Elektrine
EN
Log in Register
Paige Chat Timeline Gallery Friends Lists Email Drive DNS Resolver Domains VPN Kairo Nerve
Remote

Suriq - Always on Watch

@suriq@infosec.exchange
mastodon 4.8.0-alpha.3+glitch
  • Open on infosec.exchange

Practitioner cybersecurity analysis from the Suriq desk.
What to patch, what to detect, and why it matters, in plain English.

Managed security built on Wazuh. suriq.io

#Cyber #ThreatDetection #CVE #CISA #Cybersecurity

9 Followers
8 Following
50 Posts
Joined June 18, 2026
Suriq - Always on Watch:
https://suriq.io
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2w ago

⚠️ PATCH NOW

Microsoft Exchange has an auth-bypass flaw (CVE-2026-62911) that relays a server's own account into a webshell running as SYSTEM.

A public exploit just dropped, and 21,899 servers are still exposed.

Patch, then turn on Extended Protection.

https://suriq.io/blog/exchange-cve-2026-62911-auth-bypass-webshell-poc

#CVE #Windows #infosec #cybersecurity

Exchange CVE-2026-62911: auth-bypass RCE, PoC is out
Suriq

Exchange CVE-2026-62911: auth-bypass RCE, PoC is out

CVE-2026-62911 lets attackers relay an Exchange server

8
0
9
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1w ago

🔴 EXPLOITED

Chrome's V8 engine has its sixth zero-day of 2026 (CVE-2026-85046), exploited in the wild.

Chrome 152.0.7977.82 is only half the job. Edge, Brave, Opera and Electron apps run the same engine and patch separately.

https://suriq.io/blog/chrome-v8-cve-2026-85046-exploited

#CVE #Detection #CISAKEV #infosec

1
0
1
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2w ago

WP Fastest Cache, a WordPress plugin on 1M+ sites, has a flaw that lets a stranger poison your cached pages and serve malicious code to every visitor.

Fix: update to 1.5.1 and clear your page cache.

A public exploit is due Sept 9. (CVE-2026-74916)

https://suriq.io/blog/wp-fastest-cache-cache-poisoning-cve-2026-74916

#CVE #infosec #cybersecurity

1
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2w ago

The Manchester Airports breach did not need a hacked server. An extortion group says it read a marketing API key straight out of the site's JavaScript and exported customer data. Your EDR would never see it.

https://suriq.io/blog/manchester-airports-client-side-api-key-breach

#DataBreach #infosec #cybersecurity

1
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

🔴 EXPLOITED

North Korea's Lazarus group used fake job offers and a Windows zero-day (CVE-2026-68820) to take over defense and aerospace PCs.

Patched Aug 11, but exploited in the wild first; a kernel rootkit blinded security tools.

Run Windows? Update now and hunt.

https://suriq.io/blog/lazarus-operation-dream-job-windows-zero-day

#CVE #Windows #infosec #cybersecurity

1
0
2
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

Mozilla revoked the GPG key signing Firefox and Thunderbird Linux builds after it leaked to a private repo.

It is marked compromised, so past signatures no longer verify.

Verify by hand or ship Mozilla RPMs? Import the new key.

https://suriq.io/blog/mozilla-firefox-thunderbird-signing-key-revoked

#SupplyChain #DataBreach #Linux #infosec

1
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

🚨 BREAKING

Attackers did not breach Steam, ING or bol. They breached the shipping partner all three share, Ceva Logistics.

Customer names, addresses and order details across Europe are exposed. No passwords taken, but expect phishing that quotes your real orders.

https://suriq.io/blog/ceva-logistics-breach-customer-data-exposed

#SupplyChain #DataBreach #Phishing #infosec

Ceva Logistics breach exposes Steam, ING customer data
Suriq

Ceva Logistics breach exposes Steam, ING customer data

A cyberattack on shipping partner Ceva Logistics exposed customer names, addresses and order details for Steam, ING, bol and more. No passwords taken, but phishing risk is high.

1
0
3
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

GeoServer, the open-source map server, has an unpatched zero-day: unauthenticated SQL injection that can reach remote code execution.

No fix yet; probing began within hours.

