View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Dell discloses critical vulnerabilities in Networking OS10

πŸ’₯ BREACHES & INCIDENTS

  • Tata Nexarc B2B platform exposed OTPs in API responses
    Tata Nexarc’s B2B platform exposed one-time passwords through API responses.
    • Tata Nexarc customers and users were affected.
    • The platform returned authentication OTPs in API responses.
    • The exposure occurred through the platform’s API response data.
      πŸ“„ https://www.reddit.com/r/netsec/comments/1vx4j41/tatas_b2b_platform_returned_otps_in_api_responses/ Β· πŸ“Ž https://eaton-works.com/2026/08/24/tata-nexarc-hack/ Β· πŸ‘ via r/netsec

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • ToxicPanda 2.0 Expands Android Banking and Device-Control Capabilities
    ToxicPanda 2.0 is targeting Android banking and cryptocurrency users with expanded credential-theft capabilities.

    • Android users of banking and cryptocurrency apps are targeted across Pakistan, South Africa, Mexico, Nigeria, India, and other countries.
    • The trojan targets more than 140 apps for PIN theft and 349 financial institutions with credential-stealing overlays.
    • A dropper delivered from Amazon AWS-hosted files uses fake installation screens to obtain VPN and Accessibility permissions.
    • Accessibility abuse enables screen scraping, touch capture, deceptive overlays, and automated Wireless Debugging and ADB pairing for shell access.
    • ToxicPanda 2.0 supports 167 remote commands and can steal device unlock credentials; the local ADB address is 127.0.0.1.
      πŸ“„ http://www.prnewswire.com/news-releases/zimperium-zlabs-uncovers-toxicpanda-2-0--a-significantly-more-powerful-android-banking-trojan-302854782.html Β· πŸ“Ž https://cybersecuritynews.com/toxicpanda-android-malware/ Β· πŸ‘ via Dark Reading
  • 40 Malicious Firefox Extensions Steal Crypto Wallet Secrets
    Researchers found 40 malicious Firefox extensions stealing cryptocurrency wallet data and credentials.

    • Firefox users, especially cryptocurrency wallet users, are targeted by 40 malicious add-ons linked to 37 deceptive sports-score extensions.
    • The extensions impersonate OKX, Rabby Wallet, TronLink and other Web3 products to steal recovery phrases, private keys, serialized keyrings, credentials and clipboard data.
    • Seven extensions use Supabase-controlled remote content to deliver phishing pages, while 15 embed wallet-theft code and exfiltrate secrets through Cloudflare Workers.
    • Thirteen modified Rabby builds send serialized keyrings to hardcoded HTTP servers before local encryption; five others use hardcoded C2 infrastructure for credential and clipboard theft.
    • Observed examples include Rabbit For Desktop v8.20.10 (bright-save-feed@tabtools[.]org), Rabby impersonator v2.4.9 (flex-clock-dash@extrakits[.]com), and Safe-Themes v8.12.13 (bliss-heaven@webbrol[.]com).
      πŸ“Ž https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.html Β· πŸ‘ via Graham Cluley
  • Adfinis Document Merge Service flaw enables RCE via XLSX templates
    Adfinis Document Merge Service is vulnerable to server-side template injection RCE.

    • Adfinis Document Merge Service versions before 9.1.0 are affected (CVE-2026-53964).
    • The flaw affects XLSX document templates and can expose files, data, and the container.
    • Attackers upload malicious XLSX files containing unsandboxed Jinja expressions processed by the xltpl library.
    • Injected commands execute as the document-merge-server user, UID 901.
      πŸ“„ https://github.com/advisories/GHSA-w47q-945m-q9pc Β· πŸ“Ž https://ipurple.team/2026/08/24/text-template/ Β· πŸ‘ via r/netsec
  • Fake Microsoft Security Scans Push Victims to Uninstall Antivirus
    Fake Microsoft-branded scanners invent security problems and funnel victims into refund scams.

    • Windows users with antivirus software are targeted.
    • Fake Microsoft security scans falsely claim to find infections or other security problems.
    • Browser redirects, malicious ads, hacked sites, notification spam, and adware can deliver the scareware.
    • Victims are pressured to uninstall antivirus software and contact fake support for a refund scam.
      πŸ“Ž https://securityboulevard.com/2026/08/fake-microsoft-security-scans-trick-victims-into-uninstalling-their-antivirus/ Β· πŸ‘ via securityboulevard.com (discovered)
  • Cisco IE 1000 switches affected by stored XSS and DoS flaws
    Cisco has disclosed stored XSS and denial-of-service flaws in IE 1000 switches.

    • Cisco Industrial Ethernet 1000 Series switches are affected regardless of device configuration.
    • The web-based management interface contains stored XSS vulnerability CVE-2026-20232, rated medium with CVSS 5.4.
    • An authenticated remote attacker can inject malicious code into interface pages and execute scripts in another user’s context.
    • A separate medium-severity denial-of-service vulnerability affects the same switch series, rated CVSS 5.3; its CVE identifier is not provided.
      πŸ“„ https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-ie1k-NgXUFF52 Β· πŸ“Ž https://www.systemtek.co.uk/2026/08/cisco-industrial-ethernet-1000-series-switches-stored-cross-site-scripting-vulnerability-cve-2026-20232/ Β· πŸ‘ via InfraTrust Advisories (+1)
  • Cisco RoomOS USB driver has a medium-severity stack overflow flaw
    Cisco disclosed a medium-severity stack overflow vulnerability in the RoomOS USB driver.

