< ciso
brief />
Tag Banner

All news with #active exploitation tag

777 articles · page 5 of 39

Cursor flaw allows repo-root binaries to run

🛡️ Open a repository in Cursor on Windows and, if a file named git.exe is in the project root, Cursor runs it automatically without prompt. Whatever that binary does executes as the logged-in user and Cursor repeatedly spawns it while the project remains open. Mindgard reported the issue in December 2025, published full details seven months later, and no patch or Cursor advisory had been issued as of July 15, 2026.
read more →

CISA warns: patch actively exploited SharePoint flaws

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that attackers are actively exploiting three SharePoint Server vulnerabilities (CVE-2026-32201, CVE-2026-45659, CVE-2026-56164) in Internet-exposed on-premises instances. The flaws enable authentication bypass, remote code execution, and post-exploitation activity including theft of IIS machine keys and persistence to deploy malware. CISA urged administrators to apply Microsoft's patches, verify installation, shorten patch cycles, enable AMSI integration for SharePoint, use Microsoft Defender Antivirus detections, and implement hardening and monitoring measures.
read more →

SonicWall SMA1000 Zero-Day Flaws Prompt Urgent Patch

🛡️ SonicWall warns customers that two SMA1000 vulnerabilities, CVE-2026-15409 and CVE-2026-15410, are being actively exploited and urges immediate installation of hotfixes. CVE-2026-15409 is a critical SSRF (CVSS 10.0) in the Appliance Work Place interface allowing unauthenticated requests, while CVE-2026-15410 is a high-severity post-authentication code injection (CVSS 7.2) enabling OS command execution. Fixes are available in platform-hotfix versions 12.4.3-03453 and 12.5.0-02835 and later; SonicWall provided IOCs and recommends re-imaging compromised devices.
read more →

Microsoft July 2026 Patch Tuesday: 622 Flaws Released

🛡️ Microsoft released its July 2026 security updates addressing 622 vulnerabilities across many products, including 57 marked critical. Two flaws have confirmed in-the-wild exploitation: an AD FS elevation of privilege (CVE-2026-56155) and a SharePoint spoofing/authentication issue (CVE-2026-56164). Talos highlights multiple critical remote-code-execution and elevation-of-privilege flaws affecting Windows components, Office, SharePoint, SQL Server, Defender, Copilot and cloud services. Cisco Talos also published Snort rules and urged customers to update intrusion-detection rule sets to detect exploitation attempts.
read more →

Microsoft ships record July Patch Tuesday fixes

🔒 Microsoft released its largest Patch Tuesday ever, addressing 622 CVEs including two actively exploited elevation-of-privilege flaws in on‑premises SharePoint Server (CVE-2026-56164) and Active Directory Federation Services (CVE-2026-56155). The SharePoint bug allows unauthenticated network privilege escalation and is tied to incident responders at Mandiant and Google's FLARE; admins should patch immediately and consider enabling AMSI Full Mode. The AD FS bug permits local privilege escalation for authenticated users and was credited to Microsoft DART. A third disclosed BitLocker bypass (CVE-2026-50661) requires physical access and is lower priority. The update also finalizes Kerberos RC4 hardening, risking authentication breaks for service accounts still using RC4 unless audited and rotated first. Microsoft says AI tooling increased bug discovery, and the scale of fixes means organizations should prioritize by exploitation status rather than CVSS score.
read more →

CISA warns of exploited RCE in Joomla extensions

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that attackers are actively exploiting arbitrary file upload vulnerabilities in the iCagenda and Balbooa Forms Joomla extensions to achieve remote code execution. The agency designated these flaws as maximum priority and ordered federal agencies to apply updates or mitigations within three days. Vendors released fixes in iCagenda 4.0.8/3.9.15 and Balbooa Forms 2.4.1 after automated and zero-day exploitation was observed. Administrators should check installations and apply the available patches immediately.
read more →

