Live

Intelligence Feed

Latest threat intelligence articles from trusted security sources, auto-processed to extract entities, IoCs, and TTPs.

OperTraitors: How Kubernetes Operators Betray Your Security Posture

4d ago · unit42

Kubernetes operators, which automate cluster management, often have excessive RBAC permissions that create security risks. Researchers identified a high-severity vulnerability (CVE-2026-6389) in IBM's Prometurbo operator that granted cluster-wide access to secrets, enabling full environment compromise if exploited. The Datadog operator was also found with overly permissive configurations, highlighting a trade-off between usability and security. These misconfigurations are exacerbated by outdated, unmaintained components in public registries like OperatorHub, creating silent backdoors that could be exploited by attackers or abused by AI-driven agentic operators.

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution

3d ago · hacker-news

A critical buffer overflow vulnerability, CVE-2026-88772, in Citrix NetScaler ADC and Gateway has been actively exploited in the wild. The flaw exists in the Datagram Transport Layer Security (DTLS) protocol handling within the NetScaler Packet Processing Engine (NSPPE), where an inconsistency in fragment size validation leads to a heap-based buffer overflow. This allows unauthenticated remote attackers to execute arbitrary shellcode with root privileges by triggering memory corruption during packet reassembly. The vulnerability enables remote code execution due to improper bounds checking, and exploitation techniques have been demonstrated using mprotect() to bypass NX protections.

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

3d ago · hacker-news

OpenSSL has addressed a high-severity vulnerability, CVE-2026-84782, affecting DTLS implementations that can lead to heap memory leakage in unencrypted handshake data or cause a program crash. The flaw occurs when a DTLS handshake message is resent while a larger message is partially sent, resulting in the use of incorrect buffer positioning and potential exposure of sensitive memory contents. The vulnerability impacts multiple OpenSSL branches, with public fixes available for newer versions and only premium support customers receiving updates for older versions like 3.0, 1.1.1, and 1.0.2.

1 CVEs
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager

3d ago · hacker-news

Cisco has confirmed active exploitation of a critical zero-day authentication bypass vulnerability, CVE-2026-76504, in its Catalyst SD-WAN Manager. The flaw allows unauthenticated remote attackers to bypass authentication and access the system's API as an admin user by exploiting improper URI encoding handling in HTTP requests. The vulnerability affects all on-premises SD-WAN Manager installations regardless of configuration, with a CVSS score of 9.8, and no workaround exists other than applying fixed software releases. Cisco advises customers to restrict internet access to the Manager and check specific log files for signs of compromise involving URI-encoded paths like /%6a_security_check.

3 IoCs
Bitget hacked via zero-day in third-party security products

3d ago · bleeping-computer

Cryptocurrency exchange Bitget was breached in a $387.5 million theft after attackers exploited a zero-day vulnerability in third-party security appliances, specifically Product A and Product B. The attackers gained privileged access, deployed web shells, and executed malicious packages on Bitget's production wallet job server. They used a custom withdrawal tool to siphon funds across multiple blockchains over a three-hour period starting September 25. Bitget attributed the attack to North Korean hackers based on IP behavior and on-chain analysis, noting the compromise of a backend system used to spoof transaction data and authorize unauthorized fund transfers.

1 IoCs
TeamViewer urges users to patch severe flaws “as soon as possible”

3d ago · bleeping-computer

TeamViewer has disclosed and patched five high-severity vulnerabilities in its Full Client and Host software for Windows, Linux, and macOS. The most critical flaw, CVE-2026-92370, is a remote session access control bypass that could allow unauthorized remote code execution. The other vulnerabilities include a path traversal, a heap-based buffer overflow, a TOCTOU race condition, and improper path validation, all of which could enable local attackers to achieve remote code execution or privilege escalation. Although there is no evidence of active exploitation or public exploit code, TeamViewer strongly urges users to update to version 15.82 to mitigate potential risks.

2 Actors
CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

3d ago · bleeping-computer

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning about a critical pre-authentication remote code execution vulnerability, CVE-2026-84411, in MikroTik RouterOS. The flaw stems from an integer underflow in the web management service's HTTP request handling, which can be exploited by unauthenticated attackers to achieve arbitrary code execution as root or cause a denial of service with a single crafted request. Affected versions are RouterOS releases prior to 7.24, with mitigation advised through updating to version 7.23 or later. While no active exploitation has been observed, CISA emphasizes defensive measures due to the high risk associated with exposed MikroTik devices.

DIVD says Zammad zero-days enabled AI-driven network breach

2d ago · bleeping-computer

The Dutch Institute for Vulnerability Disclosure (DIVD) suffered a network breach enabled by a chain of two zero-day vulnerabilities in the Zammad ticketing system. The attack was executed by an autonomous AI agent that exploited the flaws to hijack sessions, achieve remote code execution, and escalate privileges to root within seconds. DIVD was able to reconstruct the attack due to detailed decision logs left by the AI agent. The organization has coordinated disclosure with Merlon Security and urges Zammad users to upgrade to version 7 or take affected instances offline.

