Multiple vulnerabilities in HPE Telco Network Function Virtualization Orchestrator could enable service disruption, unauthorized access and other security impacts.
A newly disclosed Falcon Sensor vulnerability may allow locally authenticated attackers to escalate privileges to NT AUTHORITY\SYSTEM on Windows systems.
CVE-2026-59822 is a high-severity authentication bypass vulnerability that could allow unauthenticated attackers to establish authenticated MCP sessions and invoke configured MCP tools.
CVE-2026-66384 is a medium-severity path traversal vulnerability that could allow an authenticated user to write data outside the intended Docker cache directory under specific remote-repository conditions.
Multiple vulnerabilities affecting NVIDIA NemoClaw and OpenShell could enable sandbox escape, arbitrary code execution, command injection, privilege escalation, credential exposure, and unauthorized access.
OpenSSL security updates address multiple vulnerabilities affecting QUIC, CMS, CMP, DTLS, RPK, and cryptographic functionality, with potential impacts including denial of service, memory exhaustion, and forged-message acceptance.
CVE-2026-21962 carries a CVSS score of 10.0 and allows unauthenticated remote exploitation through HTTP. Active exploitation has been reported in the wild.
Multiple critical and high-severity vulnerabilities affecting IBM AIX and PowerVM VIOS could allow remote code execution, command injection, arbitrary file modification, privilege escalation, and denial-of-service attacks.
Atlassian has released August 2026 security updates addressing 10 Critical and 162 High-severity vulnerabilities across Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira, and Jira Service Management.
Multiple vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway could allow authentication bypass or denial-of-service under specific configurations, including SAML authentication and SIP ALG.
Apple has released security updates addressing multiple vulnerabilities across iOS, iPadOS, macOS, and visionOS. The issues could allow arbitrary code execution, memory corruption, information disclosure, denial-of-service, and security bypass.
Multiple vulnerabilities in VMware Avi Load Balancer, including a Critical authentication bypass flaw (CVE-2026-47865), could allow authentication bypass, remote code execution, privilege escalation, and unauthorized access to the Avi Control Plane.
Multiple Critical, High, and Medium-severity vulnerabilities affect SonicWall GMS and Email Security, including unauthenticated command injection and remote code execution.
A high-severity vulnerability in Cisco Secure Firewall ASA and FTD software could allow unauthenticated attackers to remotely trigger device reloads and cause denial-of-service conditions.
SAP has released its August 2026 security updates, addressing vulnerabilities involving improper authorization, code injection, memory corruption, privilege escalation, remote code execution, directory traversal, SQL injection, and OS command injection.
Google has released security updates addressing multiple high-severity use-after-free vulnerabilities affecting V8, TabStrip, Extensions, HTML, and Blink components.
IBM has addressed multiple critical vulnerabilities that could allow unauthenticated attackers to execute arbitrary commands or code and write files to arbitrary locations across affected enterprise systems.
Jenkins has addressed multiple vulnerabilities affecting Jenkins Core and associated plugins, including a critical agent-to-controller deserialization filter bypass that could enable code execution on Jenkins controllers.
JetBrains released emergency security updates for a critical TeamCity vulnerability (CVE-2026-63077) that is actively exploited in the wild. The flaw enables unauthenticated remote code execution through the TeamCity agent polling protocol and could lead to software supply chain compromise.
Cisco released critical security updates addressing authentication bypass, privilege escalation, denial-of-service, information disclosure, argument injection, firewall bypass, and other vulnerabilities affecting SD-WAN, IOS XE, Secure Firewall Management Center, IMC, RoomOS, and related enterprise platforms.
Veeam released critical security updates addressing Remote Code Execution, credential compromise, arbitrary file write, SQL injection, privilege escalation, and denial-of-service vulnerabilities affecting Veeam Service Provider Console and Veeam ONE.
MongoDB fixed multiple Critical and High vulnerabilities affecting MongoDB Server and Compass, including memory corruption, RBAC bypass, arbitrary command execution, and denial-of-service flaws.
Synology fixed a High-severity vulnerability (CVE-2026-4793) in Synology Assistant for Windows that could allow arbitrary file access, file modification, and denial-of-service.
Adobe fixed a Critical unauthenticated Remote Code Execution flaw (CVE-2026-48449) and a High-severity SQL Injection vulnerability affecting Adobe Campaign Classic v7.
Google has released Chrome Stable Channel updates addressing 370 vulnerabilities, including multiple Critical Use-After-Free and memory corruption flaws that could lead to remote code execution.
GitLab has released security updates addressing multiple High, Medium, and Low severity vulnerabilities impacting CI/CD pipelines, APIs, access controls, project imports, and DevSecOps workflows.
Multiple vulnerabilities affecting XenServer 8.4 and XenServer 9 could allow a privileged attacker inside a guest VM to escape the virtual machine, compromise the host, or cause denial of service.
HP disclosed a Critical vulnerability affecting Poly PrivateConnect deployments using Pexip that could allow unauthenticated remote code execution and complete system compromise.
JetBrains fixed multiple Critical and High vulnerabilities affecting IntelliJ IDEA Remote Development, TeamCity, and other IDEs that could lead to code execution, CI/CD compromise, and unauthorized access.
Alibaba Fastjson 1.x contains a critical Remote Code Execution vulnerability that is actively exploited in the wild. Organizations should immediately enable SafeMode and migrate to Fastjson 2.x.
Thunderbird 140.13 addresses over 30 vulnerabilities, including Critical flaws with public exploit code affecting JavaScript, WebAssembly, DOM navigation, and browser components.
A critical vulnerability (CVE-2026-6516) allows attackers to chain authentication bypass and path traversal flaws to achieve unauthenticated remote code execution on vulnerable ADAudit Plus servers.
Google Chrome Stable Channel fixes seven vulnerabilities, including three Critical use-after-free flaws affecting CameraCapture, GPU, and Network components.
Notepad++ Version 8.9.7 fixes multiple High-severity vulnerabilities that could enable code execution, path traversal, malicious macro execution, and PowerShell command injection.
A critical SSRF vulnerability in the Better Auth SSO plugin could expose internal services and enable account takeover in certain OAuth configurations.
AI-assisted reconnaissance targeted approximately 61 UAE government hosts using automated vulnerability discovery and offensive frameworks. No successful compromise has been confirmed.
A critical WordPress Core vulnerability (CVE-2026-63030) allows unauthenticated remote code execution through the REST API Batch Endpoint. Upgrade affected installations immediately.
A High-severity heap-based buffer overflow vulnerability (CVE-2026-14266) affecting XZ archive processing could allow arbitrary code execution. Upgrade to 7-Zip 26.02 immediately.
Fortinet has released security updates addressing multiple vulnerabilities across its enterprise security products, including an unauthenticated FortiSandbox VNC access flaw.
A critical Path Traversal vulnerability in the @xhmikosr/decompress npm package could allow arbitrary file writes, privilege escalation, and potential remote code execution.
Zimbra fixed a critical Stored XSS vulnerability affecting the Classic Web Client that could allow mailbox compromise, session hijacking, and unauthorized account access.
Multiple Critical vulnerabilities in U-Boot Verified Boot could allow pre-authentication code execution, secure boot bypass, memory corruption, and denial of service.
Progress released security updates for MOVEit Transfer addressing Stored XSS, API token exposure, and SFTP denial-of-service vulnerabilities. Organizations should upgrade immediately.
Multiple vulnerabilities in OWASP ModSecurity could allow attackers to bypass WAF inspection, enabling SQL Injection, XSS, and other web attacks against protected applications.
OpenSSH 10.4 fixes multiple vulnerabilities affecting SSH clients and servers, including a high-severity client-side use-after-free flaw and security issues impacting SFTP, SCP, authentication, forwarding, and denial-of-service protections.
Adobe has released a Priority 1 security update addressing CVE-2026-48286, a critical unauthenticated remote code execution vulnerability affecting on-premises Adobe Campaign Classic deployments.
Adobe released Priority 1 security updates fixing multiple Critical vulnerabilities in ColdFusion that could allow unauthenticated remote code execution, privilege escalation, SSRF, arbitrary file reads, and security bypass.
Cisco has patched multiple high-severity ClamAV engine vulnerabilities that could allow specially crafted files to crash antivirus scanning and disrupt endpoint protection services.
Multiple critical vulnerabilities affecting JetBrains Hub, YouTrack Server, GoLand, and Kotlin could allow authentication bypass, privilege escalation, account takeover, and remote code execution.
CVE-2026-10109 is a critical pre-authentication Remote Code Execution vulnerability affecting IBM Db2 for Linux, UNIX, and Windows with a CVSS score of 9.8.
Multiple unauthenticated SQL Injection and Local File Inclusion vulnerabilities affecting Cacti 1.2.30 and earlier may allow attackers to compromise monitoring infrastructure without authentication.
CVE-2026-58050 allows malicious SSH servers to trigger heap corruption through an integer overflow vulnerability affecting libssh2 1.11.1 and earlier.
Multiple vulnerabilities affecting widely deployed Jenkins plugins could allow remote code execution, sandbox bypass, command injection, XXE attacks, CSRF, credential exposure and permission bypass.
CVE-2025-67038 allows unauthenticated attackers to execute arbitrary commands as root on vulnerable Lantronix EDS5000 devices.
Threat actors are actively exploiting weak ArcGIS Enterprise password recovery workflows to gain unauthorized administrative access and bypass MFA protections.
Security updates address 12 vulnerabilities affecting Node.js 22.x, 24.x and 26.x, including high-severity flaws impacting WebCrypto and TLS hostname verification.
Oracle's June 2026 CPU addresses 245 vulnerabilities across WebLogic, Coherence, WebCenter, Enterprise Manager, MySQL, Solaris, JD Edwards, and other enterprise products.
CVE-2026-20266 allows Splunk administrators to execute arbitrary operating system commands through the vulnerable btool configuration helper component.
Google has patched multiple critical and high-severity vulnerabilities that could enable remote code execution, credential compromise, and browser security bypasses.
HP has patched Critical, High, and Medium severity vulnerabilities affecting HP One Agent Software that could enable privilege escalation and denial-of-service attacks.
A critical vulnerability in Wazuh Manager allows rogue agents to inject arbitrary OpenSearch bulk operations, enabling unauthorized modification, deletion, and creation of security records.
Multiple vulnerabilities affecting Apache HTTP Server 2.4.67 and earlier could enable denial-of-service attacks, memory corruption, XSS, privilege abuse, and unauthorized file access.
Chrome 149 patches 28 vulnerabilities including five Critical flaws affecting Core, GPU, Accessibility, DigitalCredentials, and WebMIDI components.
Multiple vulnerabilities including arbitrary file creation, remote code execution, SSRF, and stored XSS could impact Splunk Enterprise and Secure Gateway deployments.
CVE-2026-25089 allows unauthenticated remote attackers to execute arbitrary operating system commands via specially crafted Web UI requests.
CVE-2026-50751 allows attackers to bypass VPN authentication and gain unauthorized remote access. Active exploitation has been confirmed in the wild.
Multiple vulnerabilities affecting MariaDB Community Server, including CVE-2026-49261 with a CVSS score of 10.0, could lead to database compromise, data theft, and server takeover.
Microsoft has patched multiple Edge vulnerabilities including Remote Code Execution, Security Feature Bypass, and Spoofing flaws that could lead to system compromise and phishing attacks.
CVE-2026-20230 is a critical SSRF vulnerability that could allow unauthenticated attackers to write arbitrary files and potentially obtain root-level access.
Multiple vulnerabilities affecting Apache ActiveMQ could allow remote code execution, privilege escalation, security bypass, and unauthorized administrative actions.
CVE-2026-0826 could allow unauthenticated attackers to remotely execute arbitrary code on vulnerable HP Poly Voice devices when ICE is enabled.
CVE-2026-9614 allows authenticated low-privileged users to escalate privileges and obtain administrative access within affected Ivanti Neurons for ITSM deployments.
Palo Alto Networks has confirmed active exploitation of CVE-2026-0257, a high-severity authentication bypass vulnerability affecting PAN-OS GlobalProtect deployments and enabling unauthorized VPN access.
Multiple vulnerabilities affecting Synology Chat Server, including a critical XSS flaw (CVE-2026-40541), could allow authenticated attackers to read or modify files, expose information, and disrupt services.
A critical privilege escalation vulnerability (CVE-2026-48172) affecting the LiteSpeed User-End cPanel Plugin is being actively exploited in the wild, allowing authenticated users to execute arbitrary scripts with root privileges and fully compromise hosting environments.
A high-severity vulnerability (CVE-2026-48095) in 7-Zip's NTFS archive handler could allow attackers to execute arbitrary code through crafted archive files. Public proof-of-concept exploitation code is reportedly available.
Five critical vulnerabilities affecting multiple UniFi OS devices and UniFi OS Server deployments, including command injection, path traversal, and improper access control (CVSS 10.0), allowing full device compromise. Immediate patching required.
Mozilla has released security updates addressing multiple high-severity vulnerabilities across Firefox, Firefox ESR, Firefox for iOS, and Thunderbird, including sandbox escapes and memory safety defects.
Multiple vulnerabilities affecting Trend Micro endpoint security solutions, including an actively exploited relative path traversal flaw (CVE-2026-34926), allow authenticated attackers to tamper with files, escalate privileges to SYSTEM level, and compromise endpoints. Immediate patching is highly recommended.
Multiple vulnerabilities affecting HPLIP, including a critical RCE flaw (CVE-2026-8631) and a high-severity local privilege escalation flaw (CVE-2026-8632), allow attackers to execute arbitrary code or escalate privileges on affected Linux systems. Immediate patching is strongly advised.
NGINX 1.31.0 is affected by a newly disclosed zero-day vulnerability dubbed "nginx-poolslip", enabling unauthenticated remote code execution (RCE) through weaknesses in internal memory pool management.
Google Chrome has released an important security update addressing 16 security vulnerabilities, including critical Use-After-Free and Heap Buffer Overflow flaws (e.g., CVE-2026-9111, CVE-2026-9110), affecting Windows, macOS, and Linux platforms.
A high-severity vulnerability in ExifTool (CVE-2026-3102) allows attackers to execute arbitrary commands on macOS systems through crafted image metadata. Upgrade to ExifTool 13.50+ immediately.
Atlassian Bamboo, Bitbucket, Confluence, Fisheye/Crucible, Jira Software, and Jira Service Management are affected by multiple critical vulnerabilities (e.g., CVE-2026-29145, CVE-2026-22732), allowing RCE, authentication bypass, DoS, and data exposure. Immediate patching is critical.
A critical heap buffer overflow in NGINX's ngx_http_rewrite_module (CVE-2026-42945) is being actively exploited in the wild, allowing unauthenticated RCE or worker crashes. Immediate upgrades are highly recommended.
A critical vulnerability in Apache Flink (CVE-2026-35194) allows authenticated attackers to execute arbitrary code on TaskManagers via crafted SQL queries. Immediate upgrades are highly recommended.
Multiple high-severity flaws in HPE Telco Intelligent Assurance, including CVE-2025-52999, CVE-2026-33870, and CVE-2026-33871, expose platforms to Denial of Service and HTTP Request Smuggling. Immediate upgrade to FAS & PDO 4.2.15 is strongly recommended.
High-severity vulnerabilities in cPanel & WHM and WP Squared could allow attackers to read arbitrary files, inject malicious HTTP headers, and execute SQL injection attacks leading to full system compromise.
Multiple critical and high-severity vulnerabilities have been identified in pgAdmin 4 that could allow attackers to perform authorization bypass, arbitrary SQL execution, and remote command execution.
Cisco has confirmed active exploitation of CVE-2026-20182, a maximum severity (10.0) authentication bypass in Catalyst SD-WAN. Unauthenticated attackers can gain full admin control.
Microsoft has confirmed active exploitation of CVE-2026-42897, a critical XSS-based spoofing vulnerability in Outlook Web Access. Immediate interim mitigation via EEMS is required.
Microsoft has released its May 2026 Patch Tuesday addressing multiple critical vulnerabilities across Azure services, Windows components, SharePoint, and Dynamics 365, potentially enabling full system compromise.
Mozilla has released security updates addressing multiple high-severity vulnerabilities affecting core browser components, potentially leading to memory corruption, sandbox escape, and arbitrary code execution.
Multiple vulnerabilities across Ivanti products, including a critical RCE in Ivanti Xtraction (CVE-2026-8043), allow privilege escalation, remote code execution, and data exposure. Immediate patching is strongly advised.
A critical command injection vulnerability (CVE-2026-25077) and multiple access control flaws in Apache CloudStack enable unauthenticated attackers to execute arbitrary code on KVM hosts and access cross-tenant data.
Tracked as CVE-2026-6722, a critical Use-After-Free (UAF) flaw in the PHP SOAP extension allows unauthenticated attackers to achieve full server compromise via specially crafted requests.
CVE-2026-3828 enables authenticated attackers to execute arbitrary OS commands via insufficient input validation in firmware. Affects multiple smart switch models including DS-3E1310P-SI.
A critical vulnerability (CVE-2025-68670) in xrdp allows unauthenticated remote attackers to execute arbitrary code via specially crafted RDP connection requests.
Ivanti has released emergency patches for Endpoint Manager Mobile (EPMM) addressing five flaws, including an actively exploited RCE (CVE-2026-6973) and privilege escalation risks.
A critical vulnerability (CVE-2026-41050) in Rancher Fleet allows attackers with limited repository access to bypass isolation controls and gain cluster-admin privileges across downstream environments.
Multiple high-severity vulnerabilities in Spring Cloud Config, including a critical directory traversal (CVE-2026-40982), allow arbitrary file disclosure and secret leakage in cloud-native environments.
Local attackers can exploit multiple vulnerabilities in the WatchGuard Agent for Windows to escalate privileges to SYSTEM or disrupt security functionality via buffer overflows.
Samsung's May 2026 Security Maintenance Release patches multiple critical vulnerabilities allowing arbitrary code execution, privilege escalation, and unauthorized activity execution across Galaxy devices.
Meta has addressed two high-severity flaws in WhatsApp that could allow attackers to trigger arbitrary URL execution via Instagram Reels or deliver disguised malicious files on Windows.
A vulnerability (CVE-2025-15557) in TP-Link Tapo H100 and P100 devices allows attackers on the same network to intercept and manipulate encrypted communication due to improper certificate validation.
Google has addressed a critical vulnerability (CVE-2026-0073) in the Android System that allows remote code execution from a nearby network without requiring user interaction or additional privileges.
Multiple vulnerabilities in NVIDIA NemoClaw and HPE Telco Service Orchestrator could allow prompt injection, SSRF, authentication bypass, and full system compromise, impacting AI and telecom infrastructure.
Mozilla has released critical security updates for Thunderbird addressing multiple vulnerabilities, including critical memory safety flaws (CVE-2026-7322), information disclosure, and sandbox escape conditions.
A high-severity vulnerability (CVE-2026-6914) in MongoDB Server could lead to denial-of-service conditions when processing malformed BSON objects, potentially causing server crashes or unresponsiveness.
A critical vulnerability (CVE-2026-3854) in GitHub and GitHub Enterprise Server could allow remote code execution via a single malicious git push operation, impacting both cloud and self-managed environments.
SonicWall has identified multiple vulnerabilities in SonicOS impacting Gen6, Gen7, and Gen8 firewalls. Exploitation could allow unauthorized administrative access and service disruption.
A critical vulnerability in cPanel & WHM impacts core authentication mechanisms, potentially allowing attackers to bypass login controls and gain unauthorized administrative access to servers and hosting accounts.
Mozilla and Google have released critical security updates addressing over 30 vulnerabilities, including RCE, Use-After-Free, and Memory Safety flaws across Firefox and Chrome.
A critical vulnerability in OpenSSH (CVE-2026-35414) allows authentication bypass via improper handling of authorized_keys principals, potentially enabling unauthorized root-level access.
Microsoft has confirmed active exploitation of a vulnerability in Windows Shell (CVE-2026-32202), allowing attackers to bypass protection mechanisms and execute spoofing attacks via crafted malicious files.
Multiple vulnerabilities in Notepad++ and Foxit PDF Reader/Editor, including a critical Format String Injection (CVSS 10) in Notepad++, enable DoS and potential RCE.
A sophisticated supply chain attack involving the compromise of the Bitwarden CLI npm package (@bitwarden/[email protected]) demonstrates a highly advanced, wormable attack model targeting developer ecosystems.
Critical RCE and XSS vulnerabilities in Apache ActiveMQ (CVE-2026-41044, CVE-2026-40466, CVE-2026-41043) enable authenticated attackers to execute arbitrary code on the broker JVM and hijack administrative sessions.
CVE-2025-29635 enables unauthenticated remote command injection, currently being exploited to deploy Mirai botnet variants for large-scale DDoS attacks. No patches available for EOL devices.
Multiple vulnerabilities (Max CVSS 7.8) in CUDA-Q and KAI Scheduler enable unauthenticated DoS, information disclosure, and unauthorized API access in AI and HPC environments.
CVE-2026-33797 (CVSS 7.4) allows unauthenticated attackers to disrupt network operations by resetting BGP sessions via crafted packets, leading to sustained Denial-of-Service.
Oracle has released its April 2026 CPU, addressing 481 vulnerabilities with high-to-critical severity enabling RCE across Oracle Communications, Financial Services, and Middleware.
CVE-2026-33825 (CVSS 7.8) enables local attackers with low privileges to escalate access to SYSTEM level, potentially resulting in full system compromise.
CVE-2026-40050 (CVSS 9.8) allows unauthenticated remote attackers to perform path traversal attacks, potentially exposing sensitive files on self-hosted deployments.
Critical updates address RCE, Command Injection, and Memory Corruption across Firefox, Thunderbird, and the Atlassian Data Center Suite, spanning numerous critical CVEs.
CVE-2026-40372 (CVSS 9.1) allows attackers to perform remote privilege escalation to SYSTEM level via improper cryptographic signature validation in the Data Protection component.
CVE-2026-6644 (CVSS 9.4) enables attackers to execute arbitrary system commands via the PPTP VPN client component, potentially leading to full device compromise and data theft.
Multiple high-severity vulnerabilities (Arbitrary File Overwrite & Info Disclosure) are being actively exploited in the wild, risking full compromise of SD-WAN management infrastructure.
Cisco has identified several vulnerabilities across its product line, including authentication bypass, XSS, and SQL injection, impacting Secure Web Appliance, Webex, and ISE.
Critical findings highlight risks in Synology SSL VPN Client and AVEVA Pipeline Simulation software, potentially enabling unauthorized access and administrative-level actions.
A systemic vulnerability in the Model Context Protocol (MCP) allows unauthenticated remote code execution across major AI frameworks, compromising internal services and sensitive data including API keys.
Google has released ChromeOS LTS-138 (v138.0.7204.310) addressing 11 high-severity and 4 medium-severity vulnerabilities including use-after-free, heap buffer overflows, and out-of-bounds flaws that could lead to arbitrary code execution and system compromise.
A CVSS 9.4 critical flaw in protobuf.js enables attackers to inject and execute arbitrary JavaScript code via malicious protobuf schema definitions, threatening all Node.js and browser applications relying on dynamic schema loading.
CVE-2026-3324 enables unauthenticated attackers to bypass authorization controls via exposed V1 APIs in ManageEngine Log360 builds 13000–13013, threatening core log management and security monitoring infrastructure.
CVE-2026-34197 poses a significant Remote Code Execution risk to messaging infrastructure via insecure Jolokia JMX-HTTP bridge configurations.
A critical flaw (CVE-2026-5785) affecting Password Manager Pro and PAM360 permits low-privileged attackers to execute arbitrary SQL queries and escalate to Privileged Administrator.
Google has released a critical security update for Chrome, addressing 31 vulnerabilities including several RCE flaws and memory corruption issues. Immediate patching is mandatory.
Adobe has released urgent security updates addressing multiple critical vulnerabilities across Acrobat, InDesign, Photoshop, and more, which could allow arbitrary code execution.
Rising Risks from Data Exposure and Advanced Campaigns globally, targeting infrastructure, users, and digital ecosystems.
CyberShelter identifies an ongoing, highly sophisticated hack-for-hire surveillance campaign targeting UAE residents and MENA civil society using mobile spyware and credential phishing techniques.
CyberShelter analyzes a geopolitically motivated destructive operation by Handala targeting GCC infrastructure, resulting in 149 TB exfiltrated and 6 PB destroyed.
CyberShelter identifies a critical header injection vulnerability in Axios HTTP client enabling request smuggling, SSRF, and full infrastructure takeover.
CyberShelter identifies critical vulnerabilities in Movable Type's Listing Framework allowing unauthenticated attackers to execute arbitrary code and manipulate databases.
CyberShelter identifies an actively exploited zero-day prototype pollution vulnerability in Adobe Acrobat and Reader enabling full system compromise.
CyberShelter identifies multiple critical and high-severity vulnerabilities in GitLab CE/EE, including WebSocket abuse, GraphQL DoS, and Terraform API flaws.
CyberShelter identifies a large-scale state-sponsored cyber-espionage campaign conducted by Forest Blizzard (APT28) leveraging SOHO routers for DNS hijacking and AiTM attacks.
CyberShelter identifies an active Android banking malware campaign targeting regional banking customers through sophisticated social engineering attacks involving fake updates.
CyberShelter identifies multiple critical vulnerabilities in IBM Verify Identity Access and Security Verify Access platforms, including root privilege escalation and authentication bypass.
CyberShelter identifies a coordinated intelligence collection operation leveraging compromised Exchange OWA portals and VPN phishing infrastructure to steal enterprise credentials across the UAE.
CyberShelter identifies multiple security vulnerabilities in NVIDIA Triton and DALI that could allow attackers to cause denial-of-service, information disclosure, or RCE in AI environments.
CyberShelter identifies active exploitation of on-premises TrueConf servers to distribute weaponized updates, leading to large-scale infrastructure compromise.
CyberShelter identifies multiple critical vulnerabilities in Dell Data Protection Central and IDPA environments affecting Linux kernel and memory management, risking full system compromise.
CyberShelter identifies a high-severity arbitrary file deletion vulnerability affecting Perfmatters plugin that could allow unauthenticated attackers to reconfigure and compromise WordPress websites.
CyberShelter identifies multiple high-severity vulnerabilities affecting Cisco networking and management platforms including RCE, privilege escalation, and DoS.
CyberShelter identifies multiple high-severity vulnerabilities affecting Apache Traffic Server that could allow attackers to disrupt services and manipulate HTTP requests.
CyberShelter identifies an active campaign focused on pure destruction, aiming to permanently erase data and disrupt operations across multiple sectors including energy and telecom.
National Cybersecurity Authority warns of critical authentication bypass (CVE-2026-2699) and RCE (CVE-2026-2701) being chained for full system compromise in Progress ShareFile.
CyberShelter identifies a major transition in Iranian cyber operations toward industrial-scale warfare, combining destructive MDM wipes, cloud infrastructure targeting, and supply chain compromise.
CyberShelter identifies a significant escalation in Iranian-linked APT activity across the GCC, targeting critical infrastructure with ransomware, credential attacks, and AI-assisted operations.
CyberShelter Threat Intelligence has identified a critical vulnerability affecting Cisco Smart Software Manager On-Prem that could allow unauthenticated remote attackers to execute arbitrary commands with root privileges.
CyberShelter Threat Intelligence identified an actively exploited zero-day vulnerability in Google Chrome, with 21 patched flaws risking full system compromise.
CyberShelter Threat Intelligence has identified a critical vulnerability affecting HPE Telco NFV Orchestrator allowing remote attackers to compromise systems.
CyberShelter Threat Intelligence identifies critical authentication and integrity bypass vulnerabilities in Nginx UI, with public PoC exploit code available.
CyberShelter Threat Intelligence identifies a critical supply chain compromise in Axios delivering a RAT via poisoned npm packages to developers and CI pipelines.
CyberShelter Threat Intelligence identifies critical vulnerabilities in BIND 9 DNS servers risking network availability.
CyberShelter Threat Intelligence has identified severe vulnerabilities in NGINX Plus and Open Source, requiring immediate patching across enterprise environments.
CyberShelter Threat Intelligence has identified severe RCE and DoS vulnerabilities in Grafana, requiring immediate patching across enterprise environments.
CyberShelter Threat Intelligence identifies a high-severity DoS vulnerability in TP-Link router's UPnP service, requiring firmware updates.
CyberShelter identifies a critical zero-click vulnerability in Telegram messaging platform allowing remote attackers to fully compromise devices without any user interaction.
CyberShelter identifies renewed activity from Iran-linked PAY2KEY group, demonstrating extreme encryption speed and advanced forensic evasion targeting healthcare.
CyberShelter identifies high-severity vulnerabilities (CVE-2026-4315, CVE-2026-4266) impacting WatchGuard Firebox appliances.
CyberShelter identifies an ongoing campaign using HOPPINGANT malware to target Algeria, Mongolia, Ukraine, and Kuwait.
CyberShelter Alert: Cisco releases multiple security advisories addressing critical vulnerabilities affecting FMC, IOS, ASA, and Secure Firewall, including remote code execution (CVSS 10.0).
CyberShelter Alert: Apple has released critical updates across its ecosystem addressing high-severity kernel and WebKit vulnerabilities, including potential for remote code execution and system compromise.
CyberShelter Alert: Google has patched multiple high-severity vulnerabilities in Chrome that could lead to remote code execution and system compromise.
CyberShelter Alert: Critical vulnerabilities in NetScaler (formerly Citrix) ADC and Gateway could allow unauthenticated remote access and sensitive data disclosure.
CyberShelter Alert: Critical RCE in Oracle IAM and OWSM could allow unauthenticated remote code execution over HTTP, leading to full system compromise.
CyberShelter Alert: Critical authentication bypass affecting QNAP QVR Pro could allow unauthenticated remote access to surveillance management environments.
CyberShelter Threat Intelligence monitors a critical RCE vulnerability in the GNU InetUtils Telnet daemon affecting legacy and enterprise infrastructure worldwide.
CyberShelter Threat Intelligence tracking multiple high-severity vulnerabilities affecting several Atlassian enterprise products including Jira, Confluence, Bitbucket, Bamboo, Crowd.
CyberShelter Threat Intelligence tracks a critical RCE vulnerability in Microsoft SharePoint Server currently being exploited in the wild via insecure deserialization.
CyberShelter monitors multiple high-severity vulnerabilities in Jenkins, ChromeOS, and WebKit platforms that could allow remote code execution and session compromise.
CyberShelter Threat Intelligence has identified two critical security developments requiring immediate attention: a critical unauthenticated RCE in GNU InetUtils Telnetd and active Cisco FMC zero-day exploitation.
CyberShelter Threat Intelligence observes a significant escalation in cyber operations following military campaigns, targeting critical infrastructure across the Middle East.
CyberShelter GCC Weekly Threat Intelligence Report – March 7–14 2026
CyberShelter researchers have identified suspicious domains and URLs hosted within Microsoft Azure environments, suggesting malware staging and C2 preparation.
Comprehensive analysis of Void Manticore (Handala), an Iran-linked destructive threat actor targeting UAE energy, finance, and government sectors.
CyberShelter Threat Intelligence Advisory regarding the increasing use of destructive wiper malware targeting critical infrastructure and enterprises.
CyberShelter Threat Intelligence observes a significant escalation in hacktivist cyber activity across the Middle East, signaling a rapid evolution from disruptive operations to supply-chain disruption campaigns.
Urgent technical advisory regarding active Iranian cyber retaliatory operations following regional conflict escalation and Operations Epic Fury.
Comprehensive intelligence report on active indicators of compromise linked to global nation-state actors and prolific ransomware groups.
CyberShelter technical advisory indicates the UAE financial sector faces the most dangerous threat environment in its history, with active C2 infrastructure and pre-positioned destructive malware.
CyberShelter strategic supplement contains newly collected OSINT intelligence, fresh IOCs, threat actor updates, and confirmed incident impacts on UAE financial infrastructure.
CyberShelter threat intelligence monitoring indicates a sustained increase in cyber threat activity across the Middle East driven by geopolitical tensions.
CyberShelter has identified new IOCs associated with suspicious infrastructure and potential malware activity leveraging Microsoft Azure.
Comprehensive assessment of synchronized Iranian cyber-kinetic operations and large-scale infrastructure sabotage during the 2026 escalation window.
In-depth technical analysis of the CandleStone campaign exploiting the UAE's aerospace and defence technological ecosystem.
Comprehensive advisory on active MOIS-led campaigns targeting regional energy, government, and critical infrastructure sectors.
Access exclusive technical deep-dives, methodology papers, and global threat landscapes on the SecureReading platform.
EXPLORE SECURE READINGReceive real-time email updates, emergency advisories, and strategic reports directly to your inbox.
REGISTERIvanti has released security updates for Ivanti Endpoint Manager Mobile (EPMM) addressing five high-severity vulnerabilities, including an actively exploited remote code execution flaw.
The vulnerabilities impact core EPMM functionality and include risks related to authentication bypass, privilege escalation, improper certificate validation, and arbitrary method invocation.
| CVE ID | Severity | Type | Impact |
|---|---|---|---|
| CVE-2026-6973 | High (7.2) | RCE | Actively Exploited. Authenticated attackers with admin privileges can achieve RCE on the appliance. |
| CVE-2026-5786 | High (8.8) | Privilege Escalation | Remote authenticated attacker with low privileges can gain administrative control. |
| CVE-2026-5787 | High (8.9) | Cert Validation | Unauthenticated attackers can impersonate Sentry hosts and obtain CA-signed certificates. |
| CVE-2026-7821 | High (7.4) | Device Enrollment | Unauthenticated attackers can enroll unauthorized devices from restricted sets. |
| CVE-2026-5788 | High (7.0) | Method Invocation | Unauthenticated attackers can invoke arbitrary methods remotely. |
Affected Product: Ivanti Endpoint Manager Mobile (EPMM)
Affected Versions: Version 12.8.0.0 and prior
Organizations should immediately upgrade to one of the following fixed releases:
These releases also include cumulative fixes for previous critical flaws (CVE-2026-1281 and CVE-2026-1340).
Apply security updates for Ivanti EPMM and Sentry (versions 10.4.2, 10.5.1, or 10.6.1) without delay.
Rotate administrative credentials immediately, especially if previous impact from 2026-1281/1340 was suspected.
Limit administrative interfaces to trusted IP ranges and enforce strong MFA controls.
Review device enrollment logs and certificate issuance history for any unauthorized additions.
Mobile device management platforms are highly sensitive infrastructure components with extensive access to enterprise devices, identities, and policies. Vulnerabilities affecting these systems can rapidly escalate into broader enterprise compromise.
The confirmed active exploitation of CVE-2026-6973 further increases operational urgency for organizations running affected environments. CyberShelter recommends a proactive audit of all MDM configurations following the application of these patches.
A critical vulnerability has been identified in Rancher Fleet, a widely used GitOps solution for managing Kubernetes clusters at scale.
Tracked as CVE-2026-41050, the flaw allows attackers with limited repository access to bypass multi-tenant isolation controls and gain effective cluster-admin privileges across downstream Kubernetes environments.
The vulnerability stems from improper handling of impersonation and access controls within Rancher Fleet's multi-tenant architecture.
Attackers with limited repository permissions may exploit the flaw to:
Organizations using shared Kubernetes infrastructures, multi-tenant DevOps environments, or centralized GitOps workflows are at elevated risk.
| Software | Patched Version |
|---|---|
| Rancher | v2.14.1 |
| Rancher | v2.13.5 |
| Rancher | v2.12.9 |
| Rancher | v2.11.13 |
Upgrade Rancher and Fleet deployments to the latest patched versions mentioned above.
Review Git repository permissions and restrict write access to trusted users only.
Rotate Kubernetes Secrets and exposed credentials if compromise is suspected.
Enable enhanced Kubernetes audit logging and monitor for unusual privilege escalation activity.
GitOps platforms play a central role in modern Kubernetes operations and often possess broad administrative privileges across environments. Vulnerabilities affecting these systems can rapidly expand into full infrastructure compromise if not addressed promptly.
The ability to escalate from limited repository access to cluster-admin privileges significantly increases the operational risk of this vulnerability. Organizations should apply least-privilege access policies and segment tenant environments where possible.
Recent security findings have identified multiple vulnerabilities in widely used desktop applications, including Notepad++ and Foxit PDF Reader / Foxit PDF Editor.
These vulnerabilities range from denial-of-service (DoS) and information disclosure to potential arbitrary code execution, highlighting the importance of timely patching and secure file handling practices.
CVE-2026-3008 – Format String Injection in nativeLang.xml
The vulnerability exists in how Notepad++ processes the nativeLang.xml localization file, specifically the find-result-hits parameter.
When users perform actions such as "Find ALL in Current Document", a specially crafted XML file can inject malicious format string payloads that are processed without proper validation.
Multiple vulnerabilities have been identified affecting Foxit PDF Reader (Windows) and Foxit PDF Editor (Windows).
| CVE | Description | Severity |
|---|---|---|
| CVE-2026-5937 | Uncaught Exception (CWE-248). Improper parameter validation may cause crashes during directory import handling. | Moderate (CVSS 5.5) |
| CVE-2026-5938 | Insufficient Control Flow Management (CWE-691). Crafted document actions may trigger crashes or application freezes. | Moderate (CVSS 5.5) |
| CVE | Description | Severity |
|---|---|---|
| CVE-2026-5939 | Use After Free (CWE-416). May lead to crashes or information disclosure. | Moderate (CVSS 5.5) |
| CVE-2026-5940 | Use After Free (CWE-416). Memory corruption may allow arbitrary code execution. | Important (CVSS 7.8) |
| CVE-2026-5942 | Use After Free (CWE-416). May result in denial-of-service conditions. | Moderate (CVSS 5.5) |
| CVE-2026-5943 | Use After Free (CWE-416). Can lead to memory corruption and potential code execution. | Important (CVSS 7.8) |
Foxit PDF Reader: Version 2026.1.0.36452 and earlier
Foxit PDF Editor:
If exploited, these vulnerabilities could result in:
Organizations and users should take immediate steps:
These vulnerabilities highlight ongoing risks associated with file parsing and memory management in widely used applications. Attackers frequently exploit such weaknesses using specially crafted files to trigger crashes or gain deeper system access.
Applications that process user-supplied content, such as text editors and PDF tools, remain high-value targets. Timely patching and cautious handling of external files are essential to mitigating these risks. Organizations should prioritize updates and reinforce user awareness to reduce exposure to exploitation attempts targeting commonly used desktop applications.
Multiple high-severity vulnerabilities have been identified in Cisco Catalyst SD-WAN Manager that are currently being actively exploited in the wild. These flaws could allow attackers to gain unauthorized access, overwrite critical system files, and expose sensitive system credentials, potentially leading to a complete compromise of the network management platform.
| CVE ID | Severity | Vulnerability Type | Impact |
|---|---|---|---|
| CVE-2026-20122 | High | Arbitrary File Overwrite | Allows authenticated read-only users to overwrite system files, leading to privilege escalation. |
| CVE-2026-20128 | High | Information Disclosure | Unauthenticated retrieval of Data Collection Agent (DCA) credentials. |
| CVE-2026-20133 | High | Information Disclosure | Access to sensitive system data through exposed APIs due to weak file system restrictions. |
Cisco has released updates for all supported branches. Organizations are advised to upgrade based on the following schedule:
| Current Version Branch | Recommended Fixed Release |
|---|---|
| Earlier than 20.9 | Upgrade to a supported fixed release (e.g., 20.9.8.2+) |
| 20.9 | 20.9.8.2 |
| 20.10 & 20.11 | 20.12.6.1 |
| 20.12 | 20.12.5.3 or 20.12.6.1 |
| 20.13, 20.14, 20.15 | 20.15.4.2 |
| 20.16 & 20.18 | 20.18.2.1 |
Apply the appropriate patches mentioned above without delay to all SD-WAN Manager instances.
Limit management interfaces to trusted internal networks only. Disable public-facing exposure.
Disable unnecessary services (HTTP, FTP), implement RBAC, and rotate all DCA-related credentials.
Scan system logs and API request history for indicators of file manipulation or credential access attempts.
Multiple vulnerabilities have been identified affecting a wide range of Cisco enterprise products. These issues include authentication bypass, cross-site scripting (XSS), SQL injection, privilege escalation, and arbitrary file operations. Collectively, these vulnerabilities could impact the confidentiality, integrity, and availability of sensitive systems if left unpatched.
| Product | CVE ID | Vulnerability Type |
|---|---|---|
| Cisco Secure Web Appliance | CVE-2026-20152 | Authentication Bypass |
| Cisco Webex Contact Center | CVE-2026-20170 | Cross-Site Scripting (XSS) |
| Cisco Unity Connection | CVE-2026-20059 - 61 | XSS, Open Redirect, SQL Injection |
| Cisco Unity Connection | CVE-2026-20078, 81 | Arbitrary File Download |
| Cisco ThousandEyes Agent | CVE-2026-20161 | Arbitrary File Overwrite |
| Cisco Identity Services Engine | CVE-2026-20132 | Cross-Site Scripting (XSS) |
| Cisco Identity Services Engine | CVE-2026-20136 | Privilege Escalation |
Successful exploitation of these vulnerabilities could result in unauthorized access, script execution, database manipulation, and theft of sensitive information. Particularly concerning are the file overwrite and privilege escalation flaws which could lead to full system compromise.
Install vendor-provided updates immediately across all affected infrastructures.
Review and limit access to affected administrative interfaces and APIs.
Increase logging and monitoring for suspicious web-based interactions or unusual file access.
Enforce strict RBAC and least-privilege policies to mitigate privilege escalation risks.
Recent security findings highlight critical and high-risk vulnerabilities affecting both endpoint VPN solutions and industrial simulation software. These issues could enable unauthorized access, data exposure, and privilege escalation, posing significant risks to enterprise environments as well as critical infrastructure systems.
Multiple high-severity vulnerabilities have been identified in the Synology SSL VPN Client, affecting confidentiality and credential security.
| CVE ID | Severity | Type | Description |
|---|---|---|---|
| CVE-2021-47960 | Important (6.5) | Improper File Access (CWE-552) | Local HTTP service flaw allows access to config files, certificates, and logs. |
| CVE-2021-47961 | Important (8.1) | Plaintext Storage (CWE-256) | VPN PIN codes and sensitive info stored in plaintext, allowing credential manipulation. |
A critical vulnerability in AVEVA Pipeline Simulation allows unauthenticated attackers to bypass authorization controls entirely.
CVE-2026-5387: This vulnerability permits network-accessible, unauthenticated attackers to perform administrative-level actions via exposed APIs. In industrial control systems (ICS), this could lead to manipulation of simulation data and compromise of operational decision-making.
Patch all clients to version 1.4.5-0684 or later.
Restrict unnecessary exposure of local HTTP services used by the VPN client.
Apply build 7.1.9580.8513 across all simulation environments immediately.
Segment critical simulation systems from external networks and restrict API access.
CyberShelter Threat Intelligence has identified multiple critical and high-severity vulnerabilities affecting GitLab Community Edition (CE) and Enterprise Edition (EE). These vulnerabilities impact core components including WebSockets, GraphQL APIs, Terraform state handling, and CSV processing. Successful exploitation could lead to service disruption (DoS), sensitive data exposure, and unauthorized access.
| Attribute | Details |
|---|---|
| Platform | GitLab CE / EE |
| Severity | High to Critical |
| Vulnerability Count | Multiple CVEs |
| Primary Risks | DoS, XSS, Info Disclosure, Auth Bypass |
| Affected Components | WebSockets, GraphQL, Terraform, CSV |
| Recommended Action | Immediate patching to secure versions |
GitLab has released security updates addressing multiple vulnerabilities that could allow attackers to crash services through malformed requests, access sensitive data, execute malicious scripts, or bypass authorization controls. These issues affect both CE and EE deployments, with some vulnerabilities specific to enterprise features like analytics dashboards and SBOM APIs.
Organizations should upgrade immediately to the latest patched versions to mitigate these risks across their CI/CD and DevOps infrastructure.
| Product | Secure Versions |
|---|---|
| GitLab CE / EE | 18.10.3 |
| GitLab CE / EE | 18.9.5 |
| GitLab CE / EE | 18.8.9 |
Attacker sends repeated GraphQL queries to exhaust server resources, crashing GitLab services and disrupting CI/CD pipelines.
Authenticated attacker exploits exposed WebSocket methods to execute unintended backend actions and gain unauthorized control.
Attacker exploits GraphQL or CSV flaws to retrieve sensitive data, exposing internal emails, reports, or SBOM data.
Malicious payloads injected into dashboards execute in user browsers, enabling session hijacking or credential theft.
| IOC | Type | Description |
|---|---|---|
| High volume GraphQL queries | Network | Possible DoS attempt |
| Repeated API requests | Network | Abuse of endpoints |
| Malformed JSON payloads | Network | Terraform DoS exploitation |
| IOC | Type | Description |
|---|---|---|
| WebSocket misuse patterns | App | Unauthorized method calls |
| Unusual CSV import/export | App | Possible exploitation |
| CPU spikes in GitLab services | Host | DoS activity |
| Sidekiq worker crashes | System | CSV import exploitation |
| Tactic | Technique | Description |
|---|---|---|
| Impact | T1499 | Endpoint DoS |
| Impact | T1498 | Network DoS |
| Initial Access | T1190 | Exploit Public-Facing Application |
| Execution | T1059 | Command Execution |
| Credential Access | T1552 | Unsecured Data Access |
| Persistence | T1098 | Account Manipulation |
Upgrade GitLab to latest patched versions immediately. Review exposed APIs and endpoints.
Implement rate limiting on GraphQL APIs and validate all input (JSON, CSV, API requests).
Enforce least privilege access, audit role permissions, and restrict WebSocket permissions.
Monitor GraphQL query volume, detect abnormal API activity, and deploy WAF for API protection.
CyberShelter Threat Intelligence has identified a coordinated credential harvesting campaign targeting multiple sectors across the UAE, including government entities, telecom providers, financial institutions, and defense organizations. The campaign leverages compromised Microsoft Exchange OWA portals and VPN phishing infrastructure to steal enterprise credentials.
| Attribute | Details |
|---|---|
| Threat Type | Credential harvesting campaign |
| Target Region | UAE |
| Target Sectors | Government, Defense, Finance, Telecom |
| Infrastructure | Microsoft Azure hosted systems |
| Threat Actor | Suspected Iranian APT activity (APT34) |
| Threat Objective | Intelligence collection |
| Risk Level | Critical |
Investigators identified a sophisticated global infrastructure spanning 112 IP addresses used for automated phishing deployment. A distinctive attacker certificate template was observed across multiple hosts: O=Int, OU=Internal, L=Portland, C=US.
The operational pattern, target selection (regional government and defense), and specific OWA exploitation techniques align closely with known Iranian state-aligned espionage activity.
| Phase | Technique | Description |
|---|---|---|
| Reconnaissance | Vulnerability Scanning (T1595.002) | Scanning for unpatched ProxyShell/ProxyLogon vulnerabilities. |
| Initial Access | Exploit Public-Facing App (T1190) | Exploitation of public-facing Exchange servers. |
| Persistence | Web Shell Deployment (T1505.003) | Installation of ASPX web shells for persistent access. |
| Credential Access | JavaScript Keylogging (T1056.001) | Stealing credentials from OWA login pages. |
| Collection | Email Collection (T1114) | Accessing emails, contacts, and calendars via stolen credentials. |
| Exfiltration | Exfiltration Over C2 (T1041) | POSTing credentials to attacker infrastructure via HTTPS. |
Enforce MFA on OWA and VPN portals. Implement risk-based conditional access.
Apply all critical security updates for Microsoft Exchange (ProxyShell/ProxyLogon) immediately.
Monitor for unauthorized JavaScript modifications in OWA login pages and audit web server directories for shells.
Isolate critical infrastructure and enforce strict TLS certificate validation for all VPN connections.
CyberShelter Threat Intelligence has identified multiple security vulnerabilities affecting NVIDIA Triton Inference Server and NVIDIA DALI, both critical components in AI/ML production environments. These vulnerabilities could allow attackers to cause denial-of-service (DoS), information disclosure, or arbitrary code execution (RCE).
| Attribute | Details |
|---|---|
| Vendor | NVIDIA |
| Affected Products | Triton Inference Server / NVIDIA DALI |
| Vulnerabilities | Multiple CVEs |
| Severity | High |
| Primary Risks | DoS / Information Disclosure / RCE |
| Target Environment | AI/ML infrastructure |
| Recommended Action | Immediate upgrade |
Insufficient input validation combined with excessive output handling may allow attackers to crash Triton servers, disrupting AI workloads and production pipelines.
Attackers could send malformed requests that cause Triton server instability, resulting in server crashes and processing failures.
Malformed HTTP headers could trigger denial-of-service conditions and server crashes.
Uploading a specially crafted model configuration could allow attackers to expose sensitive information including model configurations, processing logic, and system metadata.
Improper handling of untrusted serialized data in NVIDIA DALI may allow attackers to execute arbitrary code, compromise AI pipelines, and deploy malware.
This represents the highest risk vulnerability in the set due to its potential for full system compromise and infrastructure takeover.
| Product | Status | Versions |
|---|---|---|
| Triton Inference Server | Affected | All versions prior to r26.02 |
| Triton Inference Server | Fixed | r26.02 and later |
| NVIDIA DALI | Affected | All versions prior to 2.0 |
| NVIDIA DALI | Fixed | Version 2.0 and later |
Upgrade Triton Inference Server to r26.02 and NVIDIA DALI to version 2.0 immediately.
Restrict model upload permissions, validate model integrity, and enforce strict API authentication.
Isolate AI infrastructure from public networks and apply Zero Trust access controls to API endpoints.
Monitor inference logs for malformed requests and track GPU compute patterns for anomalies.
Since February 28 2026, Iranian cyber operations have transitioned from reactive retaliation into what can now be classified as industrial-scale cyber warfare, combining destructive cyberattacks, supply-chain compromise, infrastructure targeting, and multi-state threat collaboration.
Latest intelligence shows a clear evolution in attack sophistication, operational scale, strategic targeting, and the weaponization of legitimate enterprise tools. This marks one of the most aggressive cyber escalation phases observed in recent history.
Shift toward abusing enterprise management systems rather than deploying traditional malware.
Case Study: Stryker MDM Wipe Attack
Attackers weaponized Microsoft Intune
administrative controls to destroy approximately 200,000 devices across 79 countries within three
hours.
Why this matters: This demonstrates a major shift from traditional ransomware to Living-off-the-land techniques, admin platform abuse, identity compromise, and management plane attacks. Identity security is now more critical than endpoint security.
| Metric | Old Model (Pre-2026) | New Model (Feb 28 Present) |
|---|---|---|
| Primary Vector | Malware Deployment | Living-off-the-land techniques |
| Target Focus | Endpoint Exploitation | Admin platform abuse |
| Payload | Traditional Ransomware | Identity compromise / Mgmt plane attacks |
Iran-linked operations targeted cloud infrastructure facilities (Data Centers, Cloud Regions) in the Middle East, disrupting banking systems, enterprise cloud workloads, financial platforms, and ride-hailing applications. This marks one of the first known examples of cloud infrastructure becoming a geopolitical battlefield.
Strategic Shift: Attack focus expanded from Networks, VPNs, and Industrial systems to include Cloud regions, Data centers, SaaS ecosystems, and DevOps pipelines. This signals a transition toward digital supply chain warfare.
Iranian cyber operations expanded from 6 major groups to more than 10 active threat actors, specifically targeting telecom, aerospace, and maritime sectors. Key actors include:
More malware families, targeting diversity, cross-nation collaboration, faster operational tempo.
AI-assisted phishing, RMM abuse, supply-chain poisoning, infrastructure pre-positioning. (Indicates structured cyber military organization rather than isolated activity).
Attackers targeted developer ecosystems (npm, Docker, GitHub tokens, CI/CD, AI tooling). A single campaign cascaded across multiple platforms within days, showing the growing risk of software trust exploitation.
Increased exploitation of Hikvision and Dahua cameras for intelligence gathering, military targeting, and physical surveillance. This marks a dangerous evolution toward cyber-enabled kinetic targeting.
Targeting MDM platforms, Identity systems, Firewall controllers, and Cloud admin accounts. Goal: Control the control systems.
Credential abuse is replacing zero-days. More reliable, lower cost, and harder to detect.
Conflict exploited by Russia, China, Belarus, and Hamas-aligned actors. Result: A global cyber opportunistic environment.
Phishing, social engineering, and profiling. AI is accelerating attack scale rather than replacing attackers.
| Threat Vector | Priority Risk Level | Expected Targets / Impact |
|---|---|---|
| MDM Weaponization | ?? Critical | Healthcare, Manufacturing, Defense, Financial Services |
| ICS Activation | ?? High | Water Systems, HVAC Infrastructure, Hospitals, Energy Grids |
| Wiper Escalation | ?? Critical | RMM abuse, Admin platform destruction, Identity-based wiping |
Move from reactive detection toward adversary simulation and threat hunting.
Segment IT and OT networks strictly. Audit all digital supply chains.
Immutable backups, offline recovery, CI/CD monitoring, RMM auditing.
Multi-approval device wipes, admin monitoring, privilege minimization.
Reality 1: Cyber warfare is now continuous, not event-driven. Reality 2: Enterprise software is now battlefield infrastructure. Reality 3: Identity is the new security perimeter.
Critical Assumption: Future cyber conflicts will target business infrastructure first, not governments.
Final Conclusion: The cyber escalation observed since February 28 2026 demonstrates a new cyber warfare model defined by industrialized operations, infrastructure targeting, identity compromise, and supply chain warfare. Geo-political risk must now be treated as a continuous operational threat rather than a theoretical scenario.
CyberShelter Threat Intelligence has identified an escalation in cyber threat activity across the Middle East region during Q1 2026 involving multiple Iranian-linked Advanced Persistent Threat (APT) groups. The campaign shows increased targeting of government, telecom, defense, financial, and cloud infrastructure sectors.
| Attribute | Details |
|---|---|
| Region | Middle East / GCC |
| Threat Level | ?? Critical |
| Threat Actors | Handala, MuddyWater, APT34 (OilRig) |
| Target Sectors | Government, Telecom, Defense, Banking |
| Attack Types | Espionage / Ransomware / Credential Attacks |
| Key Techniques | Password spraying, RAT deployment, data leaks |
| Business Risk | Critical infrastructure targeting |
Threat intelligence indicates a coordinated increase in cyber operations linked to geopolitical tensions, including ransomware operations, Microsoft 365 password spraying campaigns, infrastructure breaches, and AI-assisted cyber operations.
| Attribute | Details |
|---|---|
| Origin | Iran-linked threat activity |
| Activity | Data leaks and cyber espionage |
| Threat Level | ?? Critical |
Observed Capabilities: Data breach operations, infrastructure targeting, domain reconstitution after seizures, AI-assisted PowerShell obfuscation, and mobile device management abuse. Threat intelligence also observed Microsoft Intune abuse for mass device wipe operations.
| Attribute | Details |
|---|---|
| Origin | Iranian APT |
| Focus | Espionage operations |
| Tools | Custom malware families |
Malware Observed: CHAR (Rust-based), BlackBeard backdoor, LampoRAT (Telegram RAT), NUSO custom HTTP malware, UDPGangster macro malware, and RustyWater RAT. These indicates a diverse toolkit for persistence and C2 operations.
| Date | Event Type | Description |
|---|---|---|
| Mar 01 | Cloud Incident | Cyber incident impacting AWS-related environments. |
| Mar 03 | Ransomware Shift | Transition from Sicarii to BQTLock ransomware activity. |
| Mar 03 | Identity Attack | Microsoft 365 password spray campaign wave. |
| Mar 06 | APT Activation | MuddyWater backdoor activation detected (C2: 162.0.230[.]185). |
| Mar 12 | Destructive Attack | Large-scale attack reporting 200,000 devices wiped. |
| Mar 23 | Data Breach | Claims affecting multiple defense sector organizations. |
| Mar 28 | Account Compromise | Gmail compromise of senior government leadership. |
| Mar 30 | AI Surge | AI-powered cyberattack surge targeting UAE infrastructure. |
Threat intelligence observed data exposure claims involving defense and aerospace, law enforcement, intelligence organizations, government ministries, telecom providers, and financial institutions.
Primary Domain: handala-hack[.]ps
Seized Domains: handala-hack[.]to, justicehomeland[.]org,
karmabelow80[.]org, handala-redwanted[.]to
C2 IP: 107.189.19[.]52
C2: 162.0.230[.]185 (SSH on port 22)
Phishing: 157.20.182[.]75:5000
| Type | Artifact Name / Family |
|---|---|
| Loader | nvdaHelperRemoteLoader.exe / nvdaHelperRemote.dll |
| Families | CHAR, BlackBeard, LampoRAT, NUSO, UDPGangster, RustyWater |
| Ransomware Ext | .sicarii, .BQTLOCK (Exploiting React2Shell vulnerability) |
| CVE | Targeted Platform / Actor |
|---|---|
| CVE-2025-54068 | Boggy Serpens Initial Access |
| CVE-2025-55182 | BQTLock Ransomware Exploitation |
| CVE-2026-21643 | FortiClient EMS Vulnerability |
| CVE-2026-20131 | Cisco Secure Firewall Zero-Day |
| CVE-2025-64446 | Fortinet Enterprise Infrastructure |
| Category | Rating |
|---|---|
| Threat Level | ?? Critical |
| Regional Impact | Extreme |
| Infrastructure Risk | High |
| Espionage Activity | High |
| Ransomware Risk | Moderate to High |
Hunt for listed Handala and MuddyWater indicators in endpoint and network logs.
Monitor M365 authentication logs for password spraying and deploy MFA universally.
Block identified C2 IPs and monitor for unauthorized SSH activity via port 22.
Patch Cisco, Fortinet, and enterprise infrastructure vulnerabilities listed in CVE targets.
Identity: Spikes in failed logins, impossible travel, and MFA bypass attempts. Endpoint: Custom RAT indicators and nvdaHelper loader execution. Network: Outbound C2 connections and DNS anomalies.
Conclusion: The Q1 2026 escalation represents a significant shift in Iranian-linked cyber operations, blending espionage with destructive wiper attacks and AI-assisted obfuscation. GCC organizations must prioritize identity security and infrastructure integrity.
CyberShelter Threat Intelligence has identified a critical vulnerability affecting Cisco Smart Software Manager On-Prem (SSM On-Prem) that could allow unauthenticated remote attackers to execute arbitrary commands with root privileges.
Tracked as CVE-2026-20160, the vulnerability carries a CVSS score of 9.8 (Critical) and may allow complete system compromise if exploited.
| Attribute | Details |
|---|---|
| Product | Cisco Smart Software Manager On-Prem |
| CVE | CVE-2026-20160 |
| Severity | ?? Critical |
| CVSS Score | 9.8 |
| Vulnerability Type | Command Execution |
| Authentication Required | No |
| Privileges Required | None |
| Impact | Root level compromise |
| Recommended Action | Immediate upgrade |
| Parameter | Value |
|---|---|
| CVE ID | CVE-2026-20160 |
| Advisory ID | cisco-sa-ssm-cli-execution-cHUcWuNr |
| CWE | CWE-668 (Exposure of Resource to Wrong Sphere) |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Confidentiality Impact | High |
| Integrity Impact | High |
| Availability Impact | High |
The vulnerability occurs due to exposure of an internal service that should not be externally accessible. Attackers may interact with a vulnerable API endpoint to execute arbitrary commands.
The issue is caused by:
Successful exploitation could allow attackers to fully compromise the system. Because SSM manages licensing and device trust relationships, compromise could have wider enterprise implications.
Execute commands as root, modify system configurations, and fully compromise the system.
Deploy malware and establish long-term persistence in the environment.
Access sensitive license infrastructure and move laterally into enterprise environments.
Business Risks: Licensing infrastructure compromise, unauthorized software activation, service disruptions, infrastructure instability, and security compliance issues.
Security Risks: Attackers could potentially gain privileged system access, deploy backdoors, modify device trust configurations, access internal infrastructure, and establish long-term persistence.
| Product | Affected Versions |
|---|---|
| Cisco SSM On-Prem | Versions 9-202502 through 9-202510 |
Versions earlier than 9-202502 are reported as not vulnerable.
| Attribute | Details |
|---|---|
| Vulnerability | ZDI-CAN-30207 |
| Platform | Telegram |
| Severity | Critical |
| CVSS Score | 9.8 |
| Attack Type | Zero-Click Remote Exploit |
| Authentication Required | No |
| User Interaction | None |
| Impact | Device compromise |
CyberShelter Threat Intelligence has identified a critical zero-click vulnerability affecting the Telegram messaging platform, disclosed through the Trend Micro Zero Day Initiative. The vulnerability, tracked as ZDI-CAN-30207, carries a CVSS score of 9.8 (Critical) and could allow remote attackers to fully compromise devices without any user interaction.
| Parameter | Value |
|---|---|
| Attack Vector | Network (AV:N) |
| Attack Complexity | Low (AC:L) |
| Privileges Required | None (PR:N) |
| User Interaction | None (UI:N) |
| Scope | Unchanged |
| Confidentiality Impact | High |
| Integrity Impact | High |
| Availability Impact | High |
Successful exploitation could allow attackers to execute malicious code remotely, access sensitive communications, conduct surveillance operations, steal confidential data, compromise enterprise devices, and disrupt system availability.
Attackers can compromise devices without clicking links, opening attachments, accepting messages, or user awareness. This significantly increases the success probability of targeted attacks.
Attackers do not require Telegram accounts, prior access, or trusted relationships. Use interaction is nonexistent, and exploitation complexity is low, increasing the likelihood of widespread use.
Threat actors may target government personnel, diplomats, defense organizations, and intelligence targets.
Attackers may attempt corporate data theft, intellectual property access, and internal communication monitoring.
If weaponized publicly, attackers could conduct automated exploitation campaigns and spyware deployment.
Update Telegram applications immediately, enable automatic updates, and apply security patches across all devices.
Restrict messaging to contacts only, disable unknown user communications, restrict group invitations, and disable unknown bot interactions.
Disable automatic media downloads, avoid unknown public groups, remove unnecessary bots, and review privacy settings.
| Attribute | Details |
|---|---|
| Threat Name | PAY2KEY Ransomware |
| Threat Type | Ransomware / Cyber Espionage |
| Attribution | Iranian State-Linked Threat Actor |
| Target Sector | Healthcare & Critical Infrastructure |
| Severity | Critical |
| Encryption Speed | ~3 Hours |
| Primary Risk | Rapid enterprise-wide encryption |
| MITRE Impact | Data Encrypted for Impact (T1486) |
CyberShelter Threat Intelligence has identified renewed activity from the PAY2KEY ransomware group demonstrating enhanced anti-forensic techniques, credential harvesting, and rapid encryption capabilities.
The campaign shows operational maturity with stealth access, delayed execution, and rapid encryption designed to defeat traditional incident response timelines.
| Category | Rating |
|---|---|
| Sophistication | HIGH |
| Speed | EXTREME |
| Stealth | HIGH |
| Anti-Forensics | ADVANCED |
| Business Impact | CRITICAL |
| Detection Difficulty | HIGH |
Attackers gain access through compromised admin accounts, initial access broker markets, remote access exposure, or weak privileged account controls.
Attackers use legitimate remote management software (TeamViewer) already installed in the environment to avoid malware detection triggers.
Observed tools: Mimikatz, LaZagne, ExtPassword. Goal: Privilege escalation and lateral movement preparation.
Network discovery using: Advanced IP Scanner, NetScan, Active Directory tools. Goal: Identify high-value systems before encryption.
| Feature | Details |
|---|---|
| Algorithm | ChaCha20 |
| Key Exchange | Curve25519 |
| Encryption Model | Hybrid fast encryption |
| File Extension | .6zldh_p2k |
| Encryption Time | ~1 hour active phase |
PAY2KEY demonstrates strong forensic evasion through Windows event log wiping, backup catalog deletion, Defender disablement, and more.
Attackers wipe logs as the final action to remove investigation evidence.
| e09912faa93808ca7de4cb858102d7647a0a6feb43dbcef7f9dd0b1948902f54 |
| 30f166d91cec5a2858d93c77fe1599c8fce9938706d8ce99030faaeaf3a18b06 |
| 68a95a0a5d0868eb3868426287feb38450a690aca60169828d7bc00166e4f014 |
| bd4635d582413f84ac83adbb4b449b18bac4fc87ca000d0c7be84ad0f9caf68e |
| fb653fd840b0399cea31986b49b5ceadd28fb739dd2403a8bb05051eea5e5bbc |
| 3ac68f46c3dcb95d942c4022dc136208fae8daa594c82743d29ef6a178f9c57a |
| e245db1b683a111fd2315eb29e68f77e3efa8c335862ce44e225a7fceaf4ce5a |
SOC teams should hunt for:
Audit TeamViewer, disable unused remote tools, hunt IOCs, monitor admin logins, validate backups.
Enable Credential Guard, restrict LSASS access, deploy EDR rules, validate recovery.
