π¨ ACTIVE EXPLOITATION
- GEEKOM Mini PC Realtek LAN Driver Package Found Infected With Asruex Trojan
A network driver download is meant to get a computer online. In this case, it became a potential malware route after a Realtek LAN driver package on a legacy GEEKOM support page was flagged as carrying the Asruex Trojan. The exposure involved a downloadable installer, not hardware leaving the factor
π Coverage: cybersecuritynews.com Β· π via Cyber Security News, cryptika.com (discovered)
π΅οΈ RESEARCH & DEEP DIVES
-
BTMob Fraud Platform Uses 1,402 Servers for Android Device Takeovers
BTMob is powering Android device-takeover campaigns through a fraud-as-a-service platform.- Android users, banks, and mobile providers are affected by BTMob campaigns.
- BTMob enables screen monitoring, information theft, account theft, and unauthorized transfers.
- Attackers use fake apps, cloned download pages, WhatsApp messages, and social-engineering calls to deliver sideloaded APKs.
- The platform includes a dropper, desktop control panel, backend, reseller system, and automated APK builder.
- Researchers found 1,402 hosts on port 3000; observed indicators include lnat-tv-pro.apk, btmobrat[.]net, and 77[.]111[.]101[.]24.
π Source: blog.quimerax.com Β· π Coverage: cybersecuritynews.com Β· π via Cyber Security News, cryptika.com (discovered)
-
Projextor Hides Malware in Trojanized Electron Productivity Apps
Projextor embeds malware in working Electron-based productivity applications.- Users downloading free document converters, PDF tools, meal planners and recipe apps are affected.
- Trojanized apps include FlipFormat, PDFGrip, FoodFormula and KitchenCanvas.
- The malware can execute JavaScript, run remote commands and capture screens.
- NSIS, Squirrel and Inno Setup installers download Electron apps from impersonation websites.
- Associated domains include flipformatpdf.com, pdfgrip.com, meal-formula.com, kitchen-canvas.com and doceditorinc.com.
π Source: blog.gdatasoftware.com Β· π Coverage: cybersecuritynews.com Β· π via Cyber Security News
-
Cloudflare Tracks RFC 9234 BGP Role Adoption and OTC Stripping
Cloudflare found two Tier 1 networks stripping RFC 9234βs OTC attribute.- BGP operators and Internet transit networks are affected.
- RFC 9234βs BGP Roles and Only to Customer (OTC) attribute help routers reject route leaks.
- Cloudflare measured RFC 9234 deployment across networks.
- Two Tier 1 networks were unexpectedly observed stripping the OTC attribute.
π Coverage: blog.cloudflare.com Β· π via Cloudflare Blog
-
Protonβs Lumo Analyzes Exported AI Chats for Privacy Exposure
Proton launched AI Paper Trail to analyze exported ChatGPT and Claude histories with Lumo.- ChatGPT and Claude users can upload exported conversation histories to Protonβs AI Paper Trail.
- The tool generates a privacy type, AI Exposure Score, and profile of exposed identity, habits, relationships, and interests.
- Lumo analyzes the uploaded files and estimates the dataβs value to an AI provider.
- Proton says uploaded data is deleted after analysis, while generated reports remain visible only to their creators.
π Source: proton.me Β· π Coverage: itsfoss.com Β· π via @agreenberg@infosec.exchange
π ADVISORIES
- GitLab Issues Emergency Patch for Critical GraphQL Code-Injection Flaw
GitLab patched a critical GraphQL code-injection flaw that could let unauthenticated attackers alter or delete public projects.- Self-managed GitLab Community Edition and Enterprise Edition deployments are affected; GitLab.com and GitLab Dedicated are already patched.
- CVE-2026-19478 affects GraphQL directive processing and could enable modification or deletion of public projects and user data.
- The flaw is remotely exploitable without authentication through GitLabβs GraphQL API.
- GitLab also fixed CVE-2026-19650, a CSRF flaw allowing GraphQL mutations through malicious GET requests when a victim interacts with the request.
- Fixed versions include 19.2.4, 19.1.6, 19.0.8, and 18.11.11 across supported branches.
π Source: rescana.com Β· π Coverage: cybersecuritydive.com Β· π via Cybersecurity Dive
π CVEs & KEV
-
CVE-2026-73996 β CVSS 9.8 β WordPress Masteriyo - LMS plugin through 2.3.2 - Arbitrary File Upload vulnerabili...
-
CVE-2026-74015 β CVSS 9.3 β WordPress Readabler plugin before 2.0.18 - SQL Injection vulnerabilityUnauthentica...
-
CVE-2026-63639 β CVSS 8.8 β Valkey: UAF in stream deserialization may lead to remote code executionValkey...
-
CVE-2026-74012 β CVSS 8.8 β WordPress TaxoPress plugin through 3.51.0 - PHP Object Injection vulnerabilityEdit...
-
CVE-2026-75898 β CVSS 8.4 β RAGFlow before 0.26.3 - Server-Side Request Forgery via Agent Invoke ComponentRAGF...
-
CVE-2026-73400 β CVSS 8.1 β WordPress Restaurant Menu by MotoPress plugin through 2.4.11 - Local File Inclusio...
-
CVE-2026-56684 β CVSS 7.5 β Valkey: TLS pending-data processing use-after-free may allow remote code exec...
-
CVE-2026-73994 β CVSS 7.5 β WordPress Charitable plugin through 1.8.11.3 - Broken Access Control vulnerability...