๐จ ACTIVE EXPLOITATION
- Arista VeloCloud Orchestrator On-Prem OS Command Injection (CVE-2026-16812) Exploited
CVE-2026-16812
Hackers are actively exploiting a critical command injection vulnerability in Arista VeloCloud Orchestrator on-prem servers.- Applies to Arista VeloCloud Orchestrator on-premises servers
- Vulnerability is a CVSS 10.0 remote code execution via OS command injection
- Exploitation allows attackers total control of affected assets
- Attack observed in the wild, prompting CISA to add CVE-2026-16812 to its Known Exploited Vulnerabilities Catalog
- Federal agencies mandated to prioritize remediation under BOD 26-04
๐ Coverage: arista.com ยท ๐ Original: cisa.gov ยท ๐ via @campuscodi@mastodon.social
๐ต๏ธ RESEARCH & DEEP DIVES
-
AI-Assisted Research Finds Linux Kernel Zero-Day LPE in net/sched Subsystem
CVE-2026-0770
Researchers discovered a Linux kernel zero-day enabling local root privilege escalation.- Applies to Linux kernel net/sched packet scheduling subsystem
- Vulnerability is a use-after-free in tcf_idr_check_alloc() causing race condition
- Exploited via RTM_NEWTFILTER and RTM_DELTFILTER netlink routes in unprivileged user namespaces
- Exploit uses KASLR leak, heap reclamation, and ROP to gain root privileges
- Tested successfully on CentOS Stream 9 desktop with exploit under 10 seconds
๐ Coverage: cybersecuritynews.com ยท ๐ via Cyber Security News
-
Over 24,000 exposed server BMCs leak password hashes via 20-year-old flaw
More than 24,000 internet-exposed server BMCs leak password hashes due to an old vulnerability.- Applies to over 24,000 internet-exposed servers with Baseboard Management Controllers (BMCs)
- Vulnerability is a 20-year-old IPMI 2.0 authentication flaw (CVE-2013-4786) allowing password hash leaks
- Attackers can request authentication responses to crack passwords offline using GPU rigs
- Many exposed BMCs use weak or default passwords, including Supermicro systems with factory-set credentials
- Exploitation could allow attackers to control physical servers and pivot across management interfaces
๐ Coverage: bleepingcomputer.com ยท ๐ via BleepingComputer
-
Out-of-bounds write in ImsService enables remote code execution in Android 14-16
CVE-2026-21047
An out-of-bounds write vulnerability in ImsService allows remote code execution on affected Android versions.- Affects Android versions 14, 15, and 16 prior to SMR Jul-2026 Release 1
- Vulnerability is an out-of-bounds write in the ImsService component
- Allows remote attackers to potentially execute arbitrary code
- No user interaction or privileges required for exploitation
๐ Coverage: cve.threatint.com ยท ๐ Original: cve.threatint.com ยท ๐ via CVE ThreatInt
-
Critical Unauthenticated RCE in Joomla Balbooa Forms Versions Below 2.4.3
CVE-2026-65880
An unauthenticated remote code execution vulnerability affects Joomla Balbooa Forms below version 2.4.3.- Applies to Joomla Balbooa Forms extension versions 1.0.0 to 2.4.2.1
- Vulnerability allows unauthenticated remote code execution via insecure form processing
- Exploited through forms including the signature field type
- CVSS 10.0 with high impact on confidentiality, integrity, and availability
- Identified as CWE-94: Improper Control of Generation of Code (Code Injection)
๐ Coverage: cve.threatint.com ยท ๐ via CVE ThreatInt
-
CastleLoader Campaign Uses Fake Crypto Wallet Screens to Steal Recovery Phrases and Browser Sessions
Hackers use fake crypto wallet screens and browser extensions to steal recovery phrases and sessions.- Targets Windows users managing cryptocurrency wallets including Ledger, Trezor, and Exodus
- Uses Rust-based wallet spoofer showing fake recovery phrase prompts to steal secrets
- Delivered via fake software installers, ClickFix-style prompts, and Node.js injectors
- Includes malicious Golang browser extensions posing as ad blockers to hijack sessions
- Employs social engineering to trick victims into running harmful PowerShell commands
๐ Coverage: cybersecuritynews.com
โ ๏ธ TALOS Q2 2026 IR REPORT
- Talos Q2 2026 IR report: Phishing surges, weaponized remote tools aid ransomware
Cisco Talos reports increased phishing and use of legitimate remote tools in attacks.- Phishing caused initial access in over 50% of cases, up from ~33% last quarter
- Attackers use QR code-embedded PDFs and trusted cloud platforms to evade email defenses
- Authentication abuse rose to 65% of cases, with MFA bypass via AitM proxies, token theft, and MFA fatigue
- Ransomware incidents over 20%, including Sinobi using trojanized MeshAgent and Zoho Assist for stealthy access
- Persistent QR phishing campaign targets Australian orgs via compromised Microsoft 365 accounts and internal contacts
- ARToken phishing-as-a-service platform enables MFA bypass and post-compromise token management
- Sinobi ransomware operators weaponize MeshAgent as covert backdoor, deploy ransomware via GPO scripts
๐ Coverage: blog.talosintelligence.com ยท ๐ Original: blog.talosintelligence.com ยท ๐ via Cisco Talos
๐ CVEs & KEV
- us-water-facilities-cyberattack-shutdowns โ @metacurity@infosec.exchange
- danish-central-bank-dormant-emergency-bank-project โ @metacurity@infosec.exchange