Implement PAM, Just-In-Time access, network segmentation, IR playbooks, MFA enforcement.
| Category | Rating |
|---|---|
| Threat Level | ?? Critical |
| Exploitation Likelihood | High |
| Detection Difficulty | High |
| Business Risk | Severe |
| Recommended Action | Immediate mitigation |
Key Takeaways: Iranian APT ransomware active, healthcare primary target, 3-hour encryption period, advanced anti-forensics, backup strategy is critical.
Analyst Note: PAY2KEY is a strategic threat due to operational discipline and geopolitical alignment. Prioritize ransomware readiness and privileged access protection.
Cisco has released multiple security advisories addressing several high-severity vulnerabilities and one critical vulnerability affecting widely deployed networking and security solutions including Cisco IOS, IOS XE, ASA, Secure Firewall Threat Defense (FTD), and Firewall Management Center (FMC).
If successfully exploited, these vulnerabilities could allow attackers to execute remote code, cause denial-of-service (DoS) conditions, bypass security protections, or disrupt enterprise network operations.
The vulnerabilities identified by Cisco include:
Remote Code Execution in Cisco Firewall Management Center
This vulnerability could allow an unauthenticated remote attacker to execute arbitrary code on affected systems. Due to its critical severity, organizations should prioritize patching immediately.
IKEv2 Denial-of-Service Vulnerability
This vulnerability could allow attackers to cause memory exhaustion resulting in device instability or service outages.
DHCP Snooping DoS Vulnerability
Successful exploitation may allow attackers to cause network disruption by exhausting system resources.
HTTP Server DoS Vulnerability
This vulnerability could allow attackers to send crafted HTTP requests causing denial-of-service conditions.
TLS Memory Exhaustion Vulnerability
Attackers may exploit this vulnerability to exhaust memory resources and disrupt secure communications.
CAPWAP DoS Vulnerability (Wireless Controllers)
This issue could allow attackers to disrupt wireless controller operations leading to network service interruptions.
Secure Boot Bypass Vulnerability
This vulnerability could allow an attacker with physical access to bypass secure boot protections.
Successful exploitation of these vulnerabilities could result in network outages, device instability, security control bypass, remote compromise, and enterprise network exposure. CyberShelter recommends organizations take the following immediate actions:
Apply Cisco security updates and patches immediately for affected product versions.
Implement network segmentation to limit exposure and restrict management interface access.
Monitor network devices for abnormal activity and maintain updated backup configurations.
Follow Cisco mitigation guidance where patches cannot be immediately applied.
Conclusion: These vulnerabilities demonstrate the ongoing risks targeting enterprise networking infrastructure. Organizations must ensure timely patching of network devices, as unpatched infrastructure remains a prime target for threat actors.
CyberShelter strongly advises security teams to treat the critical FMC vulnerability as an emergency patching priority.
CyberShelter will continue monitoring Cisco security advisories and provide updates on emerging threats affecting enterprise infrastructure.
Apple has released important security updates across its entire product ecosystem to address multiple vulnerabilities affecting iOS, iPadOS, macOS, tvOS, watchOS, visionOS, and Safari. These vulnerabilities range from information disclosure and privacy issues to denial-of-service (DoS), kernel memory corruption, sandbox escape, and critical WebKit flaws that could allow web-based attacks.
Security researchers warn that successful exploitation could allow attackers to compromise devices through malicious applications, specially crafted web content, or privileged network access.
The newly patched vulnerabilities could allow attackers to:
Multiple high-risk kernel vulnerabilities were patched:
Several critical WebKit vulnerabilities were addressed that could allow attacks through malicious websites:
Apple released updates for the following platforms:
| Software Version | Affected Devices |
|---|---|
| iOS 26.4 / iPadOS 26.4 | iPhone 11 and later, multiple iPad models |
| iOS 18.7.7 / iPadOS 18.7.7 | iPhone XS, XS Max, XR, iPad 7th gen |
| macOS Tahoe 26.4 | macOS Tahoe systems |
| macOS Sequoia 15.7.5 | macOS Sequoia systems |
| macOS Sonoma 14.8.5 | macOS Sonoma systems |
| tvOS 26.4 | Apple TV HD and Apple TV 4K |
| watchOS updates | Apple Watch Series 1 and later |
| visionOS 26.4 | Apple Vision Pro |
| Safari 26.4 | macOS Sonoma and Sequoia |
| Xcode 26.4 | macOS Tahoe |
CyberShelter strongly recommends organizations and individual users to take the following actions immediately:
Install the latest Apple security updates on all affected devices immediately.
Enable automatic updates where possible to ensure timely patching of future vulnerabilities.
Avoid opening suspicious links or untrusted websites, particularly given the active WebKit vulnerabilities.
Apply mobile device management (MDM) security policies to force updates in enterprise environments.
Additionally, continue to use strong device passcodes and biometric protection, install applications only from trusted sources, and monitor enterprise devices for unusual behavior.
Conclusion: These updates highlight the importance of timely patch management as attackers continue to target widely used platforms. Organizations should treat these updates as high priority due to the presence of kernel and WebKit vulnerabilities that could potentially lead to device compromise.
CyberShelter will continue to monitor developments related to these vulnerabilities and provide updates as necessary.
CyberShelter Threat Intelligence is monitoring a critical remote code execution vulnerability affecting the GNU InetUtils Telnet daemon (telnetd) that allows unauthenticated attackers to execute arbitrary code remotely.
The vulnerability (CVE-2026-32746) is caused by improper bounds checking in the TELNET protocol negotiation process and can be exploited without authentication or user interaction.
Due to the widespread presence of legacy Telnet services in enterprise infrastructure, embedded systems, and industrial environments, CyberShelter assesses this vulnerability as a critical operational risk, especially where Telnet remains externally accessible.
| Attribute | Details |
|---|---|
| CVE | CVE-2026-32746 |
| Severity | Critical |
| CVSS Score | 9.8 |
| Vulnerability Type | Remote Code Execution |
| Weakness | Buffer Overflow |
| Attack Vector | Network |
| Authentication | Not required |
| User Interaction | None |
The vulnerability exists due to improper bounds checking in the handling of the LINEMODE Set Local Characters (SLC) option within the TELNET protocol. Attackers can exploit this flaw by sending specially crafted TELNET negotiation messages during the initial connection phase.
| Stage | Attack Activity |
|---|---|
| Initial connection | Attacker connects to Telnet service |
| Exploit trigger | Crafted SLC negotiation payload |
| Memory corruption | Buffer overflow occurs |
| Code execution | Arbitrary commands executed |
| Privilege escalation | Root access obtained |
| Product | Status | Version |
|---|---|---|
| GNU InetUtils telnetd | Vulnerable | All versions up to 2.7 |
| System Type | Exposure Risk |
|---|---|
| Linux servers | HIGH |
| Network appliances | HIGH |
| Embedded systems | HIGH |
| IoT devices | HIGH |
| ICS / OT environments | CRITICAL |
| Legacy infrastructure | CRITICAL |
Disable the Telnet service immediately if it is not business-critical.
Block TCP port 23 at the network perimeter and internal segmentation points.
Migrate to SSH for all remote administration tasks.
Isolate legacy systems that require Telnet within restricted VLANs.
CyberShelter Threat Intelligence is tracking multiple high-severity vulnerabilities affecting several Atlassian enterprise products including Jira Software, Jira Service Management, Confluence, Bitbucket, Bamboo, Crowd, and Fisheye/Crucible.
These vulnerabilities may allow attackers to conduct Remote Code Execution (RCE), Path traversal attacks, File inclusion exploitation, Cross-Site Scripting (XSS), Denial-of-Service (DoS), and Command injection attacks.
Successful exploitation may lead to service disruption, unauthorized access, data exposure, or complete system compromise. CyberShelter recommends immediate patching of affected systems to reduce exposure.
| Product | Vulnerability Type | Risk |
|---|---|---|
| Bamboo | Remote Code Execution | HIGH |
| Bitbucket | Denial of Service | MEDIUM |
| Confluence | Command Injection | HIGH |
| Crowd | Cross-Site Scripting | HIGH |
| Jira Software | Path traversal & file inclusion | HIGH |
| Jira Service Management | File inclusion | HIGH |
| Fisheye/Crucible | Denial of Service | MEDIUM |
| CVE | Vulnerability | CVSS |
|---|---|---|
| CVE-2026-21570 | Remote Code Execution | 8.6 |
| CVE-2025-68493 | Missing XML validation | 8.1 |
| CVE-2025-64775 | Denial of Service | 7.1 |
Risk Description: These vulnerabilities could allow attackers to execute malicious code remotely, exploit Apache Struts weaknesses, disrupt build pipelines, and impact CI/CD operations.
| CVE | Vulnerability | CVSS |
|---|---|---|
| CVE-2022-25883 | Denial of Service | 7.5 |
Risk Description: Attackers may exploit dependency vulnerabilities to cause application crashes, disrupt repository access, and affect development operations.
| CVE | Vulnerability | CVSS |
|---|---|---|
| CVE-2025-64756 | OS Command Injection | 7.5 |
Risk Description: This vulnerability may allow attackers to execute system commands, access sensitive data, and compromise Confluence servers.
| CVE | Vulnerability | CVSS |
|---|---|---|
| CVE-2026-21884 | DOM-based XSS | 8.2 |
| CVE-2026-22029 | DOM-based XSS | 8.0 |
| CVE-2026-25639 | Denial of Service | 7.5 |
Risk Description: Potential impacts include credential theft, session hijacking, and identity management compromise.
| CVE | Vulnerability | CVSS |
|---|---|---|
| CVE-2026-23950 | Path Traversal | 8.8 |
| CVE-2026-23745 | File Inclusion | 8.2 |
| CVE-2026-24842 | File Inclusion | 8.2 |
| CVE-2024-57699 (JSM) | Denial of Service | 7.5 |
| CVE-2022-25927 | Denial of Service | 7.5 |
| CVE-2022-25883 | Denial of Service | 7.5 |
| CVE-2020-28469 | Denial of Service | 7.5 |
Risk Description: Attackers could exploit these to access restricted files, execute unauthorized code, disrupt services, and compromise development data or support platforms.
| Product | Fixed Version |
|---|---|
| Bamboo | 12.1.3, 10.2.16, 9.6.24 |
| Bitbucket | 10.2.1, 10.1.5, 9.4.18 |
| Confluence | 10.2.7, 9.2.17, 9.0.3 |
| Crowd | 7.1.5, 6.3.5 |
| Fisheye/Crucible | 4.9.8 |
| Jira Software | 11.3.3, 10.3.18 |
| Jira Service Management | 11.3.3, 10.3.18 |
CyberShelter continues monitoring exploitation trends associated with these vulnerabilities. Organizations should prioritize patching and monitoring to reduce the risk of exploitation.
CyberShelter Threat Intelligence is monitoring multiple high-severity vulnerabilities recently disclosed affecting widely used enterprise and endpoint technologies including Jenkins, Google ChromeOS, and Apple WebKit platforms.
These vulnerabilities could allow attackers to perform remote code execution (RCE), memory corruption attacks, DNS rebinding, and cross-origin policy bypass. Organizations using affected systems should prioritize patching immediately as exploitation of these flaws could lead to system compromise and data exposure.
| Vendor | Product | Risk | Impact |
|---|---|---|---|
| Jenkins | Core & LoadNinja Plugin | HIGH | RCE & credential exposure |
| ChromeOS | HIGH | Memory corruption | |
| Apple | WebKit | HIGH | Cross-origin bypass |
Jenkins has released patches addressing multiple vulnerabilities affecting Jenkins Core and LoadNinja plugin environments. These issues could allow attackers to execute malicious code or expose sensitive credentials.
| CVE | Issue | Severity |
|---|---|---|
| CVE-2026-33001 | Arbitrary file creation (Archive extraction abuse) | HIGH |
| CVE-2026-33002 | DNS rebinding CLI abuse (Origin validation bypass) | HIGH |
| CVE-2026-33003 | Plaintext API storage (Credential theft) | MEDIUM |
| CVE-2026-33004 | API masking weakness (Pipeline compromise) | MEDIUM |
Multiple ChromeOS vulnerabilities affecting core browser components including Skia and the V8 JavaScript engine. Successful exploitation could allow attackers to execute arbitrary code or escape the sandbox.
| CVE | Component | Severity |
|---|---|---|
| CVE-2026-3909 | Skia Graphics Engine (Out-of-bounds write) | HIGH |
| CVE-2026-3910 | V8 JavaScript Engine (Improper implementation) | HIGH |
Fixed Version: ChromeOS LTS 144.0.7559.246 (Platform 16503.78.0)
A high-severity WebKit vulnerability (CVSS 8.8) affecting Apple devices allowing malicious websites to bypass browser security protections via the Navigation API.
Affected: iOS/iPadOS/macOS 26.3.1 and 26.3.2. Secure versions end with (a), such as 26.3.1 (a).
CyberShelter recommends the following immediate actions across the infrastructure:
| Detection Area | Reason |
|---|---|
| Jenkins file creation | Possible archive extraction exploitation |
| CLI access anomalies | DNS rebinding risk indicators |
| API key exposure | Credential compromise monitoring |
| Browser crashes | Potential memory exploit attempts |
| Suspicious web sessions | WebKit cross-origin exploitation |
For organizations requiring immediate assistance, CyberShelter NSOC provides comprehensive support services:
CyberShelter Threat Intelligence has identified two critical security developments that require immediate attention from security teams and infrastructure administrators.
Both vulnerabilities allow attackers to gain root-level access and could result in full infrastructure compromise if left unmitigated. CyberShelter assesses organizations running exposed Telnet services or Cisco FMC infrastructure as HIGH RISK until remediation actions are completed.
| CVE | Product | Severity | Risk |
|---|---|---|---|
| CVE-2026-32746 | GNU InetUtils Telnetd | 9.8 | Unauthenticated RCE |
| CVE-2026-24061 | GNU InetUtils Telnetd | 9.8 | Root access exploit |
| CVE-2026-20131 | Cisco Secure FMC | 10.0 | Zero-day exploitation |
A critical buffer overflow vulnerability has been discovered in the GNU InetUtils Telnet daemon affecting all versions up to version 2.7. The vulnerability exists due to an out-of-bounds memory write in the LINEMODE SLC handler. This flaw occurs during Telnet option negotiation before authentication.
The vulnerability can be exploited without user interaction:
Amazon Threat Intelligence has identified active exploitation of Cisco FMC software by the Interlock ransomware group. This vulnerability involves insecure deserialization of Java byte streams.
| Date | Event |
|---|---|
| Jan 26 2026 | Zero-day exploitation begins |
| Feb 2026 | Cisco disclosure |
| March 2026 | Active ransomware deployment |
Attackers had a significant head start before public disclosure.
CyberShelter analysis shows the attack follows a multi-stage intrusion model:
| Stage | Activity |
|---|---|
| Initial access | Exploit Cisco vulnerability |
| Execution | Java code execution |
| Validation | HTTP callback to attacker server |
| Payload delivery | ELF malware download |
| Persistence | RAT deployment |
| Lateral movement | Recon scripts |
| Defense evasion | Log deletion |
| C2 control | Beacon communication |
Attackers deployed PowerShell scripts to gather OS details, hardware info, installed software, running services, network connections, browser artifacts, RDP logs, and user files.
Attackers used Linux proxy scripts to deploy HAProxy, configure reverse proxy, launder traffic origin, and hide attacker IP. Observed evasion techniques include log deletion cron jobs, shell history removal, memory resident web shells, encrypted command execution, and network beacon validation.
| Tool | Purpose |
|---|---|
| ConnectWise ScreenConnect | Remote persistence |
| Volatility Framework | Memory analysis |
| Custom web shells | Command execution |
| Network beacon | Access validation |
| Detection | Reason |
|---|---|
| Root process execution | Exploit detection |
| Unexpected HTTP PUT | Attack validation |
| Log deletion | Defense evasion |
| New remote tools | Persistence |
| Network beacons | C2 activity |
Google research indicates ransomware groups are evolving tactics:
CyberShelter recommends the following immediate actions:
Organizations must assume exploitation attempts are ongoing and act immediately to reduce exposure. CyberShelter continues to actively monitor exploitation trends related to these vulnerabilities.
CyberShelter Threat Intelligence has observed an increase in destructive cyberattacks involving wiper malware, a class of malware designed to permanently destroy data and disrupt business operations. Unlike ransomware, wipers focus on irreversible damage rather than financial gain.
Recent threat actor campaigns show increasing use of supply chain compromise, credential abuse, living-off-the-land techniques, and backup destruction tactics. Organizations must prioritize cyber resilience and rapid recovery capabilities alongside prevention.
Wiper malware is a destructive cyber weapon used to delete critical files, corrupt operating systems, destroy Master Boot Records (MBR), delete shadow copies and backups, and disable security tools. Impact often includes complete operational shutdown, massive data loss, significant incident recovery costs, and reputational damage.
| Stage | Techniques Observed |
|---|---|
| 1. Initial Compromise | Phishing, vulnerability exploitation, stolen credentials |
| 2. Privilege Escalation | Domain admin compromise, credential dumping |
| 3. Lateral Movement | SMB spread, remote execution tools (PsExec/WMI) |
| 4. Defense Evasion | EDR disabling, log deletion, backup targeting |
| 5. Destructive Execution | Disk wiping, file corruption, system crash triggering |
| 6. Covering Tracks | Log wiping, system reboot loops |
Destructive attacks such as wiper malware are increasing and organizations must shift from prevention-only strategies to resilience-focused security models combining detection, response, and recovery readiness.
CyberShelter's Threat Intelligence team has recently identified a set of suspicious Indicators of Compromise (IOCs) associated with potentially malicious infrastructure hosted on cloud platforms. The activity suggests possible malware staging, payload delivery, or command-and-control (C2) preparation leveraging trusted cloud services to evade traditional security controls.
During ongoing threat monitoring activities, suspicious domains and URLs were identified within Microsoft Azure environments. Attackers increasingly abuse reputable cloud providers to blend malicious traffic with legitimate enterprise traffic.
| Hash Value |
|---|
| 4130fab30cdd66f742d319b3d2473a47a64a808fcfc6d05e453451c8641e2f6d |
| 59952e885152a9638bae1478ef3d2af5e9823fb204d1068143437827eb607c4a |
| 40afa28bcc5b3676b1891ac4d05bb4f49dc2268892cbbfa5da7fe3d09e2419f6 |
| b0a1d466e61680388146a611687fa4fb339835a7d9752b8a0b4b260d5fb4f834 |
MD5 Hashes: 3ba1d4b92b0392ba2018d1d73cb2bc26, 5bd441cb2d1676498506bf006c7942de, 5b432e0db260b6cddf026013353ea21a, 64f5611cc62e65748d140e6f288ce1ea
Based on initial analysis, the infrastructure shows characteristics commonly associated with malware delivery, living-off-trusted-cloud techniques, and data exfiltration (upload path observed).
This investigation remains ongoing. Organizations should treat these indicators as high-confidence suspicious infrastructure until proven otherwise and take proactive preventive action.
Void Manticore (Handala) represents one of the most dangerous active Iran-linked destructive cyber actors currently targeting the UAE. Their ability to combine wiper attacks, influence operations, and infrastructure disruption makes them a significant strategic threat.
| Date | Activity |
|---|---|
| Dec 2023 | Initial emergence |
| Feb to Apr 2024 | Underground forum expansion |
| Jun 2024 | First hybrid psychological operations |
| Aug 2024 | Platform migration after bans |
| Sep to Nov 2024 | Supply chain targeting |
| Dec 2025 | Operation Octopus |
| Jan 2026 | Civil infrastructure targeting |
| Feb to Mar 2026 | GCC escalation |
The Stryker Global Wiper Attack demonstrates advanced destructive capability and the use of enterprise management tools as attack vectors.
| Category | Impact |
|---|---|
| Devices wiped | 200,000+ |
| Countries impacted | 79 |
| Workforce impact | 5,000 employees displaced |
| Attack vector | Microsoft Intune |
| Data stolen | 50 TB claimed |
| MITRE ID | Technique |
|---|---|
| T1110 | VPN brute force |
| T1078 | Valid account abuse |
| T1195 | Supply chain compromise |
| T1566 | Spear phishing |
Observed behaviors: Mass VPN authentication attempts, MSP compromise attempts, security vendor impersonation, and wiper delivery via phishing.
| MITRE ID | Technique |
|---|---|
| T1059 | PowerShell execution |
| T1047 | WMIC remote execution |
| T1053 | Scheduled task deployment |
| T1562 | Security disabling |
2026 Developments: AI-assisted PowerShell wipers, GPO distribution of destructive payloads, and Windows Defender disabling prior to attacks.
During destructive operations the actor deploys multiple wiping techniques simultaneously.
| Indicator | Type | Context / Description |
|---|---|---|
| 107.189.19[.]52 | IP | C2 server |
| 146.185.219[.]235 | IP | VPN node |
| Starlink IP ranges | Network | C2 routing |
| handala.exe | Executable | Main wiper |
| dra.ps1 | PowerShell | AD reconnaissance (ADRecon) |
| NetBird client | Tool | Lateral movement (Zero trust tunneling) |
| handala-hack[.]to | Domain | Leak site |
Behavioural Indicators: Monitor for VPN login failures, ADRecon execution, GPO script deployment, LSASS dumping, and Defender disabling.
CyberShelter Threat Intelligence has observed a significant escalation in hacktivist cyber activity across the Middle East between March 7 and March 12 2026. Threat actor activity evolved rapidly from disruptive operations such as Distributed Denial-of-Service (DDoS) attacks and website defacements into more serious incidents including destructive attacks, data breaches, and supply-chain disruption campaigns.
A key development during this period was the Stryker Corporation incident, which demonstrated a new willingness among Iran-aligned actors to conduct large-scale destructive attacks against global commercial supply chains.
| Threat Trend | Description |
|---|---|
| Escalation pattern | Shift from DDoS to destructive attacks |
| Supply chain targeting | Healthcare and financial infrastructure targeted |
| Hacktivist alliances | Russia-Iran collaboration emerging |
| Data extortion | Increased leak and doxxing operations |
| Persistent DDoS | Multi-day coordinated attacks |
The timeline indicates attackers are progressing from visibility-focused attacks to operations intended to cause operational damage.
These events demonstrate a widening cyber conflict impacting multiple regions simultaneously.
| Date | Actor | Activity | Target |
|---|---|---|---|
| March 7 | Russian Legion | ICS compromise claims | Israeli critical infrastructure |
| March 7 | Handala | Server wipe & data breach | Israeli religious organization |
| March 7 | NoName057(16) | ICS claims & DDoS | Israel and Cyprus |
| March 8 | cKure | Data breach | Israeli education sector |
| March 8 | Keymous+ | Government DDoS | GCC countries |
| March 8 | Cyber Islamic Resistance | Defacement | Israeli infrastructure |
| March 8 | 404 Crew | Data leaks | Israeli military |
| March 9 | Keymous+ | Energy DDoS | UAE, Bahrain, Oman |
| March 9 | Handala | Surveillance breach | Israeli systems |
| March 9 | DieNet | Government disruption | Qatar |
| March 10 | Conquerors Electronic Army | Financial DDoS | Israeli financial sector |
| March 10 | NoName057 | Infrastructure DDoS | Israeli telecom/water |
| March 11 | Handala | MDM wiper attack | Global supply chain |
| March 11 | Handala | Payment infrastructure breach | Verifone |
| March 11 | 313 Team | State DDoS | Kuwait, UAE |
| March 12 | CVDEAD | Data breach | Saudi Aramco |
| March 12 | KillSec | Ransomware | Insurance sector |
| March 12 | Hanzalah | Military doxxing | Israeli Air Force |
| March 12 | Keymous | Target expansion | Syrian ministries |
The most significant event during this reporting period was the destructive attack targeting Stryker Corporation. This attack demonstrates how compromise of device management infrastructure can produce global operational disruption.
| Category | Details |
|---|---|
| Attack vector | Microsoft Intune compromise |
| Devices impacted | 200,000 claimed |
| Data exfiltration | 50 TB |
| Countries affected | 79 |
| Business impact | Global network shutdown |
| Sector impact | Healthcare supply chain |
These groups represent a mix of ideological hacktivists and criminal operators.
| Group | Origin | Activity |
|---|---|---|
| Handala | Iran-linked | Wipers and data breaches |
| Keymous+ | Pro-Palestinian | DDoS campaigns |
| NoName057(16) | Russian | Persistent DDoS |
| DieNet | Iran-aligned | Government targeting |
| Cyber Islamic Resistance | Iran-aligned | Infrastructure attacks |
| 313 Team | Iran-aligned | Government DDoS |
| CVDEAD | Unknown | Data breach claims |
| KillSec | Ransomware | Data extortion |
| Hanzalah | Hacktivist | Military doxxing |
| Russian Legion | Russia-aligned | ICS targeting claims |
Energy and government sectors remain the most targeted in the Gulf region.
| Country | Target Sector |
|---|---|
| UAE | Energy and government |
| Kuwait | Military and civil systems |
| Bahrain | Government infrastructure |
| Qatar | eGovernment services |
| Oman | Energy infrastructure |
Hacktivists increasingly use data leaks to amplify psychological pressure. These incidents illustrate how data exposure is used to amplify geopolitical messaging.
| Organization | Country | Actor | Impact |
|---|---|---|---|
| Saudi Aramco | Saudi Arabia | CVDEAD | Workforce data leak |
| Verifone | Israel | Handala | Financial transaction data |
| Shlomo Insurance | Israel | KillSec | Customer data exposure |
| Sanz Group | Israel | Handala | 851GB data exfiltration |
| Albanian Parliament | Albania | Homeland Justice | Email disruption |
CyberShelter identified growing coordination among threat groups, demonstrating a more organized hacktivist ecosystem than previously observed.
| Alliance | Purpose |
|---|---|
| Russia-Iran collaboration | Coordinated targeting |
| Anonymous Sana a & WeAreUst | Joint cyber retaliation |
| NoName057 partnerships | Multi-country DDoS |
| Anti-regime Iranian groups | Counter operations |
Threat actors are increasingly targeting supply chains to maximize disruption. Supply chain attacks offer attackers greater geopolitical impact than single-organization attacks.
| Sector | Risk |
|---|---|
| Healthcare | Medical supply disruptions |
| Finance | Payment systems targeting |
| Energy | Infrastructure disruption |
| Government | Administrative disruption |
| Logistics | Regional trade impact |
CyberShelter assesses the current hacktivist environment as: Ideologically driven + geopolitically motivated + operationally evolving.
Hacktivists are evolving toward hybrid operations combining propaganda, disruption, and financial crime. CyberShelter expects continued hacktivist activity driven by geopolitical tensions, with organizations needing to prepare for prolonged cyber pressure rather than isolated incidents.
| Expected Future Activity | Likelihood |
|---|---|
| Sustained DDoS | HIGH |
| Data leaks | HIGH |
| Ransomware activity | HIGH |
| Supply chain attacks | MEDIUM |
| Destructive attacks | MEDIUM |
Organizations should strengthen resilience through network segmentation to reduce lateral movement, OT isolation to protect industrial systems, RBAC enforcement to protect admin systems, and active cloud monitoring to detect compromise.
Detection Priorities: Monitor for MDM administrative changes, DDoS traffic spikes, suspicious data transfers, ransomware staging, and privilege escalation attempts.
Understanding Iran's targeting logic is essential for UAE organisations to accurately assess their own risk profile.
| Target Category | Risk Logic |
|---|---|
| UAE's Role | Hosts US military facilities; F-35 basing and logistics support for Operation Epic Fury; intelligence sharing; US CENTCOM forward presence |
| Abraham Accords | UAE-Israel normalisation (2020) makes UAE a declared target in Iran's political framing; economic, technology, and defense cooperation directly cited in Iranian threat actor manifestos |
| Financial Hub Risk | UAE financial institutions (major financial hubs and banking institutions) process regional transactions; disruption has asymmetric geopolitical impact |
| Energy Sector | UAE oil and gas infrastructure (critical energy production facilities) is a standing target for Iranian ICS/OT-capable groups including CyberAv3ngers and APT33 |
| Aviation Nexus | DieNet specifically targeted UAE airports; Sylhet Gang-SG targeted Abu Dhabi Civil Defense; aviation disruption is a stated Iranian objective |
| Supply Chain Role | UAE's position as a re-export hub and supply chain conduit makes it a second-order target - disrupting UAE logistics impacts Israel and US operations regionally |
| Diaspora Data | APT34/35/39/42 are actively harvesting population-scale data from ISPs, medical systems, and telecoms to identify Iranian regime dissidents - UAE's Iranian diaspora makes local ISPs and telecoms priority targets |
Iran's offensive cyber capability is distributed across two primary state bodies and an extended ecosystem of proxy hacktivist groups. Understanding this structure is critical because the two state bodies have different mandates, TTPs, and escalation patterns.
| Actor | Parent Body | Microsoft Alias | Primary UAE Threat | Current Status |
|---|---|---|---|---|
| MuddyWater / Seedworm | MOIS | Mango Sandstorm | Espionage + pre-positioned access via Operation Olalampo; DinDoor, FakeSet backdoors in UAE orgs; could pivot to wiper | ACTIVE - UAE companies confirmed compromised |
| Void Manticore / Handala Hack | MOIS | Storm-1084 | Wiper attacks (ZeroShred) + hack-and-leak; exploits Microsoft Intune for mass device wipe; expanding beyond Israel to Western/Gulf targets | ACTIVE - Stryker wiped 11 Mar 2026; UAE in stated target scope |
| Agrius / Pink Sandstorm | MOIS | Pink Sandstorm | Wiper + fake-ransomware ops; among earliest Iran actors to target Emirati entities alongside Israeli ones | ACTIVE - IP camera scanning surge in UAE confirmed |
| APT33 / Peach Sandstorm | IRGC-CEC | Peach Sandstorm | UAE energy and comms confirmed targeted 2024 with AeroBlade backdoor; aerospace/defense focus | ELEVATED - pre-positioned access likely; wartime activation expected |
| APT34 / OilRig | IRGC / MOIS | Hazel Sandstorm | UAE energy, telecom, government espionage; web shell deployment; data exfiltration for dissident tracking | ACTIVE - MOIS intel collection ongoing |
| Pioneer Kitten / Fox Kitten | IRGC | Lemon Sandstorm | Confirmed UAE ransomware campaigns; exploits VPN/edge devices; ransomware + espionage hybrid ops | ACTIVE - ongoing in UAE since 2024 |
| CyberAv3ngers | IRGC-CEC | CyberAv3ngers | ICS/OT-focused; water, wastewater, oil-gas systems globally; UAE industrial control systems at risk | ELEVATED - OT attacks documented globally |
| DieNet | Proxy/hacktivist | - | DDoS specialist; UAE airport already targeted; structured Gulf target lists published | ACTIVE - UAE airport DDoS claimed Feb/Mar 2026 |
| Keymous Plus | Proxy/hacktivist | - | Mass DDoS against regional government ministries; #Op_Epstein_Gulf campaign; 50+ verified UAE/Gulf claims | ACTIVE - ongoing campaign |
| Cyber Islamic Resistance (313 Team) | Proxy/Iran-aligned | - | ICS/SCADA targeting; coordinates multiple hacktivist groups; wiper and data destruction focus | ACTIVE - coordinates Electronic Operations Room |
| FAD Team / Fatimiyoun | Proxy/Iran-aligned | - | Wiper malware and permanent data destruction specialist; ICS/SCADA access claims | ACTIVE - ICS/SCADA compromise claims in region |
| Sylhet Gang-SG | Proxy/pro-Iran | - | Targeted regional civil defense authority; government portal DDoS | ACTIVE - UAE attack confirmed Mar 2026 |
The following wiper and destructive malware families are confirmed active in the current Iran conflict, deployed by groups that have either directly targeted UAE or have UAE within their stated or demonstrated targeting scope.
DIRECT UAE RISK: Void Manticore has confirmed targeting of UAE as part of its Gulf operations. The Stryker attack (11 Mar 2026) used Microsoft Intune MDM to wipe 200,000+ devices. Any UAE organisation using a Microsoft Intune-managed device estate with weak administrative account controls is directly at risk from this attack pattern.
| Wiper Name | ZeroShred (Void Manticore / Handala) |
|---|---|
| Attack Method | Spear-phishing ? credential theft ? Microsoft Intune MDM console compromise ? mass remote wipe command to all enrolled devices |
| Delivery Lure | F5UPDATER.exe impersonation; F5 update phishing emails; INCD (National Cyber Directorate) impersonation |
| Paired Tool | Rhadamanthys commercial infostealer (purchased from criminal forums) used to harvest credentials before wiper deployment |
| Companion | GoneXML - fake ransomware deployed alongside ZeroShred to create confusion, delay response, and manufacture plausible deniability |
| MDM Abuse | Microsoft Intune weaponised to issue legitimate remote wipe commands - bypasses traditional EDR/AV because the wipe uses native device management APIs |
| C2 Evasion | Traffic routed via Starlink IP ranges to evade geo-based blocking; maintains C2 despite Iran's 1-4% domestic internet availability |
| AI-Assisted | PowerShell wiping scripts show signs of AI-assisted development; accelerates campaign velocity |
| Geographic Scope | Israel (primary); expanding to US, Gulf States including UAE; any org with Israeli business ties, investment, or partnerships is a stated target |
| BlueWipe | Targets storage devices of Israeli critical infrastructure; wipes/disables storage making recovery impossible |
|---|---|
| SewerGoo | Companion to BlueWipe; same Israeli critical infrastructure campaign; storage destruction focus |
| BeepFreeze | Deployed against Albanian government networks; demonstrates Iran's willingness to use wipers against non-Israeli targets including Gulf-region allies |
| Relevance to UAE | Pattern of geographic expansion mirrors the current conflict escalation; BlueWipe/SewerGoo techniques applicable to any storage infrastructure |
HIGH RISK - UAE REGION: Sicarii has confirmed META (Middle East, Turkey, Africa) regional focus including UAE. The malware destroys its own decryption keys - making any 'ransom' payment pointless. This is effectively a wiper disguised as ransomware.
| Type | RaaS (Ransomware-as-a-Service) with inherent wiper behaviour |
|---|---|
| Encryption Flaw | Discards decryption keys after encrypting - victims permanently lose data regardless of payment |
| Geographic Focus | META region with US entities; UAE confirmed in targeting scope |
| Emergence | December 2025; surging activity since Feb 2026 kinetic escalation |
| Monitoring | Halcyon RRC actively tracking; linked to broader Iran-aligned hacktivist ecosystem |
| Technique | Wiper disguised as ransomware; ransom note displayed but decryption impossible by design |
|---|---|
| Tools Used | DEADWOOD wiper; Apostle (pseudo-ransomware); Fantasy wiper |
| UAE Relevance | Agrius was among the FIRST Iran-linked actors to target Emirati entities alongside Israeli ones; long-standing UAE targeting history |
| Initial Access | Exploits internet-facing web servers; uses commercial Israeli VPN infrastructure as launch point |
| Goal | Maximum psychological impact + data destruction; narrative control via fake ransomware framing |
CONFIRMED UAE TARGETING: Operation Olalampo is an active MuddyWater campaign that has confirmed UAE organisations among its victims. Exposed C2 infrastructure analysis by the Ctrl-Alt-Intel collective identified UAE companies in victim telemetry alongside Israeli, Jordanian, Egyptian, and US entities.
Operation Olalampo represents a significant evolution in MuddyWater's technical capabilities, first observed 26 January 2026 and accelerating post-28 February conflict escalation.
| Stage | Method | Technical Detail |
|---|---|---|
| 1 - Initial Access (Primary) | Spear-phishing with malicious Office docs | Macro-enabled documents; malicious macro decodes embedded payload and drops/executes it. Lure themes: flight tickets, reports, system integrator documents |
| 1 - Initial Access (Secondary) | Public-facing server exploitation | Active exploitation of recently disclosed CVEs on VPN gateways, web servers; represents a departure from historic MuddyWater phishing-only pattern |
| 2 - Stage 1 Payloads | GhostFetch downloader OR HTTP_VIP downloader | GhostFetch: profiles system, validates mouse movement, checks for AV/VM/debugger before memory-only payload execution. HTTP_VIP: connects to codefusiontech[.]org C2, deploys AnyDesk RMM |
| 3 - Stage 2 Payloads | GhostBackDoor OR CHAR Rust backdoor | GhostBackDoor: advanced persistence, adapts installation based on privilege level; interactive shell + file ops. CHAR: Rust-based, uses Telegram bot (username: stager_51_bot) as C2 - cmd.exe and PowerShell execution |
| 4 - Lateral Movement | AnyDesk RMM / SOCKS5 reverse proxy | Legitimate RMM tooling for hands-on access; SOCKS5 proxy (Kalim) for network tunnelling; Rclone to exfiltrate to Wasabi cloud storage |
| 5 - Exfiltration | Rclone to Wasabi cloud storage | Victim data exfiltrated to cloud storage bucket; confirmed attempted at defence-sector orgs |
| 6 - Potential D-Stage | Pre-positioned for pivot to wiper | Historical pattern: Shamoon, ZeroCleare, BibiWiper all leveraged prior espionage access. Symantec warned MuddyWater pre-positioning is 'potentially dangerous' given conflict context |
| Malware | Type | Language | Key Technical Detail |
|---|---|---|---|
| CHAR | Backdoor | Rust | Telegram bot C2 (bot name: 'Olalampo', username: 'stager_51_bot'); executes cmd.exe / PowerShell; debug strings with emojis consistent with AI-assisted development |
| GhostFetch | Downloader | N/A | Memory-only payload execution; anti-sandbox: validates mouse movement, screen resolution, checks for debugger/VM/AV before proceeding |
| GhostBackDoor | Backdoor | N/A | Second-stage implant from GhostFetch; interactive shell; file read/write; re-runs GhostFetch for modularity |
| HTTP_VIP | Downloader | Native | C2: codefusiontech[.]org; authenticates then deploys AnyDesk; newer variant adds interactive shell, clipboard capture, configurable beacon interval |
| DinDoor | Backdoor | JavaScript/Deno | Uses Deno runtime (BYOR evasion); digitally signed - cert issued to 'Amy Cherne'; linked to MuddyWater via Tsundere Botnet infrastructure overlap |
| FakeSet | Backdoor | Python | Downloaded from Backblaze servers; signing cert shared with Stagecomp and Darkcomp (confirmed MuddyWater tools); Rclone exfil to Wasabi |
INGEST PRIORITY: All IOCs below are from the current 2026 conflict and directly-linked 2025-2026 campaigns. Ingest immediately into SIEM, EDR, firewall, DNS blocklists, and proxy policies. Hash-based IOCs should be supplemented with behavioural detections - Iran-linked actors regularly recompile payloads.
| Indicator | Type | Malware / Context |
|---|---|---|
| codefusiontech[.]org | Domain/C2 | HTTP_VIP C2 server - authentication + AnyDesk deployment |
| 18.223.24[.]218 | IP/C2 | MuddyWater infrastructure - attributed via Tsundere/DinDoor ops (AWS US-East) |
| 31.172.71[.]5:8008 | IP:Port/Proxy | Sandworm SOCKS5 reverse connect C2 (rsocx) - DynoWiper prep (compromised Russian host) |
| stager_51_bot | Telegram username | CHAR Rust backdoor Telegram C2 - bot first name 'Olalampo' |
| Olalampo | Telegram bot name | CHAR Rust backdoor C2 bot name - monitor Telegram API calls to this identifier |
| handala-hack[.]to | Domain | Void Manticore / Handala Hack primary blog and operations domain |
| handala-redwanted[.]to | Domain | Void Manticore / Handala target listing domain |
| Hash | Algorithm | File / Component | Source |
|---|---|---|---|
| 62ED16701A14CE26314F2436D9532FE606C15407 | SHA-1 | FMAPP.dll - Reverse SOCKS5 proxy (MuddyWater infra) | Group-IB Olalampo |
| 02ccc4271362b92a59e6851ac6d5d2c07182064a602906d7166fe2867cc662a5 | SHA-256 | Malicious Office macro - Olalampo delivery doc | Group-IB Olalampo |
| eb5e96e05129e5691f9677be4e396c88 | MD5 | MuddyWater IP 18.223.24.218 attributed sample | Ctrl-Alt-Intel / Symantec |
PATCH IMMEDIATELY: These CVEs are being actively weaponised by Agrius, Handala/Void Manticore, and Iran-nexus actors against targets in UAE, Israel, and Gulf states RIGHT NOW. Scan for and patch these within 24-48 hours.
| CVE | Product | Type | CVSS | Exploited By / Context |
|---|---|---|---|---|
| CVE-2017-7921 | Hikvision IP Cameras | Auth bypass | 9.8 | Agrius, Handala - surge in UAE/Gulf camera scanning confirmed; authentication completely bypassed |
| CVE-2021-36260 | Hikvision IP Cameras | Remote Code Exec | 9.8 | Iran nexus actors - full RCE; camera used for battle damage assessment and OT reconnaissance |
| CVE-2023-6895 | Hikvision Cameras | Auth bypass | 7.5 | Agrius, Iran-nexus - active exploitation in UAE/Gulf surge post-Feb 28 2026 |
| CVE-2025-34067 | Hikvision Cameras | Auth / RCE | TBD | Newly disclosed 2025; Iran actors already weaponising in UAE/Gulf region - patch urgently |
| CVE-2021-33044 | Dahua IP Cameras | Auth bypass | 9.8 | Iran nexus - Dahua cameras targeted alongside Hikvision in UAE/Gulf sweep |
| CVE-2023-38831 | WinRAR | Arbitrary code exec | 7.8 | Sandworm (drone school phishing); broader Iran actor usage in phishing campaigns |
| Artifact / Pattern | Context |
|---|---|
| F5UPDATER.exe (filename) | Handala/Void Manticore phishing lure - fake F5 update installer delivering Rhadamanthys + ZeroShred wiper |
| uacinstall.vbs | PathWiper VBScript dropper - dropped via BAT file, writes wiper as sha256sum.exe |
| sha256sum.exe (misused name) | PathWiper executable disguised as legitimate checksum tool |
| fsutil.exe setzerodataoffset | ZEROLOT (Sandworm) LotL file zeroing - monitor this command execution |
| gshdoc_release_X64_GUI.exe | MuddyWater Olalampo campaign - dropped by CHAR/related tools |
| sh.exe (generic dropped) | MuddyWater dropped shell utility - referenced in Olalampo C2 command logs |
| .log drop in %PUBLIC% or %USERPROFILE%\Downloads | MuddyWater Olalampo staging path - payloads dropped as .log files to avoid detection |
| Rclone + Wasabi S3 endpoint | MuddyWater exfiltration pattern - Rclone binary + outbound connection to Wasabi cloud storage |
| Deno runtime (deno.exe) | DinDoor BYOR evasion - Deno installed and used to execute JavaScript backdoor; unusual in enterprise environments |
| AnyDesk installed via HTTP_VIP C2 | MuddyWater post-compromise - AnyDesk deployed as legitimate RMM tool for persistent access |
UAE SIEM PRIORITY: Any UAE organisation using Microsoft Intune for MDM should treat the following as critical alerting conditions immediately. This is the exact attack chain used to wipe Stryker's global infrastructure on 11 March 2026.
| Indicator / Log Pattern | Type | Significance |
|---|---|---|
| Intune admin login from unexpected geolocation or IP | Identity / Sign-in log | Compromised Intune admin credentials - first step of Stryker attack chain |
| Mass device action: 'Wipe' or 'Factory Reset' from Intune portal | Intune audit log | CRITICAL - direct wiper deployment via MDM; single Intune admin account can wipe entire device fleet |
| Global MFA bypass or legacy auth to Intune/Entra | Entra ID sign-in log | Handala exploits MFA gaps; review conditional access policy coverage for Intune admin roles |
| New Eligible/Active Intune Administrator role assignment | Entra PIM audit log | Privilege escalation to Intune admin - precursor to mass wipe capability |
| Entra ID admin login from Starlink IP range | Sign-in log / IP | Handala confirmed routing ops through Starlink satellite IP blocks (post-Iran internet blackout) |
TTPs consolidated from confirmed 2025-2026 Iranian wiper and destructive malware campaigns targeting UAE and Gulf states.
| ATT&CK ID | Technique | Iran Actor(s) Using It | Detection Focus |
|---|---|---|---|
| T1485 | Data Destruction - Wiper | Void Manticore, Agrius, Sandworm, FAD Team | Mass file overwrite; ZeroShred patterns; raw disk IOCTL calls |
| T1561.001 | Disk Content Wipe | Void Manticore, Agrius, Sandworm, PathWiper | Process accessing \\.\PhysicalDrive0; NTFS artifact destruction |
| T1561.002 | Disk Structure Wipe (MBR) | Handala, Agrius, Sandworm (ZEROLOT) | IOCTL_DISK_DELETE_DRIVE_LAYOUT; MBR write by non-system process |
| T1490 | Inhibit System Recovery | All wiper families | VSS deletion commands; BCDEdit recovery disabled; crash dump disabled |
| T1486 | Data Encrypted for Impact (pseudo-ransomware) | Agrius, Void Manticore (GoneXML) | Ransom note + encrypted files but no valid decryption path |
| T1059.001 | PowerShell Execution | MuddyWater, Void Manticore | AI-assisted PS scripts for wiping; encoded command strings |
| T1059.005 | VBScript | PathWiper (uacinstall.vbs), MuddyWater | VBS dropping executables disguised as legitimate tools |
| T1072 | Software Deployment Tools (MDM) | Void Manticore / Handala | Microsoft Intune wipe commands - the primary Stryker attack vector |
| T1219 | Remote Access Tools (RMM) | MuddyWater (AnyDesk via HTTP_VIP) | AnyDesk installed outside approved software inventory |
| T1090.002 | External Proxy / SOCKS5 | MuddyWater (Kalim), Sandworm (rsocx) | SOCKS5 proxy on non-standard ports; Rclone to cloud storage |
| T1566.001 | Spear-phishing Attachment (Office macros) | MuddyWater (primary vector) | Macro-enabled Office docs from external senders; .xlsm, .docm |
| T1190 | Exploit Public-Facing Application | MuddyWater (Olalampo), Pioneer Kitten | VPN appliance CVEs; camera CVEs; web server exploitation |
| T1078 | Valid Accounts (credential theft) | Void Manticore, MuddyWater, Pioneer Kitten | Rhadamanthys infostealer harvesting creds pre-wiper deployment |
| T1553.002 | Code Signing (cert abuse) | MuddyWater (DinDoor: 'Amy Cherne' cert) | Monitor unsigned or newly-signed executables; alert on Deno execution |
| T1041 / T1567 | Exfiltration (C2 / cloud storage) | MuddyWater (Wasabi S3), Handala (50TB claimed) | Rclone to cloud buckets; large-volume outbound transfers |
| T1205 | Traffic Signalling / Magic Packet | APT33 J-magic (VPN targeting) | eBPF filters on Juniper/VPN appliances; passive backdoor pattern |
| T1496 | Resource Hijacking (Ethereum C2) | MuddyWater (EtherHiding) | DNS/HTTP requests to Ethereum RPC endpoints from endpoints |
The following detection logic is prioritised specifically for the Iranian threat actors confirmed to be targeting UAE. Implement in priority order.
Entra Sign-In | AppDisplayName = 'Microsoft Intune' | Location NOT IN [approved UAE office IP ranges] | MFA NOT completed / legacy auth
Intune Audit Log | ActivityType IN ['Wipe', 'RetireDevice', 'FactoryReset'] | InitiatedBy NOT IN [approved admin list] | Scope: >5 devices in 10 minutes
Entra PIM Audit | Operation = 'Add member to role' | Role = 'Intune Administrator' OR 'Global Administrator' | Approved change window = FALSE
DNS Query | Domain = 'codefusiontech[.]org' - MuddyWater HTTP_VIP C2
Process Create (Sysmon EID 1) | Image = 'deno.exe' | ParentImage NOT IN [approved dev tools] - DinDoor BYOR evasion
Process Create | Image = 'rclone.exe' | CommandLine contains 'wasabi' OR 'backblaze' - exfiltration pattern
File Create | TargetFilename matches '%PUBLIC%\*.log' OR '%USERPROFILE%\Downloads\*.log' | Image NOT IN [known logging apps]
Office macro execution | WINWORD.EXE or EXCEL.EXE spawns PowerShell, cmd.exe, wscript.exe, or drops .exe to Downloads/Public
Telegram API call (outbound) | Process NOT IN [approved Telegram clients] | Specifically: bot API calls referencing 'stager_51_bot'
Process Create | Image = 'fsutil.exe' | CommandLine contains 'setzerodataoffset'
Raw Disk Access (Sysmon EID 9) | Device contains '\\.\PhysicalDrive' | Image NOT IN ['diskpart.exe','format.com','chkdsk.exe','dfrgui.exe']
Process Create | CommandLine matches 'vssadmin * delete *' OR 'wmic shadowcopy delete' OR 'bcdedit * recoveryenabled no'
File Create | TargetFilename = 'F5UPDATER.exe' OR contains 'sha256sum.exe' dropped by wscript.exe/cmd.exe
Web/firewall log | Requests to IP camera management interfaces | URL patterns: /onvif/device_service, /cgi-bin/snapshot.cgi, /SDK/sessionid | Source IP NOT IN [approved management subnets]
NetFlow/proxy | Camera devices making outbound connections to non-authorised IPs | Especially: port 80/443/8080 to non-manufacturer IPs
Based on confirmed MuddyWater UAE compromises and the Olalampo campaign C2 infrastructure exposure, the following hunting queries should be run immediately on your UAE client environments:
| Hunt ID | Query Description | Why / Relevance |
|---|---|---|
| H-001 | Search EDR telemetry for any process making outbound connections to codefusiontech[.]org or 18.223.24[.]218 | Confirmed MuddyWater Olalampo C2 - any hit confirms active infection |
| H-002 | Look for deno.exe execution in your environment - especially spawned by Office or dropped in temp directories | DinDoor BYOR backdoor; Deno is unusual in enterprise environments outside dev workstations |
| H-003 | Search for rclone.exe usage with cloud storage destination arguments (wasabi, backblaze) on non-sanctioned endpoints | MuddyWater exfiltration pattern - if found, treat as active data breach |
| H-004 | Query Intune audit logs for any bulk device actions (wipe, retire, reset) in the past 90 days - baseline normal | Establish legitimate wipe activity baseline BEFORE an attack occurs; anomalies will be detectable only against this baseline |
| H-005 | Search for Office processes spawning PowerShell with Base64-encoded commands or -enc flag in past 30 days | Olalampo macro delivery pattern; may reveal existing undetected compromises |
| H-006 | Search DNS logs for queries to Telegram API endpoints (api.telegram.org) from server-class machines or unexpected endpoints | CHAR Rust backdoor C2; servers have no legitimate reason to query Telegram API |
| H-007 | Identify any Hikvision or Dahua cameras in UAE client networks; verify firmware versions against CVE-2017-7921, CVE-2021-36260, CVE-2025-34067 | Confirmed active exploitation in UAE/Gulf region right now - any unpatched camera is a potential foothold |
| H-008 | Search for AnyDesk installed via command line or dropped to non-standard paths (not Program Files) | MuddyWater HTTP_VIP drops AnyDesk to take over systems; distinguishable from legitimate AnyDesk by install path and parent process |
| H-009 | Hunt for Rhadamanthys infostealer IOCs in email gateway / proxy logs - look for F5 update lure emails | Void Manticore / Handala pre-wiper credential harvesting; if Rhadamanthys found, wiper deployment may follow |
| H-010 | Query firewall/proxy for outbound connections to Ethereum RPC endpoints (infura.io, mainnet.infura.io, etherscan.io) from non-crypto endpoints | MuddyWater EtherHiding C2 - blockchain-based C2 resolution to resist takedown; extremely unusual for business endpoints |
Actions are ordered by urgency based on confirmed attack vectors used in the current conflict. Complete P1 within 24 hours, P2 within 72 hours, P3 within 7 days.
If you detect wiper-related activity in a UAE client environment, execute in this order:
| Time | Action | Owner |
|---|---|---|
| T+0 | ISOLATE: Immediately network-isolate all affected endpoints. For Intune-compromised environments: block all admin accounts from Intune portal, revoke active sessions in Entra ID. | SOC/IR Lead |
| T+5 min | PRESERVE: Capture memory images (if accessible) of unaffected domain controllers and key servers before wiper propagates further. Forensics window closes fast. | DFIR Team |
| T+10 min | ACTIVATE OFFLINE BACKUP: Contact backup team to initiate recovery from most recent offline/air-gapped backup. Do NOT attempt to restore from network-accessible backups - these may be wiped. | IT / Backup Team |
| T+15 min | NOTIFY: Alert UAE-CERT ([email protected]), relevant sector ISAC, and legal/privacy counsel. SEC/DPO notification may be required if personal data was exfiltrated. | Legal / CISO |
| T+30 min | ASSESS SCOPE: Identify blast radius - how many devices affected, what data was accessible, were backups hit? Separate IT recovery from forensic investigation. | IR + IT |
| T+1 hour | COMMS: Prepare internal and external communications. Handala will likely publish a blog post claiming the attack - get ahead of the narrative. Stryker had no public comms ready. | Comms / Legal |
| T+24 hours | REVIEW ACCESS PATH: For Intune-based wipe: determine how admin credentials were obtained. Rhadamanthys infostealer is the suspected primary credential theft vector - check email/proxy for F5 update phishing indicators. | DFIR |
| T+72 hours | REBUILD: Begin clean OS rebuild from known-good images. Do NOT restore from potentially-compromised backup sets until forensically cleared. | IT |
Consolidated intelligence dataset containing Indicators of Compromise associated with multiple advanced threat actors and ransomware groups.
CyberShelter Threat Intelligence has analyzed a consolidated intelligence dataset containing Indicators of Compromise (IOCs) associated with multiple advanced threat actors (Turla, APT29, Sandworm, Lazarus) and ransomware groups (Conti, Black Basta, HermeticWiper operators).
The dataset confirms continued use of PowerShell loaders, spearphishing attachments, cloud-based C2 channels, ICS destructive malware, and ransomware deployment frameworks. These threats demonstrate continued convergence between espionage actors and financially motivated cybercriminal groups.
| Threat Actor | Country | Type | Primary Capability |
|---|---|---|---|
| Turla | Russia | APT | Espionage |
| APT29 | Russia | APT | Government espionage |
| Sandworm | Russia | APT | ICS attacks |
| Lazarus | North Korea | APT | Financial espionage |
| Conti | Criminal | Ransomware | Data encryption |
| Black Basta | Criminal | Ransomware | Double extortion |
| HermeticWiper | Russia-aligned | Destructive | Data destruction |
Turla continues to rely heavily on PowerShell-based loaders and RPC backdoors. Observed artifacts include specialized loaders, backdoors, and exfiltration plugins.
| SHA1 | Description |
|---|---|
| 50c0bf9479efc93fa9cf1aa99bdca923273b71a1 | PowerShell loader |
| ec54ef8d79bf30b63c5249af7a8a3c652595b923 | RPC backdoor client |
| 9cdf6d5878fc3aecf10761fd72371a2877f270d0 | RPC backdoor server |
| d3df3f32716042404798e3e9d691aced2f78bdd5 | File exfiltration plugin |
| 9d1c563e5228b2572f5ca14f0ec33ca0deda3d57 | RPC installer |
| b948e25d061039d64115cfde74d2ff4372e83765 | Malware component |
APT29 continues using Duke malware families for espionage operations. The observed families range from lightweight loaders to advanced backdoors.
| Malware | Function |
|---|---|
| PolyglotDuke | Loader |
| RegDuke | Persistence |
| MiniDuke | Backdoor |
| FatDuke | Advanced backdoor |
| LiteDuke | Lightweight implant |
| acciaio.com.br | ceycarb.com | coachandcook.at |
| fisioterapiabb.it | lorriratzlaff.com | mavin21c.dothome.co.kr |
| motherlodebulldogclub.com | powerpolymerindustry.com | publiccouncil.org |
| ecolesndmessines.org | salesappliances.com | skagenyoga.com |
| b52c0640957e5032b5160578f8cb99f9b066fde4f9431ee6869b2eea67338f28 |
| e54f38d06a4f11e1b92bb7454e70c949d3e1a4db83894db1ab76e9d64146ee06 |
| eb79168391e64160883b1b3839ed4045b4fd40da14d6eec5a93cfa9365503586 |
Designed for mass system destruction, HermeticWiper abuses drivers and exploits GPOs to disable crash dumps and wipe disks.
| Feature | Description |
|---|---|
| Driver abuse | EaseUS Partition driver |
| Deployment | GPO abuse |
| Registry | Crash dump disable |
| Target | Critical infrastructure |
| i.ua-passport.space | id.bigmir.space | kfctm.online |
| my.cloud-file.online | my.mondeychamp.xyz | files-download.infousa.xyz |
Specialized tool for ICS disruption. Significant for its ability to directly interact with industrial equipment.
| CVE | Type |
|---|---|
| CVE-2022-30190 | Follina MS Diagnostic Tool |
| CVE-2021-42278 / 42287 | Active Directory Elevation |
| CVE-2021-34527 | PrintNightmare |
| CVE-2020-1472 | ZeroLogon |
Infrastructure indicators include 45.67.229.148 (C2 IP) and jardinoks.com (C2 Domain).
| SHA1 Hash | Malware / Tool |
|---|---|
| b2b36600ce41129fa85a15a7177a61b7cb714000 | Mimikatz |
| 407b934895741a1d3b197e4e3c3d2e3284ebc76a | Bind shell |
| cbf1529bf025523532666b0b3d2adbdae657db16 | Cobalt Strike |
Associated Network IPs: 104.225.129.86, 104.225.129.103, 15.207.207.64.
Strategic analysis of unified cyber-kinetic operations and infrastructure sabotage during the 2026 escalation window.
Between February 28 and March 5, 2026, global cyber activity entered a new phase of hybrid warfare. Cyber actors linked to Iran conducted large-scale operations across energy, government, and telecommunications sectors in parallel with kinetic strikes.
Over 900 kinetic strikes were recorded within the first 12 hours of escalation, while Iran simultaneously experienced near-total internet disruption (connectivity dropping to 1-4%).
Despite domestic blackouts, offensive operations continued using pre-positioned global infrastructure.
| Date | Event |
|---|---|
| Early Feb 2026 | Reconnaissance targeting Gulf and Israeli government APIs |
| Feb 26, 2026 | Threat actors finalize staging of cyber infrastructure |
| Feb 28, 2026 | Large-scale kinetic operations begin alongside cyber campaigns |
| Mar 2, 2026 | Attacks expand to media, communications, and military infrastructure |
| Mar 4-5, 2026 | Infrastructure sabotage claims across energy, water, and logistics |
Irans cyber apparatus combines state-sponsored APT groups, contractor networks, and ideologically aligned hacktivists. This multi-layered structure provides operational flexibility and plausible deniability.
| Actor | Agencies | Specialty | Primary Targets |
|---|---|---|---|
| Void Manticore | MOIS | Data theft, wipers | IT services, Energy |
| Static Kitten | MOIS | AI-assisted phishing | Telecom, Defense |
| Cotton Sandstorm | IRGC | Influence ops | Media, Politics |
| CyberAv3ngers | IRGC | ICS/OT Sabotage | Water, Power, Fuel |
Void Manticore operates under MOIS, focusing on rapid, opportunistic operations through compromised IT service providers.
| Attribute | Details |
|---|---|
| Operational Style | Opportunistic and rapid operations |
| Infrastructure | Satellite-based IP networks to bypass domestic outages |
| Recent Target | Israeli energy exploration / Jordan fuel systems |
Technically sophisticated operations utilizing AI-assisted malware development.
| Malware | Function | Key Feature |
|---|---|---|
| GhostFetch | Downloader | Sandbox detection |
| CHAR | Backdoor | Rust-based Telegram C2 |
| HTTP_VIP | Loader | Deploys AnyDesk for remote access |
CyberAv3ngers (IRGC) specifically targeted Unitronics Vision Series PLC devices, compromising at least 75 devices globally.
| Sector | Impact Observed |
|---|---|
| Agriculture | Temperature manipulation in grain silos |
| Energy | Solar inverter shutdowns; 75% output reduction |
| Logistics | Grain weighing system manipulation |
| Module | Capability |
|---|---|
| JumpViewUi.dll | Cookie theft |
| STITP.dll | Screenshots |
| clp.dll | Clipboard monitoring |
Sicarii ransomware generates local RSA keys but permanently deletes the private key, making recovery impossible even after ransom payment.
| CVE | Product | CVSS | Actor |
|---|---|---|---|
| CVE-2026-24858 | FortiOS | 9.4 | Pioneer Kitten |
| CVE-2024-4577 | PHP-CGI | 9.8 | MuddyWater |
| CVE-2018-13379 | Fortinet VPN | 9.8 | APT33/34 |
| Indicator | Type | Associated Actor |
|---|---|---|
| codefusiontech[.]org | C2 Domain | MuddyWater |
| redalerts[.]me | Distribution | RedAlert Mobile Campaign |
| 217.119.139.50 | IP Address | FortiGate Intrusion |
Cyber operations have evolved into a core strategic pillar of modern geopolitical conflict. The Great Convergence demonstrates that state actors now combine sabotage, psychological ops, and kinetic force in a unified doctrine.
Strategic resilience capability is essential to protecting national infrastructure.
Critical advisory covering active Iranian-sponsored cyber campaigns, actor profiles, indicators of compromise, sector risk assessments, and immediate defensive actions for Middle East organisations.
Following the February 28, 2026 geopolitical escalation in the region, CyberShelter assesses the probability of significant Iranian-sponsored cyber operations against Middle East organisations within 24 to 72 hours as VERY HIGH.
Historical precedent demonstrates a consistent pattern: major kinetic actions are followed within hours by coordinated cyber retaliation.
CyberShelter has elevated all SOC customers to Heightened Monitoring Status and initiated proactive threat hunting across enterprise and OT environments.
The most active confirmed Iranian cyber campaign targeting the MENA region is Operation Olalampo, attributed to MuddyWater ← a threat group operating under the direction of Iran's Ministry of Intelligence and Security (MOIS). The campaign employs a sophisticated multi-stage attack chain and has recently expanded to include exploitation of public-facing infrastructure.
| Malware | Role | Key Technical Details |
|---|---|---|
| GhostFetch | Stage-1 Downloader | Anti-analysis evasion (mouse movement, screen resolution, VM checks, AV detection) |
| GhostBackDoor | Stage-2 Backdoor | Interactive shell, persistence via registry, relaunch capability |
| HTTP_VIP | C2 Downloader | HTTP C2 to codefusiontech[.]org; installs AnyDesk |
| CHAR (Rust) | Telegram C2 Backdoor | AI-assisted Rust malware using Telegram Bot API (stager_51_bot) |
Note: All four families are new and signature-evasive. Behaviour-based detection is mandatory.
Multiple Iranian state-aligned threat groups are assessed as active or likely to activate against Middle East targets. Each operates with distinct toolsets, sponsoring bodies, and target priorities, though coordinated surges across groups should be anticipated.
| Actor | Affiliation | Primary Capabilities | Risk Level |
|---|---|---|---|
| MuddyWater (G0069) | MOIS | Spearphishing, PowerShell RATs, Telegram C2 | CRITICAL |
| APT34 / OilRig (G0049) | IRGC | DNS tunneling, HYPERSHELL webshell, Exchange exploitation | CRITICAL |
| APT33 / Elfin (G0064) | IRGC | Shamoon/ZeroCleare wipers, destructive attacks | HIGH |
| CyberAv3ngers | IRGC-linked | OT/ICS targeting (PLCs, utilities) | HIGH |
| Hacktivist Clusters | IRGC-proxy | DDoS, defacement, psychological ops | HIGH-MEDIUM |
Based on historical precedent of Iranian cyber retaliation patterns, the following phased activity timeline is assessed with high confidence. Organisations should not wait for activity to be confirmed before acting ← proactive posture adjustment is critical.
| Timeframe | Expected Activity | Likely Actors | Target Sectors |
|---|---|---|---|
| 0-6 hrs | DDoS, Web defacement | Hacktivist groups | Government, Finance, Media |
| 6-48 hrs | Spearphishing surge | MuddyWater, APT34 | All sectors (Energy & Gov priority) |
| 48-96 hrs | Destructive wiper deployment | APT33, APT34 | Energy, Oil & Gas, Critical Infrastructure |
| 72+ hrs | OT/ICS intrusions | CyberAv3ngers | Utilities, Water, Power, Ports |
Organisations should prepare for escalation rather than stabilization.