Russian state hackers use new RedFlick technique to push malware

2d ago · bleeping-computer

Russian state actor Star Blizzard has been using a new malware delivery technique called 'RedFlick' to deploy the CosmicPulse backdoor. The attack begins with a phishing email containing a password-protected archive with a malicious VHDX file and an LNK shortcut disguised as a PDF. Upon execution, it creates multiple scheduled tasks to evade detection and downloads a Control Panel applet (.cpl) payload named NOROBOT or BAITSWITCH, which fetches and executes the final backdoor. The campaign has targeted Ukrainian entities and international organizations supporting Ukraine, with over 100 organizations impacted since early 2026.

3 IoCs 1 Actors 1 Malware
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

1w ago · hacker-news

Threat actor UNC6240, linked to ShinyHunters, is exploiting CVE-2026-35273, a critical unauthenticated remote code execution vulnerability in Oracle PeopleSoft, to deploy web shells and establish persistent access. The attackers bypass web application firewall (WAF) protections by URL-encoding the 'P' character as '%50' in requests to the vulnerable PSEMHUB endpoint. Exploitation leads to fileless command execution, deployment of JSP web shells, and installation of the SIDEEYE backdoor and Neo-reGeorg tunneling toolkit for data exfiltration and lateral movement. Targets span multiple sectors including education, healthcare, government, and technology, with the threat actor demonstrating root- and SYSTEM-level access on compromised systems.

6 IoCs 1 Actors
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

1w ago · hacker-news

Lunex Stealer, also known as Psychedelic Stealer, is a malware-as-a-service platform distributing information-stealing malware through compromised Ukrainian websites using fake CAPTCHA pages via ClickFix. The attack chain uses a malicious AMD driver (PDFWKRNL.sys) exploiting CVE-2023-20598 to bypass security monitoring via the BYOVD technique, enabling privilege escalation and evasion of EDR solutions. The malware steals credentials from multiple Chromium-based browsers, exfiltrates cryptocurrency wallet data, and establishes persistent remote access through a PowerShell-based Chrome Native Messaging Host. Command-and-control infrastructure includes multiple panels across 13 countries, with phishing domains linked to at least one Turkish-hosted panel.

6 IoCs
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks

6d ago · bleeping-computer

The ShinyHunters threat actor, tracked as UNC6240, is exploiting CVE-2026-35273 in Oracle PeopleSoft systems using a WAF bypass technique involving URL-encoded paths (e.g., '/%50SEMHUB/') to evade detection. This allows continued exploitation of unpatched servers where WAF rules were expected to block access. The attackers deploy JSP web shells (x.jsp, u.jsp, u2.jsp, tunnel.jsp, tunnel.jspx), execute in-memory commands, and deploy the SIDEEYE backdoor via 'Ple64.exe' on Windows systems. They also use Neo-reGeorg for tunneling and MeshAgent for persistence on Linux systems, targeting sectors including education, government, healthcare, and technology.

7 IoCs 1 Actors
A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity

2w ago · unit42

Unit 42 researchers identified a security issue in AWS AgentCore Harness where default configurations allow attackers to exfiltrate plaintext credentials from AgentCore Identity via prompt injection. The built-in shell tool, enabled by default and running as root, can access the memory space of the harness process (PID 1), where credentials are temporarily stored in plaintext during runtime. By injecting malicious commands through a support ticket, an attacker can execute reconnaissance and exfiltrate a JSON Web Token (JWT) used for downstream MCP server authentication. This stolen credential, belonging to the operator's service account (mcp-service), enables unauthorized access to sensitive data such as personally identifiable information (PII). AWS acknowledged the finding but classified it under customer responsibility, emphasizing proper scoping of allowedTools and egress filtering.

1 IoCs
GitHub Actions re-enabled with Mini Shai-Hulud payload still active

1w ago · bleeping-computer

Two previously compromised GitHub Actions, actions-cool/issues-helper and actions-cool/maintain-one-comment, were re-enabled by their maintainer on September 16, 2026, without removing the malicious payload from May's Mini Shai-Hulud supply-chain attack. The actions continued to serve an obfuscated malicious payload in 'index.js', causing dependent workflows to execute malware that targets developer tokens, credentials, and CI/CD secrets. The repositories were re-disabled on September 25 after researchers at Socket raised the alarm. Developers are advised to remove or pin these actions and rotate potentially exposed secrets.

2 IoCs
Trust and the enticing consultancy offer

1w ago · talos

The article is a commentary on social engineering tactics targeting cybersecurity professionals through fake consultancy offers and job scams, emphasizing the importance of trust in the industry. It does not describe a specific malware, vulnerability, or attack campaign with technical indicators. The piece also promotes a new open-source toolkit, CAIRN, and includes general security news summaries without detailed technical analysis or IoCs tied to a single threat event.

SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

1w ago · hacker-news

CISA has added two vulnerabilities to its Known Exploited Vulnerabilities catalog due to active in-the-wild exploitation. CVE-2026-65660 is a code injection flaw in Microsoft Office SharePoint that allows authenticated attackers to achieve remote code execution, which Microsoft initially classified as a spoofing issue. The second vulnerability, CVE-2026-67279, affects MikroTik RouterOS and enables unauthenticated attackers to open a session channel, which when combined with CVE-2026-86060 (an argument injection flaw), forms the 'MikroTrick' exploit chain allowing full administrative takeover of vulnerable routers without credentials.

Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

1w ago · hacker-news

A high-severity CSRF vulnerability in Elementor Website Builder WordPress plugin versions 4.3.0 and 4.3.1 allows unauthenticated attackers to take over WordPress sites by tricking an authenticated administrator into clicking a crafted link. The flaw bypasses CSRF protection for cookie-authenticated REST API requests when the string 'elementor/v1/events/' appears in the request URI, enabling actions like creating rogue administrator accounts. The vulnerability affects over 2 million sites and has been patched in version 4.3.2.

1 IoCs
Kiteworks urges 6-hour server shutdown over potential zero-day attacks

1w ago · bleeping-computer

Kiteworks has issued a precautionary advisory urging customers to shut down their servers for a six-hour window due to credible threat intelligence from federal authorities indicating a potential imminent cyberattack. While no confirmed breach or exploitation has been identified, the company suspects possible zero-day attacks targeting its secure file-sharing systems. The warning is preventative, with all known vulnerabilities already patched in the latest version (9.5.1). The Clop extortion gang is mentioned as a potential threat actor due to its history of targeting similar platforms.

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

1w ago · bleeping-computer

The Clop ransomware gang's data leak site was compromised by the ShinyHunters extortion group through an unpatched path traversal vulnerability in Grav CMS version 1.7.43. ShinyHunters exploited the flaw to upload malicious files, deface the site, and claim theft of source code, plugins, server logs, and Tor private keys, subsequently issuing a ransom demand. Grav CMS confirmed the vulnerability, tracked as CVE-2026-42608, resides in the core of Grav and was fixed in Grav 2.0 but not backported to the 1.7 branch until version 1.7.53.4 was released following disclosure.

1 Actors 1 CVEs
CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

1w ago · bleeping-computer

The Cybersecurity and Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, warning that they are actively exploited in attacks. These include a critical authentication bypass flaw (CVE-2026-5430) in WSO2 products, an incorrect authorization vulnerability (CVE-2026-71362) in Adobe Commerce and Magento, a high-severity code injection flaw (CVE-2026-65660) in Microsoft SharePoint, and a medium-severity SSH state-machine bypass (CVE-2026-67279) in Mikrotik RouterOS. Security firm watchTowr observed exploitation attempts against WSO2 using forged JWT tokens, and Sansec reported active exploitation of the Adobe Commerce flaw in the wild. Federal agencies are required to patch these flaws by September 27–28, 2026.

1 IoCs 1 CVEs
Elementor WordPress flaw lets attackers create admin accounts

1w ago · bleeping-computer

A cross-site request forgery (CSRF) vulnerability in Elementor plugin versions 4.3.0 and 4.3.1 for WordPress allows unauthenticated attackers to create administrator accounts by tricking a logged-in administrator into opening a malicious link. The flaw exists in the Editor Events module, which bypasses WordPress REST nonce validation when the request URI contains the 'elementor/v1/events/' path, enabling attackers to append this path via query parameters to trigger unauthorized REST API actions. The vulnerability was reported by security firm Patchstack and patched in version 4.3.2, with no CVE assigned at the time of reporting.

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

1w ago · hacker-news

Cryptocurrency exchange Bitget suffered a $351.6 million theft from its hot and warm wallets, attributed to suspected North Korean threat actors. The attackers compromised a critical backend system, spoofed transaction data, and triggered unauthorized fund transfers. While customer balances remain intact and cold wallets were unaffected, withdrawals have been suspended during a security review. Bitget has engaged Mandiant and SlowMist for investigation and is collaborating with blockchain foundations to freeze hacker-controlled wallet addresses. The attack pattern aligns with known North Korean hacking groups based on IP behavior and on-chain analysis.

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

1w ago · hacker-news

A new variant of the PamStealer macOS malware has been identified, featuring live command-and-control (C2) payload decryption and multi-layer persistence mechanisms. The malware is distributed via a fake cryptocurrency wallet website (wavel[.]app), which delivers a malicious disk image containing a compiled AppleScript that executes a JXA dropper. The dropper initiates a key exchange with the C2 server using X25519 to decrypt the payload, preventing static analysis. The malware employs four persistence methods, including LaunchAgent, shell hooks, and Git hooks, and ultimately deploys a Swift-based stealer to harvest credentials, browser data, keychain items, and system metadata.

