π΅οΈ RESEARCH & DEEP DIVES
-
Citizen Lab Uncovers Covert Exploitation of Global Telecom Networks
Citizen Lab has documented covert exploitation of global telecom networks.- Global telecommunications companies and infrastructure are affected.
- Covert surveillance actors are exploiting telecom networks and communications.
- The activity involves persistent access across telecom infrastructure in multiple countries.
- Confirmed victims reportedly include companies in 80 countries.
π Coverage: citizenlab.ca Β· π via r/netsec
-
ClawHavoc Campaign Turns OpenClaw AI Agents Into Malware Delivery Tools
Attackers poisoned OpenClawβs ClawHub registry with malicious skills that delivered infostealers.- OpenClaw users, developers, and AI power users were targeted through skills installed from the ClawHub registry.
- The campaign exposed credentials, browser data, cryptocurrency wallets, developer secrets, SSH keys, cloud credentials, and agent-linked tokens.
- At least 341 malicious skills were identified, including 335 linked to Atomic macOS Stealer; 1,184 malicious packages were associated with 12 author IDs.
- Malicious skills used fake prerequisites, ClickFix-style instructions, password-protected archives, Base64-encoded shell commands, PowerShell, Bash, and curl to deliver payloads.
- Reported indicators include 91.92.242.30, 95.92.242.30, SHA-256 998c38b430097479b015a68d9435dc5b98684119739572a4dff11e085881187e, and SHA-256 17703b3d5e8e1fe69d6a6c78a240d8c84b32465fe62bed5610fb29335fe42283; OpenClaw releases before 2026.1.29 were reportedly affected by CVE-2026-25253.
π Coverage: reddit.com Β· π via r/netsec
π CVEs & KEV
-
CVE-2026-77635 β CVSS 9.2 β CakePHP: FunctionsBuilder::jsonValue() vulerable to SQL injection with Postgr...
-
CVE-2026-75542 β CVSS 8.3 β OAuth token exchange grants repository scopes for organizations the principal...
-
CVE-2026-77634 β CVSS 8.2 β CakePHP: SmtpTransport vulnerable to CRLF header injectionCakePHP is a rapid ...
-
CVE-2026-77567 β CVSS 8.1 β Filament: App-based MFA can be bypassed when recovery codes are enabledFilame...
-
CVE-2026-19568 β CVSS 7.8 β SVG File Parsing Memory Corruption Vulnerability in Autodesk 3ds MaxA malicio...
-
CVE-2026-7455 β CVSS 7.8 β FLT File Parsing Out-of-Bounds Write Vulnerability in Autodesk 3ds MaxA malic...
-
CVE-2026-16783 β CVSS 7.8 β ABC File Parsing Out-of-Bounds Write Vulnerability in Autodesk 3ds MaxA malic...
-
CVE-2026-5006 β CVSS 6.8 β Vault Vulnerable to Privilege Escalation via Slash Injection in Templated Pol...
-
CVE-2026-75509 β CVSS 6.5 β joserfc claim-validation bypass via array-typed single-string claims (iss/sub...
π ADVISORIES
- π Source for Harness launches AI agents to triage and patch software vulnerabilities β harness.io