Visualização normal

Ontem — 8 de Setembro de 2026Cybersecurity News
  • ✇Cybersecurity News
  • Outsider Phishing Kit Survives Operation Ghost Hook Takedown Do Son
    The Outsider Phishing Kit persists despite the Operation Ghost Hook takedown. Discover how the ChenLun Outsider PhaaS kit bypasses MFA via AiTM attacks. Related Posts: Phantom Deal Scam Targets Executives With Fake NDAs Microsoft Teams IT Support Impersonation Leads to Domain Takeover Chinese Actor Gambling Goblin Hijacks Brazilian Gov Sites The post Outsider Phishing Kit Survives Operation Ghost Hook Takedown appeared first on Daily CyberSecurity.
     
Antes de ontemCybersecurity News
  • ✇Cybersecurity News
  • The Gentlemen Ransomware Deploys in Under 24 Hours Do Son
    The Gentlemen ransomware, run by GOLD SHERWOOD, encrypts networks in under 24 hours. See the affiliate playbook and how to defend against it. Related Posts: PHP Web Server Rootkit Targets F5 BIG-IP Devices StreamRat Banking Trojan Targets Spanish Android Users Silver Fox Fake Software Installers Disable Windows Defender The post The Gentlemen Ransomware Deploys in Under 24 Hours appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Cisco Secure Email S/MIME Flaws Publicly Disclosed Do Son
    A public announcement exists for the Cisco Secure Email vulnerability pair in S/MIME decryption, plus a Cisco phone SIP denial-of-service flaw. Related Posts: CVE-2026-75754 (CVSS 10): ASUS Control Center Root RCE Apache Allura Security Vulnerabilities Patched in v1.21.0 CVE-2026-52924 PoC Exploit Disclosed: 9.8 CVSS Linux Root Privilege Escalation The post Cisco Secure Email S/MIME Flaws Publicly Disclosed appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • AnonyMousKIT Uses AI Voice Calls to Unlock Stolen iPhones Do Son
    AnonyMousKIT is an AI-powered PhaaS platform that phones iPhone theft victims as fake Apple Support to steal passcodes and beat Activation Lock. Related Posts: Dark Caracal Deploys New GoCaracal Malware Framework Cambodia Malware Campaign Uses PNG Files to Deliver SparkRAT BREEZE COMET Threat Actor Attacks Brazilian Banks The post AnonyMousKIT Uses AI Voice Calls to Unlock Stolen iPhones appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • WeedHack Malware Still Hits Minecraft Gamers via Fake Sites Do Son
    WeedHack malware still targets Minecraft gamers through fake client sites and Minecraft SEO poisoning, McAfee Labs warns. Related Posts: SynkLoader Malware Deploys Multi-Language Attack Tools macOS ClickFix Malware Exploits Polygon C2 Cruciferra Malware Loader Uses ClickFix Lures to Kill EDR The post WeedHack Malware Still Hits Minecraft Gamers via Fake Sites appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Apache Tomcat Patches 11 Vulnerabilities in 11.0.25 Update Do Son
    Apache Tomcat fixed 11 vulnerabilities on August 25, 2026, including auth bypass (CVE-2026-68569) and HTTP/2 DoS flaws. Update to 11.0.25 now. Related Posts: GitLab Updates Fix Arbitrary Command Execution Vulnerability FreeBSD Patches Eight Kernel Vulnerabilities UniFi CVE-2026-77537 (CVSS 10.0): Command Injection Flaws Hit 22 Ubiquiti Products The post Apache Tomcat Patches 11 Vulnerabilities in 11.0.25 Update appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Balonx Sistema: Mexican PhaaS Adds AI Vishing and RAT Do Son
    Group-IB exposed Balonx Sistema, a Mexican PhaaS platform bundling real-time phishing, an Android RAT, and AI-driven vishing against 20+ banks. Related Posts: Core Werewolf Deploys New CoreRAT Malware Against Russian Targets StopAndProtect Malware Turns Hacked WordPress Sites Into a Botnet Cisco Talos Exposes UAT-10147 Agentic AI Attacks The post Balonx Sistema: Mexican PhaaS Adds AI Vishing and RAT appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Spring Data REST and Spring AI Vulnerabilities: Four High-Severity Flaws Patched Do Son
    Four Spring vulnerabilities hit Spring Data REST and Spring AI, including CVE-2026-47849, a privilege escalation flaw. Patch to the fixed versions now. Related Posts: EverShop CVE-2026-72843 Flaw Allows Unauthenticated Account Takeover CVE-2026-77806: SPIP Unauthenticated RCE Exploited in the Wild as Public Exploit Lands CVE-2026-75501: Public PoC for Calix Router Flaw That Bypasses NAT and Firewall Protections The post Spring Data REST and Spring AI Vulnerabilities: Four High-Severity Flaws
     
