π¨ ACTIVE EXPLOITATION
-
CISA lists Red Hat Libuser race condition CVE-2015-3246 as exploited
CVE-2015-3246
CISA has added a Red Hat Libuser race condition to its Known Exploited Vulnerabilities catalog.- Red Hat Libuser installations are affected.
- Authenticated local users can exploit the race condition to corrupt /etc/passwd.
- The flaw can cause denial of service or privilege escalation.
- CISA lists CVE-2015-3246 in its Known Exploited Vulnerabilities catalog.
π Coverage: nvd.nist.gov Β· π via CISA KEV
-
CVE-2015-5287: Red Hat ABRT privilege-escalation flaw exploited
CVE-2015-5287
CISA lists a Red Hat ABRT privilege-escalation flaw as actively exploited.- Red Hat Automatic Bug Reporting Tool (ABRT) users are affected.
- The sosreport functionality mishandles symbolic links and uses predictable filenames.
- A local attacker with certain permissions can exploit a symlink attack to gain privileges.
π Source: nvd.nist.gov Β· π Coverage: nvd.nist.gov Β· π via CISA KEV
-
CISA KEV lists CVE-2019-1068 SQL Server remote-code flaw
CVE-2019-1068
CVE-2019-1068 is an exploited remote-code-execution flaw in Microsoft SQL Server.- Microsoft SQL Server customers are affected.
- The vulnerability enables remote code execution in the SQL Server Database Engine service account context.
- CISA lists CVE-2019-1068 in its Known Exploited Vulnerabilities catalog.
π Coverage: nvd.nist.gov Β· π via CISA KEV
-
UAT-10147 Exploited AjaxPro CVE-2021-23758 Against Web Servers
CVE-2021-23758
UAT-10147 exploited AjaxPro CVE-2021-23758 for remote code execution on web servers.- Government, education, media, technology, and gaming organizations using Windows or Linux web servers were targeted.
- Ajax.NET Professional (AjaxPro) was vulnerable to unsafe deserialization of untrusted data, enabling arbitrary .NET class execution.
- UAT-10147 used the publicly disclosed CVE-2021-23758 in automated, AI-assisted intrusion campaigns alongside Metasploit and ysoserial.
- Compromised servers were used to deploy web shells, BadIIS, Noodle RAT, SPECTRE, or Meterpreter for SEO fraud, data theft, and persistence.
- The campaign's exposed infrastructure included 139.180.197[.]150 and a target list of roughly 170,000 URLs.
π Source: nvd.nist.gov Β· π Coverage: thehackernews.com Β· π via CISA KEV
-
UAT-10147 exploits Linux kernel CVE-2022-0995 for privilege escalation
CVE-2022-0995
UAT-10147 exploits CVE-2022-0995 to escalate privileges on Linux web servers.- The flaw affects Linux kernel systems, including web servers in government, education, media, technology and gaming sectors.
- CVE-2022-0995 is an out-of-bounds write in the kernelβs watch_queue event notification mechanism.
- An unprivileged local user can write arbitrary data out of bounds to gain elevated privileges or cause denial of service.
- UAT-10147 uses the flaw after web-server compromise alongside other privilege-escalation exploits and deploys web shells, NoodleRAT, SPECTRE or Meterpreter.
- Talos linked the campaign to command-and-control infrastructure at 139.180.197[.]150.
π Source: nvd.nist.gov Β· π Coverage: nvd.nist.gov Β· π via CISA KEV
-
UPDATE: Citrix NetScaler CVE-2026-8452 exploited in the wild
CVE-2026-8452
Attackers are exploiting a pre-authentication memory overflow in Citrix NetScaler.- Citrix NetScaler ADC and NetScaler Gateway deployments configured as Gateway or AAA virtual servers are affected.
- Versions before ADC/Gateway 14.1-72.61, 13.1-63.18, FIPS 14.1-72.61, and FIPS/NDcPP 13.1-37.272 are vulnerable.
- A specially crafted SAML message triggers a heap overflow during signature validation without authentication.
- Public proof-of-concept code demonstrates denial of service and potential pre-authentication remote code execution; exploitation has been reported in the wild.