Restrict access and cut the database account's privileges now.

https://suriq.io/blog/geoserver-zero-day-sql-injection-rce-no-patch

#CVE #infosec #cybersecurity

GeoServer zero-day: SQL injection to RCE, no patch yet
Suriq

GeoServer zero-day: SQL injection to RCE, no patch yet

A GeoServer zero-day lets unauthenticated attackers run SQL injection that can reach remote code execution. No CVE, no patch, and probing has already started.

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

The Fabrik add-on for Joomla has a max-severity flaw (CVSS 10, CVE-2026-67282): a stranger can run code on the server with no login.

Every site on Fabrik below 4.6.8 is exposed.

Fix: update to 4.6.8 now, then check for stray PHP files.

https://suriq.io/blog/fabrik-joomla-unauth-rce-cve-2026-67282

#CVE #infosec #cybersecurity

0
1
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

The "malicious LiteLLM packages" headlines miss it. The real breach was Trivy, the container scanner, poisoned in CI five days earlier.

CloudSEK maps 2,500+ orgs of potential exposure, not confirmed breaches.

Ran Trivy in March? Rotate your keys.

https://suriq.io/blog/trivy-litellm-supply-chain-2500-orgs

#CVE #SupplyChain #DataBreach #infosec

Trivy breach, not LiteLLM, exposed 2,500 orgs
Suriq

Trivy breach, not LiteLLM, exposed 2,500 orgs

CloudSEK maps 2,500+ organizations exposed by the TeamPCP (UNC6780) supply-chain campaign. The real vector was a poisoned Trivy scanner, not the LiteLLM packages.

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

AmnesiaStealer, a new macOS stealer, doesn't stop at saved passwords. It clones your browser and drives it live, inside your logged-in sessions.

Spread via fake GitHub pages that tell you to paste a Terminal command.

Reset sessions, not just passwords.

https://suriq.io/blog/amnesiastealer-macos-live-browser-hijack

#Detection #infosec #cybersecurity

AmnesiaStealer hijacks live macOS browser sessions
Suriq

AmnesiaStealer hijacks live macOS browser sessions

AmnesiaStealer is a Rust macOS infostealer spread via fake GitHub ClickFix pages. It steals keychain and browser data, then takes live control of your session.

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2w ago

ClickFix trained people to paste into the Run box, and defenders learned to watch it. TerminalFix moved the paste into Windows Terminal, where old rules do not look. The fix did not change: watch the sequence.

https://suriq.io/blog/terminalfix-clickfix-windows-terminal-reverse-tunnel

#Detection #Windows #infosec #cybersecurity

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago
An AI system read through 3,915 open-source projects and flagged 14,090 bugs nobody had reported, says Palo Alto's Unit 42. The count isn't the story. The gap between a bug existing and being attacked is shrinking, and the same scan works for attackers. Inventory what you run. https://suriq.io/blog/ai-scanner-14090-open-source-bugs #CVE #infosec #cybersecurity
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1w ago
🔴 EXPLOITED CVE-2025-25249: A heap-based buffer overflow in Fortinet FortiOS and FortiSwitchManager allows unauthorized code execution via crafted packets. It is listed in CISA KEV. Affected: FortiOS 6.4 through 7.6.3 and FortiSwitchManager 7.0 and 7.2 branches. Fix: upgrade to the patched releases. CISA due date September 12, 2026. https://www.cve.org/CVERecord?id=CVE-2025-25249 #CISAKEV #infosec #cybersecurity
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

Encrypted AI reasoning blocks from OpenAI, Anthropic, and Google can be decoded by a weaker model from the same provider.

Researchers pulled 182 credentials from 315,320 blocks in public repos. Stop sharing raw AI logs.

https://suriq.io/blog/ai-reasoning-traces-leak-api-keys-pii

#DataBreach #infosec #cybersecurity

AI reasoning traces leak API keys and PII from shared logs
Suriq

AI reasoning traces leak API keys and PII from shared logs

Researchers decoded 315,320 public AI reasoning blocks from OpenAI, Anthropic, and Google, recovering 182 credentials and 367 PII artifacts. What to do now.

0
0
1
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2w ago

WHMCS CVE-2026-67399: if you cannot upgrade to 8.13.7 or 9.0.8 yet, we published a stopgap hook that blocks the payload types this bug most likely needs.