  • ✇Cybersecurity News
  • CVE-2026-47627: CVSS 9.8 Denial of Service Hits NVIDIA Triton Do Son
    NVIDIA Triton vulnerability CVE-2026-47627 scores CVSS 9.8. Learn how the denial of service flaw works and why you must update to 26.06 now. Related Posts: CVE-2026-47301: PoC Exploit Achieves SYSTEM-Level Code Execution in SCCM CVE-2026-66780 (CVSS 9.9): MITM Flaw Hits Red Hat ACM CVE-2026-76404: Critical Remote Code Execution Hits Splunk MCP Server App (CVSS 9.1) The post CVE-2026-47627: CVSS 9.8 Denial of Service Hits NVIDIA Triton appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic (CVSS 9.1) Do Son
    CVE-2026-71290 (CVSS 9.1) is an Apache HttpClient TLS vulnerability that lets attackers intercept and modify traffic via MITM attacks. Update to 5.6.4. Related Posts: PoC Discloses for CVE-2026-64849: watchTowr Sees Attacks on MLflow SSRF CVE-2026-75045: Unauthenticated Attacker Could Download YouTrack Database Backups GeoServer Unauthenticated SQL Injection (CVSS 9.8) Exploited in the Wild, PoC Public The post CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic
     
  • ✇Cybersecurity News
  • CVE-2026-66804: PoC Exploit Gains SYSTEM via Cross Device Service Do Son
    A public PoC for CVE-2026-66804 escalates a standard Windows user to SYSTEM via the Cross Device Service. Details and exploit code are now disclosed. Related Posts: CVE-2026-71290: Apache HttpClient Flaw Lets Attackers Intercept and Modify Traffic (CVSS 9.1) PoC Discloses for CVE-2026-64849: watchTowr Sees Attacks on MLflow SSRF CVE-2026-75045: Unauthenticated Attacker Could Download YouTrack Database Backups The post CVE-2026-66804: PoC Exploit Gains SYSTEM via Cross Device Service appeared
     
  • ✇Cybersecurity News
  • Apache Struts Patches Five Flaws Including Unauthenticated DoS Bugs Do Son
    Apache Struts DoS flaws span CVE-2026-73633, CVE-2026-73634, and CVE-2026-73635, plus two JSON plugin bugs. Upgrade to 7.3.0. Related Posts: CVE-2026-19188: Haiwell HMI Gateway Flaw Lets Attackers Execute Arbitrary OS Commands With Root Privileges (CVSS 10.0) Linux AF_PACKET Race (03390aa): PoC Exploit Enables Local Privilege Escalation Citrix NetScaler Pre-Auth RCE CVE-2026-8452 Gets Public Exploit Code The post Apache Struts Patches Five Flaws Including Unauthenticated DoS Bugs appeared fir
     
  • ✇Cybersecurity News
  • Cisco ASA and FTD VPN Flaw CVE-2026-20349 Exploited in the Wild Do Son
    Cisco confirms CVE-2026-20349, a Cisco ASA and FTD VPN vulnerability (CVSS 8.6), is exploited in the wild to crash firewalls. Patch now. Related Posts: Zero-Click File Drop Hits Xiaomi ShareMe: PoC Public CVE-2026-65640: WordPress 7.0.4 Fixes Remote Code Execution MariaDB Low-Privilege Remote Code Execution Chain: Full Details and PoC Exploit Code Publicly Disclosed The post Cisco ASA and FTD VPN Flaw CVE-2026-20349 Exploited in the Wild appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • DOUBLECUP: New ClickFix Loader Drops CountLoader and DeviceManager RAT Do Son
    DOUBLECUP is a new Russian ClickFix Loader-as-a-Service that drops CountLoader and the DeviceManager RAT using steganography and EtherHiding. Related Posts: macOS ClickFix Campaign Hides Its Lure Behind a Fingerprinting Gate Fake AI Tools Malware Targets Developers Through GitHub Interlock Ransomware Abuses Volatility3 for Credential Theft The post DOUBLECUP: New ClickFix Loader Drops CountLoader and DeviceManager RAT appeared first on Daily CyberSecurity.
     
  • ✇Cybersecurity News
  • Multiple ClamAV Flaws Let Remote Attackers Cause DoS Do Son
    Cisco disclosed seven ClamAV vulnerabilities that let a remote attacker crash scanning via crafted files. Details are public. Patch now. Related Posts: CVE-2026-27912: PoC Released for SYSTEM Privilege Flaw CVE-2026-58231 (CVSS 10.0) and Code Injection RCE Flaws Top SAP August 2026 Patch Day Windows PnP Attack Chain Turns a USB Plug Into SYSTEM: Details and PoC Now Public The post Multiple ClamAV Flaws Let Remote Attackers Cause DoS appeared first on Daily CyberSecurity.
     
❌
❌