communication (CVE-2026-35146) β CVE ThreatInt
The application permits HTTP connections without encryption, risking interception of sensitive data and session hijacking. Enforce TLS-only communication to mitigate exposure. -
ASUS bsitf.sys Arbitrary Physical Memory Mapping 0-day (CVE-2026-13585) β r/cybersecurity
Public PoC released for a zero-day allowing arbitrary physical memory mapping, enabling privilege escalation on affected ASUS devices. Immediate mitigation and patching critical to prevent local kernel-level exploits.
π VENDOR BULLETINS & ADVISORIES
- Trend Micro, Tanium, ESET, and Tenable Patch Severe Vulnerabilities β r/cybersecurity
Multiple cybersecurity vendors have released urgent patches addressing critical product vulnerabilities this month. Organizations using these products should prioritize updates to reduce exposure to active exploits.
π° LESSER-KNOWN / UNDER-REPORTED
-
Data Breach Exposes Files from Indiaβs Largest Nuclear Power Plant Kudankulam β r/cybersecurity
Sensitive files related to Kudankulam nuclear power plant were exposed in a recent data breach. The scope and impact remain under investigation, but this raises significant concerns about critical infrastructure security in India. -
macOS Lockscreen Inconsistencies May Indicate Compromise β r/cybersecurity
Reports of unusual macOS lockscreen behavior post-update, including inconsistent password prompts and avatar anomalies, suggest possible local compromise or malware presence on M1 MacBook Pros. Recommended to audit device integrity and monitor for persistence. -
Moroccan Intelligence Insider Discloses Widespread Pegasus Use β r/cybersecurity
An insider leak reveals extensive deployment of Pegasus spyware by Moroccan intelligence, underscoring ongoing risks of state-sponsored surveillance tools in regional geopolitical contexts.