Category: Cybersecurity

  • Cybersecurity Intelligence Report — 16 June 2026

    Open the companion HTML intelligence dashboard

    Executive signal: Today’s collection produced 106 new unique intelligence items. The highest scoring signals are concentrated around ransomware data-leak activity, exploited Cisco SD-WAN exposure, a WordPress plugin supply-chain compromise, and recently added CISA Known Exploited Vulnerabilities.

    1. Critical section — score ≥ 10

    No collected item reached the score ≥ 10 critical threshold in this run. Teams should still prioritise the exploited Cisco SD-WAN issue, current KEV additions, and ransomware leak signals below.

    2. CISA KEV — Known Exploited Vulnerabilities

    CVE Vendor/Product Score Required action
    CVE-2026-54420 CVE-2026-54420: LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability – LiteSpeed cPanel Plugin 6 LiteSpeed cPanel Plugin UNIX Symbolic Link (Symlink) Following Vulnerability – LiteSpeed cPanel Plugin. Required action: Apply mitigations in accordance with vendor instructions,…
    CVE-2026-20262 CVE-2026-20262: Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability – Cisco Catalyst SD-WAN Manager 6 Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability – Cisco Catalyst SD-WAN Manager. Required action: Apply mitigations in accordance with vendor…

    3. Ransomware victims — DLS monitoring

    nova: Kedah (MY)

    qilin: Misericórdia de Santo Tirso (PT), Q Link Wireless (US)

    4. News section — other scored items

    [8] ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and More (TheHackerNews)

    Stuff broke again. Not in a movie way. An old tool was left exposed. An abandoned package was abused. A deprecated feature was still running in prod. This week is the same lesson in a new form: phishing kits are easier to rent, AI names are useful bait, old login paths still fail, and forgotten software keeps becoming someone else's entry point. Scroll…

    [7] Cisco fixes SD-WAN vManage flaw exploited in zero-day attacks (BleepingComputer)

    CVEs: CVE-2026-20262. Cisco has released security updates to address a vulnerability in the Catalyst SD-WAN Manager, tracked as CVE-2026-20262, that was exploited in attacks to escalate to root privileges. […]

    [6] OptinMonster WordPress plugin hacked in CDN supply-chain attack (BleepingComputer)

    WordPress plugins OptinMonster, TrustPulse, and PushEngage have been compromised in a supply-chain attack impacting Awesome Motive-s content distribution network (CDN). […]

    [6] Infinite Campus data breach affects 137,000 school staff accounts (BleepingComputer)

    The ShinyHunters extortion gang stole personal information from more than 137,000 school staff accounts in a Salesforce data theft attack that targeted the widely used Infinite Campus K-12 student information system in March. […]

    [5] Council of Europe investigates ShinyHunters data breach claims (BleepingComputer)

    The Council of Europe, the continent's oldest intergovernmental body, is probing claims of a data breach made by the ShinyHunters extortion group over the weekend. […]

    [5] Chinese hackers breach REDCap servers, steal medical research (BleepingComputer)

    A China-linked espionage campaign targeted exposed REDCap servers to deploy the InfiniteRed malware and steal sensitive data from a medical institution in North America. […]

    [5] Palo Alto Warns of Active Exploitation of PAN-OS GlobalProtect VPN Flaw (TheHackerNews)

    CVEs: CVE-2026-0257. Palo Alto Networks has revealed that it has observed "active exploitation" of a recently disclosed PAN-OS vulnerability by an unknown threat actor to obtain unauthorized access to GlobalProtect portals. The vulnerability in question is CVE-2026-0257 (CVSS score: 7.8), an authentication bypass flaw affecting the portal and gateway components of PAN-OS…

    [5] Chinese hackers breached North American research institutions via REDCap servers (HelpNetSecurity)

    <p>A China-linked cyber espionage operation targeted North American medical research institutions through compromised REDCap servers, using custom malware to gain persistent access and collect sensitive information, Google&#8217;s Threat Intelligence Group (GTIG) researchers found. UNC6508 exploits vulnerable REDCap servers GTIG attributed the campaign to…

    [5] Delinea and Cyera integrate for data-aware identity security (HelpNetSecurity)

    <p>Delinea and Cyera announced a product integration that connects privileged access to sensitive data exposure, automatically correlating identities with the data they can access. Together, Delinea and Cyera help security teams identify, prioritize, and remediate the highest-risk access paths across every human, machine, and AI agent. As identities…

    5. Summary

    Total new items: 106. Critical count: 0. Ransomware groups active today: 2. Top CVEs to patch urgently: CVE-2026-20262, CVE-2026-54420, CVE-2026-0257.

