< ciso
brief />
Tag Banner

All news with #active exploitation tag

914 articles · page 6 of 46

JetBrains Cadence breach after TeamCity exploit

🔒 JetBrains warns Cadence users to immediately revoke and rotate all credentials after threat actors exploited a critical TeamCity vulnerability (CVE-2026-63077) to breach a Cadence server. The attackers accessed a 2024 backup and may have obtained email addresses, project source code, AWS IAM credentials, and S3-stored files. JetBrains invalidated Cadence plugin tokens and provided IOCs, urging review of connected systems and treating all executions as untrusted.
read more →

Google patches active Chrome zero-day in V8 engine

🔒 Google released an urgent Chrome update to fix an actively exploited high-severity zero-day (CVE-2026-85046) in the V8 JavaScript engine along with 11 other vulnerabilities across Windows, macOS, and Linux. The type confusion bug, reported by researcher Salvatore Gulizia (“Serotav”), can be triggered by crafted web content and may lead to remote code execution within Chrome’s sandboxed renderer. Google withheld technical exploit details while rolling out Chrome 152.0.7977.82/.83 to give users time to update; a restart is required once the update downloads.
read more →

Mass exploit attempts target WordPress plugins

🛡️ Wordfence reports that threat actors have been actively exploiting critical vulnerabilities in the WordPress plugins Super Forms and Elementor Pro, enabling unauthenticated file uploads that lead to remote code execution. Both flaws permit attackers to upload PHP web shells, which can be used to create admin accounts, exfiltrate data, or seize control of sites. Over 440,000 exploit attempts have been blocked, and site owners are urged to apply patches and scan for compromises.
read more →

Google issues Chrome update to fix active V8 zero-day

🔒 Google released security updates fixing 12 Chrome vulnerabilities, including an actively exploited high-severity V8 type confusion bug (CVE-2026-85046) with a CVSS of 8.8. Researcher Salvatore Gulizia (Serotav) reported the flaw on August 4, 2026, and received a $1,000 bounty. Google confirmed exploits exist in the wild and urges users to update Chrome to 152.0.7977.82/.83 on supported platforms. Other Chromium-based browser users should apply vendor fixes when available.
read more →

HPE fixes critical ArubaOS‑CX remote code flaw

🔒 HPE has released patches for a critical buffer overflow in ArubaOS‑CX (CVE-2026-73749) that lets unauthenticated attackers send crafted packets to a daemon and achieve remote code execution with elevated privileges. The vendor lists fixed builds across multiple release branches and warns that some versions have reached End of Maintenance, receiving only selective critical fixes. The bulletin also addresses 23 additional vulnerabilities ranging from high to low severity and urges customers to upgrade to the patched releases.
read more →

Pegasus zero-click iMessage exploit hits Serbia protester

🛡️ A forensic investigation by Citizen Lab and the SHARE Foundation found high-confidence indicators that a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware via an iMessage zero-click exploit. The infection indicators spanned December 2025 and January 2026, and the attack method is believed to have been patched in iOS 18.4.1. The case is part of broader documented targeting of Serbia's civil society ahead of key 2026 elections, with recommendations that notification recipients seek expert assistance and enable protective measures.
read more →

Critical Elementor Pro flaw exploited to hijack sites

⚠️ A critical vulnerability (CVE-2026-32475) in Elementor Pro was patched on August 19 after active exploitation that uploads webshells and enables remote command execution. The flaw affects versions 4.2.1 and earlier and abuses faulty file-upload array validation in forms with a File Upload field. Wordfence blocked nearly 200,000 attempts and advises immediate upgrade to 4.2.2 and checks for rogue PHP files in uploads.
read more →

Researcher Publishes FalconFlank PoC for CrowdStrike

🔒 A security researcher known as Chaotic Eclipse released a zero-day PoC called FalconFlank that enables local privilege escalation by abusing CrowdStrike Falcon's office malicious macros remediation. The researcher says the exploit works on fully updated Windows 11 25H2 and Windows Server 2025 systems with Falcon installed, and cautions defenders may need to add exclusions or obfuscate detection to test it. This release follows recent PoCs targeting Kaspersky and Microsoft Defender, with the researcher criticizing vendor engagement.
read more →

CISA Adds Seven Actively Exploited Flaws to KEV

🛡️ The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added seven vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog after evidence of active exploitation. The list includes critical issues in SonicWall SMA, Sangoma Switchvox, JFrog Artifactory, Kludex Starlette, Kestra OSS, and Berri LiteLLM, ranging from SSRF and SQL injection to authentication bypasses and command injection. Several of the flaws have been observed in real-world attacks that deployed reverse shells, minted admin tokens, and delivered cryptocurrency miners. Federal agencies are being directed to prioritize patches under BOD 26-04 with staggered remediation deadlines in September 2026.
read more →

Active SQL injection in Sangoma Switchvox exploited

🔒 Horizon3 researchers report active exploitation of CVE-2026-9586, an unauthenticated SQL injection in Switchvox’s /pa endpoint that can lead to remote code execution. The issue was one of 12 flaws disclosed to Sangoma and patched in Switchvox 8.4.0.2 on July 14. Attackers have attempted to establish reverse shells and exfiltrate process data from internet-exposed systems, prompting urgent upgrade and compromise checks.
read more →