Not a fix. Copy it, test it, delete it after you patch.

https://suriq.io/blog/whmcs-cve-2026-67399-stopgap-hook

#CVE #infosec #cybersecurity

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago
Thermo Fisher patched a flaw that let forensic DNA files be altered before analysis software loaded them (CVE-2026-17583). The fix signs new files only; older archives stay unverifiable. Watch the files your software trusts but never checks. https://suriq.io/blog/thermo-fisher-dna-file-tampering-cve-2026-17583 #CVE #infosec #cybersecurity
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

Undertow, the web server inside Red Hat JBoss, has a pre-login flaw (CVE-2026-15565) that lets anyone crash the server by flooding a WebSocket until it runs out of memory.

Affects JBoss EAP 7/8 and Data Grid 8. No patch yet.

Fix: disable WebSockets where you can.

https://suriq.io/blog/undertow-jboss-websocket-preauth-dos

#CVE #Detection #infosec #cybersecurity

Undertow WebSocket flaw crashes Red Hat JBoss, no login
Suriq

Undertow WebSocket flaw crashes Red Hat JBoss, no login

A pre-auth flaw in Undertow (CVE-2026-15565), the web server in Red Hat JBoss EAP and Data Grid, lets an attacker exhaust memory and crash the server.

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2w ago

AJCloud camera firmware (CVE-2026-56718) lets anyone on the network read the files as root, no login.

The dump leaks your Wi-Fi password and video-stream logins in the clear.

Fix: firmware 01.10715.11.37, then isolate the camera.

https://suriq.io/blog/ajcloud-ipc-camera-path-traversal-cve-2026-56718

#CVE #CloudSecurity #Phishing #infosec

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 3w ago

Two of this week's five critical WordPress flaws (GiveWP, CVSS 10.0, and Avada) don't just take over the site, they run code on the hosting server. All five are unauthenticated. Patch now.

https://suriq.io/blog/wordpress-five-critical-plugin-theme-flaws-server-rce

#CVE #CloudSecurity #infosec #cybersecurity

0
0
1
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2w ago

VulnCheck found two more factory backdoors in ZBT router firmware: SPEAKINGSTONE and DARKLANTERN (CVE-2026-74232/74233).

One calls out, one listens on an open port for anyone to reach as root.

No fix. Replace the hardware.

https://suriq.io/blog/zbt-speakingstone-darklantern-router-backdoors

#CVE #SupplyChain #infosec #cybersecurity

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago
Device-code phishing rose ~1,500% in 2026. It steals Microsoft 365 tokens after you sign in, so MFA and passkeys do not stop it. Hits Entra ID tenants. Fix: block the device-code flow in Conditional Access, alert on every use. https://suriq.io/blog/device-code-phishing-microsoft-365-token-theft #Detection #Phishing #infosec #cybersecurity
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2w ago

🔴 EXPLOITED

Sangoma Switchvox has a critical unauthenticated flaw (CVE-2026-9586, CVSS 9.3) that lets a stranger run code on the phone system.

Patched in July, mass-exploited since Aug 30. Around 4,000 consoles are exposed.

Fix: update to 8.4.0.2 and hunt the logs.

https://suriq.io/blog/switchvox-cve-2026-9586-unauth-rce-exploited

#CVE #infosec #cybersecurity

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago
NatJack lets someone who controls one host behind a shared NAT hijack a neighbor's live TCP session and spoof its DNS. Two CVEs, in Windows NAT and the Linux kernel. Patch both, then stop trusting east-west traffic. https://suriq.io/blog/natjack-shared-nat-session-hijack #CVE #Linux #infosec #cybersecurity
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago
Malware can copy the device key behind Google Chrome passkeys and sign in as you, even with two-factor required, Unit 42 showed. The hole: sites that never check the "user verified" bit. Fix: validate that flag server-side. https://suriq.io/blog/chrome-passkey-malware-account-takeover #ThreatIntel #Detection #infosec #cybersecurity
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

Ivanti's Endpoint Manager has three new high-severity flaws, all fixed in the 2024 SU7 update.

One leaks stored database passwords, one lets a user rewrite session recordings, one crashes the agents.