Australia warns of widespread CMS exploitation

🛡️ The Australian Cyber Security Centre (ACSC) has warned of a large-scale campaign scanning and exploiting vulnerabilities in content management systems worldwide, impacting many SMBs in Australia. The actors deploy webshells via flaws allowing unauthenticated file upload, remote code execution, SSRF or deserialization, affecting products like WordPress, Joomla, Craft CMS and others. The ACSC advises inspecting servers for compromise, isolating and remediating infected hosts, patching vulnerable systems, and restoring from known-good backups.
read more →

Australia alerts on global CMS exploitation campaign

⚠️ The Australian Cyber Security Centre (ACSC) warned of a global campaign exploiting vulnerabilities in multiple content management systems and plugins, with many Australian small and medium businesses affected. Threat actors are deploying webshells to maintain persistence, steal credentials, and escalate access. The campaign targets several CMS platforms and specific plugins, and the ACSC cautions that AI may be used to accelerate attacks. Administrators are urged to apply patches, remove unused components, and tighten web-server protections.
read more →

Injective Labs SDK compromise exposes wallet keys

🔐 Unknown actors compromised the Injective Labs SDK repository and published a malicious npm package, @injectivelabs/sdk-ts@1.20.21, to exfiltrate cryptocurrency private keys and mnemonic phrases. The backdoored release, deployed on July 8, 2026, was embedded with fake telemetry that captured sensitive wallet data and transmitted it to an external server. The attacker pushed identical poisoned versions across 17 additional @injectivelabs-scoped packages to reach transitive users. A clean update (1.20.23) is now available and users are urged to rotate any exposed keys and check dependencies.
read more →

Progress warns ShareFile customers to shut servers

🛑 Progress Software has alerted ShareFile customers using on-premise Storage Zone Controllers to immediately shut down the Windows servers hosting those controllers after identifying a "credible external security threat." The company temporarily disabled access to Storage Zone Controller–backed accounts and says manual shutdown is required in addition to cloud-side restrictions. Progress is investigating with cybersecurity partners and will update customers within 24 hours while the ShareFile status page shows affected controllers are nonoperational.
read more →

Critical Gitea Docker auth bypass actively exploited

🔒 A critical authentication bypass (CVE-2026-20896) in the official Gitea Docker image is being actively exploited to impersonate any user, including administrators, when reverse-proxy authentication headers like X-WEBAUTH-USER are trusted from all sources. Sysdig reported the first in-the-wild exploitation roughly two weeks before public disclosure, and around 6,200 Gitea instances are internet-exposed. Gitea released versions 1.26.3 and 1.26.4 to address the issue and advises immediate upgrades or restricting REVERSE_PROXY_TRUSTED_PROXIES to known IPs.
read more →

Unpatched XRING bug in XQUIC allows remote crash

🛡️ A single wrong variable in Alibaba's XQUIC library lets any remote client crash servers using default QPACK settings with ordinary HTTP/3 traffic. FoxIO researcher Sébastien Féry disclosed the XRING flaw on July 8 and showed a crash triggered by about 260 bytes of legal QPACK frames. All XQUIC releases through v1.9.4 are affected; no patch or CVE was available as of July 10. Operators can mitigate by setting SETTINGS_QPACK_MAX_TABLE_CAPACITY to 0 or disabling HTTP/3 until a fix ships.
read more →

Zimbra urges urgent patch for Classic Web Client XSS

🔒 Zimbra released version 10.1.19 to address a critical stored cross-site scripting (XSS) vulnerability in its Classic Web Client that can be triggered via specially crafted emails. The flaw, reported by Google's Threat Analysis Group, allows attackers to execute malicious code when messages are opened and potentially steal session data, account settings, or mailbox contents. Zimbra cautioned customers to upgrade immediately, noting the issue specifically affects Classic Web Client users, while attribution and active exploitation remain under investigation.
read more →

