View Ridge Security
Back to Cyber HoseActive Exploits & Incidents

Two Men Indicted for ATM Jackpotting Scheme in Nevada

🚨 ACTIVE EXPLOITS & INCIDENTS

  • Two Men Indicted for ATM Jackpotting Scheme in Nevada @metacurity
    A federal grand jury indicted two individuals for orchestrating a jackpotting scheme targeting multiple ATMs in Reno and Sparks, Nevada. The attack involved physical compromise of ATM hardware to steal cash, highlighting ongoing risks to financial infrastructure from hardware-level attacks.

  • US Air Force Cybersecurity Lockouts Disrupt Operations @metacurity
    Rolling cybersecurity quarantines have locked out numerous Air Force personnel and civilians from their systems for days, indicating a significant internal incident or aggressive containment measures. This disruption underscores potential operational impacts from defensive cyber controls or ongoing incident response.

📋 VENDOR BULLETINS & ADVISORIES

🔓 VULNERABILITIES & CVEs

  • <https://cve.threatint.eu/CVE/CVE-2026-59235?utm_campaign=info&utm_medium=rss&utm_source=website%7CCVE-2026-59235: Missing Authorization in Prospero Flow CRM (<5.5.3)> CVE ThreatInt
    A missing authorization flaw in Prospero Flow CRM’s BankAccountListController allows low-privileged users to access sensitive bank account data via GET /api/bank-account. Urgent upgrade to version 5.5.3 or later is recommended to prevent unauthorized data access.

  • CVE-2026-40633: Sensitive Information Insertion into Logs in Dell PowerScale OneFS (9.5.0.0 - 9.13.0.2) CVE ThreatInt
    Dell PowerScale OneFS contains a vulnerability where low-privileged attackers can insert sensitive information into log files, potentially leading to information leakage or log poisoning. Affected versions span 9.5.0.0 through 9.13.0.2. Patch or mitigate accordingly.

  • CVE-2026-49501: Improper Privilege Management in Dell PowerScale OneFS (9.5.0.0 - 9.13.0.2) CVE ThreatInt
    An improper privilege management vulnerability in Dell PowerScale OneFS allows high-privileged local attackers to escalate privileges or perform unauthorized actions. Versions 9.5.0.0 through 9.13.0.2 are affected. Immediate patching is critical.

  • CVE-2026-57821: SQL Injection in Apache Fineract Office Search API (≤1.14.0) CVE ThreatInt
    A SQL injection vulnerability exists in Apache Fineract’s Office Search API via the orderBy parameter, allowing attackers to manipulate database queries. Versions up to 1.14.0 are vulnerable. Apply updates or mitigations to prevent data exfiltration or database compromise.

  • CVE-2026-35152: SQL Injection in Apache Fineract Report Execution API (≤1.14.0) CVE ThreatInt
    The runreports endpoint in Apache Fineract is vulnerable to SQL injection through report parameter values, impacting versions up to 1.14.0. This flaw can lead to unauthorized data access or modification. Patch or apply input validation controls immediately.

  • CVE-2026-56287: Boolean-Based SQL Injection in Apache Fineract Client Search API (≤1.14.0) CVE ThreatInt
    Boolean-based SQL injection exists in the Client Search API’s orderBy and sortOrder parameters in Apache Fineract versions up to 1.14.0. Exploitation risks include data leakage and unauthorized query manipulation. Urgent remediation required.

🕵️ THREAT RESEARCH & DEEP DIVES

  • Fourier Pixels: New Dual-Function Video Screen and Camera Technology Schneier on Security
    Researchers at ETH Zurich developed “Fourier pixels” capable of simultaneously displaying and sensing light fields, effectively combining screen and camera functions in one pixel. This breakthrough raises new privacy and surveillance concerns reminiscent of Orwellian “telescreens,” potentially expanding attack surfaces in visual tech.

📰 LESSER-KNOWN / UNDER-REPORTED

  • US Charges Russian Individuals and Firms for Cybercrime Services SecurityWeek
    The US has formally charged Russian nationals and companies previously sanctioned for operating cybercrime services. This legal action underscores ongoing international efforts to disrupt state-linked cybercriminal ecosystems enabling ransomware and fraud operations.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check