๐ฅ BREACHES & INCIDENTS
- Troy Hunt Weekly Update 516 Covers ShinyHunters and New Breaches
Troy Hunt's weekly roundup covers ShinyHunters and breaches at Inter-Con Security, Exact Sciences and Brinks Home.
- The roundup applies to customers and employees of Inter-Con Security, Exact Sciences and Brinks Home.
- ShinyHunters is reportedly ramping up activity again.
- Brinks Home's incident involved data exposure and criminal extortion.
- The discussed attack pattern uses vishing to obtain OAuth access before data theft and extortion. ๐ Coverage: troyhunt.com ยท ๐ via @troyhunt@infosec.exchange (+1)
๐ต๏ธ RESEARCH & DEEP DIVES
- SANS ISC Tests Gemma4 for DShield Malware Hash Analysis
SANS ISC is testing Gemma4 to analyze malware hashes collected by DShield sensors.
- The analysis covers malware hashes uploaded by DShield sensors over the previous 30 days.
- SANS ISC used the Gemma4:e4b model through Ollama.
- The results were compared with data from VirusTotal and CyberGordon. ๐ Coverage: isc.sans.edu ยท ๐ via SANS ISC
๐ CVEs & KEV
- CVE-2026-49819 โ CVSS 9.8 โ UpSnap - Unauthenticated Initial-Superuser Takeover Chains to Root RCE via wa...
- CVE-2026-49481 โ CVSS 9.6 โ UpSnap vulnerable to Remote Code Execution via IP Field Template Injection in...
- CVE-2026-71193 โ CVSS 9.6 โ In OpenStack Designate before 22.0.1, zone creation checks (_is_subzone, is...
- CVE-2026-19001 โ CVSS 9.5 โ MongoDB BI Connector ODBC Driver Critical RCE
- CVE-2026-49473 โ CVSS 8.8 โ @cedar-policy/authorization-for-expressjs has an authorization bypass via que...
- CVE-2026-47717 โ CVSS 7.5 โ FUXA's Unauthenticated Project Data Disclosure Exposes Server-Side Scripts an...
- CVE-2026-46688 โ CVSS 6.9 โ Meeting Room Booking System has an unauthenticated open redirectThe Meeting R...
- CVE-2026-71194 โ CVSS 6.8 โ In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lo...