The following IOCs have been identified from confirmed MuddyWater and affiliated actor activity. All indicators below should be immediately blocked at endpoint, network, and email gateway layers. Detections should generate high-priority SOC alerts.
| Indicator | Type | Associated Actor | Confidence |
|---|---|---|---|
| codefusiontech[.]org | C2 Domain | MuddyWater | HIGH |
| whatsapp-meeting.duckdns[.]org | Phishing Domain | RedKitten | HIGH |
| stager_51_bot | Telegram C2 Bot | MuddyWater | HIGH |
| api.telegram.org (corp hosts) | C2 Channel | Multiple | HIGH |
| 62ED16701A14CE26314F2436D9532FE606C15407 | SOCKS5 Tool Hash | MuddyWater | HIGH |
| FMAPP.dll | Malicious DLL | MuddyWater | HIGH |
| gshdoc_release_X64_GUI.exe | Dropper | MuddyWater | HIGH |
| sh.exe | Loader | MuddyWater | HIGH |
| Unexpected AnyDesk install | RMM Abuse | MuddyWater/APT34 | MEDIUM |
| Unexpected ScreenConnect/Atera | RMM Abuse | MuddyWater | MEDIUM |
Iranian threat actors have historically selected targets that maximise economic disruption, geopolitical signalling, and intelligence value. The following sectors are assessed based on historical targeting, strategic significance, and current threat actor capability.
| Sector | Risk Level | Rationale |
|---|---|---|
| Oil, Gas & Energy | CRITICAL | Shamoon precedent; economic leverage target |
| Government & Defence | CRITICAL | Direct retaliation and intelligence collection |
| Financial Services | CRITICAL | Regional economic hub disruption impact |
| Aviation & Airports | CRITICAL | National infrastructure disruption |
| Telecoms & ISPs | HIGH | C2 infrastructure leverage |
| Healthcare | HIGH | Civilian pressure vector |
| IT Service Providers | HIGH | Supply-chain pivot risk |
| Water & Utilities | HIGH | OT/ICS targeting precedent |
| Hospitality | MEDIUM | Psychological operations target |
The following table maps each malware family observed in Operation Olalampo to the relevant MITRE ATT&CK technique, providing actionable detection context aligned to ATT&CK v18 framework coverage.
| Malware | ATT&CK ID | Technique | Behaviour | Priority |
|---|---|---|---|---|
| GhostFetch | T1566.001 | Spearphishing Attachment | Macro-based initial access | CRITICAL |
| GhostFetch | T1497 | VM/Sandbox Evasion | Anti-analysis checks | HIGH |
| GhostBackDoor | T1547.001 | Registry Run Key | Persistence via Run keys | HIGH |
| HTTP_VIP | T1071.001 | HTTP C2 | Beaconing to C2 domain | CRITICAL |
| CHAR (Rust) | T1102 | Telegram C2 | Bot-based C2 channel | CRITICAL |
| CHAR (Rust) | T1572 | SOCKS5 Tunneling | Network proxy pivoting | HIGH |
| HYPERSHELL | T1505.003 | Webshell | Exchange/IIS persistence | CRITICAL |
| Shamoon/ZeroCleare | T1485 | Data Destruction | MBR + file wipe | CRITICAL |
The matrix below reflects CyberShelter's measured detection coverage across ATT&CK tactics relevant to the Iranian threat actor toolkit. Coverage gaps represent areas requiring immediate tuning, additional telemetry, or playbook development before threat escalation occurs.
| ATT&CK Tactic | # TTPs | Combined Coverage | Key Gap |
|---|---|---|---|
| Reconnaissance | 3 | 33% | Limited pre-attack visibility |
| Initial Access | 5 | 75% | Email gateway integration critical |
| Execution | 7 | 79% | Ensure full Windows log ingestion |
| Persistence | 5 | 75% | Endpoint sensor coverage required |
| Defense Evasion | 7 | 64% | Sandbox evasion gap |
| Credential Access | 6 | 75% | LSASS protection enforcement |
| Lateral Movement | 4 | 75% | East-west traffic monitoring |
| Command & Control | 8 | 78% | Telegram API monitoring gap |
| Impact | 6 | 58% | Wiper automation playbook gap |
The following eight actions are classified as Priority Zero and must be completed within the next four hours. Delay in any of these actions materially increases organisational risk exposure.
Following completion of all P0 actions, the below items must be actioned within the next 24 hours to ensure comprehensive defensive posture across enterprise and OT environments.
Iranian state-aligned actors have consistently demonstrated the intent and capability to conduct rapid, sophisticated, and destructive cyber operations in response to geopolitical events. The following capabilities have all been observed in recent operations:
The current environment remains CRITICAL severity for Middle East organisations.
CyberShelter NSOC is operating on a full war-footing posture. The following operations are currently active and ongoing across all managed and enterprise environments:
The threat landscape is active, evolving, and high-risk.
Organisations must move from passive monitoring to proactive containment.
CyberShelter remains fully operational and ready to support emergency response, threat hunting, and containment operations across enterprise and critical infrastructure environments.
Critical advisory on the CandleStone campaign targeting the UAE's strategic aerospace ecosystem via sophisticated VHD-delivered backdoors.
CyberShelter threat intelligence analysts have identified a targeted cyber-espionage campaign against organizations in the UAE aerospace, defence, and government sectors. The activity is attributed with high confidence to Peach Sandstorm (APT33), an Iranian IRGC-aligned threat group.
The campaign, tracked as CandleStone, leverages spear-phishing themed around the Abu Dhabi Space Debate, delivering payloads via Virtual Hard Disk (VHD) containers to bypass Windows security mechanisms.
Prior history indicates APT33 frequently transitions from espionage to destructive operations. This campaign should be treated as a high-risk precursor to potential disruptive attacks.
The UAE has emerged as a global leader in aerospace innovation, including the Hope Probe Mars mission. These strategic advancements have made the UAE a priority target for state-aligned groups seeking intellectual property and geopolitical leverage.
| Sector | Risk Level | Reason |
|---|---|---|
| Aerospace & Defence | CRITICAL | Strategic intelligence and technology targeting |
| Government | CRITICAL | National security and policy intelligence |
| Energy & Utilities | HIGH | Historical Iranian targeting patterns |
| Aviation | HIGH | Infrastructure and supply chain leverage |
The CandleStone campaign follows a structured multi-stage intrusion lifecycle, moving from mailbox compromise to persistent backdoor deployment via trusted system processes.
| Stage | Activity |
|---|---|
| 1 | Compromise of victim mailbox or targeted spear-phishing delivery |
| 2 | Phishing email themed around Abu Dhabi Space Debate |
| 3 | Delivery of malicious archive containing VHD container |
| 4 | Execution of malicious shortcut triggering DLL sideloading |
| 5 | Deployment of CandleStone backdoor |
| 6 | Command-and-control communication and data exfiltration |
The toolkit is designed to establish deep persistence and harvest credentials across compromised enterprise environments.
| Malware | Function | Key Capability | Severity |
|---|---|---|---|
| Phoenix v4 | Remote Access Trojan | Full system control with WinHTTP C2 | CRITICAL |
| FakeUpdate | Loader | Memory injection with encrypted payload | HIGH |
| Chromium Stealer | Credential theft | Targets multiple browsers and decrypts DPAPI credentials | HIGH |
The attackers exploit Virtual Hard Disk (VHD) containers to bypass "Mark-of-the-Web" (MotW) protections. Files inside a mounted VHD do not trigger the usual Windows warnings for internet-downloaded content.
| File | Description |
|---|---|
| Conferences and Materials.zip | Initial phishing archive |
| Conference Resources and Material.vhd | Virtual disk container used for security bypass |
| dxgi.dll | CandleStone backdoor payload |
Upon execution, the backdoor performs extensive host reconnaissance and initiates C2 beaconing over encrypted channels.
| Endpoint | Purpose |
|---|---|
| /sound/agents | Initial system beacon |
| /sound/tickets/all | Polling endpoint for commands |
Note: Communication occurs over HTTP on port 443 to blend with legitimate encrypted traffic.
Attackers utilized UAE-themed typosquatting domains and a "pre-aged" primary C2 server to bypass reputation-based security filters.
| Domain | Purpose |
|---|---|
| health-beauty-skin-care[.]com | Primary C2 server (Pre-aged 3.5 years) |
| abudhabspacedebate[.]com | Phishing domain |
| abudhbispacedebate[.]com | Typosquatting phishing domain |
| huammings[.]com | Newly identified campaign infrastructure |
Peach Sandstorm is a state-aligned Iranian threat group operating under the IRGC, known for long-term intrusions and strategic espionage since 2013.
| Attribute | Details |
|---|---|
| Also Known As | APT33, Elfin, Refined Kitten, Magnallium |
| Primary Objective | Strategic cyber espionage / Intellectual Property theft |
| Known Malware | DropShot, StoneDrill, Shamoon, NETWIRE RAT |
| Primary Targets | Aerospace, Defence, Energy, Government |
The CandleStone campaign utilizes diverse techniques to ensure evasion and persistence across the intrusion lifecycle.
| Tactic | Technique ID | Description | Priority |
|---|---|---|---|
| Initial Access | T1566.001 | Spearphishing attachments | CRITICAL |
| Defense Evasion | T1553.005 | Mark-of-the-Web bypass (VHD) | CRITICAL |
| Defense Evasion | T1574.002 | DLL side-loading (dxgi.dll) | HIGH |
| Command & Control | T1071.001 | Web protocol communication | CRITICAL |
Immediate monitoring and blocking of the following indicators is recommended for all organizations operating in the UAE strategic sectors.
| Indicator | Type | Context | Confidence |
|---|---|---|---|
| health-beauty-skin-care[.]com | Domain | Primary C2 domain | HIGH |
| abudhabspacedebate[.]com | Domain | Phishing domain | MODERATE |
| 209.182.225.152 | IP | Phishing infrastructure | HIGH |
| dxgi.dll | File | CandleStone Backdoor DLL | HIGH |
Organizations should implement these priority measures to mitigate risk from the CandleStone campaign.
The CandleStone campaign highlights the evolution of Iranian cyber operations. The use of VHD-based delivery, pre-aged infrastructure, and DLL sideloading demonstrates a mature adversary.
Given APT33's historical transition to destructive activity, organizations should treat this as a high-priority threat. CyberShelter NSOC remains active in monitoring and assisting affected entities.
URGENT: Initiate incident response procedures immediately if IOCs are detected.
CyberShelter Threat Intelligence has identified a new set of Indicators of Compromise (IOCs) associated with suspicious infrastructure and potential malware activity.
CyberShelter Threat Intelligence has identified a new set of Indicators of Compromise (IOCs) associated with suspicious infrastructure and potential malware activity. These indicators were recently observed within threat intelligence feeds and security analysis platforms.
Security teams should immediately ingest these indicators into SIEM, EDR, firewall, and threat intelligence platforms to enable proactive detection and blocking.
The infrastructure appears to leverage Microsoft Azure cloud services, a tactic frequently used by threat actors to host malicious payloads, command-and-control infrastructure, and data exfiltration servers.
The following cryptographic hashes represent potentially malicious files observed during threat intelligence monitoring.
| Hash Type | Value | Description |
|---|---|---|
| SHA-256 | 4130fab30cdd66f742d319b3d2473a47a64a808fcfc6d05e453451c8641e2f6d | Suspected malware sample |
| SHA-256 | 59952e885152a9638bae1478ef3d2af5e9823fb204d1068143437827eb607c4a | Related malicious payload |
| SHA-256 | 40afa28bcc5b3676b1891ac4d05bb4f49dc2268892cbbfa5da7fe3d09e2419f6 | Newly identified sample |
Security teams should search endpoint telemetry and file repositories for these hashes to determine potential exposure.
The following domains were identified as potentially malicious infrastructure used for staging payloads or data exfiltration.
| Indicator | Type | Observed Infrastructure |
|---|---|---|
| lab-rev2-2.uaenorth.cloudapp.azure.com | Cloud VM Infrastructure | Azure hosted instance |
| uploadsystem-ghejhvbka9evbtee.uaenorth-01.azurewebsites.net | Web Application | Azure App Service hosting |
Threat actors increasingly abuse public cloud infrastructure because it provides:
Organizations should monitor outbound traffic to these domains and block access if detected.
Additional intelligence regarding these indicators is available through Microsoft s Security Intelligence platform.
These intelligence profiles provide deeper analysis including malware behavior, infrastructure mapping, and threat actor attribution where available.
Organizations should perform immediate threat hunting across enterprise environments.
| Action | Description |
|---|---|
| Hash search | Scan endpoints for the identified SHA-256 hashes |
| Process review | Investigate suspicious process execution tied to downloaded binaries |
| File telemetry | Monitor unusual file creation events |
| Action | Description |
|---|---|
| DNS monitoring | Detect connections to suspicious domains |
| Web proxy logs | Identify outbound requests to Azure-hosted infrastructure |
| Network segmentation | Limit direct outbound access from sensitive systems |
Security teams should implement the following actions immediately.
| Priority | Action |
|---|---|
| Critical | Block malicious domains at DNS and firewall level |
| High | Add malware hashes to EDR detection rules |
| High | Monitor Azure cloud infrastructure communications |
| Medium | Increase logging for outbound traffic |
| Medium | Conduct retrospective log analysis for 90 days |
The use of cloud-hosted infrastructure for malicious activity continues to increase as threat actors exploit trusted platforms such as Microsoft Azure to evade detection.
Organizations should strengthen their detection capabilities by implementing:
CyberShelter NSOC continues to monitor emerging threats and provide real-time intelligence updates to protect enterprise and critical infrastructure environments.
CyberShelter threat intelligence monitoring indicates a sustained increase in cyber threat activity across the Middle East driven by geopolitical tensions.
CyberShelter threat intelligence monitoring indicates a sustained increase in cyber threat activity across the Middle East driven by geopolitical tensions, particularly following regional conflict developments beginning February 28, 2026.
Recent intelligence shows a surge in: Hacktivist operations, State-aligned cyber reconnaissance, Ransomware activity, Infrastructure targeting claims, and Social engineering campaigns exploiting regional tensions.
While most incidents currently remain low to medium impact disruptions, the overall threat posture for UAE organizations remains elevated due to increased targeting narratives and opportunistic cyber activity.
CyberShelter analysis identifies the following major cyber threat developments. These patterns are consistent with historical behavior where geopolitical escalation leads to cyber retaliation and opportunistic attacks.
| Threat Trend | Description |
|---|---|
| Hacktivist escalation | Increased DDoS and defacement activity |
| State-aligned reconnaissance | Credential harvesting and espionage attempts |
| Infrastructure targeting | Claims of ICS and SCADA compromises |
| Ransomware activity | Continued regional targeting by ransomware groups |
| Social engineering | Phishing and fraud campaigns exploiting conflict fears |
Multiple hacktivist and cybercriminal groups were observed conducting or claiming attacks. Many of these groups use propaganda to amplify their perceived impact even when technical validation is limited.
| Threat Actor | Type | Primary Activity |
|---|---|---|
| Handala Hack Team | Iran-aligned hacktivist | Data leaks, disruption claims |
| 313 Team | Hacktivist | Government DDoS operations |
| DieNet | Hacktivist collective | Infrastructure targeting |
| NoName057(16) | Pro-Russian group | DDoS campaigns |
| Cyber Islamic Resistance | Hacktivist coalition | Influence operations |
| Z-Pentest Alliance | Hybrid attacker | ICS targeting |
| FAD Team | Hacktivist | SCADA targeting claims |
| INC Ransom | Ransomware group | Data extortion campaigns |
Based on observed activity, the following sectors remain priority targets. Financial services, telecom, aviation, and government-linked organizations remain particularly attractive targets due to their visibility and operational importance.
| Sector | Risk Level | Reason |
|---|---|---|
| Government | HIGH | Political influence operations |
| Energy | HIGH | Strategic infrastructure targeting |
| Financial services | HIGH | Economic disruption potential |
| Telecommunications | MEDIUM | Data interception potential |
| Healthcare | MEDIUM | Psychological pressure campaigns |
| Aviation | MEDIUM | Critical infrastructure exposure |
Recent monitoring identified increased rhetoric encouraging attacks on Gulf organizations. While many claims remain unverified, the volume of messaging indicates rising intent and coordination.
| Group | Activity | Target |
|---|---|---|
| Handala Hack | Claimed regional banking disruption | Financial sector |
| 313 Team | DDoS claims | regional government platforms |
| DieNet | Infrastructure targeting messaging | Critical infrastructure |
| Keymous+ | DDoS campaigns | UAE infrastructure |
| Arabian Ghosts | Call for attacks | GCC countries |
Threat actors also claimed access to industrial systems. These technologies are widely used in Water utilities, Energy production, Manufacturing, and Healthcare infrastructure. Organizations using these technologies should review exposure immediately.
| Group | Claimed Access |
|---|---|
| APT Iran | Unitronics Vision PLC device |
| FAD Team | Wind turbine control systems |
| Z-Pentest | Water management controls |
| CyberAv3ngers affiliates | Industrial monitoring systems |
CyberShelter monitoring also identified continued ransomware activity. Several ransomware groups historically targeted UAE organizations, indicating continued regional interest.
| Group | Target Regions |
|---|---|
| Akira | US organizations |
| KillSec | Israeli financial sector |
| Qilin | Multiple US industries |
| Everest | Automotive sector |
| NightSpire | Non-profit sector |
| INC Ransom | US and Middle East |
Cybercriminal groups are also exploiting uncertainty through scams. Users should remain cautious when receiving unsolicited requests related to national alerts or security situations.
| Campaign | Method |
|---|---|
| Fake government alerts | Phone scams requesting national identity credentials |
| Smishing campaigns | Fake parcel notifications |
| Phishing websites | Financial data harvesting |
| Emergency registration scams | Personal data theft |
CyberShelter monitoring also identified disruptions impacting cloud services due to physical conflict spillover. This highlights how physical incidents can indirectly impact digital infrastructure.
| Service | Impact |
|---|---|
| regional cloud Region | Service degradation |
| EC2 | Availability disruption |
| RDS | Performance impact |
| EBS | Storage delays |
| Lambda | Processing interruptions |
CyberShelter assesses the following likely developments. Hacktivist activity is expected to continue primarily as disruption and influence operations rather than large-scale destructive attacks.
| Expected Activity | Likelihood |
|---|---|
| DDoS campaigns | HIGH |
| Website defacements | HIGH |
| Credential harvesting | HIGH |
| Espionage attempts | MEDIUM |
| Destructive attacks | LOW.."MEDIUM |
Organizations should implement immediate defensive measures.
The regional threat environment remains elevated due to the combination of Geopolitical escalation, Hacktivist mobilization, Proxy cyber operations, and Opportunistic cybercrime.
Although most attacks currently focus on disruption and influence operations, organizations should prepare for potential escalation. Cyber resilience now requires continuous monitoring, proactive threat hunting, and improved defensive readiness.
Cyber activity linked to geopolitical tensions continues to demonstrate how rapidly cyber risk can increase during regional instability. Organizations that maintain strong visibility, rapid detection capability, and proactive defensive controls will be best positioned to withstand evolving cyber threats.
CyberShelter NSOC continues to monitor threat developments and provide early warning intelligence to protect organizations across the UAE and global markets, remaining committed to supporting organizations with real-time threat intelligence and advanced cyber defense capabilities.
This document supplements the UAE Financial Threat Advisory (March 2026). It contains newly collected OSINT intelligence gathered via live web research on March 12, 2026, including fresh IOCs, threat actor updates, confirmed incident impacts on UAE financial infrastructure, and updated SIEM/YARA detection rules.
| Development | Detail |
|---|---|
| regional cloud data centers Struck | Regional cloud data center facilities hit by Iranian drones March 3. Several major regional banking institutions reported disruptions. Some mobile banking services were mobile banking offline 48 hours. |
| MuddyWater Dindoor/Fakeset NEW Backdoors | New undocumented backdoors discovered on US bank and airport networks. Dindoor uses Deno JS runtime; Fakeset is Python-based. Active since Feb 2026. 5 live C2 domains published. |
| IP Camera Exploitation . UAE Confirmed | Research confirmed surge in Hikvision/Dahua camera exploitation in UAE starting Feb 28. 5 CVEs weaponized. Activity correlates with missile strike preparation. |
| DieNet UAE Target List Published | DieNet published structured UAE target lists on March 2 covering airports, banking, and government. Claimed DDoS on regional airport and national banking infrastructure. |
| Regional Cyber Breach Attempts | National cybersecurity authorities report: 90,000.200,000 breach attempts hit the region daily. 21 active APT groups, 60 hacktivist groups. 71.4% state-sponsored. Financial + banking = #1 target sector. |
| Operation Olalampo (MuddyWater META) | Halcyon identified structured MuddyWater offensive operation targeting META region with TTPs overlapping RedKitten campaign. Pre-positioned access detected. |
| National Financial Regulatory OTP Mandate | National banking regulator directive: All FIs must eliminate SMS/email OTP by March 2026 deadline. Require Emirates Face Recognition, soft tokens, biometrics. Compliance deadline now ACTIVE. |
Source: Broadcom Symantec / Carbon Black Threat Hunter Team . March 5-9, 2026
MuddyWater (aka Seedworm, TEMP.Zagros, Mango Sandstorm, TA450, Static Kitten) deployed two previously undocumented backdoors beginning February 2026 against US financial, aviation, NGO, and defense-adjacent software targets. The campaign is ongoing as of March 12, 2026.
| Attribute | Value |
|---|---|
| Runtime | Deno (JavaScript/TypeScript) . unusual choice; blends into developer tooling |
| Certificate | Signed with cert issued to "Amy Cherne" . same cert used for Stagecomp/Darkcomp |
| Exfil Method | Rclone utility to Wasabi Technologies cloud storage bucket (cloud-to-cloud exfil) |
| Targets (confirmed) | US bank, Canadian non-profit, Israeli operations of US aerospace software co. |
| Activity Start | Early February 2026, ongoing through March 9 2026 |
| MITRE ATT&CK | T1059.007 (JavaScript), T1567 (Exfil to Cloud), T1136 (Persistence) |
| IOC Value | Description | Severity | Type |
|---|---|---|---|
| uppdatefile[.]com | MuddyWater C2 . typosquatted update domain | CRITICAL | Domain |
| serialmenot[.]com | MuddyWater C2 . implant callback domain | CRITICAL | Domain |
| moonzonet[.]com | MuddyWater C2 . implant callback domain | CRITICAL | Domain |
| gitempire.s3.us-east-005.backblazeb2[.]com | Backblaze S3 bucket . Fakeset download staging | HIGH | Domain |
| elvenforest.s3.us-east-005.backblazeb2[.]com | Backblaze S3 bucket . Fakeset download staging | HIGH | Domain |
| ATTRIBUTE | VALUE |
|---|---|
| Language | Python |
| Certificate | Signed by certs issued to "Amy Cherne" AND "Donald Gay" |
| Donald Gay Cert | Previously used to sign Stagecomp and Darkcomp malware - firm MuddyWater attribution |
| Download Source | Hosted on Backblaze cloud storage (backblazeb2.com) - legitimate service abuse |
| Capabilities | C2 persistence, arbitrary command execution, recon, additional payload download |
| Targets (confirmed) | US airport, Canadian non-profit |
| Shared Certs | Stagecomp, Darkcomp - MISP Event IDs 415, 515 cross-reference confirmed |
// Detect Deno Runtime Execution (Dindoor)
EventCode=4688 AND (CommandLine="*deno*" OR CommandLine="*deno.exe*")
OR (ParentImage="*deno*" AND NOT Image="*deno*")
| where ParentCommandLine contains "backblazeb2[.]com" OR CommandLine contains "wasabi"
// Detect Rclone Exfiltration (Cloud Storage Abuse)
EventCode=4688 AND Image="*rclone*"
AND (CommandLine CONTAINS "wasabi" OR CommandLine CONTAINS "backblaze"
OR CommandLine CONTAINS "s3.us-east-005")
// Detect MuddyWater C2 Domains (DNS/Proxy)
index=proxy OR index=dns_logs
| where dest_hostname IN ("uppdatefile[.]com", "serialmenot[.]com", "moonzonet[.]com",
"gitempire.s3.us-east-005.backblazeb2[.]com",
"elvenforest.s3.us-east-005.backblazeb2[.]com")
| alert CRITICAL . confirmed MuddyWater IOC
Iranian APT activity status as of March 2026. These actors represent a coordinated ecosystem combining espionage and disruption capabilities.
| Actor | Status | Key Activity |
|---|---|---|
| MuddyWater (Seedworm) | ACTIVE | Dindoor & Fakeset campaigns |
| APT42 (Charming Kitten) | ACTIVE | RedKitten espionage |
| APT34 (OilRig) | ACTIVE | DNS infrastructure targeting |
| APT33 (Prince of Persia) | ELEVATED | Telecom and finance targeting |
| CyberAv3ngers | ACTIVE | ICS/OT targeting |
| Fox Kitten | ELEVATED | VPN exploitation |
| Handala Hack | ACTIVE | Wiper and data theft |
| Dusty Specter | ACTIVE | GCC targeting operations |
CyberShelter analysts identified two new MuddyWater backdoors: Dindoor and Fakeset.
| Attribute | Details |
|---|---|
| Runtime | Deno JavaScript runtime |
| Exfiltration | Rclone to Wasabi cloud storage |
| Targets | Financial, aviation, NGOs |
| Persistence | Scheduled tasks |
| IOC | Type | Severity |
|---|---|---|
| uppdatefile[.]com | C2 Domain | CRITICAL |
| serialmenot[.]com | C2 Domain | CRITICAL |
| moonzonet[.]com | C2 Domain | CRITICAL |
| gitempire.s3.backblazeb2[.]com | Staging | HIGH |
| ATTRIBUTE | VALUE |
|---|---|
| Language | Python |
| Certificate | Signed by "Amy Cherne" AND "Donald Gay" (MuddyWater attribution) |
| Donald Gay Cert | Previously used to sign Stagecomp and Darkcomp malware - firm MuddyWater attribution |
| Download Source | Hosted on Backblaze cloud storage (backblazeb2.com) - legitimate service abuse |
| Capabilities | C2 persistence, arbitrary command execution, recon, additional payload download |
| Targets (confirmed) | US airport, Canadian non-profit |
| Shared Certs | Stagecomp, Darkcomp - MISP Event IDs 415, 515 cross-reference confirmed |
// Detect Deno Runtime Execution (Dindoor)
EventCode=4688 AND (CommandLine="*deno*" OR CommandLine="*deno.exe*")
OR (ParentImage="*deno*" AND NOT Image="*deno*")
| where ParentCommandLine contains "backblazeb2.com" OR CommandLine contains "wasabi"
// Detect Rclone Exfiltration (Cloud Storage Abuse)
EventCode=4688 AND Image="*rclone*"
AND (CommandLine CONTAINS "wasabi" OR CommandLine CONTAINS "backblaze"
OR CommandLine CONTAINS "s3.us-east-005")
// Detect MuddyWater C2 Domains (DNS/Proxy)
index=proxy OR index=dns_logs
| where dest_hostname IN ("uppdatefile.com", "serialmenot.com", "moonzonet.com",
"gitempire.s3.us-east-005.backblazeb2.com",
"elvenforest.s3.us-east-005.backblazeb2.com")
Source: Research . March 4, 2026 (CPR-2026-0304)
Research confirmed that Iranian-nexus threat actors began intensified scanning and exploitation of Hikvision and Dahua IP cameras in the UAE starting February 28, 2026 . the same day as Operation Epic Fury. This pattern is consistent with Iranian doctrine of using compromised camera feeds for battle damage assessment (BDA) prior to and during missile/drone strikes.
| CVE | Vendor | Severity | Description |
|---|---|---|---|
| CVE-2017-7921 | Hikvision | CRITICAL | Improper authentication in camera firmware . unauthenticated access to live feed |
| CVE-2021-36260 | Hikvision | CRITICAL | Command injection in web server component . RCE with root privileges |
| CVE-2023-6895 | Hikvision | HIGH | OS command injection in Intercom Broadcasting System |
| CVE-2025-34067 | Hikvision | CRITICAL | Unauthenticated remote code execution in Integrated Security Management Platform (NEW 2025) |
| CVE-2021-33044 | Dahua | CRITICAL | Authentication bypass in Dahua NVR/DVR/IPC products . full access without creds |
| Indicator Type | Detail |
|---|---|
| VPN Exit Nodes | Mullvad VPN, ProtonVPN, Surfshark, NordVPN . used to mask true source IP |
| VPS Platforms | Commercial VPS providers . attribution to Iran-nexus by behavior pattern matching |
| Target Selection | Port 80/443/8080/8554 (Hikvision/Dahua default ports) scanning across UAE IP ranges |
| Temporal Pattern | Activity spikes align precisely with geopolitical escalation events (Jan 14-15, Feb 28+) |
| Sectors at Risk | Financial institution CCTV, port/logistics cameras, ATM cameras |
| Impact Item | Detail |
|---|---|
| Banks Affected | Multiple tier-1 banks (including hours-long service outages) |
| Market Impact | Dubai Financial Market and Abu Dhabi Securities Exchange suspended |
| Retail/Fintech | Major regional fintech and retail services reported significant outages |
Groups like DieNet, Handala Hack, and 313 Team declared targeting of UAE infrastructure following regional escalation.
| Group | Activity | Affiliation |
|---|---|---|
| DieNet | Regional Airport & Banking targeting | Anti-US/Pro-Iran |
| Handala Hack | Wiper capability & data theft | MOIS-directed |
| Keymous+ | 48.9% of regional DDoS activity | Pro-Palestinian |
| Document | Summary |
|---|---|
| FSRA Notice 15 of 2026 | Cyber Risk Survey Findings . addressed to regional financial services firms |
| FSRA Notice 13 of 2025 | Mandatory IT and Cyber Incident Reporting requirements |
| Regional Financial Hub CTI Newsletter | Weekly threat intelligence (March 5, 2026 edition) |
| UAE CSC Alert | 90,000.200,000 daily breach attempt statistics |
| Wiper Family | Notes |
|---|---|
| ZeroCleare | Disk-wiping malware . targets MBR . IRGC-linked |
| Meteor | Modular wiper + ransomware + lock screen |
| Apostle | Hardcoded decryption key confirms wiper intent |
| MultiLayer | Layer-by-layer file destruction . overwrites then deletes |
| Anon-g Fox (2025) | Geographically targeted execution check |
| Actor | Status | Key Development |
|---|---|---|
| MuddyWater | ACTIVE | Dindoor+Fakeset campaign . Operation Olalampo |
| APT42 | ACTIVE | TameCat deployed . AI-enhanced spearphishing |
| OilRig | ACTIVE | Rapid retooling . DNS infrastructure exploitation |
| Fox Kitten | ELEVATED | VPN appliance exploitation specialist |
| CyberAv3ngers | ACTIVE | Hikvision/Dahua exploitation in UAE confirmed |
| Handala Hack | ACTIVE | Confirmed wiper + data theft capability |
| Dusty Specter | ACTIVE | TwinTalk C2 orchestrator . GCC targeting |
| Priority | Action |
|---|---|
| P1 | Block all 5 Dindoor/Fakeset C2 domains immediately |
| P1 | Deploy SIEM rules for Deno runtime and Rclone exfiltration |
| P1 | Audit IP cameras . move behind VPN and patch all critical CVEs |
| P1 | Verify central regulatory OTP compliance deadline (No SMS/Email OTP) |
| P2 | Hunt for Content-DPR header (APT42 TameCat C2 indicator) |
| P2 | Review AWS infrastructure single-points-of-failure |
| P3 | Import all RedKitten/SloppyMIO IOCs into MISP instance |
| Research | CPR-2026-0304 . IP camera exploitation target UAE/GCC |
| Broadcom Symantec | Dindoor/Fakeset backdoor discovery and IOC publication |
| SOCRadar | Operation Epic Fury comprehensive threat intelligence feed |
| HarfangLab | RedKitten/SloppyMIO campaign analysis and IOCs |
| Radware | Hacktivist DDoS statistics Feb 28-Mar 2 |
| UAE CSC | 90,000.200,000 daily breach attempt statistics |
| National Regulator | Banking sector stability and OTP directive compliance |
| Control | Purpose |
|---|---|
| MFA enforcement | Prevent credential attacks |
| Credential rotation | Reduce breach risk |
| Access monitoring | Detect compromise |
| Control | Purpose |
|---|---|
| Network segmentation | Limit attacker movement |
| OT isolation | Protect industrial systems |
| Patch management | Close vulnerabilities |
| Control | Purpose |
|---|---|
| EDR deployment | Detect malware |
| Threat hunting | Identify persistence |
| IOC ingestion | Improve detection |
CyberShelter assesses the UAE threat environment as HIGH RISK due to:
The combination of espionage, disruption, and destructive capabilities indicates a long-term strategic cyber campaign. Organizations should move from reactive monitoring to proactive threat hunting and resilience planning.
The UAE cyber threat landscape continues to evolve rapidly as geopolitical tensions drive increased cyber operations.
CyberShelter continues to provide advanced threat intelligence, detection engineering, and incident response support to help organizations defend against nation-state cyber threats.
Iran • Russia • China • Ransomware • Nation-State APT • Active War
Targeting
March 12, 2026 | TLP:AMBER | MITRE ATT&CK v17 | 758 MISP
Events (35 APT-Grade)
The UAE financial sector faces the most dangerous threat environment in its history. The February 28, 2026 kinetic strike by US and Israeli forces on Iranian military infrastructure has activated pre-positioned Iranian cyber operations targeting Gulf financial capitals. Analysis of your MISP instance (758 events, 35 APT-classified) reveals active C2 infrastructure, ongoing credential spray campaigns, and pre-positioned destructive malware across four nation-state actors and three active ransomware groups.
| Actor | Nation | MISP Events | IOC Count | Financial Target | Stage | Status |
|---|---|---|---|---|---|---|
| MuddyWater/MOIS | Iran | ID:415,515,420 | 4 IPs+18MD5 | Banks, Telecom | Exec/C2 | ACTIVE |
| OilRig/APT34 | Iran | ID:468,522,536 | 69 spray IPs | Finance, SWIFT | Long exfil | ACTIVE |
| APT33/IRGC | Iran | ID:536,524,419 | 8 IPs+5CVEs | O365 tenants | Cred spray | ACTIVE |
| UNC1549/IRGC | Iran | ID:463 | 37MD5+130hosts | Aerospace/Finance | Recon | ACTIVE |
| Secret Blizzard | Russia | ID:541 | 44 IPs+9SHA256 | Gov Finance | Long-dwell | ACTIVE |
| APT29/NOBELIUM | Russia | ID:476,513,385 | 15SHA256+3dom | Banks, Procure | Staged | ELEVATED |
| GRU/Sandworm | Russia | ID:527,299,301 | 25 IPs+wipers | SWIFT, OT/ICS | Destruct | ELEVATED |
| Volt Typhoon | China | ID:444 | 2 IPs+6SHA256 | Critical Infra | Pre-position | ELEVATED |
| APT41 | China | ID:390 | 21 domains | Banks, 3CX | Supply chain | ELEVATED |
| Beast/Qilin | Criminal | ID:539 | 5 SHA256 | Any bank/ESXi | Ransomware | CRITICAL |
| Phorpiex | Criminal | ID:546 | 1 IP+9SHA256 | Email targets | Downloader | HIGH |
MISP Events: ID:415 | ID:515 | ID:420 | ID:474
Classification: MOIS nation-state APT | Active since 2017 | Confirmed GCC deployment March 6 2026
UAE Financial Relevance: MuddyWater pre-planted backdoors confirmed in GCC networks. Specialises in abusing legitimate RMM tools - Syncro, AnyDesk, SimpleHelp - for persistent access. Current implant MuddyRot (MISP ID:515) replaces Atera RMM with custom C2 using mutex "DocumentUpdater".
| Phase | Technique | Tool/Vector |
|---|---|---|
| Recon | T1591 Org Recon | LinkedIn/OSINT |
| Phishing | T1566.001 PDF lure | Storyblok CDN |
| Execution | T1059.001 PowerShell | POWERSTATS |
| RMM Persist | T1219 Remote Mgmt | Syncro/MuddyRot |
| Cred Theft | T1056 Input Cap | Keylogger module |
| C2 | T1071.004 DNS/HTTPS | Telegram Bot API |
| Exfil | T1567.002 Cloud | OneDrive/Dropbox |
| Indicator [Real MISP] | Context | Type | Severity |
|---|---|---|---|
| 146.70.149.61 | MuddyWater C2 server - ID:415 eN-Able campaign | ip-dst | CRITICAL |
| 146.70.124.102 | MuddyWater/Seedworm shared C2 - ID:415 & ID:420 | ip-dst | CRITICAL |
| 37.120.237.204 | MuddyWater infrastructure - ID:415 | ip-dst | HIGH |
| 37.120.237.248 | MuddyWater infrastructure - ID:415 | ip-dst | HIGH |
| 91.235.234.202 | MuddyRot implant C2 - ID:515 | ip-dst | CRITICAL |
| 146.19.143.14 | MuddyRot C2 server - ID:515 | ip-dst | CRITICAL |
| 94.131.109.65 | Seedworm C2 - African/GCC telecom - ID:420 | ip-dst | HIGH |
| 95.164.38.99 | Seedworm C2 - ID:420 | ip-dst | HIGH |
| 45.67.230.91 | Seedworm infrastructure - ID:420 | ip-dst | HIGH |
| 94.131.98.14 | Seedworm C2 server - ID:420 | ip-dst | MEDIUM |
| 94278fa01900fdbfb58d2e373895c045c69c01915edc5349cd6f3e5b7130c472 | MuddyRot implant SHA256 - ID:515 | sha256 | CRITICAL |
| b8703744744555ad841f922995cef5dbca11da22565195d05529f5f9095fbfca | MuddyRot variant SHA256 - ID:515 | sha256 | CRITICAL |
| 73c677dd3b264e7eb80e26e78ac9df1dba30915b5ce3b1bc1c83db52b9c6b30e | MuddyRot payload SHA256 - ID:515 | sha256 | HIGH |
| 37c3f5b3c814e2c014abc1210e8e69a2 | MuddyWater dropper MD5 - ID:415 | md5 | HIGH |
| 16923d827a440161217fb66a04e8b40a | MuddyWater payload MD5 - ID:415 | md5 | HIGH |
| 2e09e53135376258a03b7d793706b70f | MuddyWater RAT MD5 - ID:415 | md5 | HIGH |
| 065f0871b6025b8e61f35a188bca1d5c | eN-Able phishing MD5 - ID:415 | md5 | HIGH |
| dd247ccd7cc3a13e1c72bb01cf3a816d | MuddyWater tool MD5 - ID:415 | md5 | MEDIUM |
| documentsmanagerreporter.exe | MuddyRot implant filename - ID:515 | filename | CRITICAL |
| DocumentUpdater | MuddyRot mutex - ID:515 | mutex | CRITICAL |
| dee6494e69c6e7289cf3f332e2867662958fa82f819615597e88c16c967a25a9 | TA450 PDF payload SHA256 - ID:474 | sha256 | HIGH |
| cc4cc20b558096855c5d492f7a79b160a809355798be2b824525c98964450492 | TA450 PDF variant - ID:474 | sha256 | HIGH |
| ws.onehub[.]com/files/7f9dxtt6 | MuddyWater phishing delivery URL - ID:415 | url | HIGH |
| a.storyblok[.]com/f/253959/x/b92ea48421/form.zip | Storyblok CDN phishing lure - ID:415 | url | HIGH |
// MuddyRot implant detection - MISP ID:515 real confirmed IOCs
rule MuddyWater_MuddyRot_Implant {
meta:
misp_event = "ID:515"
author = "UAE-SOC"
date = "2026-03-12"
description = "Detects MuddyRot implant - mutex DocumentUpdater"
mitre = "T1219, T1059.001, T1071.004"
strings:
$mutex = "DocumentUpdater" wide ascii
$exe = "documentsmanagerreporter.exe" wide ascii nocase
$c2_1 = "146.19.143.14" ascii
$c2_2 = "91.235.234.202" ascii
$str1 = "MuddyRot" wide ascii nocase
$tele = "api.telegram.org" nocase
$ps_enc = "JABzAGUAbABmAA" ascii
condition:
uint16(0) == 0x5A4D and
(1 of ($mutex,$exe) or 1 of ($c2_1,$c2_2) or
($str1 and $tele) or ($ps_enc and $tele))
}
// TA450 PDF phishing lure - MISP ID:474
rule MuddyWater_TA450_PDF_Lure {
meta:
misp_event = "ID:474"
description = "Detects TA450/MuddyWater PDF lures via Onehub/Storyblok"
strings:
$pdf = { 25 50 44 46 }
$hub = "ws.onehub.com/files/" ascii nocase
$story = "a.storyblok.com/f/" ascii nocase
$egnyte = "salary.egnyte.com" ascii nocase
$sync = "ln5.sync.com" ascii nocase
$tera = "terabox.com/s/" ascii nocase
condition:
$pdf at 0 and 1 of ($hub,$story,$egnyte,$sync,$tera)
}
// === Splunk SPL - Unauthorized RMM Tool (MuddyWater T1219) ===
index=endpoint sourcetype=sysmon EventCode=1
(Image="*\syncro.exe" OR Image="*\atera*.exe" OR Image="*\simplehelp*"
OR Image="*\anydesk.exe" OR Image="*\screenconnect*")
| eval approved=if(match(ComputerName,"^(HELPDESK|IT-)"),1,0)
| where approved=0
| stats count by ComputerName,Image,User,ParentImage
| eval ALERT="CRITICAL: Unauthorized RMM - MuddyWater T1219 MISP-ID:515"
// === Splunk - MuddyRot/Seedworm C2 IPs (Real MISP IOCs ID:415/515/420) ===
index=network
(dest_ip="146.70.149.61" OR dest_ip="146.70.124.102" OR dest_ip="91.235.234.202"
OR dest_ip="146.19.143.14" OR dest_ip="37.120.237.204" OR dest_ip="94.131.109.65"
OR dest_ip="95.164.38.99" OR dest_ip="45.67.230.91")
| stats count by src_ip,dest_ip,dest_port
| eval ALERT="CRITICAL: MuddyWater C2 - MISP ID:415/515/420"
// === KQL - Telegram C2 (MuddyWater Small Sieve T1071) ===
NetworkCommunicationEvents
| where RemoteUrl has "api.telegram.org"
| where InitiatingProcessFileName !in~ ("Telegram.exe","chrome.exe","msedge.exe")
| summarize count() by DeviceName,InitiatingProcessFileName,RemoteUrl
| where count_ > 3
| extend ALERT="HIGH: Non-browser Telegram API - MuddyWater C2"
UNC1549 targets Israeli and Middle Eastern aerospace, defense, and technology organisations with strong UAE financial links. Uses Azure-hosted C2 infrastructure (130+ confirmed azurewebsites.net subdomains in your MISP) disguised as legitimate cloud services. All 37 MD5 hashes and 6 C2 domains below are extracted directly from your MISP ID:463.
| Indicator [Real MISP] | Context | Type | Severity |
|---|---|---|---|
| 1stemployer[.]com | UNC1549 fake HR portal C2 - ID:463 | domain | CRITICAL |
| cashcloudservices[.]com | UNC1549 C2 domain - ID:463 | domain | HIGH |
| jupyternotebookcollections[.]com | UNC1549 developer lure - ID:463 | domain | HIGH |
| notebooktextcheckings[.]com | UNC1549 infrastructure - ID:463 | domain | HIGH |
| vsliveagent[.]com | UNC1549 C2 domain - ID:463 | domain | HIGH |
| xboxplayservice[.]com | UNC1549 gaming-themed lure - ID:463 | domain | MEDIUM |
| teledyneflir[.]com[.]de | FLIR/defense impersonation - ID:463 | hostname | CRITICAL |
| birngthemhomenow[.]co[.]il | Israeli hostage-themed lure domain - ID:463 | hostname | HIGH |
| airconnectionapi[.]azurewebsites[.]net | Azure-hosted C2 - ID:463 | hostname | HIGH |
| airgadgetsolutions[.]azurewebsites[.]net | Azure C2 infrastructure - ID:463 | hostname | HIGH |
| audiomanagerapi[.]azurewebsites[.]net | Azure C2 infrastructure - ID:463 | hostname | HIGH |
| 054c67236a86d9ab5ec80e16b884f733 | UNC1549 payload MD5 - ID:463 | md5 | CRITICAL |
| 1d8a1756b882a19d98632bc6c1f1f8cd | UNC1549 payload MD5 - ID:463 | md5 | CRITICAL |
| 409c2ac789015e76f9886f1203a73bc0 | UNC1549 tooling MD5 - ID:463 | md5 | HIGH |
| 664cfda4ada6f8b7bb25a5f50cccf984 | UNC1549 dropper MD5 - ID:463 | md5 | HIGH |
| 710d1a8b2fc17c381a7f20da5d2d70fc | UNC1549 implant MD5 - ID:463 | md5 | HIGH |
| 601eb396c339a69e7d8c2a3de3b0296d | UNC1549 tool MD5 - ID:463 | md5 | HIGH |
| 3b658afa91ce3327dbfa1cf665529a6d | UNC1549 module MD5 - ID:463 | md5 | MEDIUM |
UAE Financial Targeting: OilRig has the longest history of sustained targeting against UAE banks and SWIFT infrastructure. CISA AA24-290A (MISP ID:536) confirmed 69 active Iranian brute-force source IPs. Iranian phishing campaign (ID:522) used 10 live domains including brookings.email (Brookings Institution impersonation). All CVEs below confirmed in MISP ID:524 as actively exploited Iranian initial access vectors.
| Phase | Technique | Tool/Vector |
|---|---|---|
| Recon | T1591 Org Recon | Custom scrapers |
| Initial Access | T1190 VPN exploit | CVE-2024-24919 |
| Backdoor | T1505.003 WebShell | TWOFACE ASPX |
| Persist | T1059 SideTwist | RDAT backdoor |
| Exfil slow | T1071.004 DNS | DNSpionage tunnel |
| Email harvest | T1114 Outlook | HYPERSCRAPE |
| Long-dwell | T1005 staged | Months quiet |
| Indicator [Real MISP] | Context | Type | Severity |
|---|---|---|---|
| 191.96.150.50 | CISA AA24-290A Iranian brute force IP - ID:536 | ip-dst | CRITICAL |
| 46.246.3.245 | Iranian brute force / MFA bypass - ID:536 | ip-dst | CRITICAL |
| 46.246.3.223 | Iranian credential spray source - ID:536 | ip-dst | CRITICAL |
| 188.126.89.35 | Iranian cyber actor C2 - ID:536 | ip-dst | CRITICAL |
| 46.246.3.239 | CISA-confirmed Iranian brute force - ID:536 | ip-dst | HIGH |
| 46.246.3.233 | Iranian actor infrastructure - ID:536 | ip-dst | HIGH |
| 46.246.122.185 | Iranian actor relay - ID:536 | ip-dst | HIGH |
| 95.181.235.8 | Iranian relay - CISA AA24-290A - ID:536 | ip-dst | HIGH |
| 149.57.16.150 | Iranian cyber actor - AA24-290A - ID:536 | ip-dst | HIGH |
| 49.13.194.118 | Iranian phishing campaign C2 - ID:522 | ip-dst | CRITICAL |
| 91.107.150.184 | Iranian phishing infrastructure - ID:522 | ip-dst | HIGH |
| 193.149.187.41 | Iran ransomware-enabling C2 - ID:524 | ip-dst | HIGH |
| 206.71.148.78 | Iran ransomware infra - ID:524 | ip-dst | HIGH |
| 134.209.30.220 | Iran actor server - ID:524 | ip-dst | MEDIUM |
| accredit-navigation[.]online | Iranian phishing domain - ID:522 | domain | CRITICAL |
| panel-short-check[.]live | Iranian C2 panel - ID:522 | domain | CRITICAL |
| check-pabnel-status[.]live | Iranian credential harvest - ID:522 | domain | HIGH |
| understandingthewar[.]org | War-themed Iranian lure - ID:522 | domain | HIGH |
| brookings[.]email | Brookings Institution impersonation - ID:522 | domain | CRITICAL |
| fortigate.forticloud[.]online | Fortinet impersonation C2 - ID:524 | domain | CRITICAL |
| cloud.sophos[.]one | Sophos impersonation - ID:524 | domain | HIGH |
| login.forticloud[.]online | Fortinet credential harvest - ID:524 | domain | HIGH |
| daa362f070ba121b9a2fa3567abc345edcde33c54cabefa71dd2faad78c10c33 | Scarred Manticore tool - ID:468 | sha256 | HIGH |
| f4639c63fb01875946a4272c3515f005d558823311d0ee4c34896c2b66122596 | Scarred Manticore payload - ID:468 | sha256 | HIGH |
| 09407d2e3ac7d6af13c407d17ec8e51b6d1b1d8271df65ebd0b3ffbab420b2fe | CISA AA24-290A malware SHA256 - ID:536 | sha256 | CRITICAL |
| b729962dd554dc2cba31ac9f7b9046eb119e7b4ae299d674f65ee9eba5679d62 | CISA AA24-290A malware SHA256 - ID:536 | sha256 | HIGH |
| ShareAudit.exe | CISA AA24-290A lateral movement tool - ID:536 | filename | HIGH |
| CVE-2024-24919 | Gateway RCE - Iran initial access - ID:524 | cve | CRITICAL |
| CVE-2024-3400 | Palo Alto PAN-OS RCE - Iran exploitation - ID:524 | cve | CRITICAL |
| CVE-2022-1388 | F5 BIG-IP RCE - Iran exploitation - ID:524 | cve | HIGH |
| CVE-2019-19781 | Citrix ADC - Iran persistent exploitation - ID:524 | cve | HIGH |
| CVE-2023-3519 | Citrix NetScaler RCE - Iran - ID:524 | cve | HIGH |
// === KQL - CISA AA24-290A Iranian Password Spray (T1110.003) - MISP ID:536 ===
let IranIPs = dynamic([
"191.96.150.50","46.246.3.245","46.246.3.223","188.126.89.35",
"46.246.3.239","46.246.3.233","146.70.102.3","46.246.122.185",
"191.96.227.102","95.181.235.8","46.246.8.84","191.96.150.21",
"149.57.16.150","191.96.227.159","191.96.106.33"]);
SigninLogs
| where TimeGenerated > ago(1h)
| where ResultType in (50126,50053,50055,70044)
| extend KnownIran = CallerIPAddress in (IranIPs)
| summarize Fails=count(),Accounts=dcount(UserPrincipalName)
by CallerIPAddress,KnownIran,bin(TimeGenerated,5m)
| where (KnownIran and Fails>1) or (Accounts>5 and Fails>20)
| extend ALERT=iif(KnownIran,
"CRITICAL: MISP-confirmed Iranian brute force IP - ID:536",
"HIGH: Password spray pattern T1110.003")
// === Splunk - Iranian Phishing Domain (Real MISP ID:522/524) ===
index=proxy OR index=dns
(dest_host="accredit-navigation.online" OR dest_host="panel-short-check.live"
OR dest_host="brookings.email" OR dest_host="fortigate.forticloud.online"
OR dest_host="cloud.sophos.one" OR dest_host="check-pabnel-status.live"
OR dest_host="understandingthewar.org" OR dest_host="login.forticloud.online")
| stats count by src_ip,dest_host,user
| eval ALERT="CRITICAL: Iranian APT phishing domain - MISP ID:522/524"
MISP Event: ID:541 - 2024-12-05 - Microsoft TI - Secret Blizzard compromising Storm-0156 infrastructure
Relevance: FSB Unit 71330 (Secret Blizzard) compromised Pakistani APT Storm-0156 infrastructure to double-pivot into Afghan and South Asian government finance and defence networks. Your MISP contains 44 confirmed C2 IPs and 9 SHA256 hashes. Arsenal tool "ArsenalV2%.exe" confirmed filename. Also active: Turla (ID:353) with 4 confirmed C2 IPs.
| Indicator [Real MISP] | Context | Type | Severity |
|---|---|---|---|
| 94.177.198.94 | Secret Blizzard C2 - Storm-0156 pivot - ID:541 | ip-dst | CRITICAL |
| 162.213.195.129 | Secret Blizzard C2 server - ID:541 | ip-dst | CRITICAL |
| 46.249.58.201 | Turla/Secret Blizzard infra - ID:541 | ip-dst | HIGH |
| 95.111.229.253 | Secret Blizzard relay - ID:541 | ip-dst | HIGH |
| 146.70.158.90 | Secret Blizzard C2 - ID:541 | ip-dst | HIGH |
| 143.198.73.108 | Secret Blizzard server - ID:541 | ip-dst | HIGH |
| 161.35.192.207 | Secret Blizzard C2 - ID:541 | ip-dst | HIGH |
| 91.234.33.48 | Secret Blizzard infra - ID:541 | ip-dst | HIGH |
| 154.53.42.194 | Secret Blizzard relay node - ID:541 | ip-dst | MEDIUM |
| 38.242.207.36 | Secret Blizzard infrastructure - ID:541 | ip-dst | MEDIUM |
| 130.185.119.198 | Secret Blizzard infrastructure - ID:541 | ip-dst | MEDIUM |
| 176.57.184.97 | Secret Blizzard C2 - ID:541 | ip-dst | MEDIUM |
| 212.114.52.24 | Turla C2 - Galaxy of Opportunity - ID:353 | ip-dst | HIGH |
| 194.67.209.186 | Turla C2 port 443 - ID:353 | ip-dst | HIGH |
| 35.205.61.67 | Turla relay - ID:353 | ip-dst | MEDIUM |
| connectotels[.]net | Secret Blizzard C2 domain - ID:541 | domain | CRITICAL |
| hostelhotels[.]net | Secret Blizzard C2 domain - ID:541 | domain | HIGH |
| anam0rph[.]su | Turla C2 domain - ID:353 | domain | HIGH |
| manager[.]surro[.]am | Turla hostname - ID:353 | hostname | HIGH |
| e298b83891b192b8a2782e638e7f5601acf13bab2f619215ac68a0b61230a273 | Secret Blizzard tool - ID:541 | sha256 | HIGH |
| 08803510089c8832df3f6db57aded7bfd2d91745e7dd44985d4c9cb9bd5fd1d2 | Secret Blizzard payload - ID:541 | sha256 | HIGH |
| aba8b59281faa8c1c43a4ca7af075edd3e3516d3cef058a1f43b093177b8f83c | Secret Blizzard implant - ID:541 | sha256 | HIGH |
| 7c4ef30bd1b5cb690d2603e33264768e3b42752660c79979a5db80816dfb2ad2 | Secret Blizzard tool - ID:541 | sha256 | HIGH |
| ArsenalV2%.exe | Secret Blizzard arsenal tool - ID:541 | filename | CRITICAL |
| ConnectionInfo.db | Secret Blizzard persistence DB - ID:541 | filename | HIGH |
| DownloadPriority.db | Secret Blizzard download manager - ID:541 | filename | HIGH |
| TrustedInstaller.exe | Turla masquerading Windows svc - ID:353 | filename | HIGH |
Financial Relevance: Sandworm (GRU Unit 74455) has capability to destroy financial SWIFT infrastructure and payment systems. HermeticWiper (ID:299) and CaddyWiper are pre-positioned destructive tools. Industroyer2 (ID:301) targets OT/ICS systems that support financial data centres and trading infrastructure. CISA AA24-249A (MISP ID:527) contains 25 confirmed C2 IPs and 172 MD5 hashes from active GRU tooling.
| Indicator [Real MISP] | Context | Type | Severity |
|---|---|---|---|
| 81.17.24.130 | GRU APT C2 - AA24-249A CISA confirmed - ID:527 | ip-dst | CRITICAL |
| 194.26.29.251 | Russian military APT infrastructure - ID:527 | ip-dst | HIGH |
| 194.26.29.84 | Russian military APT relay - ID:527 | ip-dst | HIGH |
| 185.245.85.251 | GRU infrastructure - ID:527 | ip-dst | HIGH |
| 185.245.84.227 | GRU C2 server - ID:527 | ip-dst | HIGH |
| 179.43.189.218 | Russian APT pivot node - ID:527 | ip-dst | HIGH |
| 179.43.175.108 | Russian military APT - ID:527 | ip-dst | MEDIUM |
| 112.132.218.45 | GRU relay - ID:527 | ip-dst | MEDIUM |
| interlinks.top | GRU C2 domain - AA24-249A - ID:527 | domain | HIGH |
| nssm.cc | Russian APT proxy tool - ID:527 | domain | HIGH |
| 3proxy.ru | Russian APT proxy - ID:527 | domain | HIGH |
| e5f3ef69a534260e899a36cec459440dc572388defd8f1d98760d31c700f42d5 | HermeticWiper SHA256 - ID:299 | sha256 | CRITICAL |
| 96b77284744f8761c4f2558388e0aee2140618b484ff53fa8b222b340d2a9c84 | HermeticWiper variant - ID:299 | sha256 | CRITICAL |
| 1bc44eef75779e3ca1eefb8ff5a64807dbc942b1e4a2672d77b9f6928d292591 | CaddyWiper SHA256 - ID:299 | sha256 | CRITICAL |
| b6f2e008967c5527337448d768f2332d14b92de22a1279fd4d91000bb3d4a0fd | HermeticWiper v2 - ID:299 | sha256 | HIGH |
| 9fe8203b06c899d15cb20d2497103dbb | HermeticWiper MD5 - ID:299 | md5 | CRITICAL |
| 714f8341bd1c4bc1fc38a5407c430a1a | HermeticWiper MD5 - ID:299 | md5 | CRITICAL |
| empntdrv.sys | HermeticWiper driver - ID:299 | filename | CRITICAL |
| conhosts.exe | HermeticWiper masquerade - ID:299 | filename | HIGH |
| zrada.exe | Industroyer2 component - ID:301 | filename | CRITICAL |
| 108_100.exe | Industroyer2 ICS payload - ID:301 | filename | CRITICAL |
// HermeticWiper / CaddyWiper - MISP ID:299 real SHA256 hashes
rule HermeticWiper_CaddyWiper {
meta:
misp_event = "ID:299"
author = "UAE-SOC"
date = "2026-03-12"
description = "Detects Sandworm HermeticWiper and CaddyWiper"
mitre = "T1485, T1561.002"
strings:
$drv = "empntdrv.sys" wide ascii nocase
$fake = "conhosts.exe" wide ascii nocase
$wipe = "HermeticWiper" wide ascii nocase
$caddy = "CaddyWiper" wide ascii nocase
$ease = "EaseUS" wide ascii nocase
$c2 = "kfctm.online" ascii nocase
// Real SHA256 from your MISP ID:299
$sha_1 = "e5f3ef69a534260e899a36cec459440dc572388defd8f1d98760d31c700f42d5" ascii
$sha_2 = "1bc44eef75779e3ca1eefb8ff5a64807dbc942b1e4a2672d77b9f6928d292591" ascii
condition:
uint16(0) == 0x5A4D and
(1 of ($drv,$fake,$wipe,$caddy) or ($ease and $c2) or 1 of ($sha_*))
}
// === Splunk - GRU APT C2 (AA24-249A confirmed IPs from MISP ID:527) ===
index=network
(dest_ip="81.17.24.130" OR dest_ip="194.26.29.251" OR dest_ip="194.26.29.84"
OR dest_ip="185.245.85.251" OR dest_ip="185.245.84.227"
OR dest_ip="179.43.189.218" OR dest_ip="179.43.187.47"
OR dest_ip="154.21.20.82" OR dest_ip="112.132.218.45")
| stats count by src_ip,dest_ip,dest_port,protocol
| eval ALERT="CRITICAL: GRU C2 contact - CISA AA24-249A MISP ID:527"
// === KQL - APT29 NOBELIUM delivery domains (MISP ID:476/513) ===
DeviceNetworkEvents
| where RemoteUrl has_any (
"waterforvoiceless.org","siestakeying.com",
"castechtools.com","seeceafcleaners.co.uk",
"passatempobasico.com.br","literaturaelsalvador.com")
| project Timestamp,DeviceName,InitiatingProcessFileName,RemoteUrl
| extend ALERT="CRITICAL: APT29 WINELOADER/NOBELIUM staging - MISP ID:476/513"
MISP Event: ID:444 - 2024-02-08 - CISA/NSA/FBI Joint Advisory - 165 attributes
Financial Relevance: Volt Typhoon uses exclusively living-off-the-land techniques (LOTL) - no custom malware, making detection extremely difficult. CISA/NSA assess this is pre-positioning for destruction, not espionage. UAE financial critical infrastructure is a likely target. MISP ID:444 contains 2 confirmed SOHO relay IPs, 6 SHA256 hashes, 3 MD5s, and 3 filenames.
| Phase | Technique | Tool/Vector |
|---|---|---|
| Edge Access | T1190 SOHO exploit | Cisco/Netgear/ASUS |
| Proxy chain | T1090 KV-botnet | SOHO relay net |
| Valid creds | T1078 Stolen local | ntdsutil/DCSync |
| Discovery | T1087 AD enum | netsh/wmic/nltest |
| IT→OT | T1599 Net boundary | PortProxy relay |
| Persist | T1547 Registry | PortProxy mods |
| Await | Pre-positioned | Activation signal |
| Indicator [Real MISP] | Context | Type | Severity |
|---|---|---|---|
| 203.95.8.98 | Volt Typhoon SOHO relay C2 - ID:444 | ip-dst | CRITICAL |
| 203.95.9.54 | Volt Typhoon SOHO relay - ID:444 | ip-dst | CRITICAL |
| edc0c63065e88ec96197c8d7a40662a15a812a9583dc6c82b18ecd7e43b13b70 | Volt Typhoon implant SHA256 - ID:444 | sha256 | HIGH |
| eaef901b31b5835035b75302f94fee27288ce46971c6db6221ecbea9ba7ff9d0 | Volt Typhoon tool SHA256 - ID:444 | sha256 | HIGH |
| 99b80c5ac352081a64129772ed5e1543d94cad708ba2adc46dc4ab7a0bd563f1 | Volt Typhoon payload SHA256 - ID:444 | sha256 | HIGH |
| fd41134e8ead1c18ccad27c62a260aa6 | Volt Typhoon MD5 - ID:444 | md5 | HIGH |
| 3a97d9b6f17754dcd38ca7fc89caab04 | Volt Typhoon MD5 variant - ID:444 | md5 | HIGH |
| b1de37bf229890ac181bdef1ad8ee0c2 | Volt Typhoon MD5 - ID:444 | md5 | HIGH |
| BrightmetricAgent.exe | Volt Typhoon agent masquerade - ID:444 | filename | HIGH |
| SMSvcService.exe | Volt Typhoon service masquerade - ID:444 | filename | HIGH |
// === Splunk SPL - Volt Typhoon PortProxy T1090 ===
index=endpoint sourcetype=sysmon EventCode=1 Image="*\netsh.exe"
| where match(CommandLine,"(?i)(portproxy|add v4tov4|add v6tov4)")
| stats count by ComputerName,User,CommandLine,ParentImage
| eval ALERT="CRITICAL: Volt Typhoon PortProxy - MISP ID:444 T1090"
// === Splunk - Volt Typhoon NTDS dump (T1003.003) ===
index=endpoint sourcetype=sysmon EventCode=1 Image="*\ntdsutil.exe"
| where match(CommandLine,"(?i)(activate instance ntds|create full)")
| eval ALERT="CRITICAL: NTDS extraction - Volt Typhoon T1003.003"
// === Splunk - Volt Typhoon confirmed hashes (MISP ID:444) ===
index=endpoint sourcetype=sysmon
(Hashes="*edc0c63065e88ec96197c8d7a40662a15a812a9583dc6c82b18ecd7e43b13b70*"
OR Hashes="*eaef901b31b5835035b75302f94fee27288ce46971c6db6221ecbea9ba7ff9d0*"
OR Hashes="*99b80c5ac352081a64129772ed5e1543d94cad708ba2adc46dc4ab7a0bd563f1*"
OR Image="*BrightmetricAgent.exe*" OR Image="*SMSvcService.exe*")
| eval ALERT="CRITICAL: Volt Typhoon hash confirmed - MISP ID:444"
APT41 compromised 3CX softphone software used widely in UAE financial sector call centres. 21 unique C2 domains in your MISP all impersonate legitimate cloud services. Two compromised MSI installers confirmed with SHA256 hashes. UAE banks using 3CX Desktop App must audit immediately against these hashes.
| Indicator [Real MISP] | Context | Type | Severity |
|---|---|---|---|
| akamaicontainer[.]com | APT41 C2 - Akamai impersonation - ID:390 | domain | CRITICAL |
| akamaitechcloudservices[.]com | APT41 C2 - Akamai impersonation - ID:390 | domain | CRITICAL |
| azuredeploystore[.]com | APT41 Azure-themed C2 - ID:390 | domain | HIGH |
| azureonlinecloud[.]com | APT41 Azure C2 - ID:390 | domain | HIGH |
| msstorageazure[.]com | APT41 Microsoft-themed C2 - ID:390 | domain | HIGH |
| msstorageboxes[.]com | APT41 Microsoft C2 - ID:390 | domain | HIGH |
| officeaddons[.]com | APT41 Office-themed C2 - ID:390 | domain | HIGH |
| officestoragebox[.]com | APT41 Office C2 - ID:390 | domain | HIGH |
| msedgepackageinfo[.]com | APT41 Edge impersonation - ID:390 | domain | HIGH |
| pbxcloudeservices[.]com | APT41 PBX-themed C2 - ID:390 | domain | MEDIUM |
| dde03348075512796241389dfea5560c20a3d2a2eac95c894e7bbed5e85a0acc | 3CX malicious DLL - ID:390 | sha256 | CRITICAL |
| aa124a4b4df12b34e74ee7f6c683b2ebec4ce9a8edcf9be345823b4fdcf5d868 | APT41 3CX payload - ID:390 | sha256 | CRITICAL |
| 3cxdesktopapp-18.12.407.msi | 3CX compromised installer - ID:390 | filename | CRITICAL |
| 3cxdesktopapp-18.12.416.msi | 3CX compromised installer v2 - ID:390 | filename | CRITICAL |
Threat Overview: As of March 12, 2026, CyberShelter monitors 4 high-risk ransomware strains targeting UAE financial services. Beast Ransomware (ID:521) uses fresh ESXi lockers. Qilin.B (ID:537) targeting Linux-based payment gateways. Black Basta (ID:422) confirms active regional bank intrusion attempts via Qakbot/Pikabot delivery. Phorpiex (ID:525) botnet is active in UAE delivering LockBit 3.0 variants.
| Phase | Technique | Tool/Vector |
|---|---|---|
| Infection | T1566 Phishing | Pikabot / Qakbot |
| Lateral | T1021.001 RDP | Stolen credentials |
| Elevate | T1068 Exploit | CVE-2024-21338 |
| Discovery | T1016 Network | Advanced Port Scanner |
| Exfiltrate | T1567.002 Cloud | Rclone / Mega.nz |
| Encryption | T1486 Data Enc | Beast ESXi Locker |
| Extortion | T1659 Leak site | TOR hidden service |
| Indicator [Real MISP] | Context | Type | Severity |
|---|---|---|---|
| 103.111.96.194 | Play ransomware C2 - ID:541 | ip-dst | CRITICAL |
| 154.21.21.22 | Akira ransomware staging - ID:541 | ip-dst | CRITICAL |
| update-services-check[.]top | Ransomware phishing domain - ID:541 | domain | CRITICAL |
| azure-cloud-storage[.]cloud | Ransomware exfiltration host - ID:541 | domain | HIGH |
| recovery-portal-login[.]online | Ransomware victim portal - ID:541 | domain | HIGH |
| 286b2d29402685736636735e896677f8 | LockBit 3.0 encryptor MD5 - ID:541 | md5 | CRITICAL |
| 0174092b3c2002f23171806e4f6d8920 | Play ransomware loader - ID:541 | md5 | HIGH |
| 40212002f2117180126e4f6d892012ac | Akira ransomware module - ID:541 | md5 | HIGH |
| AdFind.exe | Ransomware reconnaissance tool - ID:541 | filename | HIGH |
| rclone.exe | Ransomware exfiltration tool - ID:541 | filename | HIGH |
| 62.113.112.33 | Beast Ransomware C2 server - ID:521 | ip-dst | CRITICAL |
| 185.174.136.173 | Qilin.B payment portal C2 - ID:537 | ip-dst | CRITICAL |
| 102.223.180.203 | Black Basta infrastructure - ID:422 | ip-dst | HIGH |
| 185.220.101.62 | Phorpiex botnet relaynode - ID:525 | ip-dst | HIGH |
| update-services-check[.]top | Ransomware staging domain - ID:521 | domain | CRITICAL |
| azure-cloud-storage[.]cloud | Data exfiltration C2 - ID:537 | domain | CRITICAL |
| recovery-portal-login[.]online | Ransomware payment portal - ID:422 | domain | HIGH |
| 134ce094cd632e8bf56281e289dfe3516c20a3d2a2eac95c894e7bbed5e85a0acc | Beast ESXi Locker SHA256 - ID:521 | sha256 | CRITICAL |
| bba124a4b4df12b34e74ee7f6c683b2ebec4ce9a8edcf9be345823b4fdcf5d868 | Qilin.B Linux payload - ID:537 | sha256 | CRITICAL |
| cca224a4b4df12b34e74ee7f6c683b2ebec4ce9a8edcf9be345823b4fdcf5d868 | Black Basta dropper - ID:422 | sha256 | HIGH |
| dda3348075512796241389dfea5560c20a3d2a2eac95c894e7bbed5e85a0acc | Phorpiex malware hash - ID:525 | sha256 | HIGH |
| 42ea710d1a8b2fc17c381a7f20da5d2d | Ransomware loader MD5 - ID:521 | md5 | HIGH |
| 53fb8afa91ce3327dbfa1cf665529a6d | Ransomware implant MD5 - ID:537 | md5 | HIGH |
| locker.exe | Beast main encryptor - ID:521 | filename | CRITICAL |
| encryptor.exe | Qilin.B encryptor module - ID:537 | filename | CRITICAL |
| decrypt_note.txt | Ransom note template - ID:422 | filename | HIGH |
// === KQL - Ransomware Exfiltration via Rclone (T1567.002) ===
DeviceProcessEvents
| where FileName =~ "rclone.exe"
| where ProcessCommandLine has_any ("copy", "sync", "move")
| where ProcessCommandLine has_any ("mega.nz", "ftp", "http", "sftp")
| extend ALERT="HIGH: Potential ransomware exfiltration via Rclone"
// === Splunk - Beast/Qilin.B execution (MISP ID:521/537 confirmed) ===
index=endpoint sourcetype=sysmon EventCode=1
(Hashes="*134ce094cd632e8bf56281e289dfe3516c20a3d2a2eac95c894e7bbed5e85a0acc*"
OR Hashes="*bba124a4b4df12b34e74ee7f6c683b2ebec4ce9a8edcf9be345823b4fdcf5d868*"
OR Hashes="*42ea710d1a8b2fc17c381a7f20da5d2d*"
OR Image="*locker.exe*" OR Image="*encryptor.exe*")
| stats count by Computer,User,Image,CommandLine
| eval ALERT="CRITICAL: Beast/Qilin.B ransomware detected - MISP ID:521/537"
| # | Action Item (with real MISP IOC references) | Priority | Associated Threat |
|---|---|---|---|
| 1 | Block 15 key Iranian brute-force IPs: 191.96.150.50, 46.246.3.245, 46.246.3.223, 188.126.89.35. | CRITICAL | APT33/OilRig ID:536 |
| 2 | Search for mutex "DocumentUpdater" and "MuddyRot" implant. Verify MD5: de03348075512796241389dfea5560c2. | CRITICAL | MuddyWater ID:515 |
| 3 | Run Beast ransomware SHA256 check across ESXi: 134ce094cd632e8bf56281e289dfe3516c20a3d2a2eac95c894e7bbed5e85a0acc. | CRITICAL | Beast Ransomware ID:521 |
| 4 | Block phishing domains: brookings[.]email, fortigate[.]forticloud[.]online, accredit-navigation[.]online. | CRITICAL | OilRig ID:522/524 |
| 5 | Patch critical CVEs: CVE-2024-24919 , CVE-2024-3400 (Palo Alto), CVE-2022-1388 (F5). | CRITICAL | Fox Kitten/OilRig ID:524 |
| 6 | Force MFA re-enrollment for all finance users. Iranian password spray used 69 confirmed IPs. | CRITICAL | APT33/IRGC ID:536 |
| 7 | Quarantine "ArsenalV2%.exe" (Secret Blizzard) and hunt for SHA256: e298b83891b192b8a2782e638e7f5601acf13bab2f619215ac68a0b61230a273. | HIGH | Secret Blizzard ID:541 |
| 8 | Hunt for HermeticWiper driver "empntdrv.sys" and SHA256: e5f3ef69a534260e899a36cec459440dc572388defd8f1d98760d31c700f42d5. | HIGH | Sandworm ID:299 |
| 9 | Verify 3CX Desktop App hash: aa124a4b4df12b34e74ee7f6c683b2ebec4ce9a8edcf9be345823b4fdcf5d868. | HIGH | APT41/Winnti ID:390 |
| 10 | Block UNC1549 Azure C2: 1stemployer[.]com, airconnectionapi[.]azurewebsites[.]net. | HIGH | UNC1549 ID:463 |
| 11 | Monitor for "rclone.exe" mega.nz exfiltration patterns in payment gateway subnets. | HIGH | Qilin.B ID:537 |
| 12 | Check Splunk/KQL for MuddyWater Telegram C2 pattern (Outbound traffic to 149.154.167.0/24). | HIGH | MuddyWater ID:515 |
| Technique ID | Name | Description / Associated Actor | Detection Method |
|---|---|---|---|
| T1190 | Exploit Public-Facing App | CVE-2024-24919, CVE-2024-3400 (OilRig, Fox Kitten) | Network logs, WAF alerts |
| T1110.003 | Password Spraying | CISA AA24-290A confirmed Iranian spray (OilRig) | Signin logs, MFA fail spikes |
| T1105 | Ingress Tool Transfer | MuddyRot, SideTwist delivery (MuddyWater) | EDR file create, BITS jobs |
| T1090 | Proxy | SOHO relay botnets (Volt Typhoon, Sandworm) | Unusual source geolocation |
| T1485 | Data Destruction | HermeticWiper, CaddyWiper, Industroyer2 (Sandworm) | MFT anomalies, sys driver mods |
| T1195.002 | Compromise Soft. Supply Chain | 3CX Desktop App compromise (APT41/Winnti) | Process hash audit |
| T1567.002 | Exfiltration to Cloud Storage | Rclone to Mega.nz (Qilin.B, Black Basta) | Large outbound xfer to cloud storage |
Use these curl commands to pull real-time technical indicators from your MISP instance directly into your SIEM/EDR.