Winning 54% of the Time: SOC Decisions and Threats

🎾 This week’s Threat Source reflects on decision-making in cybersecurity through a tennis analogy, arguing defenders need context and resilience rather than perfection. Cisco Talos details the China-nexus actor UAT-7810 expanding ORB networks by exploiting Ruckus and ASUS router vulnerabilities and deploying new backdoors like LONGLEASH and DOGLEASH. Additional briefs cover an AI-assisted ransomware incident, AirDrop/Quick Share flaws, a Tenda firmware backdoor, Estonia’s AI agent IDs, and new phishing and coinminer detections.
read more →

CISA directs rapid patching of Langflow auth bypass

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered federal agencies to urgently patch an actively exploited Langflow authentication bypass (CVE-2026-55255) that lets authenticated actors access other users' flows by abusing the /api/v1/responses endpoint with a victim's UUID. First observed in the wild by Sysdig on June 25, attackers sought code execution, implants, compute and credentials. CISA added the flaw to its Known Exploited Vulnerabilities Catalog and required FCEB remediation under BOD 26-04 by Friday.
read more →

CISA directs federal patch for ColdFusion zero-day

🔒 The U.S. Cybersecurity and Infrastructure Security Agency has ordered federal agencies to patch an actively exploited, maximum-severity vulnerability in Adobe ColdFusion (CVE-2026-48282) by Friday. Adobe published fixes for affected ColdFusion versions last week and urged administrators to install updates immediately. The flaw enables unauthenticated remote code execution in low-complexity attacks and has been observed in the wild soon after disclosure. CISA added the issue to its KEV catalog and invoked BOD 26-04 to enforce remediation timelines for FCEB agencies.
read more →

CISA Adds Four Newly Exploited Vulnerabilities

🛡️ The US Cybersecurity and Infrastructure Security Agency (CISA) added four vulnerabilities to its Known Exploited Vulnerabilities catalog, citing active exploitation. The flaws include critical Adobe ColdFusion path traversal (CVE-2026-48282), Joomlack Page Builder improper access control (CVE-2026-56290), Langflow authorization bypass (CVE-2026-55255), and JoomShaper SP Page Builder unrestricted file upload (CVE-2026-48908). Exploitation observed ranged from immediate post-disclosure attacks to targeted campaigns stealing credentials and deploying web shells. Agencies are urged to apply patches by July 10, 2026.
read more →

16-year KVM bug allows guest-to-host escape

🛡️ A critical KVM vulnerability, tracked as CVE-2026-53359 and nicknamed Januscape, lets an attacker with root in a guest VM execute code on the Linux host by exploiting a use-after-free in KVM's shadow MMU emulation on x86. Discovered by Hyunwoo Kim and present for 16 years, it affects both Intel and AMD servers and can enable host kernel panic, denial-of-service, or full RCE; some distros also allow local escalation via world-writable /dev/kvm. The Linux kernel was patched on June 16, but distribution rollouts may lag.
read more →

Undocumented backdoor in Tenda router firmware exposed

🔒 CERT/CC warns that an undocumented authentication backdoor in multiple Tenda router firmware versions (CVE-2026-11405) can grant administrative access via an alternate plaintext password stored in sys.rzadmin.password. The backdoor bypasses normal MD5 authentication in the '/bin/httpd' login() function, accepting any username if the backdoor password is supplied. No patch is available and Tenda could not be reached; users are advised to disable remote web management and restrict LAN exposure.
read more →

Adobe warns of exploited maximum severity ColdFusion flaw

🛡️ Adobe has urged ColdFusion customers to patch immediately after at least one maximum severity flaw was reported as being exploited. The company released fixes for 11 CVEs in the APSB26-68 bulletin on June 30, six carrying a CVSS score of 10. Researchers reported that CVE-2026-48282, a path traversal allowing potential arbitrary code execution, was targeted within hours of disclosure. There are 775 exposed ColdFusion instances online, increasing the risk for rapid exploitation.
read more →