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

  • Cybersecurity Intelligence Report — 15 June 2026

    Daily cybersecurity intelligence dispatch for 15 June 2026. We analyse the most significant exploited vulnerabilities, active ransomware operations and notable security developments, drawing on credible primary sources.

    1. Critical Section

    [10] Week in review: Exploited Check Point VPN zero-day, Oracle PeopleSoft servers under attack (HelpNetSecurity)

    Last week was dominated by an actively exploited Check Point VPN zero-day and a wave of attacks against unpatched Oracle PeopleSoft servers. Organisations running these platforms should prioritise emergency patching and review logs for signs of compromise, as both flaws are being weaponised in the wild.

    2. CISA Known Exploited Vulnerabilities (last 14 days)

    CVE Vendor / Product Score Required Action
    CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleTools KEV (2026-06-12) Remediate by 2026-06-15 per vendor guidance
    CVE-2026-10520 Ivanti Sentry KEV (2026-06-11) Remediate by 2026-06-14 per vendor guidance
    CVE-2026-11645 Google Chromium V8 KEV (2026-06-09) Remediate by 2026-06-23 per vendor guidance
    CVE-2026-7473 Arista Extensible Operating System KEV (2026-06-09) Remediate by 2026-06-23 per vendor guidance
    CVE-2026-20245 Cisco Catalyst SD-WAN Manager KEV (2026-06-09) Remediate by 2026-06-23 per vendor guidance
    CVE-2026-42271 BerriAI LiteLLM KEV (2026-06-08) Remediate by 2026-06-22 per vendor guidance
    CVE-2026-50751 Check Point Security Gateway KEV (2026-06-08) Remediate by 2026-06-11 per vendor guidance
    CVE-2026-28318 SolarWinds Serv-U KEV (2026-06-05) Remediate by 2026-06-19 per vendor guidance
    CVE-2026-45247 Mirasvit Mirasvit Full Page Cache Warmer KEV (2026-06-03) Remediate by 2026-06-06 per vendor guidance
    CVE-2022-0492 Linux Kernel KEV (2026-06-02) Remediate by 2026-06-05 per vendor guidance
    CVE-2025-48595 Android Framework KEV (2026-06-02) Remediate by 2026-06-05 per vendor guidance
    CVE-2024-21182 Oracle WebLogic Server KEV (2026-06-01) Remediate by 2026-06-04 per vendor guidance

    3. Ransomware Victims (DLS Monitoring)

    AuditTeam: I-***YS (RU)

    dragonforce: Ink (GB)

    krybit: frey.com (CH)

    nightspire: Silsbee Police Department (US), K****** County. Mi**e**ta, WaxWorks Inc (US), Blue Nile Medical Center (US)

    nova: Bandung (ID)

    4. News Section

    FBI disrupts massive AI-powered phishing service using a million URLs (BleepingComputer) — The FBI, working with Google and Black Lotus Labs, has dismantled a sprawling Chinese phishing-as-a-service operation known as Outsider Enterprise, which leveraged AI to generate over a million malicious URLs harvesting card and credential data.

    5. Summary

    Total new items analysed: 10 · Critical-tier: 1 · Active ransomware groups: 5 (AuditTeam, dragonforce, krybit, nightspire, nova) · KEV additions tracked: 12.

    Prioritise patching: CVE-2026-35273, CVE-2026-10520, CVE-2026-11645, CVE-2026-7473, CVE-2026-20245. The Oracle PeopleSoft (CVE-2026-35273), Ivanti Sentry (CVE-2026-10520) and Check Point Security Gateway (CVE-2026-50751) flaws are past or imminent on their CISA remediation deadlines and warrant immediate attention.

    📊 View the full interactive HTML intelligence dashboard →

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

  • Cybersecurity Intelligence Report — 14 June 2026

    Daily cybersecurity intelligence digest for 14 June 2026. Our automated collection pipeline processed feeds from BleepingComputer, The Hacker News, SecurityWeek, Help Net Security, KrebsOnSecurity, the CISA Known Exploited Vulnerabilities catalogue and ransomware.live data-leak-site monitoring. Below is today’s prioritised analysis.