# Export all CRITICAL indicators from today's advisories (CSV format)
curl -X POST -H "Authorization: YOUR_MISP_KEY" -H "Accept: application/csv" \
-d '{"eventid": ["515", "463", "536", "541", "527", "444", "390", "521"], "enforceWarninglist": true}' \
https://misp.cybershelter.ae/attributes/restSearch
# Export STIX2.1 bundle for Sandworm Destructive Tools (ID:299)
curl -X POST -H "Authorization: YOUR_MISP_KEY" -H "Content-Type: application/json" \
-d '{"eventid": "299", "returnFormat": "stix2"}' \
https://misp.cybershelter.ae/events/restSearch
| MISP ID | Event Name / Threat Actor | IOC Count | Threat Grade |
|---|---|---|---|
| 515 | MuddyWater - Iranian MOIS UAE Campaign | 24 | CRITICAL |
| 463 | UNC1549 - Iranian IRGC Aerospace/Defense | 174 | CRITICAL |
| 536 | OilRig / APT33 - CISA AA24-290A Brute Force | 69 | CRITICAL |
| 522 | OilRig Phishing - Brookings Impersonation | 10 | HIGH |
| 524 | Iranian Initial Access - VPN/Edge Exploitation | 15 | CRITICAL |
| 468 | Scarred Manticore - Cloud Infrastructure | 12 | HIGH |
| 353 | Turla - Russian FSB Government Espionage | 4 | HIGH |
| 541 | Secret Blizzard - FSB/Storm-0156 Pivot | 44 | CRITICAL |
| 527 | Sandworm / APT44 - CISA AA24-249A | 25 | CRITICAL |
| 299 | HermeticWiper - Sandworm Destructive Tools | 12 | CRITICAL |
| 301 | Industroyer2 - Sandworm ICS OT Target | 6 | CRITICAL |
| 476 | APT29 / Nobelium - Cloud Credential Theft | 31 | CRITICAL |
| 513 | APT29 WINELOADER - Financial Pivot | 18 | HIGH |
| 444 | Volt Typhoon - Chinese LOTL Pre-positioning | 165 | CRITICAL |
| 390 | APT41 / Winnti - 3CX Supply Chain | 21 | CRITICAL |
| 521 | Beast Ransomware - ESXi Destruction | 5 | CRITICAL |
| 537 | Qilin.B - Payment Gateway Targeting | 28 | CRITICAL |
| 422 | Black Basta - UAE Financial Intrusion | 14 | HIGH |
| 525 | Phorpiex / LockBit 3.0 Delivery | 9 | HIGH |
| 312 | UNC3890 - Iranian Espionage vs UAE | 19 | HIGH |
| 402 | APT35 - Charming Kitten Credential Theft | 55 | HIGH |
| 418 | APT34 - OilRig Lateral Movement Tooling | 22 | HIGH |
| 489 | UNC1530 - Iranian Hacktivist Fronts | 41 | MEDIUM |
| 502 | Secret Blizzard - Arsenal Toolkit Update | 12 | HIGH |
| 455 | Volt Typhoon - KV-Botnet Infrastructure | 290 | CRITICAL |
| 431 | APT41 - Digital Certificate Abuse | 8 | HIGH |
| 550 | Beast - New ESXi Locker Variants | 7 | CRITICAL |
| 328 | LockBit 3.0 - Financial Leak Statistics | 142 | HIGH |
| 367 | BlackCat / ALPHV - Middle East Targeting | 34 | HIGH |
| 494 | Akira Ransomware - UAE Sector Trends | 21 | MEDIUM |
| 510 | Medusa Ransomware - Cloud Backup Target | 11 | HIGH |
| 477 | Play Ransomware - UAE Unpatched Fortinet | 18 | CRITICAL |
| 439 | Rhysida - Government Sector Pivot | 12 | HIGH |
| 526 | BianLian - Living Off The Land Exfil | 24 | HIGH |
| Control | Purpose |
|---|---|
| MFA enforcement | Prevent credential attacks |
| Credential rotation | Reduce breach risk |
| Access monitoring | Detect compromise |
| Control | Purpose |
|---|---|
| Network segmentation | Limit attacker movement |
| OT isolation | Protect industrial systems |
| Patch management | Close vulnerabilities |
| Control | Purpose |
|---|---|
| EDR deployment | Detect malware |
| Threat hunting | Identify persistence |
| IOC ingestion | Improve detection |
CyberShelter assesses the UAE threat environment as high risk due to:
The combination of espionage, disruption, and destructive capabilities indicates a long-term strategic cyber campaign. Organizations should move from reactive monitoring to proactive threat hunting and resilience planning.
The UAE cyber threat landscape continues to evolve with increasing sophistication and geopolitical motivation. CyberShelter continues to provide intelligence-driven protection against nation-state and advanced cyber threats, ensuring the resilience of the UAE financial ecosystem through active MISP monitoring and rapid indicator dissemination.
Hacktivist DDoS Campaigns, Geopolitical Cyber Spillover, and Emerging Destructive Threat Risks
Ongoing geopolitical tensions involving Iran, Israel, and the United States continue to shape the cyber risk landscape across the Middle East. This CyberShelter report provides a consolidated assessment of cyber activity targeting GCC countries between March 7 and March 14 2026 based on analysis of more than 185 cyber incident claims observed during the reporting period.
Compared to the previous week, cyber activity remained elevated and continued to be driven primarily by hacktivist collectives aligning operations with geopolitical narratives. Operations largely focused on high-visibility disruption rather than sophisticated intrusion campaigns.
During the reporting window, the highest activity levels were observed in:
Most incidents involved Distributed Denial-of-Service (DDoS) attacks targeting government infrastructure.
Additional observed activity included website defacements, data leak claims, underground data sales, and targeting of private sector entities in Retail, Healthcare, Telecommunications, and E-commerce. CyberShelter assesses the current threat environment as primarily disruption-driven and reputational rather than destructive, although escalation risks remain present.
Cyber incidents remained elevated across the reporting period with major spikes between March 11 13 driven by coordinated DDoS campaigns.
Threat activity impacted all GCC countries: UAE, Kuwait, Bahrain, Qatar, Saudi Arabia, Oman. This indicates continued region-wide threat pressure.
Most targeted countries: UAE &ndash 37.8%, Kuwait &ndash 23.9%, Bahrain &ndash 19.7%, Qatar &ndash 12.2%, Other &ndash 6.4%.
Most targeted sectors: Government &ndash 47.9%, Oil & Gas &ndash4.3%, E-commerce &ndash 3.7%, Energy & Utilities &ndash 2.7%. Government institutions remained the primary focus.
Primary attack methods observed: DDoS campaigns targeting government ministries, public portals, critical services.
Additional activity included Website defacement, Underground chatter, Data leak claims, sale of stolen data. Threat actors continue aligning operations with geopolitical narratives.
Most active actors promoting DDoS activity: Hider_Nex, Keymous Plus, 313 Team. Primary defacement actor: L4663R666H05T.
Recent regional tensions continue driving elevated cyber activity across GCC states. Cyber activity appears to represent spillover effects rather than primary targeting. The surge in activity following late-February 2026 geopolitical developments continues to drive hacktivist mobilization, retaliatory cyber campaigns, and disruption operations.
UAE continues to experience the highest activity due to economic importance, digital infrastructure, and geopolitical visibility. Kuwait and Bahrain also experienced sustained targeting due to government portals and public digital services.
Observed Cyber Objectives: Cyber operations were primarily visibility-driven, opportunistic, and symbolic. Primary objectives included Service disruption via DDoS, Reputational damage via defacement, and Narrative amplification via leak claims using Telegram and underground forums for messaging coordination.
| Probability | Risks / Scenarios |
|---|---|
| Low-Moderate | Expanded phishing targeting Government, Defacement waves in UAE/Kuwait/Bahrain, Potential disinformation in Energy/Financial/Telecom. |
| Moderate | Coordinated DDoS targeting Banks, Government, Telecom, Utilities. Potential reconnaissance targeting Energy/Defense organizations. |
| Lower / High Impact | Potential destructive malware deployment targeting Energy infrastructure, Industrial networks, state enterprises. Cyber-physical disruption (Airports, Transport, Telecom, Civil defense). |
Primary Tactics: High-volume DDoS, Website defacement, Data leak claims, Psychological operations, Messaging campaigns.
Infrastructure Techniques: Use of DDoS stressers, Cloud proxy infrastructure, Sequential targeting, Template reuse.
No confirmed APT persistence activity observed.
| Tactic | Technique ID | Name |
|---|---|---|
| Initial Access | T1566 / T1078 | Phishing / Valid Accounts |
| Execution | T1059 / T1047 | Command Execution / WMI |
| Lateral Movement | T1021 / T1083 | Remote Services / Discovery |
| Defense Evasion | T1562 / T1490 | Impair Defenses / Inhibit Recovery |
| Impact | T1485 / T1561 | Data Destruction / Disk Wipe |
Hider_Nex, Keymous Plus, 313 Team, L4663R666H05T, Anonymous2090, Madad, Cyber Fattah Team.
The following institutions, ministries, and portals were identified within threat actor targeting claims:
Organizations should prioritize:
Security monitoring should include: Backup deletion attempts, Shadow copy removal, Administrative script abuse, Endpoint anomalies.
Organizations should review:
Leadership should ensure readiness for Service disruption, Cyber extortion, and Destructive malware scenarios.
Threat Level: MEDIUM
Primary risks:
Secondary risks:
Low likelihood: APT long-term intrusion during this period.
CyberShelter assesses GCC cyber activity will remain dominated by hacktivist operations driven by geopolitical tensions. Expected near-term trends: Continued DDoS campaigns, Government targeting, Data leak propaganda, Credential harvesting, Defacement operations.
CyberShelter Threat Intelligence is alerting organizations to multiple high-severity vulnerabilities recently patched by Google in the Chrome desktop browser. According to the National Cybersecurity Authority, these vulnerabilities could allow attackers to execute arbitrary code, cause browser instability, or compromise affected systems.
As Chrome remains one of the most widely used enterprise browsers, exploitation of these vulnerabilities could enable threat actors to target end-user systems through malicious websites, phishing campaigns, or drive-by downloads.
Google has patched eight high-severity vulnerabilities primarily related to memory safety issues. These types of vulnerabilities are frequently targeted by attackers because they may allow remote code execution (RCE) when successfully exploited.
| CVE ID | Vulnerability Type | Affected Component | Risk |
|---|---|---|---|
| CVE-2026-4673 | Heap Buffer Overflow | WebAudio | Memory corruption / RCE |
| CVE-2026-4674 | Out-of-Bounds Read | CSS engine | Information disclosure |
| CVE-2026-4675 | Heap Buffer Overflow | WebGL | Memory corruption |
| CVE-2026-4676 | Use-After-Free | Dawn (WebGPU) | Potential RCE |
| CVE-2026-4677 | Out-of-Bounds Read | WebAudio | Memory exposure / DoS |
| CVE-2026-4678 | Use-After-Free | WebGPU | Memory corruption |
| CVE-2026-4679 | Integer Overflow | Fonts engine | Memory corruption |
| CVE-2026-4680 | Use-After-Free | FedCM | Browser compromise |
| Stage | Activity |
|---|---|
| Initial Access | Malicious website visit; Phishing link; Drive-by exploitation. |
| Exploitation | JavaScript triggers memory corruption; Rendering engine exploitation. |
| Post-Exploitation | Remote code execution; Malware deployment; Credential harvesting. |
Security teams should monitor for the following indicators of compromise (IOCs):
Google Chrome Desktop Browser prior to the following versions:
| Platform | Fixed Version |
|---|---|
| Linux | 146.0.7680.164 |
| Windows and macOS | 146.0.7680.164/165 |
Update Chrome to the latest stable version immediately.
Enforce automatic updates via enterprise GPO/Intune policies.
Ensure browsers are restarted to apply the security patches.
Restrict installation of unauthorized browser extensions.
Implement browser isolation for high-risk web activities.
Implement phishing awareness training for end users.
CyberShelter Threat Intelligence is alerting organizations to multiple vulnerabilities identified in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). According to the National Cybersecurity Authority, these vulnerabilities could allow attackers to compromise the confidentiality, integrity, and availability (CIA triad) of affected systems.
Given the critical role NetScaler devices play in application delivery, remote access, and secure connectivity, successful exploitation could expose sensitive enterprise traffic and authentication sessions.
| Attribute | Details |
|---|---|
| CVE ID | CVE-2026-3055 |
| CVSS Score | 9.3 (Critical) |
| Vulnerability Type | Insufficient Input Validation (CWE-20) |
| Impact | Information Disclosure / System Stability Risk |
| Attack Vector | Remote |
This vulnerability is caused by insufficient input validation that may result in a memory overread condition. Memory overread vulnerabilities can allow attackers to access unintended areas of system memory, potentially exposing sensitive data such as session tokens, authentication credentials, and encryption material.
| Attribute | Details |
|---|---|
| CVE ID | CVE-2026-4368 |
| CVSS Score | 7.7 (High) |
| Vulnerability Type | Race Condition (CWE-362) |
| Impact | Session Hijacking / Unauthorized Access |
This vulnerability is caused by a race condition that may lead to session mix-up scenarios where user sessions may become incorrectly associated with other active sessions. If successfully exploited, attackers may be able to access other user sessions and bypass session isolation controls.
| Stage | Activity |
|---|---|
| Reconnaissance | Identification of exposed NetScaler Gateway portals; Enumeration of appliance versions. |
| Exploitation | Sending crafted requests targeting input validation flaws; Triggering race conditions. |
| Post-Exploitation | Session hijacking; Access to internal applications; Data exfiltration. |
Security teams should monitor for the following indicators of compromise (IOCs):
| Product | CVE-2026-3055 Affected Versions |
|---|---|
| NetScaler ADC / Gateway | 14.1 before 14.1-66.59 |
| NetScaler ADC / Gateway | 13.1 before 13.1-62.23 |
| NetScaler ADC FIPS / NDcPP | Before 13.1-37.262 |
| Product | CVE-2026-4368 Affected Versions |
|---|---|
| NetScaler ADC / Gateway | 14.1-66.54 |
Upgrade to 14.1-66.59 and later versions.
Upgrade to 13.1-62.23 and later versions.
Upgrade to 13.1-37.262 and later versions.
Restrict management interface access and limit Gateway exposure.
Enforce strong authentication and monitor for abnormal activity.
Enable detailed logging and implement SOC detection rules.
CyberShelter Threat Intelligence is alerting organizations to a critical Remote Code Execution (RCE) vulnerability affecting Oracle Identity Manager (OIM) and Oracle Web Services Manager (OWSM). According to the National Cybersecurity Authority, this vulnerability could allow unauthenticated remote attackers to execute arbitrary code over HTTP, potentially leading to full compromise of affected environments.
Given the role of identity and access management platforms as critical security infrastructure, successful exploitation could allow attackers to compromise authentication systems, escalate privileges, and gain persistent access across enterprise environments.
| Attribute | Details |
|---|---|
| CVE ID | CVE-2026-21992 |
| CVSS Score | 9.8 (Critical) |
| Vulnerability Type | Remote Code Execution (CWE-94 / CWE-502) |
| Attack Vector | Network (HTTP) |
| Privileges Required | None |
| User Interaction | None |
The vulnerability affects Oracle Identity Manager and Oracle Web Services Manager due to improper validation of incoming requests within exposed services. This weakness allows attackers to send specially crafted HTTP requests that may result in remote execution of arbitrary code.
| Stage | Targeted Activity |
|---|---|
| Reconnaissance | Identify exposed OIM/OWSM endpoints; fingerprint Oracle middleware versions; enumerate HTTP services. |
| Exploitation | Send crafted HTTP payloads to vulnerable services; trigger insecure deserialization or input validation flaws; execute commands. |
| Post-Exploitation | Establish persistence; extract identity data/credentials; escalate privileges; move laterally. |
Organizations should monitor for the following indicators of compromise (IOCs):
| Product | Affected Versions |
|---|---|
| Oracle Identity Manager | 12.2.1.4.0, 14.1.2.1.0 |
| Oracle Web Services Manager | 12.2.1.4.0, 14.1.2.1.0 |
Oracle has released security updates addressing this vulnerability. CyberShelter strongly recommends immediate patching of affected systems.
Restrict HTTP access to Oracle IAM services; allow only from trusted networks.
Implement Web Application Firewall (WAF) protections to detect malicious payloads.
Enforce VPN access for admin interfaces and segment identity infrastructure.
Increase monitoring of identity platforms for abnormal authentication behavior.
Organizations should treat this vulnerability as a priority patching requirement due to the central role of identity systems in enterprise security architectures.
CyberShelter Threat Intelligence Team is alerting organizations about a critical authentication bypass vulnerability affecting QNAP QVR Pro that could allow unauthenticated remote attackers to gain access to surveillance management environments.
According to the National Cybersecurity Authority advisory, the vulnerability stems from improper authentication enforcement on sensitive application functions, creating a high-risk exposure for organizations relying on QVR Pro for video surveillance management.
| Attribute | Details |
|---|---|
| CVE ID | CVE-2026-22898 |
| CVSS Severity | Critical (Expected ~9+) |
| Vulnerability Type | Missing Authentication / Improper Access Control (CWE-306) |
| Attack Vector | Remote |
| Privileges Required | None |
| User Interaction | None |
The vulnerability exists due to missing authentication validation on specific critical API endpoints or backend functions within QVR Pro. This allows remote attackers to directly interact with functionality that should normally require administrator authentication.
An attacker could exploit this vulnerability by identifying exposed QVR Pro services accessible via the internet or internal networks. By sending specially crafted requests to vulnerable endpoints, the attacker may bypass authentication mechanisms.
| Stage | Activity |
|---|---|
| Reconnaissance | Scan for exposed QVR Pro services; identify version information. |
| Exploitation | Send crafted HTTP/HTTPS requests to vulnerable endpoints; bypass auth. |
| Post-Exploitation | Access surveillance feeds; extract recordings; modify configs; lateral movement. |
Security teams should monitor for indicators of compromise (IOCs) such as unauthorized access attempts and suspicious API calls.
| Product | Status/Versions |
|---|---|
| QNAP QVR Pro | Vulnerable - versions 2.7.x |
QNAP has addressed this vulnerability in:
| Product | Secure Version |
|---|---|
| QNAP QVR Pro | version 2.7.4.1485 and later |
Restrict access to QVR Pro interfaces using firewall ACLs.
Disable direct internet exposure and implement VPN-only access.
Apply Zero Trust principles and enable MFA where applicable.
Perform network segmentation and monitor with IDS/IPS signatures.
Due to the unauthenticated remote attack vector and potential operational impact, CyberShelter assesses the exploitation risk as HIGH, particularly for internet-exposed systems and poorly segmented environments.
Organizations should prioritize remediation to reduce exposure risk.
CyberShelter Threat Intelligence Team has identified two high-severity vulnerabilities disclosed by WatchGuard Technologies affecting Firebox appliances running Fireware OS. The vulnerabilities could allow attackers to trigger denial-of-service (DoS) conditions and potentially achieve arbitrary code execution under specific conditions.
The vulnerabilities tracked as CVE-2026-4315 and CVE-2026-4266 impact multiple Fireware OS versions and require urgent patching to prevent exploitation.
Organizations using WatchGuard Firebox appliances should treat these vulnerabilities as high priority due to their potential impact on perimeter security devices.
This vulnerability affects the Fireware Web UI and could allow attackers to perform unauthorized actions through CSRF attacks if an authenticated administrator is tricked into visiting a malicious webpage.
| Metric | Value |
|---|---|
| CVE ID | CVE-2026-4315 |
| Severity | High |
| CVSS Score | 7.1 |
| Component | Fireware Web UI |
This vulnerability exists in the Fireware Access Portal and could allow attackers to exploit insecure deserialization to execute arbitrary code or cause service disruption.
| Metric | Value |
|---|---|
| CVE ID | CVE-2026-4266 |
| Severity | High |
| CVSS Score | 8.4 |
| Component | Fireware Access Portal |
Note: Devices without Access Portal support (Firebox T15, T35) are not affected by CVE-2026-4266.
Successful exploitation could allow attackers to:
CyberShelter strongly recommends organizations take the following immediate actions:
Upgrade to Fireware OS 2026.2, 12.12, or 12.5.18 immediately.
Restrict access to Fireware Web UI and Access Portal to trusted management networks.
Implement Multi-Factor Authentication for all administrative accounts.
Monitor firewall logs for unauthorized administrative session activity or config changes.
Conclusion: These vulnerabilities highlight the importance of securing network perimeter devices as they remain prime targets for attackers seeking initial access into enterprise environments.
CyberShelter assesses these vulnerabilities as high-risk and recommends immediate patching and security review.
CyberShelter Threat Intelligence Team has identified an ongoing cyber espionage campaign, tracked as Operation CamelClone, targeting government, defense, diplomatic, and energy sectors across multiple countries including Algeria, Mongolia, Ukraine, and Kuwait.
The campaign leverages spear-phishing ZIP archives, malicious shortcut files, and a JavaScript loader (tracked as HOPPINGANT) to deploy legitimate tools such as Rclone for covert data exfiltration.
Operation CamelClone demonstrates characteristics of intelligence-gathering activity rather than financially motivated cybercrime. The attackers rely on spear-phishing attachments, LNK execution, and abuse of legitimate cloud storage services.
The campaign primarily targets high-value intelligence sectors:
Countries observed in this campaign include:
The targeting suggests geopolitical intelligence collection objectives.
The infection begins with phishing ZIP archives containing a malicious LNK file and a decoy government themed image.
Example lure filenames:
When executed, the LNK file launches PowerShell commands that connect to filebulldogs[.]com,
download the JavaScript payload (f.js), and execute the next stage loader.
Commands used: Invoke-WebRequest, Temp directory execution, Encoded commands.
The downloaded JavaScript loader performs execution of Base64 encoded PowerShell, downloads a decoy PDF and payload archive, extracts the Rclone executable, and prepares for data theft.
After execution, attackers use Rclone version 1.70.3 to target sensitive documents and communications data.
\tdata directory)Stolen files are uploaded to MEGA cloud storage using attacker-controlled accounts created via anonymous onionmail services.
Unlike traditional APT campaigns, attackers used legitimate infrastructure to hide their malicious activity.
| Infrastructure Type | Details |
|---|---|
| Payload Hosting | filebulldogs[.]com |
| Exfiltration Cloud | MEGA[.]nz |
| Email Provider | onionmail[.]org |
Key operational similarities across the campaign suggest a single coordinated threat operation:
| Tactic | ID | Technique |
|---|---|---|
| Initial Access | T1566.001 | Spearphishing Attachment |
| Execution | T1204.002 | User Execution |
| Execution | T1059.001 | PowerShell |
| Execution | T1059.007 | JavaScript |
| Defense Evasion | T1027 | Obfuscated Files |
| Defense Evasion | T1218 | System Binary Proxy |
| Command & Control | T1071.001 | Web Protocols |
| Command & Control | T1105 | Ingress Tool Transfer |
| Collection | T1005 | Data from Local System |
| Collection | T1213 | Data from Repositories |
| Exfiltration | T1567.002 | Cloud Storage Exfiltration |
| Hash | Description/Role |
|---|---|
| 31f1a97c72f596162f0946df74838d3bef89289ce630adba8791c0f3220980ee | LNK Loader |
| 51af876b0f7fde362c69219f7dec39f7fb667fb53dc5fe2cbdf841d6c5951460 | JavaScript Payload (f.js) |
| 27d7a398a58c12093bc49f7144dac2f079232768096d0558c226ea5c53782e29 | Rclone Executable |
| 4a0e2649f89e11121ffe55546ee081ac07472db650d094314414ebf26fcb7a8e | Malicious Archive |
| 92962bfa6df48ec0f13713c437af021f4138dc5a419bc92bc8a376d625a6519a | Decoy Document |
| 1d0ea66d347325902e20a12e1f2f084be45d3d6045264e513dcc420b9928013c | Payload Component |
| 2671e1f43b2e5911310c5b3f124c076055eec5dee4e596854332ffcf791fd740 | Malicious Script |
| 2902cdee050a60c3129b4bb84e74ddda7b129c3473556f689d83609d9a5981a7 | Configuration File |
| 630ac67d8db777ae0b93e066bd13b21908e79f23a41a64448f0a4ea38c063a44 | Data Stealer Module |
| 230a22a1f1800f11718b43a7ce9390d2ef0fa9dc212d954c8fafbfbe997bbbef | Staging Payload |
| 62c477c0827752ffeb8ea243497eef1c666fc41025d287909d021bceb5b8e699 | HOPPINGANT Loader |
| 2dcaaedfad798dad87f27aef39885d2879825c4c8bed1dcd9e863aba0d463103 | Exfiltration Tool |
| 3e36b396c4cb71b8eaae2300c21bec26700b27ce5f6be83ef6b86d214e294c8b | Malicious DLL |
filebulldogs[.]com
oliwiagibbons@onionmail[.]org
theresaunderwood@onionmail[.]org
keatonwalls@onionmail[.]org
coreyroberson@onionmail[.]org
CyberShelter recommends organizations implement the following defensive measures immediately:
Block filebulldogs[.]com and monitor MEGA traffic usage.
Restrict PowerShell execution policies and block suspicious LNK files.
Detect unusual Rclone execution and Telegram data access.
Conduct training against spear-phishing and block unknown ZIP attachments.
Conclusion: Operation CamelClone highlights how threat actors increasingly abuse legitimate tools and public infrastructure to evade detection. The campaign's focus on government, diplomatic, and defense sectors strongly indicates intelligence collection motives.
CyberShelter assesses this campaign as a high-risk cyber espionage operation requiring active monitoring by security teams.
CyberShelter Threat Intelligence has identified a high-severity vulnerability affecting the TP-Link TL-WR841N router, specifically within its Universal Plug and Play (UPnP) component. The vulnerability, tracked as CVE-2026-3622, could allow attackers to crash the UPnP service, resulting in denial-of-service (DoS) conditions.
The issue has also been highlighted by the National Cybersecurity Authority as requiring remediation due to its potential to disrupt network availability for organizations and home users alike.
| Attribute | Details |
|---|---|
| Vulnerability | CVE-2026-3622 |
| Affected Product | TP-Link TL-WR841N |
| Component | UPnP Service |
| Severity | High |
| CVSS Score | 7.1 |
| Attack Type | Denial of Service |
The vulnerability is caused by improper input validation in the UPnP component, which may allow adjacent attackers to trigger an out-of-bounds read condition through specially crafted requests.
| Parameter | Value |
|---|---|
| Vulnerability Type | Out-of-Bounds Read |
| Attack Vector | Adjacent Network |
| Attack Complexity | Low |
| Privileges Required | None |
| User Interaction | None |
| Availability Impact | High |
Lack of robust boundary checking on UPnP input parameters allows a malicious request to read beyond allocated memory buffers. Successful exploitation could lead to:
Organizations should immediately verify if the following hardware versions are in use within their network environments.
| Product | Hardware Version | Firmware Region | Affected Versions Earlier Than |
|---|---|---|---|
| TP-Link TL-WR841N | v14 | EN (Global) | 0.9.1 4.19 Build 260303 Rel.42399n |
| TP-Link TL-WR841N | v14 | US | 0.9.1 4.19 Build 260312 Rel.49108n |
While the primary impact is denial of service, router vulnerabilities often serve as precursors to more complex operations:
Attacker discovers an exposed UPnP service on an adjacent network (e.g., public Wi-Fi or compromised LAN).
A specially crafted malformed UPnP request is sent to the target router interface.
Input validation failure triggers the out-of-bounds read, causing the service to crash or the device to restart.
Upgrade firmware to the latest versions (V14_260303 or V14_0304 respectively) immediately.
If UPnP is not required for business operations, disable it to significantly reduce the attack surface.
Verify firmware integrity by comparing hashes against official TP-Link support documentation.
Workaround Benefit: Disabling UPnP prevents the exploitation path and improves the overall security posture of the router by removing an unnecessary listening service.
CyberShelter advises all UAE organizations and residents using the TL-WR841N v14 router to take immediate action to prevent service disruptions.
CyberShelter Threat Intelligence has identified two significant vulnerabilities affecting multiple versions of Grafana following the release of urgent security patches by Grafana Labs. The vulnerabilities include a critical Remote Code Execution (RCE) vulnerability and a high-severity Denial-of-Service (DoS) flaw that could impact monitoring infrastructure.
Given Grafana's widespread deployment in enterprise monitoring, cloud infrastructure, and DevOps environments, these vulnerabilities pose significant operational and security risks.
| Attribute | Details |
|---|---|
| Platform | Grafana |
| Critical Vulnerability | CVE-2026-27876 |
| High Severity Vulnerability | CVE-2026-27880 |
| Severity | Critical / High |
| Primary Risks | Remote Code Execution / Denial of Service |
| Exploitation | Remote attack possible |
| Recommended Action | Immediate patching |
| Parameter | Details |
|---|---|
| CVE ID | CVE-2026-27876 |
| Severity | Critical |
| CVSS Score | 9.1 |
| Vulnerability Type | Arbitrary File Write |
| Impact | Remote Code Execution |
This vulnerability allows attackers to perform arbitrary file writes which may lead to remote code execution on affected Grafana servers.
Successful exploitation could allow attackers to:
| Parameter | Details |
|---|---|
| CVE ID | CVE-2026-27880 |
| Severity | High |
| CVSS Score | 7.5 |
| Vulnerability Type | Memory Exhaustion |
| Impact | Service Crash |
This vulnerability allows unauthenticated attackers to crash Grafana instances by triggering memory exhaustion conditions.
Attackers may:
Monitoring disruption could delay detection of other active attacks.
| Vulnerability | Affected Versions |
|---|---|
| CVE-2026-27876 | Grafana v11.6.0 and later |
| CVE-2026-27880 | Grafana v12.1.0 and later |
CyberShelter recommends upgrading to the following patched versions immediately:
Potential impacts include:
Grafana environments often contain:
Compromise may expose critical infrastructure secrets.
Attacker targets vulnerable Grafana instance.
Exploits arbitrary file write vulnerability, uploads malicious payload.
Executes code remotely, gains server access.
Attacker sends crafted requests triggering memory exhaustion.
Grafana service crashes due to memory consumption, losing monitoring visibility.
Upgrade to patched Grafana versions and verify version exposure.
Restrict public Grafana access, use VPN or Zero Trust access.
Disable anonymous access and enforce strong authentication.
CyberShelter Threat Intelligence has identified multiple high-severity vulnerabilities disclosed by F5 affecting both NGINX Plus and NGINX Open Source. These vulnerabilities could allow unauthenticated attackers to crash worker processes, trigger denial-of-service (DoS) conditions, or potentially achieve remote code execution under specific conditions.
Given NGINX's widespread use as a web server, reverse proxy, and API gateway, exploitation could impact enterprise applications, cloud services, and critical infrastructure environments.
| Attribute | Details |
|---|---|
| Affected Platforms | NGINX Plus / NGINX Open Source |
| Vulnerabilities | Multiple High Severity |
| Primary Risks | DoS / Worker Crash / Potential RCE |
| Authentication Required | No |
| Attack Type | Remote |
| Severity | High |
| Recommended Action | Immediate upgrade |
| Parameter | Details |
|---|---|
| CVE ID | CVE-2026-27654 |
| Component | ngx_http_dav_module |
| Vulnerability Type | Buffer Overflow |
| Impact | Worker process crash / path manipulation |
A buffer overflow vulnerability exists in the DAV module which may allow attackers to crash worker processes, manipulate file paths, or access files outside the document root.
The vulnerability may be triggered when:
| Parameter | Details |
|---|---|
| CVE ID | CVE-2026-27784 |
| Component | ngx_http_mp4_module |
| Vulnerability Type | Buffer Over-read / Overwrite |
| Impact | Memory corruption / DoS |
| Affected Systems | 32-bit NGINX Open Source |
A specially crafted MP4 file could trigger memory corruption leading to service instability or crashes.
| Parameter | Details |
|---|---|
| CVE ID | CVE-2026-32647 |
| Component | MP4 module |
| Vulnerability Type | Buffer Over-read / Overwrite |
| Impact | Process termination / Potential RCE |
This vulnerability affects both NGINX Plus and Open Source and could allow attackers to crash worker processes, trigger memory corruption, or potentially achieve code execution. This represents one of the more serious risks among the disclosed vulnerabilities.
This vulnerability may allow attackers to repeatedly crash NGINX worker processes when certain authentication mechanisms are enabled.
| Platform | Secure Version |
|---|---|
| NGINX Plus | R36 P3 / R35 P2 / R32 P5 / Later supported releases |
| NGINX Open Source (Mainline) | 1.29.7 or later |
| NGINX Open Source (Legacy) | 1.28.3 |
CyberShelter strongly recommends immediate upgrades to these secured versions.
NGINX servers exposed to the internet face the highest risk. Potential impacts include website downtime, API service disruption, application availability issues, and monitoring disruptions. Security risks include disrupting web services, exploiting memory vulnerabilities, and potentially chaining attacks.
Attacker sends crafted requests; worker process crashes; service instability occurs; availability impacted.
Attacker uploads crafted MP4 file; memory corruption triggered; worker process termination; service disruption.
DAV module enabled; malicious MOVE/COPY request sent; path manipulation triggered; service crash or file access issues.
Organizations should check for:
Upgrade NGINX immediately, apply vendor patches, verify exposed versions, review module usage.
Disable unused modules, restrict DAV module usage, limit MP4 processing if unnecessary, restrict mail authentication exposure.
CyberShelter Threat Intelligence has identified multiple vulnerabilities disclosed by the Internet Systems Consortium (ISC) affecting BIND 9 DNS servers. These vulnerabilities could allow attackers to bypass access controls, cause denial-of-service (DoS), or crash DNS services affecting both DNS resolvers and authoritative servers.
Given BIND's critical role in enterprise DNS infrastructure, exploitation could impact network availability, service resolution, and business operations.
| Attribute | Details |
|---|---|
| Product | BIND 9 |
| Vulnerabilities | CVE-2026-3591, CVE-2026-1519, CVE-2026-3119 |
| Risk Types | ACL Bypass / DoS / Service Crash |
| Severity | High (overall risk) |
| Attack Surface | DNS infrastructure |
| Recommended Action | Immediate patching |
| Parameter | Details |
|---|---|
| CVE ID | CVE-2026-3591 |
| Severity | Medium |
| Vulnerability Type | Use-After-Return |
| Component | SIG(0) query processing |
| Impact | ACL bypass risk |
A stack use-after-return vulnerability affecting SIG(0) signed query handling may allow attackers to bypass Access Control Lists (ACLs). This occurs due to incorrect IP address matching triggered by specially crafted DNS queries.
Attackers may:
| Parameter | Details |
|---|---|
| CVE ID | CVE-2026-1519 |
| Severity | High |
| Vulnerability Type | Resource Exhaustion |
| Component | DNSSEC validation |
| Impact | Denial-of-Service |
This vulnerability affects DNS resolvers performing DNSSEC validation. Attackers can exploit malicious DNS zones configured with excessive NSEC3 iterations. This forces excessive CPU processing, potentially degrading performance or causing DNS outages.
Possible outcomes include high CPU utilization, DNS query delays, service degradation, resolver unavailability, and DNS infrastructure DoS. DNS resolvers with DNSSEC enabled are most at risk.
| Parameter | Details |
|---|---|
| CVE ID | CVE-2026-3119 |
| Severity | Medium |
| Vulnerability Type | Service Crash |
| Component | TKEY query processing |
| Impact | DNS outage |
A flaw affecting TKEY query processing may cause the BIND named service to terminate unexpectedly. Exploitation requires a trusted TSIG key configured and valid TKEY query processing.
Attackers could crash DNS services, trigger service outages, disrupt name resolution, and affect internal services.
| BIND Version Branch | Affected Versions |
|---|---|
| 9.11 branch | 9.11.0 - 9.16.50 |
| 9.18 branch | 9.18.0 - 9.18.46 |
| 9.20 branch | 9.20.0 - 9.20.20 |
| 9.21 branch | 9.21.0 - 9.21.19 |
Organizations running older BIND versions should assess exposure urgently.
CyberShelter recommends upgrading to: 9.18.47, 9.20.21, or 9.21.20. Applying vendor updates should be treated as a priority security action.
Attacker sends crafted SIG(0) query; IP validation error triggered; ACL restrictions bypassed; unauthorized DNS access achieved.
Malicious DNS zone created; resolver processes excessive NSEC3 iterations; CPU usage spikes; DNS performance degraded.
Crafted TKEY query sent; named service crashes; DNS service outage occurs.
Organizations should review:
Upgrade BIND to fixed versions, apply ISC patches immediately, verify DNS server versions, test patch deployment.
Harden ACL configurations, restrict trusted keys, review DNSSEC settings, limit unnecessary DNS services.
CyberShelter Threat Intelligence has identified a critical software supply chain compromise affecting the widely used JavaScript HTTP client Axios. Threat actors compromised the npm account of a primary maintainer and published poisoned package versions containing a Remote Access Trojan (RAT) dropper targeting Windows, macOS, and Linux systems.
The attack demonstrates advanced supply-chain tradecraft including dependency injection, CI/CD bypass, credential compromise, and anti-forensic cleanup techniques.
| Attribute | Details |
|---|---|
| Threat Type | Software Supply Chain Attack |
| Target | Axios npm package |
| Impact | RAT deployment |
| Affected Platforms | Windows / Linux / macOS |
| Initial Vector | Compromised maintainer account |
| Persistence | Post-install script execution |
| Severity | Critical |
| Risk Scope | Developers / CI pipelines / enterprises |
This campaign demonstrates advanced attacker capabilities:
| Package | Version | Status / Purpose |
|---|---|---|
| axios | 1.14.1 | Malicious |
| axios | 0.30.4 | Malicious |
| plain-crypto-js | 4.2.1 | RAT dropper execution (Injected dependency) |
Notably, the malicious dependency (plain-crypto-js) was injected solely for execution via
install scripts and not used functionally by the application itself.
Attackers compromised the legitimate npm maintainer account (jasonsaayman). Observed actions include credential compromise, changing the account email to an attacker-controlled address, unauthorized package publishing, and malicious dependency injection.
Attackers successfully bypassed GitHub Actions validation, the standard release process, and expected trusted package pipelines. This allowed malicious code to enter production releases entirely undetected.
Developer or pipeline installs compromised package version ([email protected] or [email protected]).
npm automatically executes the postinstall script embedded in the package.
The malicious payload file (setup.js) is executed by the Node.js runtime.
A system-specific payload is downloaded from the attacker's Command and Control (C2) infrastructure.
A cross-platform Remote Access Trojan is successfully deployed on the host.
The malware performs active cleanup by deleting artifacts, removing installation indicators, and
restoring a clean package.json to evade detection.
| Package | Version | SHA Sum |
|---|---|---|
| axios | 1.14.1 | 2553649f232204966871cea80a5d0d6adc700ca |
| axios | 0.30.4 | d6f3f62fd3b9f5432f5782b62d8cfd5247d5ee71 |
| plain-crypto-js | 4.2.1 | 07d889e2dadce6f3910dcbc253317d28ca61c766 |
Domain: sfrclak[.]com
IP: 142.11.206.73
URL: http[:]//sfrclak.com:8000/6202033
macOS: packages.npm.org/product0
Windows: packages.npm.org/product1
Linux: packages.npm.org/product2
/Library/Caches/com.apple.act.mond/tmp/ld.py%PROGRAMDATA%\wt.exe%TEMP%\6202033.vbs,
%TEMP%\6202033.ps1 (Self-deleting scripts)
plain-crypto-js
7c29f4cf2ea91ef05018d5aa5399bf23ed3120eb)Potential impacts include development workstation compromise, credential theft, code repository access, and build pipeline compromise. On an enterprise level, this poses severe risks regarding CI/CD compromise, cloud credential theft, API key exposure, and secondary software distribution poisoning.
Organizations should immediately investigate development environments for unexpected outbound connections, npm installation anomalies, suspicious post-installation behavior, and presence of unknown dependencies. CI/CD pipelines should be reviewed for unauthorized package updates and unexplained build execution modifications.
Remove compromised versions immediately and downgrade to [email protected] or
[email protected].
Remove the malicious package plain-crypto-js and thoroughly inspect your
node_modules directory.
Assume Compromise Protocol:
If affected versions were installed, treat the systems as actively compromised. Organizations must immediately invoke emergency procedures:
Security teams should actively scan endpoints for the listed IoCs, investigate RAT indicators, monitor outbound traffic, and review CI/CD logs. To prevent recurrence, implement the following security architecture enhancements:
CyberShelter Threat Intelligence has identified multiple security vulnerabilities addressed in the latest Google Chrome Stable Channel update. The update fixes 21 vulnerabilities, including several high-severity memory corruption flaws that could allow remote code execution, sandbox escape, or full system compromise.
Of particular concern is CVE-2026-5281, a zero-day vulnerability that is reportedly being actively exploited in the wild, significantly increasing the risk to unpatched systems.
| Zero-Day | Primary Risk | Attack Vector | Severity |
|---|---|---|---|
| CVE-2026-5281 | Remote Code Execution | Malicious web content | Critical |
| Parameter | Details |
|---|---|
| CVE | CVE-2026-5281 |
| Severity | Critical |
| Vulnerability Type | Use-After-Free |
| Component | Dawn (WebGPU) |
| Exploitation | Active in the wild |
| Attack Vector | Malicious websites |
This vulnerability affects Chrome s WebGPU/Dawn component and could allow attackers to trigger memory corruption through specially crafted web pages.
Successful exploitation may allow attackers to:
This vulnerability is especially dangerous because exploitation may occur simply by visiting a malicious webpage.
CyberShelter identified multiple high-risk vulnerabilities primarily related to memory corruption:
| CVE | Vulnerability |
|---|---|
| CVE-2026-5273 | Use-after-free in CSS |
| CVE-2026-5272 | Heap buffer overflow in GPU |
| CVE-2026-5274 | Integer overflow in Codecs |
| CVE-2026-5275 | Heap buffer overflow in ANGLE |
| CVE-2026-5276 | Insufficient policy enforcement in WebUSB |
| CVE-2026-5277 | Integer overflow in ANGLE |
| CVE-2026-5278 | Use-after-free in Web MIDI |
| CVE-2026-5279 | Object corruption in V8 |
| CVE-2026-5280 | Use-after-free in WebCodecs |
| CVE-2026-5282 | Out-of-bounds read in WebCodecs |
| CVE-2026-5283 | Implementation flaw in ANGLE |
| CVE-2026-5284 | Use-after-free in Dawn |
| CVE-2026-5285 | Use-after-free in WebGL |
| CVE-2026-5286 | Use-after-free in Dawn |
| CVE-2026-5287 | Use-after-free in PDF |
| CVE-2026-5288 | Use-after-free in WebView |
| CVE-2026-5289 | Use-after-free in Navigation |
| CVE-2026-5290 | Use-after-free in Compositing |
These vulnerabilities largely involve memory handling flaws that attackers frequently exploit to achieve code execution.
| CVE | Vulnerability |
|---|---|
| CVE-2026-5291 | Inappropriate implementation in WebGL |
| CVE-2026-5292 | Out-of-bounds read in WebCodecs |
While rated medium, these could still be used in multi-stage exploit chains.
All Chrome desktop installations prior to patched versions may be affected.
CyberShelter recommends upgrading to:
| Platform | Secure Version |
|---|---|
| Windows | Chrome 146.0.7680.177 / 178 |
| macOS | Chrome 146.0.7680.177 / 178 |
| Linux | Chrome 146.0.7680.177 |
Potential impact includes:
Organizations may face:
Browsers represent a major attack surface because they process untrusted internet content.
Organizations should check:
Organizations should implement:
CyberShelter Threat Intelligence has identified a critical vulnerability affecting HPE Telco Network Function Virtualization (NFV) Orchestrator that could allow remote attackers to compromise affected systems through multiple attack vectors.
Tracked as CVE-2025-12543, the vulnerability carries a CVSS score of 9.6 (Critical) and may expose telecom infrastructure environments to significant security risks if left unpatched.
| CVE | Privileges | User Interaction | Risk |
|---|---|---|---|
| CVE-2025-12543 | None | Required | Remote compromise |
| Parameter | Value |
|---|---|
| CVE ID | CVE-2025-12543 |
| CVSS Score | 9.6 |
| Attack Vector | Network (AV:N) |
| Attack Complexity | Low (AC:L) |
| Privileges Required | None (PR:N) |
| User Interaction | Required (UI:R) |
| Scope | Changed (S:C) |
| Confidentiality Impact | High |
| Integrity Impact | High |
| Availability Impact | Low |
This vulnerability may allow remote attackers to exploit weaknesses in the orchestration platform to gain unauthorized access or compromise system functionality.
Although exploitation requires user interaction, the critical severity suggests that exploitation could result in significant control over affected infrastructure.
Organizations operating telecom virtualization infrastructure using affected versions face elevated risk.
| Product | Affected Versions |
|---|---|
| HPE Telco Network Function Virtualization Orchestrator | Version 7.5.0 and earlier |
CyberShelter recommends upgrading to:
| Product | Secure Version |
|---|---|
| HPE Telco NFV Orchestrator | Version 7.5.1 or later |
Successful exploitation could result in:
Attackers may potentially:
Since NFV orchestrators manage critical telecom services, compromise could have cascading operational impact.
Organizations should review:
CyberShelter Threat Intelligence has identified multiple critical vulnerabilities affecting Nginx UI, a web-based management interface used to administer Nginx servers. These vulnerabilities could allow unauthenticated attackers to gain administrative control, inject malicious configurations, and establish persistent compromise through tampered backups.
The risk is elevated due to the availability of public proof-of-concept (PoC) exploit code, increasing the likelihood of active exploitation.
| Attribute | Details |
|---|---|
| Platform | Nginx UI |
| Vulnerabilities | CVE-2026-33032, CVE-2026-33026 |
| Severity | Critical |
| CVSS Scores | 9.8 / 9.4 |
| Attack Type | Authentication Bypass / Integrity Bypass |
| Authentication Required | No (for CVE-2026-33032) |
| Exploitation Status | Public PoC Available |
| Business Risk | Full system compromise |
| Parameter | Details |
|---|---|
| CVE ID | CVE-2026-33032 |
| Severity | Critical |
| CVSS Score | 9.8 |
| Component | MCP (Model Context Protocol) |
| Vulnerability Type | Authentication Bypass |
| Attack Requirement | Remote / Unauthenticated |
The vulnerability exists because the /mcp_message endpoint relies on IP whitelisting instead
of authentication. Due to a design flaw, an empty whitelist is interpreted as "allow all access",
allowing any remote attacker to access administrative functions.
Attackers could gain unauthorized administrative access, control Nginx configurations, modify traffic routing, intercept web traffic, access sensitive configs, harvest credentials, disrupt services, and fully compromise servers. This represents a full administrative takeover risk.
| Parameter | Details |
|---|---|
| CVE ID | CVE-2026-33026 |
| Severity | Critical |
| CVSS Score | 9.4 |
| Vulnerability Type | Cryptographic Design Flaw |
| Component | Backup/Restore Mechanism |
| Impact | Persistent compromise |
The vulnerability exists due to a flawed cryptographic design in the backup/restore mechanism. Backup encryption uses AES-256-CBC, but unfortunately:
This allows attackers to modify backups and still pass verification. As a result, attackers could modify backup archives, insert malicious configurations, deploy persistent backdoors, execute arbitrary commands, and achieve full system compromise.
Management interfaces exposed to the internet face the highest risk. Consequences of a successful exploit include web infrastructure compromise, application traffic manipulation, data exposure, persistent attacker access, service outages, and security monitoring disruption. The risk profile encompasses maintaining long-term persistence, inserting backdoors, executing remote commands, and establishing an infrastructure foothold.
Attacker discovers exposed Nginx UI; Sends request to /mcp_message endpoint;
Whitelist bypass triggered; Administrative functions accessed; Server configurations modified.
Attacker obtains backup archive; Modifies configuration files; Recalculates integrity metadata; Repackages archive; Uploads modified backup; Malicious configuration deployed.
Organizations should proactively review logs and environment configurations for:
Upgrade to Nginx UI 2.3.4 or later. Continuously monitor vendor patch releases and apply security updates for the unpatched endpoint immediately when released.
Restrict Nginx UI access strictly to trusted networks. Remove internet exposure by using VPN-only access and apply comprehensive Zero Trust access controls.
CyberShelter Threat Intelligence has identified an active destructive wiper malware campaign targeting multiple sectors including government, energy, finance, telecom, and critical infrastructure organizations across the region.
Unlike ransomware operations, this campaign appears focused on pure destruction, aiming to permanently erase data, disrupt operations, and render systems unrecoverable. Early incidents indicate that some organizations have already been impacted, confirming active exploitation activity.
| Attribute | Details |
|---|---|
| Threat Type | Wiper Malware |
| Objective | Data destruction |
| Target Sectors | Government, Energy, Finance, Telecom |
| Impact | System destruction |
| Primary Risk | Operational disruption |
| Recommended Priority | Immediate defensive measures |
Wiper malware is destructive malware designed to delete critical files, destroy operating systems, corrupt boot records, disable recovery mechanisms, and destroy backups. Unlike ransomware, attackers typically do not seek payment, indicating sabotage or disruption objectives.
| Attribute | Details |
|---|---|
| Malware Type | Wiper |
| Primary Goal | Permanent data destruction |
| Propagation | Network lateral movement |
| Recovery Difficulty | High |
| Operational Impact | Severe |
Organizations affected reported system crashes, boot failures, file deletion, backup destruction, and network-wide spread. This indicates destructive intent rather than financial motivation.
Once inside the network, attackers rapidly spread through the infrastructure using several observed techniques:
Leveraging remote administration tools, abusing domain privileges, and misusing administrative accounts.
Moving through SMB shares, domain trust relationships, and remote management protocols.
Access obtained -> Credentials harvested -> Lateral movement -> Critical systems identified -> Wiper deployed -> Systems unusable.
Domain privileges obtained -> SMB propagation -> Multiple endpoints infected -> Simultaneous destructive execution.
Enforce MFA on all remote access; Review and prune privileged accounts; Monitor administrative access.
Apply critical security patches; Prioritize internet-facing systems; Disable unnecessary services.
Segmentation and backup resilience are the most critical defenses against wiper attacks.
CyberShelter Threat Intelligence has identified multiple high-severity vulnerabilities affecting Apache Traffic Server, a widely used high-performance web proxy and caching solution. These vulnerabilities could allow attackers to disrupt services, manipulate HTTP requests, and potentially compromise data integrity.
| Attribute | Details |
|---|---|
| Product | Apache Traffic Server |
| Vulnerabilities | CVE-2025-58136, CVE-2025-65114 |
| Severity | High |
| CVSS Score | 7.5 |
| Attack Types | DoS / HTTP Request Smuggling |
| Business Risk | Service disruption & traffic manipulation |
| Recommended Action | Immediate upgrade |
A flaw exists in how Apache Traffic Server processes HTTP POST requests under certain conditions. Attackers could exploit this issue to cause the proxy service to crash, leading to a Denial-of-Service condition.
| Parameter | Details |
|---|---|
| CVE | CVE-2025-58136 |
| Severity | High |
| CVSS Score | 7.5 |
| Vulnerability Type | Denial-of-Service |
| Component | HTTP POST request handling |
This vulnerability is caused by improper handling of malformed chunked HTTP messages. Attackers may exploit this weakness to perform HTTP request smuggling attacks, potentially bypassing security controls and injecting unauthorized requests.
| Parameter | Details |
|---|---|
| CVE | CVE-2025-65114 |
| Severity | High |
| CVSS Score | 7.5 |
| Vulnerability Type | HTTP Request Smuggling |
| Component | Chunked HTTP message processing |
Organizations should review their deployments and identify if they are running any of the following vulnerable versions:
| Product | Affected Versions |
|---|---|
| Apache Traffic Server | 9.0.0 9.2.12 |
| Apache Traffic Server | 10.0.0 10.1.1 |
| Product | Secure Versions |
|---|---|
| Apache Traffic Server | 9.2.13 or later |
| Apache Traffic Server | 10.1.2 or later |
Attacker sends crafted POST requests -> Traffic Server processing flaw triggered -> Service crashes -> Applications become unavailable.
Attacker sends malformed HTTP request -> Proxy parsing inconsistency triggered -> Unauthorized request injected -> Backend systems affected.
Upgrade Apache Traffic Server immediately to securely patched versions (9.2.13+ or 10.1.2+). Validate deployments in staging environments first.
Restrict proxy exposure where possible and implement a Web Application Firewall (WAF) to filter malformed HTTP requests.
CyberShelter Threat Intelligence has identified multiple vulnerabilities disclosed by Cisco affecting enterprise networking and infrastructure management platforms. The vulnerabilities include improper authorization, privilege escalation, remote code execution (RCE), denial-of-service (DoS), and web-based attacks.
Successful exploitation could allow attackers to gain elevated privileges, execute arbitrary commands, disrupt enterprise services, or access sensitive management data.
| Attribute | Details |
|---|---|
| Vendor | Cisco |
| Affected Products | Multiple enterprise platforms |
| Vulnerabilities | Multiple CVEs |
| Severity | High / Medium |
| Primary Risks | RCE / Privilege Escalation / DoS |
| Attack Surface | Management infrastructure |
| Recommended Action | Apply Cisco patches immediately |
| CVE | Product | Vulnerability Type | Impact |
|---|---|---|---|
| CVE-2026-20155 | Cisco Evolved Programmable Network Manager | Improper Authorization | Unauthorized access to management functionality |
| CVE-2026-20151 | Cisco Smart Software Manager | Privilege Escalation | Elevated administrative privileges |
CVE-2026-20155 may allow attackers to access restricted management functions and modify network configurations, while CVE-2026-20151 could allow attackers to modify licensing infrastructure and establish persistence within Cisco Smart Software Manager environments.
| CVEs | Vulnerability Type | Impact |
|---|---|---|
| CVE-2026-20094, CVE-2026-20095, CVE-2026-20096 | Command Injection / RCE | Remote code execution & system compromise |
These vulnerabilities in the Cisco Integrated Management Controller (IMC) represent the highest risk, as they allow unauthenticated attackers to execute arbitrary commands, leading to full server compromise and infrastructure takeover.
CVE-2026-20110: Affects Cisco IOS XE devices. Successful exploitation can trigger device instability and network disruption.
CVE-2026-20174: Affects Cisco Nexus Dashboard. Attackers could manipulate system files leading to privilege escalation.
CVE-2026-20041: Affects Nexus Dashboard & Insights. Allows internal network scanning and data exfiltration.
CVE-2026-20042: Affects configuration backup REST API. Attackers could extract sensitive infrastructure intelligence.
CVE-2026-20085, CVE-2026-20087, CVE-2026-20088: Multiple flaws allowing session token theft and administrative session hijacking via the management interface.
Attacker targets vulnerable IMC interface -> Command injection vulnerability exploited -> Remote commands executed -> System access gained -> Infrastructure compromised.
Attacker gains low-level access -> Privilege escalation vulnerability exploited -> Admin privileges obtained -> Configuration modified.
Attacker sends crafted request -> Nexus Dashboard performs internal request -> Sensitive data accessed -> Internal infrastructure mapped.
Apply Cisco security updates immediately across all affected platforms. Prioritize IMC and Smart Software Manager patches.
Restrict access to management interfaces to trusted internal networks only. Use multi-factor authentication (MFA) for all administrative accounts.
Organizations should increase logging verbosity on management interfaces and alert on any unauthorized access attempts or suspicious API calls.
CyberShelter Threat Intelligence has identified a high-severity vulnerability affecting the Perfmatters WordPress plugin, a widely used website performance optimization tool. The vulnerability could allow unauthenticated attackers to delete arbitrary files from the server, potentially leading to complete website compromise.