Not exploited yet. Patch now. (CVE-2026-18129)

https://suriq.io/blog/ivanti-epm-august-2026-su7-management-plane-flaws

#CVE #DataBreach #infosec #cybersecurity

Ivanti Endpoint Manager August 2026 patch: 3 high-severity flaws
Suriq

Ivanti Endpoint Manager August 2026 patch: 3 high-severity flaws

Ivanti

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2w ago

JFrog Artifactory has an unauthenticated bypass (CVE-2026-82329, CVSS 9.8) that lets a stranger forge admin tokens, exploited now.

Self-managed instances in default config are in scope.

Patch, then rotate tokens: the upgrade won't revoke a forged one.

https://suriq.io/blog/jfrog-artifactory-cve-2026-82329-admin-token-forge

#CVE #SupplyChain #Detection #CISAKEV

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

Close to 800 malicious npm packages ship a cross-platform stealer that runs on import, not at install.

Blocked web C2 falls back to DNS.

Pulled a new npm dependency this week? Hunt host and DNS logs.

https://suriq.io/blog/malicious-npm-packages-dns-c2-stealer

#SupplyChain #infosec #cybersecurity

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2w ago

⚠️ PATCH NOW

Predis, a widely used PHP client for Redis, has a critical flaw (CVSS 9.8, CVE-2026-84372): attacker-controlled cache keys can smuggle extra Redis commands.

Hits versions 3.0 to 3.2 on cluster and replication setups.

Fix: upgrade to Predis 3.3.0.

https://suriq.io/blog/predis-crlf-command-injection-cve-2026-84372

#CVE #SupplyChain #infosec #cybersecurity

Critical Predis flaw injects Redis commands, fix in 3.3.0
Suriq

Critical Predis flaw injects Redis commands, fix in 3.3.0

CVE-2026-84372 is a CVSS 9.8 command-injection flaw in the Predis PHP client. It hits 3.0 to 3.2 on cluster and replication connections. Upgrade to 3.3.0.

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2w ago

A public exploit, HardBreacher, turns Kaspersky's endpoint agent into a local privilege-escalation tool on fully patched Windows 11.

The flaw is in the agent, not Windows, so OS patching misses it.

Kaspersky says it is fixed. Check your agent version.

https://suriq.io/blog/kaspersky-endpoint-security-hardbreacher-privilege-escalation

#CVE #Detection #DataBreach #Windows

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

Adobe patched a critical Magento and Adobe Commerce flaw (CVE-2026-71362, CVSS 9.1): a stranger can switch into any customer's account with no login.

Affects all stores through the July 2026 patch level.

Fix: apply Adobe bulletin APSB26-92 now.

https://suriq.io/blog/magento-adobe-commerce-account-takeover-cve-2026-71362

#CVE #infosec #cybersecurity

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2w ago

⚠️ PATCH NOW

Dell PowerStore storage arrays have a critical flaw (CVSS 9.8): reach the management interface with no login and you can read files that hold admin credentials.

Affects the PowerStore T line (500T to 9200T).

Patch, then rotate the array's credentials.

https://suriq.io/blog/dell-powerstore-unauth-credential-leak-cve-2026-58574

#CVE #Phishing #infosec #cybersecurity

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 3w ago

The Unitree G1 humanoid robot has two flaws that give root with no login (CVE-2026-76639, CVE-2026-76640).

One works over Bluetooth from across a room, and a hacked robot can infect other G1 units nearby.

Unitree fixed the cloud part; isolate the rest.

https://suriq.io/blog/unitree-g1-robot-bluetooth-root-rce

#CVE #CloudSecurity #infosec #cybersecurity

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2w ago

⚠️ PATCH NOW

WHMCS, the billing platform many hosting firms run, has a critical flaw (CVE-2026-67399): a stranger with no login can run code on the server.

Affects 9.x before 9.0.8 and 8.x before 8.13.7. No workaround.

Patch now.

https://suriq.io/blog/whmcs-unauthenticated-rce-cve-2026-67399-patch

#CVE #infosec #cybersecurity

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago
⚠️ PATCH NOW Commvault patched a critical flaw (CVSS 9.2) in CommServe, the brain of its backup platform: an allowlist bypass lets blocked commands run. Affects versions 11.36 to 11.46 on Linux and Windows. Fix: update to the patched release now. (CVE-2026-13737) https://suriq.io/blog/commvault-commserve-command-restriction-bypass #Ransomware #CVE #infosec #cybersecurity
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

🔴 EXPLOITED

macOS Screen Sharing has an auth bypass (CVE-2026-65400) that gives a network attacker root with no password.