π Source: support.citrix.com Β· π Coverage: bishopfox.com Β· π via CISA KEV
π₯ BREACHES & INCIDENTS
- (no items)
π CVEs & KEV
-
CVE-2026-54523 β CVSS 9.6 β Kyverno Critical Cross-Namespace Resource Creation (CVE-2026-54523)
-
CVE-2026-76784 β CVSS 8.7 β Insufficient Cryptographic Protections in Local Device Communication Protocol...
-
CVE-2026-58474 β CVSS 8.6 β whichllm before 0.5.16 Code Injection via run and snippet commandswhichllm before ...
-
CVE-2026-32258 β CVSS 8.1 β Winter: Stored XSS through Editor Settings custom stylesWinter is a free, ope...
-
CVE-2026-32257 β CVSS 8.1 β Winter: Stored XSS through Brand Settings custom stylesWinter is a free, open...
-
CVE-2026-47841 β CVSS 7.4 β WebAuthn User Verification Bypass via Session SerializationAn application usi...
-
CVE-2026-47836 β CVSS 7.2 β Spring Cloud Config Server Susceptible To TOCTOU Attack When Using SVNThe bas...
-
CVE-2026-35445 β CVSS 7.1 β Winter: Authenticated backend users can bypass Users controller permission ch...
-
CVE-2026-32639 β CVSS 6.8 β Winter: Broken access control in
Cms\Controllers\Indexallows cross-templat... -
CVE-2026-47837 β CVSS 6.8 β Spring Cloud Config Server Monitor Endpoint Does Not Validate Webhook Request...
π΅οΈ RESEARCH & DEEP DIVES
-
GPUThor Rowhammer Attack Bypasses NVIDIA GPU ECC for Root Access
GPUThor bypasses ECC protections on NVIDIA GPUs.- NVIDIA GPU users relying on ECC memory are affected.
- The attack can cause denial of service and root-level privilege escalation.
- GPUThor uses Rowhammer to bypass GPU error-correcting code protections.
π Coverage: bleepingcomputer.com Β· π via BleepingComputer
-
Nimbus Manticore Adds TWOSTROKE-Like Backdoor and Reverse SSH Tool
Group-IB has identified new Nimbus Manticore malware and infrastructure.- The activity targets defense, aerospace, IT service providers, and military organizations in the Middle East, Europe, and the United States.
- A Windows C++ backdoor collects system information, executes commands, manages files, and supports persistence.
- The backdoor masquerades as wtsapi32.dll and uses HTTPS to connect to hard-coded C2 servers.
- A reverse SSH tool disguises itself as the Windows Terminal Server SDK API and connects to 172.86.98[.]113 over port 443.
π Source: group-ib.com Β· π Coverage: thehackernews.com Β· π via The Hacker News
-
Microsoft details attacks targeting LiteLLM, RAGFlow and Kestra AI workloads
Microsoft observed attackers compromising exposed AI infrastructure to steal credentials and monetize compute.- Organizations deploying LiteLLM gateways, RAGFlow retrieval platforms, and Kestra workflow environments are affected.
- Attackers targeted model-provider keys, database connection strings, tenant credentials, workflow access, and host compute.
- LiteLLM intrusions likely exploited CVE-2026-42271 and CVE-2026-48710 for remote code execution.
- RAGFlow activity involved possible SSRF reconnaissance, code execution, and a Python hook that intercepted LLM credentials.
- Kestra attacks used workflow-originated shell execution, container discovery, XMRig cryptomining, and data collection.
π Coverage: microsoft.com Β· π via Microsoft Security Blog
-
PATCHCORD malware targets Afghan telecoms and South Asian infrastructure
Transparent Tribe is targeting Afghan telecoms and South Asian infrastructure with PATCHCORD malware.- Afghan telecom providers and South Asian critical infrastructure organizations are targeted.
- Transparent Tribe, also known as APT36, uses the custom C/C++ PATCHCORD backdoor.
- Phishing lures impersonate AFTEL VPN installers and telecom or network-management tools.
- PATCHCORD executes code in memory, fingerprints hosts, enumerates processes, and checks for sandboxes.
- The malware persists by hijacking browser shortcuts; related Sheetcord uses Windows startup and Google Sheets for C2.
π <https://www.reddit.com/r/netsec/comments/1vz6179/patchcord