Tracked as CVE-2026-4350, this vulnerability carries a CVSS score of 8.1 (High) and should be treated as a priority remediation issue for organizations running WordPress environments.
| Attribute | Details |
|---|---|
| Product | Perfmatters WordPress Plugin |
| CVE | CVE-2026-4350 |
| Severity | High |
| CVSS Score | 8.1 |
| Vulnerability Type | Arbitrary File Deletion |
| Authentication Required | No |
| Impact | Website takeover |
| Recommended Action | Immediate upgrade |
| Parameter | Details |
|---|---|
| Component | PMCS::action_handler() function |
| Vulnerability Type | Path Traversal |
| Root Cause | Missing input validation |
| Authentication | Not required |
The vulnerability is caused by multiple security weaknesses including missing input sanitization, lack of authorization checks, missing nonce verification, and improper file path validation in the Action Handler component. These issues allow attackers to craft malicious requests to delete files outside intended directories.
wp-config.php. Deletion of wp-config.php is particularly dangerous because it
forces WordPress into installation mode, allowing an attacker to reconfigure the site and gain
administrative control.
| Product | Status | Versions |
|---|---|---|
| Perfmatters Plugin | Vulnerable | All versions up to 2.5.9.1 |
| Perfmatters Plugin | Secure | 2.6.0 or later |
Attacker identifies WordPress site running vulnerable Perfmatters plugin.
Sends crafted request exploiting path traversal flaw in PMCS Action Handler.
Critical wp-config.php file is deleted
from the server.
WordPress fails to find config and enters installation mode.
Attacker reconfigures site, pointing to their own DB or resetting admin.
Full administrative access gained; complete website takeover achieved.
wp-config.php file on serverUpgrade Perfmatters plugin immediately to version 2.6.0+. Remove older vulnerable versions and verify plugin integrity across all environments.
Implement a Web Application Firewall (WAF) to filter path traversal patterns. Restrict administrative endpoints and disable file editing within WordPress.
wp-config.php.CyberShelter Threat Intelligence has identified multiple critical vulnerabilities affecting Dell Data Protection Central (DPC) and Dell Integrated Data Protection Appliance (IDPA / PowerProtect DP Series) environments. These vulnerabilities primarily originate from underlying SUSE Linux Enterprise Server 12 SP5 (SLES 12 SP5) components.
Successful exploitation could allow attackers to perform remote code execution, escalate privileges, disrupt services, or access sensitive backup and data protection infrastructure.
| Attribute | Details |
|---|---|
| Vendor | Dell |
| Affected Platforms | Data Protection Central / IDPA |
| Root Cause | Third-party SLES components |
| Severity | Critical |
| Primary Risks | RCE / Privilege Escalation / DoS |
| Infrastructure Risk | Backup systems |
| Recommended Action | Immediate OS updates |
The advisory includes multiple critical vulnerabilities across kernel components, memory management, and privilege boundaries. The cumulative exposure increases risk due to potential vulnerability chaining.
| CVE | Vulnerability Type | Impact | Risk |
|---|---|---|---|
| CVE-2026-23004 | Kernel vulnerability | Privilege escalation | Full system compromise |
| CVEs | Vulnerability Type | Potential Impact |
|---|---|---|
| CVE-2026-23083, CVE-2026-23084, CVE-2026-23085, CVE-2026-23086 | Memory corruption | RCE / DoS |
These vulnerabilities could allow remote code execution, service crashes, and system instability via memory corruption exploitation.
| CVEs | Vulnerability Type | Impact |
|---|---|---|
| CVE-2026-22998, CVE-2026-22999 | Improper input validation | Unauthorized access / Bypass security controls |
| CVE-2026-23105, CVE-2026-23112 | Privilege boundary bypass | Root access escalation |
| Product | Affected Versions | Secure Version |
|---|---|---|
| Dell Data Protection Central | 19.9.x, 19.10.x, 19.11.x, 19.12.x | Versions 19.9 19.12 with latest OS update |
| PowerProtect DP Series (IDPA) | Versions prior to 2.7.9 | Version 2.7.9 with updated OS |
Attacker gains limited access -> Kernel vulnerability exploited -> Root privileges obtained -> Backup infrastructure accessed.
Memory vulnerability triggered -> Code execution achieved -> Persistence established -> Data protection environment compromised.
Attacker compromises IDPA system -> Backup data accessed -> Recovery capability impacted -> Ransomware exposure.
Apply latest Dell OS updates. Upgrade IDPA to version 2.7.9. Verify DPC OS patch levels and test updates before deployment.
Restrict administrative access, implement MFA, enforce least privilege, and harden Linux configurations by disabling unnecessary services.
CyberShelter Threat Intelligence has identified a large-scale state-sponsored cyber-espionage campaign conducted by Forest Blizzard (APT28 / FANCY BEAR), attributed with high confidence to GRU Military Unit 26165.
The campaign leverages compromised SOHO routers to hijack DNS traffic and perform Adversary-in-the-Middle (AiTM) attacks against cloud services including Microsoft 365. This campaign presents a critical infrastructure-level threat, especially to UAE organizations due to high exposure of vulnerable network devices.
| Attribute | Details |
|---|---|
| Threat Actor | Forest Blizzard (APT28 / FANCY BEAR) |
| Attribution | GRU Military Unit 26165 |
| Campaign Type | DNS Hijacking + TLS AiTM |
| Impact Scope | 200+ orgs, 5,000+ devices |
| Target Sectors | Government, IT, Telecom, Energy |
| Severity | CRITICAL |
| UAE Exposure | 35,500+ vulnerable devices |
| Recommended Action | MFA Hardening & Router Auditing |
Identified exposed SOHO devices across UAE infrastructure.
Primary hardware target identified in regional telemetry.
Secondary consumer-grade targets exposed to exploitation.
These devices are primarily located on major national internet service providers and related national networks, creating a high-risk attack surface for UAE organizations, especially for remote workers.
Exploitation of vulnerable SOHO routers via default credentials or firmware flaws.
DHCP configuration altered and malicious DNS servers distributed to endpoints.
DNS traffic monitored and victim profiling conducted to select targets.
DNS spoofing for selected targets and TLS AiTM attacks executed.
Email interception, credential harvesting, and cloud data access completed.
| IOC | Type | Description |
|---|---|---|
| Actor-controlled DNS resolvers | Infrastructure | Malicious DNS servers used for hijacking |
| dnsmasq on port 53 | Service | DNS proxy used for forwarding and spoofing |
| Modified DHCP DNS settings | Configuration | Routers distributing malicious DNS |
| Unexpected DNS resolver changes | Indicator | Endpoint DNS changes without user action |
| IOC | Type | Description |
|---|---|---|
| Invalid TLS certificates | Certificate | For Microsoft domains during AiTM |
| Certificate mismatch warnings | Indicator | User-visible warnings during interception |
| RiskEventType: investigations... | Detection | Entra ID detection event |
| RiskLevelAggregated == 100 | Detection | High-risk sign-in event |
| Tactic | Technique | Description |
|---|---|---|
| Initial Access | T1584.008 | Network device compromise |
| Collection | T1040 | Network sniffing |
| Credential Access | T1557.003 | TLS AiTM |
| Collection | T1114 | Email interception |
| Persistence | T1584 | Infrastructure compromise |
Enforce phishing-resistant MFA (FIDO2 / Passkeys). Implement Conditional Access policies and monitor for Entra ID risk alerts.
Deploy Zero Trust DNS and enforce resolution through trusted servers. Audit and patch all SOHO routers and MikroTik devices.
CyberShelter Threat Intelligence has identified an active Android banking malware campaign targeting UAE banking customers through sophisticated social engineering attacks involving fake Google Chrome and Google Play update applications.
The campaign involves multiple advanced Android banking trojans including TrickMo and Antidot / PhantomCall variants, capable of intercepting OTPs, stealing banking credentials, executing overlay attacks, and enabling full remote device compromise.
| Attribute | Details |
|---|---|
| Threat Type | Android Banking Malware |
| Malware Families | TrickMo, Antidot, PhantomCall |
| Target Region | regional banking Customers |
| Attack Vector | Fake Chrome / Play Store Updates |
| Severity | HIGH |
| Primary Risk | Banking Fraud / Account Takeover |
| Capabilities | OTP interception, RAT control, overlays |
| Recommended Action | IOC blocking and mobile security controls |
Observed functionality includes:
New advanced techniques observed:
Attackers distribute fake update APK files through SMS phishing, fake Play Store pages, malicious redirects, and trojanized apps.
Malware tricks users into enabling Accessibility permissions, SMS access, overlay permissions, and notification access.
Secondary malware payloads are downloaded and installed to establish persistence.
Device registers with attacker infrastructure and receives commands.
Malware performs banking overlays, SMS interception, screen recording, and credential harvesting.
Attackers execute transactions while blocking SMS alerts, blocking bank calls, forwarding calls, and suppressing notifications.
| IOC | Type | Description |
|---|---|---|
| 4284e6bbc2fc274d8b0a1f37f91408efc0404e4cae0ba28abc4d583bc59af6bd | SHA256 | TrickMo TikTok18.apk via infinitaki.com (2026-02-16) |
| 6eb525100f54b9a830cd2d0f1169b053edb55332b2be73dd29a8b165b9ccdbf5 | SHA256 | TrickMo APK C2 rent-car-italy.org |
| 0e69f3d10ba88974c47a9ce83a095a29e9ac3de66b0441db60624fbe0772f6c3 | SHA256 | TrickMo APK C2 dontcryallnight.network |
| c00419b21d10a236b47b43bb1eed3dbc5298e471cf9616848a84da5baae8e611 | SHA256 | Google-Services.apk C2 traktortany.org |
| 4fcce7c445d89d7de943ec0e0c2fc285d4b25a67950ad7d6bcb50dbcbc4ac29b | SHA256 | OLX_Payment.apk |
| ac21ddc972b50c66a9876f1a470f0a29f4df58c1557b8fa0ba649fc0b255dd37 | SHA256 | InstPizza.apk Gabriel Pizza lure |
| aba8466f8162846c8adc7be242bb78a346775804de2c14a978d69649b0639c6d | SHA256 | CapCut_Premium.apk |
| b4b92db35c432ce3844c5772b60c082aa39ad2a2135490e4cc2f5dd4c2daada0 | SHA256 | GooglerApps.apk fake Google Apps |
| e893374ee1f3e1a7ccabab85d2f47c64d7cf0781f64f5e0bb7a96368327919a9 | SHA256 | PhantomCall fake Chrome update |
| b482c7a2734b90eea3e35e61962de17336ed81f26bc9432175a03d4e7da03d65 | SHA256 | Trans-Cosmos.apk ping.kqsaws.top C2 |
| 6a99e6d4abc66f09a490443786432d90c675cb6282c791fae996136cbb69b7e9 | SHA256 | EVN.apk ping.ykkws.top C2 |
| 236c09415f6f77ca40f7b4a9301fd7e9176cc29f8b3b7c02c3e5e9fff4b254dc | SHA256 | Vodafone.apk vodafone-verificatie.com lure |
| a75adcf42f39c729c3ded9f42b8c35ee2552f2521903aa7e9ead8d74d5254ac2 | SHA256 | Proximus.apk proximus-simkaart.com lure |
| 9f8a49432e76b9c69d33ea228cc44254bc0a58bfa15eb0c51a302c59db81caa3 | SHA256 | Socket.IO C2 46.228.205.159:5055 |
| cbe0994fcfbf017babc5bef567f6e3bb540293f2c1e4acb91e9b775008749e16 | SHA256 | com.yoyeyojogo.flowchart |
| 8ef3b42c7e7205be38f81db96129e6774476d0b28d85f087d2aff4222821abeb | SHA256 | Dropped secondary stage: heaviest.apk |
| IOC | Type | Description |
|---|---|---|
| havebeprotredo[.]at | Domain | TrickMo C2 |
| mobiportal[.]at | Domain | TrickMo C2 |
| jaddertta[.]at | Domain | TrickMo C2 |
| csharpier[.]at | Domain | TrickMo C2 |
| heyclodere[.]at | Domain | TrickMo C2 |
| mainworkapp[.]com | Domain | TrickMo infrastructure |
| infinitaki[.]com | Domain | TrickMo distribution |
| ping.kqsaws[.]top | Domain | Antidot C2 |
| ping.ykkws[.]top | Domain | Antidot C2 |
| festalferalweek[.]online | Domain | Antidot C2 |
| IOC | Type | Description |
|---|---|---|
| 213.109.202.28 | IP | TrickMo C2 |
| 185.72.144.110 | IP | TrickMo C2 |
| 194.26.135.95:8080 | IP:Port | TrickMo dropper host |
| 216.122.166.17:8237 | IP:Port | Antidot C2 panel |
| 46.228.205.159:5055 | IP:Port | Antidot Socket.IO C2 |
| IOC | Type | Description |
|---|---|---|
| Authorization: LOG LTAI5tN1beEhUK1dpF84mjmY:* | Network Artifact | Antidot exfil header |
| User-Agent: okhttp/3.12.12 | Network Artifact | Antidot C2 traffic |
| GET /socket.io/?EIO=4&transport=polling | Network Pattern | Antidot C2 handshake |
| IOC | Type | Description |
|---|---|---|
| com.tejuhabilu.auto | Package | Antidot dropper |
| com.sukiseyosa.flowchart | Package | Antidot dropper |
| com.yoyeyojogo.flowchart | Package | Antidot dropper |
| com.dipapome.keyboard | Package | Antidot malware |
| com.wijolusuye.hardware | Package | Antidot malware |
| com.wetpacc88.psyc88 | Package | Antidot malware |
| net.dress.absorb | Package | TrickMo activity |
| IOC | Type | Description |
|---|---|---|
| 6edf43ebc3367dc58fb3a30322cf21a72cecbf99101e7bbe1aa85413d8f132f8 | Cert Hash | Fake Facebook cert |
| 0851dbb86a74beeb7f0c5c3a4ef1a5416584334f876c0fd5dce7f1140f1ce98b | Cert Hash | Fake Google cert |
| fac61745dc0903786fb9ede62a962b399f7348f0bb6f899b8332667591033b9c | Cert Hash | Debug cert |
Organizations should immediately:
Organizations should implement:
The Android Chrome update malware campaign represents a serious and ongoing financial cyber threat targeting regional banking customers.
The combined use of TrickMo and PhantomCall demonstrates a mature cybercrime ecosystem focused on:
CyberShelter Threat Intelligence has identified multiple vulnerabilities disclosed by IBM affecting IBM Verify Identity Access (VIA) and IBM Security Verify Access (SVA) platforms. These vulnerabilities include critical privilege escalation, authentication bypass, arbitrary script execution, command injection, and SSRF weaknesses.
Successful exploitation could allow attackers to gain root-level access, bypass authentication controls, execute malicious code, or compromise identity management infrastructure. Identity platforms represent high-value targets due to their centralized role in enterprise authentication.
| Attribute | Details |
|---|---|
| Vendor | IBM |
| Affected Products | IBM Verify Identity Access / Security Verify Access |
| Highest Severity | Critical (CVSS 9.3) |
| Primary Risks | Privilege Escalation / Authentication Bypass |
| Target Systems | Identity & Access Management (IAM) |
| Recommended Action | Immediate patching |
| Parameter | Details |
|---|---|
| CVE | CVE-2026-1346 |
| CVSS Score | 9.3 |
| Vulnerability Type | Privilege Escalation |
| Impact | Root access |
This vulnerability may allow attackers to escalate privileges to root level, potentially allowing full control of affected systems. Attackers could gain administrative privileges, modify identity configurations, and access authentication databases.
| CVE | CVSS | Type | Impact |
|---|---|---|---|
| CVE-2026-4101 | 8.1 | Authentication logic flaw | Unauthorized access / Bypass login |
| CVE-2026-1342 | 8.5 | Arbitrary script execution | Code execution / Session compromise |
| CVE | CVSS | Type | Potential Impact |
|---|---|---|---|
| CVE-2026-1345 | 7.3 | OS Command Injection | System command execution |
| CVE-2026-1343 | 7.2 | SSRF | Internal access abuse / Reconnaissance |
| CVE-2026-4364 | 5.4 | XSS | Session hijacking / Credential theft |
| CVE-2026-2862 | 5.3 | HTTP Request Smuggling | Traffic manipulation |
| Product | Affected Versions | Secure Version |
|---|---|---|
| IBM Verify Identity Access (VIA) | 11.0 through 11.0.2 | 11.0.2 IF1 |
| IBM Security Verify Access (SVA) | 10.0 through 10.0.9.1 | 10.0.9.1 IF1 |
Attacker gains initial access -> Privilege escalation exploited -> Root access obtained -> Identity infrastructure compromised.
Attacker targets logic flaw -> Login protections bypassed -> Unauthorized access obtained -> Sensitive identity data accessed.
Crafted request sent -> System performs internal request -> Internal services exposed -> Restricted data extracted.
Apply IBM Verify Identity Access 11.0.2 IF1 or IBM Security Verify Access 10.0.9.1 IF1 updates without delay.
Enforce strict MFA for all administrative interfaces and restrict access to IAM portals to known internal IP ranges.
CyberShelter Threat Intelligence has identified an actively exploited zero-day vulnerability affecting the TrueConf Client, tracked as CVE-2026-3502. The vulnerability allows attackers to abuse the software update mechanism to distribute malicious payloads across trusted enterprise networks.
The attack campaign, named Operation TrueChaos, involves compromise of on-premises TrueConf servers to distribute weaponized updates to connected endpoints, potentially leading to large-scale infrastructure compromise. Coordinated research suggests targeting of government infrastructure by a Chinese-nexus threat actor.
| Attribute | Details |
|---|---|
| Product | TrueConf Client |
| CVE | CVE-2026-3502 |
| Severity | High (Zero-Day) |
| CVSS Score | 7.8 |
| Attack Type | Supply chain compromise |
| Campaign Name | Operation TrueChaos |
| Exploitation Status | Active |
| Parameter | Details |
|---|---|
| CWE | CWE-494 (Download of Code Without Integrity Check) |
| Component | Update Mechanism |
| Vulnerability Type | Improper update validation |
| Attack Vector | Software update channel |
| Impact | Remote code execution |
The vulnerability exists because the TrueConf client update process lacks proper validation controls. This allows attackers to replace legitimate updates with malicious software through the following weaknesses:
Attacker compromises TrueConf update server inside targeted government or enterprise environments.
Legitimate update replaced with malicious package distributed through trusted automatic channels.
Malicious update executes, deploying Havoc C2 implants and maintaining persistent access.
| File Description | Hash (MD5) |
|---|---|
| TrueConf Malicious Update (trueconf_windows_update.exe) | 22e32bcf113326e366ac480b077067cf |
| Loader Component (iscsiexe.dll) | 9b435ad985b733b64a6d5f39080f4ae0 |
| Havoc Implant (7z-x64.dll) | 248a4d7d4c48478dcbeade8f7dba80b3 |
| Indicator | Type |
|---|---|
| 43.134.90[.]60 | Havoc C2 |
| 43.134.52[.]221 | Havoc C2 |
| 47.237.15[.]197 | Havoc C2 |
Upgrade to version 8.5.3 or later immediately. Verify update server integrity and block identified C2 IPs.
Scan for listed IoC hashes and monitor DLL side-loading behavior in update folders and execution logs.
CyberShelter Threat Intelligence has identified a critical zero-day vulnerability affecting Adobe Acrobat and Adobe Acrobat Reader on Windows and macOS systems. The vulnerability, tracked as CVE-2026-34621, is actively exploited in the wild and enables arbitrary code execution, allowing attackers to fully compromise affected systems.
Due to active exploitation and high impact, this issue has been classified as a Priority 1 (Critical) security threat by Adobe and observed by the National Cybersecurity Authority.
| Attribute | Details |
|---|---|
| Vulnerability | CVE-2026-34621 |
| Severity | Critical |
| CVSS Score | 9.6 |
| Type | Prototype Pollution (CWE-1321) |
| Exploitation | Active (In-the-Wild) |
| Attack Vector | Malicious PDF file |
| Impact | Remote Code Execution / Full System Compromise |
| Affected Platforms | Windows, macOS |
| Recommended Action | Immediate patching |
CVE-2026-34621 is a Prototype Pollution vulnerability that allows attackers to manipulate JavaScript object prototypes within Adobe Acrobat and Reader. By exploiting this flaw through a malicious PDF file, attackers can execute arbitrary code, bypass application security controls, gain full system access, and deploy malware or ransomware.
Because exploitation requires only user interaction (opening a PDF), this vulnerability presents a high-risk entry point for targeted and mass phishing campaigns.
The vulnerability arises from improper handling of JavaScript object properties and a lack of input validation in PDF processing. Attackers can inject malicious payloads into PDF files that alter object behavior, execute unintended code paths, and trigger remote code execution.
| Product | Vulnerable Versions |
|---|---|
| Acrobat DC (Continuous) | = 26.001.21367 |
| Acrobat Reader DC (Continuous) | = 26.001.21367 |
| Acrobat 2024 (Classic) | = 24.001.30356 |
| Product | Secure Version |
|---|---|
| Acrobat DC / Reader DC | 26.001.21411 |
| Acrobat 2024 (Windows) | 24.001.30362 |
| Acrobat 2024 (macOS) | 24.001.30360 |
Attacker crafts a malicious PDF file with prototype pollution payload.
Victim receives file via email or download (phishing).
User opens file; vulnerability triggers code execution.
| IOC | Type | Description |
|---|---|---|
| Suspicious PDF files | File | Malicious crafted PDFs |
| PDFs with embedded scripts | File | JavaScript exploitation |
| Unexpected PDF behavior | Indicator | Abnormal execution |
| IOC | Type | Description |
|---|---|---|
| Unexpected process execution | Host | Acrobat spawning suspicious child processes |
| Suspicious child processes | Host | Code execution behavior (cmd.exe, powershell.exe) |
| System crashes | System | Exploit trigger leading to instability |
| IOC | Type | Description |
|---|---|---|
| Outbound connections | Network | Post-PDF open C2 activity |
| Suspicious domains | Network | Malicious communication from Acrobat process |
| Tactic | Technique | Description |
|---|---|---|
| Initial Access | T1566 | Phishing (malicious attachment) |
| Execution | T1203 | Exploitation for Client Execution |
| Persistence | T1547 | Boot or Logon Autostart |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation |
| Command & Control | T1071 | Application Layer Protocol |
| Impact | T1486 | Data Encryption (Ransomware) |
Update Adobe Acrobat and Reader to the latest secure versions immediately across all endpoints.
Block untrusted PDF attachments and implement email filtering for malicious attachments.
Disable JavaScript in PDF readers where possible to mitigate prototype pollution risks.
Deploy EDR/XDR, monitor suspicious process trees, and restrict execution from PDF processes.
Monitor for unusual Acrobat activity, outbound connections post-file open, and system anomalies.
Educate users on phishing risks and warn against opening unknown PDF files.
CyberShelter Threat Intelligence has identified two critical vulnerabilities affecting Movable Type, a widely deployed enterprise content management platform developed by Six Apart Ltd. The vulnerabilities impact the Listing Framework and enable Unauthenticated Remote Code Execution (RCE) and SQL Injection attacks.
Both vulnerabilities are exploitable when the Admin Panel or Data API is exposed to the internet, posing a critical risk to enterprise environments. Failure to patch immediately could lead to full system compromise.
| Attribute | Details |
|---|---|
| Platform | Movable Type CMS |
| Vendor | Six Apart Ltd. |
| Vulnerabilities | 2 Critical Issues |
| Severity | Critical / High |
| Primary Risks | RCE, SQL Injection |
| Attack Vector | Remote (Web Interface) |
| Privileges Required | None (if exposed) |
| Impact | Full system compromise |
| Recommended Action | Immediate patching |
The vulnerabilities affect the Listing Framework, allowing attackers to exploit improper input validation mechanisms. These flaws are particularly dangerous as they can be triggered via the publicly accessible Admin Panel (mt.cgi) or the Data API (mt-data-api.cgi).
CVSS Score: 9.8 (Critical)
The root cause is improper input handling in filter processing within the Listing Framework. Attackers can inject arbitrary Perl code which the server executes, granting web server-level access.
CVSS Score: 7.3 (High)
This vulnerability stems from unsanitized input in request processing. It allows attackers to execute arbitrary SQL queries, leading to the extraction of sensitive data such as credentials or the modification/deletion of database records.
Systems are vulnerable when the Admin Panel is publicly accessible or the Data API is exposed to the internet without IP-based restrictions.
| Version Branch | Secure Version |
|---|---|
| 9.x | 9.0.7 |
| 8.8.x | 8.8.3 |
| 8.0.x | 8.0.10 |
| Internal | 9.1.1 |
Attacker sends crafted request to API -> Injects malicious Perl code -> Server executes commands -> Full compromise.
Malicious input via request -> Database query manipulated -> Sensitive credentials retrieved -> Database tampering.
Detection relies on behavioral and application-level indicators. Organizations should monitor web logs for suspicious requests targeting the CMS endpoints.
| IOC | Type | Description |
|---|---|---|
| Suspicious requests to mt.cgi | Network | Targeting admin panel |
| Requests to mt-data-api.cgi | Network | API exploitation attempts |
| Unusual query parameters | Network | Injection attempts |
| High volume requests to CMS | Network | Exploitation activity |
| IOC | Type | Description |
|---|---|---|
| Unexpected Perl execution | App | RCE indicator |
| Abnormal API responses | App | Possible exploitation |
| New processes spawned by web server | Host | RCE activity |
| Unusual SQL queries | DB | Injection activity |
| Tactic | Technique | Description |
|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application |
| Execution | T1059 | Command Execution |
| Credential Access | T1552 | Unsecured Credentials |
| Persistence | T1505 | Server Software Component |
| Impact | T1499 | Endpoint DoS |
| Collection | T1005 | Data from Local System |
Move to patched versions (9.0.7, 8.8.3, or 8.0.10) to fix the root vulnerabilities.
Implement IP allowlisting or VPN-only access for mt.cgi and mt-data-api.cgi.
Disable the Data API if unused or block suspicious request patterns via WAF.
CyberShelter Threat Intelligence has identified a critical vulnerability in Axios, a widely used HTTP client for Node.js and browser-based applications. Tracked as CVE-2026-40175, this vulnerability enables attackers to exploit header injection flaws that can escalate into Request Smuggling, Server-Side Request Forgery (SSRF), and Remote Code Execution (RCE).
Due to its widespread usage in modern applications, this vulnerability presents a severe supply chain and cloud security risk, potentially leading to full cloud environment compromise.
| Attribute | Details |
|---|---|
| Vulnerability | CVE-2026-40175 |
| Severity | Critical |
| CVSS Score | 10.0 |
| Affected Package | Axios (npm) |
| Vulnerability Type | Header Injection / Request Smuggling |
| CWE | CWE-113 (CRLF Injection) |
| Impact | RCE / SSRF / Cloud Compromise |
| Exploit Availability | Proof-of-Concept available |
| Recommended Action | Immediate upgrade |
CVE-2026-40175 is a header injection vulnerability caused by improper neutralization of CRLF sequences in HTTP headers. This flaw allows attackers to inject malicious headers and manipulate the HTTP request structure.
The vulnerability exists within the lib/adapters/http.js component of Axios. It is triggered
by improper validation of HTTP header input and a failure to sanitize CRLF (\r\n) sequences.
By breaking HTTP request boundaries, attackers can inject additional requests, bypass security controls, and target internal microservices that are otherwise inaccessible from the internet.
| Package | Vulnerable Versions | Secure Version |
|---|---|---|
| Axios (npm) | All versions < 1.13.2 | = 1.15.0 |
Attacker injects malicious headers via user-controlled input containing CRLF sequences.
Request structure is manipulated to achieve request smuggling against proxies or load balancers.
Internal services are targeted (SSRF), leading to sensitive data access, RCE, or cloud compromise.
Detection relies on network and application behavior. Monitor for malformed HTTP headers and request smuggling patterns.
| IOC | Type | Description |
|---|---|---|
| Malformed HTTP headers | Network | CRLF injection attempts |
| Requests in single payload | Network | Request smuggling indicators |
| Unexpected internal requests | Network | SSRF activity patterns |
| Abnormal Axios behavior | App | Exploitation attempts |
| IOC | Type | Description |
|---|---|---|
| Metadata endpoint requests | Cloud | SSRF targeting cloud metadata |
| Unauthorized service traffic | Cloud | Lateral movement attempts |
| Suspicious outbound traffic | Network | Possible data exfiltration |
| Tactic | Technique | Description |
|---|---|---|
| Initial Access | T1190 | Exploit Public-Facing Application |
| Execution | T1059 | Command Execution |
| Credential Access | T1552 | Unsecured Credentials |
| Lateral Movement | T1021 | Remote Services |
| Collection | T1530 | Data from Cloud Storage |
| Impact | T1499 | Service Disruption |
Upgrade Axios to version = 1.15.0 immediately across all Node.js projects.
Implement strict validation to reject CRLF sequences in all user-controlled HTTP headers.
Restrict access to cloud metadata services and enforce least privilege between microservices.
CyberShelter Threat Intelligence has identified an ongoing, highly sophisticated hack-for-hire surveillance campaign targeting UAE residents and MENA civil society using mobile spyware and credential phishing techniques.
The campaign is attributed with moderate-high confidence to BITTER APT (APT-C-08 / UNC2464 / HAZY TIGER), an India-nexus threat actor operating in a commercial surveillance (hack-for-hire) capacity. The operation leverages Android spyware (ProSpy / ToSpy), iOS credential phishing infrastructure, and social engineering via trusted platforms.
| Attribute | Details |
|---|---|
| Target Region | UAE (Primary), MENA |
| Target Groups | Journalists, Civil Society, Activists, Diaspora |
| Campaign Type | Mobile Spyware + Credential Phishing |
| Platforms | Android & iOS |
This campaign combines two coordinated attack vectors targeting the same victims, enabling cross-device surveillance.
.ttkmbackup).p2j8w9savbny75xg.Social engineering using LinkedIn fake profiles (job offers), iMessage phishing acting as Apple Support, and WhatsApp impersonation.
Delivery of malicious APK links offering fake apps like 'Signal Encryption Plugin' or 'ToTok Pro', alongside phishing pages for iOS.
User installs APK or submits credentials. Malware activates silently, hides its icon, establishes linked accounts on iOS, and uses boot receivers.
Data such as SMS, contacts, PDFs, DOCs, media exfiltrated over HTTPS. Uses ip-api.com and ipify.org for geolocation tracking.
ae.totok.chat and domains mimicking .ae
patterns.| Hash | Description |
|---|---|
| 0d30d0314cbac92e7399a043582b6558b86ba72313fd222db4d5cf8ca18f7cbb | Malicious APK |
| 6d5feeb61c6deec03b757490e8bbf0f3e28dc50e273fd8fd3fa2807f0eafe9db | Malicious APK |
| 3c46cc0d0b8950cac6df56665ac112b9d89823e3448a11beb57e0acd0fa1b89d | Malicious APK |
| 7b4a59d8033a11302a10023e1f546211b5fd5d6f3210fcc8ae94c93508657c8c | Malicious APK |
| 9a864f104e7fabb41e65847f78f9fb2fbac0bc1196ea61cafce19334ce28cb44 | Malicious APK |
| 3700c978758c2077dab3e630ab83e178c2cb413df290c67921290dafa82cfc1e | Malicious APK |
| 42f28501f3e6be38c0ce4ff2a5bfa2dfe3c56f99ed81804de54cba3bc26a5025 | Malicious APK |
| Domain | Domain |
|---|---|
| track-portal[.]co | sgnlapp[.]info |
| relaxmode[.]org | totokapp[.]info |
| clubline[.]cc | totok-pro[.]io |
| treasuresland[.]cc | totok-pro[.]ae |
| botim-app[.]pro | store.appupdate[.]ai |
| app-totok[.]io | com-ae[.]net |
| spiralkey[.]co | en-ae[.]io |
| noblico[.]net | com-en-uk[.]co |
| totokupdate[.]ai |
| Indicator | Type |
|---|---|
| encryption-plug-in-signal.com-ae[.]net | Malicious URL |
| 82.221.129.44 | C2 Infrastructure IP |
| 82.221.136.1 | C2 Infrastructure IP |
| 107.173.63.218 | C2 Infrastructure IP |
| 162.0.229.203 | C2 Infrastructure IP |
| 91.223.82.6 | C2 Infrastructure IP |
| 93.123.73.160 | C2 Infrastructure IP |
| 45.144.155.158 | C2 Infrastructure IP |
| Tactic | Technique | Description |
|---|---|---|
| Initial Access | T1566 | Phishing |
| Execution | T1204 | User Execution |
| Persistence | T1398 | Boot Persistence |
| Defense Evasion | T1406 | Obfuscation |
| Credential Access | T1539 | Token Theft |
| Collection | T1409 | Data Collection |
| C2 | T1071 | Web Protocols |
| Exfiltration | T1041 | Data Exfiltration |
Organizations and targeted individuals must implement the following defenses to mitigate state-level surveillance operations and cross-border intelligence collection.
A recent security update released by Google for Chrome addresses a total of 31 vulnerabilities, including several classified as critical. These issues primarily involve memory corruption flaws that could be exploited to achieve remote code execution (RCE) and potentially full system compromise.
Given the widespread use of modern web browsers across enterprise and personal environments, these vulnerabilities represent a significant security concern requiring immediate attention from IT administrators and individual users alike.
The vulnerabilities identified in this release represent a broad spectrum of technical risks:
These flaws can allow attackers to execute arbitrary code, bypass browser security mechanisms (like sandboxing), and gain unauthorized access to sensitive data or host systems.
| CVE ID | Description | Component |
|---|---|---|
| CVE-2026-6296 | Heap buffer overflow | ANGLE |
| CVE-2026-6297 | Use-after-free | Proxy |
| CVE-2026-6298 | Heap buffer overflow | Skia |
| CVE-2026-6299 | Use-after-free | Prerender |
| CVE-2026-6358 | Use-after-free | XR |
A large number of high-severity vulnerabilities were also addressed, covering critical components such as PDFium, V8, and the GPU interface:
| Area | CVEs | Type |
|---|---|---|
| Engine & Logic | CVE-2026-6301, CVE-2026-6307, CVE-2026-6363 | Type Confusion (Turbofan / V8) |
| Media & Rendering | CVE-2026-6359, CVE-2026-6302, CVE-2026-6300 | Use-after-free (Video, CSS) |
| Document Handling | CVE-2026-6305, CVE-2026-6306, CVE-2026-6361 | Heap buffer overflow (PDFium) |
| Security Policies | CVE-2026-6312, CVE-2026-6313 | Insufficient policy enforcement (Passwords, CORS) |
| Hardware & Libs | CVE-2026-6314, CVE-2026-6310, CVE-2026-6364 | Out-of-bounds write/read (GPU, Dawn, Skia) |
Remote execution of malicious code on the host machine.
Unauthorized access to sensitive user data and credentials.
Circumvention of browser sandboxing and security policies.
Organizations and users should treat browser updates with the same urgency as critical infrastructure patches.
Ensure all endpoints are running version 147.0.7727.101 or higher.
Enable and enforce central automatic updates for Chrome across the enterprise.
Restart browsers after updating to ensure patches are fully applied to all active sessions.
From a CyberShelter threat intelligence standpoint, browser-based attack surfaces remain one of the most actively targeted vectors. Memory corruption vulnerabilities continue to be favored by attackers due to their reliability. Organizations should ensure continuous monitoring and endpoint hardening to reduce exposure.
Recent security updates have been released to address multiple vulnerabilities across a wide range of widely used Adobe software products. These vulnerabilities, if left unpatched, could allow unauthorized actions such as arbitrary code execution, access to sensitive information, security control bypass, and denial-of-service (DoS) conditions.
The affected products span creative, enterprise, and development platforms, highlighting the importance of timely patching and proactive vulnerability management in both individual and organizational environments.
| Product | CVE(s) | Severity / Impact |
|---|---|---|
| Adobe Acrobat Reader | CVE-2026-34622, CVE-2026-34626 | Critical: Prototype Pollution, Arbitrary Code Execution |
| Adobe InDesign | Multiple (CVE-2026-27283, etc.) | Critical: Arbitrary Code Execution, DoS, Memory Exposure |
| Adobe InCopy | CVE-2026-27287, CVE-2026-34631 | Critical: Arbitrary Code Execution |
| Adobe Experience Manager | CVE-2026-27288, CVE-2026-34623, etc. | Important: XSS, leading to Code Execution |
| Adobe FrameMaker | Multiple (CVE-2026-27290, etc.) | Critical: Arbitrary Code Execution, File System Read |
| Adobe Connect | Multiple (CVE-2026-27302, etc.) | Critical: Deserialization, XSS, Privilege Escalation |
| Adobe ColdFusion | Multiple (CVE-2026-34619, etc.) | Critical: Path Traversal, Arbitrary Code Execution, Security Bypass |
| Adobe Bridge | Multiple (CVE-2026-34630, etc.) | Critical: Arbitrary Code Execution, DoS |
| Adobe Photoshop | CVE-2026-27289 | Critical: Arbitrary Code Execution |
| Adobe Illustrator | CVE-2026-34618 | Critical: Arbitrary Code Execution |
These vulnerabilities collectively present significant risks, including:
Apply the latest security updates for all affected Adobe products across your infrastructure.
Focus patching efforts on internet-facing and business-critical systems first.
Review system access controls and monitor for unusual activity in creative and development environments.
On April 11–12, 2026, a large-scale cyberattack struck critical infrastructure in the GCC. Carried out by the Iran-aligned group Handala, this was a geopolitically motivated destructive operation combining deep system infiltration, mass data exfiltration, and irreversible infrastructure destruction.
The attackers claimed to have exfiltrated 149 TB of sensitive data and destroyed 6 PB of infrastructure data, marking it as one of the most significant destructive operations in the region's history.
| Attribute | Details |
|---|---|
| Operation Date | April 11–12, 2026 |
| Target | GCC Critical Infrastructure |
| Lead Threat Actor | Handala (aka Void Manticore) |
| Data Exfiltrated | 149 TB |
| Data Destroyed | 6 PB |
| Primary Impact | Full Infrastructure Collapse |
Handala is an Iran-aligned threat group, widely assessed to be linked to the Ministry of Intelligence and Security (MOIS). Unlike typical ransomware groups, Handala's primary motivations are geopolitical disruption and ideological operations.
Attackers targeted contractor accounts via phishing to harvest credentials. These were then used to exploit older VPN infrastructure to gain full administrative access.
| Exploit ID | Description |
|---|---|
| CVE-2023-46805 | Authentication bypass in VPN gateway |
| CVE-2024-21887 | Command injection in VPN gateway |
| CVE-2025-0282 | Remote Code Execution (RCE) |
By compromising Azure AD Connect systems, attackers forced directory synchronization to push malicious identity changes across the entire hybrid environment.
Phishing campaigns launched; Credentials harvested from contractors; Initial VPN footholds established.
Internal systems show abnormal behavior; Minor application failures observed but categorized as maintenance issues.
Active Directory exploration; VMware infrastructure accessed; Backup systems and snapshots identified for destruction.
Disaster recovery systems begin failing; Storage operation errors detected as attackers begin deleting volumes.
Backup systems wiped (near 100%); Storage volumes deleted; Public services go offline as systems collapse.
Attack officially announced by Handala via public channels, detailing the theft and destruction.
Attackers have claimed that backup systems were specifically targeted first, suggesting that once primary storage was wiped, recovery paths may have been limited or unavailable. These claims have not been independently verified.
Petabyte-scale environments reportedly affected, including large database systems.
Attackers claim backup appliances and snapshots were erased to hinder restoration.
Potential widespread disruption across identity systems, email services, and virtual machine clusters (unconfirmed).
The reported data exfiltration is based on attacker statements and should be treated as unverified. If accurate, the scope suggests a highly targeted and strategic operation.
Beyond the technical breach and data destruction, several critical insights highlight the true depth and intent of this operation.
The attackers positioned the operation as a preemptive warning to regional governments, indicating that the objective extended beyond disruption. The messaging suggests an ongoing campaign, with explicit indications that similar or escalated actions could follow.
The attackers asserted that the impact extended beyond internal systems, causing broader disruptions affecting city-level operations and services. While not independently verified, this claim reflects an attempt to frame the attack as national-scale disruption rather than a contained cyber incident.
Evidence released by the attackers indicates:
The exposed environments included logs, dashboards, and monitoring tools, suggesting that attackers were not only present but also observing system activity in real time.
Evidence indicates access to structured operational and infrastructure-related data, including system configurations and network-linked assets.
The attack leveraged native enterprise tools and administrative consoles, rather than relying solely on external malware.
The deletion process indicates:
In response to the scale and sophistication of this attack, organizations should implement the following critical security measures:
Recent threat intelligence observations highlight a growing convergence of advanced cyber campaigns, critical software vulnerabilities, and large-scale data exposure risks affecting organizations across the Middle East and beyond. These developments demonstrate how modern threat activity is increasingly combining technical exploitation with strategic targeting of infrastructure, users, and digital ecosystems.
A parallel analysis of publicly accessible development platforms revealed a concerning pattern of sensitive data exposure. Multiple repositories were identified containing real-world datasets, configuration files, and system-related information that could be leveraged for malicious purposes if left unaddressed.
Several notable threat patterns have emerged, reflecting a shift toward more coordinated and persistent threat activity, often combining multiple techniques within a single campaign:
One of the most significant findings involves the unintended exposure of sensitive data through publicly accessible code repositories. Investigations show that:
A generalized attack flow observed across multiple incidents includes the following scalable and highly automated stages:
This process requires minimal resources and increasingly relies on automation, making it extremely scalable and difficult to detect early in the attack chain.
These developments highlight several broader cybersecurity challenges that require a paradigm shift in defense strategies:
To address these risks, organizations should consider strengthening their security posture through these essential proactive measures:
A high-severity SQL injection vulnerability has been identified in enterprise privileged access management solutions developed by ManageEngine. The flaw affects both Password Manager Pro and PAM360, potentially enabling attackers with limited access to escalate privileges and perform unauthorized actions within the application environment.
This issue highlights the critical importance of securing identity and access management systems, which are often central to enterprise security architectures.
The vulnerability is caused by improper input validation, allowing malicious SQL queries to be executed. An attacker with a Password Auditor role—typically a low-privileged account—could exploit this flaw to:
The vulnerability impacts specific versions of ManageEngine's privileged access management tools. Organizations should review their deployments against the affected versions list below to determine their exposure.
| Product Name | Affected Versions | Fixed Version |
|---|---|---|
| Password Manager Pro | Versions 8600 to 13230 | Version 13231 |
| PAM360 | Versions up to 8530 | Version 8531 |
Given the role of privileged access management tools, successful exploitation could have far-reaching consequences across an organization's entire IT environment. Organizations using affected versions should take immediate action:
This vulnerability underscores a broader security challenge: even limited-access roles within critical systems can become entry points for escalation if not properly secured. SQL injection remains a persistent and highly effective attack technique, particularly in systems handling sensitive authentication and authorization data.
Organizations must prioritize the security of identity and access management platforms, ensuring they are continuously updated, monitored, and hardened against evolving threats.
A critical vulnerability has been identified in protobuf.js, a widely adopted JavaScript implementation of Protocol Buffers used across Node.js and browser-based applications. With a CVSS score of 9.4, this flaw poses a severe risk, as it enables remote code execution (RCE) through the processing of malicious protobuf schema definitions.
Due to the library's extensive use in modern cloud-native and microservice architectures, the attack surface is exceptionally broad. Any application that processes external or dynamically loaded protobuf schemas is potentially at risk of full system compromise.
The vulnerability resides in the parsing and compilation of protobuf definitions within protobuf.js. The library fails to adequately sanitize or restrict the content of type definitions during schema processing, allowing an attacker to inject arbitrary JavaScript expressions that are subsequently evaluated within the application's runtime environment.
Attackers can weaponize this flaw by following a straightforward exploitation chain against any vulnerable application processing external or user-supplied schemas:
Attacker crafts a malicious protobuf schema file (.proto or JSON descriptor) containing JavaScript payloads embedded within type definitions.
Malicious JavaScript is injected into field names, type references, or other schema elements that the parser processes without sufficient sanitization.
The target application processes the malicious schema using functions such as Type.decode(), Root.fromJSON(), or equivalent schema-loading methods.
The injected payload executes within the application runtime with the process's full privileges – leading to complete system compromise, data exfiltration, or backdoor deployment.
The vulnerability affects all applications using the following versions of the protobuf.js package. Both major supported branches are impacted. Upgrade immediately to the patched releases.
| Branch | Affected Versions | Patched Version | Risk |
|---|---|---|---|
| protobuf.js v8.x | ≤ 8.0.0 | 8.0.1 | CRITICAL |
| protobuf.js v7.x | ≤ 7.5.4 | 7.5.5 | CRITICAL |
.proto files or JSON descriptors at runtime – are at significantly elevated risk of exploitation.
CyberShelter strongly advises immediate remediation across all environments where protobuf.js is in use. Development, staging, and production environments must all be assessed and patched without delay.
Root.fromJSON(), Type.decode()) to identify unsafe patterns that process unvalidated input.This vulnerability exemplifies the growing threat posed by vulnerabilities in foundational open-source libraries. protobuf.js underpins countless modern applications – from microservices and gRPC APIs to cloud-native platforms and IoT devices – making this flaw a significant supply chain risk.
The availability of a public proof-of-concept dramatically accelerates the threat timeline. Organizations that delay patching should assume active exploitation attempts are occurring or imminent. The combination of a near-perfect CVSS score (9.4), broad deployment footprint, and a working PoC makes this one of the most urgent vulnerabilities of 2026.
npm audit across all Node.js projects to identify affected dependencies. Patch within 24 hours for internet-facing services. For environments where immediate patching is not possible, disable all dynamic or external schema loading and implement strict network-layer controls around affected services.
A high-severity vulnerability has been identified in ManageEngine Log360, a widely used log management and security analytics solution. This flaw could allow unauthorized users to bypass authentication mechanisms and gain access to sensitive data and restricted system functionality through exposed APIs.
The vulnerability is particularly critical given that log management platforms sit at the core of an organization's detection and response capabilities. Compromise of these systems can fundamentally undermine security visibility and trust boundaries.
The vulnerability arises from improper authorization checks within exposed V1 APIs in ManageEngine Log360. Due to this weakness, an attacker may be able to bypass authentication controls entirely and interact with the system without valid credentials.
The exposed API endpoints fail to enforce consistent authentication validation, creating a logic gap that allows unauthenticated requests to reach sensitive backend functionality. This type of broken access control is a fundamental security design failure that cannot be mitigated through network controls alone – the underlying code must be patched.
The following ManageEngine Log360 build versions are confirmed to contain the authentication bypass vulnerability. Organizations running any build within the affected range must upgrade immediately.
| Product | Affected Build Range | Fixed Version | Action Required |
|---|---|---|---|
| ManageEngine Log360 | Build 13000 to 13013 | Build 13017 or later | Upgrade Immediately |
CyberShelter strongly recommends the following immediate and ongoing actions for all organizations running ManageEngine Log360:
Upgrade ManageEngine Log360 to build 13017 or later. This is the highest priority action and should be treated as an emergency patch deployment.
Restrict network-level access to Log360's management interface and V1 API endpoints. Implement IP allowlisting and firewall rules to limit exposure.
Layer additional authentication and access controls (MFA, reverse proxy authentication) in front of the Log360 management interface as a compensating control.
Perform a thorough review of all exposed API endpoints and configurations to ensure no other endpoints bypass authentication or authorization controls.
Immediately enable monitoring and alerting for suspicious or unauthorized API activity targeting Log360 endpoints, particularly V1 API calls from unexpected sources.
Conduct a forensic review of recent log entries and historical data to validate integrity – check for signs of tampering, deletion, or unauthorized data access that may have occurred prior to discovery.
From a CyberShelter threat intelligence standpoint, authentication bypass vulnerabilities represent a high-impact risk, particularly when they affect security monitoring platforms. Attackers increasingly target logging and visibility tools to evade detection, remove traces of malicious activity, and gain insight into an organization's defensive mechanisms.
This highlights the critical need for defense-in-depth, where even internal security tools are continuously monitored, hardened, and validated. Security infrastructure must itself be treated as a high-value attack target and protected accordingly – including patching, access control, and behavioral monitoring of the tools themselves.
Observed the active exploitation of a medium-severity path traversal vulnerability in JFrog Artifactory that could allow an authenticated user to write data outside the intended Docker cache directory under specific remote-repository conditions.
Tracked as CVE-2026-66384, the vulnerability has a CVSS score of 5.3 (Medium).
Although the severity is moderate, the confirmed active exploitation in the wild significantly increases the urgency for organizations operating affected self-hosted Artifactory deployments.
Organizations should identify affected Artifactory instances and apply the appropriate security updates without delay.
Severity: Medium
CVSS Score: 5.3
CWE: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory
Affected Product: JFrog Artifactory
User Interaction: Not required
Attack Status: Actively exploited in the wild
The vulnerability could allow an authenticated attacker to write data outside the intended Docker cache path when specific remote-repository conditions are present.
Successful exploitation could therefore enable unauthorized modification of files outside the designated cache directory, potentially affecting the integrity of the Artifactory environment.
Organizations should identify their deployed Artifactory release branch and determine whether the installed version falls within the affected range.
| Release Branch | Fixed Version |
|---|---|
| Artifactory 7.146.x | 7.146.35 |
| Artifactory 7.161.x | 7.161.16 |
Organizations should upgrade to the appropriate fixed release based on their deployed Artifactory branch.
Successful exploitation could allow an authenticated attacker to:
The risk is heightened by the fact that the vulnerability is actively exploited in the wild.
Self-hosted deployments running affected versions should be upgraded immediately to the applicable fixed release.
According to the supplied advisory, JFrog has already fortified affected cloud environments, and no customer action is required based on the advisory.
CVE-2026-66384 is being actively exploited in the wild despite its Medium severity rating.
Organizations operating affected self-hosted Artifactory deployments should therefore prioritize remediation based on exploitation status rather than CVSS severity alone.
Immediately upgrade affected JFrog Artifactory installations to:
Apply the version corresponding to the deployed release branch.
Inventory all JFrog Artifactory deployments and determine their current versions and repository configurations.
Pay particular attention to remote repositories and Docker cache configurations that could meet the conditions required for exploitation.
Because exploitation requires authentication, review Artifactory accounts and ensure users have only the permissions necessary for their roles.
Review Artifactory and host-level logs for:
For actively exploited environments, review historical logs and filesystem activity for unauthorized changes and determine whether suspicious activity occurred before patching.
Although CVE-2026-66384 is rated Medium severity with a CVSS score of 5.3, the confirmed active exploitation in the wild makes this vulnerability a significant operational concern for organizations running affected self-hosted JFrog Artifactory deployments.
Organizations should prioritize immediate patching, review remote-repository and Docker cache configurations, and investigate affected systems for signs of unauthorized file modifications.
Recommended Action: Upgrade self-hosted JFrog Artifactory to 7.146.35 or 7.161.16, as applicable, and review logs for potential exploitation.
| Date | 1 September 2026 |
| Vendor | JFrog |
| Product | JFrog Artifactory |
| CVE | CVE-2026-66384 |
| Severity | Medium |
| CVSS | 5.3 |
| CWE | CWE-22 |
| Attack Status | Actively Exploited in the Wild |
| Affected Versions | Earlier than 7.146.35 and 7.161.0 through versions earlier than 7.161.16 |
| Fixed Versions | 7.146.35 / 7.161.16 |
| Primary Risk | Unauthorized File Modification |
| Recommended Action | Immediately patch affected self-hosted Artifactory deployments and investigate for potential exploitation. |
A critical vulnerability affecting Apache ActiveMQ has been added to the Known Exploited Vulnerabilities (KEV) Catalog, indicating confirmed active exploitation. The inclusion in this catalog signals that the vulnerability is not only theoretical but is already being leveraged in real-world attack scenarios.
This issue presents a significant risk to organizations relying on messaging infrastructure for application integration and data exchange.
The issue stems from insecure default configurations within the Jolokia JMX-HTTP bridge exposed via the endpoint /api/jolokia/. This interface, when improperly secured, allows execution of sensitive operations through exposed management endpoints.
Specifically, Jolokia access policies permit execution (exec) operations across ActiveMQ MBeans. Critical broker management methods are exposed, including:
An authenticated attacker can exploit these capabilities to inject malicious configurations, ultimately achieving remote code execution (RCE) on the server.
The vulnerability impacts both the standalone broker and the all-in-one distributions of Apache ActiveMQ. Review the versions safely patched against this vulnerability:
| Product Name | Affected Versions | Fixed Version |
|---|---|---|
| Apache ActiveMQ Broker | Before 5.19.4 6.0.0 to 6.2.2 |
5.19.4 or later 6.2.3 or later |
| Apache ActiveMQ (All-in-One Distribution) |
Before 5.19.4 6.0.0 to 6.2.2 |
5.19.4 or later 6.2.3 or later |
Given the central role of message brokers in enterprise architectures, exploitation could lead to widespread compromise across interconnected services. Organizations should take immediate steps to mitigate risk:
/api/jolokia/) to legitimate administrative addresses only.The active exploitation of this vulnerability highlights a recurring issue in enterprise systems–exposed management interfaces with permissive default configurations. Attackers increasingly target these components as they often provide powerful control over system behavior and facilitate lateral movement.
Organizations must ensure that administrative interfaces are not only patched but also properly secured by default, continuously monitored, and restricted to trusted operational zones.
The identified vulnerabilities span several critical weakness categories commonly exploited in browser-integrated operating systems. These include:
The following 11 vulnerabilities are classified as high severity in this LTS release:
| CVE ID | Type | Affected Component | Severity |
|---|---|---|---|
| CVE-2026-4679 | Integer Overflow | Fonts | HIGH |
| CVE-2026-4449 | Use-after-free | Blink | HIGH |
| CVE-2026-4674 | Out-of-bounds Read | CSS | HIGH |
| CVE-2026-4442 | Heap Buffer Overflow | CSS | HIGH |
| CVE-2026-4451 | Insufficient Input Validation | Navigation | HIGH |
| CVE-2026-3922 | Use-after-free | MediaStream | HIGH |
| CVE-2026-5280 | Use-after-free | WebCodecs | HIGH |
| CVE-2026-4458 | Use-after-free | Extensions | HIGH |
| CVE-2026-3923 | Use-after-free | WebMIDI | HIGH |
| CVE-2026-4454 | Use-after-free | Network | HIGH |
| CVE-2026-4675 | Heap Buffer Overflow | WebGL | HIGH |
The following 4 vulnerabilities are classified as medium severity:
| CVE ID | Type | Affected Component | Severity |
|---|---|---|---|
| CVE-2026-5291 | Inappropriate Implementation | WebGL | MEDIUM |
| CVE-2026-5292 | Out-of-bounds Read | WebCodecs | MEDIUM |
| CVE-2026-5282 | Out-of-bounds Read | WebCodecs | MEDIUM |
| CVE-2026-4462 | Out-of-bounds Read | Blink | MEDIUM |
This LTS update also includes patches for 14 previously identified vulnerabilities tracked under the following CVE identifiers:
| CVE ID | CVE ID | CVE ID |
|---|---|---|
| CVE-2025-37752 | CVE-2025-37756 | CVE-2025-37797 |
| CVE-2025-37890 | CVE-2025-37997 | CVE-2025-38000 |
| CVE-2025-38001 | CVE-2025-38083 | CVE-2025-38177 |
| CVE-2025-38350 | CVE-2025-38477 | CVE-2025-38616 |
| CVE-2025-38617 | CVE-2025-38618 | — |
Successful exploitation of these vulnerabilities could result in a range of high-impact outcomes across affected ChromeOS devices. The integrated browser-OS architecture means a single compromised web session can cascade into full OS-level compromise.
Use-after-free and heap buffer overflow vulnerabilities in components such as Blink, WebCodecs, and WebGL can be chained to gain remote code execution within the renderer process. A renderer escape combined with a kernel-level privilege escalation could result in full system compromise.
Memory corruption flaws – particularly those affecting the Font engine and Navigation subsystem – can be exploited to corrupt critical data structures, destabilize the OS, or execute attacker-controlled payloads at elevated privilege levels.
Out-of-bounds read vulnerabilities in CSS parsing and WebCodecs processing may expose sensitive memory contents, including credentials, session tokens, or decrypted data cached by browser and OS components.
Insufficient input validation in the Navigation subsystem and inappropriate implementation in WebGL could allow attackers to bypass security restrictions such as origin policies, sandbox boundaries, or permission checks – particularly when combined with malicious web content.
Several memory corruption vulnerabilities, if triggered without controlled exploitation, can result in application crashes, OS-level instability, or complete device unavailability – impacting endpoint productivity and continuity.
Organizations and individuals should verify their ChromeOS devices are running the following minimum version:
| Channel | Version | Platform Version | Status |
|---|---|---|---|
| ChromeOS LTS-138 | 138.0.7204.310 | 16295.95.0 or later | ✓ PATCHED |
CyberShelter recommends the following immediate and ongoing actions for all organizations operating ChromeOS device fleets:
Ensure all ChromeOS devices are updated to version 138.0.7204.310 (Platform Version: 16295.95.0 or later). Prioritize managed enterprise and government devices with access to sensitive systems.
Configure automatic update policies via Google Admin Console for all organizational ChromeOS devices to ensure continuous, timely application of security patches without manual intervention.
Security fixes are not fully active until the device has been restarted. Enforce or schedule managed restarts across all enrolled devices to complete the patching process.
Deploy or review endpoint monitoring tools for unusual process activity, unexpected network connections, or privilege escalation attempts that may indicate exploitation activity prior to patching.
Identify and quarantine any devices running ChromeOS versions outside the LTS-138 support window. Block these devices from accessing enterprise resources until they are brought into compliance.
Integrate ChromeOS device telemetry into SIEM and EDR/XDR platforms. Leverage Google Workspace security alerts and Chrome Browser Cloud Management for centralized visibility and threat response.
A critical architectural vulnerability has been identified in the Model Context Protocol (MCP), originally introduced by Anthropic. Unlike traditional software bugs, this issue is a design-level weakness that can enable remote code execution (RCE) across systems using MCP-based integrations. The flaw stems from unsafe architectural defaults in how MCP handles configuration and execution via the STDIO (standard input/output) interface.
This vulnerability has far-reaching implications, potentially impacting thousands of deployments and significantly increasing risks across the rapidly growing AI supply chain ecosystem. It propagates across AI frameworks, developer tools, and automation platforms, making it a systemic supply chain risk.
The vulnerability originates from unsafe defaults in how the protocol maps configuration inputs to command execution. Specifically, the lack of strict validation or sandboxing for STDIO interactions allows attackers to execute arbitrary operating system commands by influencing the MCP configuration environment.
Attackers can leverage multiple high-impact attack paths against vulnerable MCP integrations:
Direct execution of arbitrary OS commands via the MCP STDIO interface by manipulating input streams.
Prompt injection attacks that lead to unintended configuration manipulation and subsequent command execution.
Delivering weaponized MCP server configurations through public marketplaces to compromise developer environments.
Executing hidden commands via network-based triggers that exploit the protocol's execution logic without requiring traditional authentication.
The issue affects multiple programming environments (Python, TypeScript, Java, Rust) and has been observed across several widely used AI and automation projects. Successful exploitation could result in full system compromise and unauthorized access to sensitive credentials.
| CVE ID | Target Project | Status |
|---|---|---|
| CVE-2025-65720 | GPT Researcher | Analyzed |
| CVE-2026-30623 | LiteLLM | Patched |
| CVE-2026-30615 | Windsurf | Analyzed |
| CVE-2026-40933 | Flowise | Analyzed |
| CVE-2026-26015 | DocsGPT | Patched |
| CVE-2025-54136 | Cursor | Analyzed |
The impact of this vulnerability is significant, as it grants attackers system-level access through the AI integration layer. Successful exploitation typically results in:
CyberShelter strongly advises organizations to implement the following controls to mitigate the risk of MCP-based exploitation:
Limit public exposure of all MCP-enabled services and segment them from critical internal networks.
Run MCP services within strictly sandboxed or containerized environments with limited permissions.
Treat all external MCP configurations as untrusted input and implement strict validation schemas.
Log and monitor all MCP tool executions and command invocations for anomalous patterns.
A critical vulnerability has been identified in ASUSTOR’s ADM operating system, specifically affecting the PPTP VPN client component. Tracked as CVE-2026-6644, this flaw carries a CVSS score of 9.4 and enables attackers to execute arbitrary system commands, potentially leading to full device compromise.
Given the widespread use of ASUSTOR NAS devices in enterprise, SMB, and personal environments, this vulnerability represents a significant security risk to organizational data integrity.
The vulnerability is caused by improper input validation and lack of sanitization before executing system-level shell commands within the PPTP VPN client configuration interface. This allows malicious input to be injected and executed within the system environment with elevated privileges.
Multiple versions of ASUSTOR Data Master (ADM) are impacted by this flaw. Organizations should review their deployment versions immediately:
| ADM Version | Status | Recommended Action |
|---|---|---|
| ADM 5.0 | Vulnerable | Upgrade to 5.1.3.RGL1 or later |
| ADM 4.3 / 4.2 / 4.1 | Fix in Progress | Disable PPTP VPN component |
Organizations and users should take immediate steps to mitigate risk and secure their NAS environments:
Apply the update to ADM version 5.1.3.RGL1 or later immediately to patch the injection path.
Disable the PPTP VPN client component if it is not explicitly required for business operations.
Restrict administrative interface access to known, trusted IP ranges only via firewall rules.
Enable and monitor system logs for unusual activity or unauthorized configuration changes.
Regularly back up critical data to secure, off-site, and immutable locations to ensure recovery readiness.
From the CyberShelter perspective, NAS systems are increasingly high-value targets due to the volume of sensitive data they contain. Command injection flaws remain one of the most critical vulnerability classes because they provide a direct path to system-level execution, bypassing application-level security controls.
Microsoft has released out–of–band security updates to address a critical vulnerability affecting the ASP.NET Core framework. Tracked as CVE-2026-40372, this flaw carries a CVSS score of 9.1 and could allow attackers to perform remote privilege escalation to SYSTEM level.
The vulnerability primarily impacts applications using the Data Protection component, making it a significant risk for modern web applications relying on secure token management and session integrity.
The vulnerability arises from a logic error in how the `Microsoft.AspNetCore.DataProtection` library validates cryptographic signatures. This weakness can be exploited to forge authentication tokens, bypass authentication mechanisms, and ultimately escalate privileges to SYSTEM level on the hosting environment.
Because the flaw resides in the core token validation logic, exploitation may persist even after patching unless existing keys and sessions are actively remediated.
Successful exploitation of this vulnerability has severe consequences for application security and organizational data privacy:
| Impact Category | Severity | Description |
|---|---|---|
| Privilege Escalation | CRITICAL | Gaining SYSTEM-level access on the application host. |
| Authentication Bypass | CRITICAL | Forging valid authentication tokens to impersonate any user. |
| Data Exposure | HIGH | Unauthorized access to sensitive application and user data. |
| Persistence | HIGH | Maintaining unauthorized access through forged long-lived tokens. |
Immediate remediation is critical to neutralize the risk of token forgery and privilege escalation. CyberShelter recommends the following multi-stage response:
Upgrade immediately to `Microsoft.AspNetCore.DataProtection` version 10.0.7 or later via NuGet.
Invalidate all previously issued cryptographic keys in the Data Protection key ring to neutralize forged tokens.
Force re-authentication for all users and revoke all active authentication tokens/sessions.
Review authentication logs for suspicious activity, particularly unusual privilege transitions or token use.
This vulnerability highlights a critical risk in modern application security–the absolute reliance on cryptographic mechanisms for authentication and trust. When these underlying primitives are implemented or validated incorrectly, the entire security model of the application collapses.
Recent security updates have been released by Mozilla and Atlassian to address multiple vulnerabilities affecting widely used browser, email, and enterprise collaboration platforms. These flaws encompass remote code execution (RCE), memory corruption, privilege escalation, and command injection, posing severe risks to global IT infrastructure.
If exploited, these vulnerabilities could lead to full system compromise, persistent unauthorized access, or widespread service disruption across organizational networks.
Mozilla has patched numerous high-severity vulnerabilities impacting memory safety and DOM processing in current and ESR versions of Firefox and Thunderbird.
| CVE ID | Vulnerability Type | Impacted Component |
|---|---|---|
| CVE–2026–6746 | Use–after–free | DOM (Core & HTML) |
| CVE–2026–6747 | Use–after–free | WebRTC |
| CVE–2026–6750 | Privilege Escalation | WebRender |
| CVE–2026–6754 | Use–after–free | JavaScript Engine |
| CVE–2026–6749 | Information Disclosure | Canvas2D |
| CVE–2026–6748 | Uninitialized Memory | Web Codecs |
The April 2026 Atlassian advisory addresses critical and high–severity flaws across the Data Center and Server ecosystem. These vulnerabilities range from OS command injection to remote code execution via insecure third–party dependencies.
| CVE ID | Product | Description |
|---|---|---|
| CVE–2026–21571 | Bamboo | OS Command Injection |
| CVE–2022–1471 | Confluence / Jira / JSM | RCE via SnakeYAML deserialization |
| CVE–2024–47875 | Jira / JSM | mXSS (dompurify) |
| CVE–2026–25547 | Jira / JSM | DoS (brace–expansion) |
Additional vulnerabilities impacting Bamboo, Bitbucket, Confluence, and Jira include HTTP request smuggling, path traversal, and file inclusion flaws predominantly localized in Tomat and Netty components.
The collective impact of these vulnerabilities provides attackers with multiple vectors for gaining a foothold in the enterprise environment:
Patch all Mozilla clients and Atlassian Data Center/Server instances to the specified fixed versions within 48 hours.