Apple patched it Aug 6; exposed Macs are already being hit to mine Monero.

Update now, or turn Screen Sharing off.

https://suriq.io/blog/macos-screen-sharing-cve-2026-65400

#CVE #infosec #cybersecurity

macOS Screen Sharing bug CVE-2026-65400 exploited for root
Suriq

macOS Screen Sharing bug CVE-2026-65400 exploited for root

A macOS Screen Sharing auth bypass (CVE-2026-65400) lets network attackers get root with no password. Patched Aug 6, now exploited to mine Monero. What to do.

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago
SMOKE#SCREEN disables Windows Defender, then installs a validly signed ScreenConnect agent as its backdoor. Your signature allowlist trusts it. The tampering it does first is what gives it away. https://suriq.io/blog/smokescreen-screenconnect-rmm-defender-evasion #ThreatIntel #Detection #Phishing #Windows
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago
Replying to on social.falkensweb.com
@falken@social.falkensweb.com Hi :) "East-west" just means one of your machines talking to another machine right next to it, NatJack lets a bad neighbor abuse that.
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago
Sharp and Toshiba Tec office copiers sold outside Japan shipped with the device login turned OFF by default. Anyone on the network can read saved scans and edit the address book, no password needed. Fix: enable authentication and patch. (CVE-2026-63563) https://suriq.io/blog/sharp-toshiba-mfp-auth-off-default-cve-2026-63563 #infosec #cybersecurity
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago
A second dracut flaw (CVE-2026-15816) lets a rogue DHCP server run code as root when a Linux machine boots over the network. June's fix for the first bug missed it. Only network-booted systems are exposed. Update dracut and rebuild your initramfs. https://suriq.io/blog/dracut-cve-2026-15816-dhcp-root-execution #CVE #Linux #infosec #cybersecurity
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

🔴 EXPLOITED

Gunra ransomware beat multi-factor authentication without phishing anyone. It rewrote a company's login server so one attacker-chosen code always passed.

MFA stayed on; every login looked clean.

It gets in via unpatched Fortinet flaws. Patching won't evict it.

https://suriq.io/blog/gunra-ransomware-mfa-auth-backdoor

#Ransomware #CVE #Detection #infosec

Gunra Ransomware Backdoors the Login Server to Defeat MFA (AA26-222a)
Suriq

Gunra Ransomware Backdoors the Login Server to Defeat MFA (AA26-222a)

Gunra ransomware beats MFA by rewriting the login server so one chosen code always passes, after entering through Fortinet flaws. Why patching won

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

A Cisco firewall flaw (CVE-2026-20349) lets a stranger crash your ASA or FTD with one crafted request. No login, no workaround, already exploited.

When the box reloads, your VPN tunnels drop and its logs go dark.

Patch to the fixed build by August 14.

https://suriq.io/blog/cisco-asa-ftd-cve-2026-20349-dos-exploited

#CVE #CISAKEV #infosec #cybersecurity

Cisco ASA/FTD DoS flaw CVE-2026-20349 exploited
Suriq

Cisco ASA/FTD DoS flaw CVE-2026-20349 exploited

CVE-2026-20349 lets an unauthenticated attacker reload Cisco ASA and FTD firewalls for a denial of service. Exploited now, no workaround. Patch by Aug 14.

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2w ago
China-linked Fire Ant compromised Cisco IOS XR routers and TACACS servers, then rewrote the logs to stay invisible. The routers logged only "Health" heartbeats, so liveness checks passed while everything else vanished. Off-host logging catches it. https://suriq.io/blog/fire-ant-cisco-router-tacacs-credential-theft #Detection #Phishing #infosec #cybersecurity
0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2w ago

🚨 BREAKING

Police, the FBI and CrowdStrike disrupted Sality, a botnet that has infected 15,000+ machines since 2003.

The catch: it breaks the operator's control, not the infections. Every hit machine is still infected.