SQL Injection Flaw in WP Backup Plugin Risks Site Takeover

🛡️ A high-severity SQL injection in the All-in-One WP Migration and Backup plugin (CVE-2026-19949) can let unauthenticated attackers achieve remote code execution and site takeover. Discovered by Jack Taylor and reported via Wordfence, the flaw stems from incorrect parsing of escaped backslashes and quotes during archive restoration. Exploitation requires an admin to perform an export/import action, and despite a patch in version 7.110, roughly 3.25 million sites remain vulnerable.
read more →

Critical JFrog Artifactory Authentication Bypass Exploited

🛡️ A critical authentication bypass (CVE-2026-82329) in self-managed JFrog Artifactory is being actively exploited to mint admin tokens. The flaw exists in default configurations and allows unauthenticated attackers with network access to obtain administrative privileges. JFrog released fixes on August 28 for multiple Artifactory 7.x versions and says cloud instances were already protected.
read more →

Malicious Apache Modules Hijack High‑Reputation Sites

🔍 A Chinese-speaking cybercrime cluster called Gambling Goblin has been observed installing malicious Apache modules on compromised Brazilian government and educational servers to redirect visitors to attacker-controlled pages promoting online gambling. Check Point Research has tracked the campaign since mid-2025 and found modules that reverse-proxy traffic while stripping security headers so injected content can run. The actors use multiple Linux and reconnaissance tools including DownPro, AlphaAgent, oRAT, and a 3snake-based credential stealer, and the operation appears aimed at large-scale SEO manipulation using high-reputation domains.
read more →

Critical JFrog Artifactory Bug Sparks Supply-Chain Alarm

🔒 A critical authentication bypass in JFrog Artifactory (CVE-2026-82329) is being actively exploited, allowing unauthenticated attackers under default configuration to obtain administrative privileges. Threat actors were observed creating admin tokens and enumerating users, groups and credentials, prompting urgent advisories to upgrade affected self-hosted versions and fortify cloud instances. Organizations are urged to patch exposed systems, revoke potentially compromised tokens, inspect logs and verify artifact integrity to mitigate downstream risks.
read more →

SonicWall SMA zero-day flaws exploited in attacks

🔒 SonicWall released hotfixes for two critical vulnerabilities in its Secure Mobile Access (SMA) 1000 series appliances after confirming active exploitation. The flaws — a pre-authentication SSRF (CVE-2026-83548) and a post-authentication command injection (CVE-2026-83549) — affect SMA 6210, 7210, and 8200v on older platform-hotfix builds. SonicWall recommends upgrading to the latest fixes, searching for IoCs, and re-imaging or resetting credentials if compromises are detected.
read more →

GeoNetwork fixes chained unauthenticated RCE vulnerabilities

🛡️ GeoNetwork patched two chained vulnerabilities that allow unauthenticated remote code execution by combining a missing authorization check on the formatter upload endpoint with an unsafe Saxon XSLT configuration. The fixes were released in versions 4.4.12 and 4.2.17 on July 8, 2026, with advisory details published August 31. Vendor-sourced scans found 121 internet-exposed instances across 39 countries, many tied to government or national agencies, and administrators are urged to upgrade or block write methods to the formatter endpoint as an interim mitigation.
read more →

How China Industrialized State Hacking Infrastructure

🛡️ Last week the US Justice Department and FBI seized domains tied to QScan and QTRouter, platforms used by PRC-linked group QTFY to target US agencies and critical infrastructure. QTFY, operated by Nanjing Xinjiuwei, provided scanning, exploitation, and obfuscation services—turning IoT devices into routing infrastructure for state clients. The takedown highlights how marketized contractors and shared services scale Chinese offensive operations while creating choke points for law enforcement. Experts urge CISOs to shift from IP-based defenses to behavioral visibility, rapid patching, and stronger edge controls.
read more →

SonicWall warns of exploited SMA1000 zero-days

🛡️ SonicWall warned customers that attackers are chaining two newly discovered SMA1000 zero-day vulnerabilities to achieve remote code execution. The first is a critical command injection flaw (CVE-2026-83548) tied to an SSRF issue in the Appliance WorkPlace, while the second (CVE-2026-83549) affects the Management Console and requires admin privileges. Affected models include SMA1000 6210, 7210, and 8200v; SonicWall urges immediate hotfix upgrades and recommends re-imaging and credential resets if compromise is suspected.
read more →

Counterfeit installers enable persistent system compromise

🛡️ Microsoft Defender Experts are tracking an active campaign that uses counterfeit software-download sites impersonating trusted vendors to distribute malicious installers. The campaign targets users seeking popular software and has caused compromises across multiple industries, with a concentration on China-based operations and Chinese-speaking users. The malicious installers establish persistence, evade defenses, and communicate with attacker infrastructure; Microsoft disrupted activity and recommends enabling protections such as SmartScreen, network protection, tamper protection, and Microsoft Defender XDR.
read more →

PaperCut zero-days exploited for data theft

🛡️ Two recently patched vulnerabilities in PaperCut NG and MF print management software, tracked as CVE-2026-81578 and CVE-2026-82078, are being abused in live data theft campaigns. PaperCut issued emergency patches and IOCs after confirming exploitation, while defenders report attackers dumping Derby database tables rather than pursuing public RCE paths. Shadowserver currently tracks over 800 exposed servers, and the vendor has not yet attributed the intrusions.
read more →