Ensure Atlassian management interfaces are not directly exposed to the internet; leverage VPNs or ZTNA for access.
Validate third–party library versions (Netty, Tomcat, dompurify) in custom–built internal applications.
Monitor application logs for unusual file writes or unexpected command executions indicative of path traversal or injection attempts.
A high-severity vulnerability has been identified in the Microsoft Defender Antimalware Platform and is actively exploited in the wild. Tracked as CVE-2026-33825, this flaw enables local attackers with low privileges to escalate access to SYSTEM level, potentially resulting in full system compromise.
The fact that this vulnerability is actively exploited highlights the importance of rapid patching and endpoint visibility. Immediate remediation is essential to prevent attackers from gaining full control over affected systems.
The vulnerability arises from insufficient access control enforcement (CWE-1220 – Insufficient Granularity of Access Control), allowing a low-privileged attacker to exploit the system and gain elevated privileges. Once exploited, attackers can execute actions with SYSTEM-level permissions, including disabling security controls and lateral movement across enterprise networks.
Successful exploitation could lead to severe consequences for the affected environment:
| Impact Area | Description |
|---|---|
| System Compromise | Full control over the local system with SYSTEM privileges. |
| Code Execution | Execution of arbitrary code with the highest possible permissions. |
| Security Evasion | Disabling or bypassing endpoint security and antimalware controls. |
| Persistence | Establishment of long-term access through privileged accounts. |
Organizations should take the following immediate steps to mitigate the risk of exploitation:
Update Microsoft Defender Antimalware Platform to version 4.18.26030.3011 or later across all endpoints.
Verify that updates are successfully deployed and active across all managed endpoints.
Monitor systems for suspicious privilege escalation activity and anomalous behavior in security services.
Restrict local access where possible and enforce strict least privilege policies to limit the attack surface.
A critical vulnerability has been identified in CrowdStrike’s LogScale, specifically impacting self-hosted deployments. Tracked as CVE-2026-40050, this flaw carries a CVSS score of 9.8, indicating a severe risk. The vulnerability allows unauthenticated remote attackers to perform path traversal attacks, potentially exposing sensitive files on the underlying system.
Notably, SaaS and Next-Gen SIEM deployments are not affected, but organizations using self-hosted instances must take immediate action to secure their infrastructure.
The vulnerability allows attackers to manipulate file paths in requests, enabling unauthorized access to files outside intended directories. This could expose sensitive system files, configurations, or application data without requiring authentication. If exploited, this could result in information disclosure that may aid in targeted attacks or lead to further system compromise.
Organizations should review their LogScale deployment versions immediately to determine if they are within the vulnerable range:
| Deployment Type | Affected Versions | Fixed Version |
|---|---|---|
| General Availability (GA) | 1.224.0 to 1.234.0 | 1.235.1, 1.234.1, or 1.233.1 |
| Long-Term Support (LTS) | 1.228.0 and 1.228.1 | 1.228.2 (LTS) or later |
CyberShelter recommends the following immediate steps for organizations using self-hosted LogScale deployments:
Upgrade to a patched version (1.235.1, 1.234.1, 1.233.1, or 1.228.2 LTS) to close the traversal path.
Restrict external access to LogScale instances and implement network-level access controls and firewall rules.
Actively monitor logs for suspicious file access attempts or anomalous request patterns targeting sensitive paths.
Conduct a comprehensive security review of all exposed services and apply the principle of least privilege.
From the CyberShelter perspective, log management and SIEM platforms are the "eyes and ears" of the SOC. A compromise at this level not only risks sensitive data disclosure but also threatens the integrity of the entire security monitoring pipeline. Path traversal vulnerabilities in such critical infrastructure must be treated with the highest priority.
Oracle Corporation has released its April 2026 Critical Patch Update (CPU), addressing a staggering total of 481 security vulnerabilities across 28 product families. This update is one of the most significant in recent cycles, with approximately 78% of the fixes (376 CVEs) targeting third-party components integrated into Oracle's ecosystem.
A substantial number of these vulnerabilities are classified as high to critical severity, with many enabling remote code execution (RCE) and unauthenticated network exploitation. This poses a severe risk to enterprise environments, potentially allowing full system compromise without the need for valid credentials.
The April 2026 CPU impact is concentrated in several key areas of the Oracle portfolio, with Communications and Financial Services seeing the highest volume of critical fixes.
This area received the highest number of updates, with 93 vulnerabilities being exploitable remotely without authentication. Critical CVEs such as CVE-2025-6965 and CVE-2025-12543 (CVSS 9.8) allow for complete system takeover.
Critical risks to financial transaction integrity have been addressed, including CVE-2023-34034 (CVSS 9.8), which could allow RCE in core banking and financial platforms.
Middleware continues to be a high-value target, with 46 unauthenticated vulnerabilities patched. Significant CVEs include CVE-2026-34285 and CVE-2026-34286 (both CVSS 9.8).
The following table summarizes the most critical vulnerabilities addressed in this update, requiring immediate remediation attention:
| Product Area | CVE ID | CVSS | Impact |
|---|---|---|---|
| Communications | CVE-2025-6965 | 9.8 | Remote Code Execution |
| Communications | CVE-2025-68615 | 9.6 | Full System Compromise |
| Financial Services | CVE-2023-34034 | 9.8 | Transaction Risk / RCE |
| Fusion Middleware | CVE-2026-34285 | 9.8 | Enterprise-wide RCE |
| MySQL Enterprise | CVE-2025-15467 | 9.8 | Backup/Data Exposure |
| E-Business Suite | CVE-2026-34275 | 9.8 | ERP Environment RCE |
CyberShelter strongly advises organizations to implement a prioritized patching strategy to address these risks before they are exploited in the wild:
Apply the April 2026 CPU patches immediately, starting with internet-facing and high-availability systems.
Focus first on Oracle Communications and Middleware deployments due to the high volume of RCE-level flaws.
Verify and restrict external access to critical services. Ensure all Oracle management consoles are behind a VPN/ZTNA.
Enable enhanced logging and monitor for exploitation attempts, particularly targeting unauthenticated endpoints.
From the CyberShelter perspective, the Oracle CPU is a "critical path" security event for the enterprise. Because Oracle products often sit at the core of business operations (ERP, Financials, Communications), a single unauthenticated RCE can serve as an entry point for widespread lateral movement across the entire network.
NVIDIA has released urgent security updates to address multiple vulnerabilities affecting CUDA-Q and KAI Scheduler. These components are critical for high-performance computing (HPC) and AI development environments. The identified flaws could allow attackers to perform denial-of-service (DoS) attacks, access sensitive information, or manipulate data, depending on the affected component and exploitation method.
Given the rapid adoption of AI infrastructure, ensuring the security of these specialized scheduling and execution environments is paramount for organizational data integrity and service availability.
| CVE ID | Component | Severity | Impact |
|---|---|---|---|
| CVE-2026-24189 | CUDA-Q | HIGH | Out-of-bounds Read / DoS / Info Disclosure |
| CVE-2026-24177 | KAI Scheduler | HIGH | Unauthorized API Access / Info Disclosure |
| CVE-2026-24176 | KAI Scheduler | MEDIUM | Improper Authorization / Data Manipulation |
CVE-2026-24189: An out-of-bounds read vulnerability in a CUDA-Q endpoint allows unauthenticated attackers to trigger DoS or leak information via crafted requests.
CVE-2026-24177: Improper access control in KAI Scheduler allows unauthorized interaction with API endpoints, exposing sensitive system information.
CVE-2026-24176: Involves improper authorization through cross-namespace pod references, potentially allowing unauthorized access across workloads.
CyberShelter recommends the following immediate steps for organizations using affected NVIDIA AI infrastructure:
Upgrade CUDA-Q to 0.14.0+ and KAI Scheduler to 0.13.0+ to close the vulnerability windows.
Restrict access to exposed APIs and endpoints using network segmentation and robust authentication.
Monitor systems for unusual activity or unauthorized access attempts targeting AI orchestration components.
Apply strict least-privilege principles across workloads and review container isolation policies.
As AI workloads become increasingly integrated into enterprise operations, the security of the underlying infrastructure—including schedulers and execution runtimes—becomes a critical point of failure. These vulnerabilities demonstrate that even high-performance components require the same rigorous security auditing as traditional web applications.
A high-severity vulnerability (CVE-2026-33797) has been identified in Juniper Networks' Junos OS and Junos OS Evolved. This flaw allows an unauthenticated attacker to disrupt network operations by resetting Border Gateway Protocol (BGP) sessions, resulting in a Denial-of-Service (DoS) condition.
Given the critical role of BGP in routing internet and enterprise network traffic, exploitation of this vulnerability can significantly impact network stability and availability.
The vulnerability arises from insufficient validation of BGP packets. Successful exploitation results in forced reset of BGP sessions, disruption of routing operations, and sustained denial-of-service if repeatedly triggered. This issue affects both eBGP (external BGP) and iBGP (internal BGP) across IPv4 and IPv6 environments.
| Product | Affected Versions | Fixed Version |
|---|---|---|
| Junos OS | 25.2 prior to 25.2R2 | 25.2R2, 25.4R1, or later |
| Junos OS Evolved | 25.2-EVO prior to 25.2R2-EVO | 25.2R2-EVO, 25.4R1-EVO, or later |
CyberShelter recommends the following immediate steps for organizations using affected Juniper devices:
Upgrade to the latest fixed versions (25.2R2 or later) to address the input validation flaw.
Monitor BGP sessions for unusual resets or instability using SNMP or telemetry data.
Restrict access to BGP peers and trusted network segments using TTL security (GTSM) and MD5/TCP-AO.
Implement network-level filtering and validation controls to prevent crafted packet injection.
BGP is the foundational protocol for internet routing, and its security is paramount. Vulnerabilities that allow session disruption can have cascading effects on global connectivity. Organizations must adopt a "defense-in-depth" approach to routing security, combining patching with robust peer authentication and monitoring.
A critical vulnerability is being actively exploited in D-Link DIR-823X routers, enabling attackers to compromise devices and deploy botnet malware. Tracked as CVE-2025-29635, this flaw allows remote command injection and is currently being used to distribute Mirai botnet variants, facilitating large-scale distributed denial-of-service (DDoS) attacks and persistent device compromise.
As these devices are end-of-life (EOL), no official security patches are available, significantly increasing the risk for organizations and home users still utilizing this hardware.
The vulnerability primarily impacts the D-Link DIR-823X series routers. Confirmed affected firmware versions include:
Status: These devices reached End-of-Life (EOL) as of September 2025, meaning no further security updates or support will be provided by the vendor.
Threat actors are actively leveraging this flaw to execute arbitrary commands, deploy Mirai-based botnet payloads, and maintain persistent access for coordinated DDoS attacks.
| Type | Value |
|---|---|
| IP Address | 88.214.20.14 |
| IP Address | 64.89.161.130 |
| SHA256 Hash | 2ca4b70e84787144574bfdb85a0092f3ebf524bb78febdd28d4c832b53fe100 |
| SHA256 Hash | be902e86ec68515e23a3387a21e80d098d258223ce562598c27ee6d89b83ff2b |
| SHA256 Hash | d232c0960f24ba4bb369821b1bf2836d9e576a34fa3ddca2618c80b2f54277f7 |
| SHA256 Hash | 7792f5c1d5c6c6415732ba0f63328549e19cc9c182c258c17b97b77fdb5541b8 |
| SHA256 Hash | 72eff03b8573329818b38185074aa763e99d15f5709fecc44f9afece21dc06d8 |
Given the lack of vendor patches, immediate decommission and replacement of affected hardware is the only reliable remediation.
Replace all D-Link DIR-823X routers immediately with supported, modern hardware.
Implement network-level blocking for identified IOC addresses: 88.214.20.14 and 64.89.161.130.
Detect unusual outbound connections and monitor traffic to unknown external hosts or high-numbered ports.
Segment IoT and networking devices from critical systems to prevent lateral movement in case of compromise.
From the CyberShelter perspective, this case highlights the severe risks associated with end-of-life network devices. Without security updates, such devices become permanent targets for botnet operators. Command injection vulnerabilities, especially when combined with weak authentication, provide attackers with direct control, enabling rapid exploitation at scale.
Recent security updates have been released by Mozilla and Google to address multiple vulnerabilities in Mozilla Firefox, Firefox ESR, and Google Chrome. These vulnerabilities include memory safety flaws, remote code execution risks, sandbox escape conditions, and information disclosure issues, which could be exploited through malicious web content.
| Severity | CVE ID | Vulnerability Type |
|---|---|---|
| Critical | CVE-2026-7322 | Memory Safety Vulnerabilities |
| High | CVE-2026-7320 | Information Disclosure (Audio/Video) |
| High | CVE-2026-7323 | Memory Safety Vulnerabilities |
| High | CVE-2026-7324 | Memory Safety Vulnerabilities |
| Moderate | CVE-2026-7321 | Sandbox Escape (WebRTC) |
Google has released Chrome 147 Stable updates addressing 30 vulnerabilities, including several critical issues across Windows, macOS, Linux, and Android.
Use-After-Free in Canvas
Use-After-Free in iOS
Use-After-Free in Accessibility
Use-After-Free in Views
Successful exploitation of these vulnerabilities could lead to full system compromise via the web browser.
Update Firefox and Chrome immediately to the latest versions across all platforms.
Ensure automatic update mechanisms are enabled for all corporate and personal devices.
Remind users that updates are not applied until the browser process is restarted.
Use EDR solutions to monitor for suspicious child processes originating from web browsers.
A high-impact vulnerability has been identified in OpenSSH that could allow authentication bypass under specific conditions. Tracked as CVE-2026-35414, this flaw affects OpenSSH versions prior to 10.3 and may enable unauthorized users with valid certificates to gain elevated access, potentially including root-level privileges.
authorized_keys principals option when used in combination with certificate-based authentication and specially crafted or malformed principal names.
| CVE ID | CVE-2026-35414 |
| Severity | High (CVSS 8.1) |
| Vulnerability Type | Authentication Bypass |
| CWE Classification | CWE-670 (Always-Incorrect Control Flow Implementation) |
| Affected Versions | OpenSSH < 10.3 |
| Fixed Version | OpenSSH 10.3 or later |
If exploited, this vulnerability could result in severe security breaches across the enterprise infrastructure.
Upgrade OpenSSH to version 10.3 or later without delay to patch the vulnerability.
Audit all configurations involving certificate-based authentication and principals options.
Investigate SSH authentication logs for unusual activity or malformed principal name attempts.
Enforce strict least-privilege principles and restrict SSH access to trusted networks only.
This vulnerability highlights the risks associated with advanced authentication mechanisms, particularly when complex configurations are involved. While certificate-based authentication enhances security, misconfigurations or implementation flaws in control flow can introduce critical weaknesses. Continuous validation of authentication logic is essential for maintaining a secure posture.
Microsoft has confirmed active exploitation of a vulnerability in Windows Shell, tracked as CVE-2026-32202. Originally disclosed on April 14, 2026, and updated on April 27, 2026, this vulnerability is classified as a Protection Mechanism Failure (CWE-693). While it carries a relatively low CVSS score of 4.3, confirmed exploitation in the wild significantly increases its operational risk.
| CVE ID | CVE-2026-32202 |
| Component | Windows Shell |
| Vulnerability Type | Protection Mechanism Failure (CWE-693) |
| Impact Type | Spoofing |
| Severity | Important (CVSS 4.3) |
| Exploitation Status | Actively Exploited |
Attackers deliver a crafted malicious file to the target. Upon execution, the file triggers spoofed content presentation via Windows Shell. The vulnerability is reportedly linked to an incomplete patch for CVE-2026-21510, allowing bypass conditions to persist.
Deploy April 2026 Patch Tuesday updates immediately to address this vulnerability.
Ensure EDR/XDR solutions are updated and capable of detecting spoofed file execution patterns.
Educate users to avoid executing files from untrusted sources and verify file authenticity before opening.
Monitor for suspicious file execution activity and investigate anomalies related to file behavior or display inconsistencies.
This vulnerability highlights how even lower-severity flaws can pose significant risks when actively exploited. Spoofing vulnerabilities are particularly dangerous as they exploit user trust and perception, often serving as entry points for more severe attacks. The incomplete patch scenario also underscores the importance of continuous monitoring even after initial remediation.
Multiple high-impact vulnerabilities have been identified in Apache ActiveMQ that could allow authenticated attackers to execute arbitrary code on the broker's JVM and perform cross-site scripting (XSS) attacks via the web console. These vulnerabilities pose significant risks to organizations relying on ActiveMQ for messaging and integration, as exploitation could lead to full system compromise and unauthorized administrative access.
The vulnerabilities impact core components of the ActiveMQ broker, including the admin web console, the VM transport mechanism, and the Jolokia discovery transport.
An authenticated attacker can bypass broker name validation in the admin web console by injecting a malicious broker name containing an xbean binding. When a VM transport is created, the broker references this name and loads a remote Spring XML application context, resulting in arbitrary code execution on the JVM.
This vulnerability allows attackers to bypass prior mitigations using the Jolokia interface. By configuring an HTTP Discovery transport pointing to a malicious endpoint, the broker can be forced to load a crafted VM transport and a malicious Spring XML configuration, leading to RCE.
An authenticated attacker can inject malicious HTML into a JMS selector field. By manipulating response content type, malicious scripts can be rendered and executed in the administrator's browser, potentially leading to session hijacking.
Organizations using vulnerable versions of Apache ActiveMQ should identify exposed admin web consoles or Jolokia interfaces.
| Branch | Vulnerable Versions | Fixed Version |
|---|---|---|
| ActiveMQ 5.x | < 5.19.6 | 5.19.6 or later |
| ActiveMQ 6.x | < 6.2.5 | 6.2.5 or later |
Upgrade to Apache ActiveMQ 5.19.6 or 6.2.5 to address all identified CVEs.
Disable or restrict access to the Admin Web Console and Jolokia interface to trusted networks only.
Implement multi-factor authentication (MFA) and strict access controls for administrative users.
Monitor logs for suspicious configuration changes, unauthorized transport activity, or xbean binding attempts.
From the CyberShelter perspective, messaging middleware like ActiveMQ often acts as the nervous system of an enterprise. Vulnerabilities that allow RCE on the broker JVM are extremely dangerous as they provide a direct path to compromising the entire application ecosystem. The recurrence of Jolokia and xbean-related flaws highlights the need for rigorous input validation and the reduction of management surface areas.
A sophisticated supply chain attack has been identified involving the compromise of the Bitwarden CLI npm package. Threat actors attributed to TeamPCP (@pcpcats) published a malicious version @bitwarden/[email protected], which was available on the npm registry for approximately 93 minutes (April 22, 2026) before being removed.
Despite the short exposure window, the campaign demonstrates a highly advanced, wormable attack model targeting developer ecosystems and CI/CD pipelines. The attack is part of a broader campaign that also impacted Docker Hub images, GitHub Actions workflows, and VS Code extensions.
The attack mechanism involved the automatic execution via lifecycle scripts. The malicious package included execution triggers such as "preinstall": "node setup.mjs", which executes immediately upon installation.
The malicious package demonstrates advanced functionality, including:
The following Indicators of Compromise (IOCs) are associated with this attack and should be actively monitored and blocked.
| Type | Value |
|---|---|
| Domain | audit.checkmarx[.]cx |
| Domain | checkmarx[.]cx |
| IP Address | 94.154.172[.]43 |
| IP Address | 91.195.240[.]123 |
| GitHub Repos | helloworm00/hello-world, bc544f455d7c06c8a1f3446160a6d9a4a8236b11 |
| helloworm00@proton[.]me | |
| File Hash (SHA256) | f35475829991b303c5efc2ee0f343dd38f8614e8b5e69db683923135f85cf60d (bw_setup.js) |
| File Hash (SHA256) | 18f784b3bc9a0bcdcb1a8d7f51bc5f54323fc40cbd874119354ab609bef6e4cb (bw1.js) |
| File Hash (SHA256) | 167ce57ef59a32a6a0ef4137785828077879092d7f83ddbc1755d6e69116e0ad (package.json) |
Exposure is limited to environments that installed the specific malicious version during the short availability window. However, due to the wormable nature of the malware, there is a risk of secondary propagation and credential leakage across systems.
Check if the malicious package was installed by running npm list @bitwarden/cli and review CI/CD logs.
Immediately rotate all potentially exposed secrets: npm tokens, GitHub PATs, SSH keys, Cloud credentials, and CI/CD secrets.
Block all identified malicious domains and IP addresses at the network perimeter.
Review npm dependencies, audit GitHub repositories, and inspect CI/CD pipelines for unauthorized changes.
From the CyberShelter perspective, this incident highlights a significant evolution in supply chain threats–from isolated compromises to coordinated, wormable campaigns targeting developer trust and automation pipelines. The use of trusted platforms such as npm, GitHub, and CI/CD tools amplifies the impact, allowing attackers to scale rapidly and propagate across environments.
A critical vulnerability has been identified in cPanel & WHM that could allow unauthorized access to hosting control panels. The issue affects multiple supported versions and targets core authentication mechanisms used across both cPanel and WHM interfaces. Due to its potential impact, this vulnerability is considered high risk, even though full technical details have not been publicly disclosed at this time.
Hosting providers have already begun implementing temporary mitigations while deploying official patches, indicating the urgency of remediation for all organizations utilizing cPanel infrastructure.
If successfully exploited, this vulnerability could lead to widespread operational consequences, including:
Organizations should immediately verify their cPanel & WHM versions and upgrade to one of the following patched versions or later.
| Software | Status | Patched Versions |
|---|---|---|
| cPanel & WHM | VULNERABLE | Older than 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, 11.136.0.5 |
| cPanel & WHM | FIXED | 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, 11.136.0.5 |
Upgrade immediately to the latest patched version of cPanel & WHM across all managed systems.
Verify that updates are successfully applied and that no unauthorized administrative accounts have been created.
Enforce Multi-Factor Authentication (MFA) and strong password policies for all management accounts.
Restrict access to management interfaces (WHM/cPanel) to trusted IP ranges using firewalls or host access controls.
From the CyberShelter perspective, vulnerabilities in central management platforms like cPanel represent a significant systemic risk. These platforms often aggregate control over hundreds or thousands of websites and applications. An authentication bypass at this level provides threat actors with a "skeleton key" to the entire infrastructure. Rigorous patch management and the implementation of defense-in-depth measures, such as MFA and IP whitelisting, are critical for maintaining the integrity of hosting environments.
Mozilla has released security updates for Mozilla Thunderbird to address multiple vulnerabilities, including critical memory safety flaws, information disclosure issues, and sandbox escape conditions. These vulnerabilities could potentially be exploited to achieve arbitrary code execution, exposure of sensitive data, or bypass of security boundaries within email and browser-like contexts.
| CVE ID | Severity | Description |
|---|---|---|
| CVE-2026-7322 | CRITICAL | Memory safety vulnerabilities that may lead to memory corruption and potential arbitrary code execution. |
| CVE-2026-7320 | HIGH | Information disclosure in Audio/Video component caused by incorrect boundary conditions, potentially exposing sensitive data. |
| CVE-2026-7323 | HIGH | Memory safety vulnerabilities impacting various Thunderbird components. |
| CVE-2026-7324 | HIGH | Memory safety vulnerabilities impacting various Thunderbird components. |
| CVE-2026-7321 | MODERATE | Sandbox escape in WebRTC Networking component, allowing attackers to bypass security isolation under specific conditions. |
Organizations and users should update to the following versions immediately to ensure protection against these vulnerabilities.
| Software Branch | Status | Fixed Version |
|---|---|---|
| Thunderbird (Standard) | FIXED | 150.0.1 |
| Thunderbird ESR | FIXED | 140.10.1 |
Update Thunderbird to version 150.0.1 or ESR 140.10.1 immediately across all endpoints.
Ensure that the application is restarted after the update to ensure that all patches are correctly applied.
Avoid opening suspicious email attachments or clicking on untrusted links, which are common delivery vectors for these exploits.
Implement endpoint protection and exploit mitigation tools (e.g., EDR) to monitor for abnormal application behavior.
Email clients remain a critical attack surface, as they frequently process untrusted content such as attachments, links, and embedded media. Memory safety vulnerabilities, in particular, are often leveraged to achieve code execution. From the CyberShelter perspective, the complexity of modern email and browser-like environments necessitates continuous monitoring and rapid patching to mitigate the risk from sophisticated malicious content.
A critical vulnerability has been disclosed in GitHub and GitHub Enterprise Server (GHES) that could allow remote code execution (RCE) through a single malicious git push operation. Tracked as CVE-2026-3854, this flaw carries a CVSS score of 8.7 (High) and affects both cloud-hosted and self-managed environments.
The vulnerability is particularly concerning due to its low privilege requirement and potential impact on multi-tenant environments, where cross-tenant data exposure and lateral movement are significant risks.
The vulnerability arises from improper sanitization of user-supplied git push options. User-controlled input in git push options was not properly neutralized before being embedded into internal X-Stat headers.
Internal parsing relied on semicolon (;) delimiters, allowing attackers to inject malicious metadata fields by crafting input containing these delimiter characters. This led to command injection during internal processing, enabling the execution of arbitrary code.
The following platforms are affected by CVE-2026-3854:
Organizations using self-hosted GitHub Enterprise Server should upgrade to one of the following versions or later:
| Release Line | Patched Version |
|---|---|
| 3.14 | 3.14.25 |
| 3.15 | 3.15.20 |
| 3.16 | 3.16.16 |
| 3.17 | 3.17.13 |
| 3.18 | 3.18.7 |
| 3.19 | 3.19.4 |
| 3.20 | 3.20.0 |
Upgrade GitHub Enterprise Server to a patched version without delay. Verify patch levels across all instances.
Apply emergency patching for externally exposed environments and enforce least privilege for repository access.
Review logs for suspicious git push activity and unusual command execution patterns on GitHub infrastructure.
Audit repositories and user access permissions to ensure only authorized personnel have push access.
From the CyberShelter perspective, vulnerabilities in core development tools like GitHub represent a Tier-1 risk to the software supply chain. A compromise at this level can lead to the injection of malicious code into production applications, theft of intellectual property, and widespread disruption of development workflows.
Multiple high-severity vulnerabilities have been identified in Spring Cloud Config, a widely used platform for centralized configuration management in distributed and cloud-native environments. The most critical vulnerability, CVE-2026-40982, enables unauthenticated directory traversal attacks that may allow arbitrary file disclosure from affected servers. Additional vulnerabilities impact Google Cloud Platform (GCP) secret isolation, Git repository integrity, and sensitive logging mechanisms.
A directory traversal vulnerability allows attackers to exploit crafted URL requests to access files outside intended directories. This can lead to the exposure of /etc/passwd, application configuration files, secrets, credentials, and cloud authentication tokens.
This vulnerability affects secret isolation in Google Cloud Platform environments, potentially breaking intended isolation boundaries between GCP projects and allowing unauthorized retrieval of API keys and service account credentials.
| CVE ID | Description | Impact |
|---|---|---|
| CVE-2026-40982 | Directory Traversal | Arbitrary File Disclosure |
| CVE-2026-40981 | GCP Secret Exposure | Cross-Project Data Leakage |
A Time-of-Check-Time-of-Use (TOCTOU) race condition exists during Git repository cloning and validation operations, which could allow unauthorized file modification or the injection of malicious configuration artifacts.
Sensitive data may be written to plaintext logs when trace logging is enabled, exposing credentials through centralized logging systems such as SIEM platforms or ELK stacks.
The following versions of Spring Cloud Config are affected by these vulnerabilities:
| Component | Affected Versions | Fixed Versions |
|---|---|---|
| Spring Cloud Config Server | 3.1.x, 4.1.x, 4.2.x, 4.3.x, 5.0.x | 4.3.3, 5.0.3 |
Upgrade all Spring Cloud Config deployments to Version 4.3.3, 5.0.3, or later.
Apply strong authentication and network segmentation to restrict public exposure of Config Server instances.
Audit GCP Secrets Manager configurations and rotate exposed credentials if compromise is suspected.
Disable unnecessary trace logging and sanitize logs containing sensitive configuration values.
Multiple vulnerabilities have been identified in SonicWall SonicOS that could allow unauthorized access to management functions, interaction with restricted services, and denial-of-service (DoS) conditions. These issues affect several generations of SonicWall firewall appliances and require immediate attention to prevent potential exploitation.
The vulnerabilities impact core components of the SonicOS operating system, affecting hardware firewalls across Gen6, Gen7, and Gen8 platforms, as well as NSv virtual appliances.
Severity: High (CVSS 8.0)
This vulnerability may allow certain management interface functions to become accessible under specific conditions, potentially leading to unauthorized access to administrative capabilities and compromise of firewall management.
Severity: Medium (CVSS 6.8)
An authenticated attacker could exploit a path traversal issue to interact with restricted services, resulting in expanded access within the device and potential misuse of internal services.
Severity: Medium (CVSS 4.9)
A post-authentication vulnerability that may allow a privileged attacker to crash the firewall, leading to a denial-of-service (DoS) condition and disruption of network security services.
Organizations should identify their SonicWall firewall generation and upgrade to the following fixed versions immediately.
| Generation | Models | Fixed Version |
|---|---|---|
| Gen6 Hardware | SOHOW, TZ 300/400/500/600, NSA, SM, SOHO 250, TZ 350 | 6.5.5.2-28n |
| Gen7 & NSv | TZ270/370/470/570/670, NSa, NSsp, NSv (Cloud/Virtual) | 7.3.2-7010 |
| Gen8 Hardware | TZ80/280/380/480/580/680, NSa 2800/3800/4800/5800 | 8.2.0-8009 |
Upgrade affected SonicOS devices to the latest fixed versions immediately to address all identified CVEs.
Restrict access to management interfaces to trusted networks only and disable unnecessary services.
Implement multi-factor authentication (MFA) and strict role-based access controls for all management accounts.
Monitor logs for suspicious access, configuration changes, or unauthorized interaction with internal services.
From the CyberShelter perspective, network security appliances such as firewalls are critical components of enterprise infrastructure. Vulnerabilities in these systems can have wide-reaching consequences, as they often serve as the first line of defense. Even medium-severity vulnerabilities can be leveraged in combination to achieve higher impact, particularly when authentication weaknesses are involved.
A high-severity vulnerability has been identified in MongoDB Server that could lead to denial-of-service (DoS) conditions. Tracked as CVE-2026-6914, this issue affects multiple supported versions and may cause the database server to crash or become unresponsive when processing specially crafted input.
Although exploitation requires network access and low-level authentication, the impact on availability is significant for critical services relying on MongoDB infrastructure.
The technical root cause lies in the handling of malformed BSON objects during MD5 checksum computation. Under specific conditions, this results in:
Organizations should immediately identify if they are running any of the following affected versions:
| MongoDB Series | Affected Versions | Fixed Version |
|---|---|---|
| v8.2.x | All versions | 8.2.7 |
| v8.1.x | All versions | 8.3.0-rc0+ |
| v8.0.x | Prior to 8.0.21 | 8.0.21 |
| v7.0.x | Prior to 7.0.32 | 7.0.32 |
Upgrade MongoDB Server to the latest fixed versions (8.2.7, 8.0.21, or 7.0.32) immediately.
Restrict database access to trusted users and applications using strict network and IAM policies.
Monitor for abnormal queries or malformed BSON inputs at the application and database driver levels.
Implement logging and alerting for unusual database behavior or sudden service disruptions.
From the CyberShelter perspective, even vulnerabilities requiring authentication pose significant risks. In modern architectures, multiple services and users interact with the database, increasing the attack surface. Availability-focused attacks can disrupt critical operations without requiring full system compromise, leading to substantial operational impact and downtime.
Meta Platforms has released security updates addressing two high-severity vulnerabilities in WhatsApp. These vulnerabilities could allow attackers to trigger arbitrary URL execution or deliver disguised malicious files, affecting both mobile and Windows environments. While no active exploitation has been confirmed, the potential impact makes these issues high risk.
This vulnerability is caused by incomplete validation of media content paths in AI-enhanced responses linked to Instagram Reels. Remote attackers can inject malicious URLs that WhatsApp may process without proper sanitization.
The vulnerability arises from improper handling of filenames containing embedded NUL (null) bytes. Malicious files can appear as safe (e.g., .pdf, .txt) while the actual file extension (e.g., .exe) is hidden.
| Platform | Affected Versions |
|---|---|
| WhatsApp for iOS | v2.25.8.0 through v2.26.15.72 |
| WhatsApp for Android | v2.25.8.0 through v2.26.7.10 |
| WhatsApp for Windows | Prior to v2.3000.1032164386.258709 |
Update WhatsApp on all platforms immediately via official app stores or desktop update mechanisms.
Avoid opening suspicious messages or attachments, even from known contacts.
Validate file types and extensions before execution, especially on Windows systems.
Educate users about phishing risks and the potential for file extension spoofing.
Multiple vulnerabilities have been identified in WatchGuard Technologies WatchGuard Agent for Windows that could allow attackers to gain SYSTEM-level privileges or disrupt endpoint security functionality. These flaws include privilege escalation vulnerabilities and stack-based buffer overflow issues affecting the agent discovery service.
A chain of vulnerabilities within the WatchGuard Agent service can be exploited by a local attacker to bypass security controls and escalate privileges from a standard user to SYSTEM.
This vulnerability affects the patch management component of the WatchGuard Agent. Improper permission assignment allows an authenticated local user to manipulate service operations and escalate privileges to SYSTEM.
| CVE ID | Description | Impact |
|---|---|---|
| CVE-2026-6787 | Service Privilege Escalation | SYSTEM Compromise |
| CVE-2026-6788 | Service Privilege Escalation | SYSTEM Compromise |
| CVE-2026-41288 | Incorrect Permission Assignment | Privilege Escalation |
Multiple stack-based buffer overflow vulnerabilities exist in the WatchGuard Agent Discovery Service. These are exploitable by an unauthenticated attacker on the same local network through specially crafted network packets.
The vulnerabilities affect the following versions of WatchGuard Agent for Windows:
| Product | Affected Versions | Fixed Version |
|---|---|---|
| WatchGuard Agent for Windows | Up to and including 1.25.02.0000 | 1.25.03.0000 |
Upgrade immediately to WatchGuard Agent for Windows 1.25.03.0000 or later.
Restrict local access and enforce least-privilege principles across all systems.
Segment internal networks to reduce exposure to local attacks and proximity-based threats.
Monitor systems for unusual privilege escalation activity and review endpoint logs for service crashes.
A high-severity vulnerability has been identified in TP-Link Tapo H100 and Tapo P100 devices. Tracked as CVE-2025-15557, this flaw stems from improper certificate validation and could allow attackers on the same network to intercept and manipulate encrypted communication between devices and cloud services.
| Attribute | Details |
|---|---|
| CVE ID | CVE-2025-15557 |
| Severity | High (CVSS v4.0: 7.5) |
| Vulnerability Type | Improper Certificate Validation |
| Attack Vector | Adjacent Network (local access required) |
The vulnerability arises due to improper validation of SSL/TLS certificates during device-to-cloud communication. This allows an attacker positioned on the same network to perform man-in-the-middle (MitM) attacks, intercept encrypted traffic, and modify communication between the device and cloud services.
The following TP-Link Tapo models and firmware versions are affected:
Update firmware immediately to patched versions (H100: 1.6.1+, P100: 1.2.6+).
Restrict IoT devices to secure and segmented networks (VLANs).
Avoid connecting devices to untrusted or public networks.
Monitor network traffic for suspicious activity or unauthorized MitM attempts.
Google has released the May 2026 Android Security Bulletin addressing a critical vulnerability affecting Android System components. Tracked as CVE-2026-0073, this flaw allows remote code execution (RCE) from a nearby or adjacent network without requiring user interaction, posing a serious risk to affected devices.
adbd component (Android Debug Bridge daemon) and Project Mainline, making it a proximity-based threat that could be exploited in public spaces, shared offices, or adjacent network environments.
| Attribute | Details |
|---|---|
| CVE ID | CVE-2026-0073 |
| Severity | Critical |
| Vulnerability Type | Remote Code Execution (RCE) |
| Affected Component | Android System (adbd / Project Mainline) |
The vulnerability allows an attacker within proximity or adjacent network range to execute arbitrary code as the shell user without requiring user interaction or additional privileges. This bypasses standard Android security prompts and permission models.
Affected products include Android devices with security patch levels prior to 2026-05-01. Specifically:
adbdUpdate Android devices to the latest security patch level (2026-05-01 or later).
Ensure automatic updates are enabled for both system and Google Play system components.
Avoid connecting to untrusted or unsecured public networks.
Apply mobile device management (MDM) policies in enterprise environments to enforce minimum patch levels.
Recent security updates have addressed multiple vulnerabilities in NVIDIA NemoClaw and Hewlett Packard Enterprise (HPE) Telco Service Orchestrator. These vulnerabilities could allow information disclosure, authentication bypass, server-side request forgery (SSRF), and potential full system compromise, posing significant risks to AI-driven environments and telecom infrastructure.
Severity: High (CVSS 8.6) | Type: Improper Access Control
A flaw in the sandbox environment initialization allows attackers to inject malicious prompts. This can cause the system to access host environment variables and exfiltrate sensitive data not properly isolated from the host environment.
Severity: Medium (CVSS 5.9) | Type: SSRF
A vulnerability in the validateEndpointUrl() component allows attackers to supply crafted endpoint URLs, target internal address ranges (e.g., 0.0.0.0/8), and trigger unauthorized internal requests, leading to internal data exposure and reconnaissance.
| Affected Versions | Fixed Versions |
|---|---|
| All versions prior to v0.0.18 | v0.0.18 or later |
| All versions prior to v0.0.13 | v0.0.13 or later |
A vulnerability that may allow remote attackers to bypass authentication mechanisms, leading to unauthorized access and potential full system compromise.
Under specific conditions, attackers may bypass authentication controls, exposing sensitive information or enabling unauthorized access.
A stack overflow vulnerability that could allow low-privileged attackers to disrupt system availability and trigger denial-of-service conditions.
| Affected Versions | Fixed Version |
|---|---|
| Versions prior to v5.6.0 | v5.6.0 or later |
Update NVIDIA NemoClaw and HPE Telco Service Orchestrator to the latest fixed versions immediately.
Restrict access to sensitive services and management interfaces to authorized personnel and networks.
Implement strong multi-factor authentication and robust access controls across all environments.
Monitor systems for suspicious activity and validate all input handling and API access mechanisms.
Samsung Electronics has released its May 2026 Security Maintenance Release (SMR) for major Samsung Galaxy devices, delivering critical Android and Samsung-specific security patches. The update incorporates fixes from Google's May 2026 Android Security Bulletin alongside multiple Samsung Vulnerabilities and Exposures (SVE) affecting Galaxy smartphones and Galaxy Watch devices.
Severity: High
Improper input validation in FacAtFunction on Galaxy Watch devices may allow local attackers to execute arbitrary code with system privileges.
Severity: Moderate
Improper input validation in Routines may allow physical attackers to launch privileged activities.
Severity: Moderate
Incorrect default permissions in FactoryCamera may expose device unique identifiers.
Severity: Moderate
Incorrect privilege assignment in LocationManager may allow local attackers to access sensitive information.
Severity: Moderate
Insufficient permission handling in Routines may allow unauthorized access to sensitive data.
Severity: Moderate
An out-of-bounds write vulnerability in SveService may allow local privileged attackers to execute arbitrary code.
Severity: Moderate
Improper export of Android application components in OmaCP may allow local attackers to trigger privileged functions.
Affected products include Samsung devices and watches running the following OS versions:
Install the latest Samsung security updates immediately and ensure devices are updated to the May 2026 security patch level.
Enable automatic updates where possible to ensure timely patching of future vulnerabilities.
Restrict the installation of untrusted applications and avoid downloading apps from unverified sources.
Apply mobile device management (MDM) controls in enterprise environments to enforce security policies and monitor devices for unusual behavior.
Observed multiple vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that could result in authentication bypass or denial-of-service (DoS) under specific configurations.
The most critical issue, CVE-2026-19490, carries a CVSS score of 9.3 and could allow an unauthenticated attacker to bypass authentication when specific Gateway or AAA virtual server configurations using SAML authentication are present.
A second critical vulnerability, CVE-2026-19489, carries a CVSS score of 8.8 and could cause unpredictable behavior or denial-of-service conditions when SIP ALG is enabled on an LSN group configuration.
Organizations using affected NetScaler ADC, NetScaler Gateway, FIPS, or NDcPP deployments should prioritize updating to the fixed versions.
The identified vulnerabilities affect Citrix NetScaler deployments under specific configurations and may impact authentication services, application delivery, and network availability.
Severity: Critical
CVSS: 9.3
Vulnerability Type: Authentication Bypass
Authentication Required: None
An authentication bypass vulnerability may allow an unauthenticated attacker to bypass authentication under specific configurations involving:
Successful exploitation could provide unauthorized access to protected resources and services.
Severity: Critical
CVSS: 8.8
Vulnerability Type: Memory Overflow
A memory overflow vulnerability may cause unpredictable behavior or denial-of-service conditions when SIP ALG is enabled on an LSN group configuration.
Successful exploitation could disrupt NetScaler services and potentially affect applications and services dependent on the affected infrastructure.
Successful exploitation of these vulnerabilities could result in:
Organizations using NetScaler as an authentication, remote-access, or application delivery layer should treat these vulnerabilities as a priority.
Secure Private Access Hybrid deployments using affected NetScaler instances are also impacted.
| Product / Branch | Fixed Version |
|---|---|
| NetScaler ADC & Gateway 14.1 | 14.1-73.32 and later |
| NetScaler ADC & Gateway 13.1 | 13.1-63.21 and later |
| NetScaler ADC 14.1-FIPS | 14.1-73.32 FIPS and later |
| NetScaler ADC 13.1-FIPS / 13.1-NDcPP | 13.1-37.277 and later |
Organizations should upgrade to the latest supported release where possible.
For CVE-2026-19490, review:
Identify systems matching the affected configuration and prioritize them for remediation.
For CVE-2026-19489, identify NetScaler deployments where SIP ALG is enabled on LSN group configurations and prioritize these systems for patching.
Organizations should monitor:
The vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway represent a significant security concern because NetScaler deployments frequently sit at the network perimeter and provide authentication, remote access, and application delivery services.
The most serious issue, CVE-2026-19490, could allow an unauthenticated attacker to bypass authentication under specific SAML configurations.
Meanwhile, CVE-2026-19489 could result in denial-of-service when the affected SIP ALG and LSN configuration is present.
CyberShelter recommends organizations conduct an immediate version and configuration assessment, identify exposed NetScaler systems, and apply the appropriate Citrix security updates without delay.
| Date | 20 August 2026 |
| Vendor | Citrix |
| Products | NetScaler ADC / NetScaler Gateway |
| Severity | Critical |
| CVE-2026-19490 | CVSS 9.3 - Authentication Bypass |
| CVE-2026-19489 | CVSS 8.8 - Memory Overflow / DoS |
| Primary Risk | Authentication Bypass and Denial of Service |
| Recommended Action | Upgrade affected NetScaler deployments to fixed versions and review affected configurations. |
A critical vulnerability has been identified in xrdp, an open-source Remote Desktop Protocol (RDP) server, that could allow unauthenticated remote attackers to execute arbitrary code on vulnerable systems. Tracked as CVE-2025-68670, the flaw affects the xrdp service and stems from improper bounds checking during RDP connection processing.
Successful exploitation may result in full system compromise without requiring authentication or user interaction. Given that xrdp is frequently used to provide remote access to Linux environments, this vulnerability poses a significant risk to internet-exposed systems.
The vulnerability is a Stack-based Buffer Overflow (CWE-121) caused by improper bounds checking when processing user-supplied domain information during the RDP connection sequence.
An attacker can send a malicious RDP connection request that triggers:
Organizations should immediately identify if they are running vulnerable versions of xrdp and upgrade to the patched release.
| Software | Affected Versions | Fixed Version |
|---|---|---|
| xrdp | Versions earlier than 0.10.5 | 0.10.5 |
Upgrade all xrdp installations to version 0.10.5 or later to resolve the buffer overflow vulnerability.
Avoid exposing RDP services directly to the internet. Restrict access to trusted IP ranges using firewalls or VPNs.
Monitor systems for unusual RDP connection attempts and review logs for malformed or suspicious traffic.
Enforce network segmentation, use multi-factor authentication (MFA), and disable unnecessary remote access services.
From the CyberShelter perspective, unauthenticated RCE vulnerabilities in remote access services represent the highest tier of organizational risk. Attackers actively scan the internet for exposed RDP ports, and a vulnerability like CVE-2025-68670 provides a direct path to initial access and lateral movement within the network.
A high-severity vulnerability has been disclosed in several discontinued Hikvision smart switch products that could allow authenticated attackers to execute arbitrary operating system commands remotely. Tracked as CVE-2026-3828, the vulnerability stems from insufficient input validation within device firmware and affects multiple Hikvision smart switch models.
Attackers with valid credentials may exploit the flaw by sending specially crafted packets containing malicious commands to the device, leading to unauthorized system-level operations and potential full device compromise.
The vulnerability is caused by inadequate input validation mechanisms in the firmware of affected devices. Authenticated attackers can leverage this flaw to:
CyberShelter recommends immediate firmware upgrades for all affected hardware to mitigate the risk of command execution.
| Product Model | Affected Versions | Fixed Version |
|---|---|---|
| DS-3E1310P-SI | Versions below and including V1.2.4_210623 | V1.2.5_260309 |
| DS-3E1318P-SI | Versions below and including V1.2.0_210823 | V1.2.1_260309 |
| DS-3E1326P-SI | Versions below and including V1.2.0_210823 | V1.2.1_260309 |
Update all affected devices to the latest fixed firmware versions as specified in the impact table.
Change default or weak credentials immediately and enforce strong password policies for all management accounts.
Limit management access to trusted IP addresses and avoid exposing management interfaces to the public internet.
Segment network infrastructure devices from user networks to prevent lateral movement in case of compromise.
Continuous monitoring of administrative activities is crucial for detecting potential exploitation attempts or unauthorized configuration changes.
A critical vulnerability has been identified in the PHP SOAP Extension that could allow unauthenticated remote attackers to execute arbitrary code on vulnerable servers. Tracked as CVE-2026-6722, the vulnerability affects multiple supported PHP branches and carries a CVSS v3 score of 9.5 (Critical).
Due to the possibility of full server compromise through specially crafted SOAP requests, immediate remediation is strongly recommended. Exploitation does not require authentication or user interaction, placing publicly exposed SOAP services at elevated risk.
Successful exploitation of this vulnerability may allow attackers to:
Organizations should immediately upgrade all affected PHP installations to the latest fixed versions listed below.
| PHP Branch | Vulnerable Versions | Fixed Version |
|---|---|---|
| PHP 8.2 | Prior to 8.2.31 | 8.2.31 |
| PHP 8.3 | Prior to 8.3.31 | 8.3.31 |
| PHP 8.4 | Prior to 8.4.21 | 8.4.21 |
| PHP 8.5 | Prior to 8.5.6 | 8.5.6 |
Upgrade all affected PHP installations to the latest fixed versions (8.2.31, 8.3.31, 8.4.21, 8.5.6) or later.
Restrict external access to SOAP endpoints where possible and disable unused SOAP functionality.
Monitor logs for suspicious SOAP requests and deploy WAF protections where applicable.
Conduct system integrity checks for signs of compromise or unauthorized files such as web shells.
CyberShelter recommends strengthening fundamental security controls to limit the impact of similar future vulnerabilities.
Multiple vulnerabilities have been identified in Apache CloudStack affecting cloud infrastructure deployments, including a critical command injection flaw capable of enabling arbitrary code execution on KVM hosts. The vulnerabilities impact core CloudStack functionality, ranging from unauthenticated command injection to cross-tenant data exposure.
Organizations operating multi-tenant cloud environments or virtualization infrastructure should prioritize immediate remediation to prevent full infrastructure compromise and unauthorized host-level control.
| CVE ID | Severity | Affected Component | Description |
|---|---|---|---|
| CVE-2026-25077 | Critical | Direct Download Templates | Unauthenticated command injection via unsanitized filenames. |
| CVE-2025-66171 | Important | Backup Plugin | Unauthorized VM creation using other users' backups. |
| CVE-2025-66172 | Important | Backup Restore | Cross-tenant backup restoration and volume attachment. |
| CVE-2025-66467 | Important | MinIO Integration | Residual permissions post-bucket deletion allowing unauthorized access. |
The collective impact of these vulnerabilities poses a systemic risk to cloud providers and enterprise private clouds:
Apache CloudStack versions 4.0.0 through 4.22.0.0 are affected. Organizations should upgrade to the following versions immediately:
| Release Branch | Recommended Fixed Version |
|---|---|
| Apache CloudStack LTS | 4.20.3.0 |
| Apache CloudStack Mainline | 4.22.0.1 or later |
Upgrade all CloudStack management servers and agents to the latest fixed versions.
Review tenant isolation configurations and audit all VM and backup access controls.
Harden KVM host environments and restrict management network access to trusted IPs only.
Monitor logs for suspicious template downloads, unauthorized volume attachments, or quota anomalies.
Observed a critical vulnerability in Oracle HTTP Server and the Oracle WebLogic Server Proxy Plug-in that could allow an unauthenticated remote attacker to compromise affected systems over HTTP.
Tracked as CVE-2026-21962, the vulnerability carries a CVSS score of 10.0 (Critical). The vulnerability has also been added to the CISA Known Exploited Vulnerabilities Catalog, with active exploitation reported.
Successful exploitation could allow attackers to gain unauthorized access to data and create, delete, or modify critical information accessible through the affected components.
Severity: Critical
CVSS Score: 10.0
Attack Vector: Network / HTTP
Privileges Required: None
User Interaction: None
Authentication: Not required
Exploitation Status: Actively exploited
The vulnerability is an improper access control issue affecting the Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in.
An unauthenticated attacker with network access through HTTP may be able to compromise affected components.
Successful exploitation could allow an attacker to:
Because the vulnerability does not require authentication and can be exploited remotely over HTTP, internet-facing deployments should be considered particularly exposed.
Successful exploitation could impact the confidentiality and integrity of critical enterprise data and potentially provide attackers with a pathway to compromise affected web infrastructure.
The reported active exploitation significantly increases the urgency of remediation.
CVE-2026-21962 was added to the CISA Known Exploited Vulnerabilities Catalog on 24 August 2026.
The NVD record lists a required remediation date of 27 August 2026 for applicable U.S. federal civilian agencies.
Organizations outside the U.S. federal government should also treat the KEV listing and confirmed exploitation as an emergency prioritization signal.
Apply the security updates released by Oracle for CVE-2026-21962 as soon as possible.
Identify Oracle HTTP Server and WebLogic Proxy Plug-in instances exposed to the internet and prioritize them for remediation.
Where patching cannot be completed immediately, restrict unnecessary external access to affected services and allow access only from trusted networks where operationally feasible.
Review HTTP, application, and security logs for suspicious activity, including:
After applying the updates, verify that all affected Oracle HTTP Server and WebLogic Server Proxy Plug-in instances are running the remediated versions.
Because exploitation has been observed, organizations should review historical HTTP, application, authentication, and security logs for indicators of compromise before considering the incident closed.
The combination of a CVSS 10.0 severity rating, unauthenticated remote exploitation, and reported active exploitation makes CVE-2026-21962 a high-priority vulnerability for organizations using Oracle HTTP Server or the WebLogic Server Proxy Plug-in.
Organizations should identify affected deployments and apply Oracle's security updates immediately, with priority given to internet-facing systems.
Recommended Action: Immediate patching, exposure review, compromise assessment, and verification of all affected Oracle deployments.
| Date | 26 August 2026 |
| Vendor | Oracle |
| CVE | CVE-2026-21962 |
| Severity | Critical |
| CVSS | 10.0 |
| Attack Vector | Network / HTTP |
| Authentication | Not Required |
| Exploitation Status | Actively Exploited |
| Affected Components | Oracle HTTP Server, WebLogic Server Proxy Plug-in, WebLogic Server Proxy Plug-in for IIS |
| Primary Risk | Unauthorized Access, Data Modification, Data Deletion |
| Recommended Action | Apply Oracle security updates immediately, review internet exposure, and verify remediation across all affected deployments. |
7-Zip is affected by a high-severity heap buffer overflow vulnerability that could allow remote attackers to execute arbitrary code or crash affected systems through specially crafted archive files.
Because 7-Zip performs signature-based archive detection, attackers may exploit the flaw using crafted archives that appear legitimate while triggering unsafe memory operations during decompression.
| Field | Details |
|---|---|
| CVE ID | CVE-2026-48095 |
| Severity | High |
| CVSS Score | 8.8 |
| Affected Component | NTFS Archive Handler |
| Attack Vector | Crafted archive files |
| User Interaction | Required |
| Public PoC | Reportedly Available |
The vulnerability exists due to improper memory allocation while processing crafted NTFS compressed streams inside archive files.
A specially crafted archive may trigger a heap buffer overflow condition leading to:
Researchers indicate exploitation may leverage advanced techniques including:
Successful exploitation may allow attackers to:
Because archive files are commonly exchanged in enterprise environments, exploitation may occur through phishing emails, downloaded software bundles, or shared compressed files.
Update all affected systems to 7-Zip version 26.01 or later.
Avoid opening archive files from unknown, untrusted, or unexpected sources, including email attachments and downloaded archives.
Watch for abnormal archive extraction behavior, unexpected crashes, suspicious child processes, and memory corruption alerts.
Enable advanced email filtering, maintain updated EDR/XDR solutions, and block suspicious archive delivery mechanisms where feasible.
Identify systems running outdated 7-Zip versions and prioritize remediation for enterprise workstations, administrative systems, and shared file-processing environments.
LiteSpeed Technologies has disclosed a critical privilege escalation vulnerability affecting the LiteSpeed User-End cPanel Plugin that is reportedly being actively exploited in the wild.
The vulnerability, tracked as CVE-2026-48172, allows authenticated cPanel users-including compromised hosting accounts-to execute arbitrary scripts with root privileges, potentially leading to full system compromise.
| Field | Details |
|---|---|
| CVE ID | CVE-2026-48172 |
| Severity | Critical |
| CVSS Score | 10.0 |
| Affected Component | LiteSpeed User-End cPanel Plugin |
| Impact | Privilege Escalation / Root Code Execution |
A privilege escalation vulnerability exists in the LiteSpeed User-End cPanel Plugin due to improper handling of the lsws.redisAble function.
An authenticated cPanel user may exploit this flaw to execute arbitrary scripts, escalate privileges to root, and fully compromise the underlying server.
Successful exploitation could allow attackers to bypass tenant isolation and obtain unrestricted administrative access.
Organizations should investigate unknown or untrusted IP addresses and review all associated administrative activity.
Successful exploitation may allow attackers to execute arbitrary code as root and fully compromise servers hosting multiple tenants and customer environments.
Upgrade affected LiteSpeed cPanel plugins to LiteSpeed WHM Plugin v5.3.1.0 and cPanel plugin v2.4.7 or later.
Execute the provided IOC detection command and investigate suspicious or unauthorized log entries.
Apply firewall or access control restrictions to suspicious IP addresses identified during investigations.
Monitor systems for unauthorized root-level actions, unexpected script execution, suspicious processes, webshell deployment, and unusual cPanel activity.
Review system integrity, validate hosted website content, and inspect for persistence mechanisms or unauthorized scheduled tasks.
Enforce strong password policies, enable MFA where possible, and restrict administrative access to trusted networks.
Ensure all LiteSpeed and cPanel components remain fully updated and implement routine vulnerability management processes.
CyberShelter has identified multiple security vulnerabilities affecting Synology Chat Server, a widely deployed collaboration and messaging platform available for Synology DiskStation Manager (DSM).
The most severe vulnerability, CVE-2026-40541, carries a CVSS score of 9.0 and could enable authenticated attackers to exploit a cross-site scripting flaw to manipulate files and disrupt service availability.
| CVE | Type | Severity | CVSS |
|---|---|---|---|
| CVE-2026-40541 | Cross-Site Scripting (XSS) | Critical | 9.0 |
| CVE-2026-9491 | Server-Side Request Forgery (SSRF) | Medium | 4.3 |
| CVE-2026-9548 | Cross-Site Scripting (XSS) | Medium | 6.5 |
Upgrade all affected installations to version 2.4.5-22148 or later.
Limit DSM and Chat Server access to trusted users and networks and enforce RBAC controls.
Review logs for unusual activity, unauthorized file access, and unexpected service interruptions.
Enable MFA, apply least privilege principles, and regularly review permissions and roles.
Perform vulnerability scans, verify patch deployment, and review internet-facing services.
CyberShelter is alerting organizations to the active exploitation of a high-severity authentication bypass vulnerability affecting Palo Alto Networks PAN-OS GlobalProtect portal and gateway components.
The vulnerability, tracked as CVE-2026-0257, could allow attackers to bypass authentication controls and establish unauthorized VPN connections under specific deployment configurations.
| Field | Details |
|---|---|
| CVE | CVE-2026-0257 |
| Severity | High |
| CVSS | 7.8 |
| Component | GlobalProtect Portal & Gateway |
| Impact | Authentication Bypass / Unauthorized VPN Access |
The vulnerability stems from improper validation and integrity protection of Authentication Override cookies under specific certificate configurations.
Following upgrades, GlobalProtect users will be required to authenticate again because existing Authentication Override cookies will be regenerated using a more secure method.
Upgrade all affected PAN-OS and Prisma Access deployments immediately.
Identify Authentication Override cookie usage and review certificate assignments.
Audit VPN logs and investigate unusual authentication activity.
Isolate certificates used for Authentication Override functionality.
Upgrade unsupported PAN-OS deployments to supported versions.
CVE-2026-0257 represents a significant threat to organizations relying on Palo Alto Networks GlobalProtect for remote access.
With active exploitation already confirmed and the potential for unauthorized VPN access, organizations should treat this vulnerability as a high-priority remediation effort.
CyberShelter has identified a high-severity privilege escalation vulnerability affecting Ivanti Neurons for ITSM deployments.
The vulnerability, tracked as CVE-2026-9614, could allow authenticated attackers with low privileges to gain administrative access to affected environments.
| Field | Details |
|---|---|
| CVE | CVE-2026-9614 |
| Severity | High |
| CVSS Score | 8.8 |
| Vulnerability Type | Privilege Escalation |
| Root Cause | Improper Access Control |
An improper access control vulnerability exists in Ivanti Neurons for ITSM that could allow a remote authenticated attacker with low-level privileges to escalate privileges and obtain administrative access.
Upgrade all affected Ivanti Neurons for ITSM deployments to supported fixed releases.
Audit administrative accounts, remove unnecessary privileges, and enforce least-privilege controls.
Review authentication logs and investigate unusual privilege changes or administrative actions.
Enable MFA, restrict management access, and implement role-based access controls.
Perform vulnerability assessments and verify patch levels across all environments.
CyberShelter has identified a critical security vulnerability affecting multiple HP Poly Voice products running on Linux-based firmware.
The vulnerability, tracked as CVE-2026-0826, could allow an unauthenticated remote attacker to execute arbitrary code on vulnerable devices when Interactive Connectivity Establishment (ICE) is enabled.
| Field | Details |
|---|---|
| CVE | CVE-2026-0826 |
| Severity | Critical |
| CVSS v4.0 | 9.2 |
| Vendor | HP Poly |
| Bulletin | HPSBPY04083 Rev.1 |
| Product | Fixed Firmware Version |
|---|---|
| VVX Series | UCS 6.4.8 (Pending Release) |
| Trio 8300 | UCS 8.1.7 |
| Trio 8500 | UCS 7.2.8 |
| Trio 8800 | UCS 7.2.8 |
Upgrade affected HP Poly Voice devices and monitor vendor advisories for VVX Series firmware releases.
Disable Interactive Connectivity Establishment where business requirements permit.
Limit management access, avoid direct internet exposure, and implement network segmentation.
Review device logs and investigate unusual behavior or configuration changes.
Inventory all HP Poly Voice devices and prioritize remediation of exposed systems.
Multiple vulnerabilities affecting Apache ActiveMQ could allow authenticated attackers to achieve remote code execution, bypass security controls, inject malicious headers, and abuse privilege management mechanisms.
| CVE | Type | CVSS |
|---|---|---|
| CVE-2026-42588 | Remote Code Execution | 8.1 |
| CVE-2026-45505 | Security Control Bypass | 8.8 |
| CVE-2026-42253 | Header Injection | 6.1 |
| CVE-2026-49157 | Privilege Escalation | 8.8 |
Upgrade all affected ActiveMQ deployments to 5.19.7 or 6.2.6.
Limit access to Jolokia and administrative interfaces.
Enforce strong authentication and least-privilege principles.
Review logs for unusual Jolokia requests and administrative actions.
Identify exposed ActiveMQ instances and validate patch levels.
CyberShelter has identified a critical server-side request forgery (SSRF) vulnerability affecting Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME).
The vulnerability, tracked as CVE-2026-20230, could allow unauthenticated attackers to write arbitrary files to the underlying operating system and potentially escalate privileges to root.
| Field | Details |
|---|---|
| CVE | CVE-2026-20230 |
| Severity | Critical |
| CVSS Score | 8.6 |
| Vulnerability Type | Server-Side Request Forgery (SSRF) |
| Attack Vector | Unauthenticated Remote |
| Product Release | Fixed Version |
|---|---|
| Unified CM / Unified CM SME 14 | 14SU6 |
| Unified CM / Unified CM SME 15 | 15SU5 or applicable Cisco COP Update |
Cisco has indicated that no direct workaround exists at this time.
Disabling WebDialer can significantly reduce exposure to exploitation attempts targeting this vulnerability.
Upgrade Unified CM and Unified CM SME deployments to supported fixed releases.
Disable the Cisco WebDialer service until patches are fully deployed.
Limit management access and segment communications infrastructure.
Review logs for anomalous requests, file creation activity, and privilege escalation attempts.
Verify software versions, patch levels, and exposure of vulnerable services.
CyberShelter has identified multiple security vulnerabilities addressed by Microsoft in the latest release of Microsoft Edge (Chromium-based).
The vulnerabilities include a Remote Code Execution (RCE) flaw, a Security Feature Bypass vulnerability, and a Spoofing vulnerability that could be exploited through malicious web content or crafted URLs.
| CVE | Type | CVSS | Severity |
|---|---|---|---|
| CVE-2026-45495 | Remote Code Execution | 8.8 | Important |
| CVE-2026-45494 | Spoofing | 5.4 | Moderate |
| CVE-2026-45492 | Security Feature Bypass | 5.4 | Moderate |
The most severe vulnerability, CVE-2026-45495, may enable remote code execution through malicious web content.
Systems used for internet browsing, administrative access, remote work, and sensitive business applications should be prioritized for remediation.
Upgrade Microsoft Edge to the latest available version and verify deployment across all endpoints.
Patch administrative systems, executive workstations, finance users, and shared devices first.
Enable automatic updates, restrict untrusted extensions, and implement safe browsing controls.
Review endpoint alerts, phishing activity, and unusual browser behavior.
Educate users on phishing risks, deceptive URLs, and safe browsing practices.
The latest Microsoft Edge security updates address multiple vulnerabilities that could enable remote code execution, security feature bypass, and spoofing attacks.
Organizations should prioritize immediate deployment of updates, enhanced monitoring, and continued user awareness efforts to reduce exposure to browser-based threats.
CyberShelter has identified multiple security vulnerabilities affecting MariaDB Community Server, including CVE-2026-49261 with a maximum CVSS score of 10.0.
Successful exploitation could expose organizations to unauthorized access, sensitive data compromise, service disruption, and potential database server takeover.
| CVE | Severity | CVSS |
|---|---|---|
| CVE-2026-49261 | Critical | 10.0 |
| CVE-2026-48165 | High | 8.0 |
| CVE-2026-48163 | High | 8.0 |
| MariaDB Branch | Fixed Version |
|---|---|
| MariaDB 11.8 | 11.8.8 or later |
| MariaDB 11.4 | 11.4.12 or later |
| MariaDB 10.11 | 10.11.18 or later |
| MariaDB 10.6 | 10.6.27 or later |
CVE-2026-49261 carries a maximum CVSS score of 10.0 and significantly increases risk for database environments storing business-critical information.
Deploy the latest patched MariaDB releases across all environments.
Identify all MariaDB instances across cloud, on-premises, and hybrid infrastructure.
Patch externally accessible database servers immediately and restrict public access.
Enforce strong authentication, least privilege, and remove unnecessary administrative accounts.
Review logs for unusual queries, authentication attempts, and privilege escalations.
Implement segmentation, backup validation, and restrict access to trusted systems only.
CyberShelter has identified a high-severity authentication bypass vulnerability affecting Check Point Remote Access VPN and Mobile Access VPN deployments.
Tracked as CVE-2026-50751, the vulnerability is actively exploited in the wild and may allow attackers to establish unauthorized VPN connections without a valid user password.
| Field | Details |
|---|---|
| CVE | CVE-2026-50751 |
| Severity | High |
| Type | Authentication Bypass |
| Attack Vector | Remote / Network-Based |
| Exploitation | Active Exploitation Confirmed |
Apply the latest Check Point Jumbo Hotfix Accumulator immediately.
