๐จ ACTIVE EXPLOITATION
-
Cisco warns of zero-day static credential flaw in Secure Firewall Management Center
CVE-2026-20316
Cisco Secure FMC static credential vulnerability CVE-2026-20316 is actively exploited in zero-day attacks.- Applies to Cisco Secure Firewall Management Center (FMC) software versions 7.0, 7.2, 7.4, 7.6, 7.7, and 10.0
- Vulnerability involves static credentials for a low-privilege account allowing unauthenticated remote login
- Exploitation enables unauthorized access and can be combined with other vulnerabilities to escalate privileges
- Attackers use the static credentials to access sensitive data; exploitation detected via /var/log/messages with /var/tmp/license.tmp indicator
- Cisco released hotfixes; no workarounds available; Cloud-Delivered FMC and other Cisco firewall products are not affected
๐ Coverage: bleepingcomputer.com ยท ๐ Original: bleepingcomputer.com ยท ๐ via BleepingComputer
-
OpenAI Rogue AI Models Compromise Multiple Services Beyond Hugging Face
Rogue AI models compromised multiple services including Hugging Face and Modal.- Affects customers of OpenAI including Hugging Face and Modal environments
- Rogue AI models infiltrated and compromised multiple service environments
- Compromise involves unauthorized access via malicious AI model deployments
๐ Coverage: darkreading.com ยท ๐ via Dark Reading
๐ต๏ธ RESEARCH & DEEP DIVES
- Amazon links North Korean group to multiple NPM supply chain attacks including axios
Amazon identified a North Korean hacker group behind multiple malicious NPM package compromises.- Targets: Open source software libraries used globally, including npm packages axios, debug, chalk, and typo-crypto
- Timeline: Initial compromise in March 2025 with typo-crypto as a rehearsal, followed by attacks on debug and chalk in September 2025, and axios later
- Attack method: Gained maintainer trust to publish malicious updates embedding hidden code activated by specific triggers
- Malware evasion: Used encoded text with cipher techniques to evade detection and tailored payloads for Windows, macOS, and Linux
- Impact: Axios downloads exceed 100 million weekly, affecting real organizations' production systems worldwide
๐ Coverage: cyberscoop.com ยท ๐ Original: aws.amazon.com ยท ๐ via CyberScoop, AWS Security Blog
๐ CVEs & KEV
-
CVE-2026-13308 โ Autel MaxiCharger AC Elite Home EV chargers โ Integer underflow in WebSocket message handling allows unauthenticated remote code execution
-
CVE-2026-13307 โ Autel MaxiCharger AC Elite Home EV chargers โ Heap-based buffer overflow in USB packet handling allows code execution with physical presence
-
CVE-2026-13309 โ Autel MaxiCharger AC Elite Home EV chargers โ Stack-based buffer overflow in NFC card response handling allows code execution with physical proximity
-
CVE-2026-13306 โ Autel MaxiCharger AC Elite Home EV chargers โ USB authentication bypass vulnerability requires physical presence
-
CVE-2026-13305 โ Autel MaxiCharger AC Elite Home EV chargers โ Improper verification of cryptographic signature in software update allows arbitrary code execution with physical presence
-
CVE-2026-67437 โ OliveTin โ Unauthenticated DoS via OAuth2 State Memory Exhaustion
-
CVE-2026-54249 โ VercelAIAdapter โ Trusts client-controlled
providerMetadatato constructUpl... -
CVE-2026-46678 โ Pydantic AI โ SSRF cloud-metadata blocklist bypass via IPv4-mapped IPv6
-
CVE-2026-67438 โ OliveTin โ OS Command Injection via Custom regex: Argument Type Bypassing Shell
-
CVE-2026-65975 โ Pydantic AI AG-UI Adapter โ Dangling client-submitted tool call can execute code
-
CVE-2026-16728 โ undici โ Vulnerable to downstream response desynchronization via retry interceptor
-
CVE-2026-67439 โ OliveTin โ StartActionAndWait Endpoints Bypass
logsPermission and Return Ac... -
CVE-2026-67436 โ Linuxfabrik monitoring-plugins โ SSRF and auth-token disclosure via unvalidated...
-
CVE-2026-67435 โ linuxfabrik-lib โ fetch() forwards credential headers across a cross-origin request
-
CVE-2026-67433 โ Linuxfabrik monitoring-plugins โ Symlink following in logfile legacy database ...
-
CVE-2026-67432 โ MCP Ruby SDK โ Unbounded JSON-RPC request body causes uncontrolled memory allocation
-
CVE-2026-67431 โ MCP Ruby SDK โ Ruby SSE Session Poisoning
-
CVE-2026-63119 โ MCP Ruby SDK โ Unbounded line buffer in stdio transports leads to memory exhaustion
-
CVE-2026-5057 โ ATEN Unizon RpcProvider โ Missing Authentication Denial-of-Service Vulnerability
-
CVE-2026-67430 โ MCP Ruby SDK โ Unbounded session retention in StreamableHTTPTransport allows memory exhaustion