Overview of incoming advisories.
1553 results found
CVE-2026-61773 affects NVIDIA Megatron Bridge, exposing a deserialization of untrusted data vulnerability. An attacker who successfully exploits this flaw could achieve remote code execution, tamper with data, and access sensitive information. The vulnerability is rated high criticality given its potential impact across code execution, data integrity, and confidentiality. NVIDIA has published an advisory through their product-security GitHub repository. The issue is tracked by both the NVD and CVE Program. No additional technical details or proof-of-concept code have been publicly disclosed at this time. Users of NVIDIA Megatron Bridge are advised to monitor NVIDIA's security advisories for patches and mitigations.
View original advisory →A SQL injection vulnerability (CVE-2026-18210) has been identified in TRtek Technological Products Computer Software Hardware Industry and Trade Limited Company's 'Products Store' application. The vulnerability is classified as an improper neutralization of special elements used in SQL commands, allowing attackers to perform SQL injection attacks. All versions of Products Store prior to commit 030631b2 are affected. The vulnerability was reported via the Turkish cybersecurity authority (siberguvenlik.gov.tr) and published on the NVD. Exploitation could allow unauthorized access to or manipulation of the underlying database. Users are advised to update to a version at or after commit 030631b2 to remediate the issue.
View original advisory →CVE-2026-61751 is a high-severity vulnerability affecting NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, which can be exploited by an attacker to achieve remote code execution, data tampering, and information disclosure. The vulnerability was disclosed via the NVD and NVIDIA's product security advisory. No patch or workaround details are included in the article, and the NVD entry is still undergoing analysis. The potential impact is significant given the possible consequences of full code execution on affected systems. NVIDIA's product security GitHub repository references internal tracking number 5868 for this issue.
View original advisory →CVE-2026-61771 affects NVIDIA Megatron Bridge, a component likely related to NVIDIA's AI/ML infrastructure. The vulnerability involves deserialization of untrusted data, a class of flaw that can be particularly dangerous. A successful exploit could lead to remote code execution, data tampering, and information disclosure. The vulnerability was published via the NVD (National Vulnerability Database) and is also tracked on CVE.org. NVIDIA has published a security advisory on their GitHub product-security repository. The high severity rating reflects the potential for full system compromise. Organizations using NVIDIA Megatron Bridge should review NVIDIA's advisory and apply any available patches promptly.
View original advisory →CVE-2026-61767 is a high-severity vulnerability affecting NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, which can be exploited by an attacker to achieve code execution, data tampering, and information disclosure. The vulnerability is catalogued in the National Vulnerability Database and has an associated NVIDIA product security advisory. Successful exploitation could have significant impact on confidentiality, integrity, and availability. NVIDIA has published details via their product-security GitHub repository. No specific workarounds are mentioned in the article. Users of NVIDIA Megatron Bridge are advised to review the advisory for remediation steps.
View original advisory →A stored cross-site scripting (XSS) vulnerability has been identified in the web-based management interface of HPE Networking Fabric Composer. An authenticated low-privilege operator user can inject malicious scripts that are later executed in the browser of an administrative user. A successful exploit allows arbitrary script execution in the victim's browser within the context of the affected interface. This represents a privilege escalation risk, as a lower-privileged user can potentially compromise administrative sessions. The vulnerability requires authentication, limiting but not eliminating the attack surface. HPE has published a security bulletin addressing the issue. Organizations using HPE Networking Fabric Composer should apply available patches or mitigations promptly.
View original advisory →CVE-2026-61766 is a high-severity vulnerability affecting NVIDIA Megatron Bridge. The flaw involves deserialization of untrusted data, which can be exploited by an attacker to achieve remote code execution, tamper with data, and disclose sensitive information. The vulnerability was published via the NVD and NVIDIA's product security advisory. No authentication or user interaction details are specified in the current disclosure. The potential impact is significant given the consequences include code execution and data tampering. NVIDIA has published an advisory on their GitHub product-security repository. Organizations using NVIDIA Megatron Bridge should review the advisory and apply any available patches promptly.