    • Cisco RoomOS devices are affected.
    • The USB driver contains a stack overflow vulnerability tracked as CVE-2026-20302.
    • An unauthenticated local attacker needs physical access to a device’s USB port.
    • The flaw has a CVSS score of 6.1.
      πŸ“„ https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-roomos-bof-vTMANZgu Β· πŸ“Ž https://infrarepo.com/cisco-%f0%9f%97%93%ef%b8%8f%f0%9f%93%85-august-19-2026/ Β· πŸ‘ via InfraTrust Advisories

🚨 ACTIVE EXPLOITATION

  • Dell discloses critical vulnerabilities in Networking OS10
    Dell disclosed critical vulnerabilities in SmartFabric OS10.

    • Dell SmartFabric OS10 customers are affected.
    • The advisory covers 67 CVEs, including six proprietary OS10 vulnerabilities.
    • Versions prior to 10.5.6.14 are vulnerable to command execution, denial of service, session theft, and code execution.
    • Remote attackers can exploit command injection, authorization flaws, session fixation, and unverified code downloads.
    • The advisory rates the update critical, with a maximum CVSS score of 10.0.
      πŸ“Ž https://www.dell.com/support/kbdoc/en-us/000501840/dsa-2026-322-security-update-for-dell-networking-os10-vulnerabilities Β· πŸ‘ via InfraTrust Advisories
  • Dell Watchdog Timer Driver flaw enables local privilege escalation
    Dell disclosed a high-severity privilege-escalation flaw in its Watchdog Timer Driver.

    • Dell Precision, Dell Pro, and OptiPlex systems listed in the advisory are affected.
    • Watchdog Timer Driver versions before 2.0.0.1 contain an exposed IOCTL with insufficient access control.
    • A low-privileged attacker with local access could exploit the driver to alter system controls and escalate privileges.
    • CVE-2026-61407 has a CVSS score of 8.8.
      πŸ“Ž https://www.dell.com/support/kbdoc/en-us/000501078/dsa-2026-248-security-update-for-dell-watchdog-timer-driver-for-an-exposed-ioctl-with-insufficient-access-control-vulnerability Β· πŸ‘ via InfraTrust Advisories
  • Metal Gear Online 3 flaw lets match hosts remotely execute code CVE-2026-19874
    Metal Gear Online 3 contains a heap-based buffer overflow enabling remote code execution.

    • Konami’s Metal Gear Online 3 version 1.1.2.8 for Steam AppID 287700 is affected.
    • The flaw is an input-validation vulnerability in Steam lobby metadata for the player-removal feature.
    • Malformed kick_num and Steam ID entries trigger a heap-based buffer overflow.
    • A malicious match host can send crafted lobby data to remotely execute arbitrary code on lobby members’ machines.
    • CVE-2026-19874 is assigned to the vulnerability.
      πŸ“Ž https://kb.cert.org/vuls/id/728712 Β· πŸ‘ via CERT/CC Vulnerability Notes, CVE ThreatInt
  • HP Web Jetadmin has a high-severity arbitrary file read/write flaw
    HP Web Jetadmin is affected by a high-severity arbitrary file read/write vulnerability.

    • HP Web Jetadmin deployments are affected.
    • The flaw may allow arbitrary file reading and writing.
    • HP rates the issue High with a CVSS score of 8.9.
      πŸ“„ https://support.hp.com/us-en/document/ish_15260929-15260951-16/HPSBPI04130 Β· πŸ“Ž https://support.hp.com/us-en/document/ish_15260929-15260951-16/HPSBPI04130 Β· πŸ‘ via InfraTrust Advisories
  • HP Smart Tank All-in-One Printers Face Potential Denial-of-Service Issue
    HP has disclosed a potential denial-of-service issue affecting certain Smart Tank all-in-one printers.

    • Certain HP Smart Tank all-in-one printer models are affected.
    • The issue could cause a denial-of-service condition and is rated Medium with a CVSS score of 6.9.
    • The attack mechanism and affected firmware versions are not specified in the provided material.
      πŸ“Ž https://support.hp.com/us-en/document/ish_15407218-15407241-16/HPSBPI04142 Β· πŸ‘ via InfraTrust Advisories
  • Dell ThinOS 10 Update Fixes 83 Critical Vulnerabilities
    Dell released a critical security update for ThinOS 10 vulnerabilities.

    • Dell ThinOS 10 customers are affected.
    • The update addresses 83 vulnerabilities with a maximum CVSS score of 9.8.
    • The vulnerabilities are listed as known exploited vulnerabilities.
    • The supplied material does not describe attack vectors, tooling, or evasion techniques.
      πŸ“„ https://www.dell.com/support/kbdoc/en-us/000496663/dsa-2026-352 Β· πŸ“Ž https://www.dell.com/support/kbdoc/en-us/000496663/dsa-2026-352 Β· πŸ‘ via InfraTrust Advisories

πŸ”“ CVEs & KEV

  • CVE-2026-76071 β€” CVSS 9.3 β€” Netis NC63 V3.0.0.3327 Stack Buffer Overflow via destHost ParameterNetis NC63...

  • CVE-2026-76070 β€” CVSS 9.3 β€” Netis NC63 V3.0.0.3327 Stack Buffer Overflow via Login Password ParameterNeti...

  • CVE-2026-13212 β€” CVSS 8.8 β€” Zephyr virtio driver calls an arbitrary function pointer from an out-of-range...

  • CVE-2026-78416 β€” CVSS 8.7 β€” Authenticated RCE via condition.config JSON cleanse bypassCraft CMS version...

  • CVE-2026-39915 β€” CVSS 8.5 β€” TIM Flow before 26.0.6 CRLF Injection via rt Parameter and access_token CookieTIM ...

  • CVE-2026-78414 β€” CVSS 8.0 β€” Cross-site scripting in Nx Witness VMS Web Administration allows session toke...

  • CVE-2026-71366 β€” CVSS 7.7 β€” Awx: notification backends allow ssrf and credential leakageA server-side req

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check