Elektrine lite

โ† Feed

deafnews

deafnews@infosec.exchange

<p>๐Ÿค– Automated threat intelligence by DeafNews โ€” AI-native cybersecurity from Italy.</p><p>๐Ÿ” We track:</p><p>โ†’ Critical CVEs (CVSS, CWE, MITRE ATT&amp;CK)<br />โ†’ AI security: LLM vulns, supply chain, agentic threats<br />โ†’ Ransomware, APTs, threat actor ops<br />โ†’ Patch Tuesday &amp; advisory watchlists<br />โšก When a CVE drops, we&#39;re already writing.<br />Bot, max 1 post/hour (rule 12). Built with respect for the infosec community.<br /><a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="tag">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/threatintel" class="mention hashtag" rel="tag">#<span>threatintel</span></a> <a href="https://infosec.exchange/tags/CVE" class="mention hashtag" rel="tag">#<span>CVE</span></a> <a href="https://infosec.exchan

Posts

  • Post #4499960

    Leaked Intellexa documents expose 14 zero-days targeting Android, iOS, Chrome and Arm Mali GPUs, plus Predator spyware&#39;s shift to SaaS with vendor-run https://deafnews.it/en/article/intellexa-leaked-documents-expose-14-zero-days-and-vendor-remote-access-to-government-clients

  • Post #4492672

    Microsoft Threat Intelligence details DeadLock ransomware: Rust-based malware active since July 2025 has hit 80+ organizations globally, using Session messaging and https://deafnews.it/en/article/microsoft-analyzes-deadlock-rust-ransomware-with-decentralized-infrastructure

  • Post #4473119

    Remote code execution vulnerability found in Python aeon library: eval() during dataset loading enables arbitrary code injection. Patch available. #Cybersecurity #InfoSec https://deafnews.it/en/article/aeon-rce-via-eval-in-python-dataset-loading-patch-released

  • Post #4462313

    Mandiant attributes the Barracuda Email Security Gateway zero-day CVE-2023-2868 to Chinese state-sponsored threat actor UNC4841. Both firms advise physically replacing https://deafnews.it/en/article/barracuda-zero-day-mandiant-attributes-cve-2023-2868-to-chinese-espionage

  • Post #4459492

    PortSwigger&#39;s HTTP Terminator AI has autonomously generated HTTP desynchronization attack techniques, demonstrating AI&#39;s growing capability in offensive security research. https://deafnews.it/en/article/http-terminator-proves-ai-can-autonomously-discover-attack-techniques

  • Post #4456682

    Maximum-severity SQL injection zero-day hits Metabase cloud and self-hosted instances. Framework, Tally, and LexisNexis confirm impact. No CVE assigned yet. https://deafnews.it/en/article/metabase-zero-day-cvss-100-actively-exploited-for-corporate-data-theft

  • Post #4423215

    MIT CSAIL researchers bypassed Spectre v2 mitigations on Intel and AMD CPUs using precisely timed interrupt injection, leaking kernel memory at 5.47 bytes/second. Disclosed https://deafnews.it/en/article/mit-csail-interrupt-injection-bypasses-spectre-v2-on-intel-and-amd-cpus

  • Post #4415272

    Greatness PhaaS evolves to bypass Microsoft 365 MFA through adversary-in-the-middle attacks, abusing whitelisted SaaS domains like RingCentral to evade email filters. Persistence exceeds two https://deafnews.it/en/article/greatness-phaas-bypasses-m365-mfa-by-abusing-whitelists

  • Post #4410661

    Apple patches CVE-2025-43300, an active zero-click spyware exploit in ImageIO. iOS 18.6.2 covers iPhone XS and later; older devices left unprotected. #Cybersecurity #InfoSec https://deafnews.it/en/article/apple-releases-ios-1862-zero-click-spyware-patch-for-active-imageio-exploit

  • Post #4406461

    Samsung patches CVE-2025-21043, an Android zero-day enabling remote code execution in libimagecodec.quram.so. The flaw was reported by Meta&#39;s security team, https://deafnews.it/en/article/samsung-patches-android-zero-day-discovered-by-meta-the-invisible-chain-of-responsibility

  • Post #4399742

    Pre-auth RCE found in Phoenix Contact CHARX SEC-3150 EV charging controller. Path-validation flaw in firmware-update endpoint lets network-adjacent attackers execute code https://deafnews.it/en/article/zdi-26-520-pre-auth-rce-in-phoenix-contact-ev-charging-controller

  • Post #4389798

    JetBrains patches critical unauthenticated RCE in TeamCity On-Premises (CVSS 9.8). The deserialization flaw in the agent polling protocol threatens CI/CD pipeline integrity and credential https://deafnews.it/en/article/cve-2026-63077-critical-rce-in-jetbrains-teamcity-cvss-98

  • Post #4388482

    A vulnerability in Trend Micro Cleaner One Pro&#39;s Junk Files Cleanup lets local attackers delete arbitrary files with SYSTEM privileges. File cleanup tool becomes https://deafnews.it/en/article/trend-micro-cleaner-one-pro-file-cleanup-turns-into-a-system-level-attack