    1. Critical alerts (score ≥ 10)

    • [11] [RANSOMWARE] lapsus$ leaked INGKA GROUP (ransomware.live)
      A major data-leak event affecting INGKA GROUP (SE). This represents a high-severity breach with substantial organisational exposure and should be treated as a priority for affected supply chains.

    2. CISA Known Exploited Vulnerabilities (last 14 days)

    No new CISA KEV catalogue additions were recorded in today’s collection window.

    3. Ransomware victims — data-leak-site monitoring

    • lapsus$: INGKA GROUP (SE); GITHUB INTERNAL (US)
    • shinyhunters: coe.int (FR)
    • krybit: www.mbt-energy.com (DE)
    • securotrop: Charisma Media (US)
    • Black X: Daechang Solution (KR)
    • Triple X: Bni.co.id bank of indonesia free data. (ID); Law Offices US immigrationonline.com (US)

    Listings reflect claims published on criminal data-leak sites and have not been independently verified. Organisations named should treat these as alleged compromises pending confirmation.

    4. Security news (score ≥ 5)

    5. Summary

    • Total new items analysed: 15
    • Critical items (score ≥ 10): 1
    • CISA KEV additions: 0
    • Ransomware data-leak victims: 8 across 6 active group(s)
    • CVEs to prioritise for patching: CVE-2026-20253

    The most pressing patching priority today is CVE-2026-20253 — organisations running affected software should apply the vendor update without delay given the unauthenticated remote-code-execution risk.

    Active ransomware operators today: Black X, Triple X, krybit, lapsus$, securotrop, shinyhunters. Defenders should review external attack surface, enforce multi-factor authentication, and validate offline backups.

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    📊 View the interactive HTML threat dashboard for today

  • Cybersecurity Daily — 13 June 2026

    Cybersecurity Daily — 2026-06-13

    CRITICAL SECTION

    Items with zero-days, exploited-in-wild, critical CVEs

    • [13] Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters (CVE-2026-35273) (SecurityWeek)
    • [11] Researchers release details, PoC for exploited Check Point VPN flaw (CVE-2026-50751) (CVE-2026-50751) (HelpNetSecurity)

    CISA KEV SECTION (Known Exploited Vulnerabilities)

    Only include items from last 14 days

    CVE Vendor/Product Score Required Action
    CVE-2026-35273 Oracle PeopleSoft Enterprise PeopleTools Missing Authentication for Critical Function Vulnerability – Oracle PeopleSoft Enterprise PeopleTools 9 See CISA KEV entry

    RANSOMWARE VICTIMS (DLS Monitoring)

    Group by ransomware group. Only include today’s victims.

    payload: myipo.gov.my

    NEWS SECTION

    Other scored items (score >= 5)

    • [13] Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters (SecurityWeek) – Oracle has mitigated CVE-2026-35273, but it has not publicly confirmed the vulnerability’s in-the-wild exploitation.
      The post Google Confirms Exploitation of Oracle PeopleSoft Zero-Day by ShinyHunters…
    • [11] Researchers release details, PoC for exploited Check Point VPN flaw (CVE-2026-50751) (HelpNetSecurity) – WatchTowr researchers have disclosed a technical analysis and a “Detection Artefact Generator” for CVE-2026-50751, an authentication bypass flaw in Check Point’s Remote Access VPN an…
    • [8] [RANSOMWARE] shinyhunters leaked Zayo.com & Allstream.com (ransomware.live/shinyhunters) – Victim: Zayo.com & Allstream.com | Group: shinyhunters | Country: US | Details: You wouldn’t want us to describe what data was taken from you publicly here. A fair assessment of this breach in terms o…
    • [7] LangGraph Flaw Chain Exposes Self-Hosted AI Agents to Remote Code Execution (TheHackerNews) – Cybersecurity researchers have disclosed details of three now-patched security flaws impacting LangGraph, including a critical vulnerability chain that could result in remote code execution.

