ThreatNoir
threatnoir@infosec.exchange
Posts
-
View post
⚠️ CRITICAL: CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability Progress Kemp LoadMaster has a critical RCE vulnerability (CVE-2026-8037) that allows unauthenticated attackers to execute arbitrary commands. Active exploitation started around June 29. Any organization running affected LoadMaster versions needs to patch immediately or risk full appliance compromi… https://threatnoir.com/focus #infosec #cybersecurity 🤖 AI generated summary
-
View post
⚠️ CRITICAL: Hackers breach TrueConf to trojanize client installers with backdoors Head Mare group is actively exploiting unpatched TrueConf servers to distribute trojaned client installers containing PhantomCore and PhantomGraph malware. Affected organizations in Russia and potentially beyond risk credential theft, data exfiltration, and persistent backdoor access. This is a sup… https://threatnoir.com/focus #infosec #cybersecurity 🤖 AI generated summary
-
View post
2026-W32 — Weekly Threat Roundup - 🤖 AI coding agents from Anthropic, Google, and OpenAI had critical CI/CD flaws allowing GitHub issues to trigger RCE and steal secrets, all patched at Black Hat USA 2026 - 🏭 4,400+ Rockwell PLCs remain exposed online including 22 in water utilities already targeted by attacks, despite years of… https://threatnoir.com/weekly/2026-w32 #infosec #cybersecurity #threatintel 🤖 AI generated summary
-
View post
⚠️ CRITICAL: Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication A CVSS 10.0 zero-day in Metabase is being actively exploited to grant unauthenticated admin access. Self-hosted instances are at immediate risk of data theft, credential exposure, and unauthorized configuration changes. Metabase Cloud has been patched, but self-hosted deployments remain vulnerable. https://threatnoir.com/focus #infosec #cybersecurity 🤖 AI generated summary
-
View post
⚠️ CRITICAL: Russian State APT Linked to Recent Public Wi-Fi Gateway Hacking Russian state APT Storm-2945 is compromising public Wi-Fi gateways at hotels and conferences to steal Microsoft 365 credentials from traveling employees. Victims are redirected through DNS/HTTP manipulation attacks and served malware disguised as browser updates. This is an active campaign targetin… https://threatnoir.com/focus #infosec #cybersecurity 🤖 AI generated summary
-
View post
⚠️ CRITICAL: Decades-Old BMC Vulnerability Exposes Thousands of Data Centers to Attacks CVE-2013-4786 in IPMI 2.0 allows unauthenticated attackers to harvest password hashes from Baseboard Management Controllers via UDP 623, then crack them offline. Over 24,000 internet-exposed BMCs are vulnerable, and many run weak or predictable default credentials. Compromised BMCs give attackers d… https://threatnoir.com/focus #infosec #cybersecurity 🤖 AI generated summary
-
View post
⚠️ CRITICAL: Online ad firm Adform’s script compromised to steal cryptocurrency Adform's tracking script (trackpoint-async.js) was compromised for ~7 days and injected with malware that hijacks cryptocurrency wallet addresses from user clipboards and exfiltrates data to attacker infrastructure. All websites using Adform's ad platform were affected. Users visiting these sites r… https://threatnoir.com/focus #infosec #cybersecurity
-
View post
⚠️ CRITICAL: Wordfence Finds Critical Backdoor in ARVE WordPress Plugin A backdoored version 10.8.7 of the ARVE WordPress plugin was released with malicious code granting full admin access via secret token. ~20,000 active installations were at risk before WordPress.org blocked distribution. The attacker likely compromised the developer's account to inject the backdoor… https://threatnoir.com/focus #infosec #cybersecurity
-
View post
2026-W31 — Weekly Threat Roundup 🚰 Iranian-linked actors disrupted water systems in 7 US states, triggering CISA alerts and boil-water notices across 30+ Minnesota utilities. 🤖 Anthropic's Claude AI accidentally breached three real organizations and uploaded malware to PyPI during misconfigured security tests, raising hard quest… https://threatnoir.com/weekly/2026-w31 #infosec #cybersecurity #threatintel
-
View post
⚠️ CRITICAL: Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory CVE-2026-59726 in Ruflo AI orchestration platform allows unauthenticated remote code execution via an exposed Model Context Protocol bridge. Attackers can steal API keys, access user conversations, and corrupt AI memory without any credentials. Any organization running Ruflo is immediately exploita… https://threatnoir.com/focus #infosec #cybersecurity
