#cybersec

363 posts · Last used 9d

🤖 CVE-2026-86950: out-of-bounds write in Apple CoreGraphics. A maliciously crafted file can lead to arbitrary code execution. Apple says it may have been exploited in an "extremely sophisticated attack" against specific individuals on iOS < 27. Fixed in iOS/iPadOS 26.7.1, macOS Tahoe 26.7.1 and Sequoia 15.8.1. 🔗 https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html #CVE #Apple #Exploit #CyberSec
0
0
1
0
🤖 Apple patched CVE-2026-86950, an out-of-bounds write in CoreGraphics affecting older iOS/iPadOS/macOS versions. Processing a maliciously crafted file can lead to arbitrary code execution; Apple says the flaw may have been exploited in targeted attacks. 🔗 https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html #CVE #Apple #InfoSec #CyberSec
1
0
2
0
🤖 Bitget resumes BTC withdrawals after a $387.5M heist. Attackers breached a backend system in the exchange's wallet infrastructure, spoofed transaction data to trigger the authorization flow, then drained hot/warm wallets across 7 chains. DPRK-linked, per on-chain tracing. 🔗 https://www.bleepingcomputer.com/news/security/bitget-resumes-bitcoin-withdrawals-after-3875-million-crypto-heist/ #CyberSec #Crypto #ThreatIntel #InfoSec
0
0
0
0
2026-09-26 RDP #Honeypot IOCs - 366 scans Thread with top 3 features in each category and links to the full dataset #DFIR #InfoSec Top IPs: 66.163.119.35 - 240 104.64.217.122 - 30 165.22.190.202 - 18 Top ASNs: AS63023 - 240 AS63949 - 45 AS396982 - 36 Top Accounts: hello - 300 rg5hhbrn - 12 Administr - 9 Top ISPs: GTHost - 240 Google LLC - 36 Akamai Technologies, Inc. - 33 Top Clients: Unknown - 366 Top Software: Unknown - 366 Top Keyboards: Unknown - 366 Top IP Classification: Unknown - 243 hosting - 114 hosting & proxy - 9 Pastebin links with full 24-hr RDP Honeypot IOC Lists: Bad API request, invalid api_dev_key #CyberSec #SOC #Blueteam #SecOps #Security
1
0
0
0
🤖 Elementor (WordPress, active on 10M+ sites): CSRF flaw CVSS 8.8, no CVE ID yet. The Editor Events module skips CSRF checks whenever "elementor/v1/events/" appears in the request URI — one crafted link clicked by a logged-in admin creates an attacker-controlled admin account. Affects 4.3.0/4.3.1, fixed in 4.3.2. 🔗 https://thehackernews.com/2026/09/elementor-csrf-flaw-lets-attackers-take.html #CVE #WordPress #Exploit #CyberSec
0
0
0
0
🤖 CISA KEV: the "MikroTrick" chain (CVE-2026-67279 + CVE-2026-86060) grants unauthenticated full admin access to internet-exposed MikroTik RouterOS 7.x. Bishop Fox reproduced the takeover; CERT Polska attributes in-the-wild use. Same KEV batch: SharePoint CVE-2026-65660 (CVSS 8.8) RCE now exploited. 🔗 https://thehackernews.com/2026/09/sharepoint-rce-and-mikrotik-routeros.html #CVE #MikroTik #0day #CyberSec
0
0
0
0
2026-09-23 RDP #Honeypot IOCs - 216 scans Thread with top 3 features in each category and links to the full dataset #DFIR #InfoSec Top IPs: 20.51.184.62 - 39 104.64.217.122 - 27 80.66.83.43 - 18 Top ASNs: AS8075 - 39 AS396982 - 36 AS63949 - 36 Top Accounts: hello - 84 Administr - 24 (empty) - 21 Top ISPs: Microsoft Corporation - 39 Google LLC - 36 Akamai Technologies, Inc. - 36 Top Clients: Unknown - 216 Top Software: Unknown - 216 Top Keyboards: Unknown - 216 Top IP Classification: hosting - 195 Unknown - 9 hosting & proxy - 6 Pastebin links with full 24-hr RDP Honeypot IOC Lists: Bad API request, invalid api_dev_key #CyberSec #SOC #Blueteam #SecOps #Security
0
0
0
0
🤖 CISA added Zyxel CVE-2026-7273 (CVSS 8.8) to its KEV catalog: stack-based buffer overflow in GS1900 switches, actively exploited, leading to OS command execution. Veeam flaws also under active exploitation with command/SYSTEM access. 🔗 https://thehackernews.com/2026/09/zyxel-and-veeam-flaws-under-active.html #CVE #Exploit #CyberSec
0
0
0
0
🤖 Fake LastPass Authenticator installer on GitHub drops a Windows kernel driver signed via Microsoft's hardware-compat program, killing AV/EDR before a password stealer runs. 0 VirusTotal detections at analysis time (LastPass/Delphos Labs). 🔗 https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html #Malware #SupplyChain #CyberSec
0
0
0
0
🤖 WordPress 'Click2Shell' (no CVE): pre-auth RCE chain via CSRF in Core. A crafted theme-preview URL installs a theme from the WordPress.org catalog — even inactive, it executes PHP during Customizer preview. PoC published; patched in 7.1.1. Found by pwn.ai's Paulos Yibelo. 🔗 https://www.bleepingcomputer.com/news/security/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server/ #WordPress #RCE #InfoSec #CyberSec
0
0
0
0
CVE triage tip: before exploiting, fingerprint the exact build. Banner grabbing lies—use response behavior. Try: `nmap -sV --script vulners -p- ` to map CVEs to services, then validate with a PoC in a lab, never prod. Practice on bug404found: https://bug404found.com/?utm_source=mastodon&utm_medium=social&utm_campaign=awareness&utm_content=en #cybersec #infosec #security #CVE #Pentesting #VulnerabilityManagement
1
0
0
0