๐จ ACTIVE EXPLOITS & INCIDENTS
-
Dysphoria IoT Botnet Uses Blockchain C2 and Victim Relays After JackSkid Takedown Dysphoria IoT botnet adopted blockchain-based command and control and victim relays after disruption of JackSkid.
- Targets IoT devices like routers, gateways, and cameras with weak Telnet/SSH credentials or known RCE flaws
- Uses Ethereum and Solana Name Services for decentralized C2 resolution
- Employs infected-device relay mesh to hide controllers and complicate takedown
- Spreads via weak-password guessing and exploits such as CVE-2025-9528 in Linksys E1700
- Estimated botnet size over 200,000 devices, active in internet-service and gaming sectors ๐ Coverage: thehackernews.com ยท ๐ via The Hacker News
-
phpMyFAQ before 4.1.6 vulnerable to remote code execution via configuration API
CVE-2026-66398phpMyFAQ versions before 4.1.6 have an RCE vulnerability in the configuration API exploitable by authenticated admins.- Requires CONFIGURATION_EDIT and ATTACHMENT_ADD privileges
- Attack involves uploading a malicious ZIP and manipulating upgrade.lastDownloadedPackage setting
- Malicious code executes as the web server user after extraction into application root ๐ Coverage: cve.threatint.com ยท ๐ Original: cve.threatint.com ยท ๐ via CVE ThreatInt
-
SiYuan before v3.7.2 vulnerable to stored XSS leading to RCE via title-img attribute
CVE-2026-66396Stored XSS in SiYuan before v3.7.2 allows remote code execution via title-img attribute.- Affects Gallery and Kanban cover images rendering unescaped style attribute
- Attackers with editor permissions can inject onload handlers to execute arbitrary code
- Exploited in Electron renderer with full Node.js access when opening affected documents ๐ Coverage: cve.threatint.com ยท ๐ Original: cve.threatint.com ยท ๐ via CVE ThreatInt
-
SiYuan Desktop before v3.7.2 vulnerable to reflected XSS leading to RCE via siyuan protocol
CVE-2026-66395Reflected XSS in SiYuan Desktop before 3.7.2 enables remote code execution without privileges or user interaction.- Vulnerability in bazaar plugin readme handler via siyuan:// deep links
- Injected HTML executes with full Node.js access through insecure Electron renderer insertAdjacentHTML
- CVSS 3.1 score 9.6, critical severity ๐ Coverage: cve.threatint.com ยท ๐ Original: cve.threatint.com ยท ๐ via CVE ThreatInt
-
Apple sued over fake Sparrow Wallet app stealing $1.8M in Bitcoin Users lost $1.8 million in Bitcoin to a fake Sparrow Wallet app on Apple's App Store.
- Fake app impersonated legitimate desktop-only wallet not available on iOS
- Victims entered seed phrases enabling theft of Bitcoin
- Apple allegedly failed to remove fraudulent apps despite warnings
- Plaintiffs seek damages and improved crypto app risk detection ๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
-
Microsoft Defender for Endpoint Update Disabled Protection on Linux Servers After Reboot Microsoft Defender update disabled antivirus protection on some Linux servers after reboot.
- Affected builds: 101.26042.0000 to 101.26042.0009
- Defender service (mdatp) silently disabled after upgrade and reboot
- Microsoft pulled affected builds and released fixed version 101.26042.0011
- Business-critical Linux servers left unprotected and without visibility ๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
๐ CVEs & KEV
- CVE-2026-66398 โ phpMyFAQ before 4.1.6 โ CVSS 7.0 โ Remote code execution via configuration API [KEV]
- CVE-2026-66396 โ SiYuan before 3.7.2 โ CVSS 7.0 โ Stored XSS leading to RCE via title-img attribute
- CVE-2026-66395 โ SiYuan Desktop before 3.7.2 โ CVSS 9.6 โ Reflected XSS leading to RCE via siyuan protocol
๐ฐ UNDER-REPORTED
- braindrain-chrome-extension-ai-prompt-theft โ r/netsec