View original advisory →Kyverno versions v1.9.0 through v1.12.7 contain a flaw in policy exception handling. When a policy running in enforce mode is combined with two PolicyExceptions, the less restrictive exception incorrectly takes precedence over the more restrictive one. An attacker can exploit this by crafting a resource name that matches the second exception's wildcard name pattern (e.g., '*ingress*'), effectively bypassing enforced policies. This vulnerability can be used to circumvent critical security policies, such as those blocking hostPath volume mounts in Kubernetes workloads. The issue represents a security control bypass in a Kubernetes-native policy engine widely used for admission control. The flaw was fixed in Kyverno v1.13.0. Organizations running affected versions should upgrade immediately to mitigate the risk of policy bypass attacks.
View original advisory →The Cronos blockchain network was forced to restart following a price-manipulation attack targeting the Tectonic cryptocurrency lending platform. An attacker exploited the platform to borrow approximately $74 million through the manipulation attack. Cronos subsequently halted and then resumed trading activity after addressing the incident. The attack highlights ongoing vulnerabilities in decentralized finance (DeFi) lending protocols, particularly around price oracle manipulation. Tectonic is a crypto lending service built on the Cronos blockchain. The exploit allowed the attacker to leverage manipulated asset prices to borrow funds far exceeding what would normally be collateralized. This type of flash loan or price oracle attack is a recurring threat vector in the DeFi ecosystem. The incident underscores the financial risks associated with DeFi platforms and the systemic impact such exploits can have on underlying blockchain networks.
View original advisory →A researcher running an internet-exposed inference honeypot discovered it had been co-opted by adversaries who relabeled it with popular AI model names and incorporated it into infrastructure advertised as providing 'free' LLM backends. The honeypot subsequently received a real coding-agent session containing sensitive context including conversation history, filesystem output, working directory paths, and the agent's local tool manifest. The researcher clarifies the honeypot did not request or trigger any tool execution, but the incident demonstrates what a malicious operator in that position could do with such access. This highlights a significant supply-chain and data-exposure risk for developers using unverified or 'free' LLM endpoints with AI coding agents. The attacker effectively performed a man-in-the-middle interception of an AI agent workflow, gaining visibility into the developer's local environment. The scenario underscores risks of trusting unverified AI infrastructure and the potential for credential, code, and environment data exfiltration through compromised LLM endpoints.
View original advisory →Microsoft has issued a warning about a new variant of the ClickFix social engineering technique called TerminalFix. The attack leverages fake Cloudflare CAPTCHA prompts displayed on compromised websites to deceive victims. Users are tricked into copying and running malicious PowerShell commands in Windows Terminal. The campaign deploys reverse tunnels as part of its payload delivery or persistence mechanism. TerminalFix represents an evolution of the ClickFix attack pattern, expanding the attack surface beyond the Run dialog to Windows Terminal. The use of reverse tunnels suggests the attackers seek persistent, covert access to compromised systems. This technique is particularly dangerous as it abuses legitimate user interfaces and trusted brand names like Cloudflare.
View original advisory →Socket's Threat Research Team discovered 13 malicious Composer/Packagist theme packages across five vendor namespaces (vsmov, vsphim, haiau009, chilltvcms, ophimcms) that inject malicious JavaScript into Vietnamese movie and comic streaming sites. The injected code runs two operations: a mobile ad-fraud/gambling redirect chain, and on iPhones, a WebKit-to-kernel exploit chain (DarkSword-linked, using CVE-2025-31277 and CVE-2025-43529) that installs spyware. The spyware collects keychain data, Wi-Fi passwords, SMS, contacts, photos, browser cookies, location history, and cryptocurrency wallet seeds from seven wallet apps (Bitget, BitKeep, Bitpie, Phantom, Tonkeeper, Trust Wallet, OKX). The campaign is attributed to Vietnamese-operated threat actors using FUNNULL infrastructure (sanctioned by OFAC). On 2026-08-12, the operators redeployed with fresh filenames and added crypto-wallet seed theft. The kernel escape was patched in iOS 26.1 and WebKit entry points in iOS 18.7.3/iOS 26.2; unpatched devices remain vulnerable.
View original advisory →Berlin's city administration has confirmed a data theft incident after the Rhysida ransomware gang listed the city on their data leak site. The cybercriminals are actively attempting to extort the city government. Rhysida is a ransomware-as-a-service group known for targeting government and public sector entities. The attack resulted in confirmed exfiltration of data belonging to the city. Berlin authorities are responding to the extortion attempt. This incident highlights the continued targeting of European municipal governments by ransomware groups. The Rhysida gang uses double extortion tactics, threatening to publish stolen data if ransom is not paid.