Run old Windows hosts? Hunt for it now.

https://suriq.io/blog/sality-botnet-takedown-machines-still-infected

#ThreatIntel #Detection #Windows #infosec

Sality botnet disrupted after 23 years, PCs still infected
Suriq

Sality botnet disrupted after 23 years, PCs still infected

Police and CrowdStrike disrupted the 23-year-old Sality botnet across 15,000+ machines. The takedown breaks its control, not the infections. What to do now.

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

⚠️ PATCH NOW

SAP NetWeaver has a critical flaw (CVSS 9.8) that lets a stranger crash the server or leak its memory with no login, through the protocol SAP GUI speaks.

Affects SAP NetWeaver AS ABAP; no public exploit yet.

Fix: apply SAP's August kernel patch. (CVE-2026-34265)

https://suriq.io/blog/sap-netweaver-diag-unauth-memory-corruption

#CVE #DataBreach #infosec #cybersecurity

Critical SAP NetWeaver flaw (CVE-2026-34265): patch now
Suriq

Critical SAP NetWeaver flaw (CVE-2026-34265): patch now

SAP

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

Evooo1Bot is a new Linux botnet that exploits internet-facing devices, then turns them into proxies and credential thieves.

It targets Confluence, WSO2 and ingress-nginx, not just routers.

Watch for rogue services and odd outbound traffic.

https://suriq.io/blog/evooo1bot-linux-botnet-servers-socks-relay

#CVE #ThreatIntel #Detection #DataBreach

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2w ago

A BGP route hijack redirected Softaculous traffic and pushed a malicious Virtualizor update that ran as root.

Encryption checked the connection, not the file. The updates were not signed.

Run Virtualizor? Patch to 3.2.9.9 and hunt for the rogue service.

https://suriq.io/blog/virtualizor-bgp-hijack-malicious-update

#SupplyChain #infosec #cybersecurity

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 2w ago

🔴 EXPLOITED

LiteLLM, the open-source gateway fronting your LLM providers, has an auth bypass (CVE-2026-59822) CISA confirms is exploited.

Attackers reach its MCP tools and steal the provider keys it stores.

Fix: update to 1.84.0 and rotate keys.

https://suriq.io/blog/litellm-cve-2026-59822-mcp-auth-bypass

#CVE #CISAKEV #infosec #cybersecurity

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

Microsoft ties new StormEncryptor ransomware to China-linked Storm-1175, which breaks in via an N-able N-central auth bypass (CVE-2026-18577).

One management console breach reaches every downstream client.

Patch to 2026.3.1.7, then hunt.

https://suriq.io/blog/storm-1175-stormencryptor-rmm-ransomware

#Ransomware #CVE #SupplyChain #Detection

0
0
0
0
Open post
Suriq - Always on Watch @suriq@infosec.exchange
· 1mo ago

Opening a booby-trapped code repository can run an attacker's commands in editors built on Eclipse Theia (the framework under Arduino IDE 2.x and other tools).

A crafted git config runs on folder open, no trust prompt. CVE-2026-19884, CVSS 8.4.

Fix: update to Theia 1.70.0.

https://suriq.io/blog/eclipse-theia-repo-open-command-execution-cve-2026-19884

#infosec #cybersecurity

Eclipse Theia repo-open command execution (CVE-2026-19884)
Suriq

Eclipse Theia repo-open command execution (CVE-2026-19884)

Opening a malicious repository in an editor built on Eclipse Theia could run attacker commands via a crafted git config. CVE-2026-19884, CVSS 8.4, fixed in Theia 1.70.0. Detection and mitigation.

0
0
0
0
Back
313k7r1n3
Elektrine

Tor hidden service

elekhj7afj4qnrr4yd3bkzslsyo5jgfxw3orgjkhlcxifueodybyiiad.onion

Platform

  • Email
  • Chat
  • Timeline
  • VPN
  • DNS

Company

  • About
  • Contact
  • FAQ
  • Lite (no JS)
  • Source code

Legal

  • Terms of Service
  • Privacy Policy
  • Warrant Canary
  • VPN Policy

Support

  • support@elektrine.com
  • Report Security Issue
Mail client setup IMAP mail.elektrine.com:993 POP3 mail.elektrine.com:995 SMTP mail.elektrine.com:465
© 2026 Elektrine. All rights reserved. Server: 13:52:34 UTC