๐จ ACTIVE EXPLOITATION
-
INC Ransomware Exploits Two SonicWall SMA1000 Zero-Days INC Ransomware is exploiting two SonicWall SMA1000 zero-days.
- SonicWall SMA1000 appliances, including models 6210, 7210, 8200v and CMS, are affected.
- CVE-2026-15409 enables unauthenticated WebSocket tunneling; CVE-2026-15410 escalates privileges to root.
- Attackers chain the flaws to compromise VPN appliances and pivot into internal networks.
- Observed tooling includes the KNUCKLEBALL Python script, Suo5 HTTP proxy and ORANGETAIL web shell.
- Post-compromise activity includes theft of credentials, session databases and TOTP MFA seeds. ๐ Source: resecurity.com ยท ๐ Coverage: securityweek.com ยท ๐ via BleepingComputer
-
UPDATE: Attackers Exploit Critical Progress LoadMaster Command-Injection Flaw
CVE-2026-8037Attackers are exploiting CVE-2026-8037 in Progress LoadMaster appliances.- Progress Kemp LoadMaster and ADC products, plus affected MOVEit WAF deployments, are impacted.
- CVE-2026-8037 is a critical OS command-injection flaw affecting GA 7.2.63.1 and earlier and LTSF 7.2.54.17 and earlier.
- Unauthenticated attackers exploit unsanitized API input in multiple command endpoints to execute arbitrary commands as root.
- Exploitation targets the apiuser parameter at the /accessv2 endpoint through the vulnerable escape_quotes() function.
- KEVIntel recorded 792 attempts from 65 IP addresses across 18 countries; observed IPs include 192.42.116[.]58, 192.42.116[.]105, and 146.70.139[.]154. ๐ Source: kevintel.com ยท ๐ Coverage: securityweek.com ยท ๐ via Cyber Security News
๐ฅ BREACHES & INCIDENTS
(no items)
๐ CVEs & KEV
- CVE-2026-10090 โ CVSS 9.9 โ Red Hat ACM Privilege Escalation Vulnerability Lets Attackers Gain Full Cluster-Admin Access
- CVE-2026-72761 โ CVSS 6.9 โ Webhook SSRF guard bypassed by IPv6 transition addresses (NAT64/6to4/Teredo p...
- CVE-2026-72759 โ CVSS 6.9 โ cti-transmute Conversion History Authorization Bypass Leads to Sensitive Data...
- CVE-2026-71959 โ CVSS 6.9 โ Bitwarden Server before 2026.7.2 Audit Log Injection via POST /collectBitwarden Se...
- CVE-2026-16742 โ CVSS 6.7 โ systemd-homed: local privilege escalation via missing home-record signature v...
๐ต๏ธ RESEARCH & DEEP DIVES
-
UPDATE: Kimsuky Builds Local AI Toolkit for Phishing and Malware Development Kimsuky has built local AI tooling to support phishing and malware development.
- Kimsuky targets diplomatic missions and military, security, and virtual asset sectors.
- The group uses local Ollama, GPT4All, and Msty LLM environments with RAG and Cursor for stolen-data analysis, malware development, and attack automation.
- AI-generated finance and cryptocurrency decoys imitate legitimate investment and workplace documents.
- Spear-phishing emails deliver ZIP archives containing malicious LNK files that launch obfuscated PowerShell loaders.
- GitHub and GitLab repositories provide C2 and distribution for encrypted AsyncRAT payloads. ๐ Source: beritaharian.sg ยท ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News, @metacurity@infosec.exchange
-
Windows WalletService flaw enables SYSTEM escalation; public PoC released
CVE-2026-49176A Windows WalletService flaw allows local attackers to gain SYSTEM privileges.- Windows endpoints and servers using WalletService are affected by CVE-2026-49176.
- The flaw is an elevation-of-privilege issue caused by improper privilege management.
- A local authenticated attacker can manipulate the user-controlled Wallet database path.
- ESE processes attacker-controlled callback data, enabling WalletService to load a malicious DLL as LocalSystem.
- The PoC was tested on Windows 11 25H2 build 26200.8737. ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
-
Fake GoogleTranslate Chrome Extension Enables Hidden Browser Takeover A malicious Chrome extension can let attackers remotely control victims' browsers.
- Chrome users who install the fraudulent GoogleTranslate extension are affected.
- The extension steals browsing history, bookmarks, cookies, credentials, and extension details.
- Attackers can live-stream Chrome sessions and remotely click, type, and submit forms in hidden windows.
- A suspected Rust-based loader drops the extension and an AutoIt script that deploys Stealcv2.
- The extension supports proxy configuration and JavaScript injection into selected websites. ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ ADVISORIES
- Cisco Warns of High-Severity ClamAV Flaws With Public PoC
Cisco disclosed high-severity ClamAV vulnerabilities with public proof-of-concept code.
- Cisco Secure Endpoint Connectors for Windows, Linux, and Mac are affected.
- Seven ClamAV vulnerabilities can disrupt malware scanning and cause denial-of-service conditions.
- Remote unauthenticated attackers can submit specially crafted files to vulnerable ZIP, PESpin, GPT, PDF, Mach-O, and XAR parsers.
- Public proof-of-concept code exists for CVE-2026-20337 and CVE-2026-20338; no in-the-wild exploitation is known. ๐ Source: sec.cloudapps.cisco.com ยท ๐ [Coverage: securityweek.com](https://www.securityweek.com/cisco-warns-of-high-severity