< ciso
brief />
Tag Banner

All news with #active exploitation tag

914 articles · page 7 of 46

Aurora ransomware actors leveraging AI coding tools

🛡️ Threat actors tied to the Aurora (Aur0ra) ransomware have been observed using AI coding assistants like Cursor to plan and execute intrusions, according to CloudSEK and Gambit Security. Exposed infrastructure revealed months of activity targeting organizations across multiple countries between April and July 2026, with both Windows and Linux encryptors written in Zig. The attack chain includes credential theft, lateral movement, AD CS exploitation, and disabling recovery mechanisms before encryption. Investigators also identified affiliate payout splits and evidence of agentic use of Anthropic's Claude Sonnet for hands-on exploitation tasks.
read more →

PaperCut issues second emergency patch for exploited flaws

🛡️ PaperCut released a second emergency security update after researchers found multiple bypasses of the initial fix for actively exploited vulnerabilities in PaperCut NG/MF. The company disclosed two CVEs—CVE-2026-81578 (auth bypass, 8.8) and CVE-2026-82078 (unsafe dynamic class-loading, 9.4)—that can be chained for remote code execution. The updated Emergency Patch Release 2 provides additional hardening and is available for versions 24–26 on Windows, Linux, and macOS; administrators are urged to install it and restrict web interface access.
read more →

Attackers Chain Two PaperCut Flaws to Achieve RCE

🛡️ Huntress and watchTowr reported attackers chaining two recently patched PaperCut vulnerabilities to bypass authentication and achieve remote code execution. PaperCut released a second emergency patch with additional hardening after disclosure of CVE-2026-81578 and CVE-2026-82078. Observed activity includes execution of Base64-encoded commands and deployment of a cross-platform Java .class file used for reconnaissance and cleanup.
read more →

Thousands of Gitea Servers Remain Vulnerable to RCE

🔒 Shadowserver reports over 8,300 Internet-exposed Gitea instances remain unpatched against a critical code injection flaw (CVE-2026-60004) exploited in active remote code execution attacks. The vulnerability, disclosed by a Salesforce researcher, lets authenticated users execute shell commands via the diffpatch API, and default open registration enables easy exploitation. Gitea issued version 1.27.1 on July 27 to fix the issue and urged immediate upgrades, while CISA added the flaw to its actively exploited catalog and ordered federal agencies to patch swiftly.
read more →

PaperCut zero-day actively exploited; emergency patch

🚨 PaperCut warned customers that attackers are actively exploiting a zero-day affecting all versions of PaperCut NG and PaperCut MF. The vendor issued emergency patches for v25 and v26 and confirmed known customer incidents while an investigation continues. Indicators include suspicious post-exploitation activity by "pc-app.exe," missing or truncated server.log files, and specific error entries such as ERROR No suitable driver found for jdbc:no:x. Users with internet-exposed PaperCut servers are urged to immediately restrict access to trusted IPs and apply network controls.
read more →

Next.js fixes critical RCE via AVIF and Windows path

🔒 Vercel released urgent patches for two critical remote code execution flaws in Next.js: one triggered by specially crafted AVIF images and another by a Windows-specific path traversal. Fixes are available in Next.js 15.5.24 and 16.3.3 published August 25, 2026; Vercel-hosted apps are already protected. Users on affected versions should upgrade immediately, especially Windows-hosted servers which have no workaround.
read more →

CISA Adds Six Exploited Flaws, Urges Immediate Patching

🔒 The US Cybersecurity and Infrastructure Security Agency (CISA) added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog on August 26, urging prompt patching by government agencies and critical infrastructure. Two high-severity flaws—CVE-2026-8452 in Citrix NetScaler and CVE-2019-1068 in Microsoft SQL Server—carry CVSS scores of 8.8 and require immediate attention. Citrix has published updates to address the NetScaler memory overflow, while the SQL Server RCE remains actively exploited despite a seven-year-old patch. CISA set accelerated patch deadlines for the critical and other listed flaws.
read more →

CISA directs urgent patching for Citrix NetScaler RCE

🔒 CISA has ordered federal agencies to patch Citrix NetScaler appliances by Saturday due to an actively exploited vulnerability, CVE-2026-8452. The flaw is a memory overflow affecting NetScaler ADC and Gateway appliances configured with Gateway VPN or AAA virtual servers and can lead to unpredictable behavior, DoS, or remote code execution. Researchers have observed active exploitation in attacks deploying web shells, and Citrix's advisory has not yet acknowledged in-the-wild targeting. Shadowserver currently tracks thousands of exposed NetScaler instances online.
read more →

CISA Adds Six Actively Exploited Flaws to KEV Catalog

🔒 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added six vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity issue in Citrix NetScaler ADC and NetScaler Gateway with evidence of active exploitation. The list includes flaws affecting Microsoft SQL Server, the Linux Kernel, Red Hat components, Ajax.NET Professional, and Citrix, with CISA issuing remediation deadlines for federal agencies. Security firms reported web shells and discovery activity tied to attempts exploiting the Citrix flaw, and telemetry has identified multiple attacker IPs worldwide. CISA also published a vulnerability review highlighting injection and memory-safety weaknesses as frequent root causes of exploitation.
read more →

Attackers Target SharePoint RCE Chain and PoC Exploits

🛡️ Defused warns attackers are chaining two Microsoft SharePoint flaws — CVE-2026-55040 and CVE-2026-63520 — to achieve remote code execution on unpatched servers. Public proof-of-concept exploits were published in August and were quickly weaponized, with probes observed against honeypots and large-scale internet-exposed SharePoint instances. CISA has issued directives to secure SharePoint servers while Microsoft monitors exploitation activity.
read more →

