π¨ ACTIVE EXPLOITS & INCIDENTS
- US charges alleged operators of Russian bulletproof hosting service β BleepingComputer
U.S. prosecutors charged three Russian nationals running a bulletproof hosting (BPH) service that supported ransomware gangs responsible for over $62M in global damages. This takedown disrupts a critical infrastructure node enabling ransomware operations.
π VULNERABILITIES & CVEs
-
CVE-2026-15583: SSRF (confused deputy) in Grafana MCP Server β CVE ThreatInt
Unauthenticated remote attackers can exploit a confused-deputy SSRF flaw via theX-Grafana-URLheader to exfiltrate environment-configured Grafana service-account tokens. This allows potential privilege escalation and lateral movement in compromised environments. Patch or mitigate immediately. -
CVE-2026-15804: SQL Injection in MetaGuru HCM β CVE ThreatInt
Authenticated remote attackers can inject SQL commands through specific parameters, risking data confidentiality and integrity. Affects MetaGuruβs Human Capital Management software. Prioritize patching and review database access controls. -
CVE-2026-14251: Missing allowednamespace check in OpenShift GitOps operator β CVE ThreatInt
Namespace-scoped Argo CD instances can trigger unauthorized reconciliation of ClusterRole objects due to lack of ownership validation, enabling privilege escalation within Kubernetes clusters. Critical for organizations using OpenShift GitOps to apply fixes or implement compensating controls.
π VENDOR BULLETINS & ADVISORIES
- Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates β SecurityWeek
Google Chrome 150 and Firefox 152 address multiple critical vulnerabilities, including publicly available exploit code for Firefox flaws (no in-the-wild exploitation reported yet). Immediate patching recommended to close attack vectors.
π° LESSER-KNOWN / UNDER-REPORTED
- Nigeria Deepens Cybersecurity Efforts as Cybercriminals See More Profits β Dark Reading
Nigeria introduces mandatory cyberattack disclosure rules, aligning with global trends toward transparency. This regulatory shift may increase visibility into regional cybercrime trends and improve incident response collaboration.