      LangGrap…

    • [7] Ivanti Sentry Exploitation Attempts Hitting Honeypots (SecurityWeek) – The critical-severity OS command injection vulnerability allows attackers to execute arbitrary code with root privileges.
      The post Ivanti Sentry Exploitation Attempts Hitting Honeypots appeared first …
    • [7] Authorities dismantle crypto laundering service that moved €336 million for cybercriminals (HelpNetSecurity) – An international law enforcement operation has dismantled a cryptocurrency laundering service linked to ransomware groups and other cybercriminals that processed more than €336 million in illicit fund…
    • [7] [RANSOMWARE] threeam leaked mgrlaw.com (ransomware.live/threeam) – Victim: mgrlaw.com | Group: threeam | Website: mgrlaw.com | Country: US | Details: Mogren, Glessner & Ahrens Law Firm is a full-service law firm located in King County, specializing in family law, div…
    • [7] [RANSOMWARE] coinbasecartel leaked Demand.io (ransomware.live/coinbasecartel) – Victim: Demand.io | Group: coinbasecartel | Website: Demand.io | Country: US | Details: [AI generated] Demand.io is a technology company based in the United States that operates in the e-commerce and …
    • [7] [RANSOMWARE] dragonforce leaked Cheoy Lee Shipyards (ransomware.live/dragonforce) – Victim: Cheoy Lee Shipyards | Group: dragonforce | Website: www.cheoylee.com | Country: HK | Details: Cheoy Lee Shipyards Ltd. specializes in the design and manufacturing of a diverse range of vessels…
    • [7] [RANSOMWARE] dragonforce leaked Al Ishrak Contracting (ransomware.live/dragonforce) – Victim: Al Ishrak Contracting | Group: dragonforce | Website: www.alishrak.com | Country: AE | Details: Al Ishrak Contracting Company, established in 1975 in Dubai, specializes in construction works i…
    • [7] [RANSOMWARE] dragonforce leaked Corniche Hotel Abu Dhabi (ransomware.live/dragonforce) – Victim: Corniche Hotel Abu Dhabi | Group: dragonforce | Website: abudhabi.corniche-hotels.com | Country: AE | Details: At the heart of the Central Business District. Situated along the stunning Cornic…
    • [7] [RANSOMWARE] dragonforce leaked A. Liberty Engineering Co. Ltd (ransomware.live/dragonforce) – Victim: A. Liberty Engineering Co. Ltd | Group: dragonforce | Website: aleengg.com.hk | Country: HK | Details: Founded in 1973 as Liberty Electrical Engineering Company Limited, A. Liberty Engineering…
    • [7] [RANSOMWARE] dragonforce leaked Al Shafar GRC (ransomware.live/dragonforce) – Victim: Al Shafar GRC | Group: dragonforce | Website: www.asgrc.ae | Country: AE | Details: ASGRC is a leading provider of Glass Fiber Reinforced Concrete (GRC) solutions, specializing in the design, …
    • [7] [RANSOMWARE] dragonforce leaked The DRM (ransomware.live/dragonforce) – Victim: The DRM | Group: dragonforce | Website: www.drm.bh | Country: BH | Details: Durrat Resort Management specializes in providing high-quality resort management services. Their offerings include o…
    • [6] CISA orders feds to patch actively exploited Ivanti flaw by Sunday (BleepingComputer) – The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies to patch an actively exploited Ivanti Sentry flaw within three days, as mandated by the newly issued Bindin…
    • [5] In Other News: Google Security Layoffs, AudiA6 Takedown, $400 Million Coupang Fine (SecurityWeek) – Other noteworthy stories that might have slipped under the radar: ICS device exposure remains flat as attack surface widens, Microsoft issues incident response playbook for AI, IBM and AT&T accus…
    • [5] [RANSOMWARE] stormous leaked mlit.com.my (ransomware.live/stormous) – Victim: mlit.com.my | Group: stormous | Website: mlit.com.my | Country: MY | Details: We have successfully breached the internal servers and network infrastructure of MLIT, gaining full unauthorized a…
    • [5] [RANSOMWARE] threeam leaked jetmachprod.com (ransomware.live/threeam) – Victim: jetmachprod.com | Group: threeam | Website: jetmachprod.com | Details: Jet Machined Products specializes in high-performance milled and turned components for the aerospace, instrumentation, ro…
    • [5] [RANSOMWARE] threeam leaked jastrebarsko.hr (ransomware.live/threeam) – Victim: jastrebarsko.hr | Group: threeam | Website: jastrebarsko.hr | Country: HR | Details: Town of Jastrebarsko, a historic city in Central Croatia located between Zagreb and Karlovac.
    • [5] [RANSOMWARE] threeam leaked palmero.com (ransomware.live/threeam) – Victim: palmero.com | Group: threeam | Website: palmero.com | Details: Palmero is a company dedicated to the manufacturing and marketing of capital goods, providing comprehensive solutions across vari…
    • [5] [RANSOMWARE] threeam leaked insamani.com.ar (ransomware.live/threeam) – Victim: insamani.com.ar | Group: threeam | Website: insamani.com.ar | Country: AR | Details: INSA INDELMA S.A. is a leading agro-industrial company in Argentina specializing in peanut production, expo…
    • [5] [RANSOMWARE] threeam leaked bsynchro.com (ransomware.live/threeam) – Victim: bsynchro.com | Group: threeam | Website: bsynchro.com | Country: DE | Details: BSynchro Holding is an insurtech software provider that specializes in innovative insurance solutions tailored fo…