5 IoCs
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

1w ago · hacker-news

Two compromised GitHub Actions, 'actions-cool/issues-helper' and 'actions-cool/maintain-one-comment', were reactivated on September 16, 2026, after being previously disabled due to their involvement in the Mini Shai-Hulud supply chain attack campaign. The repositories resumed serving malicious code that had been introduced on May 18, 2026, allowing credential harvesting from CI/CD pipelines without any new attacker action. The malicious payloads were re-downloaded and executed by workflows referencing the affected version tags, highlighting the risk of mutable version tags in supply chain security. The incident is linked to the Mini Shai-Hulud activity cluster, which also targeted npm packages under the @antv ecosystem.

4 IoCs
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud

1w ago · socket-dev

The compromised GitHub Actions repositories 'actions-cool/issues-helper' and 'actions-cool/maintain-one-comment' were re-enabled on September 16, 2026, while still hosting malicious code from the May 2026 Mini Shai-Hulud campaign. This reactivation allowed the malicious payload to execute in downstream workflows that referenced the actions by mutable tags, affecting an estimated 15,000+ repositories. The attack resumed without any new exploit or infrastructure, as the malicious tags were never cleaned. Workflows referencing these actions by tag instead of pinned commit SHA began executing the obfuscated payload, which installs the Bun runtime and runs a malicious script, potentially exfiltrating secrets and gaining unauthorized access.

4 IoCs
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

1w ago · hacker-news

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog due to evidence of active exploitation. CVE-2026-5430 is a path traversal flaw in WSO2 API Control Plane, API Manager, Traffic Manager, and Universal Gateway that enables unrestricted file upload and remote code execution. CVE-2026-71362 is an incorrect authorization vulnerability in Adobe Commerce and Magento that allows attackers to escalate privileges and access sensitive customer data without user interaction. Exploitation of both vulnerabilities has been observed in the wild, with attacks detected as early as September 10, 2026.

1 CVEs
Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data

1w ago · hacker-news

Cloudflare patched a vulnerability in its Containers and Sandboxes services that allowed a customer's container to read leftover disk data from previously deleted containers on the same server. The issue stemmed from thin-provisioned disks that were not properly wiped before reallocation, enabling data remnants—including SQLite databases, .env files, and browser profiles—to be recovered. The flaw was reported by researcher Oren Yomtov via Cloudflare's bug bounty program and was fixed by re-enabling block wiping and retiring all running container disks and caches. Cloudflare found no evidence of exploitation beyond authorized testing.

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

1w ago · hacker-news

A pre-authentication SQL injection vulnerability in Roundcube Webmail, tracked as CVE-2026-48842, is being actively exploited in the wild. The flaw exists in the virtuser_query plugin of versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1, allowing unauthenticated attackers to inject arbitrary SQL and potentially access mail account credentials and stored messages. The Canadian Centre for Cyber Security and SentinelOne have confirmed active exploitation, though specific threat actor details remain limited. Patches were released in May 2026, but over 500,000 Roundcube instances remain internet-exposed, with at least 10 identified as vulnerable as of late September 2026.

1 Malware 3 CVEs
Hackers steal $351.6 million in Bitget crypto exchange hack

1w ago · bleeping-computer

Cryptocurrency exchange Bitget suffered a breach in which $351.6 million was stolen from its hot and warm wallets. The attack is attributed to suspected North Korean hackers who compromised a critical backend system within Bitget's wallet infrastructure, enabling them to forge transaction data and trigger fund transfers. The breach affected multiple blockchain networks including Ethereum, XRP Ledger, Arbitrum, Avalanche, Optimism, BSC, and Base, with XRP suffering the largest single-chain loss. Bitget has suspended withdrawals pending investigation and confirmed that its cold wallets and self-custodial Bitget Wallet were unaffected. The losses will be covered by the User Protection Fund.

MacSync malware uses public iCloud calendars to deliver new payloads

1w ago · bleeping-computer

A new variant of the MacSync info-stealing malware targeting macOS systems has evolved to use public iCloud calendar events as a delivery mechanism for new payloads. Distributed via social engineering and fake applications such as a counterfeit crypto wallet called Toria, the malware retrieves commands from the description field of a public iCloud calendar, which are then executed in the macOS zsh shell. The infection chain leads to the deployment of a backdoor module written in Objective-C that masquerades as Finder, establishes persistence via LaunchAgent, .zshrc modifications, and Git hooks, and can execute remote AppleScripts, deploy malicious browser extensions, and exfiltrate system data.

1 IoCs
← Previous Next →