๐จ Active Exploits & Incidents
- Trend Micro Apex One Zero-Day (CVE-2026-34926) โ Exploited in the Wild
Directory traversal flaw in on-premise Apex One actively exploited in the wild. CISA added to KEV catalog. Patch immediately โ no workaround available.
[BleepingComputer / SecurityWeek] - Drupal Critical SQL Injection โ Active Exploitation Underway
Highly critical SQL injection flaw disclosed earlier this week is now being actively targeted. Unpatched Drupal sites should be treated as compromised.
[BleepingComputer] - CISA KEV: Langflow CVE-2025-34291 (CVSS 9.4) Added
Origin validation error in Langflow AI workflow builder added to KEV. If you run Langflow in any environment, treat this as urgent.
[The Hacker News]
๐ Vulnerabilities & CVEs
- Cisco Secure Workload REST API โ CVSS 10.0 (CVE-2026-20223)
Unauthenticated remote attacker can access sensitive data via insufficient validation on REST API endpoints. Maximum severity โ patch or isolate immediately.
[The Hacker News] - Ubiquiti UniFi OS โ Three Max-Severity RCE Flaws
Three CVSS 10.0 vulnerabilities patched in UniFi OS, all exploitable remotely without credentials. High exposure given UniFi prevalence in SMB and enterprise networks.
[BleepingComputer] - Unpatched Chromium RCE โ Google Accidentally Leaked the Details
Google inadvertently disclosed an unfixed bug allowing JavaScript to persist after browser close, enabling RCE. No patch yet โ details are now public.
[BleepingComputer]
๐ต๏ธ Threat Research & Deep Dives
- Megalodon: Automated Supply Chain Attack Hits 5,561 GitHub Repos
Attackers using throwaway accounts with forged CI bot identities pushed 5,718 malicious commits injecting base64-encoded bash payloads into GitHub Actions workflows to exfiltrate CI/CD secrets.
[The Hacker News] - BYOVD Deep Dive: Hardware-Gated Kernel Drivers Exploitable Without the Hardware
Technical analysis of how Windows kernel-mode drivers can be reached from user mode without the target hardware present โ directly relevant to BYOVD attack chains.
[The Hacker News] - Grafana Codebase Stolen via TanStack Supply Chain Attack
Grafana confirms attackers accessed GitHub repos after a token compromised in the TanStack attack was not rotated โ a cascading supply chain failure.
[SecurityWeek] - SANS ISC: Cross-Platform NPM Stealer โ Static Analysis
Handler diary on a heavily obfuscated Node.js stealer (SHA256: 049300aa...ddeb9). Didn't execute cleanly in sandbox โ static analysis only. Watch for variants.
[SANS ISC]
๐ Vendor Bulletins & Law Enforcement
- Kimwolf Botnet Admin Arrested โ 23-Year-Old Ottawa Man Charged
Jacob Butler (aka Dort) arrested for operating the Kimwolf IoT DDoS botnet (~2M infected devices, AISURU variant). Krebs had previously named him after he launched DDoS/doxing/swatting attacks against researchers.
[Krebs / SecurityWeek / THN] - First VPN Cybercrime Service Disrupted โ Used by Dozens of Ransomware Groups
FBI disrupted First VPN, used by ransomware operators for network reconnaissance and initial access. Administrator arrested.
[SecurityWeek]
๐ฐ Lesser-Known / Under-Reported
- CISA Contractor Exposed AWS GovCloud Credentials on Public GitHub
A CISA contractor's public GitHub repo contained credentials to highly privileged AWS GovCloud accounts plus internal CISA build/test/deploy pipeline details. Schneier: "one of the most egregious government data leaks in recent history."
[Schneier on Security] - Industrial Router Exploitation + Gas Station Hacking โ Under-Radar Roundup
Huawei industrial router flaw triggered a telecom blackout; gas station POS hacking research published; CISA launches public KEV nomination form.
[SecurityWeek]โฑ Hourly updates run 6amโmidnight PT ยท Next automated update at the top of the next hour Sent using Manus