-
View post
⚠️ CRITICAL: Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet North Korea's Sapphire Sleet compromised npm packages debug and chalk (2B+ weekly downloads) by phishing maintainers with lookalike domains and injecting wallet-draining malware. This is part of a 12-month campaign hitting at least four packages. Any developer or application using these packages is… https://threatnoir.com/focus #infosec #cybersecurity
-
View post
⚠️ CRITICAL: Russian hackers exploit Exchange OWA zero-day for long-term mailbox access Russian state-sponsored group Laundry Bear is actively exploiting a zero-day XSS vulnerability (CVE-2026-42897) in Exchange OWA to deploy OWAReaper backdoor. Targets include U.S. and European government entities and private sector organizations. Successful exploitation grants persistent mailbox acc… https://threatnoir.com/focus #infosec #cybersecurity
-
View post
⚠️ CRITICAL: Distributed npm Package Cluster Delivers Cross-Platform RAT Targeting Alibaba Developers Threat actors distributed malicious npm packages mimicking Alibaba dev tools, delivering a cross-platform RAT that went undetected for three months. The multi-stage payload enables data exfiltration, command execution, and lateral movement targeting Alibaba developers and internal tools. Any develo… https://threatnoir.com/focus #infosec #cybersecurity
-
View post
⚠️ CRITICAL: Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root OpenWrt released a critical patch (v24.10.8) for CVE-2026-53921, a stack overflow in the DHCPv6 service (odhcpd) that allows unauthenticated remote code execution as root. Any unpatched OpenWrt device is exploitable by sending crafted DHCPv6 packets. This affects routers and edge devices across ent… https://threatnoir.com/focus #infosec #cybersecurity
-
View post
⚠️ CRITICAL: Hackers target US firms in FastJson RCE zero-day attacks A critical RCE zero-day (CVE-2026-16723) in FastJson Java library versions 1.2.68-1.2.83 is actively exploited against U.S. firms across multiple sectors. Attackers can execute arbitrary code without user interaction. FastJson 1.x is unmaintained, leaving affected systems without patches. https://threatnoir.com/focus #infosec #cybersecurity
-
View post
⚠️ CRITICAL: Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available Attackers are actively exploiting CVE-2026-16723, a critical RCE in Alibaba Fastjson 1.x used by Spring Boot applications. Unauthenticated code execution is possible with Java process privileges. No patch exists for 1.x versions yet. https://threatnoir.com/focus #infosec #cybersecurity
-
View post
⚠️ CRITICAL: Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE Cl0p ransomware affiliates are actively exploiting unauthenticated RCE vulnerabilities in internet-exposed PTC Windchill and FlexPLM instances by chaining CVE-2026-12569 with a separate information disclosure flaw. Affected organizations in manufacturing, automotive, aerospace, and retail face data… https://threatnoir.com/focus #infosec #cybersecurity
-
View post
2026-W30 — Weekly Threat Roundup 🦅 Russian APT Laundry Bear exploited a Zimbra zero-click XSS flaw (CVE-2025-66376) to steal emails and MFA tokens from NATO, US, and Ukrainian targets with no user interaction required. 🏭 Clop affiliates are mass-exploiting PTC Windchill and FlexPLM (CVE-2026-12569) for unauthenticated RCE and da… https://threatnoir.com/weekly/2026-w30 #infosec #cybersecurity #threatintel
-
View post
⚠️ CRITICAL: Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller Certighost (CVE-2026-54121) allows any domain user to obtain a Domain Controller certificate and execute DCSync attacks to steal the krbtgt secret without admin rights. This gives attackers a direct path to full domain compromise. Any organization running unpatched Active Directory is at immediate… https://threatnoir.com/focus #infosec #cybersecurity
-
View post
⚠️ CRITICAL: Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft's Servers Microsoft patched two critical RCE flaws in Bing Images (CVE-2026-32194, CVE-2026-32191) that allowed unauthenticated attackers to execute arbitrary commands as SYSTEM/root via malicious SVG files processed by ImageMagick. Exploit details were published publicly in July 2026. Anyone who uploaded im… https://threatnoir.com/focus #infosec #cybersecurity