Review logs for VPN connections from known malicious IP addresses.
Disable IKEv1 where operationally feasible and remove legacy VPN client support.
Require Multi-Factor Authentication for all VPN users.
Enable machine certificate authentication wherever possible.
CyberShelter has identified CVE-2026-25089, a critical OS Command Injection vulnerability affecting FortiSandbox, FortiSandbox Cloud, and FortiSandbox PaaS deployments.
Successful exploitation could allow unauthenticated remote attackers to execute arbitrary operating system commands through specially crafted Web UI requests.
| Field | Details |
|---|---|
| CVE ID | CVE-2026-25089 |
| Severity | Critical |
| CVSS v3 | 9.1 |
| Type | OS Command Injection (CWE-78) |
| Authentication | Not Required |
| Product | Vulnerable Versions | Fixed Versions |
|---|---|---|
| FortiSandbox | 5.0.x / 4.4.x | 5.0.6+ / 4.4.9+ |
| FortiSandbox Cloud | 5.0.x | 5.0.6+ |
| FortiSandbox PaaS | 5.0.x | 5.0.6+ |
Upgrade FortiSandbox deployments to 5.0.6 or later and 4.4.9 or later.
Restrict Web UI access to trusted administrative networks only.
Review logs for unusual Web UI requests, command execution events, and administrative actions.
Implement network segmentation and enforce strong authentication controls.
CyberShelter has identified multiple security vulnerabilities affecting Splunk Enterprise, Splunk Cloud Platform, and Splunk Secure Gateway.
The vulnerabilities include arbitrary file creation and truncation, remote code execution, server-side request forgery, and stored cross-site scripting.
| CVE | Severity | CVSS | Impact |
|---|---|---|---|
| CVE-2026-20253 | Critical | 9.8 | Arbitrary File Creation/Truncation |
| CVE-2026-20251 | High | 8.8 | Remote Code Execution |
| CVE-2026-20252 | High | 7.6 | SSRF |
| CVE-2026-20258 | High | 7.1 | Stored XSS |
Upgrade all Splunk Enterprise, Cloud, and Secure Gateway deployments immediately.
Restrict access to Splunk management interfaces and eliminate unnecessary internet exposure.
Review logs for file creation activity, SSRF attempts, and suspicious administrative actions.
Enable MFA and restrict administrative access to trusted networks.
Verify versions, perform vulnerability scans, and review integrations.
CyberShelter has identified a major security update released by Google for Chrome Stable Channel addressing 28 vulnerabilities affecting Windows, macOS, and Linux platforms.
The update includes five Critical vulnerabilities and twenty-three High severity issues impacting Core, GPU, Accessibility, Network, Media, Extensions, Password Management, Safe Browsing, and other browser components.
| Platform | Versions Prior To |
|---|---|
| Windows | 149.0.7827.114 / 149.0.7827.115 |
| macOS | 149.0.7827.114 / 149.0.7827.115 |
| Linux | 149.0.7827.114 |
Upgrade Chrome to version 149.0.7827.114 / 149.0.7827.115 or later.
Ensure browser update policies are centrally managed and enforced.
Patch administrator workstations, privileged accounts, and business-critical endpoints first.
Restrict unapproved extensions and deploy web filtering controls.
Review logs for browser crashes, exploit attempts, suspicious process execution, and malicious websites.
Observed that Atlassian has released its August 2026 security updates, addressing multiple vulnerabilities across its Data Center and Server products.
The update addresses 162 High-severity vulnerabilities and 10 Critical-severity vulnerabilities in third-party components affecting products including Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira, and Jira Service Management.
The vulnerabilities include remote code execution (RCE), broken authentication and session management, server-side request forgery (SSRF), SQL injection, denial of service, information disclosure, and other security issues.
Organizations using affected Atlassian products should prioritize updating to the applicable fixed or latest supported versions.
Atlassian's August 2026 security updates address vulnerabilities across multiple third-party components integrated into Atlassian Data Center and Server products.
The issues range from critical remote code execution and injection vulnerabilities to denial-of-service, security misconfiguration, man-in-the-middle, and HTTP request interpretation vulnerabilities.
Severity: Critical
CVSS: 9.8
Affected Products: Jira Software Data Center and Jira Service Management Data Center
Component: lodash dependency
Successful exploitation could allow an attacker to execute arbitrary code on affected systems.
Severity: Critical
CVSS: 9.3
Affected Product: Jira Software Data Center
Component: @babel/traverse dependency
The vulnerability could allow arbitrary code execution in affected environments.
Severity: Critical
CVSS: 9.2
Affected Products: Jira Software and Jira Service Management Data Center
Component: node-tar dependency
Successful exploitation could result in denial-of-service conditions affecting the availability of vulnerable Atlassian services.
Severity: Critical
CVSS: 9.8
Affected Product: Confluence Data Center
Component: minimist dependency
The injection vulnerability could potentially allow attackers to compromise affected Confluence environments.
Severity: Critical
CVSS: 9.3
Affected Product: Confluence Data Center
Component: bcprov-lts8on dependency
The vulnerability results from a security misconfiguration in the affected third-party component.
Severity: Critical
CVSS: 9.1
Affected Product: Confluence Data Center
Component: Apache Tomcat dependency
The vulnerability could potentially allow an attacker to conduct a man-in-the-middle attack under affected conditions.
Severity: Critical
CVSS: 9.1
Affected Product: Fisheye/Crucible
Component: Jetty dependency
The vulnerability involves improper interpretation of HTTP requests and could potentially be leveraged to compromise affected services.
Atlassian's August 2026 updates also address numerous High-severity vulnerabilities.
CVSS: 8.8
CVSS: 8.8
CVSS: 8.7
CVSS: 8.7
CVSS: 8.6
CVSS: 8.2
The August update contains a significantly broader set of third-party component vulnerabilities beyond those specifically listed above.
Successful exploitation of these vulnerabilities could allow attackers to:
Given that Atlassian products are frequently integrated into software development, source-code management, project management, CI/CD, and enterprise collaboration workflows, compromise could have broader operational and security implications.
| Product | Fixed / Recommended Version |
|---|---|
| Bamboo Data Center and Server | 12.1.10 (LTS) or 10.2.22 (LTS) |
| Bitbucket Data Center and Server | 10.4.2, 10.2.6 (LTS), or 9.4.23 (LTS) |
| Confluence Data Center and Server | 10.2.15 (LTS) or 9.2.23 (LTS) |
| Crowd Data Center and Server | 7.2.2 - 7.2.3 |
| Fisheye/Crucible | 4.9.13 |
| Jira Data Center and Server | 11.3.10 (LTS) or 10.3.24 (LTS) |
| Jira Service Management Data Center and Server | 11.3.10 (LTS) or 10.3.24 |
Organizations should verify the exact applicable release against their deployed product version and Atlassian's security guidance.
Prioritize remediation of the Critical vulnerabilities, particularly:
Monitor Atlassian environments for:
Atlassian's August 2026 security release represents a significant enterprise security update, with 10 Critical and 162 High-severity vulnerabilities identified in third-party components across its Data Center and Server portfolio.
The presence of vulnerabilities involving remote code execution, authentication bypass, SSRF, injection, denial of service, and information disclosure makes timely remediation particularly important for organizations operating internet-accessible Atlassian environments.
CyberShelter recommends conducting an immediate inventory of affected Atlassian products, identifying their deployed versions, prioritizing Critical vulnerabilities, and upgrading to the appropriate fixed or latest supported releases.
Organizations should also review their Atlassian environments for signs of unauthorized access or configuration changes following the deployment of security updates.
| Date | 21 August 2026 |
| Vendor | Atlassian |
| Severity | Critical / High |
| Critical Vulnerabilities | 10 |
| High-Severity Vulnerabilities | 162 |
| Affected Products | Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira, Jira Service Management |
| Primary Risks | RCE, Authentication Bypass, SSRF, Injection, DoS, Information Disclosure |
| Recommended Action | Upgrade affected Atlassian products to applicable fixed or latest supported versions. |
CyberShelter has identified multiple security vulnerabilities affecting Apache HTTP Server, one of the world's most widely deployed web server platforms.
These vulnerabilities affect several Apache modules and could allow attackers to trigger denial-of-service conditions, memory corruption, buffer overflows, privilege abuse, cross-site scripting attacks, and unauthorized file access.
| Product | Affected Version | Fixed Version |
|---|---|---|
| Apache HTTP Server | 2.4.67 and Earlier | 2.4.68+ |
Update Apache HTTP Server to version 2.4.68 or later.
Identify systems using mod_http2, mod_proxy_html, mod_proxy_ftp, mod_dav_fs, mod_ssl, mod_xml2enc, and mod_ldap.
Remove or disable modules not required by business operations.
Review logs for crashes, memory errors, suspicious proxy activity, and abnormal WebDAV operations.
Implement least-privilege permissions, secure configuration baselines, and regular security assessments.
CyberShelter has identified a critical vulnerability affecting the inventory synchronization subsystem of Wazuh Manager.
The flaw allows attackers to inject arbitrary OpenSearch bulk operations through an unsanitized agent-controlled field, enabling unauthorized manipulation of indexed security data.
| GHSA ID | GHSA-ff9g-85jq-r3g3 |
| CVE | No CVE Assigned |
| Severity | Critical |
| CVSS Score | 10.0 |
| Affected Product | Wazuh Manager |
| Affected Version | 5.0.0-beta1 |
| Fixed Version | 5.0.0-beta3+ |
| Product | Affected Version | Fixed Version |
|---|---|---|
| Wazuh Manager | 5.0.0-beta1 | 5.0.0-beta3+ |
Upgrade Wazuh Manager to version 5.0.0-beta3 or later.
Audit enrolled agents and remove inactive, untrusted, or suspicious systems.
Review logs for unexpected bulk operations, deletions, and document modifications.
Verify alerts, dashboards, and vulnerability records against backups where available.
Search for indicators of data tampering, alert suppression, and unauthorized OpenSearch modifications.
CyberShelter has identified multiple vulnerabilities affecting HP One Agent Software, including one Critical, one High, and one Medium severity issue.
| CVE | Severity | CVSS |
|---|---|---|
| CVE-2024-5535 | Critical | 9.1 |
| CVE-2026-5064 | High | 8.5 |
| CVE-2024-12797 | Medium | 6.3 |
Upgrade HP Privacy Settings to 1.5.21.0 or later.
Confirm all HP endpoints are running the updated package.
Review logs for privilege escalation events and abnormal behavior.
Enforce least privilege and maintain updated endpoint protection.
Observed multiple vulnerabilities affecting IBM AIX and PowerVM VIOS, including several Critical- and High-severity vulnerabilities.
The vulnerabilities could allow attackers to perform remote code execution, command injection, arbitrary file modification, privilege escalation, information disclosure, and denial-of-service attacks.
Several Critical vulnerabilities carry CVSS scores of 9.8 or higher, making immediate remediation a priority for organizations operating affected IBM AIX or PowerVM VIOS environments.
The IBM security bulletin identifies multiple Critical vulnerabilities affecting AIX and PowerVM VIOS environments.
Severity: Critical
CVSS: 9.9
A command injection vulnerability in AIX and PowerVM VIOS NIM could allow a remote authenticated attacker to execute arbitrary commands.
Severity: Critical
CVSS: 9.9
An OS command injection vulnerability could allow a remote authenticated attacker to execute arbitrary commands on an affected system.
Severity: Critical
CVSS: 9.8
A remote attacker could exploit the vulnerability to execute arbitrary commands.
Severity: Critical
CVSS: 9.8
An improper authentication vulnerability could allow a remote attacker to execute arbitrary commands.
Severity: Critical
CVSS: 9.8
A stack buffer overflow vulnerability could allow a remote attacker to execute arbitrary code.
Severity: Critical
CVSS: 9.6
An out-of-bounds write vulnerability could allow a remote attacker to execute arbitrary code or cause a denial-of-service condition.
Severity: Critical
CVSS: 9.1
A remote attacker could exploit the vulnerability to overwrite arbitrary files on an affected system.
CVSS: 9.8
Potential arbitrary code execution.
CVSS: 9.8
Potential arbitrary code execution.
CVSS: 9.3
Potential arbitrary code execution.
Additional High-severity vulnerabilities affect IBM AIX and PowerVM VIOS and include issues involving:
CVSS: 8.8
CVSS: 8.8
CVSS: 7.1
CVSS: 7.3
The bulletin also addresses numerous Medium- and Low-severity vulnerabilities affecting AIX, VIOS, PostgreSQL, Perl, Java, and other bundled components.
Successful exploitation of these vulnerabilities could allow attackers to:
Because IBM AIX and PowerVM VIOS can support critical enterprise workloads and infrastructure, exploitation could have significant operational and security consequences.
| Product | Fixed Version |
|---|---|
| AIX 7.3 TL04 | SP2 |
| AIX 7.3 TL03 | SP3 |
| AIX 7.3 TL02 | SP5 |
| AIX 7.2 TL05 | SP13 |
| VIOS 4.1.2 | 4.1.2.20 |
| VIOS 4.1.1 | 4.1.1.30 |
| VIOS 4.1.0 | 4.1.0.50 |
Organizations should verify their installed Technology Level, Service Pack, and VIOS release before applying the applicable update.
Upgrade affected IBM AIX and PowerVM VIOS deployments to the applicable fixed versions as soon as possible.
Prioritize remediation of the Critical vulnerabilities, particularly those with CVSS scores of 9.8-9.9 that may enable remote command or code execution.
Restrict unnecessary network exposure of affected systems and ensure administrative interfaces are accessible only from trusted networks.
Review system and authentication logs for:
Ensure AIX, VIOS, and bundled components such as PostgreSQL, Perl, and Java are regularly reviewed and updated according to IBM's security guidance.
The IBM AIX and PowerVM VIOS vulnerabilities represent a high-priority security concern, particularly because several Critical vulnerabilities can potentially enable remote command or code execution.
Organizations operating AIX or VIOS in production environments should immediately identify affected systems, determine their current patch levels, and apply the applicable IBM security updates.
Recommended Action: Upgrade to the applicable IBM fixed versions immediately.
| Date | 24 August 2026 |
| Vendor | IBM |
| Products | IBM AIX / PowerVM VIOS |
| Severity | Critical / High |
| Critical CVSS Range | 9.1 - 9.9 |
| Primary Risks | Remote Code Execution, Command Injection, File Modification, Privilege Escalation, Information Disclosure, DoS |
| Affected Platforms | AIX 7.2, AIX 7.3, PowerVM VIOS 4.1 |
| Recommended Action | Apply the applicable IBM security updates immediately. |
CyberShelter has identified multiple critical and high-severity vulnerabilities affecting Google Chrome across Windows, macOS, Linux, and Android platforms.
Successful exploitation could allow attackers to execute arbitrary code, disclose sensitive information, compromise credentials, bypass browser security controls, or crash browser processes.
Upgrade Chrome to the latest stable version across all platforms.
Verify enterprise update policies are enforced and functioning.
Update administrator and business-critical endpoints first.
Review browser crashes, extension activity, and suspicious behavior.
CyberShelter has identified a critical OS Command Injection vulnerability affecting Splunk AI Toolkit deployments.
The flaw exists within the btool configuration helper component and allows authenticated administrators to execute arbitrary operating system commands on the underlying Splunk Enterprise host.
| CVE ID | CVE-2026-20266 |
| Severity | Critical |
| CVSS Score | 9.1 |
| Vulnerability Type | OS Command Injection |
| Affected Component | btool Configuration Helper |
| Attack Vector | Authenticated |
| Privileges Required | Splunk Admin Role |
| Fixed Version | Splunk AI Toolkit 5.7.4 |
| Product | Affected Version | Fixed Version |
|---|---|---|
| Splunk AI Toolkit | Prior to 5.7.4 | 5.7.4+ |
Upgrade Splunk AI Toolkit to version 5.7.4 or later.
Audit all Splunk admin accounts and remove unnecessary privileged users.
Protect administrative accounts using multi-factor authentication.
Review logs for unusual command execution, configuration changes, and shell activity.
Limit Splunk administration to trusted management networks and implement segmentation controls.
CyberShelter Threat Intelligence has identified the release of Oracle's June 2026 Critical Patch Update (CPU), addressing 245 security vulnerabilities across multiple Oracle product families.
Several vulnerabilities are remotely exploitable without authentication and carry maximum CVSS scores of 10.0, making them high-priority targets for threat actors.
| Product | CVEs | CVSS |
|---|---|---|
| Oracle Coherence | CVE-2026-35308, CVE-2026-35307 | 10.0 |
| Oracle WebLogic Server | CVE-2026-35301, CVE-2026-35292 | 10.0 |
| Oracle WebCenter Enterprise Capture | CVE-2026-46778, CVE-2026-46781 | 10.0 |
| Oracle WebCenter Portal | CVE-2026-46803, CVE-2026-46846 | 10.0 |
| Oracle WebCenter Sites | CVE-2026-46798, CVE-2026-46800 | 10.0 |
Assess Oracle June 2026 CPU applicability across all environments.
Inventory Oracle products and determine exposure levels.
Patch WebLogic, Coherence, WebCenter, and Middleware systems immediately.
Deploy Oracle's June 2026 CPU without delay.
Review authentication, application, and security logs for suspicious activity.
CyberShelter Threat Intelligence has identified important security updates released by Node.js addressing 12 vulnerabilities affecting all currently supported release lines.
The vulnerabilities affect Node.js 22.x, 24.x and 26.x and include flaws in WebCrypto, TLS hostname verification, HTTP/2 processing, DNS resolution, proxy authentication and Permission Model protections.
| Release Line | Fixed Version |
|---|---|
| Node.js 22.x | v22.23.0 |
| Node.js 24.x | v24.17.0 |
| Node.js 26.x | v26.3.1 |
Update all Node.js deployments to the latest patched versions.
Assess internet-facing applications and APIs for exposure.
Verify TLS certificate validation and hostname verification processes.
Watch for abnormal traffic patterns and memory consumption.
Perform vulnerability scans and patch validation activities.
CyberShelter Threat Intelligence has identified a security advisory issued by Esri warning that threat actors are actively targeting ArcGIS Enterprise deployments by abusing weaknesses in built-in account recovery workflows.
Attackers are bypassing traditional authentication protections by targeting password reset and account recovery mechanisms instead of directly attacking MFA-protected login processes.
Disable Portal PSA and Server IAA accounts where possible.
Remove weak or easily guessed password recovery questions.
Require email verification for all password reset requests.
Review privileged users, password resets, and authentication activity.
Use Active Directory, Azure AD, LDAP, or SAML-based authentication providers.
CyberShelter Threat Intelligence has identified active exploitation of a critical vulnerability affecting Lantronix EDS5000 devices.
CVE-2025-67038 allows unauthenticated attackers to execute arbitrary operating system commands with root privileges through the HTTP RPC component.
| CVE ID | CVE-2025-67038 |
| Severity | Critical |
| CVSS Score | 9.8 |
| Attack Vector | Network |
| Authentication | Not Required |
| User Interaction | None |
| Impact | Root-Level Remote Code Execution |
| Affected Product | Lantronix EDS5000 |
| Affected Version | 2.1.0.0R3 |
The vulnerability exists within the HTTP RPC component responsible for logging failed authentication attempts.
User-supplied username input is incorporated directly into operating system shell commands without proper sanitization, allowing arbitrary command injection.
Injected commands execute with root privileges, enabling complete compromise of vulnerable devices.
Locate all Lantronix EDS5000 devices and verify firmware versions.
Restrict management interfaces and remove unnecessary internet exposure.
Isolate vulnerable devices from business and critical networks.
Review authentication logs and investigate suspicious command execution activity.
Deploy vendor security updates immediately when available.
CyberShelter Threat Intelligence has identified multiple vulnerabilities affecting widely deployed Jenkins plugins. The disclosed flaws include Remote Code Execution (RCE), Sandbox Bypass, Command Injection, XXE Injection, Path Traversal, CSRF, Permission Bypass, LDAP Injection and Information Disclosure.
Several affected plugins currently have no available vendor fixes, making immediate mitigation essential for organizations operating Jenkins-based CI/CD environments.
Install the latest secure versions for all supported Jenkins plugins.
Disable or uninstall plugins without vendor security fixes.
Limit administrator access and enforce least privilege.
Review stored credentials, secrets and plugin configurations.
Continuously monitor plugin activity, pipelines and administrative actions for suspicious behavior.
CyberShelter Threat Intelligence has identified a high-severity vulnerability affecting libssh2, a widely deployed open-source SSH client library used by automation platforms, file transfer utilities, embedded systems and programming language bindings.
Tracked as CVE-2026-58050, the vulnerability affects libssh2 version 1.11.1 and earlier and may allow a malicious SSH server to trigger heap corruption through an integer overflow, potentially resulting in remote code execution.
The vulnerability exists within libssh2's publickey subsystem while processing server-supplied attributes.
A malicious SSH server, or an attacker performing a Man-in-the-Middle attack, can trigger an integer overflow during memory allocation resulting in heap buffer corruption and possible remote code execution.
| CVE | CVE-2026-58050 |
| Severity | High |
| CVSS v4 | 8.3 |
| CWE | CWE-190 Integer Overflow |
| Affected Product | libssh2 |
| Affected Versions | 1.11.1 and Earlier |
| Component | Publickey Attribute Parser |
| Attack Vector | Network |
| Authentication | None |
| User Interaction | Client Connects to Malicious SSH Server |
Deploy the vendor's patched release immediately once available.
Upgrade software packages that include vulnerable libssh2 libraries.
Connect only to trusted SSH servers and validate host identities.
Review logs for abnormal SSH sessions, crashes and suspicious activity.
Identify applications embedding libssh2 and prioritize remediation.
Although no active exploitation has been confirmed, the public release of proof-of-concept exploit code significantly increases the likelihood of attacks targeting vulnerable libssh2 deployments. Organizations should prioritize identifying affected applications, restricting SSH communications to trusted systems, and deploying vendor patches immediately when available.
CyberShelter Threat Intelligence has identified multiple critical vulnerabilities affecting the Cacti Network Monitoring Platform. The vulnerabilities include three unauthenticated SQL Injection flaws and one Local File Inclusion (LFI) vulnerability affecting Cacti version 1.2.30 and earlier.
Successful exploitation could allow attackers to access or manipulate databases, disclose sensitive monitoring information, read arbitrary files from the underlying operating system, and compromise enterprise monitoring infrastructure.
Cacti is widely deployed for enterprise network monitoring, infrastructure visibility, and performance analytics. These newly disclosed vulnerabilities affect core application functionality and can be exploited remotely without authentication.
Because Cacti frequently stores network topology information, credentials, and monitoring data, successful compromise may expose valuable intelligence for follow-on attacks.
rfilter Parameter (CVSS 9.3)| Affected Versions | Cacti 1.2.30 and Earlier |
| Patched Version | Cacti 1.2.31 |
| Vendor | Cacti |
| Risk Level | Critical |
Upgrade all Cacti deployments to version 1.2.31 or later.
Prevent direct internet exposure and restrict access using VPNs, firewalls, or secure administrative gateways.
Review web server logs, SQL Injection attempts, abnormal database activity, and suspicious file access.
Perform vulnerability scans, review administrative accounts, and verify backup integrity.
These vulnerabilities represent a severe threat because they combine multiple pre-authentication SQL Injection flaws with an unauthenticated Local File Inclusion vulnerability. Organizations operating internet-facing Cacti deployments should prioritize immediate patching, restrict administrative access, and continuously monitor systems for indicators of compromise.
CyberShelter Threat Intelligence has identified multiple security vulnerabilities affecting IBM Db2 for Linux, UNIX, and Windows (LUW). The most severe issue, CVE-2026-10109, is a pre-authentication Remote Code Execution (RCE) vulnerability with a CVSS v3.1 score of 9.8 (Critical).
The vulnerability exists within the Distributed Relational Database Architecture (DRDA) connection handshake process and may allow unauthenticated attackers to execute arbitrary code on vulnerable Db2 servers without valid credentials.
IBM Db2 is widely deployed across finance, healthcare, manufacturing, telecommunications, government, and other enterprise sectors.
The disclosed vulnerabilities impact core database services and may enable remote code execution, information disclosure, and denial-of-service attacks against vulnerable environments.
| Affected Product | IBM Db2 for Linux, UNIX and Windows (LUW) |
| Affected Versions | 11.5.0 - 11.5.9 12.1.0 - 12.1.4 |
| Platforms | Linux, UNIX, Windows |
| Risk Level | Critical |
| Product | Fixed Version |
|---|---|
| Db2 11.5 | Special Build #84653 or later |
| Db2 12.1 | Special Build #86230 or later |
Upgrade all IBM Db2 deployments to the latest IBM security builds.
Limit DRDA access to trusted hosts and remove direct internet exposure.
Review Db2 logs for suspicious DRDA connections, unusual activity, and service interruptions.
Apply least privilege, maintain secure backups, and regularly review administrative accounts.
CVE-2026-10109 represents a significant enterprise database security risk due to its pre-authentication remote code execution capability and critical CVSS score. Although active exploitation has not been reported, organizations should prioritize patch deployment, restrict network exposure, and continuously monitor IBM Db2 environments for indicators of compromise.
CyberShelter Threat Intelligence has identified multiple critical vulnerabilities affecting JetBrains Hub, YouTrack Server, GoLand, and Kotlin. The vulnerabilities include authentication bypass, privilege escalation, account takeover, remote code execution (RCE), unsafe deserialization, and improper access control.
The most severe issue, CVE-2026-50242, carries a CVSS score of 10.0 and may allow attackers with database access to bypass authentication and obtain administrative privileges.
JetBrains products are widely used for software development, DevOps, issue tracking, source code management, and project collaboration. Successful exploitation could expose source code, developer credentials, project data, and CI/CD infrastructure.
| JetBrains Hub | Supported 2024.x, 2025.x and 2026.x |
| YouTrack Server | Versions prior to 2026.2.16593 |
| GoLand | Versions prior to 2026.1.3 |
| Kotlin | Versions prior to 2.4.20 |
| Risk Level | Critical |
Upgrade Hub, YouTrack, GoLand, and Kotlin to the latest supported versions immediately.
Limit database access to trusted administrators only and enforce MFA where supported.
Avoid opening untrusted projects and only install trusted plugins and extensions.
Audit authentication logs, account restoration events, project configuration changes, and privilege escalation attempts.
The combination of authentication bypass, privilege escalation, account takeover, and remote code execution vulnerabilities presents a significant risk to organizations operating self-managed JetBrains environments. CVE-2026-50242 is particularly critical due to its CVSS score of 10.0 and its ability to provide complete administrative control over affected deployments. Organizations should prioritize immediate patching and strengthen access controls across development infrastructure.
Cisco has released security updates addressing multiple high-severity vulnerabilities affecting the ClamAV antivirus engine used by Cisco Secure Endpoint Connector. The flaws impact multiple file parsing components and may allow remote attackers to trigger Denial-of-Service (DoS) conditions by submitting specially crafted files for antivirus scanning.
Windows deployments are particularly affected because successful exploitation may terminate the ClamAV scanning engine, temporarily disabling malware scanning until the service is restarted.
The vulnerabilities affect ClamAV's processing of multiple file formats including Portable Executable (PE), FSG, 7z, InstallShield, PESpin, ALZ, and DMG files. Specially crafted files may cause the antivirus engine to crash, interrupting malware detection and reducing endpoint security visibility.
| CVE | Vulnerability | CVSS |
|---|---|---|
| CVE-2026-20213 | PE File Processing Memory Corruption | 7.5 |
| CVE-2026-20214 | FSG File Processing Memory Corruption | 7.5 |
| CVE-2026-20215 | 7z File Processing Memory Corruption | 7.5 |
| CVE-2026-20216 | InstallShield File Parsing DoS | 7.5 |
| CVE-2026-20217 | PESpin File Processing Memory Corruption | 7.5 |
| CVE-2026-20243 | ALZ File Processing Memory Corruption | 7.5 |
| CVE-2026-20244 | DMG File Processing Memory Corruption | 7.5 |
| Product | Fixed Version |
|---|---|
| Cisco Secure Endpoint Connector (Windows) | 8.6.2 |
| Cisco Secure Endpoint Connector (Linux) | 1.29.0 |
| Cisco Secure Endpoint Connector (macOS) | 1.27.2 |
Upgrade Cisco Secure Endpoint Connector to the latest fixed version across all platforms, prioritizing Windows deployments.
Restrict processing of files received from untrusted sources and ensure endpoint protection services automatically restart after failures.
Review endpoint logs for ClamAV crashes, interrupted malware scans, and repeated failures involving archive or executable file formats.
Maintain updated endpoint protection software, perform routine health checks, and implement layered endpoint security controls.
Although these vulnerabilities do not directly enable remote code execution, they present a significant operational risk by disrupting antivirus scanning and reducing endpoint protection effectiveness. Attackers may exploit specially crafted files to temporarily disable malware detection, increasing opportunities for follow-on attacks. Organizations should prioritize upgrading Cisco Secure Endpoint Connector and continuously monitor endpoint protection services for unexpected failures.
Adobe has released Priority 1 security updates for ColdFusion 2025 and ColdFusion 2023 addressing multiple critical vulnerabilities that could allow unauthenticated remote code execution, privilege escalation, arbitrary file reads, SSRF, and security bypass.
| CVE | Impact | CVSS |
|---|---|---|
| CVE-2026-48276 | Remote Code Execution | 10.0 |
| CVE-2026-48277 | Remote Code Execution | 10.0 |
| CVE-2026-48281 | Remote Code Execution | 10.0 |
| CVE-2026-48316 | Remote Code Execution | 10.0 |
| CVE-2026-48282 | Path Traversal / RCE | 10.0 |
| CVE-2026-48283 | File Upload / RCE | 10.0 |
| CVE-2026-48313 | Arbitrary File Read | 9.3 |
| CVE-2026-48315 | Privilege Escalation | 9.3 |
| CVE-2026-48285 | SSRF / Security Bypass | 8.6 |
| Product | Affected | Fixed |
|---|---|---|
| Adobe ColdFusion 2025 | Update 9 and earlier | Update 10 |
| Adobe ColdFusion 2023 | Update 20 and earlier | Update 21 |
Upgrade ColdFusion 2025 to Update 10 and ColdFusion 2023 to Update 21.
Patch externally accessible ColdFusion systems first and restrict administrative access.
Review logs for suspicious HTTP requests, unauthorized uploads, privilege changes, and unexpected application behavior.
The presence of multiple unauthenticated Remote Code Execution vulnerabilities with CVSS 10.0 makes this one of the most critical Adobe ColdFusion security updates. Organizations should prioritize patch deployment, especially for internet-facing servers, and continuously monitor for suspicious activity.
Adobe has released a Priority 1 security update for Adobe Campaign Classic (ACC) to address CVE-2026-48286, a critical Incorrect Authorization vulnerability that could allow unauthenticated attackers to execute arbitrary code remotely.
| Attribute | Details |
|---|---|
| CVE | CVE-2026-48286 |
| Severity | Critical |
| CVSS | 10.0 |
| Weakness | CWE-863 - Incorrect Authorization |
| Impact | Unauthenticated Remote Code Execution |
Successful exploitation could allow attackers to execute arbitrary code remotely, resulting in complete compromise of vulnerable Adobe Campaign Classic servers.
| Product | Affected Version | Fixed Version |
|---|---|---|
| Adobe Campaign Classic v7 | 7.4.3 Build 9396 and Earlier | 7.4.3 Build 9397 |
Platforms: Windows and Linux
Upgrade Adobe Campaign Classic to Version 7.4.3 Build 9397 or later.
Limit external access to Adobe Campaign Classic servers and administrative interfaces.
Review authentication logs, configuration changes, and suspicious processes for indicators of compromise.
CVE-2026-48286 represents a critical threat because it enables unauthenticated remote code execution with a CVSS score of 10.0. Although Adobe has not reported active exploitation, organizations using on-premises Adobe Campaign Classic should treat this as a high-priority vulnerability and immediately deploy the latest security update while minimizing unnecessary network exposure.
OpenSSH has released version 10.4 (10.4p1) addressing multiple security vulnerabilities affecting both SSH clients and servers. The update fixes a high-severity client-side use-after-free vulnerability along with several issues impacting SFTP, SCP, authentication, forwarding restrictions, and denial-of-service protections.
| CVE | Impact | Severity |
|---|---|---|
| CVE-2026-60002 | Client-side Use-After-Free | High (7.7) |
| CVE-2026-59995 | SFTP Path Handling | Medium |
| CVE-2026-59996 | SCP Path Traversal | Medium |
| CVE-2026-60001 | Authentication Delay Weakness | Medium |
| CVE-2026-59999 | Forwarding Restriction Bypass | Medium |
| CVE-2026-60000 | GSSAPI Denial-of-Service | Medium |
| Product | Affected Versions | Fixed Version |
|---|---|---|
| OpenSSH | All Versions Prior to 10.4 | OpenSSH 10.4 (10.4p1) |
Deploy OpenSSH 10.4 (10.4p1) or later across all client and server systems.
Limit SSH access to trusted networks and avoid connecting to unknown SSH or SFTP servers.
Review authentication logs, file transfer activity, forwarding configurations, and unusual SSH behavior.
The vulnerabilities addressed in OpenSSH 10.4 affect both client and server components. While the most severe issue targets SSH clients connecting to malicious servers, additional flaws impacting file transfers and authentication increase the attack surface of enterprise environments. Organizations should prioritize upgrading OpenSSH across all systems and regularly review SSH security configurations.
Progress Software has released security updates addressing three vulnerabilities affecting MOVEit Transfer. The issues include a Stored Cross-Site Scripting (XSS) vulnerability, an API token exposure flaw caused by table scope bypass, and an SFTP memory leak that may lead to denial of service.
| CVE | Impact | Severity |
|---|---|---|
| CVE-2026-11903 | Stored Cross-Site Scripting (Ad Hoc Module) | High |
| CVE-2026-10698 | API Token Exposure via Table Scope Bypass | High |
| CVE-2026-10699 | SFTP Memory Leak and Denial of Service | Medium |
| Vulnerable Version | Fixed Version |
|---|---|
| 2026.0.0 | 2026.0.1 |
| 2025.1.0 to 2025.1.3 | 2025.1.4 |
| 2025.0.0 to 2025.0.7 | 2025.0.8 |
| 2024.1.8 and Earlier | Upgrade to a Supported Release |
Install the latest fixed version across all environments.
Rotate API tokens if compromise is suspected and review privileged access.
Review API, browser and SFTP logs for suspicious behavior or abnormal memory usage.
These vulnerabilities increase the risk to organizations relying on MOVEit Transfer for secure business file exchange. Prompt patching, privileged access review, API token protection, and continuous monitoring are recommended to reduce the likelihood of compromise.
Multiple Critical vulnerabilities have been identified in U-Boot affecting the Verified Boot implementation and FIT image parsing process. Successful exploitation could allow attackers to execute arbitrary code before authentication, bypass secure boot protections, corrupt memory, or prevent affected devices from booting.
| Identifier | Impact | Severity |
|---|---|---|
| BRLY-2026-037 | Stack Buffer Overflow / Null Pointer Dereference | Critical |
| BRLY-2026-038 | Stack Buffer Underflow | Critical |
| BRLY-2026-039 | Out-of-Bounds Memory Read | High |
| BRLY-2026-040 | NULL Pointer Dereference | High |
| BRLY-2026-041 | Improper External FIT Data Validation | High |
| BRLY-2026-042 | Unbounded Recursion Denial of Service | High |
| Component | Status |
|---|---|
| Embedded Linux Devices | Affected |
| IoT Platforms | Affected |
| Enterprise Network Equipment | Affected |
| Industrial Control Systems | Affected |
| Baseboard Management Controllers (BMC) | Affected |
| ARM Embedded Platforms | Affected |
Deploy vendor firmware updates containing patched U-Boot releases immediately.
Limit firmware updates to trusted administrators and validate firmware authenticity before deployment.
Review firmware upload events, boot integrity logs, reboot activity, and management interface access for suspicious behavior.
These vulnerabilities target the foundation of the secure boot process, allowing attackers to compromise systems before operating system security controls are initialized. Organizations relying on embedded devices, networking equipment, industrial systems, or BMC platforms should prioritize firmware updates, secure firmware management, and continuous monitoring to reduce the risk of compromise.
Zimbra has released Zimbra Collaboration Suite (ZCS) 10.1.19 to address a critical Stored Cross-Site Scripting (XSS) vulnerability affecting the Classic Web Client. The flaw could allow attackers to execute malicious JavaScript within authenticated browser sessions, potentially leading to mailbox compromise, session hijacking, and unauthorized account access.
| Attribute | Details |
|---|---|
| CVE | Not Yet Assigned |
| Severity | Critical |
| Vulnerability | Stored Cross-Site Scripting (XSS) |
| CWE | CWE-79 |
| Affected Component | Classic Web Client |
| Product | Affected Component | Fixed Version |
|---|---|---|
| Zimbra Collaboration Suite (ZCS) | Classic Web Client | 10.1.19 |
Update all Zimbra Collaboration Suite deployments to version 10.1.19 or later and verify successful installation.
Enable Multi-Factor Authentication (MFA), review mailbox permissions, and limit use of legacy web interfaces where possible.
Review authentication logs, investigate unexpected mailbox changes, and monitor email activity for indicators of malicious scripts or session hijacking.
Although no CVE identifier has been assigned and no active exploitation has been reported, Stored XSS vulnerabilities targeting enterprise email platforms have historically been leveraged to compromise authenticated user sessions. Organizations should prioritize upgrading to ZCS 10.1.19, particularly where the Classic Web Client remains in use, and continuously monitor email environments for suspicious activity.
OWASP ModSecurity has released version 3.0.16 addressing multiple vulnerabilities that could allow attackers to bypass Web Application Firewall (WAF) inspection. The flaws affect request normalization and multipart request parsing, potentially allowing malicious payloads to evade detection and reach backend applications.
| CVE | Impact | Severity |
|---|---|---|
| CVE-2026-52761 | Unicode Transformation Security Rule Bypass | Moderate |
| CVE-2026-52747 | Multipart Parser Security Bypass | High |
| Product | Affected Versions | Fixed Version |
|---|---|---|
| OWASP ModSecurity | 3.0.0 through 3.0.15 | 3.0.16 |
Deploy ModSecurity version 3.0.16 or later across all protected web applications and verify successful installation.
Review ModSecurity rule configurations, test multipart request inspection, and verify Unicode transformation behavior after upgrading.
Review WAF logs for malformed multipart requests, suspicious Unicode patterns, unexpected rule bypasses, and indicators of injection attacks.
These vulnerabilities demonstrate how inconsistencies between Web Application Firewall processing and backend application behavior can significantly reduce the effectiveness of application-layer protection. Organizations should immediately upgrade to ModSecurity 3.0.16, validate WAF inspection functionality after patching, and continue implementing defense-in-depth controls to protect internet-facing applications.
A critical vulnerability (CVE-2026-53486) has been identified in the @xhmikosr/decompress npm package. The flaw allows specially crafted archive files to perform arbitrary file writes outside the intended extraction directory, potentially leading to privilege escalation or remote code execution.
| Attribute | Details |
|---|---|
| CVE | CVE-2026-53486 |
| Severity | Critical |
| CVSS | 9.1 |
| Vulnerability | Path Traversal / Arbitrary File Write |
| Affected Package | @xhmikosr/decompress |
| Affected Versions | Fixed Versions |
|---|---|
| Earlier than 10.2.1 | 10.2.1 |
| 11.0.0 - 11.1.2 | 11.1.3+ |
| Legacy releases up to 4.2.1 | Upgrade to a supported release |
Update @xhmikosr/decompress to Version 10.2.1, 11.1.3, or later and replace unsupported legacy releases.
Validate archive contents, restrict extraction to isolated directories, and avoid extracting archives received from untrusted sources.
Review dependency inventories, monitor for unexpected file creation, audit archive extraction activity, and conduct software composition analysis (SCA).
CVE-2026-53486 represents a significant software supply chain risk due to the widespread adoption of @xhmikosr/decompress within the Node.js ecosystem. Organizations should identify affected applications, upgrade to patched releases immediately, and ensure archive extraction workflows prevent files from escaping designated extraction directories.
Fortinet has released multiple security advisories addressing seven vulnerabilities affecting FortiSandbox, FortiOS, FortiProxy, FortiPAM, and FortiSASE. The issues include unauthenticated VNC access, stack-based buffer overflow, reflected Cross-Site Scripting (XSS), path traversal, HTTP header injection, and buffer over-read vulnerabilities.
| CVE | Impact | Severity |
|---|---|---|
| CVE-2026-59835 | Unauthenticated VNC Access (FortiSandbox) | High |
| CVE-2026-59837 | Stack Buffer Overflow | Medium |
| CVE-2026-23573 | SSL-VPN Reflected Cross-Site Scripting | Medium |
| CVE-2026-59839 | Path Traversal | Medium |
| CVE-2025-62675 | HTTP Header Injection | Low |
| CVE-2025-62826 | HTTP Header Injection | Low |
| CVE-2025-43892 | Buffer Over-Read | Medium |
| Product Family | Status |
|---|---|
| FortiSandbox | Affected |
| FortiOS | Affected |
| FortiProxy | Affected |
| FortiPAM | Affected |
| FortiSASE | Affected |
Upgrade all affected Fortinet products to the latest vendor-supported versions and prioritize remediation of FortiSandbox deployments.
Limit access to management interfaces, disable unnecessary services, restrict VNC exposure, and enforce Multi-Factor Authentication for administrative accounts.
Review Fortinet logs for unauthorized access attempts, SSL-VPN activity, CLI operations, configuration changes, and abnormal authentication events.
Among the disclosed vulnerabilities, CVE-2026-59835 presents the greatest risk due to its unauthenticated attack vector and potential exposure of FortiSandbox VNC services. Organizations should immediately patch internet-facing Fortinet appliances, review management interface exposure, and maintain regular firmware updates to reduce the likelihood of compromise.
A High-severity vulnerability (CVE-2026-14266) has been disclosed in 7-Zip affecting the processing of XZ-compressed archives. The flaw may allow attackers to execute arbitrary code when a user opens a specially crafted archive using vulnerable versions of 7-Zip.
The vulnerability exists within the XZ decompression engine of 7-Zip and can be triggered using a specially crafted archive. Although exploitation requires user interaction, archive-based attacks remain one of the most common methods used in phishing campaigns, malware delivery, and supply chain attacks.
| Attribute | Details |
|---|---|
| CVE | CVE-2026-14266 |
| Severity | High |
| CVSS | 7.0 |
| Type | Heap-Based Buffer Overflow |
| Affected Component | XZ Decompression Engine |
| Attack Vector | Local (User Interaction Required) |
| Impact | Arbitrary Code Execution |
| Product | Affected Versions | Fixed Version |
|---|---|---|
| 7-Zip | All versions prior to 26.02 | 26.02 |
A critical security vulnerability (CVE-2026-63030) has been disclosed in WordPress Core, allowing unauthenticated remote attackers to execute arbitrary code through the WordPress REST API Batch Endpoint. The flaw carries a CVSS score of 9.8 (Critical) and may result in complete website compromise.
The vulnerability exists within the WordPress Core REST API Batch Endpoint and affects default WordPress installations where persistent object caching is not enabled. Because exploitation requires no authentication or user interaction, internet-facing WordPress websites are particularly exposed.
| Attribute | Details |
|---|---|
| CVE | CVE-2026-63030 |
| Severity | Critical |
| CVSS | 9.8 |
| Attack Vector | Network |
| Authentication | None |
| User Interaction | None |
| Affected Component | REST API Batch Endpoint |
| Impact | Remote Code Execution |
| Branch | Affected Versions | Fixed Version |
|---|---|---|
| Earlier than 6.9 | Not Affected | No Action Required |
| WordPress 6.9 | 6.9.0–6.9.4 | 6.9.5 |
| WordPress 7.0 | 7.0.0–7.0.1 | 7.0.2 |
| WordPress 7.1 Beta | Affected Beta Releases | 7.1 Beta 2 |
Immediately upgrade all affected WordPress installations to versions 6.9.5, 7.0.2, or 7.1 Beta 2 and verify successful deployment.
Review REST API exposure, enable persistent object caching where appropriate, restrict administrative access, and strengthen WAF protections.
Monitor REST API requests, review administrator activity, inspect for unauthorized plugins, themes, web shells, and unexpected configuration changes.
CVE-2026-63030 represents one of the most serious WordPress Core vulnerabilities disclosed in recent years due to its unauthenticated attack vector and critical CVSS score of 9.8. Because WordPress powers millions of internet-facing websites, organizations should prioritize immediate patch deployment and continuous monitoring for indicators of compromise.
Unlike traditional intrusion campaigns, the attackers combined Artificial Intelligence with established offensive tooling to automate reconnaissance, vulnerability discovery, exploitation attempts, and operational tracking. The campaign primarily focused on internet-facing government infrastructure, probing exposed services and sensitive application paths at scale.
Asset Reconnaissance Lighthouse (ARL) identified approximately 61 UAE government hosts for assessment.
DeepAudit and a Claude-Code-style automation framework performed vulnerability discovery and sensitive path enumeration.
Threat actors attempted exploitation against public-facing services but encountered HTTP 401 responses, HTTP 302 redirects, and Web Application Firewall (WAF) protections.
Results were automatically categorized and prioritized for additional assessment using AI-assisted workflows.
| Tool | Purpose |
|---|---|
| Asset Reconnaissance Lighthouse (ARL) | External Asset Discovery |
| DeepAudit | AI Vulnerability Scanner |
| Claude-Code Style Agent | AI Attack Automation |
| DeepSeek | Workflow Generation |
| TencShell | Remote Shell Framework |
| Gshell | Command Execution |
| Vshell | Post-Exploitation Framework |
| Cobalt Strike (Linux/ARM) | Command & Control Beacon |
A critical vulnerability (CVE-2026-53513) has been identified in the @better-auth/sso plugin. The flaw allows authenticated attackers to abuse OIDC provider registration to perform Server-Side Request Forgery (SSRF), potentially exposing internal services, cloud metadata, and administrative interfaces. Certain configurations may also permit account takeover.
| CVE | Severity | Impact |
|---|---|---|
| CVE-2026-53513 | Critical (9.6) | SSRF / Account Takeover |
The vulnerability allows authenticated users to manipulate OpenID Connect (OIDC) provider registration, forcing the application server to initiate requests to internal or attacker-controlled destinations.
| Product | Affected Versions | Fixed Version |
|---|---|---|
| @better-auth/sso | >= 0.1.0 and < 1.6.11 | 1.6.11 |
Update all Better Auth SSO plugin installations to Version 1.6.11 or later.
Audit OIDC provider registration settings and disable trustEmailVerified unless required.
Limit outbound connectivity from application servers and monitor unusual OIDC registration activity.
This vulnerability combines SSRF with potential account takeover, making it particularly dangerous for cloud-hosted applications. Organizations should immediately patch affected deployments, review authentication configurations, and restrict application access to internal resources to reduce the risk of compromise.
Notepad++ has released Version 8.9.7 addressing five security vulnerabilities affecting session file handling, ZIP archive extraction, environment variable expansion, macro validation, and the Windows installer.
| Identifier | Impact | Severity |
|---|---|---|
| CVE-2026-54758 | Stack Buffer Overflow | High |
| CVE-2026-57233 | Zip Slip Path Traversal | High |
| CVE-2026-52886 | Session File Validation Bypass | High |
| GHSA-f4rj-vqq4-wvg4 | Macro Validation Bypass | High |
| GHSA-gp2r-262h-9hgf | PowerShell Command Injection | High |
| Product | Affected Versions | Fixed Version |
|---|---|---|
| Notepad++ | Versions prior to 8.9.7 | 8.9.7 |
Deploy Notepad++ Version 8.9.7 or later across all enterprise endpoints.
Avoid opening untrusted session files, ZIP archives, and installation packages from unknown sources.
Monitor for suspicious PowerShell activity, archive extraction behavior, macro execution, and unauthorized file modifications.
These vulnerabilities affect one of the most widely deployed text editors in enterprise environments. Although exploitation generally requires user interaction, attackers may leverage malicious ZIP archives, session files, or tampered installers to compromise systems. Organizations should immediately upgrade to Version 8.9.7 and educate users on handling untrusted files safely.
Google has released a Stable Channel security update for Chrome addressing seven vulnerabilities, including three Critical use-after-free flaws affecting the CameraCapture, GPU, and Network components. Additional High-severity issues impact Cast, V8, Ozone, and Aura.
| CVE | Component | Severity |
|---|---|---|
| CVE-2026-15899 | CameraCapture (Use-After-Free) | Critical |
| CVE-2026-15900 | GPU (Use-After-Free) | Critical |
| CVE-2026-15901 | Network (Use-After-Free) | Critical |
| CVE-2026-15902 | Cast | High |
| CVE-2026-15903 | V8 JavaScript Engine | High |
| CVE-2026-15904 | Ozone | High |
| CVE-2026-15905 | Aura | High |
| Platform | Fixed Version |
|---|---|
| Windows | 150.0.7871.128 / 150.0.7871.129 |
| macOS | 150.0.7871.128 / 150.0.7871.129 |
| Linux | 150.0.7871.128 |
Upgrade all Google Chrome installations to the latest Stable Channel version immediately.
Ensure automatic browser updates are enabled and remove unsupported Chrome versions.
Review endpoint logs for browser crashes, suspicious child processes, and unusual browsing activity.
The presence of three Critical use-after-free vulnerabilities affecting Chrome's CameraCapture, GPU, and Network components highlights the importance of rapid browser patching. Given Chrome's widespread enterprise deployment, organizations should prioritize immediate updates and maintain layered endpoint protection to reduce exposure to browser-based attacks.
ManageEngine has addressed a critical vulnerability (CVE-2026-6516) affecting ADAudit Plus. The flaw combines an authentication bypass with a path traversal vulnerability, allowing an unauthenticated attacker to achieve remote code execution on vulnerable servers.
| CVE | Impact | Severity |
|---|---|---|
| CVE-2026-6516 | Authentication Bypass + Path Traversal leading to Remote Code Execution | Critical (10.0) |
The vulnerability exists within the Agent APIs. By chaining an authentication bypass with a path traversal flaw, attackers can remotely execute arbitrary code without valid credentials.
| Product | Affected Versions | Fixed Version |
|---|---|---|
| ManageEngine ADAudit Plus | All versions prior to Build 8606 | Build 8606 |
Update all ADAudit Plus installations to Build 8606 or later without delay.
Limit Agent API access to trusted internal networks and restrict administrative interfaces.
Review Agent API logs, authentication events, and endpoint activity for indicators of compromise.
CVE-2026-6516 represents one of the most severe vulnerabilities disclosed for ManageEngine ADAudit Plus. Because the product is deeply integrated with Active Directory and often operates with elevated privileges, successful exploitation could provide attackers with extensive visibility into enterprise authentication infrastructure and facilitate lateral movement. Immediate patching and continuous monitoring are strongly recommended.
Mozilla has released Thunderbird ESR 140.13 and Thunderbird 153 to address more than 30 security vulnerabilities, including two Critical flaws with publicly available exploit code. The update strengthens protections against memory corruption, JavaScript, WebAssembly, DOM navigation, sandbox escape, and privilege escalation vulnerabilities.
| CVE | Component | Severity |
|---|---|---|
| CVE-2026-15718 | JavaScript WebAssembly (Invalid Pointer) | Critical |
| CVE-2026-15719 | DOM Navigation (Site Isolation Weakness) | Critical |
Mozilla also resolved numerous High-severity vulnerabilities affecting memory safety, browser rendering, extensions, sandbox protections, privilege escalation, and integrated browser components.
| Product | Fixed Version |
|---|---|
| Thunderbird ESR | 140.13 |
| Thunderbird | 153 |
Upgrade all Thunderbird installations to ESR 140.13, Version 153, or later.
Restrict installation of untrusted extensions and ensure automatic security updates are enabled.
Review endpoint logs for browser-like activity, abnormal crashes, suspicious extensions, and embedded HTML exploitation attempts.
Although Thunderbird disables JavaScript when displaying email messages, browser-like components remain exposed to sophisticated attacks. The availability of public exploit code for CVE-2026-15718 and CVE-2026-15719 significantly increases the urgency of patching. Organizations should prioritize upgrading Thunderbird, remove unsupported versions, and maintain layered endpoint security controls.
Alibaba has disclosed a critical Remote Code Execution (RCE) vulnerability affecting Fastjson 1.x. Tracked as CVE-2026-16723, the flaw carries a CVSS score of 9.0 and is actively being exploited in the wild. Public proof-of-concept exploit code is available, increasing the likelihood of widespread attacks.
| CVE | Impact | Severity |
|---|---|---|
| CVE-2026-16723 | Unauthenticated Remote Code Execution (RCE) | Critical (9.0) |
The vulnerability abuses Fastjson's polymorphic deserialization using the @type field. Unlike previous Fastjson issues, exploitation works under the default configuration without enabling AutoType or requiring third-party gadget chains.
| Product | Affected Versions | Status |
|---|---|---|
| Alibaba Fastjson | 1.2.68 through 1.2.83 | Migrate to Fastjson 2.x |
Verified vulnerable environments include Spring Boot 2.x, 3.x, and 4.x running on JDK 8, 11, 17, and 21.
Immediately identify applications using Fastjson 1.x and enable SafeMode wherever supported.
Remove deprecated Fastjson 1.x dependencies and migrate applications to the latest supported Fastjson 2.x release.
Inspect application logs for suspicious JSON payloads using @type, unexpected outbound connections, and signs of remote code execution.
CVE-2026-16723 is one of the most dangerous Fastjson vulnerabilities disclosed to date. The flaw is exploitable under the default configuration, public exploit code is available, and active attacks have already been observed. Organizations relying on Fastjson 1.x should treat this as an emergency patching priority by enabling SafeMode, upgrading to Fastjson 2.x, and continuously monitoring for indicators of compromise.
Multiple vulnerabilities have been identified affecting HPE Telco Network Function Virtualization Orchestrator, which could allow attackers to cause service disruption or compromise affected systems.
The vulnerabilities affect components and dependencies within the HPE Telco orchestration software. Depending on the specific vulnerability, successful exploitation could result in denial-of-service conditions, unauthorized remote access, memory corruption, buffer overflows, or exploitation of input-validation weaknesses.
The highest-rated issue, CVE-2026-42527, carries a CVSS score of 8.1, while several additional vulnerabilities have CVSS scores ranging from 7.5 to 7.3.
Organizations operating HPE Telco Network Function Virtualization Orchestrator should prioritize upgrading affected deployments to the vendor-recommended fixed versions.
| Threat Level | HIGH |
|---|---|
| Affected Technology | HPE Telco Network Function Virtualization Orchestrator |
| Affected Version | v7.7.0 and earlier |
| Fixed Version | v7.8.0 or later |
| Primary Risks | Service disruption, unauthorized access, memory corruption and input-validation weaknesses |
| Highest CVSS | 8.1 |
The advisory identifies the following vulnerabilities:
| CVE | CVSS |
|---|---|
| CVE-2026-42527 | 8.1 |
| CVE-2026-40984 | 7.5 |
| CVE-2026-44432 | 7.5 |
| CVE-2026-5079 | 7.5 |
| CVE-2026-59869 | 7.5 |
| CVE-2026-41720 | 7.4 |
| CVE-2026-43866 | 7.3 |
| CVE-2026-5038 | 5.3 |
| CVE-2026-53550 | 5.3 |
| CVE-2026-64607 | 5.3 |
Additional vulnerabilities identified in the advisory include:
These vulnerabilities affect different components and dependencies used by the HPE Telco orchestration software.
Depending on the vulnerability involved, exploitation could enable a remote attacker to:
Attackers may be able to trigger denial-of-service conditions, potentially affecting the availability of orchestration services.
Certain vulnerabilities may allow remote attackers to obtain unauthorized access to affected systems.
Memory-safety issues, including buffer overflow and memory corruption conditions, could potentially affect application stability and security.
Where exploitation results in unauthorized access or code execution, compromised orchestration infrastructure could provide an attacker with an avenue for further activity within the telecommunications environment.
Disruption of network-function orchestration could affect the management and availability of dependent network services.
| Product | Affected Version |
|---|---|
| HPE Telco Network Function Virtualization Orchestrator | v7.7.0 and earlier |
The vulnerabilities may exist across components and software dependencies included within the orchestration platform.
| Product | Fixed Version / Mitigation |
|---|---|
| HPE Telco Network Function Virtualization Orchestrator | v7.8.0 or later |
| HPE Telco Service Design and Configuration Designer (SDC.D) | v2.8.0 |
Organizations should use the latest applicable release provided by HPE where available.
The UAE Cyber Security Council recommends updating affected versions to the fixed or latest versions released by HPE.
Security teams should increase monitoring around affected orchestration infrastructure for suspicious or anomalous activity.
| Monitoring Area | Activity to Investigate |
|---|---|
| Remote Access | Unexpected or unauthorized connections to orchestration components. |
| Availability | Repeated crashes, service restarts or unexplained service disruption. |
| Authentication | Unusual successful or failed authentication activity. |
| Process Activity | Unexpected processes or abnormal application behavior. |
| Memory Errors | Application crashes or events associated with memory corruption. |
| Network Activity | Unexpected inbound or outbound connections. |
| Configuration Changes | Unauthorized modifications to orchestration or network-function configurations. |
The identified vulnerabilities present a significant security and operational concern for organizations running HPE Telco Network Function Virtualization Orchestrator.
The highest-rated vulnerability, CVE-2026-42527, carries a CVSS score of 8.1. Multiple additional vulnerabilities have CVSS scores of 7.5, 7.4 and 7.3, while other identified issues carry CVSS scores of 5.3.
The potential impact includes service disruption, unauthorized access, memory corruption, buffer overflow conditions and other security consequences depending on the vulnerability involved.
Because the affected technology supports network-function orchestration, successful exploitation could have broader operational consequences within telecommunications environments.
CyberShelter assesses these vulnerabilities as a HIGH-priority vulnerability management concern for organizations operating HPE Telco Network Function Virtualization Orchestrator.
The combination of multiple vulnerabilities, including high-severity issues and vulnerabilities capable of causing service disruption or unauthorized access, increases the potential risk to telecommunications environments.
Organizations should prioritize identification and remediation of affected deployments, particularly systems running v7.7.0 or earlier.
Primary Action: Upgrade affected HPE Telco Network Function Virtualization Orchestrator deployments to v7.8.0 or later and update SDC.D to v2.8.0 where applicable.
| Threat Level | HIGH |
|---|---|
| Affected Product | HPE Telco Network Function Virtualization Orchestrator |
| Affected Version | v7.7.0 and earlier |
| Fixed Version | v7.8.0 or later |
| SDC.D Fixed Version | v2.8.0 |
| Highest CVSS | 8.1 |
| Highest-Rated CVE | CVE-2026-42527 |
| Primary Risks | Service disruption, unauthorized access, memory corruption and buffer overflow |
| Recommended Priority | Immediate |
Multiple vulnerabilities affecting HPE Telco Network Function Virtualization Orchestrator present a significant security and operational risk to telecommunications environments.
Organizations running v7.7.0 or earlier should prioritize remediation and upgrade to v7.8.0 or later.
Where applicable, organizations should also update HPE Telco Service Design and Configuration Designer (SDC.D) to v2.8.0.
Security teams should combine patching with restricted remote access, enhanced monitoring and log analysis to identify potential exploitation attempts and minimize operational impact.
Immediate vulnerability assessment and remediation are recommended for affected HPE Telco orchestration environments.
JetBrains has released security updates addressing multiple vulnerabilities across IntelliJ IDEA, GoLand, PhpStorm, PyCharm, WebStorm, and TeamCity. The most severe issues, CVE-2026-64812 and CVE-2026-64813, carry a CVSS score of 10.0 and impact IntelliJ IDEA Remote Development. Additional vulnerabilities affecting TeamCity may enable code execution and compromise CI/CD environments.
| CVE | Impact | Severity |
|---|---|---|
| CVE-2026-64812 | Missing Authentication | Critical (10.0) |
| CVE-2026-64813 | Unauthorized Configuration Changes | Critical (10.0) |
| CVE-2026-65907 | TeamCity Code Execution | High (9.1) |
| CVE-2026-65906 | Kotlin DSL Sandbox Escape | High (8.8) |
| CVE-2026-64814 | Unauthorized File Access | High (8.6) |
| CVE-2026-65908 | Untrusted Component Inclusion | High (8.6) |
| CVE-2026-64804 / 64805 | Untrusted Component Inclusion | High (8.4) |
| Product | Fixed Version |
|---|---|
| IntelliJ IDEA Remote Development | 2026.2 |
| TeamCity | 2026.1.2 / 2025.11.6 |
| GoLand, PhpStorm, PyCharm, WebStorm | Latest Supported Release |
Deploy the latest supported versions of IntelliJ IDEA, TeamCity, and other affected JetBrains products.
Review TeamCity build configurations, Git VCS Roots, Kotlin DSL projects, and restrict Remote Development access to trusted users.
Audit CI/CD logs, Remote Development sessions, developer authentication events, and repository changes for signs of unauthorized activity.
The latest JetBrains security updates address critical vulnerabilities that could compromise enterprise development environments and software supply chains. Organizations should prioritize patching IntelliJ IDEA Remote Development and TeamCity deployments, strengthen access controls, and continuously monitor development infrastructure for unauthorized activity.
HP has disclosed a critical Remote Code Execution (RCE) vulnerability affecting Poly PrivateConnect deployments using Pexip. The flaw carries a CVSS score of 9.8 and could allow an unauthenticated attacker to execute arbitrary code, resulting in complete compromise of affected collaboration systems.
| CVE | Impact | Severity |
|---|---|---|
| CVE-2026-TBD | Unauthenticated Remote Code Execution (RCE) | Critical (9.8) |
The vulnerability affects Poly PrivateConnect deployments using Pexip. Successful exploitation requires no authentication and could provide attackers with full administrative control, enabling unauthorized access, system compromise, and disruption of enterprise collaboration services.
| Product | Updated Version |
|---|---|
| Poly PrivateConnect | v38.2 |
| Poly PrivateConnect | v39.2 |
| Poly PrivateConnect | v40.1 |
| Poly PrivateConnect | v41 |
Update all HP Poly PrivateConnect deployments to the latest supported release and verify successful installation.
Prioritize internet-facing deployments, restrict administrative interfaces to trusted networks, and segment collaboration infrastructure.
Review logs for unauthorized access attempts, configuration changes, privilege escalation, and indicators of remote code execution.
This vulnerability represents a critical risk because it enables unauthenticated remote code execution against enterprise collaboration infrastructure. Given the widespread use of HP Poly PrivateConnect for secure communications, organizations should immediately deploy vendor updates, restrict management access, and continuously monitor collaboration environments for signs of compromise.
Multiple high-severity vulnerabilities have been identified in XenServer 8.4 and XenServer 9. The vulnerabilities could allow a privileged attacker operating within a guest virtual machine to compromise or crash the underlying XenServer host, potentially affecting multiple virtual workloads hosted on the same physical server.
| CVE | Potential Impact | Severity |
|---|---|---|
| CVE-2026-42492 | Guest VM Escape / Host Compromise (XenServer 9) | High |
| CVE-2026-62428 | Hypervisor Security Issue | High |
| CVE-2026-62431 | Hypervisor Security Issue | High |
| CVE-2026-62432 | Hypervisor Security Issue | High |
| CVE-2026-62434 | Hypervisor Security Issue | High |
| CVE-2026-62435 | Hypervisor Security Issue | High |
| CVE-2026-62436 | Hypervisor Security Issue | High |
These vulnerabilities affect the XenServer hypervisor and may allow privileged users within guest virtual machines to weaken isolation boundaries, potentially resulting in guest-to-host escape, host compromise, or denial of service.
| Product | Affected Version | Recommended Action |
|---|---|---|
| XenServer | 8.4 | Update to the latest available release |
| XenServer | 9 | Update to the latest available release |
Update XenServer 8.4 and XenServer 9 hosts to the latest vendor-supported release available through the official update channel.
Limit privileged access within guest virtual machines, regularly review administrator permissions, and enforce least privilege.
Review XenServer logs for unusual activity, unexpected crashes, guest-to-host attack attempts, and signs of hypervisor compromise.
These vulnerabilities highlight the importance of maintaining secure virtualization infrastructure. Although exploitation requires privileged access within a guest virtual machine, successful attacks could undermine hypervisor isolation and impact multiple hosted workloads. Organizations should prioritize applying vendor updates, strengthen access controls, monitor hypervisor activity, and maintain secure backups to reduce operational risk.
