View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Critical Gitea auth bypass under active exploitation

🚨 ACTIVE EXPLOITS & INCIDENTS

  • Critical Gitea Flaw Under Active ExploitationSecurityWeek Attackers are actively exploiting CVE-2026-20896, a critical Gitea authentication bypass vulnerability (CVSS 9.8) that allows unauthorized access to repositories and secrets via a single HTTP header. Immediate patching is strongly advised to prevent compromise of source code and credentials.
  • Chinese Hackers Develop LONGLEASH Malware to Expand ORB NetworkBleepingComputer Chinese threat group UAT-7810 is evolving LONGLEASH malware to compromise unpatched internet-facing Ruckus routers, expanding their Operational Relay Box (ORB) network for stealthy command and control. Network device hardening and patching are critical to disrupt this active campaign.
  • Continued Exploitation of Cisco Catalyst SD-WAN Vulnerabilities (CVE-2026-20182)Tenable Multiple critical authentication bypass flaws in Cisco Catalyst SD-WAN Controller/Manager (CVSS 10.0) are under active exploitation by sophisticated threat actor UAT-8616 and others. Patches are available; urgent remediation is mandated by CISA to prevent full network compromise.
  • County Government Paid $1 Million Ransom to Cyber Extortion GroupSecurityWeek A small Ohio county reportedly paid $1M to prevent public release of stolen sensitive data. This incident underscores the ongoing risk of ransomware/extortion impacting local governments and the importance of incident response readiness.

🔓 VULNERABILITIES & CVEs

  • CVE-2026-9082: Highly Critical SQL Injection in Drupal CoreTenable A critical SQL injection (CVSS 9.8) affects Drupal core’s database abstraction layer on PostgreSQL sites, exploitable by unauthenticated attackers. Exploitation attempts observed; patches available across six supported branches. Immediate patching required for affected Drupal deployments.
  • Dirty Frag Linux Kernel Privilege Escalation (CVE-2026-43284, CVE-2026-43500)Tenable A chained local privilege escalation vulnerability with public exploit code targets Linux kernels, enabling root access. Patches forthcoming; affected systems should apply updates promptly and monitor for exploitation attempts.
  • Fragnesia (CVE-2026-46300): New Linux Kernel Privilege EscalationTenable A new local privilege escalation exploit with public PoC affects the Linux kernel’s XFRM ESP-in-TCP subsystem. Patch released May 13; existing Dirty Frag patches do not cover this flaw. Ubuntu systems confirmed vulnerable; immediate patching recommended.

🕵️ THREAT RESEARCH & DEEP DIVES

  • Mini Shai-Hulud: Self-Propagating Supply Chain Worm in npm & PyPITenable TeamPCP’s Mini Shai-Hulud worm compromised 170+ npm and PyPI packages, bypassing SLSA Build Level 3 provenance attestations and stealing developer/cloud credentials, including from OpenAI and Mistral AI. Any system installing affected packages should be treated as fully compromised.
  • Verizon DBIR 2026: Vulnerability Exploitation Surges as Patch Times LagTenable Vulnerability exploitation is now the top initial access vector (31% of breaches), while median patch times increased by 11 days year-over-year. AI-powered discovery accelerates exploit availability, emphasizing the need for continuous exposure management and automated remediation.
  • RedWing MaaS: Android Bank Fraud Offered as Telegram Rental ServiceThe Hacker News RedWing, a new Android malware-as-a-service, enables low-skill criminals to hijack phones, steal banking credentials, and intercept OTPs. Resembling the Oblivion malware, it rents for ~$300/month on Telegram, lowering the barrier for mobile banking fraud.
  • Rogue Agent Flaw in Google Dialogflow CX Could Hijack ChatbotsThe Hacker News A critical flaw allows attackers with edit rights on one Code Block-enabled Dialogflow CX agent to compromise others in the same Google Cloud project, reading live conversations and injecting malicious messages. Fixes have been deployed; review permissions and patch immediately.

📋 VENDOR BULLETINS & ADVISORIES

  • Microsoft June 2026 Patch Tuesday: 198 CVEs, Including 3 Zero-DaysTenable Largest Patch Tuesday ever with 198 CVEs fixed (32 critical), including three zero-days. Key patches cover .NET, ASP.NET Core, Active Directory, Azure services, and Copilot Chat. Immediate deployment advised to mitigate active threats.
  • Oracle June 2026 CSPU: 243 CVEs, 122 CriticalTenable Oracle’s June CSPU delivers 245 patches addressing 243 CVEs, nearly half critical. Fusion Middleware is heavily impacted (106 patches). Organizations should prioritize patching to reduce exposure.
  • AWS Enforces Zero Data Retention on Amazon BedrockAWS Security Blog Amazon Bedrock introduces controls to enforce zero data retention on AI inference requests, critical for compliance when using third-party AI models like Claude Fable 5. Security teams should review and apply service control policies accordingly.

📰 LESSER-KNOWN / UNDER-REPORTED

  • Hidden Backdoor in Tenda Router Firmware Grants Admin AccessBleepingComputer Multiple Tenda router firmware versions contain a hidden authentication backdoor allowing attackers admin web panel access. Given widespread deployment, affected devices should be updated or isolated to prevent compromise.
  • More Odd DNS Records: NIMLOCSANS ISC Technical deep dive into NIMLOC DNS records, an uncommon but significant DNS record type observed in logs. Useful for SOC analysts monitoring unusual DNS activity or investigating RCS-related infrastructure.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check