    • [5] [RANSOMWARE] threeam leaked molinoscabodi.com.ar (ransomware.live/threeam) – Victim: molinoscabodi.com.ar | Group: threeam | Website: molinoscabodi.com.ar | Country: AR | Details: Molinos Cabodi Hnos. S.A. has been providing high-quality flour products since 1853, including va…
    • [5] [RANSOMWARE] threeam leaked ws.com.br (ransomware.live/threeam) – Victim: ws.com.br | Group: threeam | Website: ws.com.br | Country: BR | Details: WS Group Brasil is a Brazilian operations and business services provider engaged in logistics, technical support, contr…
    • [5] [RANSOMWARE] threeam leaked consultic.be (ransomware.live/threeam) – Victim: consultic.be | Group: threeam | Website: consultic.be | Country: BE | Details: ConsulTIC specializes in IT solutions, offering services such as application hosting, virtualization, telecommuti…
    • [5] [RANSOMWARE] threeam leaked amc.org.au (ransomware.live/threeam) – Victim: amc.org.au | Group: threeam | Website: amc.org.au | Country: AU | Details: The Australian Medical Council (AMC) is an independent national standards body responsible for the accreditation and …
    • [5] [RANSOMWARE] threeam leaked agroexportavocados.com (ransomware.live/threeam) – Victim: agroexportavocados.com | Group: threeam | Website: agroexportavocados.com | Country: MX | Details: Agro Industrial Exportadora SA de CV (AGRIEXP) is a Mexican holding company which is engaged …
    • [5] [RANSOMWARE] threeam leaked hoplongtech.com (ransomware.live/threeam) – Victim: hoplongtech.com | Group: threeam | Website: hoplongtech.com | Country: VN | Details: Công ty Cổ phần Công Nghệ Hợp Long is a leading distributor of automation equipment and industrial robotics…
    • [5] [RANSOMWARE] coinbasecartel leaked Cambridge Mobile Telematics (ransomware.live/coinbasecartel) – Victim: Cambridge Mobile Telematics | Group: coinbasecartel | Country: US | Details: [AI generated] Cambridge Mobile Telematics (CMT) is an American telematics technology company headquartered in Camb…
    • [5] [RANSOMWARE] shadowbyt3$ leaked Nintendo Company (Nintendo.com) (ransomware.live/shadowbyt3$) – Victim: Nintendo Company (Nintendo.com) | Group: shadowbyt3$ | Website: Nintendo.com | Country: JP | Details: proof: https://mega.nz/folder/3kBzQKgR#rIhDePsPMeFpfEGTPopDVQ We are ShadowByt3$ a extorti…
    • [5] [RANSOMWARE] qilin leaked DISTINET MURCIA SL (ransomware.live/qilin) – Victim: DISTINET MURCIA SL | Group: qilin | Website: www.distinetmurcia.es | Country: ES | Details: N/A
    • [5] [RANSOMWARE] gunra leaked MHE9 Logística Ltda (ransomware.live/gunra) – Victim: MHE9 Logística Ltda | Group: gunra | Website: grupomhe9.com.br | Country: BR | Details: [AI generated] N/A
    • [5] [RANSOMWARE] gunra leaked Suárez&Clavera (ransomware.live/gunra) – Victim: Suárez&Clavera | Group: gunra | Website: suarezyclavera.com.uy | Country: UY | Details: [AI generated] N/A
    • [5] [RANSOMWARE] akira leaked DDC Domus Design Collection (ransomware.live/akira) – Victim: DDC Domus Design Collection | Group: akira | Details: Founded in 1991 and headquartered in New York City, New York, DDC Domus Design Collection is a
      company that manufactures as well as sell …
    • [5] [RANSOMWARE] shinyhunters leaked Madison Square Garden Sports Corp. (ransomware.live/shinyhunters) – Victim: Madison Square Garden Sports Corp. | Group: shinyhunters | Country: US | Details: Over 26 million records containing customer PII and other internal corporate data was compromised. This is a f…
    • [5] [RANSOMWARE] shinyhunters leaked JCPenney & several other subsdiaries under Catalyst Brands & Authentic Brands Group (ransomware.live/shinyhunters) – Victim: JCPenney & several other subsdiaries under Catalyst Brands & Authentic Brands Group | Group: shinyhunters | Country: US | Details: Hundreds of thousands of records containing PII (SSN, DOB, et…
    • [5] [RANSOMWARE] shinyhunters leaked American Tower Corporation (ransomware.live/shinyhunters) – Victim: American Tower Corporation | Group: shinyhunters | Country: US | Details: Over 5.2 million records consiting of a significant amount of customer and landowner PII, other records tied to other …
    • [5] [RANSOMWARE] krybit leaked aisem.gob.bo (ransomware.live/krybit) – Victim: aisem.gob.bo | Group: krybit | Website: aisem.gob.bo | Country: BO | Details: AISEM (Agencia de Infraestructura en Salud y Equipamiento Médico) is a Bolivian government agency responsible for …
    • [5] [RANSOMWARE] krybit leaked www.progress-security.com (ransomware.live/krybit) – Victim: www.progress-security.com | Group: krybit | Website: www.progress-security.com | Country: DE | Details: Progress Security Systems is a leading UAE-based provider of enterprise-grade security s…
    • [5] [RANSOMWARE] insomnia leaked The Vant Group (ransomware.live/insomnia) – Victim: The Vant Group | Group: insomnia | Website: www.thevantgroup.com | Country: US | Details: The Vant Group, founded in 1999, is an M&A advisory firm serving businesses up to $250M in revenue. It…

