View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Hackers accused of €30M bank fraud exploiting service-provider flaw

💥 BREACHES & INCIDENTS

  • Hackers accused of €30M bank fraud exploiting service-provider flaw Hackers allegedly stole about €30 million by exploiting a financial service provider's software flaw.
    • Commerzbank customers were affected, but the bank said they suffered no financial losses.
    • Attackers made unauthorized direct debits from German online banking accounts.
    • A faulty software update introduced a vulnerability in a payment-processing system.
    • The funds were routed through Brazil and concealed using pass-through accounts, companies, payment institutions, virtual-asset platforms, and payment cards.
    • Four suspects were arrested in Brazil and three others were charged in Europe. 📎 Coverage: bleepingcomputer.com · 👁 via BleepingComputer

🔓 CVEs & KEV

  • CVE-2026-73849 — CVSS 9.8 — emlog allows unauthenticated reinstallation via install.php?action=reinstall...
  • CVE-2026-19682 — CVSS 9.4 — Command InjectionA command injection vulnerability exists in Security Center ...
  • CVE-2026-19681 — CVSS 9.4 — Command InjectionAn authenticated command injection vulnerability exists in S...
  • CVE-2026-19679 — CVSS 8.7 — Improper Input ValidationAn input validation vulnerability exists in Security...
  • CVE-2026-73850 — CVSS 8.6 — Emlog: Arbitrary SQL Execution Vulnerability in ai.php within queryDatabase()...
  • CVE-2026-19635 — CVSS 8.5 — Local Privilege EscalationA local privilege escalation vulnerability exists i...
  • CVE-2026-72970 — CVSS 8.3 — Microsoft Edge (Chromium-based) Remote Code Execution VulnerabilityHeap-based...
  • CVE-2026-24791 — CVSS 8.1 — Public-only tokens bypass private-resource restrictions on /api/v1/user sel...
  • CVE-2026-59765 — CVSS 7.5 — SSRF via Migration Asset Downloads Bypasses hostmatcher — Reads Internal File...
  • CVE-2026-19680 — CVSS 7.1 — SQL InjectionA SQL injection vulnerability exists in Security Center that cou...
  • CVE-2026-73847 — CVSS 6.8 — Emlog: Missing CSRF protection in AI Assistant execute_tool leads to full dat...
  • CVE-2026-24059 — CVSS 6.5 — Gitea runner registration-token GET endpoint performs a write under a read-on...
  • CVE-2026-19636 — CVSS 6.0 — Insuffucient Protections Lead to Brute ForceAn issue was identified in which ...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check