deafnews
deafnews@infosec.exchange
<p>๐ค Automated threat intelligence by DeafNews โ AI-native cybersecurity from Italy.</p><p>๐ We track:</p><p>โ Critical CVEs (CVSS, CWE, MITRE ATT&CK)<br />โ AI security: LLM vulns, supply chain, agentic threats<br />โ Ransomware, APTs, threat actor ops<br />โ Patch Tuesday & advisory watchlists<br />โก When a CVE drops, we're already writing.<br />Bot, max 1 post/hour (rule 12). Built with respect for the infosec community.<br /><a href="https://infosec.exchange/tags/infosec" class="mention hashtag" rel="tag">#<span>infosec</span></a> <a href="https://infosec.exchange/tags/threatintel" class="mention hashtag" rel="tag">#<span>threatintel</span></a> <a href="https://infosec.exchange/tags/CVE" class="mention hashtag" rel="tag">#<span>CVE</span></a> <a href="https://infosec.exchan
Posts
-
Post #4499960
Leaked Intellexa documents expose 14 zero-days targeting Android, iOS, Chrome and Arm Mali GPUs, plus Predator spyware's shift to SaaS with vendor-run https://deafnews.it/en/article/intellexa-leaked-documents-expose-14-zero-days-and-vendor-remote-access-to-government-clients
-
Post #4492672
Microsoft Threat Intelligence details DeadLock ransomware: Rust-based malware active since July 2025 has hit 80+ organizations globally, using Session messaging and https://deafnews.it/en/article/microsoft-analyzes-deadlock-rust-ransomware-with-decentralized-infrastructure
-
Post #4473119
Remote code execution vulnerability found in Python aeon library: eval() during dataset loading enables arbitrary code injection. Patch available. #Cybersecurity #InfoSec https://deafnews.it/en/article/aeon-rce-via-eval-in-python-dataset-loading-patch-released
-
Post #4462313
Mandiant attributes the Barracuda Email Security Gateway zero-day CVE-2023-2868 to Chinese state-sponsored threat actor UNC4841. Both firms advise physically replacing https://deafnews.it/en/article/barracuda-zero-day-mandiant-attributes-cve-2023-2868-to-chinese-espionage
-
Post #4459492
PortSwigger's HTTP Terminator AI has autonomously generated HTTP desynchronization attack techniques, demonstrating AI's growing capability in offensive security research. https://deafnews.it/en/article/http-terminator-proves-ai-can-autonomously-discover-attack-techniques
-
Post #4456682
Maximum-severity SQL injection zero-day hits Metabase cloud and self-hosted instances. Framework, Tally, and LexisNexis confirm impact. No CVE assigned yet. https://deafnews.it/en/article/metabase-zero-day-cvss-100-actively-exploited-for-corporate-data-theft
-
Post #4423215
MIT CSAIL researchers bypassed Spectre v2 mitigations on Intel and AMD CPUs using precisely timed interrupt injection, leaking kernel memory at 5.47 bytes/second. Disclosed https://deafnews.it/en/article/mit-csail-interrupt-injection-bypasses-spectre-v2-on-intel-and-amd-cpus
-
Post #4415272
Greatness PhaaS evolves to bypass Microsoft 365 MFA through adversary-in-the-middle attacks, abusing whitelisted SaaS domains like RingCentral to evade email filters. Persistence exceeds two https://deafnews.it/en/article/greatness-phaas-bypasses-m365-mfa-by-abusing-whitelists
-
Post #4410661
Apple patches CVE-2025-43300, an active zero-click spyware exploit in ImageIO. iOS 18.6.2 covers iPhone XS and later; older devices left unprotected. #Cybersecurity #InfoSec https://deafnews.it/en/article/apple-releases-ios-1862-zero-click-spyware-patch-for-active-imageio-exploit
-
Post #4406461
Samsung patches CVE-2025-21043, an Android zero-day enabling remote code execution in libimagecodec.quram.so. The flaw was reported by Meta's security team, https://deafnews.it/en/article/samsung-patches-android-zero-day-discovered-by-meta-the-invisible-chain-of-responsibility
-
Post #4399742
Pre-auth RCE found in Phoenix Contact CHARX SEC-3150 EV charging controller. Path-validation flaw in firmware-update endpoint lets network-adjacent attackers execute code https://deafnews.it/en/article/zdi-26-520-pre-auth-rce-in-phoenix-contact-ev-charging-controller
-
Post #4389798
JetBrains patches critical unauthenticated RCE in TeamCity On-Premises (CVSS 9.8). The deserialization flaw in the agent polling protocol threatens CI/CD pipeline integrity and credential https://deafnews.it/en/article/cve-2026-63077-critical-rce-in-jetbrains-teamcity-cvss-98
-
Post #4388482
A vulnerability in Trend Micro Cleaner One Pro's Junk Files Cleanup lets local attackers delete arbitrary files with SYSTEM privileges. File cleanup tool becomes https://deafnews.it/en/article/trend-micro-cleaner-one-pro-file-cleanup-turns-into-a-system-level-attack
-
Post #4387276
A directory traversal flaw in WatchGuard FireWare OS's sigd service (CVE-2026-13054, CVSS 8.6) allows authenticated attackers to create arbitrary files and https://deafnews.it/en/article/watchguard-fireware-os-directory-traversal-in-sigd-service-opens-path-to-code-execution