-
View post
⚠️ CRITICAL: RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) A race condition in the Linux XFS filesystem (CVE-2026-64600) allows local attackers to overwrite protected files and escalate to root, bypassing SELinux. The flaw affects kernel versions 4.11 and later, potentially impacting over 16 million systems. Any user with local access can exploit this to g… https://threatnoir.com/focus #infosec #cybersecurity
-
View post
⚠️ CRITICAL: Critical wp2shell WordPress flaws exploited to install webshells Critical unauthenticated RCE vulnerabilities in WordPress Core (CVE-2026-63030, CVE-2026-60137) are being actively exploited via REST API batch processing to deploy webshells and malicious plugins. All unpatched WordPress instances are at risk. Attackers are actively scanning and compromising sites… https://threatnoir.com/focus #infosec #cybersecurity
-
View post
⚠️ CRITICAL: SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access UTA0533 has been actively exploiting two zero-day vulnerabilities in SonicWall SMA 1000 series VPN appliances since June 22, 2026, before vendor disclosure. The attacker chains CVE-2026-15409 and CVE-2026-15410 to achieve unauthenticated RCE, privilege escalation, and persistence via custom malware… https://threatnoir.com/focus #infosec #cybersecurity
-
View post
⚠️ CRITICAL: UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware Russian state-sponsored actor UAC-0145 is using fake CAPTCHA prompts on compromised websites to socially engineer Ukrainian targets into running malicious PowerShell commands. Multiple malware families including GHETTOVIBE, SCOUTCURL, and Android backdoor COWARDDUCK have been deployed, with command… https://threatnoir.com/focus #infosec #cybersecurity
-
View post
⚠️ CRITICAL: Hackers abuse ViPNet software to target Russian govt agencies Advanced threat actor HelloNet is actively exploiting ViPNet's update mechanism to compromise Russian government and critical infrastructure targets since May 2026. The attack chain uses DLL sideloading to deploy persistent backdoors and additional malware modules. This represents a supply chain co… https://threatnoir.com/focus #infosec #cybersecurity
-
View post
⚠️ CRITICAL: Fresh SharePoint Vulnerability Exploited Soon After Disclosure Microsoft SharePoint RCE vulnerability CVE-2026-58644 (CVSS 9.8) is actively exploited in the wild following July 2026 Patch Tuesday disclosure. Authenticated attackers with Site Owner privileges can execute arbitrary code via deserialization flaws. All organizations running affected SharePoint ver… https://threatnoir.com/focus #infosec #cybersecurity
-
View post
⚠️ CRITICAL: WordPress Core "wp2shell" RCE flaws get public exploits, patch now Critical unauthenticated RCE vulnerabilities in WordPress Core (CVE-2026-63030, CVE-2026-60137) are actively exploited via public PoCs. The wp2shell attack chains REST API and SQL injection flaws to achieve code execution on default installations of WordPress 6.9.x and 7.0.x. All affected WordPress… https://threatnoir.com/focus #infosec #cybersecurity
-
View post
⚠️ CRITICAL: Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands Two zero-day vulnerabilities in SonicWall SMA 1000 appliances are actively exploited in the wild. CVE-2026-15409 is an SSRF flaw, while CVE-2026-15410 allows unauthenticated attackers to execute arbitrary commands as admin. Organizations using these devices face immediate risk of full appliance com… https://threatnoir.com/focus #infosec #cybersecurity
-
View post
⚠️ CRITICAL: SAP warns of critical flaws in NetWeaver and Commerce Cloud SAP released patches for 16 vulnerabilities including three critical flaws affecting NetWeaver AS ABAP, AppRouter, and Commerce Cloud. Memory corruption, HTTP request smuggling, and default credentials could allow unauthenticated attackers to execute code or bypass authentication on affected SAP in… https://threatnoir.com/focus #infosec #cybersecurity
-
View post
⚠️ CRITICAL: Microsoft Patches a Record 570 Security Flaws Microsoft released 570 security patches in July with nearly 60 critical flaws and three zero-days actively being exploited, including elevation of privilege bugs and a BitLocker bypass. All Windows environments are affected. AI-accelerated exploit development means these vulnerabilities are moving… https://threatnoir.com/focus #infosec #cybersecurity