Unpatched Kaltura mwEmbed flaws enable file read and RCE

🛡️ CERT/CC disclosed two unpatched vulnerabilities in Kaltura's mwEmbed/html5lib player that allow unauthenticated remote file reads and remote code execution via unsafe PHP deserialization. The flaws (CVE-2026-19913 & CVE-2026-19912) stem from mwEmbedLoader.php accepting an attacker-controlled ServiceUrl and using PHP's unserialize() without validation. No patch is available and CERT/CC was unable to reach Kaltura; administrators are advised to restrict endpoint access, allow-list ServiceUrl, and take mitigation steps including rotating credentials in local.ini.
read more →

AI accelerates attacks on exposed internet-facing servers

🔍 Cisco Talos reports a Chinese-speaking cybercrime group, tracked as UAT-10147, is using AI-driven tools to compromise internet-facing Windows and Linux web servers. Researchers found AI-generated operational guidance, tooling to refine exploits, and automation that accelerates post-access activity, with a target list of about 170,000 URLs. The group exploits publicly disclosed vulnerabilities for financially motivated goals like data theft and SEO fraud.
read more →

miniOrange SAML plugin under active exploitation

🔒 Patchstack and DigitalOcean reported active exploitation attempts against miniOrange SAML 2.0 Single Sign On, where two unauthenticated flaws allow attackers to authenticate as any WordPress user, including admins. The issues are tracked as CVE-2026-61979 and CVE-2026-15981 and have been fixed in recent Standard edition updates. Owners are urged to update immediately due to available PoC code and observed opportunistic scanning from multiple IPs.
read more →

CISA Adds Critical Oracle WebLogic Flaw to KEV

🔒 CISA has added a maximum-severity vulnerability affecting Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in (CVE-2026-21962, CVSS 10.0) to its Known Exploited Vulnerabilities catalog after evidence of active exploitation. The flaw allows unauthenticated HTTP access to create, modify, or delete critical data and potentially gain full access to affected instances. Oracle released patches in January, but reports from GreyNoise and CloudSEK indicate ongoing exploitation activity. Federal agencies must remediate under BOD 26-04 by August 27, 2026.
read more →

Unpatched Calix NAT bypass risk exposes internal devices

🔒 An unpatched authentication flaw in Calix GS7 XGS (GS5239XG) residential gateways running EXOS/6.6.47 lets remote unauthenticated attackers create and manipulate port-forwarding rules via the MiniUPnPd control endpoint on TCP port 5000. Researcher Brian Khan Quintana reported the issue as CVE-2026-75501 after failed vendor notification and worked with CERT/CC for disclosure. Exploitation can permanently open firewall rules that expose internal cameras, NAS, IoT devices, and admin interfaces; users are advised to disable UPnP or contact their ISP if the setting is locked.
read more →

Weekly Recap: AI-Enabled PLC Exploits Rise

🔍 U.S. agencies warn that threat actors are using AI to craft exploit scripts targeting internet-exposed Siemens S7 Series programmable logic controllers (PLCs), posing risks to water, energy, manufacturing, and other critical infrastructure. Attackers leverage public scanning services to locate vulnerable PLCs and deploy AI-generated tools that masquerade as legitimate monitoring software to probe and prepare for disruptive write operations. The advisory stresses this is an active, not theoretical, threat and highlights the need for improved segmentation, monitoring, and remediation.
read more →

Operation QUICSILVER: QUICAgent Targets Myanmar Networks

🛡️ Cybersecurity researchers have uncovered Operation QUICSILVER, a cyber espionage campaign targeting Myanmar's government and IT sectors that uses graduation ceremony invitation lures to deliver a Go-based backdoor named QUICAgent. First seen in April 2026, the multi-stage attack abuses a Windows Shortcut (LNK) and the legitimate ftp.exe binary as a LOLBAS to reconstruct and deploy the payload from hidden files inside a VHD. QUICAgent employs sandbox evasion, fetches a C2 address via Cloudflare Workers, and communicates over QUIC on UDP/443, while maintaining persistence through a Startup LNK.
read more →

CISA orders urgent Zimbra patching for active exploit

🔔 The Cybersecurity and Infrastructure Security Agency (CISA) directed U.S. federal civilian agencies to patch an actively exploited Zimbra Collaboration Suite flaw (CVE-2026-73570) within three days after CERT Polska reported in-the-wild attacks. The flaw, fixed in Zimbra 10.1.20 released July 20, permits unauthenticated remote code execution via a command injection in the SNMP notification component when enabled. Administrators are urged to review recent logs for indicators such as unexpected service restarts and newly created files under zimbra-owned webapps and /tmp directories.
read more →

Microsoft patches critical Entra ID deserialization flaw

🔐 Microsoft patched a maximum-severity vulnerability in Entra ID that was exploited in attacks, tracked as CVE-2026-69836. Discovered by Microsoft engineer Robert Fitzpatrick, the flaw allowed unauthenticated actors to achieve code execution via deserialization of untrusted data. Microsoft states the issue is fully mitigated and no user action is required, and said exploit code is not publicly available. The company provided limited additional details on the incidents.
read more →

GitLab critical code injection exploited rapidly

🛡️ A critical GitLab vulnerability, CVE-2026-19478 (CVSS 9.4), enables unauthenticated code injection allowing modification or deletion of public projects under certain conditions. Affected CE and EE versions include 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. GitLab released fixes in patched releases, while watchTowr reports rapid in-the-wild exploitation and reproduction using probes targeting GraphQL directives.
read more →