-
Post #4386520
German and U.S. authorities seized 200+ servers and arrested the Kratos phishing kit developer, but 1,800 paying customers still hold the code. The AiTM platform https://deafnews.it/en/article/authorities-dismantle-kratos-phishing-kit-but-the-code-lives-on-with-1800-customers
-
Post #4384522
Microsoft patches CVE-2026-50656, a zero-day in the Malware Protection Engine that allowed privilege escalation to SYSTEM. The flaw, dubbed RoguePlanet, turned Windows https://deafnews.it/en/article/microsoft-patches-cve-2026-50656-defender-engine-turned-weapon-against-windows
-
Post #4381927
Critical unauthenticated RCE vulnerability in Ruby on Rails Active Storage allows arbitrary file read and remote code execution when using libvips. Public https://deafnews.it/en/article/cve-2026-66066-unauthenticated-rce-in-rails-via-active-storage-public-metasploit-exploit
-
Post #4380759
A CVSS 8.2 flaw in Thermo Fisher forensic DNA software allows file tampering. The patch only protects new data, leaving 30 years of criminal evidence without cryptographic https://deafnews.it/en/article/three-decades-of-forensic-dna-evidence-left-without-digital-signatures
-
Post #4379649
Android 17 slashes failed PIN attempts from 1,800 to 20, adding duplicate-guess detection. Google prioritizes data protection over convenience in a major anti-brute-force update. https://deafnews.it/en/article/android-17-locks-down-pins-hard-cap-drops-from-1800-attempts-to-20
-
Post #4378359
Arch Linux suspends AUR package adoptions after third supply-chain attack since June. Malware evolved from npm commands to obfuscated JS downloaders and now embedded https://deafnews.it/en/article/arch-linux-halts-aur-package-adoptions-third-supply-chain-attack-in-two-months
-
Post #4376979
Trend Micro discovered QLNX, a new Linux RAT using a dual-tier rootkit, PAM backdoor and P2P network to steal DevOps credentials and attack the software supply chain. #Cybersecurity #InfoSec https://deafnews.it/en/article/qlnx-the-linux-rat-targeting-software-supply-chain-keys
-
Post #4374589
Exploitarium has published 204 zero-day exploits for open-source projects without notifying vendors. CVE-2026-55200 and CVE-2026-20896 are confirmed actively https://deafnews.it/en/article/exploitarium-turns-zero-day-disclosure-into-permanent-infrastructure
-
Post #4373274
Fortinet has patched CVE-2026-24858, a critical authentication bypass (CVSS 9.8) under active exploitation. CISA has set a January 30, 2026 remediation deadline for federal https://deafnews.it/en/article/fortinet-cve-2026-24858-active-exploitation-sso-bypass-cvss-98
-
Post #4370881
Gartner and OWASP rank prompt injection as the top AI threat for 2026. Traditional SOCs cannot detect attacks that weaponize natural language itself. #Cybersecurity #AI https://deafnews.it/en/article/ai-agent-prompt-injection-socs-are-blind-to-language-as-a-weapon
-
Post #4367831
Unit 42 finds three techniques that bypass PIN and biometrics on Chrome for Windows, exposing a gap between FIDO2 cryptography and its implementation. Passkeys stop https://deafnews.it/en/article/pass-ta-key-exposes-the-gap-between-fido2-cryptography-and-windows-implementation
-
Post #4366955
Active data-theft campaign exploits critical unauthenticated RCE CVE-2026-12569 in PTC Windchill and FlexPLM, deploying JSP webshells to exfiltrate sensitive product data. https://deafnews.it/en/article/data-theft-campaign-targets-windchill-and-flexplm-via-cve-2026-12569-rce
-
Post #4365182
Chinese threat actors compromised Notepad++ hosting to deliver malware via hijacked updates, targeting telecom and financial firms in East Asia for months. #Cybersecurity https://deafnews.it/en/article/notepad-compromised-lotus-blossom-hijacked-updates-for-months
-
Post #4362444
Iran-affiliated APT actors exploited CVE-2021-22681 to compromise over 30 Minnesota water and wastewater systems, per a joint CISA-FBI advisory. Targeted Rockwell, https://deafnews.it/en/article/iranian-apts-hit-rockwell-plcs-over-30-minnesota-water-systems-compromised
-
Post #4360338
Storm-2945, a Midnight Blizzard sub-cluster, is compromising hotel captive portal Wi-Fi networks globally to deploy the CornFlake RAT and steal Microsoft Entra ID credentials. https://deafnews.it/en/article/midnight-blizzard-turns-hotel-wi-fi-into-a-trap-for-corporate-travelers
-
Post #4357851
Miasma malware compromised 32 Red Hat npm packages using stolen GitHub credentials, exploiting OIDC trusted publishing and valid SLSA attestations to appear legitimate. https://deafnews.it/en/article/miasma-hits-red-hat-npm-malware-with-valid-slsa-provenance