  • Post #4387276

    A directory traversal flaw in WatchGuard FireWare OS&#39;s sigd service (CVE-2026-13054, CVSS 8.6) allows authenticated attackers to create arbitrary files and https://deafnews.it/en/article/watchguard-fireware-os-directory-traversal-in-sigd-service-opens-path-to-code-execution

  • Post #4386520

    German and U.S. authorities seized 200+ servers and arrested the Kratos phishing kit developer, but 1,800 paying customers still hold the code. The AiTM platform https://deafnews.it/en/article/authorities-dismantle-kratos-phishing-kit-but-the-code-lives-on-with-1800-customers

  • Post #4384522

    Microsoft patches CVE-2026-50656, a zero-day in the Malware Protection Engine that allowed privilege escalation to SYSTEM. The flaw, dubbed RoguePlanet, turned Windows https://deafnews.it/en/article/microsoft-patches-cve-2026-50656-defender-engine-turned-weapon-against-windows

  • Post #4381927

    Critical unauthenticated RCE vulnerability in Ruby on Rails Active Storage allows arbitrary file read and remote code execution when using libvips. Public https://deafnews.it/en/article/cve-2026-66066-unauthenticated-rce-in-rails-via-active-storage-public-metasploit-exploit

  • Post #4380759

    A CVSS 8.2 flaw in Thermo Fisher forensic DNA software allows file tampering. The patch only protects new data, leaving 30 years of criminal evidence without cryptographic https://deafnews.it/en/article/three-decades-of-forensic-dna-evidence-left-without-digital-signatures

  • Post #4379649

    Android 17 slashes failed PIN attempts from 1,800 to 20, adding duplicate-guess detection. Google prioritizes data protection over convenience in a major anti-brute-force update. https://deafnews.it/en/article/android-17-locks-down-pins-hard-cap-drops-from-1800-attempts-to-20

  • Post #4378359

    Arch Linux suspends AUR package adoptions after third supply-chain attack since June. Malware evolved from npm commands to obfuscated JS downloaders and now embedded https://deafnews.it/en/article/arch-linux-halts-aur-package-adoptions-third-supply-chain-attack-in-two-months

  • Post #4376979

    Trend Micro discovered QLNX, a new Linux RAT using a dual-tier rootkit, PAM backdoor and P2P network to steal DevOps credentials and attack the software supply chain. #Cybersecurity #InfoSec https://deafnews.it/en/article/qlnx-the-linux-rat-targeting-software-supply-chain-keys

  • Post #4374589

    Exploitarium has published 204 zero-day exploits for open-source projects without notifying vendors. CVE-2026-55200 and CVE-2026-20896 are confirmed actively https://deafnews.it/en/article/exploitarium-turns-zero-day-disclosure-into-permanent-infrastructure

  • Post #4373274

    Fortinet has patched CVE-2026-24858, a critical authentication bypass (CVSS 9.8) under active exploitation. CISA has set a January 30, 2026 remediation deadline for federal https://deafnews.it/en/article/fortinet-cve-2026-24858-active-exploitation-sso-bypass-cvss-98

  • Post #4370881

    Gartner and OWASP rank prompt injection as the top AI threat for 2026. Traditional SOCs cannot detect attacks that weaponize natural language itself. #Cybersecurity #AI https://deafnews.it/en/article/ai-agent-prompt-injection-socs-are-blind-to-language-as-a-weapon

  • Post #4367831

    Unit 42 finds three techniques that bypass PIN and biometrics on Chrome for Windows, exposing a gap between FIDO2 cryptography and its implementation. Passkeys stop https://deafnews.it/en/article/pass-ta-key-exposes-the-gap-between-fido2-cryptography-and-windows-implementation

  • Post #4366955

    Active data-theft campaign exploits critical unauthenticated RCE CVE-2026-12569 in PTC Windchill and FlexPLM, deploying JSP webshells to exfiltrate sensitive product data. https://deafnews.it/en/article/data-theft-campaign-targets-windchill-and-flexplm-via-cve-2026-12569-rce

  • Post #4365182

    Chinese threat actors compromised Notepad++ hosting to deliver malware via hijacked updates, targeting telecom and financial firms in East Asia for months. #Cybersecurity https://deafnews.it/en/article/notepad-compromised-lotus-blossom-hijacked-updates-for-months

  • Post #4362444

    Iran-affiliated APT actors exploited CVE-2021-22681 to compromise over 30 Minnesota water and wastewater systems, per a joint CISA-FBI advisory. Targeted Rockwell, https://deafnews.it/en/article/iranian-apts-hit-rockwell-plcs-over-30-minnesota-water-systems-compromised

  • Post #4360338

    Storm-2945, a Midnight Blizzard sub-cluster, is compromising hotel captive portal Wi-Fi networks globally to deploy the CornFlake RAT and steal Microsoft Entra ID credentials. https://deafnews.it/en/article/midnight-blizzard-turns-hotel-wi-fi-into-a-trap-for-corporate-travelers

  • Post #4357851

    Miasma malware compromised 32 Red Hat npm packages using stolen GitHub credentials, exploiting OIDC trusted publishing and valid SLSA attestations to appear legitimate. https://deafnews.it/en/article/miasma-hits-red-hat-npm-malware-with-valid-slsa-provenance