    SUMMARY

    Total new items: 69

    Critical count: 2

    Ransomware groups active: 1

    Top CVEs to patch urgently: CVE-2026-50751, CVE-2026-35273

    Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Companion HTML report: Click to view the full report

  • Cybersecurity Intelligence Report — 11 June 2026

    Critical Section — Zero-Day / RCE / Exploited in the Wild

    The following threats represent the highest risk to organisations and require immediate attention:

    [17] Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs
    Source: TheHackerNews

    [17] Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert
    Source: HelpNetSecurity | CVEs: CVE-2026-35273

    [15] Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild – Patch Now
    Source: TheHackerNews | CVEs: CVE-2026-11645

    [12] Microsoft patches Exchange Server zero-day exploited in attacks
    Source: BleepingComputer

    [11] LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE
    Source: TheHackerNews | CVEs: CVE-2026-42271

    [11] [RANSOMWARE] dragonforce leaked importservices.co.uk
    Source: ransomware.live/dragonforce

    [11] [RANSOMWARE] dragonforce leaked ukimportservices.com
    Source: ransomware.live/dragonforce

    [11] [RANSOMWARE] coinbasecartel leaked NGC Software
    Source: ransomware.live/coinbasecartel

    CISA Known Exploited Vulnerabilities (Last 14 Days)

    The following vulnerabilities are being actively exploited and have been added to CISA’s Known Exploited Vulnerabilities catalogue:

    CVEProductScoreAction Required
    CVE-2026-28318SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerab8Apply mitigations per vendor instructions, follow applicable
    CVE-2026-0257Palo Alto Networks PAN-OS Authentication Bypass Vulnerabilit8Apply mitigations per vendor instructions, follow applicable
    CVE-2026-11645Google Chromium V8 Out-of-Bounds Read and Write Vulnerabilit5Apply mitigations per vendor instructions, follow applicable
    CVE-2026-7473Arista Extensible Operating System Incomplete Comparison wit5Apply mitigations per vendor instructions, follow applicable
    CVE-2026-20245Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping 5Apply mitigations per vendor instructions, follow applicable
    CVE-2026-42271BerriAI LiteLLM Command Injection Vulnerability – BerriAI Li5Apply mitigations per vendor instructions, follow applicable
    CVE-2026-50751Check Point Security Gateway Improper Authentication Vulnera5Apply mitigations per vendor instructions, follow applicable
    CVE-2026-45247Mirasvit Full Page Cache Warmer Deserialization of Untrusted5Apply mitigations per vendor instructions, follow applicable
    CVE-2022-0492Linux Kernel Improper Authentication Vulnerability – Linux K5Apply mitigations per vendor instructions, follow applicable
    CVE-2025-48595Android Framework Integer Overflow Vulnerability – Android F5Apply mitigations per vendor instructions, follow applicable
    CVE-2024-21182Oracle WebLogic Server Unspecified Vulnerability – Oracle We5Apply mitigations per vendor instructions, follow applicable

    Ransomware Victims (DLS Monitoring)

    Active ransomware groups with recent victims posted on data leak sites:

    • lockbit3 (2016): texline-global.com, fairfieldmemorial.org, inphenix.com, craigwire.com, tuttoperlufficio.eu (+2011 more)
    • qilin (1921): Erie Management Group, LLC, Town of Chatham, MASSACHUSETTS, ClearCare Periodontal & Implant Centre, Patterson Health Center, Marc Dorcel (+1916 more)
    • akira (1519): TSG Enterprises, Manhattan Broadcasting, Pipestone, ATF Aerospace, French Engineering (+1514 more)
    • play (1265): One Source Associates, Cortez Resources, Accounting Resource Group, The Rubber Resources, Lambda Energy Resources (+1260 more)
    • clop (1254): JAGGEDPEAK.COM, APTEAN.COM, OUTSOURCELOGISTICS.COM, JPWEST.COM, WORKFORCESOFTWARE.COM (+1249 more)
    • lockbit2 (1002): arcelormittal.h…, liceu.barcelon, liceu.barcelona, meritresources, meritresources…. (+997 more)
    • ransomhub (842): www.hexosys.com, www.townofbourne.com, www.obrienavocats.qc.ca, www.confabca.com, headcount.com (+837 more)
    • incransom (824): bayviewci.org, WellLife Network Inc., Pennsylvania Office of Attorney General, Darlington EMS, Mecanizados y Montajes Aeronáuticos (mymgroup.es) (+819 more)
    • alphv (731): James Group, ResultsCX | The result of many unknown breaches?, Petrus Resources Ltd, ANDFLA SRL, The Source (+726 more)
    • dragonforce (571): importservices.co.uk, ukimportservices.com, Gruenberg Kelly Della, sphvalue.com, Advanced Rehabilitation Technology (+566 more)
    • bianlian (552): Encompass Technologies, Northern Minerals Limited, Aspire Rural Health System, Saunders and Saunders, Legal Aid Society of Salt Lake (+547 more)
    • blackbasta (523): snatt.it, celo.com, memc.com, atlasoil.com, theshootingwarehouse.com (+518 more)
    • medusa (517): Macildowie Associates, Expert E-commerce GmbH, Philip Laney & Jolly, Prosolit, Resource Corporation of America (+512 more)
    • safepay (490): bootstransport.ca, briwaycarriers.com, gsglobalresources.com, 47club.jp, wachtmann.eu (+485 more)
    • thegentlemen (478): Paltrack, KlearNow.AI, Empty, FESCO Adecco, Internal Medicine (+473 more)

    Additional Security News

    [9] Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues — TheHackerNews

    [9] Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer — TheHackerNews

    [8] Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities — TheHackerNews

    [8] Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code — TheHackerNews

    [8] ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More — TheHackerNews

    [7] CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog — TheHackerNews

    [7] Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available — TheHackerNews

    [7] Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks — SecurityWeek

    Priority CVEs to Patch

    CVEMentionsPriority
    CVE-2026-202453CRITICAL
    CVE-2026-352732HIGH
    CVE-2026-116452HIGH
    CVE-2026-422712HIGH
    CVE-2026-283182HIGH

    Full HTML Report (CSSLTD Dashboard)

    Summary

    • New unique items: 28931
    • Critical alerts (score >= 10): 49
    • CISA KEV additions in last 14 days: 11
    • Active ransomware groups: 327
    • Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live

    Report generated automatically by Hermes AI. Data collected daily at 04:00 UTC.