Critical Section — Zero-Day / RCE / Exploited in the Wild
The following threats represent the highest risk to organisations and require immediate attention:
[17] Microsoft Patches Record 206 Flaws, Including Three Zero-Days and Critical RCE Bugs
Source: TheHackerNews
[17] Oracle PeopleSoft servers under attack, Oracle pushes out-of-band security alert
Source: HelpNetSecurity | CVEs: CVE-2026-35273
[15] Chrome V8 Zero-Day CVE-2026-11645 Exploited in the Wild – Patch Now
Source: TheHackerNews | CVEs: CVE-2026-11645
[12] Microsoft patches Exchange Server zero-day exploited in attacks
Source: BleepingComputer
[11] LiteLLM Flaw CVE-2026-42271 Exploited in the Wild, Chains to Unauthenticated RCE
Source: TheHackerNews | CVEs: CVE-2026-42271
[11] [RANSOMWARE] dragonforce leaked importservices.co.uk
Source: ransomware.live/dragonforce
[11] [RANSOMWARE] dragonforce leaked ukimportservices.com
Source: ransomware.live/dragonforce
[11] [RANSOMWARE] coinbasecartel leaked NGC Software
Source: ransomware.live/coinbasecartel
CISA Known Exploited Vulnerabilities (Last 14 Days)
The following vulnerabilities are being actively exploited and have been added to CISA’s Known Exploited Vulnerabilities catalogue:
| CVE | Product | Score | Action Required |
|---|---|---|---|
| CVE-2026-28318 | SolarWinds Serv-U Uncontrolled Resource Consumption Vulnerab | 8 | Apply mitigations per vendor instructions, follow applicable |
| CVE-2026-0257 | Palo Alto Networks PAN-OS Authentication Bypass Vulnerabilit | 8 | Apply mitigations per vendor instructions, follow applicable |
| CVE-2026-11645 | Google Chromium V8 Out-of-Bounds Read and Write Vulnerabilit | 5 | Apply mitigations per vendor instructions, follow applicable |
| CVE-2026-7473 | Arista Extensible Operating System Incomplete Comparison wit | 5 | Apply mitigations per vendor instructions, follow applicable |
| CVE-2026-20245 | Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping | 5 | Apply mitigations per vendor instructions, follow applicable |
| CVE-2026-42271 | BerriAI LiteLLM Command Injection Vulnerability – BerriAI Li | 5 | Apply mitigations per vendor instructions, follow applicable |
| CVE-2026-50751 | Check Point Security Gateway Improper Authentication Vulnera | 5 | Apply mitigations per vendor instructions, follow applicable |
| CVE-2026-45247 | Mirasvit Full Page Cache Warmer Deserialization of Untrusted | 5 | Apply mitigations per vendor instructions, follow applicable |
| CVE-2022-0492 | Linux Kernel Improper Authentication Vulnerability – Linux K | 5 | Apply mitigations per vendor instructions, follow applicable |
| CVE-2025-48595 | Android Framework Integer Overflow Vulnerability – Android F | 5 | Apply mitigations per vendor instructions, follow applicable |
| CVE-2024-21182 | Oracle WebLogic Server Unspecified Vulnerability – Oracle We | 5 | Apply mitigations per vendor instructions, follow applicable |
Ransomware Victims (DLS Monitoring)
Active ransomware groups with recent victims posted on data leak sites:
- lockbit3 (2016): texline-global.com, fairfieldmemorial.org, inphenix.com, craigwire.com, tuttoperlufficio.eu (+2011 more)
- qilin (1921): Erie Management Group, LLC, Town of Chatham, MASSACHUSETTS, ClearCare Periodontal & Implant Centre, Patterson Health Center, Marc Dorcel (+1916 more)
- akira (1519): TSG Enterprises, Manhattan Broadcasting, Pipestone, ATF Aerospace, French Engineering (+1514 more)
- play (1265): One Source Associates, Cortez Resources, Accounting Resource Group, The Rubber Resources, Lambda Energy Resources (+1260 more)
- clop (1254): JAGGEDPEAK.COM, APTEAN.COM, OUTSOURCELOGISTICS.COM, JPWEST.COM, WORKFORCESOFTWARE.COM (+1249 more)
- lockbit2 (1002): arcelormittal.h…, liceu.barcelon, liceu.barcelona, meritresources, meritresources…. (+997 more)
- ransomhub (842): www.hexosys.com, www.townofbourne.com, www.obrienavocats.qc.ca, www.confabca.com, headcount.com (+837 more)
- incransom (824): bayviewci.org, WellLife Network Inc., Pennsylvania Office of Attorney General, Darlington EMS, Mecanizados y Montajes Aeronáuticos (mymgroup.es) (+819 more)
- alphv (731): James Group, ResultsCX | The result of many unknown breaches?, Petrus Resources Ltd, ANDFLA SRL, The Source (+726 more)
- dragonforce (571): importservices.co.uk, ukimportservices.com, Gruenberg Kelly Della, sphvalue.com, Advanced Rehabilitation Technology (+566 more)
- bianlian (552): Encompass Technologies, Northern Minerals Limited, Aspire Rural Health System, Saunders and Saunders, Legal Aid Society of Salt Lake (+547 more)
- blackbasta (523): snatt.it, celo.com, memc.com, atlasoil.com, theshootingwarehouse.com (+518 more)
- medusa (517): Macildowie Associates, Expert E-commerce GmbH, Philip Laney & Jolly, Prosolit, Resource Corporation of America (+512 more)
- safepay (490): bootstransport.ca, briwaycarriers.com, gsglobalresources.com, 47club.jp, wachtmann.eu (+485 more)
- thegentlemen (478): Paltrack, KlearNow.AI, Empty, FESCO Adecco, Internal Medicine (+473 more)
Additional Security News
[9] Microsoft Restores Some GitHub Repos, Keeps Others Offline as Miasma Probe Continues — TheHackerNews
[9] Hades PyPI Attack: 19 Packages Poisoned to Auto-Run Bun Credential Stealer — TheHackerNews
[8] Ivanti, Fortinet, and SAP Release Patches for Multiple Critical Vulnerabilities — TheHackerNews
[8] Veeam Backup & Replication RCE Flaw Lets Domain Users Run Remote Code — TheHackerNews
[8] ⚡ Weekly Recap: Instagram Account Hacks, Android Zero-Day, GitHub Worm and More — TheHackerNews
[7] CISA Adds Actively Exploited SolarWinds Serv-U DoS Flaw to KEV Catalog — TheHackerNews
[7] Cisco Catalyst SD-WAN Manager CVE-2026-20245 Flaw Actively Exploited – No Patch Available — TheHackerNews
[7] Oracle Addresses PeopleSoft Vulnerability Amid Reports of Zero-Day Attacks — SecurityWeek
Priority CVEs to Patch
| CVE | Mentions | Priority |
|---|---|---|
| CVE-2026-20245 | 3 | CRITICAL |
| CVE-2026-35273 | 2 | HIGH |
| CVE-2026-11645 | 2 | HIGH |
| CVE-2026-42271 | 2 | HIGH |
| CVE-2026-28318 | 2 | HIGH |
Full HTML Report (CSSLTD Dashboard)
Summary
- New unique items: 28931
- Critical alerts (score >= 10): 49
- CISA KEV additions in last 14 days: 11
- Active ransomware groups: 327
- Sources: BleepingComputer, TheHackerNews, SecurityWeek, HelpNetSecurity, KrebsOnSecurity, CISA KEV, ransomware.live
Report generated automatically by Hermes AI. Data collected daily at 04:00 UTC.
Leave a Reply