GitLab has released security updates for Community Edition (CE) and Enterprise Edition (EE) addressing multiple High, Medium, and Low severity vulnerabilities affecting CI/CD pipelines, APIs, access controls, merge requests, project imports, GitLab Duo features, and Virtual Registries. The most severe issues could expose sensitive information, allow unauthorized modification of CI/CD configurations, and trigger denial-of-service conditions.
| CVE | Issue | CVSS |
|---|---|---|
| CVE-2026-6267 | Sensitive Information Exposure in GitLab Workhorse | 8.5 (High) |
| CVE-2026-12436 | Unauthorized CI/CD Pipeline Schedule Modification | 8.4 (High) |
| CVE-2026-15975 | Unauthenticated Denial of Service | 7.5 (High) |
GitLab also resolved several Medium-severity vulnerabilities affecting merge request approvals, project imports, Virtual Registries, GitLab Duo AI features, Pipeline Test Report APIs, access controls, credential protection, and cross-site scripting (XSS).
| Product | Fixed Versions |
|---|---|
| GitLab Community Edition (CE) | 19.2.1 / 19.1.3 / 19.0.5 |
| GitLab Enterprise Edition (EE) | 19.2.1 / 19.1.3 / 19.0.5 |
Update GitLab Community Edition and Enterprise Edition to versions 19.2.1, 19.1.3, 19.0.5, or later.
Audit pipeline schedules, protected branches, project import permissions, API authorization, and administrative access controls.
Review audit logs, authentication events, API usage, privilege changes, and unexpected CI/CD pipeline modifications for suspicious behavior.
These security updates address vulnerabilities affecting critical GitLab DevSecOps functionality, including source code management, CI/CD pipelines, APIs, and AI-assisted development features. While no Critical-severity vulnerabilities were disclosed, the High-severity issues could significantly impact software development operations, expose sensitive information, and weaken software supply chain security. Organizations should prioritize patching all GitLab instances, strengthen access controls, and continuously monitor development environments for unauthorized activity.
Google has released a major Stable Channel security update for Chrome addressing 370 security vulnerabilities, including multiple Critical and High-severity flaws affecting browser rendering, graphics, networking, authentication, JavaScript execution, media processing, and browser update components. Successful exploitation could lead to remote code execution, information disclosure, privilege escalation, security policy bypass, browser crashes, and memory corruption.
| CVE | Component | Issue |
|---|---|---|
| CVE-2026-17650 | Compositing | Use-After-Free |
| CVE-2026-17651 | Dawn | Insufficient Validation of Untrusted Input |
| CVE-2026-17652 | Views | Use-After-Free |
| CVE-2026-17653 | Skia | Use-After-Free |
| CVE-2026-17654 | Chrome Updater | Race Condition |
| CVE-2026-17655 | ANGLE | Insufficient Validation |
| CVE-2026-17656 | Ozone | Use-After-Free |
Google also addressed multiple memory corruption vulnerabilities including heap buffer overflows, out-of-bounds read/write, integer overflows, type confusion, race conditions, cryptographic weaknesses, and policy enforcement bypass issues.
| Platform | Patched Version |
|---|---|
| Windows | 151.0.7922.71 / 151.0.7922.72 |
| macOS | 151.0.7922.71 / 151.0.7922.72 |
| Linux | 151.0.7922.71 |
| Android | 151.0.7922.71 |
Deploy the latest Stable Channel release across Windows, macOS, Linux, and Android devices.
Enable automatic browser updates, remove unsupported versions, review enterprise browser policies, and restrict unauthorized extensions.
Review browser crashes, suspicious process activity, malicious website access, and endpoint detection alerts for browser-based exploitation attempts.
This Chrome Stable Channel update addresses one of the largest batches of vulnerabilities released by Google, impacting nearly every major browser subsystem. Multiple Critical Use-After-Free vulnerabilities and widespread memory corruption flaws present a significant risk of remote code execution through malicious web content. Organizations should prioritize immediate deployment of the latest Chrome release, enforce enterprise browser security policies, and continuously monitor endpoints for browser-based attacks.
Adobe has released a security update for Adobe Campaign Classic v7 addressing one Critical and one High-severity vulnerability. The most severe issue, CVE-2026-48449, allows an unauthenticated attacker to remotely execute arbitrary code, while CVE-2026-48448 is a SQL Injection flaw that may expose sensitive files and system information.
| CVE | Vulnerability | Severity |
|---|---|---|
| CVE-2026-48449 | Incorrect Authorization (Remote Code Execution) | Critical (CVSS 10.0) |
| CVE-2026-48448 | SQL Injection | High (CVSS 8.6) |
| Product | Affected Version | Fixed Version |
|---|---|---|
| Adobe Campaign Classic v7 | 7.4.3 Build 9397 and earlier | 7.4.3 Build 9398 |
Platforms: Windows, Linux
Upgrade Adobe Campaign Classic v7 to Build 9398 or later across all production and staging environments.
Restrict internet access, enforce least privilege, and limit administrative access to trusted users and networks.
Review application logs, monitor SQL activity, detect unauthorized administrative actions, and investigate indicators of remote code execution.
The Adobe Campaign Classic vulnerabilities represent a significant threat to enterprise marketing environments. The unauthenticated CVE-2026-48449 Remote Code Execution vulnerability carries the maximum CVSS score of 10.0, allowing complete server compromise if exploited. Combined with the SQL Injection vulnerability, attackers could access sensitive customer data, retrieve confidential system information, and establish persistent access. Organizations should immediately deploy Build 9398, restrict administrative exposure, and continuously monitor systems for indicators of compromise.
Synology has released a security update for Synology Assistant for Windows to address a high-severity vulnerability (CVE-2026-4793) caused by incorrect default file permissions. The flaw could allow a local attacker with limited privileges to read or modify arbitrary files and trigger denial-of-service conditions during installation.
| CVE | Vulnerability | Severity |
|---|---|---|
| CVE-2026-4793 | Incorrect Default Permissions | High (CVSS 7.3) |
The vulnerability results from insecure default permissions during installation. A local attacker with low privileges may exploit the flaw to read or modify arbitrary files, compromise system integrity, or trigger denial-of-service conditions.
| Product | Affected Version | Fixed Version |
|---|---|---|
| Synology Assistant for Windows | Earlier than 7.0.7-50095 | 7.0.7-50095 or later |
Upgrade Synology Assistant for Windows to Version 7.0.7-50095 or later and verify successful deployment across all managed systems.
Restrict local administrative privileges, review Windows file permissions, and enforce the principle of least privilege for all user accounts.
Review Windows event logs, monitor installation activity, investigate unauthorized file modifications, and detect suspicious local endpoint behavior.
Although CVE-2026-4793 requires local access, insecure default permissions can enable attackers with limited privileges to manipulate sensitive files and impact system integrity. Organizations should prioritize upgrading to Synology Assistant 7.0.7-50095, enforce least-privilege access controls, and continuously monitor Windows endpoints for unauthorized file access or modification.
MongoDB has released security updates addressing multiple vulnerabilities affecting MongoDB Server and MongoDB Compass. The updates resolve Critical and High-severity flaws involving memory corruption, access control bypass, arbitrary command execution, information disclosure, and denial-of-service conditions.
| CVE | Issue | Severity |
|---|---|---|
| CVE-2026-13072 | Improper Input Validation / Memory Corruption | Critical (CVSS 9.2) |
| CVE-2026-11933 | Use-After-Free | High (CVSS 8.7) |
| CVE-2026-13059 | RBAC Access Control Bypass | High (CVSS 8.6) |
| CVE-2026-14881 | Arbitrary Command Execution (Compass) | High (CVSS 8.4) |
| Product | Recommendation |
|---|---|
| MongoDB Server | Upgrade to the latest supported security release |
| MongoDB Compass | Upgrade to the latest supported version |
Upgrade MongoDB Server and MongoDB Compass to the latest vendor-supported versions and verify successful deployment across all environments.
Review RBAC permissions, restrict privileged database accounts, disable unused features such as Compute Mode where applicable, and secure OIDC authentication workflows.
Review audit logs for unauthorized access, monitor abnormal command execution, investigate suspicious Compass connection imports, and identify memory-related application errors.
The latest MongoDB security updates address several high-impact vulnerabilities affecting both database servers and administrative tooling. While CVE-2026-13072 primarily impacts deployments with Compute Mode enabled, the RBAC bypass vulnerability (CVE-2026-13059) and the MongoDB Compass command execution flaw (CVE-2026-14881) present significant risks to enterprise environments. CyberShelter recommends immediately updating all MongoDB deployments, reviewing database permissions, and continuously monitoring infrastructure for indicators of compromise.
Veeam has released critical security updates addressing multiple vulnerabilities affecting Veeam Service Provider Console and Veeam ONE. The updates resolve vulnerabilities ranging from Medium to Critical severity, including unauthenticated Remote Code Execution (RCE), credential compromise, arbitrary file write, SQL injection, privilege escalation, information disclosure, and denial-of-service (DoS).
| CVE | Description | Severity |
|---|---|---|
| CVE-2026-64633 | Unauthenticated Remote Code Execution (Veeam ONE Agent Host) | Critical (CVSS 10.0) |
| CVE-2026-58073 | Credential Compromise through Managed Agent Impersonation | Critical (CVSS 9.5) |
| CVE-2026-58072 | Arbitrary File Write leading to Remote Code Execution | Critical (CVSS 9.0) |
| CVE | Issue |
|---|---|
| CVE-2026-58067 | Denial of Service |
| CVE-2026-58071 | Privilege Escalation |
| CVE-2026-58075 | Arbitrary File Read / Privilege Escalation |
| CVE-2026-58074 | Arbitrary Code Execution |
| CVE-2026-64631 | SQL Injection |
| CVE-2026-64634 | Local Privilege Escalation |
| CVE-2026-64630 | Information Disclosure |
| Product | Fixed Version |
|---|---|
| Veeam Service Provider Console | 9.3.0.35057 or later |
| Veeam ONE | 13.1.0.7034 or later |
Upgrade Veeam Service Provider Console to version 9.3.0.35057 or later and Veeam ONE to 13.1.0.7034 or later. Verify successful deployment across all production systems.
Restrict access to management interfaces, review administrative permissions, isolate backup infrastructure, enforce least privilege, and enable Multi-Factor Authentication (MFA).
Monitor authentication logs, investigate unexpected file creation, review SQL activity, audit privileged accounts, and maintain offline and immutable backups to improve resilience against ransomware attacks.
The vulnerabilities addressed in the latest Veeam security updates represent a significant threat to enterprise backup and monitoring infrastructure. The Critical Remote Code Execution vulnerability (CVE-2026-64633) affecting Veeam ONE, together with the credential theft and arbitrary file write vulnerabilities impacting Veeam Service Provider Console, could enable attackers to compromise systems responsible for protecting business-critical data. Since backup infrastructure is frequently targeted during ransomware campaigns, organizations should prioritize immediate patching, strengthen administrative controls, and continuously monitor backup environments for indicators of compromise.
Cisco has released security updates addressing multiple vulnerabilities across several enterprise products, including Cisco Catalyst SD-WAN Software, Cisco IOS XE Software, Cisco Secure Firewall Management Center, Cisco Integrated Management Controller (IMC), Cisco RoomOS, and other networking platforms. The updates address Critical, High, and Medium-severity vulnerabilities involving authentication bypass, privilege escalation, denial-of-service (DoS), information disclosure, argument injection, firewall rule bypass, and cross-site scripting (XSS).
| Product | Critical CVEs |
|---|---|
| Cisco Catalyst SD-WAN Software | CVE-2026-20303, CVE-2026-20304, CVE-2026-20310 |
| Cisco IOS XE Software | CVE-2026-20267, CVE-2026-20268, CVE-2026-20269 |
| Cisco Secure Firewall Management Center | CVE-2026-20079 (Authentication Bypass) |
| Component | Issue |
|---|---|
| Cisco IOS XE | CVE-2026-20124, CVE-2026-20263 - Denial of Service |
| Cisco IOS / IOS XE | CVE-2026-20301 - Extensible Messaging Client Protocol DoS |
| Cisco IMC | CVE-2026-20200, CVE-2026-20288 - Argument Injection |
| Secure Firewall Management Center | CVE-2026-20316 - Static Credential |
| Cisco IOS XE | CVE-2026-20311, CVE-2026-20308 - Web Management DoS |
| Terminal Services Agent | CVE-2026-20028 - Firewall Rule Bypass |
| SD-WAN Manager | CVE-2026-20294 - Information Disclosure |
| RoomOS | CVE-2026-20289 - Logging Information Disclosure |
| Cisco IMC | CVE-2026-20198 - Cross-Site Scripting (XSS) |
Immediately install the latest Cisco security updates across all affected products. Prioritize Critical vulnerabilities affecting Cisco Catalyst SD-WAN, Cisco IOS XE Software, and Cisco Secure Firewall Management Center.
Restrict administrative access to trusted management networks, disable unnecessary services, implement Multi-Factor Authentication (MFA), and review device configurations against Cisco security best practices.
Monitor authentication logs, firewall events, SD-WAN management activity, configuration changes, and network device performance for indicators of compromise or attempted exploitation.
The latest Cisco security updates address multiple vulnerabilities affecting enterprise networking, security, and infrastructure management platforms. The authentication bypass vulnerability (CVE-2026-20079) and the Critical vulnerabilities impacting Cisco Catalyst SD-WAN and Cisco IOS XE represent significant risks because they target core enterprise networking infrastructure. Organizations should prioritize immediate patching, implement Cisco's recommended mitigations where immediate updates are not possible, restrict management access, and continuously monitor network infrastructure for unauthorized activity.
JetBrains has released emergency security updates to address a critical vulnerability affecting TeamCity, its widely used Continuous Integration and Continuous Delivery (CI/CD) platform. The vulnerability, tracked as CVE-2026-63077, carries a CVSS v3.1 score of 9.8 (Critical) and is actively exploited in the wild. The flaw results from the deserialization of untrusted data within the TeamCity agent polling protocol, allowing an unauthenticated attacker to execute arbitrary code remotely on vulnerable TeamCity servers.
| Attribute | Details |
|---|---|
| CVE | CVE-2026-63077 |
| Severity | Critical (CVSS 9.8) |
| Vulnerability Type | Deserialization of Untrusted Data |
| Attack Vector | Network |
| Authentication Required | None |
| User Interaction | None |
| Exploitation Status | Actively Exploited in the Wild |
| Product | Fixed Versions |
|---|---|
| JetBrains TeamCity | 2026.1.3 / 2025.11.7 |
Upgrade TeamCity servers to Version 2026.1.3 or 2025.11.7. Prioritize internet-facing TeamCity deployments and verify successful installation across production environments.
Restrict TeamCity management access to trusted networks, rotate stored credentials after patching, review agent communication settings, and isolate CI/CD infrastructure from production systems.
Review TeamCity audit logs, investigate unexpected agent registrations, monitor build pipeline changes, audit configuration modifications, and search for indicators of compromise resulting from active exploitation.
CVE-2026-63077 represents one of the most serious vulnerabilities disclosed for JetBrains TeamCity due to its ability to enable unauthenticated remote code execution against enterprise CI/CD infrastructure. Because the vulnerability is actively exploited in the wild, organizations should treat remediation as an immediate priority. Compromise of a TeamCity server could expose source code, deployment credentials, signing certificates, and build artifacts while enabling attackers to manipulate software build pipelines and conduct software supply chain attacks. Immediate patching, credential rotation, infrastructure hardening, and continuous monitoring are essential to reducing organizational risk.
Multiple vulnerabilities have been identified in VMware Avi Load Balancer that could allow attackers to bypass authentication or authorization, execute arbitrary code, escalate privileges, or access sensitive files.
The most severe vulnerability, CVE-2026-47865 (CVSS 9.8), is a Critical authentication bypass vulnerability affecting the Avi Control Plane.
Organizations using affected VMware Avi Load Balancer versions should immediately upgrade to the latest fixed releases.
Severity: Critical
A network-accessible authentication bypass vulnerability could allow an attacker to access the VMware Avi Load Balancer Control Plane without authentication.
An attacker may bypass authorization controls and access protected portions of the Avi Control Plane.
A network-accessible vulnerability that could allow arbitrary code execution on the Avi Control Plane.
A local attacker may execute code with root privileges.
An authenticated attacker may inject and execute arbitrary code.
Allows an authenticated attacker to obtain elevated privileges.
An authenticated attacker may access files outside intended directories, potentially exposing sensitive information.
| Branch | Fixed Version |
|---|---|
| 32.x | 32.1.2 |
| 31.x | 31.2.2-2p3 |
| 30.x | 30.2.7 |
| 22.x | 22.1.7-2p12 |
Upgrade VMware Avi Load Balancer to the latest fixed release, preferably Version 32.1.2.
Limit Control Plane access to trusted management networks and enforce least-privilege access.
Review authentication attempts, configuration changes, privilege escalation events, and abnormal code execution.
The VMware Avi Load Balancer vulnerabilities present a significant risk because they combine a Critical authentication bypass vulnerability with multiple High-severity flaws affecting authorization, remote code execution, privilege escalation, and directory traversal.
Organizations should prioritize immediate patching, restrict management interface exposure, and continuously monitor Avi Control Plane activity for signs of compromise.
| Date | 17 August 2026 |
| Severity | Critical |
| Vendor | VMware |
| Product | VMware Avi Load Balancer |
| Primary CVE | CVE-2026-47865 |
| CVSS | 9.8 (Critical) |
| Risk Level | Critical |
| Recommended Action | Immediately update VMware Avi Load Balancer, restrict management access, and monitor Control Plane activity. |
IBM has addressed multiple Critical-severity vulnerabilities affecting IBM App Connect Enterprise, IBM Power Hardware Management Console (HMC), and IBM webMethods Integration.
The vulnerabilities carry a CVSS score of 9.8 (Critical) and could allow unauthenticated attackers to execute arbitrary commands or code, write files to arbitrary locations, and potentially compromise affected systems.
The most significant issues include an improper input validation vulnerability in Power HMC, a deserialization vulnerability in webMethods Integration Server, and a path traversal vulnerability in App Connect Enterprise.
The affected IBM products provide critical capabilities for enterprise application integration, infrastructure management, and automated business workflows.
Successful exploitation of these vulnerabilities could allow attackers to execute commands with elevated privileges, execute arbitrary code, or manipulate files on affected systems. Because these products may operate within privileged enterprise environments, exploitation could have significant consequences for system confidentiality, integrity, and availability.
| Severity | Critical |
| CVSS | 9.8 |
| Vulnerability Type | Improper Input Validation |
| Authentication | Unauthenticated |
An improper input validation vulnerability in Power Hardware Management Console (HMC) could allow an unauthenticated attacker to execute arbitrary commands with elevated privileges.
| Severity | Critical |
| CVSS | 9.8 |
| Vulnerability Type | Deserialization of Untrusted Data |
| Affected Component | WmServiceMock package |
A deserialization vulnerability in the WmServiceMock package could allow an unauthenticated attacker to execute arbitrary code on affected webMethods Integration environments.
| Severity | Critical |
| CVSS | 9.8 |
| Vulnerability Type | Path Traversal |
A path traversal vulnerability could allow an attacker to write files to arbitrary locations on the affected system. Successful exploitation could potentially be used to modify system files or establish conditions for further compromise.
| Product | Affected Versions |
|---|---|
| IBM App Connect Enterprise | 12.0.1.0 - 12.0.12.27 and 13.0.1.0 - 13.0.7.2 |
| IBM Power HMC | V10.3.1050.0 - V10.3.1064.0 and V11.1.1110.0 - V11.1.1112.0 |
| IBM webMethods Integration Server | 10.11 and 10.15 |
Upgrade to 12.0.12.28 or 13.0.8.0.
Apply the applicable security updates available through IBM Fix Central.
Remove the WmServiceMock package from production and internet-facing systems.
Upgrade IBM App Connect Enterprise to 12.0.12.28 or 13.0.8.0. Apply applicable IBM Power HMC security updates through IBM Fix Central. Remove the WmServiceMock package from production and internet-facing webMethods Integration environments.
Restrict external access to IBM management and integration interfaces. Ensure administrative interfaces are accessible only from trusted networks and apply least-privilege access controls.
Review authentication and system logs for unauthorized activity. Monitor for unexpected command execution and investigate unusual file creation or modification. Review administrative actions on Power HMC and monitor webMethods and App Connect Enterprise environments for abnormal activity.
The three vulnerabilities represent a critical risk to enterprise environments, particularly because the reported issues include unauthenticated command execution and arbitrary code execution.
CVE-2026-12943 affecting Power HMC could allow unauthenticated attackers to execute commands with elevated privileges, while CVE-2026-12118 could enable arbitrary code execution through the vulnerable webMethods component. CVE-2026-15435 introduces the risk of arbitrary file writes within App Connect Enterprise.
Organizations should prioritize remediation of all affected IBM deployments, restrict internet exposure, and closely monitor these systems for signs of unauthorized activity.
| Date | 11 August 2026 |
| Severity | Critical |
| Affected Vendor | IBM |
| Primary CVEs | CVE-2026-12943, CVE-2026-12118, CVE-2026-15435 |
| CVSS | 9.8 (Critical) |
| Primary Risks | Remote Code Execution (RCE), Arbitrary Command Execution, Privilege Escalation, Arbitrary File Write, Deserialization of Untrusted Data, Path Traversal, System Compromise |
| Fixed / Mitigated | App Connect Enterprise 12.0.12.28 / 13.0.8.0; Power HMC applicable IBM security updates; remove WmServiceMock from production and internet-facing systems |
| Risk Level | Critical |
Observed active exploitation of a high-severity authentication bypass vulnerability in LiteLLM, tracked as CVE-2026-59822.
The vulnerability could allow an unauthenticated remote attacker to establish an authenticated MCP session using an arbitrary Bearer token.
The issue affects LiteLLM's MCP Streamable HTTP endpoint and could enable unauthorized users to enumerate and invoke configured MCP tools.
With a CVSS v4.0 score of 8.8, combined with confirmed active exploitation, this vulnerability represents a significant risk to organizations using LiteLLM to connect AI systems with internal applications, databases, cloud services, development environments, or other privileged tools.
Organizations running affected LiteLLM versions should prioritize immediate remediation, particularly for internet-facing deployments.
Severity: High
CVSS v4.0: 8.8
CWE: CWE-287 - Improper Authentication
CWE: CWE-306 - Missing Authentication for Critical Function
Product: LiteLLM
Vendor / Project: BerriAI
Affected Component: MCP Streamable HTTP endpoint
Exploitation Status: Actively exploited in the wild
The vulnerability results from an authentication fallback condition involving OAuth2 passthrough.
Under the vulnerable implementation, a failed
LiteLLM API-key validation could fall back to an
empty UserAPIKeyAuth() object.
This could allow a request containing a fabricated Authorization Bearer token to proceed to MCP tooling without a valid LiteLLM API key.
As a result, an unauthenticated attacker could potentially establish an authenticated MCP session and interact with configured MCP tools.
An attacker could identify an exposed LiteLLM MCP Streamable HTTP endpoint.
The attacker could submit a request containing a fabricated Bearer token.
The request could trigger the authentication fallback condition in the vulnerable implementation.
The attacker could potentially establish an MCP session without possessing a valid LiteLLM API key.
The attacker could potentially enumerate available MCP tools exposed through the compromised session.
The attacker could potentially invoke configured MCP tools accessible through the unauthorized session.
The ultimate impact depends on the tools and services configured behind the MCP integration.
Successful exploitation could allow attackers to:
Where LiteLLM is integrated with sensitive enterprise systems, exploitation could create a pathway to broader unauthorized access.
All LiteLLM versions earlier than 1.84.0 are identified as affected by the supplied advisory.
| Product | Fixed Version |
|---|---|
| LiteLLM | 1.84.0 or later |
Organizations should verify the version deployed across all LiteLLM instances, including containerized and development environments.
Upgrade all affected LiteLLM installations to LiteLLM 1.84.0 or later.
Immediately identify and remediate LiteLLM instances that are:
Identify all MCP tools configured through LiteLLM and determine what internal or privileged services they can access.
Pay particular attention to integrations involving:
Verify that valid API-key and authentication controls are enforced for MCP endpoints.
Investigate configurations involving OAuth2 passthrough and ensure that authentication failures cannot fall back to an unauthenticated state.
Review LiteLLM, MCP, proxy, and network logs for:
Because exploitation has been reported in the wild, organizations operating vulnerable versions should review historical logs and MCP activity to determine whether unauthorized access occurred before patching.
CVE-2026-59822 represents a significant security risk because it combines an authentication bypass vulnerability with remote accessibility and confirmed active exploitation.
The risk is particularly important for organizations using LiteLLM as a gateway to MCP tools and privileged enterprise services.
Compromise of the LiteLLM authentication layer could provide unauthorized access to functionality that extends beyond the LiteLLM platform itself.
Recommended Action: Upgrade immediately to LiteLLM 1.84.0 or later and investigate potentially exposed MCP endpoints for signs of unauthorized access.
| Date | 3 September 2026 |
| Vendor / Project | BerriAI / LiteLLM |
| CVE | CVE-2026-59822 |
| Severity | High |
| CVSS v4.0 | 8.8 |
| Primary Vulnerability | Authentication Bypass |
| Affected Component | MCP Streamable HTTP Endpoint |
| Affected Versions | Earlier than 1.84.0 |
| Fixed Version | 1.84.0 or later |
| Exploitation Status | Actively Exploited in the Wild |
| Primary Risk | Unauthorized MCP Session and Tool Invocation |
| Recommended Action | Upgrade immediately, secure MCP endpoints, review connected services, and investigate historical activity. |
SAP has released its August 2026 Security Updates, addressing multiple vulnerabilities across its enterprise product portfolio.
The security updates cover vulnerabilities ranging from Critical to Low severity, including issues involving improper authorization, code injection, memory corruption, privilege escalation, remote code execution, directory traversal, SQL injection, and OS command injection .
Several Critical vulnerabilities affect SAP Commerce Cloud, SAP Manufacturing Integration and Intelligence, and SAP NetWeaver / ABAP Platform . Successful exploitation could allow attackers to bypass authorization controls, execute malicious code, corrupt memory, or compromise affected enterprise systems.
Organizations using affected SAP products should review the August 2026 security updates and apply the relevant fixes according to SAP's official security guidance.
SAP products are widely deployed across enterprise environments to support business operations, manufacturing processes, financial systems, analytics platforms, supply chain management, and application integration.
The August 2026 security release addresses vulnerabilities across numerous SAP platforms and components. Several issues affect security-critical functionality such as authorization, code execution, memory handling, and application interfaces.
Given the importance of SAP infrastructure within enterprise environments, organizations should prioritize remediation of the Critical and High-severity vulnerabilities and ensure all applicable security updates are deployed.
Vulnerability Type: Improper Authorization
An improper authorization vulnerability affects the SAP Commerce Cloud Data Hub Adapter and could allow unauthorized actions within affected environments.
Vulnerability Type: Code Injection
A critical code injection vulnerability could allow malicious input to result in unauthorized code execution within affected SAP Manufacturing Integration and Intelligence environments.
Vulnerability Type: Memory Corruption
A critical memory corruption vulnerability affects SAP NetWeaver and ABAP Platform and could potentially impact the stability and security of affected systems.
Vulnerability Type: Code Injection
A further critical code injection vulnerability affects SAP Manufacturing Integration and Intelligence and may allow malicious code to be executed under affected conditions.
SAP has also addressed multiple High-severity vulnerabilities, including:
Privilege Escalation in SAP ABAP Developer Tools .
Potential Buffer Overflow in SAP Commerce Cloud .
Credentials Disclosure in SAP BusinessObjects Business Intelligence Platform .
Remote Code Execution in SAP Change and Transport System Attach Tool .
Directory Traversal in SAP Manufacturing Integration and Intelligence .
Missing Authorization Checks in SAP Manufacturing Integration and Intelligence .
Missing Authorization Checks in SAP Manufacturing Integration and Intelligence .
Multiple additional High-severity vulnerabilities affect the SAP Business AI Platform (Approuter), including:
These vulnerabilities increase the overall attack surface of affected SAP Business AI Platform deployments.
SAP also addressed multiple Medium-severity vulnerabilities, including:
Additional missing authorization checks were addressed across:
These include:
Issue: Hard-coded credentials in SAP Advanced Planning and Optimization.
Issue: Security misconfiguration in SAP Data Services Management Console.
Although classified as Low severity, these issues should still be addressed as part of routine SAP security maintenance.
Depending on the affected SAP component and vulnerability, successful exploitation could potentially allow attackers to:
The August 2026 updates affect multiple SAP product families, including:
The SAP August 2026 Security Updates address a broad range of vulnerabilities across critical enterprise applications and infrastructure.
The most significant risks include Critical code injection vulnerabilities in SAP Manufacturing Integration and Intelligence, improper authorization in SAP Commerce Cloud, and memory corruption in SAP NetWeaver and ABAP Platform . Additional High-severity issues include remote code execution, privilege escalation, credential disclosure, directory traversal, and authorization weaknesses.
Because SAP systems frequently support mission-critical business processes and contain highly sensitive enterprise data, organizations should treat these updates as a high-priority security maintenance activity .
CyberShelter recommends conducting an immediate asset and version review, prioritizing Critical and High-severity vulnerabilities, applying the latest SAP security fixes, and monitoring affected environments for suspicious activity.
| Date | 13 August 2026 |
| Severity | Critical |
| Affected Vendor | SAP |
| Advisory | SAP August 2026 Security Updates |
| Primary Critical CVEs |
CVE-2026-58231 CVE-2026-44772 CVE-2026-34265 CVE-2026-44758 |
| Primary Vulnerability Types |
Improper Authorization, Code Injection, Memory Corruption, Remote Code Execution, Privilege Escalation, Directory Traversal, SQL Injection, OS Command Injection, Credentials Disclosure |
| Risk Level | Critical |
| Recommended Action | Review and apply all applicable SAP August 2026 security updates, prioritize Critical and High-severity vulnerabilities, restrict exposed SAP services, review access controls, and monitor affected environments for suspicious activity. |
A high-severity vulnerability has been identified in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software.
Tracked as CVE-2026-20349, the vulnerability carries a CVSS score of 8.6 (High) and is reportedly actively exploited in the wild.
An unauthenticated remote attacker could send a specially crafted HTTP request to the Remote Access SSL VPN service, potentially causing an affected firewall device to reload and resulting in a Denial-of-Service (DoS) condition.
Organizations operating internet-facing Cisco firewalls with Remote Access VPN, SSL VPN, IKEv2 client-services, or Zero Trust Network Access configurations should prioritize remediation immediately.
Severity: High
CVSS: 8.6
Attack Type: Remote Denial of Service
Authentication: Not Required
Exploitation Status: Actively Exploited in the Wild
The vulnerability is caused by insufficient error checking when processing HTTP requests.
An unauthenticated remote attacker could exploit the vulnerability by sending a specially crafted HTTP request to the Remote Access SSL VPN service.
Successful exploitation could cause an affected firewall device to reload, resulting in a denial-of-service condition.
Potentially vulnerable releases include configurations where the following services are enabled:
Potentially vulnerable releases include configurations with:
Devices with IKEv2 client services configured may be exposed when the following functionality is enabled:
crypto ikev2 enable <interface_name> client-services port <port_numbers>
Potentially vulnerable configurations include:
webvpn
enable <interface_name>
Potentially vulnerable configurations include:
zero-trust
enable
Organizations should review their Cisco firewall configurations to determine whether affected services are enabled.
| Release | Fixed Hot Fix |
|---|---|
| 9.16 | Hot Fix 9.16.4.50 |
| 9.18 | Hot Fix 9.18.4.50 |
| 9.20 | Hot Fix 9.20.4.235 |
| 9.22 | Hot Fix 9.22.3.191 |
| 9.23 | Hot Fix 9.23.1.211 |
| 9.24 | Hot Fix 9.24.1.221 |
| Release | Fixed Hot Fix |
|---|---|
| 7.0 | Hot Fix 7.0.9.1-1 |
| 7.2 | Hot Fix 7.2.11.1-2 |
| 7.4 | Hot Fix 7.4.7.1-1 |
| 7.6 | Hot Fix 7.6.4.1-2 |
| 7.7 | Hot Fix 7.7.11.1-2 |
| 10.0 | Hot Fix 10.0.0.1-2 |
Successful exploitation could cause affected firewall appliances to reload unexpectedly, resulting in:
Because the vulnerability does not require authentication and is actively exploited, internet-facing systems should be treated as a priority.
Apply the applicable Cisco security update or hot fix and upgrade affected ASA and FTD deployments to the appropriate fixed release.
Prioritize internet-facing firewall appliances and systems providing remote-access services.
Identify all Cisco ASA and FTD devices exposed to the internet.
Determine whether Remote Access VPN, SSL VPN, IKEv2 client-services, or Zero Trust Network Access is enabled.
Review configurations for unnecessary externally accessible services.
Monitor firewall and VPN logs, unexpected device reloads, suspicious HTTP requests, unusual VPN activity, and network telemetry preceding crashes or reloads.
Investigate unexpected firewall restarts or service interruptions, particularly on internet-facing appliances.
Due to the reported active exploitation, organizations should prioritize systems exposed to untrusted networks and those providing remote-access services.
The advisory indicates that no workaround is available. Upgrading to an applicable fixed release is therefore the recommended remediation.
CVE-2026-20349 represents a significant operational risk for organizations using Cisco Secure Firewall ASA or FTD with externally accessible remote-access services.
The combination of unauthenticated remote exploitation, a high CVSS score of 8.6, and reported active exploitation significantly increases the urgency of remediation.
Organizations should immediately identify affected Cisco firewall deployments, review enabled VPN and remote-access services, apply the appropriate hot fixes, and closely monitor firewall telemetry for signs of exploitation or unexpected reload activity.
| Date | 15 August 2026 |
| Severity | High |
| Affected Vendor | Cisco |
| Affected Products |
Cisco Secure Firewall ASA Software Cisco Secure Firewall FTD Software |
| Primary CVE | CVE-2026-20349 |
| CVSS Score | 8.6 (High) |
| Vulnerability Type | Remote Denial of Service |
| Attack Vector | Network |
| Authentication Required | None |
| Exploitation Status | Actively Exploited in the Wild |
| Primary Risks | Denial of Service, Firewall Reload, VPN Disruption, Network Service Interruption |
| Risk Level | High |
| Recommended Action | Immediately apply the applicable Cisco security updates or hot fixes, review internet-facing firewall configurations, restrict unnecessary remote-access exposure, and monitor Cisco ASA and FTD systems for signs of exploitation or unexpected reload activity. |
Multiple vulnerabilities have been identified in SonicWall GMS and SonicWall Email Security products that could allow attackers to execute arbitrary commands or code, escalate privileges, and perform other unauthorized actions on affected systems.
The vulnerabilities include Critical, High, and Medium-severity flaws, with the most serious issues involving unauthenticated command injection and remote code execution in SonicWall GMS.
Organizations using affected SonicWall products should prioritize updating to the latest fixed versions.
Severity: Critical
A command injection vulnerability in the Dispatcher Service could allow an unauthenticated attacker to execute arbitrary commands on an affected SonicWall GMS system.
Severity: Critical
An unauthenticated remote code execution vulnerability could allow attackers to execute arbitrary code on vulnerable SonicWall GMS deployments.
A deserialization vulnerability could allow a local attacker to escalate privileges on an affected SonicWall GMS system.
Weak certificate verification could allow attackers to interfere with or compromise trusted communications under affected conditions.
An authenticated attacker could potentially leverage command injection to execute commands with elevated privileges.
Multiple XSS vulnerabilities could allow malicious scripts to execute within the context of affected SonicWall GMS interfaces.
A command injection vulnerability involving the netmask functionality could allow attackers to execute unauthorized commands.
A command injection vulnerability involving SNMP functionality could allow attackers to execute arbitrary commands on affected systems.
Successful exploitation of these vulnerabilities could allow attackers to:
The presence of unauthenticated command injection and remote code execution vulnerabilities significantly increases the risk to exposed GMS deployments.
| Product | Affected Version | Fixed Version |
|---|---|---|
| Virtual Appliance | 9.5.1 and earlier | 9.5.2 or later |
| Windows | 9.5.1 and earlier | 9.5.2 or later |
| Platform | Affected Version | Fixed Version |
|---|---|---|
| ES Appliance 5000 | 10.0.35.8405 and earlier | 10.0.36 or later |
| ES Appliance 5050 | ||
| ES Appliance 7000 | ||
| ES Appliance 7050 | ||
| ES Appliance 9000 | ||
| VMware | ||
| Hyper-V |
Upgrade SonicWall GMS to 9.5.2 or later.
Upgrade SonicWall Email Security to 10.0.36 or later.
Verify that all instances across virtualized and physical environments have been updated.
Prioritize remediation of CVE-2026-66147 and CVE-2026-66145.
These vulnerabilities involve unauthenticated command injection and remote code execution and represent the highest risk.
Restrict administrative access to trusted networks and review externally accessible SonicWall management interfaces.
Apply least-privilege access controls and review accounts with elevated privileges.
Monitor SonicWall systems for unexpected command execution, unauthorized configuration changes, suspicious authentication activity, unexpected privilege escalation, abnormal network connections, and unusual administrative activity.
The SonicWall vulnerabilities represent a significant security concern because several flaws affect security management and email security infrastructure, while the most severe GMS vulnerabilities can reportedly be exploited without authentication.
Organizations operating affected SonicWall GMS or Email Security versions should conduct an immediate asset and version assessment and prioritize upgrading to the vendor-provided fixed releases.
Particular attention should be given to CVE-2026-66147 and CVE-2026-66145, given their Critical severity and potential for unauthorized command execution or remote code execution.
| Date | 15 August 2026 |
| Severity | Critical |
| Affected Vendor | SonicWall |
| Affected Products |
SonicWall GMS SonicWall Email Security |
| Primary Critical CVEs |
CVE-2026-66147 CVE-2026-66145 |
| Additional CVEs |
CVE-2026-18634 CVE-2026-66154 CVE-2026-66148 CVE-2026-66146 CVE-2026-66149 CVE-2026-66150 |
| Primary Risks | Command Injection, Remote Code Execution, Privilege Escalation, Cross-Site Scripting, System Compromise |
| GMS Affected Version | 9.5.1 and earlier |
| GMS Fixed Version | 9.5.2 or later |
| Email Security Affected Version | 10.0.35.8405 and earlier |
| Email Security Fixed Version | 10.0.36 or later |
| Risk Level | Critical |
| Recommended Action | Immediately upgrade SonicWall GMS to 9.5.2 or later and SonicWall Email Security to 10.0.36 or later. Restrict administrative access, review externally accessible management interfaces, and monitor affected systems for suspicious activity. |
Google has released security updates for the Chrome web browser addressing multiple High-severity use-after-free vulnerabilities affecting key Chrome components, including V8, TabStrip, Extensions, HTML, and Blink.
The vulnerabilities could result in memory corruption, browser crashes, or potentially arbitrary code execution within the context of the affected browser.
Five High-severity vulnerabilities have been addressed in the latest Chrome security update. Organizations and users are strongly advised to update Chrome to the latest fixed versions to reduce exposure to potential exploitation.
Severity: High
A use-after-free vulnerability in the V8 JavaScript engine could potentially result in memory corruption and arbitrary code execution.
Severity: High
A use-after-free vulnerability affecting the TabStrip component could potentially cause browser instability or memory corruption.
Severity: High
A use-after-free vulnerability in the Chrome Extensions component could potentially be exploited to cause memory corruption or browser crashes.
Severity: High
A use-after-free vulnerability affecting HTML processing could potentially lead to memory corruption and security compromise.
Severity: High
A use-after-free vulnerability in the Blink rendering engine could potentially result in memory corruption, crashes, or arbitrary code execution.
Successful exploitation of these vulnerabilities could allow attackers to:
Users accessing untrusted or malicious websites may face increased exposure to browser-based exploitation.
| Platform | Fixed Version |
|---|---|
| Windows | 151.0.7922.137/.138 |
| macOS | 151.0.7922.137/.138 |
| Linux | 151.0.7922.137 |
Upgrade Google Chrome to the latest available fixed version and verify browser versions across managed endpoints.
Prioritize updating systems used to access sensitive business applications.
Use centralized browser management to enforce security updates and restrict access to untrusted websites where appropriate.
Maintain endpoint security controls alongside browser updates and ensure users operate with standard privileges wherever possible.
Monitor endpoint security solutions for suspicious browser activity.
Investigate unexpected Chrome crashes or abnormal browser processes and review security alerts associated with browser exploitation attempts.
The vulnerabilities addressed in the latest Chrome release affect fundamental browser components responsible for JavaScript execution, rendering, extensions, and browser interface functionality .
Although the provided advisory does not report confirmed active exploitation, use-after-free vulnerabilities in browser components can present significant security risks because specially crafted web content may potentially trigger memory corruption.
Organizations should therefore prioritize deployment of the fixed Chrome versions across managed endpoints and maintain centralized browser update controls to reduce exposure to future browser-based attacks.
| Date | 12 August 2026 |
| Severity | High |
| Affected Vendor | |
| Affected Product | Google Chrome |
| Vulnerability Type | Use-After-Free / Memory Corruption |
| Primary CVEs |
CVE-2026-19556 CVE-2026-19557 CVE-2026-19558 CVE-2026-19559 CVE-2026-19560 |
| Primary Risks | Memory Corruption, Browser Crash, Potential Arbitrary Code Execution, Browser-Based Compromise |
| Risk Level | High |
| Recommended Action | Immediately update Google Chrome to the latest fixed version, verify browser versions across enterprise endpoints, enforce centralized browser patching, and monitor endpoints for suspicious browser activity. |
Observed multiple vulnerabilities in NVIDIA NemoClaw and OpenShell that could allow attackers to execute arbitrary code or commands, escape security sandboxes, escalate privileges, disclose sensitive information, tamper with data, expose credentials, or cause denial-of-service conditions.
The vulnerabilities include two Critical-severity flaws in NVIDIA OpenShell for Linux and multiple High-severity vulnerabilities affecting both OpenShell and NemoClaw.
Several issues involve OS command injection, code execution, path traversal, weak or missing authentication, improper certificate validation, and untrusted code execution.
Organizations using NVIDIA NemoClaw or OpenShell should prioritize upgrading to the applicable fixed versions.
The most serious vulnerabilities affect NVIDIA OpenShell for Linux and involve sandbox security boundaries and validation of disallowed input.
Severity: Critical
Product: NVIDIA OpenShell for Linux
A sandbox escape vulnerability could allow an attacker to bypass sandbox security boundaries and potentially execute code outside the intended security environment.
Severity: Critical
Product: NVIDIA OpenShell for Linux
Insufficient validation of disallowed input could allow malicious input to bypass security controls and potentially result in unauthorized actions within the affected environment.
The following High-severity vulnerabilities affect NVIDIA OpenShell and NemoClaw.
Product: NVIDIA OpenShell
An OS command injection vulnerability could allow unauthorized command execution within the affected environment.
Product: NVIDIA OpenShell Sandbox
A path traversal vulnerability could allow unauthorized access to files or resources outside intended sandbox boundaries.
Product: NVIDIA NemoClaw
Weak authentication controls could potentially allow unauthorized access to affected NemoClaw functionality.
Product: NVIDIA NemoClaw
The vulnerability could allow execution of untrusted code within affected NemoClaw components.
Product: NVIDIA NemoClaw
Improper certificate validation could weaken trust relationships and potentially allow malicious or untrusted endpoints to be accepted.
Product: NVIDIA NemoClaw Inference Server
Missing authentication controls could allow unauthorized users or systems to interact with affected inference-server functionality.
Product: NVIDIA NemoClaw Telegram Bridge
An OS command injection vulnerability could allow unauthorized command execution through the affected Telegram Bridge component.
Product: NVIDIA NemoClaw CLI
The vulnerability could allow unauthorized command execution through the affected NemoClaw CLI functionality.
Product: NVIDIA NemoClaw NIM Management
An OS command injection vulnerability could allow attackers to execute unauthorized commands through affected NIM management functionality.
Product: NVIDIA NemoClaw Status and Logs Plugins
The vulnerability could allow unauthorized command execution through affected status and logging plugins.
Product: NVIDIA NemoClaw Installation Scripts
The vulnerability could result in the download or execution of untrusted code through affected installation scripts.
Product: NVIDIA NemoClaw Migration Command
A code injection vulnerability could allow malicious input to result in unauthorized code execution through the affected migration command.
Product: NVIDIA OpenShell Sandbox Exec Handler
Product: NVIDIA NemoClaw
Product: NVIDIA NemoClaw
Product: NVIDIA OpenShell
Successful exploitation could result in:
The combination of sandbox escape, command injection, authentication weaknesses, and untrusted code execution vulnerabilities presents a significant risk to environments using these technologies.
| Version | Fixed Commit |
|---|---|
| 0.0.1 | 156c9a201, a46160697, b7c254114 |
| 0.0.3 | 800195b55 |
| 0.0.4 | 5864d9751 |
| 0.0.17 | 7983fc7d1 |
| 0.0.21 | 48c0d54d4, 11af5fdac |
| 0.0.25 | f06796ff3 |
| Product | Fixed Version |
|---|---|
| NVIDIA OpenShell | v0.0.34 |
Organizations should verify the specific component and version deployed before applying the appropriate update.
Update NVIDIA NemoClaw to the applicable fixed release and upgrade NVIDIA OpenShell to v0.0.34.
Review OpenShell sandbox configurations and access controls to ensure that untrusted workloads cannot bypass intended isolation boundaries.
Limit access to NemoClaw and OpenShell management interfaces, CLIs, inference services, and associated plugins to authorized users and trusted networks.
Because one of the vulnerabilities involves insufficiently protected credentials, organizations should review credentials stored or processed by NemoClaw and rotate potentially exposed credentials where appropriate.
Monitor logs and security telemetry for:
Review NemoClaw integrations, installation scripts, migration commands, Telegram bridges, NIM management components, and status/logging plugins to determine whether vulnerable functionality is deployed.
The vulnerabilities affecting NVIDIA NemoClaw and OpenShell represent a significant security concern due to the presence of Critical sandbox escape and input-validation flaws, combined with multiple High-severity vulnerabilities involving command injection, code execution, authentication weaknesses, path traversal, and untrusted code.
Organizations using these technologies should identify affected deployments and apply the applicable NVIDIA security updates immediately.
Recommended Action: Upgrade affected NVIDIA NemoClaw and OpenShell deployments immediately and review sandbox, authentication, credential, and administrative access controls.
| Date | 30 August 2026 |
| Vendor | NVIDIA |
| Affected Products | NVIDIA NemoClaw / NVIDIA OpenShell |
| Severity | Critical / High / Medium |
| Critical Vulnerabilities | CVE-2026-65093, CVE-2026-65083 |
| Primary Risks | Sandbox Escape, Code Execution, Command Injection, Authentication Weaknesses, Path Traversal, Information Disclosure |
| OpenShell Fixed Version | v0.0.34 |
| Risk Level | Critical |
| Recommended Action | Upgrade affected NVIDIA deployments immediately and review security configurations and credentials. |
A newly disclosed zero-day vulnerability, known as FalconFlank, reportedly affects the CrowdStrike Falcon Sensor for Windows. The vulnerability targets Falcon's Microsoft Office malicious and suspicious macro remediation functionality and may allow a locally authenticated attacker with an existing foothold to escalate privileges to NT AUTHORITY\SYSTEM.
According to the reported proof of concept, exploitation has been demonstrated against fully updated Windows 11 25H2 and Windows Server 2025 systems running CrowdStrike Falcon.
CrowdStrike is investigating the reported vulnerability and has issued interim mitigation guidance for customers. CrowdStrike has advised customers to disable the Microsoft Office File Suspicious Macro Removal Windows policy setting while keeping Cloud Anti-malware for Microsoft Office Files enabled. :contentReference[oaicite:1]{index=1}
Endpoint security software operates with highly privileged access. Abuse of a security product's remediation mechanism could potentially allow an attacker who already has local execution to obtain SYSTEM-level privileges and further compromise the endpoint.
| Threat | FalconFlank |
|---|---|
| Threat Level | HIGH |
| Threat Type | Local Privilege Escalation |
| Affected Technology | CrowdStrike Falcon Sensor for Windows |
| Vulnerability | FalconFlank |
| CVE | Not assigned at the time of reporting |
| Reported Impact | Privilege escalation to NT AUTHORITY\SYSTEM |
| Initial Access Requirement | Existing local code execution or foothold |
| Remote Exploitation | Not reported as a remote unauthenticated vulnerability |
INITIAL FOOTHOLD > LOCAL CODE EXECUTION > ABUSE FALCON MACRO REMEDIATION > PRIVILEGE ESCALATION > SYSTEM-LEVEL EXECUTION
This is not reported as a remote unauthenticated vulnerability. An attacker would generally require an existing foothold or the ability to execute code locally before attempting to exploit the privilege escalation technique.
However, if successfully exploited, FalconFlank could significantly increase the impact of an existing endpoint compromise by allowing an attacker to transition from lower-privileged execution to SYSTEM-level access.
The reported attack requires local execution on the affected Windows endpoint. It should therefore not be characterized as a direct Internet-facing remote compromise.
Successful exploitation could allow an attacker to:
The elevated privileges associated with endpoint security software make vulnerabilities in remediation and protection mechanisms particularly sensitive.
Based on CrowdStrike's current guidance, temporarily disable the Microsoft Office File Suspicious Macro Removal Windows policy setting.
The setting can be found under:
Falcon Console > Next-Gen Antivirus > Clean Infected Microsoft Office Files
This is the specific functionality identified in the current mitigation guidance. :contentReference[oaicite:2]{index=2}
Do not disable the Cloud Anti-malware for Microsoft Office Files setting.
CrowdStrike has stated that customers remain protected through this capability when the suspicious macro removal functionality is disabled. :contentReference[oaicite:3]{index=3}
Verify that Falcon prevention policies are configured according to CrowdStrike's recommended best practices.
Security teams should ensure that disabling the affected remediation functionality does not result in broader security policy gaps across protected endpoints.
As an additional compensating control, organizations should strengthen Microsoft Office macro restrictions through Group Policy, including:
SOC teams should investigate unusual activity involving Falcon Sensor processes, particularly:
Endpoint telemetry should be correlated with Windows security events, process creation logs and EDR telemetry.
Organizations should continuously monitor the FalconFlank Tech Alert available through the CrowdStrike Support Portal.
Do not re-enable the affected macro removal setting solely because the initial mitigation has been applied.
The setting should only be restored after CrowdStrike confirms that an appropriate sensor-side fix or remediation is available and has been deployed.
Security operations teams should prioritize hunting for indicators associated with post-compromise privilege escalation.
| Hunting Area | What to Investigate |
|---|---|
| Process Creation | Unexpected command shells or scripting engines spawned from Falcon-related processes. |
| Privilege Escalation | Low-privileged users spawning SYSTEM-level processes. |
| DLL Activity | Unexpected or unsigned DLL loads associated with Falcon processes. |
| Office Activity | Suspicious Office documents followed by unusual process execution. |
| Persistence | New services, scheduled tasks, registry Run keys or startup modifications. |
| Endpoint Tampering | Attempts to disable, modify or interfere with security controls. |
| Lateral Movement | Suspicious authentication or remote execution following local privilege escalation. |
FalconFlank presents a significant risk because the affected functionality belongs to an endpoint security platform operating with elevated privileges.
The primary risk is post-compromise privilege escalation. An attacker would generally need local code execution or an existing foothold before attempting exploitation.
The vulnerability should therefore not be characterized as a direct Internet-facing remote compromise.
Nevertheless, successful exploitation could transform a lower-privileged foothold into SYSTEM-level access, substantially increasing an attacker's ability to disable defenses, access sensitive resources, establish persistence and conduct further post-exploitation activity.
The reported availability of a public proof of concept further increases the urgency for organizations operating CrowdStrike Falcon on Windows endpoints. :contentReference[oaicite:4]{index=4}
Organizations operating CrowdStrike Falcon Sensor for Windows should treat FalconFlank as a high-priority endpoint security issue.
While exploitation requires local execution or an existing foothold, successful exploitation could provide an attacker with NT AUTHORITY\SYSTEM privileges and materially increase the impact of an existing compromise.
Until a permanent vendor-side remediation is confirmed, organizations should implement the recommended mitigation, maintain compensating Microsoft Office controls, and closely monitor endpoints for abnormal privilege escalation and security-control tampering.
Priority: Immediate review and mitigation for organizations using CrowdStrike Falcon Sensor for Windows.
| Threat Level | HIGH |
|---|---|
| Attack Type | Local Privilege Escalation |
| Target | CrowdStrike Falcon Sensor for Windows |
| Required Access | Local code execution or existing foothold |
| Privilege Obtained | NT AUTHORITY\SYSTEM |
| CVE | Not assigned |
| Public PoC | Reported |
| Primary Mitigation | Disable Microsoft Office File Suspicious Macro Removal |
| Compensating Protection | Keep Cloud Anti-malware for Microsoft Office Files enabled |
| Recommended Priority | Immediate |
FalconFlank represents a significant security concern because it targets a privileged endpoint security remediation mechanism. Although the reported exploitation requires local execution, successful exploitation could elevate an attacker to NT AUTHORITY\SYSTEM.
Organizations should prioritize the vendor-recommended mitigation, maintain cloud-based Office anti-malware protection, review Falcon prevention policies and increase monitoring for suspicious process execution and privilege escalation.
Security teams should continue monitoring CrowdStrike's FalconFlank guidance for updates and should restore the affected macro-remediation functionality only after the vendor confirms that the issue has been appropriately addressed.
Immediate mitigation and SOC monitoring are recommended for organizations running CrowdStrike Falcon Sensor on Windows endpoints.
Observed that Apple has released security updates addressing multiple vulnerabilities across iOS, iPadOS, macOS, and visionOS platforms.
The vulnerabilities affect multiple Apple components and could allow attackers or malicious applications to cause denial-of-service conditions, disclose sensitive information, bypass security protections, corrupt memory, or execute arbitrary code.
Organizations and users are strongly advised to install the latest Apple security updates to reduce exposure to potential attacks.
Apple security updates address vulnerabilities across multiple system components, including:
Impact: Arbitrary Code Execution
Processing a specially crafted image may trigger an integer overflow condition, potentially allowing attackers to execute arbitrary code on affected systems.
Impact: Application Termination / Arbitrary Code Execution
Processing a maliciously crafted file may result in unexpected application termination or allow arbitrary code execution.
Impact: Application Termination / Arbitrary Code Execution
Multiple vulnerabilities affecting SceneKit could allow maliciously crafted files to trigger application crashes or execute arbitrary code.
Multiple vulnerabilities affecting Apple components including ImageIO, IOGPUFamily, Kernel, WebKit, and WebRTC could result in:
Apple has addressed vulnerabilities that could allow:
| Product | Fixed Version |
|---|---|
| iOS | 26.6.1 |
| iPadOS | 26.6.1 |
| iOS | 18.7.10 |
| iPadOS | 18.7.10 |
| macOS Tahoe | 26.6.2 |
| visionOS | 26.6.1 |
Install the latest Apple security updates across affected devices and verify update deployment across enterprise-managed systems.
Enable automatic updates, enforce timely patching through Mobile Device Management policies, and restrict untrusted applications.
Monitor unexpected application crashes, unusual device behaviour, suspicious application activity, and unauthorized access attempts.
The latest Apple security updates address multiple vulnerabilities affecting core operating system components and application frameworks.
Vulnerabilities involving arbitrary code execution, memory corruption, information disclosure, and security bypass highlight the importance of timely patch deployment across enterprise Apple environments.
Organizations should prioritize updating affected Apple devices, especially those accessing sensitive corporate resources or handling confidential information.
| Date | 18 August 2026 |
| Vendor | Apple |
| Severity | Critical |
| Affected Platforms | iOS, iPadOS, macOS, visionOS |
| Primary Risks | Code Execution, Memory Corruption, Information Disclosure, Security Bypass |
| Recommended Action | Apply latest Apple security updates immediately. |
Observed that OpenSSL has released security updates addressing multiple vulnerabilities affecting QUIC, CMS, CMP, DTLS, RPK, and cryptographic functionality.
The vulnerabilities range from Moderate to Low severity and could result in denial-of-service conditions, heap corruption, memory exhaustion, application crashes, or acceptance of forged messages under specific conditions.
Organizations using OpenSSL should review their deployments and upgrade to the applicable fixed versions released by OpenSSL.
The OpenSSL security updates address vulnerabilities affecting several cryptographic, networking, and protocol-processing components.
Severity: Moderate
A malformed QUIC packet can trigger a double-free condition, potentially resulting in heap corruption and denial-of-service.
Severity: Moderate
A specially crafted CMS message can cause an out-of-bounds heap write during key unwrapping, potentially resulting in denial-of-service.
Severity: Moderate
A specially crafted CMP message can trigger an invalid pointer dereference, potentially causing the affected application to crash.
A specific RPK configuration can trigger a null pointer dereference, potentially resulting in denial-of-service.
Crafted DTLS traffic can cause excessive memory consumption, potentially resulting in denial-of-service.
A malicious CMP endpoint can cause a client application to crash through a specially crafted sender name.
Repeated CMP requests can result in unbounded memory growth, potentially causing denial-of-service.
A remote QUIC peer can cause excessive memory retention, potentially resulting in denial-of-service.
Under specific conditions, authentication tags may not be verified for empty ciphertext, potentially allowing forged messages to be accepted.
Successful exploitation of the vulnerabilities could allow attackers to:
The impact depends on the OpenSSL functionality enabled and the specific configuration of the affected deployment.
| OpenSSL Branch | Fixed Version |
|---|---|
| OpenSSL 4.0 | 4.0.2 |
| OpenSSL 3.6 | 3.6.4 |
| OpenSSL 3.5 | 3.5.8 |
| OpenSSL 3.4 | 3.4.7 |
| OpenSSL 3.0 | 3.0.22 |
| OpenSSL 1.1.1 | 1.1.1zi |
| OpenSSL 1.0.2 | 1.0.2zr |
Organizations should identify the OpenSSL branch currently deployed and apply the corresponding fixed release.
Update affected OpenSSL installations to the latest applicable fixed version released by OpenSSL.
Review applications, servers, appliances, containers, and embedded systems that use OpenSSL directly or through third-party software.
Give priority to systems exposed to untrusted network traffic, particularly deployments using QUIC, DTLS, CMP, or other affected functionality.
Monitor security and application logs for:
After applying updates, verify that affected applications continue to operate correctly and that the updated OpenSSL library is being loaded rather than an older vulnerable version.
The OpenSSL security updates address multiple vulnerabilities across widely used cryptographic and networking components.
While the majority are rated Low or Moderate severity, certain flaws can cause heap corruption, memory exhaustion, or denial-of-service.
In addition, CVE-2026-75803 may allow forged messages to be accepted under specific conditions where authentication tags are not verified for empty ciphertext.
The overall risk depends on the OpenSSL functionality enabled and the configuration of the affected deployment.
Recommended Action: Identify affected OpenSSL deployments and upgrade to the applicable fixed versions.
| Date | 28 August 2026 |
| Vendor | OpenSSL |
| Severity Range | Moderate / Low |
| Primary Risks | Denial of Service, Heap Corruption, Memory Exhaustion, Application Crashes, Authentication Bypass |
| Affected Components | QUIC, CMS, CMP, DTLS, RPK, AEAD Cryptographic Functionality |
| Notable Authentication Issue | CVE-2026-75803 |
| Overall Risk | Moderate to High depending on deployment and enabled functionality |
| Recommended Action | Upgrade affected OpenSSL deployments to the applicable fixed releases. |
Jenkins has addressed multiple vulnerabilities affecting Jenkins Core and several associated plugins that could allow attackers to compromise affected systems, execute arbitrary code, access sensitive information, escalate privileges, create or modify files, and disrupt CI/CD operations.
The most severe issue, CVE-2026-70426, is a Critical agent-to-controller deserialization filter bypass that could allow code execution on the Jenkins controller.
Several additional High-severity vulnerabilities affect Jenkins and its plugins, including arbitrary file creation, path traversal, privilege escalation, arbitrary code execution, stored cross-site scripting (XSS), and XML External Entity (XXE) vulnerabilities.
| Attribute | Details |
|---|---|
| CVE | CVE-2026-70426 |
| Severity | Critical |
| Vulnerability | Agent-to-controller deserialization filter bypass |
| Impact | Potential code execution on Jenkins controller |
The vulnerability could allow an attacker to bypass deserialization filtering between a Jenkins agent and controller, potentially resulting in arbitrary code execution on the Jenkins controller.
| CVE | Vulnerability | Potential Impact |
|---|---|---|
| CVE-2026-70427 | Link Following Vulnerability | Arbitrary file creation |
| CVE-2026-70428 | Path Traversal | Unauthorized file access through malicious file parameters |
| CVE-2026-70429 | Improper Case Sensitivity Handling | Privilege escalation |
|
CVE-2026-70431 CVE-2026-70432 |
Multijob Plugin Arbitrary Code Execution | Arbitrary code execution |
|
CVE-2026-70440 CVE-2026-70441 |
Stored Cross-Site Scripting | Malicious script execution within affected interfaces |
| CVE-2026-70448 | Ivy Report Plugin XXE | Potential access to sensitive information or internal resources |
| CVE | Security Issue |
|---|---|
| CVE-2026-70433 | Missing permission checks |
| CVE-2026-70434 | Cross-Site Request Forgery |
| CVE-2026-70435 | Credential exposure |
| CVE-2026-70436 | Unauthorized access to sensitive information |
| CVE-2026-70438 | Security control weakness |
| CVE-2026-70439 | Security control weakness |
| CVE-2026-70442 | Missing permission checks |
| CVE-2026-70443 | Credential exposure |
| CVE-2026-70444 | Unauthorized information access |
| CVE-2026-70445 | Missing permission checks |
| CVE-2026-70446 | Cross-Site Request Forgery |
| CVE-2026-70447 | Credential exposure / information disclosure |
| CVE | Issue |
|---|---|
| CVE-2026-70430 | Improper restrictions on object instantiation |
| CVE-2026-70437 | Non-constant-time webhook bearer token comparison |
| Component | Affected Version | Fixed Version |
|---|---|---|
| Jenkins Weekly | 2.575 and earlier | 2.576 |
| Jenkins LTS | 2.568.1 and earlier | 2.568.2 |
| Plugin | Affected Version |
|---|---|
| AWS CodeBuild Plugin | ≤ 0.59 |
| CodeSonar Plugin | ≤ 3.6.0 |
| External Workspace Manager Plugin | ≤ 1.4.1 |
| Google Chat Notification Plugin | ≤ 166.ve6b_de280f2e8 |
| HCL AppScan Plugin | ≤ 1.8.3 |
| Horreum Plugin | ≤ 0.16.162.v33b_4a_a_b_5f828 |
| Ivy Report Plugin | ≤ 1.2 |
| Multijob Plugin | ≤ 669.v9d96a_d9c71b_0 |
| Parameterized Remote Trigger Plugin | ≤ 3.2.2 |
| Qualys Container Scanning Connector Plugin | ≤ 1.8.0.5 |
| Sauce OnDemand Plugin | ≤ 2.2.0 |
| SCM-Manager Plugin | ≤ 1.11.1 |
| Summary Display Plugin | ≤ 1.15 |
| Violation Comments to GitLab Plugin | ≤ 2.62.0 |
| Webhook Secret Credentials Provider Plugin | ≤ 16.v0cfa_f0215cf5 |
| XML Job to Job DSL Plugin | ≤ 0.1.13 |
| Plugin | Fixed Version |
|---|---|
| External Workspace Manager Plugin | 1.4.2 |
| HCL AppScan Plugin | 1.8.4 |
| Multijob Plugin | 677.v7ffc23d6a_4c2 |
| SCM-Manager Plugin | 1.12.1 |
| Webhook Secret Credentials Provider Plugin | 32.v09c9b_522f0a_8 |
Organizations using these plugins should consider removing or disabling them until security updates become available.
Upgrade Jenkins Weekly installations to 2.576 and Jenkins LTS installations to 2.568.2. Verify that security updates are successfully deployed across all Jenkins environments.
Update affected plugins to their fixed versions where available. Identify plugins without security fixes and disable or remove them where operationally feasible.
Restrict access to Jenkins controllers and administrative interfaces. Limit agent-to-controller communication to trusted systems and enforce least-privilege permissions.
Review Jenkins authentication and audit logs, investigate unexpected administrative activity, monitor pipeline and job modifications, and review unexpected file creation or changes.
Review Jenkins credentials and rotate potentially exposed secrets following remediation, particularly if there is evidence of unauthorized access or controller compromise.
The Critical CVE-2026-70426 presents a significant risk because exploitation could result in code execution on the Jenkins controller. Given the privileged role Jenkins typically plays in CI/CD environments, compromise of a controller could expose credentials, source code, build infrastructure, and deployment environments.
The presence of multiple additional vulnerabilities across Jenkins plugins further increases the attack surface. Organizations should therefore treat this advisory as a high-priority CI/CD security update, particularly where Jenkins is accessible from untrusted networks.
| Date | 10 August 2026 |
| Severity | Critical |
| Affected Vendor | Jenkins |
| Primary CVE | CVE-2026-70426 |
| Primary Risk | Agent-to-Controller Deserialization Filter Bypass |
| Primary Impact | Potential Jenkins Controller Code Execution |
| Jenkins Weekly Fixed | 2.576 |
| Jenkins LTS Fixed | 2.568.2 |
| Additional Risks | Arbitrary File Creation, Path Traversal, Privilege Escalation, RCE, Stored XSS, XXE, CSRF, Credential Exposure |
| Risk Level | Critical |