View original advisory →The Silver Fox threat actor has been distributing the ValleyRAT backdoor disguised as a signed Chinese adware application called QN Wallpaper, a legitimate desktop-wallpaper tool. By hiding malware within a signed application, attackers exploit the tendency of users to add trusted or familiar software to antivirus exclusion lists. This allows the malware to run under a trusted process, effectively bypassing antivirus detection. Kaspersky, a Russian cybersecurity vendor, identified and reported on this campaign. The technique highlights the growing abuse of signed software and user trust as a vector for malware delivery. The campaign demonstrates sophisticated social engineering combined with code-signing abuse to evade security controls.
View original advisory →Threat actors linked to Aurora ransomware (also known as Aur0ra) have been observed leveraging Cursor, an AI-powered coding assistant, to conduct attacks against at least 10 targets. The findings come from independent analyses by CloudSEK and Gambit Security, based on exposed infrastructure tied to the Russian-speaking cybercrime group. The use of AI coding tools in ransomware operations marks a notable evolution in attack methodology. The group appears to be utilizing Cursor to assist in developing or refining attack tooling. This incident highlights growing concerns about the abuse of legitimate AI development tools by ransomware operators.
View original advisory →The Spring Ring campaign exploits Microsoft Teams as a vector for voice phishing (vishing) attacks targeting enterprise environments. Attackers abuse Teams' communication features to socially engineer victims into executing malware. The campaign ultimately aims to compromise enterprise domain controllers, indicating a high-level threat to organizational infrastructure. The attack chain combines voice-based social engineering with malware deployment, making it a sophisticated multi-stage operation. This research from Palo Alto Networks Unit 42 provides an inside look at the tactics, techniques, and procedures used in these campaigns. The targeting of domain controllers suggests the threat actors are seeking privileged access and lateral movement within enterprise networks.
View original advisory →A China-linked cyber espionage group tracked as Fire Ant has expanded its campaign beyond VMware hypervisors to target Cisco IOS XR routers, TACACS servers, and Linux management hosts. The threat actor aims to steal credentials and disable security logging on high-value networks. Incident response firm Sygnia investigated the intrusion and attributed it to Fire Ant. The campaign targets critical network infrastructure used for routing, authentication, and management. The expansion of attack surface suggests an evolving and sophisticated threat actor with persistent access objectives. TACACS server compromise enables credential theft at scale across managed network devices. Blinding security logs indicates deliberate operational security measures to evade detection. The campaign reflects broader Chinese cyber espionage interest in telecommunications and enterprise network infrastructure.
View original advisory →The U.S. Department of Justice issued a correction to a previously released press statement regarding Chinese threat actor attacks on U.S. government agencies. The DoJ clarified that agencies including NASA, the Federal Reserve, the Department of Energy, and the DoJ itself were targeted rather than confirmed victims. This distinction between 'targeted' and 'victims' is significant in cybersecurity and legal contexts. The correction suggests the initial statement may have overstated the impact or success of the intrusion attempts. The incident highlights ongoing Chinese cyber espionage efforts directed at critical U.S. government institutions. The clarification raises questions about the accuracy of initial threat assessments and public communications from federal agencies.
View original advisory →PaperCut NG/MF contains a critical unsafe reflection vulnerability (CVE-2026-82078) that allows attackers to manipulate system configuration parameters and execute arbitrary Java bytecode on the application classpath. The execution occurs under the security context of the PaperCut server process, granting significant privileges to a potential attacker. This vulnerability can be chained with CVE-2026-81578 to increase attack impact. CISA has flagged this vulnerability under BOD 26-04, which prioritizes security updates based on risk. PaperCut has issued an urgent security advisory urging immediate patching. Forensic triage requirements have also been outlined by CISA for affected organizations. The vulnerability poses a high risk to enterprise print management environments running PaperCut NG or MF.
View original advisory →PaperCut NG/MF contains a missing authentication for critical function vulnerability (CVE-2026-81578) that allows unauthenticated remote attackers to modify system configurations. The vulnerability can be chained with CVE-2026-82078 to potentially increase the impact of exploitation. CISA has flagged this vulnerability under BOD 26-04, requiring prioritized security updates. An urgent security advisory was published by PaperCut on August 27, 2026. The flaw is classified as high severity due to its unauthenticated remote exploitation potential. Organizations using PaperCut NG/MF are urged to apply patches immediately. CISA also provides forensic triage requirements as part of the BOD 26-04 implementation guidance.
View original advisory →